Legal

Privacy Policy

Effective date: June 20, 2026

This Privacy Policy describes how ReCura (“ReCura”, “we”, “us”, or “our”) collects, uses, discloses, and protects information when you use the ReCura mobile application (“App”) and related services that link to this policy.

By creating an account or using the App, you agree to the practices described here. If you do not agree, please do not use the App.

1. Who We Are

ReCura is the official companion app for Respond Animal Therapeutics laser therapy devices. We help veterinary professionals and pet owners access safety tutorials, treatment protocols, device information, and support resources.

Data controller: ReCura
Address: Address - 16304 E 32nd Ave. Suite 40, Aurora, CO, 80011
Privacy enquiries: info@respondanimal.com
Support: info@respondanimal.com

2. Information We Collect

We collect the following categories of information:

Information you provide. When you create or manage an account, we collect your full name, email address, password (stored only as a one-way hash — we never store plain-text passwords), optional phone number, user role (for example, veterinary professional or pet owner), and the animal types you work with. You may update your profile information at any time in the App.

Device and product information. We store which ReCura device(s) you have linked to your account, optional serial numbers you enter, your primary device selection, and the date and version of any safety agreement you accept after completing the safety tutorial.

Protocol and usage data. When you use the protocol wizard, we process your selections (species, coat colour, weight category, and condition) to retrieve the correct treatment protocol. When you save a protocol as a favourite, we store that preference on our servers and link it to your account and device.

Analytics and diagnostics. We use PostHog, a third-party analytics and error-reporting service, to understand how the App is used and to diagnose crashes. PostHog receives:

  • Your email address, used to identify your session across App launches (via PostHog’s identify feature).
  • Custom in-app events, including: account sign-up and sign-in (success and failure), device changes, safety tutorial started/completed/skipped, protocol runs, protocols favourited or unfavourited, and support contact initiated (email, text, or call).
  • Event properties such as user role, animal types, device identifier, protocol parameters (species, coat colour, weight category, condition, mode), tutorial duration, and contact method.
  • Automatic diagnostic data collected by PostHog, which may include device type, operating system and version, App version, session timestamps, and uncaught exceptions or unhandled promise rejections.

Analytics events are sent only when the App detects an active network connection. PostHog may also store a small analytics identifier locally on your device (file persistence) to maintain session continuity.

Information stored locally on your device. To keep you signed in and support offline use, the App stores data on your device using encrypted secure storage and local device storage, including:

  • Authentication token and basic profile information.
  • Your selected device preference.
  • Cached copies of device content, protocols, and favourites for offline access.

Technical and security data. When you use authentication-related features (such as sign-in, sign-up, or password reset), our servers may temporarily process your IP address for rate limiting and abuse prevention. Server error logs may include request metadata needed to troubleshoot issues.

What we do not collect. The App does not require or collect precise location data, contacts, photos, camera or microphone input, Bluetooth connections, health records, advertising identifiers (IDFA/GAID), or payment card details. We do not currently send push notifications and do not collect push notification tokens.

3. How We Use Your Information

We use the information we collect to:

  • Create, authenticate, and maintain your account.
  • Provide personalised treatment protocol recommendations.
  • Save and sync your favourite protocols across sessions.
  • Track safety tutorial completion and agreement records.
  • Send transactional emails, such as password-reset links, when you request them.
  • Operate, maintain, and improve the App’s features and content.
  • Analyse usage patterns and diagnose errors so we can improve reliability and safety guidance.
  • Detect, prevent, and respond to fraud, abuse, or security incidents.
  • Comply with applicable legal obligations.

We do not use your information for cross-app tracking, targeted advertising, or selling your personal information to third parties.

