Skip to content
BARKLENS
How it worksWhy BarkLensCare TeamPlansOur StoryBlog
QuestionsJoin WaitlistSave my spot
01How it works02Why BarkLens03Care Team04Plans05Our Story06Blog07Questions
Join Waitlist
InstagramTikTokPinterestFacebookYouTube
info@barklens.com

Privacy

Your records are not our business model.

This Policy explains what BarkLens collects, how it is used, who processes it, how long it is kept, and the choices available to you.

Effective September 16, 2026info@barklens.com

Company

ThinkTanc LLC d/b/a BarkLens
7804 Fairview Rd C-162
Charlotte, NC 28226
info@barklens.com

United States only · Age 18+

2. BarkLens Privacy Policy

Effective: September 16, 2026

2.1 Who we are and how to reach us

BarkLens is operated by ThinkTanc LLC, a Delaware limited liability company doing business as BarkLens. For purposes of state privacy laws that use the term, ThinkTanc LLC is the business and controller of the personal information described in this Policy, except with respect to information a Care Team member sees in an account owner’s record, where the account owner determines what is shared (see §8.3).

This Policy explains what we collect, why, who we share it with, how long we keep it, and what you can do about it. It applies to the BarkLens mobile application, the barklens.com website, our waitlist and email communications, and any related service we operate. It does not apply to your veterinarian, to any third-party website we link to, or to the app stores through which you buy a subscription. It also does not govern clinics, retailers, publishers, or independent Care Team members, each of whom acts under its own notices. BarkLens concerns canine health, is not a human healthcare provider, and is not intended to receive human health information; do not infer that BarkLens is subject to or compliant with a law that does not apply to it.

Contact us about privacy: info@barklens.com Legal notices: info@barklens.com Mail: ThinkTanc LLC d/b/a BarkLens, 7804 Fairview Rd C-162, Charlotte, NC 28226

We respond to privacy requests within the time required by applicable law and in any event within forty-five (45) days, with one extension where the law allows it and we tell you.

2.2 A note on whose information this is

Most of what BarkLens holds is information about a dog, not about a person. Animal health information is not human health information, and BarkLens is not a HIPAA-covered entity or business associate. But your dog’s paperwork often has you on it. A clinic invoice may carry your name, home address, phone number, and the last four digits of a payment card. A prescription label may carry your name. When you upload those documents, that information comes with them. We treat it as your personal information and protect it accordingly, and we ask you not to upload any other person’s health or personal information (see §1.10.1).

2.3 What we collect

2.3.1 Account information. Your email address, authentication identifiers, and (if you provide them) your name and display name; your password or the credential produced by whichever sign-in method you use; account settings and preferences; and your subscription status as reported to us by the app store. We do not collect or store your payment card number. Purchases are processed by Apple or Google, who tell us only whether an entitlement is active.

2.3.2 Dog profile information. Your dog’s name, breed or breed mix, sex, reproductive status, date of birth or estimated age, weight history, and similar profile fields you enter.

2.3.3 Records, documents, and photographs you submit. Veterinary records, laboratory reports, discharge summaries, invoices, vaccination records, prescription and supplement labels, food packaging and guaranteed-analysis panels, product and treat packaging, photographs of meals, and photographs of stool, together with text and structured values derived from those materials.

2.3.4 Your questions and chat history. The questions you ask, the answers returned to you, the sources cited in those answers, and the surrounding conversation, retained so your history is available to you across sessions and devices.

2.3.5 Observations and confirmations. Values you enter or confirm yourself, including stool scores you accept or adjust, notes, dates, and corrections. These are recorded as your observations, attributed to you.

2.3.6 Care Team information. The email addresses of people you invite, the permissions you set for each, and a log of invitations, acceptances, and revocations. If you are an invited member, we hold your account information and a record of the access granted to you.

2.3.7 Waitlist information. If you joined the waitlist, your email address, the date and source of sign-up, any information you volunteered (for example, your dog’s age or the reason you signed up), your consent record, and your engagement with our emails. See §4.

2.3.8 Device, log, and usage data. IP address, device and operating-system type and version, app version, device identifiers as provided by the platform, crash reports and diagnostics, timestamps, request and error logs, and product-analytics events describing which screens and features were used.

