Privacy policy
Nihao ("Nihao", "we") is a social app for pet owners. This policy explains what we collect, why, how long we keep it, and how to get it back or delete it.
One principle drives most of what follows: location is the most sensitive thing here, so it is blurred by default. Everything this document says about location describes behaviour that is already in the product, not an intention.
1. What we collect
| Data | Why | Where it lives |
|---|---|---|
| Email address | Sign-in, account recovery, necessary notifications | Supabase Auth. Our application database does not store it. |
| Nickname, photo, bio | So other people know who they are talking to | Application database; images in Supabase Storage |
| Area name (e.g. "College Park") | Shows roughly where you are | Application database |
| Location coordinates | To compute the distance between you and other people | Application database, stored already blurred according to your mode (see §2) |
| Pet profile: name, species, breed, sex, neutered, temperament, meetup preferences, photos | This is the main content of the app | Application database; photos in Supabase Storage |
| Posts, comments and likes | Shown to the audience you chose | Application database; images in Supabase Storage |
| Direct and group message content and images | Delivered to the other side of the conversation | Application database; images in Supabase Storage |
| Activity joins and participation | So the host knows who is coming | Application database |
| Walk records: duration, distance, count, and a temporary location while you share one | To build the walk summary and let nearby walkers see you | Application database |
| Device push tokens | To send push notifications | Application database |
| Name, email and message from the website contact form | To reply to you | Application database |
We do not collect your contacts, your photo library (beyond the images you choose to upload), your street address, payment information (V1 has nothing to pay for), or your behaviour in other apps.
About IP addresses
We do not store your raw IP address. To limit abuse — dozens of contact-form submissions in an hour from one network, say — we store a salted SHA-256 hash of it, which cannot be reversed and is deleted automatically after 24 hours.
Server logs are retained by Vercel and Sentry for about 30 days. They do not contain request bodies, query strings, email addresses, IP addresses or coordinates.
2. Location: four modes
You can change this in settings at any time, and the change takes effect immediately:
- Precise — the raw coordinates the device reports. Only used if you choose it.
- Approximate (default, recommended) — coordinates are snapped to a roughly 500 m grid before being stored. The blurred value is the one we keep.
- Pick a neighbourhood — you choose an area and we use that area's centre point.
- Pick a public place — a park, a campus, a plaza. A home address is never an option.
Whichever mode you use:
- Our API never returns your coordinates to another user. What other people receive is a distance rounded to 0.1 miles, an area name, or the name of a public place.
- Anything under 0.3 miles is reported as "within 0.3 mi", so that repeated sampling cannot be used to triangulate you.
- The markers other people see on a map are drawn by their own device from that distance, or are the coordinates of a public place. They are not your position.
Temporary location during a walk
Only when you start a walk and turn sharing on does the app publish a temporary location so nearby walkers can see you. That location:
- updates only while the app is in the foreground — we do not track you in the background;
- can be switched off at any moment, with the walk continuing;
- is erased when the walk ends, or after at most 4 hours, whichever comes first.
3. What we do with it
Four things: run the app's features; keep people safe (handling reports, banning abusive accounts); send you the notifications you asked for; and answer you when you contact us.
We do not sell your data and we do not give it to advertisers. V1 has no advertising, no third-party ad SDK, and no cross-app tracking.
4. Who can see it
| Who | What they see |
|---|---|
| Other users | Your nickname, photo, bio, pet profiles, the posts you made public, the activities you joined, and a blurred distance |
| People in your chats | What you sent in that conversation |
| Our team | Only what is needed to act on a report, or on something you asked us about |
| Law enforcement | On receipt of a legally valid request, limited to what it requires |
5. Third parties we use
| Service | For | What it touches |
|---|---|---|
| Supabase | Database, authentication, image storage | Everything in the table above |
| Vercel | Hosting for the site and the API | Request metadata; logs carry no bodies, emails, IPs or coordinates |
| Resend | Email (sign-in codes, notifications, contact replies) | Recipient address and message body |
| Expo Push Service | Push notifications | Device push token and the notification text |
| Sentry | Crash and error monitoring | Stack traces and device info; personal-data capture is off (send_default_pii=False) |
| PostHog | Product analytics | Anonymous events such as "finished onboarding" — never message content or coordinates |
6. How long we keep it
- Message content is kept indefinitely, because a conversation belongs to both sides of it. If you delete your account, the words you sent remain in the other person's thread with the sender shown as a deleted user; the images you sent are deleted and appear as placeholders. You deserve to know this before you sign up rather than after.
- In-app notifications: 90 days.
- Push tokens: deleted after 90 days of inactivity.
- IP hashes: 24 hours.
- Website contact-form submissions: 24 months, or sooner if you ask us to delete one.
- Reports and moderation audit records are kept indefinitely — safety cannot be something an account deletion switches off — but the identifiers pointing at you are cleared when your account is erased.
- Everything else lives as long as your account does.
7. Deletion and export
You can deactivate or delete your account at any time under Me → Account in the app, or by writing to privacy@nihao-pet.com and asking us to do it.
After a deletion:
- Immediately: your nickname becomes a deleted-user placeholder; bio, photo, area, coordinates and last-seen time are cleared; pets, posts and comments are hidden; you leave or cancel activities that have not started; push is disabled.
- Within 30 days: signing in restores the account (the cleared fields have to be filled in again, which the app says plainly).
- After 30 days: the application data is physically deleted, stored images are removed, and the authentication record — including your email address — is deleted.
For a copy of your data, write to privacy@nihao-pet.com. We confirm within one business day and deliver within a reasonable time.
8. Children
Nihao is not intended for children under 13 and we do not knowingly collect their information. If you believe a child under 13 has given us data, write to privacy@nihao-pet.com and we will delete it.
9. Changes to this policy
When we update this policy we change the "last updated" date at the top of the page. If a change affects how we use your data, we tell you inside the app in advance rather than only editing this page.
10. Contact
Privacy and data requests: privacy@nihao-pet.com Anything else: support@nihao-pet.com
We reply within one business day, in English or Chinese.