4. Legal Bases for Processing (EEA, UK, and Switzerland)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data on the following legal bases:

  • Contract. Processing needed to provide the App and your account (for example, authentication, protocols, and favourites).
  • Legitimate interests. Processing needed to secure, maintain, and improve the App, including analytics, error reporting, and abuse prevention, balanced against your privacy rights.
  • Legal obligation. Processing required to comply with applicable law.
  • Consent. Where required by law for specific processing activities, we will request your consent separately.

5. How We Share Information

We do not sell or rent your personal information. We share information only in the following circumstances:

  • Service providers. We use trusted third parties to operate the App on our behalf. These providers process data only under our instructions and contractual safeguards:
    • PostHog — product analytics, session identification, and crash/error reporting.
    • Resend — delivery of transactional emails (for example, password resets).
    • Cloudflare R2 — storage and delivery of device images and other static assets.
    • Database and infrastructure providers — hosting of account data, protocol records, and related application data (PostgreSQL and Redis).
  • Legal and safety. We may disclose information if required by law, regulation, legal process, or government request, or when we believe disclosure is necessary to protect the rights, property, or safety of ReCura, our users, or the public.
  • Business transfers. If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or applicable privacy policy.

6. International Data Transfers

ReCura is operated from the United States. If you access the App from outside the United States, your information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate. These countries may have data protection laws that differ from those in your country.

Where required, we rely on appropriate safeguards for international transfers, such as Standard Contractual Clauses or equivalent mechanisms approved by applicable regulators.

7. Data Retention

We retain your account information for as long as your account is active or as needed to provide the App. If you delete your account, we delete or anonymise your personal data within 30 days, except where longer retention is required by law or reasonably needed to resolve disputes, enforce agreements, or maintain security logs.

Analytics and diagnostic data retained by PostHog is subject to PostHog’s retention settings and our internal data retention policies. Rate-limiting and security logs containing IP addresses are retained only for as long as needed for abuse prevention and troubleshooting.

Locally cached data on your device remains until you sign out, delete the App, or clear the App’s storage.

8. Security

We implement technical and organisational measures designed to protect your information, including:

  • Password hashing using industry-standard algorithms.
  • Authentication tokens stored in your device’s encrypted secure storage.
  • Transport encryption (TLS) for communications between the App and our servers.
  • Access controls and rate limiting on sensitive authentication endpoints.

No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately at info@respondanimal.com.

9. Your Rights and Choices

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Request deletion of your personal data.
  • Object to or restrict certain processing activities.
  • Receive a portable copy of your data.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with your local data protection authority.

Account deletion. You can delete your account at any time from My Account in the App by selecting Delete account. This permanently removes your account and associated data from our servers, subject to the retention exceptions described above. Deleting your account does not automatically delete analytics data already processed by PostHog; contact us if you would like us to request deletion of associated analytics records.

Analytics. If you wish to opt out of analytics processing, contact us at info@respondanimal.com. Note that some diagnostic data may still be collected as necessary to maintain App security and stability.

To exercise any privacy right, email info@respondanimal.com. We may need to verify your identity before responding. We aim to respond within 30 days.

10. California Privacy Rights

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to delete personal information, and the right to correct inaccurate personal information.

We do not sell or share personal information for cross-context behavioural advertising. We do not use sensitive personal information for purposes other than those permitted by California law.

To submit a request, email info@respondanimal.com. We will not discriminate against you for exercising your privacy rights.

11. Children's Privacy

The App is intended for users aged 13 and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at info@respondanimal.com and we will take steps to delete it.

12. Third-Party Links and Services

The App may open external links (for example, email, phone, or SMS apps) to help you contact support. When you leave the App or interact with third-party services, their privacy policies apply. We encourage you to review the privacy policies of any third-party services you use, including PostHog.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page and, where required by law, provide additional notice within the App or by email. Your continued use of the App after changes are posted constitutes acceptance of the updated policy.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:

ReCura
Address - 16304 E 32nd Ave. Suite 40, Aurora, CO, 80011
info@respondanimal.com

© 2026 ReCura. All rights reserved.