2.3.9 Communications with us. Emails and support messages you send us, and our replies.

2.3.10 Cookies and similar technologies on our website. See §5 and the separate Cookie Policy.

2.3.11 What we do not collect. We do not access your email inbox — there is no email or inbox integration in the Service (see §1.3.5). We do not collect precise geolocation, we do not access your contacts, and we do not access your photo library except for the images you choose to submit. We do not buy personal information from data brokers. We do not use your information for third-party advertising, and we do not run ad-network trackers in the app.

2.3.12 Information we receive from other people and services. We may receive information from an account owner who invites you to a Care Team, from a Care Team member who adds information within the access the owner granted, from an app store, from an authentication provider, and from a service provider that helps us operate and secure the Service. Do not submit information about another person unless you are authorized to do so.

2.4 How we use information

We use information for these purposes and no others:

2.4.1 To run the Service for you. To create and secure your account; to store and organize your dog’s records; to read documents you submit and extract values from them; to build and display your dog’s chart with provenance back to each source; to answer your questions using our source library; to produce exports; to deliver Care Team access you have granted; and to keep your history available across your devices.

2.4.2 Model inference on your own account’s data. To answer a question or produce an interpretation, we send the relevant portion of your account’s content — for example, the extracted text of a report you asked about, along with retrieved library passages — to a third-party artificial-intelligence provider, which returns output to us and to you. This processing is performed to serve you, on your own data. It is not used to build a profile of you, it is not shared with advertisers, and it is our contractual requirement that it is not used to train the provider’s models. See §2.7 and §7.

2.4.3 Transactional communications. To send account, security, billing, trial, renewal, Care Team, and service-change messages. These are not marketing and you cannot unsubscribe from them while you have an account, although you may close your account at any time.

2.4.4 Marketing communications. To send you product news, launch announcements, founding-member offers, and educational content if you opted in. Every marketing email includes one-click unsubscribe. See §4.

2.4.5 Support. To respond to you, investigate a problem you report, and fix errors. Support staff access account content only when necessary to resolve an issue, under the access controls described in §2.11.

2.4.6 Safety, integrity, and abuse prevention. To detect and prevent fraud, credential abuse, scraping, evasion of free-tier limits, security incidents, and violations of §1.10, and to protect users, animals, our systems, and our vendors.

2.4.7 Product improvement. To measure and improve accuracy and reliability — for example, how often a class of document fails to parse, whether retrieved passages matched the question asked, and which features are used. Our default posture is that improvement work is done on de-identified or aggregated data, not on identifiable account content. Where we would need identifiable content — for example, to reproduce a parsing failure you reported — we use it only for that purpose. Any broader use of identifiable content for improvement will be opt-in, described plainly, and revocable at any time.

2.4.8 Legal and compliance. To comply with law, respond to lawful requests, enforce our Terms, and establish, exercise, or defend legal claims.

2.4.9 No decisions about people. We do not use your information for automated decision-making that produces legal or similarly significant effects about you, for credit, insurance, employment, or housing purposes, or for any form of profiling for targeted advertising.

2.5 How we share information

We share personal information only in the following circumstances. We do not sell personal information and we do not share it for cross-context behavioral advertising (see §2.10.2).

2.5.1 Service providers and subprocessors. With vendors that process information on our behalf, under contract, only for the purposes we specify, and subject to confidentiality and security obligations. The categories are: email delivery; web hosting; authentication, storage, and database; artificial-intelligence inference; usage analytics; and app-store billing. Each vendor, what it does, and where it processes are listed in §7 (Vendor and AI Processing Disclosure).

2.5.2 Care Team members you invite. With the people you invite, limited to the parts of the record you selected, until you revoke access. See §8. You control this sharing; we do not initiate it.

2.5.3 Legal and safety disclosures. With courts, regulators, or law enforcement where required by valid legal process or where we reasonably believe disclosure is necessary to comply with law, enforce our Terms, or protect the rights, property, or safety of any person or animal. Where permitted by law, we will attempt to notify you before disclosing your content in response to legal process, unless we are prohibited from doing so or notice would be futile or create a risk of harm.

2.5.4 Business transfers. In connection with a merger, acquisition, financing, reorganization, sale of assets, or insolvency, information may be transferred as a business asset. Any acquirer will remain bound by this Policy with respect to information transferred, or you will be given notice and an opportunity to delete your data and export your records before any materially different policy applies. We will give notice by email and in-app notice at least thirty (30) days before any such change takes effect where practicable.

2.5.5 Professional advisors. With our attorneys, accountants, auditors, and insurers, under duties of confidentiality, where reasonably necessary.

