PetHive is a social app for pet families — share moments, join communities and events, message and call other pet people, and give your pets profiles of their own. PetHive is operated by Zero Gravity Cybernetics Private Limited ("we", "us", "our"), Pentagon 3, Magarpatta City, Hadapsar, Pune, India – 411013.
This Policy explains what personal data we collect, why we collect it, and the rights you have over it. It applies to the PetHive mobile application and related services, and is written to comply with the EU General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act).
The short version:
- Your private chats are end-to-end encrypted — we cannot read them, ever.
- We do not sell your personal data.
- Your feed is not sold to advertisers; sponsored content, where shown, is clearly marked.
- You can delete your account and data at any time, directly in the app (how it works).
1. Who is responsible for your data
Zero Gravity Cybernetics Private Limited is the data controller for personal data processed through PetHive.
Email:
info@zgcns.com
Address: Pentagon 3, Magarpatta City, Hadapsar, Pune, India – 411013
Contact for users in the EU/EEA (Art. 27 GDPR representative):
Ramakant Haralkar —
ramakant.haralkar@zgcns.com
This is also our single point of contact for users and authorities under the EU Digital Services Act.
Grievance Officer (India — IT Rules, 2021):
Name:
Nikita Chouhan, Grievance Officer
Email:
nikita.chouhan@zgcns.com
Address: Pentagon 3, Magarpatta City, Hadapsar, Pune, India – 411013
Grievances are acknowledged within 24 hours and resolved within 15 days of receipt.
2. Data we collect
2.1 Data you give us
- Account data: username, email address, password (stored as a secure hash — we never see or store it in plain text), first and last name, gender, and date of birth (used to enforce our minimum age).
- Phone number (optional): if you sign in with a one-time SMS code, we process your phone number to send and verify the code.
- Profile data: display name, bio, profile photo, and cover photo.
- Pet profiles: your pets' names, species, breed, date of birth, gender, weight, and photos.
- Content you create: posts, photos and videos, stories, comments, reactions, shares, community posts, and event RSVPs.
- Location tags (optional): a post is only geotagged when you choose to add a location to it.
- Support requests: messages you send our support team and the details you include in them.
Data about you from other users: other users may include you in their content — for example by mentioning your username, commenting on your posts, or inviting you to a group or event. That data is processed under the same rules as all other content, and you can report anything inappropriate.
What you must provide: the account data in the first bullet is required to create and use a PetHive account; everything marked optional is your choice, and the app works without it.
2.2 Messages and calls — end-to-end encrypted
Private chats in PetHive are protected with the Signal protocol, the industry standard for end-to-end encryption. Message content is encrypted on your device and can only be decrypted by the intended recipients. We cannot read your messages, and neither can anyone with access to our servers.
- Our servers store only encrypted message data and delivery metadata (who sent a message to whom, and when), which is required to deliver messages to your devices.
- Optional chat backups are encrypted with a recovery code that only you hold. We cannot decrypt your backup.
- Disappearing messages are deleted according to the timer you choose.
- Audio and video calls are not recorded by us. We keep call logs (participants, time, duration, and whether a call was missed or declined) so your call history works.
2.3 Data collected automatically
- Device and app data: device model, operating system and version, app version, language, and push-notification token.
- Security data: IP address and sign-in events (used for account security, fraud prevention, and abuse protection), and device-integrity signals used to protect the service from automated abuse.
- Usage data: interactions such as likes, follows, views, and reports, used to run the product (for example ranking your feed) and to keep the community safe.
- Diagnostics: if the app crashes or errors, we receive a technical report (stack trace, screen involved, app version, device model, OS version) tied to a pseudonymous identifier. These reports are scrubbed on your device before sending: they never contain message content, your email, name, password, recovery code, or authentication tokens.
2.4 What we do not collect
- We do not read or analyze the content of your end-to-end encrypted chats — we technically cannot.
- We do not access your contact list, SMS inbox, or photo library beyond the specific items you choose to share. On Android, one-time sign-in codes can be filled automatically through Google's SMS Retriever service, which hands the app only its own verification message — the app has no SMS permissions and cannot see any other messages.
- Biometric unlock (Face ID / fingerprint) is handled entirely by your device's operating system. Biometric data never reaches us.
3. Why we process your data (legal bases)
| Purpose | Legal basis (GDPR) |
| Creating and running your account; delivering posts, messages, calls, communities, and events | Performance of a contract (Art. 6(1)(b)) |
| Sending and verifying one-time sign-in codes | Performance of a contract (Art. 6(1)(b)) |
| Security, fraud and abuse prevention, moderation of reported content | Legitimate interests (Art. 6(1)(f)) |
| Crash and error diagnostics | Legitimate interests (Art. 6(1)(f)) |
| Optional features: location tags, promotional communications | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Responding to lawful requests; tax and accounting duties | Legal obligation (Art. 6(1)(c)) |
Where processing is based on consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
3.1 Automated decision-making and profiling
PetHive ranks your feed and suggests content using signals such as your follows, likes, and viewing activity — a form of profiling used solely to order what you see. We make no automated decisions about you that produce legal effects or similarly significantly affect you (Art. 22 GDPR). You can reduce personalization by using the chronological following feed and the "not interested" / hide controls on posts.
