Privacy Policy
Last updated: 10 August 2026 · Version 1.5
English translation for convenience. This is a courtesy translation of the Italian document, which is the legally binding version. In case of any discrepancy, the Italian version prevails.
In short: Squamy is designed to work offline: your enclosure and animal data stays on your device. We process personal data only in limited cases — when you visit this website (advertising cookies, with your consent) and if you choose to enable cloud sync in the app (optional).
1. Data controller
The controller of personal data is Simone Dall'Asta, based at Via Schedoni 3, 43010 Fontevivo (PR), Italy.
For any privacy-related matter you can write to: squamy.app@gmail.com.
2. Data processed by this website
This site is a static showcase hosted on Cloudflare Pages. When you visit it, the following may be processed:
- Technical browsing data (IP address, browser/device type, pages viewed): processed by the hosting/CDN infrastructure (Cloudflare) to deliver the site and keep it secure.
- Cookies and advertising identifiers via Google AdSense — only with your consent (see §5 and the Cookie Policy).
- Cookie preference: stored locally in your browser (localStorage) to remember your choice. It is not a cookie and never leaves your device.
3. Data processed by the Squamy app
Squamy is offline-first. By default:
- The data you enter (enclosures, animals, feedings, sheds, weigh-ins, readings, activities, notes, etc.) is stored locally only on your device. It is not transmitted to us.
- Voice dictation (optional): if you use the microphone to dictate a reading, the audio is processed by your device's speech-recognition service (e.g. the Android system one, which may involve processing by its provider under its own policy); the app receives only the recognised text and neither records nor stores the audio, nor sends it to our servers. The microphone permission is requested only on first use and you can revoke it whenever you like.
- No account is required to use the core features.
- In-app advertising (Free plan only): the app shows a discreet banner via Google AdMob. Before any ad you are asked for consent through Google's UMP form (Consent Mode); without consent, personalised ads are not shown. AdMob may process device advertising identifiers under its own policy. The Premium plan contains no advertising.
- Amazon affiliate links: the product catalog, the inventory and their search forms contain links to Amazon with our affiliate code (Amazon Associates programme). The app does not transmit personal data to Amazon: the link opens the Amazon site/app — or, on mobile, an in-app Amazon search screen (WebView) — and from that point Amazon processes the data (including any cookies) under its own policy. On eligible purchases we earn a commission, at no extra cost to you.
If you choose to enable the cloud features (optional; the account and manual sync are free, automatic background sync is part of the Premium plan):
- Account: you create an account with email and password (or Google sign-in; on iPhone and iPad also Sign in with Apple, which lets you hide your real email address). Managed through Supabase.
- Sync: your enclosure and animal data is copied to the server so it can be shared across your devices. It stays tied to your account and is not sold or transferred to third parties.
- Signing out: when you sign out of an account (“Sign out”), that account's data is removed from the device (it stays on the server and comes back on your next sign-in with the same account). This prevents two different accounts' data from getting mixed on the same device.
- AI fallback (Premium, optional, off by default, requires your explicit consent): only if you enable it, the individual phrases that the on-device local parser cannot interpret are sent — through one of our servers (a Supabase Edge Function) — to a language-model provider (OpenRouter, with Google AI Studio as a fallback) to be converted into structured data. Only the phrase and your enclosure and parameter names are sent, never your measurement history. We do not store the text of the phrases: we only record an anonymous technical event (outcome, model, latency) to count usage. On OpenRouter's free models the submitted text may be used by the provider for training: that is why the feature is opt-in. You can turn it off at any time from your account. With the feature off, no phrase leaves the device.
- AI enclosure doctor (Premium, optional, off by default, with a dedicated consent because it sends more data than the AI fallback): only if you enable it, your problem description and a summary of the enclosure's data (type, dimensions, latest values of the tracked parameters with any out-of-range and trend, the animals housed there, recent feedings and sheds, recent activities) are sent — through one of our servers (a Supabase Edge Function) — to the same language-model provider (OpenRouter, with Google AI Studio as a fallback) to obtain hypotheses and suggestions. Only that concise summary is sent, never your full measurement history. We do not store the problem text or the data sent: we only record an anonymous technical event (outcome, model, latency) to count usage. You can turn it off at any time from your account. With the feature off, no enclosure data leaves the device for this purpose.
- AI assistant (Premium feature, optional, off by default, covered by the same consent as the enclosure doctor because it sends a subset of that data): only if you enable it, your question and your enclosures' profile (name, type, dimensions, age) are sent — through our server (Supabase Edge Function) — to the same language-model provider (OpenRouter, with Google AI Studio as a fallback) to get a general answer. Your readings and activity log are not sent. We do not keep the text of your question: we only record an anonymous technical event (outcome, model, latency, which of the two AI features) to count usage, which is shared between assistant and doctor. You can turn it off at any time from your account.