2.5.6 With your direction. Where you ask us to share something — for example, by exporting a record and sending it to your veterinarian yourself. Once you export a file and send it somewhere, that copy is outside the Service and outside our control.

2.5.7 Aggregated and de-identified information. We may create and use aggregated or de-identified information that cannot reasonably be linked to you or your account, including for research, benchmarking, and public statistics about the product. We will not attempt to re-identify it, and we will require anyone we share it with to do the same.

2.6 Legal bases for processing (United States framing)

The Service is offered only in the United States, where most state privacy laws do not use the EU-style “legal basis” framework. For clarity, and because some users ask, we describe our processing grounds as follows:

  • Performance of our contract with you — everything in §2.4.1 through §2.4.3 and §2.4.5. Without this processing we cannot provide the Service you signed up for.
  • Our legitimate interests, balanced against your rights — §2.4.6 (safety and abuse prevention), §2.4.7 as limited to de-identified and aggregate improvement work, and internal record-keeping. We assess these interests against the sensitivity of the data and use the least-identifiable data that will work.
  • Your consent — §2.4.4 (marketing email), any opt-in improvement program, any use of cookies or analytics that requires consent under applicable law (see §5), and any processing for a materially new purpose we have not described. You may withdraw consent at any time, and withdrawal does not affect processing already carried out.
  • Legal obligation and legal claims — §2.4.8.

If we ever process personal information for a purpose not described in this Policy, we will update this Policy and, where the purpose is materially different, obtain your consent first.

Where a state law requires consent to process a category of information that the law treats as sensitive, we will request the required consent before that processing and provide the withdrawal mechanism the law requires. Consent to receive marketing email may be withdrawn at any time, and withdrawal does not affect the transactional messages described in §2.4.3.

2.7 Artificial-intelligence model providers — plain statement about training

This is the question users ask most, so we answer it directly.

2.7.1 What is sent, and when. When you ask a question or request an interpretation, we transmit to a third-party model provider the material needed to produce that specific output — typically the extracted text of the relevant document or chart rows, the passages retrieved from our source library, and your question. Transmission happens only in response to an action you take. We do not send your library of records to a model provider in bulk, and we do not send content for background processing you did not request. We seek to minimize what is sent, to avoid direct identifiers where reasonably possible, and to use enterprise or API offerings rather than consumer chat accounts.

2.7.2 Training. It is our requirement and our contractual position that content from your account is not used to train, fine-tune, or improve any third-party model. We use enterprise or API service tiers whose terms provide that submitted content is not used for model training, and we configure zero-retention or limited-retention options where available.

2.7.3 Provider-side retention for safety. Some providers retain submitted content for a short period for abuse monitoring, even where training is contractually excluded. Where that is the case, retention is limited by contract and content is deleted at the end of that period.

2.7.4 Which providers. The model providers we use are listed in §7.

2.7.5 Human review. Our own staff do not read your questions or records except as described in §2.4.5 and §2.4.6.

2.7.6 What these safeguards do not do. Generated answers are not individually reviewed by a veterinarian, model processing can produce mistakes even where the underlying source passages are accurate, and no privacy safeguard converts a generated answer into veterinary care.

2.8 Retention and deletion

We keep information for as long as needed to provide the Service to you and for the periods set out in §6 (Data Retention and Deletion Schedule), which is part of this Policy. In summary: records stay for the life of your account; when you close your account there is a 30-day grace period during which you can reopen and export; you can delete anything, or everything, at any time; backups and system logs age out on a 30-to-90-day rolling basis; unsubscribe records are kept indefinitely so we can keep honoring your unsubscribe.

Deletion is real: when you delete a record, we delete the file, the extracted text, and the derived structured values, and remove the corresponding chart rows. Copies persisting in encrypted backups are overwritten as those backups age out. Where we are legally required to retain something (for example, a transaction record or a document subject to a legal hold), we retain only that item, only for as long as required, and we stop using it for any other purpose. Deletion is not always instantaneous: information may persist briefly in rolling backups and logs, in suppression records, in transaction or legal records, under a litigation hold, in de-identified form, or in another person’s independent copy. Data restored from a backup remains subject to any deletion that was pending when the backup was taken.

2.9 Your rights and how to exercise them

Regardless of where you live in the United States, we offer every user the following. We do not charge for these requests and we do not discriminate against you for making one.