For users in India, we process personal data for these same stated purposes in accordance with the DPDP Act, 2023.
4. Who we share data with
We do not sell your personal data. We share it only with:
- Service providers (processors) who run parts of the service under contract with us:
- Amazon Web Services — application hosting and media storage. Our production infrastructure is located in the EU (Frankfurt, eu-central-1).
- Twilio — sending and verifying one-time SMS sign-in codes.
- Sentry (Functional Software, Inc.) — crash and error diagnostics, under a data processing agreement.
- Apple Push Notification service / Google (Firebase Cloud Messaging) — delivering push notifications to your device. Notification payloads for chats do not expose your message content in transit through these services beyond what is needed to notify you.
- Other users — according to your choices: public posts are visible to other users, follower-only content to your approved followers, and community content to that community's members.
- Authorities — where we are legally required to respond to valid legal process. End-to-end encrypted message content cannot be produced by us in readable form, because we do not hold the keys.
5. International transfers
Our servers for the PetHive service are hosted in the European Union (Frankfurt, Germany). Some service providers process limited data in the United States: Twilio (phone number, for SMS delivery) and Sentry (pseudonymized diagnostics). These transfers are protected by the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework. Where any other provider processes data outside the EU/EEA, we rely on the same safeguards or an applicable adequacy decision. As the controller is established in India, account data is also accessible to our team in India under these safeguards, strictly for operating the service.
6. How long we keep data
- Account and content data: for as long as your account exists. When you delete your account, your personal data is erased or irreversibly anonymized immediately — see Account Deletion for exactly what happens.
- Diagnostics: crash reports are retained for a limited period (up to 90 days) and then deleted automatically.
- Security and audit records: kept for a limited period where required for fraud prevention, dispute resolution, or legal compliance, then deleted.
- Disappearing messages are removed according to the timer you set; delivered end-to-end encrypted messages are removed from our servers once delivered to your devices or on expiry.
7. Security
- End-to-end encryption (Signal protocol) for private chats; user-held recovery codes for chat backups.
- Encryption in transit (TLS) for all connections to our servers.
- Passwords stored only as secure hashes; optional biometric app lock on your device.
- Access controls, monitoring, and device-integrity checks protecting our infrastructure and APIs.
No system can be guaranteed 100% secure, but if a breach affecting your personal data occurs, we will notify you and the relevant supervisory authority without undue delay, as required by law.
8. Your rights
You have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data (most profile data can be edited directly in the app);
- Erase your data (delete your account in the app — see Account Deletion);
- Restrict or object to certain processing, including processing based on legitimate interests;
- Data portability — receive a copy of data you provided in a structured, machine-readable format;
- Withdraw consent at any time, where processing is based on consent (for example in the app's privacy settings);
- Complain to a supervisory authority — your local EU Data Protection Authority, or the Data Protection Board of India, as applicable.
To exercise any of these rights, use the in-app settings where available or contact us at info@zgcns.com. We will respond within the timelines required by applicable law and may ask you to verify your identity first.
8.1 Additional rights for users in India (DPDP Act, 2023)
- Access and correction/erasure of your personal data, as described above;
- Grievance redressal: contact our Grievance Officer (details in section 1); grievances are acknowledged within 24 hours and resolved within 15 days;
- Nomination: you may nominate another person to exercise your rights in the event of your death or incapacity — email info@zgcns.com to record a nomination;
- If unsatisfied with our response, you may complain to the Data Protection Board of India.
9. Children
PetHive requires users to be at least 14 years old, and we verify age at sign-up. Where the law of your country sets a higher age for consenting to data processing (up to 16 in some EU member states), you may only use PetHive with the consent of a parent or guardian as required by that law. If we learn that we have collected personal data from a child below the applicable age without required consent, we will delete it promptly.
10. In-app privacy controls
- Private account mode — approve who follows you.
- Per-post visibility (public, followers, only me) and optional location tags.
- Read receipts you can turn off (symmetrically — you neither send nor see them).
- Disappearing messages per chat.
- Blocking and reporting of users and content — reported content is reviewed and acted on within 24 hours (see our Community Guidelines).
- Privacy choices presented at sign-up, changeable at any time in Settings → Privacy.
11. These web pages
Our policy pages (this site) are static documents: they set no cookies and use no analytics or tracking. Visiting them leaves no personal data with us beyond standard, short-lived server logs kept by our hosting provider for security.
12. Changes to this Policy
We may update this Policy as PetHive evolves or as legal requirements change. Material changes will be announced in the app or by email before they take effect, and the "Last updated" date above will always tell you when the Policy was last revised.
13. Contact
Zero Gravity Cybernetics Private Limited
Pentagon 3, Magarpatta City, Hadapsar, Pune, India – 411013
Email:
info@zgcns.com