Privacy Policy
1. Who we are and how to reach us
Pawnda is operated by Kinovia LLC. For any privacy question, or to exercise any right described here, write to support@pawnda.app.
This policy covers the Pawnda owner app and the pawnda.app website. It applies to people in the United States and Canada, where Pawnda is offered.
2. What we collect, and where it comes from
Account. Your name, email address, role, plan, the password you set with our identity provider, and the username you choose. Your username forms your Pawnda addresses, which are public mail addresses: your username followed by @pawnda.com is yours (for example maria.chen@pawnda.com), and your username, an underscore and a pet’s name is that pet’s (maria.chen_luna@pawnda.com). Anyone you give one of them to, or anyone who guesses one, can send mail to it; section 6 says what happens to that mail. An account made before usernames also keeps the address first issued to it. When you accept these documents we store which versions you accepted, when, your confirmation that you are 18 or older, whether you accepted in the app or on the web, and the IP address the acceptance came from. If you ask us to delete your account, we store that request and its date. We also keep the time zone your phone or browser reports (for example America/Los_Angeles), so that days, visits and question limits follow your own calendar; a change is saved at most once a day.
Pet profile. Your pet’s name, species, breed, birth date, weight, and the veterinarian you assign.
Home checks, symptoms and check-ins. The resting-breath counts, weights, skin-tent hydration checks and gum checks (the gum color you saw and the refill time) you record, each with the local date and time you recorded it. Symptoms you log: what happened and the note you wrote in your own words. Daily check-ins: your pet’s mood, appetite, walks and play, and any note you add. Foods you register for a pet, including brand, product, lot number and best-by date.
Pre-triage. When you run one: what is wrong, since when, the symptoms and changes you pick, and any medications, diet, notes, questions for your vet and photos from your pet’s gallery that you add; and the urgency, guidance, warning signs and any AI advice Pawnda gave you, and when. Each one is also saved as an owner-entered record in your pet’s records. As you fill it in, what you have written so far is checked for an emergency; that check keeps nothing.
Photos and camera. Photos you import from your photo library, take in the app or add on the website, the tag you file each one under (moment, portrait, poop, vomit, skin, wound, food, record), and the date the photo was taken. That date comes from the photo’s own metadata, or from the creation date your photo library reports, or else is the day you add it. A photo’s metadata can also record where it was taken: Pawnda removes that location from every photo it receives, whether from the app, the website, mail or a chat, and again whenever it shows or sends a photo, so no one who opens a photo through Pawnda gets its location. A photo stored before this version, and a message as it arrived at a Pawnda address (kept at most 7 days, section 6), can still hold it in our storage. iOS asks for your permission before Pawnda can read your library or use the camera, and you can withdraw it in iOS Settings.
Location. If you tap “Near me” on the Vets screen, iOS asks whether Pawnda may use your location while you use the app. It is used on your phone only, to sort Pawnda clinics by distance and to center the map. That location is never sent to Pawnda’s servers and is not stored; the place a photo was taken is a separate matter (see Photos and camera, above). You can withdraw the permission in iOS Settings.
Pawnda addresses and mail. For every message sent to one of your Pawnda addresses: the sender’s address, the subject, the time it arrived, which pet it went to and how that was decided, and the attachment filenames, types and contents. We read the words of the message when it arrives, to find which pet it is for, but we do not keep them, except in a message with no attachment: then its own text (without the earlier messages a reply quotes) is kept like an attachment. Attachments from a sender you have not approved are held, not filed, until you approve or block the message. We also keep your trusted senders (each address, the name you gave it, when it was added, and whether you approved their mail, added them yourself, or added them when you asked your clinic to send records) and the senders you blocked. Each mailbox keeps the newest 100 messages from senders you have not approved (section 7); filed mail, and mail from senders you trust, stays listed.
Ask Pawnda. Your question, any photo you attach to it, and the chart summary assembled for that question. We keep a count of how many questions you asked in the current month, used to enforce plan limits. A pre-triage that asks the model has its own monthly count, so it never uses up your questions.
Sharing. The share links you create (the token, when it was created and when it expires, the recipient email or a hash of the access code that unlocks it, who opened it, and how many questions were asked on it today), which pet each one points at, and the vets you have connected. When a vet keeps your pet from one of your links for 30 days, we record which vet and which link, when the 30 days end, and when and why their access ended.
Care team and visits. The vets on your pet’s care team, how each one joined and since when; and the visits you mark: the vet, the date and time, the reason, your questions, and the pre-triage and records you attach.
Guardian Score reports. The reports you make: what each one showed when you made it (section 5 lists it), when it was made and when it expires, whether you revoked it, and how many times its link was opened and when it was last opened. A report does not record who opened it.
Support. Anything you write to us through the support form or by email, and our replies.
Technical. Server logs including IP address, request path, device type and app version, kept to run and secure the service. Pawnda contains no advertising SDK and does no cross-app or cross-site tracking.
3. How we use it
To run your account and keep you signed in. To build your pet’s chart and its trends. To match the foods you log against recall notices. To read mail sent to your Pawnda addresses and file it against the right pet. To make the Guardian Score reports you ask for. To generate answers and photo observations in Ask Pawnda. To show a record to a veterinarian when you share it. To give you pre-triage guidance, and to show it, with an alert when it cannot wait, to the vets on your pet’s care team. To let you find vets on Pawnda, add them to your pet’s care team and show them the visits you mark. To screen AI output for medical content that owners must not receive. To answer support requests. To detect abuse, and to meet legal obligations.
We do not use your pet’s records, your photos or your questions to train our own models, and we do not use them for advertising.
4. AI processing
Ask Pawnda is powered by a large language model operated by Anthropic, a third-party model provider under contract with Kinovia.
When you ask a question we send Anthropic three things. First, the text of your question. Second, a context block assembled from your own records for that pet: the pet’s species, the pet’s name, and the pet’s birth date if you recorded one (these go on every plan, free included); the pet’s breed on Prime only; your most recent weight and its trend; your most recent resting-breath count and hydration check; up to four recent symptoms you logged, including the notes you wrote; and any active recall match on a food you registered. Third, if you attached one, the photo itself, encoded as image data.
For a question, we do not send your own name, your email address, your Pawnda addresses, your other pets, or any other account’s data.
The reply comes back to the app with the standing disclaimer attached. Pawnda’s prompt and screening are built to keep diagnosis, medication names and dosing out of every answer, and to redirect emergencies before the model is called at all. Kinovia staff may review flagged or reported outputs to improve that screening.
Mail to your own address. When you have more than one pet and a message arrives at your own address (not a pet’s) from a sender you trust, whose address passed the sender checks in section 6, Pawnda first looks for a pet’s name or microchip number in it. If that does not settle which pet it is for, we may ask the same model provider. We send your pets’ names and species, the subject, and up to 4,000 characters of the message’s words and of the text in its attachments. We never do this for mail from a sender you have not approved, and if the answer is not clearly one of your pets, the message waits for you to choose.
Records and photos you add. Records and photos you add are stored in your pet’s chart at once. Pawnda sends them to the same model provider to read what they contain (the image itself, or the file’s name and text) only once a veterinarian on your pet’s care team, or their office desk, has approved your pet for Pawnda review. Until then nothing you add is read by the model; the moment they approve, Pawnda reads every record already on the chart and each one that follows. What it reads back, such as dates, vaccinations, medications and lab values, is saved in your pet’s chart and marked unverified. A snapped food label is the one exception: its brand, product, lot and best-by date are suggested for you to confirm when you snap it. Attachments filed from mail are read the same way once your pet is approved.
Pre-triage. A pre-triage’s urgency and guidance come from fixed rules, and an emergency is answered by those rules alone, before anything else happens. Otherwise, when our model is available, we also send Anthropic what you wrote about what is wrong, how long it has been going on, the symptoms and changes you picked and your notes, with the same context block as an Ask Pawnda question; the answer passes the same screening, can make the guidance more urgent but never less, and any advice it gives is kept apart from the rules’ guidance, labeled “From Pawnda’s AI” with the line “Not professional advice · AI can make mistakes”, wherever the pre-triage appears, its record included. The medications, diet, questions and photos you add are not sent to the model.
Questions on a share page. When someone who holds a share link’s password asks Pawnda about the page, we send Anthropic their question and the same context block as your own Ask Pawnda questions, with your pet’s breed on any plan. If they are signed in to a Pawnda vet account, we send what the portal sends for a veterinarian’s question instead (see the appendix). These conversations are not saved with your pet’s records or your account.
Anthropic processes everything this section describes as our service provider under its commercial terms and, under those terms, does not use it to train its models. Counsel must confirm Anthropic’s current retention period before this policy is published; this draft does not state one.
5. How information is shared
With your direction. With a veterinarian or clinic when you create a share link, add a vet to your pet’s care team, mark a visit, forward records, submit documents, or make a pet visible to a vet. A share page only opens with the password you set on the link (the recipient’s email address or an access code you give them), and anyone with the password can also open the records on it, as section 8 of the Terms of Service describes. It expires on its own (3 days by default, 7 at most) and you can revoke it from the app or the website at any time. A veterinarian with active Pawnda access who unlocks your link while signed in keeps access to that pet’s chart until you remove them; any other vet with a Pawnda account can keep that access for 30 days, read-only, including records you add later; it ends sooner if you turn off the link or remove them, and lasts until you remove them if the vet gets a membership meanwhile. A clinic that receives records keeps its own copy under the recordkeeping rules that apply to it.
Your pet’s care team. The vets on your pet’s care team (the ones you add, the ones you name on a visit, and the ones who keep your pet from a share link) see your pet’s records and photos, your home logs and pre-triages, every visit you mark for that pet whichever vet it is with, and your name, while their Pawnda access is active, and read-only for 14 days after it ends. When your latest pre-triage says go now or see a vet today, they also see an alert in their Pawnda portal for 14 days; Pawnda does not phone, text or email them. In the portal they can ask Pawnda about your pet, which sends its chart to our AI model provider as the appendix describes. A visit note a vet adds to your pet’s records carries their name and clinic, and goes wherever you share your records.
Guardian Score reports. When you make a Guardian Score report, anyone who has its link or its QR code can open it, without signing in and without a password, until it expires 30 days after you made it or until you revoke it. Search engines are told not to list it. It shows your first name and last initial, your Guardian Score and its level, your care streak, each pet’s first name and care points, what the score measures and what it never measures, and the date Pawnda issued it, all as they were when you made the report. It never shows a medical detail, a record, your pets’ full names or your email address. The PDF of a report shows the same, with the report’s link, a QR code for it and the report’s ID, and a PDF someone has already saved stays as it is after you revoke the link. We count how many times the link is opened and show you the count and the last time; your own opens are not counted, and we do not record who opened it (like any request to our servers, an open also appears in the server logs described in section 2).
Service providers. Cloud hosting and storage (Amazon Web Services), identity and sign-in (Amazon Cognito), receiving and screening mail sent to Pawnda addresses (Amazon Simple Email Service, part of Amazon Web Services), and our AI model provider (Anthropic). They act on our instructions under contract.
Legal requirements. When required by law, legal process, or to protect the rights and safety of people or animals.
Business transfers. In connection with a merger, acquisition or sale of assets, with notice where the law requires it.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
6. Mail sent to a Pawnda address
Who can send it. Anyone who has one of your Pawnda addresses can send mail to it: your clinic, another clinic, you forwarding your own mail, or anyone else who has or guesses the address. Mail to an address nobody holds reaches no one.
Where it goes. Mail to a pet’s address is for that pet. Mail to your own address is for your only pet; if you have more than one, Pawnda looks for a pet’s name, written as the pet’s name (a capitalized “Bear”, never “bear in mind”), in the subject, on a “Patient:” line of the message or its attachments, or in an attachment’s file name, and for a microchip number anywhere in it; a name that appears only in the body of the message is not enough. For a sender you trust it may also ask our AI model provider (section 4). When it cannot tell, the message waits for you to choose, and you can move a filed record to another of your pets. It never guesses. A message with records for two pets is split between them only when each attachment clearly names one pet.
Unknown senders wait; trusted senders file automatically. Mail from a sender you have not approved always waits for you on the Mail screen, and nothing in it is filed until you approve it. Mail from a sender you trust files itself, and so does mail you forward from the email address you sign in with.
Sender checks. A message counts as coming from the sender it names only when that sender’s own domain vouches for it (the DMARC check, which builds on SPF and DKIM). A message that does not pass it waits for you, even when it names a sender you trust, so mail from a clinic whose domain publishes no DMARC policy always waits for your approval. A message that does not name exactly one sender, or that our mail provider marks as spam or as carrying a virus, is dropped before it reaches your mailbox.
The message as it arrived. We keep the message as it arrived, with its attachments, in encrypted storage only until it has been delivered to your mailbox, and never more than 7 days; then it is deleted.
Attachments become records. When mail is filed, each attachment becomes a record in that pet’s file, where you, and any veterinarian you share the pet with, can see it. A message with no attachment from a sender you trust files its own text as a record when there is enough of it to read as one (a visit summary written in the email); a shorter one, and any message with no attachment that you send from your own address, waits for you. The request the app writes when you ask your clinic for records is not filed or kept. Pawnda does not file an attachment over 10 MB, a PDF over 50 pages, or an image over 60 megapixels; the message says which one and why, and mail with such an attachment waits for you even from a sender you trust.
If you sent mail to a Pawnda address. If you are a clinic or an individual who emailed someone’s Pawnda address, we store your address, your subject line and your attachments so the account holder can decide whether to accept them, or file them at once if the account holder trusts you. We do so on the account holder’s behalf. If you want that copy removed, write to support@pawnda.app with the address you sent from.
7. How long we keep it
Account, pet and chart data: while your account exists.
A message as it arrived at a Pawnda address: in encrypted storage until it has been delivered to your mailbox, and never more than 7 days (section 6).
Held attachments from senders you have not approved: until you approve or block the message, or until the account is deleted. Each mailbox keeps the newest 100 messages from senders you have not approved; older ones are dropped with their attachments. It keeps the contents of at most 30 messages a day from senders who are not on your trusted list; past that, or when our space for waiting mail is full, a message is held back: you see a note that it came and from whom, without its contents, and the message as it arrived is deleted within 7 days (section 6). Filed mail, and mail from senders you trust, is never dropped this way. If the attachments waiting in one mailbox grow past our size limit, the oldest are dropped, and the message stays listed so you can see it came. A fixed holding period is planned; this version does not promise one.
Mail from a sender you have blocked: we keep only a note that it arrived (at most the sender, the subject and the attachment names), never its attachments.
Share links: they open only until they expire, at most 7 days, after which the record they point at is no longer reachable through them. The note of who opened a link stays with your account, so you can see which vets have seen your pet’s record.
A vet keeping your pet for 30 days from a share link: their access ends 30 days after they kept it, when you turn off that link, or when you remove the vet, whichever comes first, unless they get a membership meanwhile (then it lasts until you remove them). A note that they kept it and how it ended stays with the vet’s account.
Pre-triages, visits and your pet’s care team: while your account exists. A visit you delete leaves the vets’ view right away, and a vet you remove stops seeing your pet right away; a pre-triage stays in your pet’s records like any other record.
Guardian Score reports: a report opens only until it expires, 30 days after you made it, or until you revoke it. What it showed, its dates and its open count stay with your account, so you can see your past reports, until the account is deleted.
Ask Pawnda questions and answers in the owner app: not stored on our servers today beyond the monthly question count. (A veterinary practice’s Ask Pawnda conversations in the portal are kept with that practice’s account until the practice clears them; see the appendix.) If we introduce an audit log of AI answers in the owner app, we will say so here first.
Deleted accounts: erased within 30 days of the request, except records already delivered to a veterinary practice and anything the law requires us to keep. Today the erasure is carried out by our team against the request and erase-by date we record when you ask; it is not yet automatic. We also keep the Pawnda addresses themselves (your username and any address first issued to your account), with nothing attached to them, so they are never given to anyone else; mail sent to them afterwards reaches no one.
Server logs and backups: kept for a limited period on a rolling schedule, then overwritten.
A durability note, honestly. Photos, uploaded files and attachments filed from mail are archived, with the original file, in storage on our servers that survives restarts and new versions of the app. They are not yet replicated to a second location, so a failure of that storage could lose them: keep your originals until we say this has changed. They are kept and erased under the rules above: while your account exists, and within 30 days of a request to delete it.
8. Your rights and choices
You can ask us for a copy of what we hold, to correct it, or to delete it. Depending on where you live, you may also have the right to object to or restrict certain processing, and not to be discriminated against for exercising any of these rights. We will not charge you for a reasonable request.
Delete your account in the app: open your account from Today, then choose Delete my account. On the website, pet owners choose Delete my account in the account menu, veterinarians choose it in Settings in the vet portal, under Account, and a clinic’s office desk account has it in its account menu. We record the request and erase within 30 days, subject to the exceptions in section 7. The founders see each request (the email address, the account type, when it was asked and the erase-by date) so they can carry it out, and they can withdraw it if you ask them to before then.
Correct or export a record. You can export a pet’s records as one PDF from the pet’s Share screen in the app, or with Export as one PDF on its Records tab on the website. In-app editing isn’t built yet; email support@pawnda.app and we will make the change.
Cancel a share link early. On the pet’s Share screen, revoke the link, or on the website turn it off under the pet’s Vets tab. It stops opening immediately, and a vet keeping your pet for 30 days through it loses access.
Stop a vet seeing a pet. On the pet’s Share screen, remove the vet from the vets with access, or remove them from the pet’s care team in the app or on the website. The pet leaves their patient list right away. A copy a practice already holds is governed by its own recordkeeping rules.
Change or delete a visit. In the app or on the website, change or delete a visit you marked; the vets on the care team see the change right away.
Manage senders. When a new sender’s message is waiting, you approve or block it from the Mail screen in the app. Approving files it and trusts the sender, so their later mail files itself; blocking drops what they sent, and we keep only a note of their later mail. Under Trusted senders you can add a sender yourself and remove one at any time, and a removed sender’s next message waits for you again. You can unblock a sender you blocked, and dismiss a waiting message without blocking its sender.
Revoke a Guardian Score report. On the Guardian Score screen, open the report and revoke it. Its link and QR code stop opening right away; a PDF someone has already saved stays as it is.
Withdraw consent. Stop using the app and delete your account. Some processing continues after deletion: keeping the acceptance record itself, and anything the law requires.
Device permissions. Camera, photo-library and location access are granted and withdrawn in iOS Settings.
To exercise any of these, write to support@pawnda.app from the email address on the account. We may ask you to confirm it is you before we act.
9. Children
Pawnda is not directed to children under 13 and we do not knowingly collect their information. An account requires you to be 18 or older. If you believe a child has given us information, contact support@pawnda.app and we will delete it.
10. Security
We use administrative, technical and organizational measures designed to protect your information, including encryption in transit, access controls, and infrastructure hosted with reputable cloud providers.
No method of transmission or storage is completely secure and we cannot guarantee absolute security. If you find a vulnerability, please report it to support@pawnda.app rather than testing it against other people’s accounts.
11. Where your information is processed
Pawnda is operated from North America and your information is processed and stored in North American data centers. If you use Pawnda from elsewhere, you understand your information will be transferred to jurisdictions whose privacy laws differ from your own.
12. Sample and demo data
Demo and preview accounts show fictional pets and fictional recall notices, labeled “Sample data”. They are not real animals, real clinics or real regulatory notices, and no real recall is ever hidden behind them. No live recall feed is connected yet, so other accounts see no recall notices until one is.
Every vet account also shows one demo patient, labeled as a demo wherever it appears and never shown to pet owners: a fictional cat built from a real cat’s records, with the personal details (names, clinics, vets, addresses and numbers) replaced and the clinical content kept.
Apart from that demo patient, a new account never receives another person’s pet, records or mail.
13. Website forms
The Pawnda website has three forms: early access for pet owners, the application for founding clinics, and the contact form.
What they collect. Each form sends only the fields it shows, and each is stored with the time it was sent.
The early-access form for pet owners sends your email address and, if you choose one, how many pets you have (1, 2, or 3 or more), and marks the sign-up as a pet owner’s.
The founding-clinic application sends your name, your work email, the clinic’s name, your role at the clinic (veterinarian, practice manager, owner or partner, or other), how many doctors work at the clinic, the practice software it uses if you name it, and anything you add in the notes box, and marks the sign-up as a clinic’s. The clinic’s name and your email are kept as their own fields; your name, role, the number of doctors, the practice software and your notes are kept together as one note on the application.
The contact form sends your name, your email address, a subject and your message.
None of the forms saves your IP address with what you send. The early-access and clinic forms hold it in memory for up to ten minutes to limit repeated sign-ups. Like any request to our servers, sending a form is also recorded in the server logs described in section 2.
Why. To tell you when Pawnda is ready for you, to consider a clinic for the founding program, and to answer what you wrote. We use them for nothing else, and we do not sell them or use them for advertising.
Where they are kept. Early-access and founding-clinic sign-ups are kept in Pawnda’s own data store on our servers. Contact messages are kept in our support message table, in our cloud database with Amazon Web Services.
How long. Until you ask us to delete them. We have not set an automatic deletion period for these forms; this version does not promise one.
Deleting them. Write to support@pawnda.app from the email address you used, and we will delete your sign-up or your message.
14. Changes to this policy
This policy is versioned by date. When we make a material change (in particular to sections 2 through 8), the app, and your pet owner account on the website, will ask you to accept the new version before you continue using it, and we will post the new version on pawnda.app. Minor corrections keep the same version number.
15. Contact
Kinovia LLC · support@pawnda.app
Appendix: veterinary practices using Pawnda
This appendix is not part of the numbered sections; it covers the portal Kinovia operates for veterinarians and veterinary practices. A practice with its own agreement with Kinovia uses the portal under that agreement; a veterinarian who opens a vet account on the Pawnda website accepts this policy and the Terms of Service at sign-up.
What a clinic account adds. Alongside the account information in section 2, we hold the clinic details given at registration or onboarding, the documents a practice uploads or receives through Pawnda (labs, visit summaries, vaccination records, images), and the structured data extracted from them, with each value traced to the page it came from.
Vet accounts and access. For each vet account we also keep: the profile you give owners (your name, specialty, clinic name, city, region and country, your clinic’s phone number if you add one, and whether owners can find you in search, which is on unless you turn it off); your access (whether it came from a coupon, founding access, a membership or a founder’s test, when it started and when it ends, the coupon’s code and months, and whether a membership renews) and a history of its changes, with coupon codes masked; the coupons you redeemed, with the account, email address and time of each redemption; whether you are verified, which founder or coupon verified you, and when; the first and the latest day you used the portal, and whether our sign-in provider had confirmed your email address then; how many Ask Pawnda questions you have asked today without active access; the pets you kept from share links for 30 days, with the link, the dates and how each one ended; and, if you pressed Subscribe before payments opened, your name, email address, the billing interval you chose and when you asked, so we can write to you when memberships open. Ending access deletes none of this.
What Pawnda’s founders see. The founders can see every vet account (name, email address, clinic, city, specialty, access and when it ends, whether you are verified, listed and findable, when you joined and last used the portal, and whether you asked to subscribe), every coupon and the list of testers, and can give founding access, issue and revoke coupons, add and remove testers, and mark a vet as verified.
Team and test accounts. A vet account whose confirmed email address is at pawnda.app, Pawnda’s own domain, has access without a coupon or a membership (team access). The founders also keep a list of testers they let into the vet portal to try Pawnda, such as investors, advisors and test users: for each, the email address, a short note on who they are, which founder added them and when, an optional end date, and, once removed, which founder removed them and when, kept as history. A vet account whose confirmed email address is on the list has test access until the founders remove it or its end date passes; it then ends at once, with no read-only days. The founders see whether each tester has signed up and when they last used the portal. Team and test accounts are listed for owners, and can be shown as Verified, on the same terms as any other vet account. To have a tester entry deleted, removed ones included, write to support@pawnda.app from that email address.
What owners see about you. Owners find you in Pawnda search, by your name, clinic or city, only while your account setup is finished, your clinic’s name and city are set and your listing is on. Pawnda’s founders can also hide an account from owner search; when they do, we keep which founder hid it and when. While Pawnda requires active access to open patients, your access must also be active. Search shows your name, specialty, clinic, city and region and whether you are Verified, never your email address or phone number, and neither does Pawnda’s verified clinic list, which shows a listed vet’s name and specialty and the clinic’s name and address on a map. Owners who have you on a pet’s care team also see your clinic’s phone number, since when you have had access to the pet, and whether you can open its records now (your access state, never its end date). An owner whose share link you open while signed in sees your name, or your email address if your account has no name, and when you opened it.
Pets owners share with you. A pet whose owner adds you to its care team, names you on a visit, or shares it with you by link stays in your patient list until the owner removes you; you can open it while your access is active, and read-only for 14 days after it ends. Without active access, a pet you keep from a share link stays for 30 days, read-only, including records the owner adds, and leaves sooner if the owner turns off that link or removes you; if your access becomes active meanwhile, it stays until the owner removes you. A visit note you add to a pet’s records becomes part of the owner’s records: it carries your name and clinic, the owner and anyone they share the pet with can read it, including through a share link, and later edits to your note never change that copy.
AI processing in the portal. Section 4 describes what the owner app sends to the model. The portal sends more, because it works from the full chart: when a veterinarian asks Pawnda about a patient, we send Anthropic the question, the text of the records on that chart that the question needs (newest first, within a size budget), the values extracted from them, the practice’s own notes and corrections on that chart, and any file the veterinarian attached to the question. Document extraction itself, turning an uploaded record into structured values, also runs through the model. We do not send the practice’s account details. The portal keeps each veterinarian’s Ask Pawnda conversation per patient, with the practice’s account, until the veterinarian clears it. The same provider terms as section 4 apply.
A practice’s own responsibilities. A veterinarian or clinic using Pawnda is responsible for giving pet owners the notices they are owed, obtaining the consents their jurisdiction requires for record handling, and using the platform in line with the veterinary recordkeeping and privacy laws that apply to them.
Records a practice receives stay with the practice. A record an owner shares becomes that practice’s record under its own recordkeeping obligations. Deleting a Pawnda owner account does not delete the practice’s copy (section 7).