Leu

Privacy Policy

How Leu keeps your pet-care history private while supporting iCloud sync and caregiver collaboration.

Last updated: September 13, 2026

Overview

Leu is an iPhone app for tracking pet medications, medication doses, seizure events, important contacts, and caregiver collaboration. Leu is designed to keep pet-care history on your device and, when cloud sync or caregiver sharing is enabled, in your iCloud account through CloudKit.

Leu does not use ads, third-party analytics SDKs, or cross-app tracking.

Leu does not publish pet profiles or care history to a public feed. Information may still appear in local notifications, sync through iCloud, be shared with invited caregivers, or be included in an export you choose to share, as described below.

Pet history and care data

Leu can store the following data for app functionality:

  • pet profile information, including pet names, species, birthday or adoption information, estimated age, and food or diet details
  • medications and schedules
  • dose logs
  • seizure history
  • important contacts
  • caregiver display names used inside shared history

This data, including pet names, is stored locally on your device. When you use iCloud sync or caregiver sharing, it is also stored through Apple's CloudKit infrastructure so your devices and invited caregivers can stay up to date. Leu uses caregiver display names as attribution inside shared care history; it does not create a separate Leu account with a password or Leu-hosted account profile.

Real-time caregiver alerts

To deliver real-time caregiver notifications, Leu uses a push relay built on Cloudflare Workers, D1 and Durable Objects.

That relay stores only what is needed to deliver and deduplicate notifications, including:

  • APNs device tokens
  • opaque installation identifiers
  • verified Apple account and shared-resource identifiers, notification permissions, and revocation records
  • opaque caregiver, account, pet, and event identifiers
  • caregiver-event kind: dose logged, medication missed, medication skipped, or seizure logged
  • minimal relay housekeeping metadata used for dedupe, cleanup, and rate limiting

Leu automatically verifies your existing native iCloud identity and accepted pet sharing with Apple when registering a phone or sending caregiver activity. The single-use Apple authorization tokens are used for verification and are not retained by the relay. There is no separate Leu sign-in or caregiver-alert connection step. The relay encrypts registration, permission, and delivery records in storage and keeps only a hash of the phone's relay access credential. Accepted delivery jobs are retried by the server for up to ten minutes. Sharing edits made through Leu pause alerts for that pet until notification permissions are confirmed; alerts may remain paused if confirmation is interrupted. Changes made outside Leu are reconciled when the owner next verifies the share. The relay does not keep a copy of your pet history. Shared caregiver alerts use generic lock-screen text, without pet names, caregiver names, medication names or dosage amounts, or seizure timing details. Their push payload can include opaque identifiers and event kind so Leu can open the relevant shared-care context. This generic-text promise applies to relay-delivered caregiver alerts, not to local medication reminders.

Notifications, sharing, and export

Medication schedules can be saved even when notifications are off. Notification permission only controls whether iOS can deliver reminder notifications and caregiver alerts.

Leu uses two notification paths: local medication reminders for the person using the device, and shared caregiver alerts for invited caregivers.

Local medication reminders are generated on device from the schedules saved in Leu. These reminders can display the active pet's name, medication name, and formatted dose on the lock screen, in Notification Center, on paired Apple devices, and in notification previews depending on the user's Apple notification settings. Anyone who can view those previews may see that information. Users can hide previews or disable Leu notifications in system settings. Leu also includes the relevant pet, medication, schedule, dose, and reminder identifiers in local notification metadata so tapping a reminder can open the relevant pet context for review.

Local medication reminder content is not sent through Leu's Cloudflare relay. If iCloud sync or caregiver sharing is enabled, the underlying pet, medication, schedule, dose, and seizure records may sync through Apple's CloudKit infrastructure as described above.

CSV exports are generated on device and include the pet name and selected care-history details. They are only sent elsewhere when you explicitly choose a share or save destination; after that, the selected destination controls its copy.

Caregiver collaboration uses Apple's iCloud sharing flow. Shared pets are scoped per pet. Collaborators can view and add care activity for shared pets, while owner-only pet administration, important contacts, and sharing controls remain managed by the pet owner.

Deletion, app removal, and restore

Deleting the Leu app from a device removes that device's local Leu app data and local notification setup. If iCloud sync or caregiver sharing has stored records in CloudKit, deleting the app from one device does not necessarily delete those iCloud-backed records.

To remove Leu pet records from the tracker, use the in-app destructive flows, such as Delete Pet for pets you own. Deleting a pet removes that pet's profile, medications, schedules, dose logs, seizure history, and related records from the Leu tracker. Collaborators can leave a shared pet from their device, but only the owner can delete or stop sharing the owner's pet records.

If you reinstall Leu or install it on another device using the same Apple ID, Leu may offer to restore owner data or accepted shared pets from iCloud when those records are still available.

Retention

Leu's relay housekeeping currently aims to:

  • retain recipient registration while valid; an inactive or closed app does not cause it to expire
  • remove caregiver delivery jobs and deduplication receipts after fourteen days; accepted jobs are retried for at most ten minutes
  • retain notification permission and revocation records to enforce sharing decisions; reset rate-limit windows after one hour and clean up expired counters with the relay scheduler

Expired delivery entries are removed during scheduler cleanup. Leu removes a phone's installation on successful unregistration, replacement of the device address, or an invalid APNs token. Single-use Apple authorization tokens are not retained. These windows may change if Leu's notification architecture changes.

Tracking and analytics

Leu does not use your data for advertising, marketing, or cross-app tracking.

Leu's product goal is that pet history remains on device and in iCloud, not in a Leu-owned analytics backend.

Changes

If Leu's data flows change, this policy will be updated before the related build is shipped.

Privacy questions

Email support@leuapp.com. Please avoid sending unnecessary pet medical details or other sensitive information. Leu support cannot provide veterinary or emergency advice.