Privacy
What we hold, and what we do with it.
A shelter’s records include people who never chose to deal with us — adopters, fosters, surrenderers. That is the part of this worth being careful about.
Whose data this is
Everything your shelter enters belongs to your shelter. We hold it so the software can run and so we can give it back to you. We do not own it and we do not license it from you.
Two different kinds of record live in that data and we treat them differently. The people in it — your staff and volunteers, and the adopters, fosters and surrenderers in your files — are never studied, profiled or counted for any purpose of ours. The animals in it may be, in aggregate, with no person and no shelter named. The next section says exactly what that covers.
What we learn from animal records
How long different animals wait, what they were treated for, what became of them, and where an illness is turning up in more than one place at once — those are questions no single shelter can answer from its own records, and every shelter is better off for them being answered.
So we may study animal records in aggregate: outcomes and length of stay, medical conditions that turn out to be common, and the geographic spread of an illness or an outbreak. We use what that shows to make the product better and, where it is useful to the field, to publish findings no single shelter could produce alone.
What it never includes:
- Any person. Adopters, fosters, surrenderers, staff and volunteers are left out entirely. Who you are and who works for you is not part of this and never will be.
- Any named shelter. Nothing we publish says which shelter a number came from, and nothing traces back to one animal’s record.
- Any sale. None of it is sold, licensed, or handed to an advertiser or a data broker, aggregated or otherwise.
If you would rather your shelter were not part of even that, there is a switch in your settings, under Research. Turning it off leaves your animal records out of every pooled figure from that moment, and nothing else about your account changes. You do not have to ask us, and we do not ask why.
What we hold about your shelter
- Your organization’s name, address, registration number and the public records we matched it against when verifying you.
- Your staff and volunteer accounts: name, email, role, and when they last signed in.
- Everything you enter about animals, people and the care you give them.
- An audit trail of who changed what and when, because a shelter record without one is not a record.
What we deliberately do not hold
Identity documents are stored as a type plus the last four characters — never a whole driving license number, passport number, social security number, or date of birth. That is enforced by a test that fails the build if any part of the system tries to return more than that, not by a policy somebody has to remember.
The one exception is a veterinarian’s license number, which is stored in full because a rabies certificate legally carries it. It is never returned by any part of the system except the certificate itself; every screen and every API response shows the last four.
Keeping shelters apart
Every record carries the id of the shelter it belongs to, and every query is filtered by it. That is not a convention we follow carefully — it is enforced by tests that inspect every database query and fail the build if one is missing the filter, and by a check that stops the application outright if a row belonging to another shelter is ever returned.
People who never signed up with us
Most people in a shelter’s records — an adopter, a foster, someone who surrendered an animal — have a relationship with the shelter, not with us. We hold their details only so the shelter can do its work, we do not contact them, and we do not build a profile of them across shelters. A person who appears at two shelters is two separate records that we make no attempt to connect.
AI assistants
If your shelter turns on AI assistants, the animal’s own record — species, breed, weight, status, care log entries — is sent to Google’s Vertex AI to produce the draft you asked for.
No person’s name, address, phone number or email is ever included. An adopter did not agree to that, none of the questions the assistants answer needs it, and a shelter cannot un-send it. There is a test that fails if a person’s details ever appear in what is sent.
If you never turn the assistants on, nothing about your shelter is ever sent to a model.
Signing up
When somebody registers a shelter we record the address they came from and their browser’s user agent, and keep them whether or not the signup succeeded. That is how a wave of automated signups is recognized afterwards, and it is the only reason we keep it.
Verifying your organization means matching what you told us against public records — the IRS list of tax-exempt organizations, state registries, the adoption listing sites. We hold our own copy of the IRS list, so verifying you does not tell anyone that you applied.
Logs
We log requests to diagnose faults. Passwords, tokens, API keys and email addresses are masked before anything is written, and we never log the contents of a search or a form. Logs are kept for thirty days.
Who else sees it
Nobody, unless you ask us to. We do not sell data, share it with advertisers, or hand it to a data broker. The only thing we do with it beyond running the software is the aggregate animal research described above, which carries no person and names no shelter. The services we do use — the server itself, the payment processor if you take card donations, Google’s Vertex AI if you turn on the assistants — see only what they need to do their part, and each of those is named above.
Getting it back, and getting it deleted
Full CSV and JSON export of everything your shelter owns, on demand, at no charge, without asking anyone. If you close your account we delete your data within thirty days; ask us and we will do it sooner.
Backups
The database is backed up nightly and kept for fourteen days. A deleted record can survive in a backup until those roll off, which is worth knowing if you delete something because it should never have been entered.
Asking us
Write to privacy@rescuely.net. If you are a person whose details are in a shelter’s records rather than a shelter yourself, the shelter holds that record and is the right place to start — but write to us anyway if that gets you nowhere.
Your shelter can be running this by the end of the day.
Create your account, verify your organization, and start entering animals. No sales call, no quote, no card. The part of Rescuely that runs a shelter is free and stays free.