  • Access — a copy of the personal information we hold about you, and information about how we use and share it.
  • Correction — correction of inaccurate personal information. You can edit most information directly in the app; corrections to your dog’s chart append a correction rather than erasing history, so that the record of what a document said remains traceable.
  • Deletion — deletion of your personal information, a specific record, a specific photograph, your chat history, or your entire account. Deleting your account deletes your dog’s records, so export first if you want to keep them.
  • Export and portability — a machine-readable and human-readable copy of your records and chart, available to you at any time, including after you cancel a paid plan and after you close your account, for the window described in §3.9. Available formats are PDF, RTF, and JSON.
  • Opt out of marketing — unsubscribe from any marketing email at any time.
  • Withdraw consent — for any processing based on consent.
  • Account closure — close your account, ending all processing except what §6 requires us to retain.
  • Appeal — if we deny a request, you may appeal by replying to our decision or writing to info@barklens.com with “Appeal” in the subject line. We will respond within forty-five (45) days and, if we deny the appeal, tell you how to contact your state attorney general.

How to make a request: email info@barklens.com from the address on your account, or use the in-app privacy controls. We verify requests by confirming control of the account email and, where a request is sensitive or high-risk, by additional means proportionate to the request. We will not ask you for more information than we need to verify you. An authorized agent may submit a request on your behalf with written authorization that we can verify; we may also ask you to confirm the agent’s authority directly. We will not discriminate against you for exercising a privacy right, although a request may affect features that depend on the data you asked us to delete.

2.10 State privacy rights

2.10.1 Where these rights come from. Several states give residents specific privacy rights. We grant the rights in §2.9 to all users regardless of state, so you do not need to determine whether a particular law covers you. This section adds the state-specific disclosures those laws require.

2.10.2 No sale, no sharing, no targeted advertising. We do not sell your personal information for money or other valuable consideration. We do not share it for cross-context behavioral advertising or targeted advertising. We do not use it for profiling in furtherance of decisions that produce legal or similarly significant effects. Because we do not do these things, there is nothing to opt out of, and we honor opt-out preference signals such as Global Privacy Control on our website as a matter of course. We have not sold or shared personal information in the preceding twelve months. We do not knowingly sell or share the personal information of anyone under 18 — and no one under 18 may use the Service.

2.10.3 California (CCPA/CPRA). California residents have the rights to know, access, delete, correct, and obtain a portable copy of personal information; to opt out of sale and sharing (we do neither); to limit the use of sensitive personal information (we use it only to provide the Service you requested and for the purposes state law permits without a limitation right); and to be free from discrimination for exercising these rights. Categories of personal information collected in the past twelve months: identifiers (email, device identifiers, IP address); commercial information (subscription status and history); internet or network activity (app and site usage, log data); geolocation limited to coarse, IP-derived location; audio, electronic, or visual information (photographs you submit, which are ordinarily images of documents and stool rather than of people); and inferences drawn from the foregoing solely to operate the Service. Sources: you, your device, your app store, and our vendors. Purposes: those in §2.4. Disclosures for a business purpose: to the categories of service providers listed in §7. We retain each category as described in §6. California residents may designate an authorized agent and may contact us at info@barklens.com.

2.10.4 Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana. Residents of these states have rights to confirm processing and access, correct, delete, and obtain a portable copy of personal data, and to opt out of targeted advertising, sale, and certain profiling — none of which we conduct. Colorado, Connecticut, Virginia, Oregon, and Montana residents also have a right to appeal a denied request (see §2.9). Sensitive data: where a state treats any category of the data we hold as sensitive, we process it only with your consent or as necessary to provide the Service you requested, and we do not use it for advertising or profiling. We conduct data protection assessments where required. Texas and Oregon residents: this Policy is the notice those statutes require of the categories of data processed and shared.

2.10.5 Your state generally. If you live in any other state, including a state that enacts a privacy law after the effective date of this Policy, we extend the same rights to you — access, correction, deletion, export, portability, opt-out of marketing, and appeal — through info@barklens.com. We will update this section as new laws take effect.

2.10.6 Notice of financial incentive. Any founding-member pricing or referral reward described in §4 is offered as a commercial promotion, not in exchange for permission to sell or share your personal information. We do not offer a financial incentive in exchange for personal information unless a program notice explains its material terms, the good-faith value calculation, and the right to withdraw. A subscription discount, a founding-member price, or a referral reward based on purchase or participation is not intended as payment for personal information.

2.11 Security

2.11.1 Measures we take. We use administrative, technical, and physical safeguards designed to protect your information, including: encryption in transit using TLS for all connections between your device, our services, and our vendors; encryption at rest for stored files, extracted text, and database contents as provided by our storage and database platform; authentication through a managed identity provider, with support for the sign-in methods offered in the app; access controls limiting staff access to production data to the smallest number of people whose role requires it, on a least-privilege basis, with access logged; network and platform controls provided by our hosting and cloud vendors; vendor diligence before engaging a processor that will handle account content; logging and monitoring of access to production systems; backups with restoration testing; and secure development practices including code review and dependency monitoring.

2.11.2 What security cannot do. No service is perfectly secure. We cannot guarantee that unauthorized parties will never defeat our safeguards or those of our vendors. You play a part too: use a strong, unique credential, keep your device locked and updated, do not share your account, and invite to your Care Team only people you trust (see §8).

2.11.3 Incident response. We maintain an incident-response process covering detection, triage, containment, forensic assessment, notification, and remediation. If a security incident affects your personal information, we will notify you and any regulator entitled to notice without unreasonable delay, and we target notification within seventy-two (72) hours of confirming a reportable incident — recognizing that some state statutes require faster notice in specific circumstances and some allow longer, and that law-enforcement requests may lawfully delay notice. Our notice will describe what happened, what information was involved, what we are doing, and what you can do.

2.11.4 Vulnerability reports. If you believe you have found a security vulnerability, report it to info@barklens.com rather than testing it against other users’ accounts. Good-faith reports submitted responsibly will not be pursued by us.

2.12 International visitors

2.12.1 United States only. The Service is offered only in the United States, and information is processed in the United States and, for web hosting and content delivery, at global edge locations operated by our hosting vendor (see §7). We do not offer the Service in the European Economic Area, the United Kingdom, Switzerland, Canada, or anywhere else, and we do not target users in those places.

2.12.2 If you visit our website from outside the United States. You may still be able to view barklens.com. If you do, we collect the minimum necessary to serve the page and keep it secure — request logs including IP address, and, only with your consent where consent is required, analytics cookies (see §5). We do not use that information to market to you, and we will not create an account for you. If you sign up for the waitlist from outside the United States, you consent to the transfer of your email address to and its processing in the United States, where privacy laws differ from those in your country. You may unsubscribe and request deletion at any time at info@barklens.com. The mere accessibility of barklens.com from another country is not an offer of the Service in that country. If BarkLens later targets a jurisdiction that restricts transfers, it will assess local obligations and implement the required transfer mechanism, such as the EU Standard Contractual Clauses or a UK addendum, before doing so.

2.12.3 Transfer mechanism. Where personal information of an individual in the EEA, UK, or Switzerland is transferred to us or our vendors in the United States incidentally, we and our vendors rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, or another lawful mechanism, as applicable.

2.13 Children

The Service is for adults. You must be 18 or older to use it (see §1.2.1). The Service is not directed to children, we do not knowingly collect personal information from anyone under 18, and we do not knowingly sell or share the personal information of minors. If we learn that we have collected personal information from someone under 18, we will delete it and close any associated account. If you believe a minor has provided information to us, contact info@barklens.com and we will act promptly.

2.14 Changes to this Policy

We may update this Policy. If a change is material — for example, a new category of information, a new purpose, a new vendor category, or a change in our position on model training — we will give at least thirty (30) days’ advance notice by email and in-app notice before it takes effect, update the “Effective” date, and record the change in the revision history at the end of this document. Where a change requires consent under applicable law, we will obtain consent before applying the change to information already collected. We keep prior versions available on request at info@barklens.com.

2.15 How to contact us about privacy

Email: info@barklens.com. Mail: ThinkTanc LLC d/b/a BarkLens, 7804 Fairview Rd C-162, Charlotte, NC 28226. If you are unsatisfied with our response, you may contact your state attorney general.



Cookie and Analytics Policy

This section explains the technologies that may be used on barklens.com, what may operate before consent, and the boundaries that apply to analytics data.

Analytics disclosure

If analytics is enabled, the following terms apply:

If analytics is enabled, we may use Google Analytics 4 to understand how visitors use barklens.com — which pages are viewed, how visitors arrive, and where they encounter problems. Google Analytics is configured so that IP addresses are not stored and are anonymized or truncated on collection, Google Signals and all advertising features are disabled, no data is shared with Google advertising products or used for remarketing or ad personalization, and no data is used for Google’s own product improvement beyond what our agreement permits. Data retention in Google Analytics is set to the shortest practical period. We do not link analytics data to your BarkLens account, and we do not attempt to identify you from it. Our use is governed by a data processing agreement with Google, including Google’s data-processing terms and the applicable standard contractual clauses. If you are in a region where consent is required, no analytics tag loads until you consent, and you may withdraw consent at any time through the cookie preferences link in our footer.

5.4 What may run before consent

Permitted before any consent, because it is strictly necessary:

  • session and load-balancing cookies needed to serve the page;
  • authentication and session-security cookies for signed-in users;
  • CSRF and other security tokens;
  • the cookie that records your cookie choice (necessary by definition — otherwise we would have to ask again on every page);
  • fraud-prevention and rate-limiting signals;
  • and short-lived server request logs, including IP address, kept for security and debugging as described in §6.

Permitted before consent for United States visitors only, and only with anonymization: first-party analytics with IP anonymization or truncation, no cross-site identifiers, no advertising integration, and no sharing with any ad network.

Never before consent, anywhere:

  • any tag that transmits data to an advertising network or ad exchange;
  • any conversion pixel, remarketing tag, or audience-building tag (including Meta, Google Ads, TikTok, LinkedIn, and similar);
  • any cross-site or cross-context identifier, fingerprinting technique, or device-graph service;
  • any session-replay or heat-mapping tool that records interactions;
  • and any A/B-testing or personalization tool that sets a persistent identifier.

Standing rule: if a proposed tag shares data with a party that has its own commercial use for it, it does not run before consent and will not run unless this Policy and the available privacy choices are updated first. A single ad pixel added by a growth experiment would falsify that statement across the entire Privacy Policy.

5.5 Analytics data boundaries

Analytics events must describe interface behavior and nothing else. No analytics event may carry User Content — not a dog’s name, an owner’s name or email address, record text, a health value, a laboratory result, a question asked, a generated answer, a source excerpt, an invitation’s contents, an upload file name, or free text of any kind. Access to analytics environments is limited and logged, development and production data are separated, retention is set to the shortest period consistent with product need, and no analytics export may be provided to an advertising network or a data broker unless the disclosures in §2.5 and §2.10.2 and the choices in §5.2 are revised first. Pre-consent first-party analytics may run only where lawful, only in a limited non-cross-site form, only without a persistent advertising identifier, and only where accurately described; when in doubt, analytics stays off. Google Analytics and every other third-party analytics tool is treated as nonessential in a prior-consent jurisdiction absent a documented exception.



6. Data Retention and Deletion Schedule

Effective: September 16, 2026 This schedule is part of the Privacy Policy (§2.8) and is incorporated into the Terms of Use.

6.1 Schedule

Data category What it includes Retention period Deletion trigger and mechanics
Active-account records Uploaded veterinary records, lab reports, labels, packaging, extracted text, structured values, chart rows, coverage statements Life of the account You may delete any item or all items at any time in the app. Deletion removes the file, its extracted text, and its derived values, and removes the corresponding chart rows.
Uploaded photographs and original images The original image files you captured or uploaded Same as records, except that where you choose the option to discard originals after processing, the original image is deleted after OCR and structured extraction complete and the derived data is stored User-selected setting, applied per upload or as a default.
Questions and answer history Your questions, returned answers, cited sources, conversation context Life of the account, on free and paid plans alike Deletable by you individually or in bulk. We do not delete chat history when a paid plan lapses.
Chart corrections and superseded entries Prior values that were corrected, with their provenance Life of the account Retained by design: a correction appends rather than overwrites, so the record of what a document said stays traceable. Deleting the underlying record deletes the chain.
Closed accounts — grace period Everything above 30 days from closure, during which the account can be reopened and records exported Automatic. At closure we email a confirmation that states the grace-period end date and links to export.
Closed accounts — export window Export-only access to records 90 days from closure Automatic.
Closed accounts — final purge Everything above Automatic purge after three (3) months from closure, and immediately on a user-initiated deletion request On purge, account content is deleted from production systems; backup copies age out under the backup row below.
Immediate deletion on request Any item, or the entire account Processed without undue delay and within 45 days, ordinarily within days User request in-app or to info@barklens.com. Overrides the grace and export windows if you ask us to delete now.
Account and authentication records Email address, authentication identifiers, consent and acceptance timestamps, Terms-version acceptance Life of the account + twenty-four (24) months after closure, for dispute defense and to prove which Terms version you accepted Automatic. Minimized to the fields needed.
Subscription and transaction records Store-reported entitlement history, plan, dates, amounts as reported to us 7 years Automatic. Retained even after account deletion, in minimized form, because we are required to keep transaction records.
Care Team invitation and access logs Who was invited, what permissions were granted, acceptance, revocation, and timestamps Life of the account + twenty-four (24) months Retained while the account exists because it is the evidence of who had access to a record and when.
Unaccepted Care Team invitations Invitation token, the recipient’s contact information, reminder and status events Until accepted, declined, suppressed, or expired; unaccepted invitations expire after thirty (30) days Delete or minimize the invitation token and the recipient’s contact information after expiration, retaining only the limited suppression and abuse-prevention evidence needed to honor a “no further invitations” request.
Waitlist information Email address, sign-up date and source, consent text and IP, engagement Until conversion to an account, or 24 months of inactivity, whichever comes first Automatic purge at 24 months without engagement; immediate on unsubscribe-plus-deletion request, except the suppression record below.
Unsubscribe and suppression records Email address in hashed or plain form, unsubscribe date, source Indefinite Kept indefinitely for the sole purpose of continuing to honor your unsubscribe. Removed only if you specifically ask us to remove your address from the suppression list.
Email delivery logs Send, delivery, bounce, complaint, and open/click events at the vendor thirty (30) days Vendor-side aging plus our configuration.
Support communications Your emails to us and our replies 24 months from the last message in the thread Automatic.
Security and system logs Request logs, IP addresses, authentication events, error and crash logs, audit logs of staff access 30–90 days rolling, except that logs pertaining to an open security investigation, an abuse case, or a legal hold are preserved until it closes Automatic rolling expiry.
Backups and disaster-recovery copies Encrypted snapshots of production data 30–90 days rolling Automatic expiry. Deleted content may persist in a backup until the backup that contains it ages out; backups are not used to restore individual deleted items.
Model-provider transient copies Content transmitted for inference Per provider contract; our requirement is zero retention where available, otherwise a short abuse-monitoring window
Analytics data Aggregated and anonymized usage events two (2) months Aggregate or delete at the end of the configured period; never allow User Content into an analytics event. Security analytics may follow the log schedule, and consent and opt-out records may be retained longer.
De-identified and aggregated data Statistics that cannot reasonably be linked to you Indefinite Not deleted, because it is no longer personal information. We do not attempt re-identification.
Legal-hold material Anything subject to litigation hold, subpoena, or regulatory demand Until the hold is released Manual, documented, and limited to the specific items in scope. Retained for that purpose only.

6.2 Standing rules that govern the table

  1. Your deletion request beats every discretionary period above. If you ask us to delete, we delete, except where retention is legally required (transaction records, legal holds) or where the item is an unsubscribe suppression record whose only purpose is to protect you.
  2. Export before you delete. Deletion is irreversible after the windows above close. We cannot recover purged records — not from backups, not on appeal, not for a fee.
  3. Deleting a record deletes what was derived from it, including its extracted text and structured values and the chart rows built from them.
  4. Backups are not a shadow archive. They exist for disaster recovery, they are encrypted, they are not searchable for ordinary purposes, and they age out. We do not mine backups.
  5. Care Team copies are outside this schedule. If a Care Team member exported or screenshotted something before you revoked access, that copy is theirs and is not reachable by our deletion process. See §8.5.
  6. We do not retain data to make leaving harder. Records stay free, export stays free, and no retention period in this table exists to create a switching cost.
  7. The shorter commitment controls; the longer one needs a reason. Where a legal, contractual, or user-facing commitment is shorter than a period in the table above, the shorter period governs. Retention longer than the table allows requires a documented basis — a legal obligation, an open dispute, a fraud or security investigation, a transaction record, a user instruction, or a litigation hold — recorded at the time the decision is made.
  8. Deletion is tested end to end, not assumed. We maintain a system-level data and deletion map, and we test deletion across authentication, primary storage, database indexes, search indexes, model-provider logs, analytics, email systems, support tooling, and generated exports. A record that survives in a secondary index has not been deleted.
  9. Vendor contracts carry this schedule. Every processor agreement must address deletion or return of data at exit, assistance with user deletion and access requests, and the vendor’s own backup and log cycles, so that a commitment in this table is not defeated by a vendor’s default retention.


7. Vendor and AI Processing Disclosure

Effective: September 16, 2026 This disclosure is part of the Privacy Policy (§2.5.1) and is referenced by the Terms of Use (§1.12.5).

7.1 Vendors by category

Vendor Category What it does for us Data it processes Processing location
Mailgun (Sinch) Email delivery Sends waitlist confirmation and welcome email, marketing email, and transactional/account email; handles bounces, complaints, and unsubscribe processing Email address, name if provided, message content, delivery and engagement events, IP at sign-up where included United States
Vercel Web hosting and content delivery Hosts and serves barklens.com and related web endpoints Request data including IP address, user agent, and requested URL; no account records are stored here United States primary, with global edge locations for content delivery
Firebase / Google Cloud Platform (Google LLC) Authentication, file storage, database, and infrastructure Authenticates sign-in; stores uploaded documents and images; stores the chart, extracted values, questions, and answers; runs backend functions Account identifiers, credentials handled by the identity provider, all uploaded records and images, extracted text and structured values, chart data, chat history, device and log data United States
Model providers — enterprise or API model providers used by BarkLens Artificial-intelligence inference Generates educational answers and interpretive output from your account’s content plus retrieved library passages, in response to your request The specific content sent for that request: extracted document text or chart rows, retrieved source passages, and your question United States
Google Analytics 4 (Google LLC) Usage analytics Measures website usage in anonymized form, as described in §5.3 Anonymized/truncated IP, page and event data, device and browser type, referrer; not linked to your account United States

| Apple App Store (Apple Inc.) | Billing and distribution | Distributes the iOS app; sells, renews, cancels, and refunds subscriptions; processes payment | Purchase and entitlement data, payment information handled entirely by Apple, store account identifiers | United States | | Google Play (Google LLC) | Billing and distribution | Distributes the Android app; sells, renews, cancels, and refunds subscriptions; processes payment | Purchase and entitlement data, payment information handled entirely by Google, store account identifiers | United States |

7.2 How we govern vendors

Each vendor that processes personal information on our behalf is engaged under a written agreement that limits it to processing on our instructions and for our purposes, requires confidentiality and appropriate security, restricts onward subprocessing, and requires deletion or return of data at the end of the engagement. We assess a vendor’s security posture before granting it access to account content, and we prefer vendors that publish independent audit reports. Apple and Google, acting as the sellers of subscriptions, act as independent businesses with respect to payment data, not as our processors. Before a vendor receives production data we document its purpose, the data it will receive, who at the vendor may access it, where it processes, how long it retains, its security posture, its subprocessors, its deletion behavior, its incident-notice timing, its model-training status, and the plan for leaving it. We maintain a current subprocessor list and a change process for it, and a material vendor change is reviewed under §1.20.1 and §2.14. Production data is never placed in a consumer model account, an unapproved public tool, a personal cloud drive, or any tool that has not been approved through this process.

7.3 Processing locations and international transfers

Primary processing is in the United States. A vendor’s stated country is not a promise that every support, telemetry, or edge operation happens only there, which is why each row in §7.1 requires the vendor to identify its actual locations. The exception is web content delivery: our hosting vendor serves the marketing site from global edge locations, which means a request from outside the United States may be served from an edge node in that region, and request-level data (IP address, URL) may be processed there transiently.

We do not intentionally transfer personal information outside the United States. If personal information of a person in the EEA, the UK, or Switzerland reaches us or our vendors incidentally — for example, because someone abroad visited barklens.com or joined the waitlist — we and our vendors rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, or another lawful transfer mechanism, as applicable. See §2.12.

7.4 Changes to this list

We will update this section when we add or remove a vendor that processes account content, and we will note the change in the revision history. Where an addition materially changes how account content is processed — for example, adding a new model provider or a new analytics tool that receives record content — we will give notice as described in §2.14.


BARKLENS

BarkLens doesn’t diagnose. Your vet does.
Not veterinary advice — see Terms.

Product

How it worksWhy BarkLensPlans

Company

Our StoryCare TeamBlogContact

Legal

PrivacyTermsYour records

Follow

InstagramTikTokPinterestFacebookYouTube
© 2026 ThinkTanc LLC