Privacy Policy
Last updated: May 2, 2026
This Policy describes how personal data is collected, used, and protected in the Nosik app and on nosik.pet (the "Service").
1. Data Controller
The controller of your personal data is:
2. What data we process
2.1. Account data
- Email address (obtained from Google Sign In or Sign in with Apple)
- Name (if provided during sign-in)
- Unique identifier from the authentication provider
2.2. Data you add in the app
- Names and breeds of your pets
- Medication names, intervals, and administration history
- Vaccine names and dates
- Veterinary appointment dates
2.3. Technical data
- Device push token — for sending reminders
- IP address (temporary, in server logs)
- Device type and app version
- Request timestamps
We do NOT collect: location, contacts, photos, messages, data from other apps, advertising identifiers, or biometric data.
3. Why we process your data
- Service delivery: storing your pets, medications, and vaccines; syncing across devices.
- Sending reminders: push notifications about buying or giving medication, booking a vet visit.
- Security: abuse detection and fraud prevention.
- Legal obligations: responding to official lawful requests from authorities.
Legal basis for processing (GDPR Art. 6):
- Performance of a contract (Terms of Use) — for service delivery.
- Your consent — for push notifications. You can withdraw consent in your OS settings at any time.
- Legitimate interests — for security, diagnostics, and abuse prevention.
4. Who we share data with
We do not sell your data and do not share it with third parties for marketing purposes. We use the following third-party processors to operate the Service:
- Google LLC — Google Sign In (only if you chose this method).
- Apple Inc. — Sign in with Apple (only if you chose this method).
- Hetzner Online GmbH (Falkenstein, Germany) — server infrastructure where your data is hosted.
- Apple Push Notification Service and/or Firebase Cloud Messaging (Google) — push notification delivery.
Where data is processed by Google LLC or Apple Inc. (US-based companies), any transfer outside the EEA is governed by Standard Contractual Clauses adopted by the European Commission, incorporated into Google's and Apple's data processing terms.
Data may be disclosed to law enforcement exclusively upon receipt of an official lawful request under applicable law.
5. Where and how long we store data
- Servers are located in Falkenstein, Germany (Hetzner Online GmbH), within the EU/EEA — GDPR applies.
- Data is stored for as long as you use the Service.
- After account deletion, personal data is deleted within 30 days.
- Server logs (IP addresses, request timestamps) are stored for up to 90 days and then automatically deleted.
- Certain data may be retained longer if required by law.
6. Security
We apply technical and organisational security measures:
- Encrypted connections (HTTPS/TLS).
- OAuth authentication — we never see or store your Google or Apple passwords.
- Restricted server access.
- Regular backups.
No internet service can guarantee absolute security. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the competent authority within 72 hours as required by GDPR.
7. Cookies and tracking
The Nosik app does not use cookies, advertising trackers, or third-party analytics. The website nosik.pet does not use tracking cookies either.
8. Your rights
Under GDPR you have the right to:
- Access — obtain a copy of your personal data.
- Rectification — correct inaccurate or incomplete data.
- Erasure — delete your account and all associated data. Instructions on the delete account page.
- Restriction of processing — suspend processing in certain cases.
- Data portability — receive your data in a machine-readable format (JSON).
- Objection — object to processing based on legitimate interests.
- Withdrawal of consent — at any time, without affecting the lawfulness of prior processing.
- Lodge a complaint — with the supervisory authority in your country of residence (e.g. ICO in the UK, or the relevant EU national DPA).
To exercise your rights, contact us at [email protected]. We will respond within 30 days.
9. Children
The Service is not intended for persons under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with data without parental consent, please contact [email protected] and we will delete it.
10. Changes to this Policy
We may update this Policy from time to time. The date of the last update is shown at the top of this document. We will notify you of significant changes in the app or on the website. Continued use of the Service after an update constitutes your acceptance of the revised Policy.
11. Contact
For questions about data processing: