Privacy Policy
Effective May 24, 2026 · Operated by Ember Ventures Ltd. (British Columbia, Canada)
This Privacy Policy explains how Ember Ventures Ltd. ("Haku", "we", "us") collects, uses, and protects information when you use the Haku mobile app, web app, and related services (the "Service").
We aim to collect the minimum data needed to make Haku work — and to be plain about what we do with it. This policy applies regardless of where you live.
1. What we collect
You give us
- Account info. Email address and password (passwords are hashed by our auth provider and never visible to us).
- Pet profile data. Names, photos, breed, sex, birth date, weight history, diet, vet contact, insurance info, medications, allergies, scanned vet documents — whatever you choose to add.
- Videos and audio. The 10-second video clips you record during scans, including their audio track.
- Email preferences. Your choices about which transactional emails you receive.
Generated by the app
- Scan analyses. The AI-generated reading produced from your video — primary state, FGS pain score, mood radar, body-language notes, inner monologue, etc.
- Baselines and trends. Statistical summaries of your cat's scans over time.
- Earned badges. Gamification awards tied to scan history.
Collected automatically
- Device info. Device type, OS version, locale, time zone — used to render the app correctly and time-calibrate readings.
- Crash + error logs. Stack traces from app crashes (no personal data attached).
2. How we use it
- To run the Service. Process your video into a reading, save your pet history, sync across your devices, send password-reset and account emails.
- To send the emails you've opted into. Welcome email, pain alerts, weekly digests — only those you've left enabled in Account settings.
- To improve the Service. Anonymized, aggregated data (with no individual videos and no personally identifying information) may be used to refine our analysis models. We do not train models on your individual videos by default.
- To meet legal obligations. Tax records, fraud prevention, responding to lawful requests.
3. How videos are handled
Your scan videos are the most sensitive thing you give us. We treat them accordingly:
- Acoustic analysis runs in your browser. Audio features (pitch, duration, frequency content) are computed locally on your device using Web Audio. The audio waveform is not transmitted to our servers.
- Video frames are processed transiently. A small number of frames are extracted from your clip and sent to our AI provider (Anthropic) for analysis. They are not persisted to our long-term storage.
- Only a small thumbnail is saved. A compressed thumbnail (≤360px) is stored with your scan record so you can browse your history. The full-resolution video is discarded after analysis.
- We do not sell your videos. Ever.
4. Who we share it with
We share data only with the service providers Haku depends on, under contractual safeguards:
- Supabase (database + authentication hosting). EU/US regions.
- Anthropic (AI model API — Claude Sonnet/Haiku) for processing scan frames. Per their policy, API inputs are not used to train their models.
- ElevenLabs (text-to-speech for inner monologues and voice memos), when you trigger playback.
- Resend (email delivery) for transactional emails.
- Vercel (hosting + serverless compute).
- Apple and Google (app stores) for subscription processing — we don't see your payment details.
We don't share data with advertisers, data brokers, or analytics vendors that build profiles on you.
5. Data retention
- Account + pet data: retained as long as your account is active.
- Scan records: retained as long as your account is active or until you delete them.
- Crash logs: 90 days.
- Deleted account: all of your data is permanently deleted from our active databases within 30 days. Backups are cycled out within 90 days.
6. Your rights
Depending on where you live, you may have rights including:
- Access: request a copy of your data.
- Correction: ask us to fix inaccurate data.
- Deletion: ask us to delete your data (you can also delete from Account settings).
- Portability: request your data in a portable format.
- Withdraw consent: at any time, with no impact on prior processing.
To exercise any of these, email hello@hakuapp.io. We respond within 30 days.
7. Children
The Service is not directed to children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
8. Security
We use industry-standard encryption in transit (HTTPS/TLS) and at rest, row-level security on our database, and SOC-2-certified hosting providers. No system is ever 100% secure — if you discover a vulnerability, please email hello@hakuapp.io.
9. International transfers
Haku is operated from Canada, with hosting in the US and EU. By using the Service, you consent to your data being transferred to and processed in those jurisdictions, with appropriate contractual protections.
10. Changes to this policy
We'll post any updates with a new effective date and notify you in-app or by email if the changes are material.
11. Contact
Ember Ventures Ltd. · British Columbia, Canada
Privacy questions or rights requests: hello@hakuapp.io