- Premium subscription (only if you subscribe): the purchase and the payment happen on Google Play, which acts as an independent controller under its own policy — we never receive or store your card details. To know whether your account is Premium we rely on RevenueCat, which receives the purchase receipt from Google and reports its status to us against a technical identifier of your account (the Supabase uid, not your email). We therefore process subscription data only (plan, status, renewal or expiry date, any billing issue), which we store on our database (Supabase) to unlock Premium features across your devices. If you do not subscribe, no data is sent to RevenueCat.
- Statistics on linked Amazon items (only if you are logged in): when you link an Amazon item to a product/stock via "Paste link", we record the event on our database (Supabase) — which link, to which product/stock — associated with your account, for internal statistics (e.g. understanding which items are searched most often). We do not use it for advertising profiling, do not share it with third parties, and it is removed if you delete your account.
Artificial-intelligence transparency (Reg. EU 2024/1689 "AI Act"). The "AI fallback", the "Enclosure doctor" and the "AI assistant" are artificial-intelligence features: when you use them you are interacting with an AI system, not a person, and their content is generated automatically (every answer from the doctor and the assistant is labelled "AI-generated", and in the app an "AI" mark flags every place where artificial intelligence is involved). They are support tools and do not replace the advice of a vet or a professional: they can contain errors, so always verify before acting, especially on drug dosages. The features are optional, off by default and enabled only with your explicit consent, which you can withdraw at any time from your account.
4. Purposes and legal bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Providing the site and app and the features you request | Performance of a contract / pre-contractual measures |
| Security, abuse prevention, technical logs | Legitimate interest |
| Cookies and advertising on the site (AdSense) | Consent |
| In-app advertising on the Free plan (AdMob) | Consent |
| Cloud sync and account (if enabled) | Performance of the contract (Premium service) |
| Managing the Premium subscription (if taken out) | Performance of the contract |
| AI fallback (optional, if enabled) | Consent |
| AI enclosure doctor (optional, if enabled) | Consent |
| AI assistant (optional, if enabled) | Consent |
5. Advertising — Google AdSense
To support the project, this site may show ads via Google AdSense. AdSense and its partners may use cookies and identifiers to show ads and, with your consent, personalise them based on your browsing.
No advertising cookie is installed without your consent. The AdSense script is loaded only after you accept the "Advertising" category in the cookie banner (we implement Google Consent Mode v2, with consent denied by default).
You can manage your Google ad preferences from the Google My Ad Center page and withdraw consent at any time from Cookie preferences.
6. Providers and recipients of the data
We rely on providers acting as data processors:
- Cloudflare, Inc. — site hosting and CDN/security.
- Google Ireland/LLC — advertising on the site (AdSense) and in the app (AdMob, Free plan only) and fonts on this website (Google Fonts; the app bundles them instead and downloads nothing); Google AI Studio is the fallback provider of the language models behind the AI features.
- Supabase — authentication and database for sync (only if you enable the cloud).
- OpenRouter, Inc. — provider of the language models behind the AI features, and only if you switch them on with your consent: it receives the single phrase or question and, for the Enclosure Doctor, the short summary of your enclosure's data.
- RevenueCat, Inc. — in-app subscription management: it receives purchase receipts from the store and reports the subscription status to us (only if you subscribe).
With each of these providers a data processing agreement under Article 28 GDPR is in place, binding them to process the data only on our instructions, with appropriate security measures and never for their own purposes. We keep a dated copy of those agreements with the product documentation.
We do not sell your personal data.
7. Transfers outside the EU
Some providers — Google, Cloudflare, Supabase, RevenueCat and OpenRouter — may also process data outside the European Economic Area, in particular in the United States. In that case the transfer takes place on the basis of appropriate safeguards under the GDPR: Standard Contractual Clauses and/or adherence to the EU-US Data Privacy Framework. You can ask us for a copy of the applicable safeguards by writing to the contact in section 1.
8. Retention
- Local app data: kept until you delete it (by uninstalling the app or removing it).
- Account/cloud data: kept while the account is active; deleted upon a deletion request (from the app, "Delete account"). All that remains of the deletion is a pseudonymous technical trace (an encrypted identifier not traceable to you and the count of removed records), for security and verification purposes: it contains no personal data.
- Subscription data (plan, status, renewal or expiry date, where the purchase came from): kept while the account exists, because they are what keeps Premium active across your devices; deleted along with the account. No payment data: your card is only ever seen by the store, it never reaches us — so there is nothing to keep.
- Cookies: according to the durations indicated in the Cookie Policy.
9. Your rights
You have the right of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw consent at any time. The details and how to exercise them are on the dedicated GDPR page. You may also lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
10. Minors
The service is not intended for children under 16. We do not knowingly collect data from minors without the consent of those exercising parental responsibility.
11. Changes to this policy
We may update this policy; the date at the top indicates the latest revision. Material changes will be flagged on the site.
See also: Cookie Policy · GDPR rights · Manage cookie preferences