Trust

Your records are yours. Here is exactly what that means.

Rescues are asked to trust software with the only copy of information that decides where an animal ends up. This page answers the questions worth asking, including the ones where our answer is not the flattering one.

Last reviewed: August 30, 2026

The questions that actually matter

Not a summary of our legal documents. The Privacy Policy and Terms are the binding versions. This is the plain-language one.

Who owns your rescue's data?

You do. Your organization decides what to collect and why; we hold it on your behalf and act on your instructions. In the language of privacy law, your rescue is the controller and RescueSphere is the processor.

We do not sell your data. We do not share it with advertisers or data brokers. We do not mine it to build a product we sell to someone else. Ending your subscription does not change who owns the records — it only changes whether you are paying us to host them.

How do exports work?

From Settings, any administrator can export the organization's full record set as JSON, at any time, without asking us. Animals and finance records additionally export as CSV from their own screens, for the common case of handing a spreadsheet to a board member or an accountant.

There is no export fee, no support ticket, no waiting period, and no reduced export for organizations on the way out. A product that is only easy to leave when you are not leaving is not portable, and the ability to walk away with everything is most of what makes the rest of this page meaningful.

How do backups work?

Your database is backed up automatically and continuously, encrypted with a key we control, and retained for 30 days. That covers the failure people usually mean by "do you have backups" — a database problem on our side.

Uploaded files are a narrower story, and it is worth being precise rather than letting the sentence above cover both. Photos and documents are stored encrypted on Amazon S3 and replicated across facilities, so hardware failure will not lose them. But we do not currently keep point-in-time file history, which means that if someone on your team deletes a photo, we cannot bring it back. That is a real limitation, we are working on it, and you should know about it now rather than on the day it matters.

After you cancel, we keep your data for 30 days so you can come back or pull a final export, then remove it from active systems. Encrypted backups age out on their normal rolling schedule after that.

Do you train AI on our records?

No. Your data is not used to train AI models — not by us, and not by our AI provider.

Dispatch, the assistant built into RescueSphere, runs on Anthropic's Claude models. When you ask Dispatch to summarize a medical note or draft a reply, the content of that request is sent to Anthropic to answer it, and nothing beyond that request goes with it. Anthropic does not train its models on data submitted through its API.

Anthropic is not the only AI provider, and listing only the flattering half of that would defeat the point of this page. The Studio video tools use OpenAI for voiceover and for transcribing audio, or ElevenLabs for voiceover if you pick it in Settings. Those tools are opt-in and gated: if your plan does not include Studio, or you never open it, nothing of yours reaches either company. Both are in the sub-processor table below, on the same footing as everyone else.

Every AI feature also has a non-AI fallback, and the fallback is real rather than a degraded error state — triage falls back to heuristics, bios fall back to templates. RescueSphere runs with AI switched off entirely, which means you are never obliged to send anything to a model to keep working.

Can other rescues see our data?

No. Nothing is shared between organizations, and there is no setting that turns it on.

This is enforced by how the system is built rather than by policy: every organization gets its own separate database, and a request is bound to one organization before it reaches any code that could read a record. Isolation you have to remember to apply eventually fails; this kind does not depend on anyone remembering.

What can RescueSphere staff see?

Here is the honest answer, because a vague one would be worth nothing. A small number of our engineers can reach production systems, which is unavoidable for anyone who has to keep a database running. Beyond that, our support tooling can open a session as a user in your organization — the mechanism that lets someone help you with a problem they cannot otherwise see.

What makes that acceptable rather than alarming is that it is not silent. Every use is written to a central audit log under its own category, so it is a recorded event rather than an invisible one. Inside your own organization, access follows the roles you assign, and your activity log shows who changed what.

How the system is protected

The measures below are in place today. We have left out everything we intend to do later, because a security page is the worst possible place to describe a roadmap as though it were a control.

Separate database per organization

Your records do not sit in a shared table filtered by an organization column. They sit in their own database, so a missing filter cannot leak another rescue's data.

Encryption in transit and at rest

All traffic is served over TLS. Databases, file storage, and backups are encrypted at rest.

Two-factor authentication

Available on every account and on every plan, including the free one. Administrators can require it, and the requirement is enforced on each request rather than only at sign-in.

Role-based access

Admin, staff, veterinarian, foster, volunteer, and adopter roles each see a different product. Permission is checked when a page loads and again when an action runs.

Audit logging

Meaningful changes are recorded with who made them and when — inside your organization, and separately for administrative actions on our side.

Payment data never reaches us

Card details go directly to Stripe. Our servers never see or store a card number, for your subscription or for donations your supporters make.

What we do not have yet

RescueSphere does not hold SOC 2 or any other formal third-party security certification. We are an early-stage company and an audit we have not completed is not a control we can claim. We would rather you learn that here than discover it during a procurement review. If your organization needs documented controls today, talk to us and we will share exactly what we have.

Every company that touches your data

Running RescueSphere means relying on other companies, and naming them is the only version of this list that is worth reading. Each one receives the narrowest slice of data its job requires, under contractual data-protection obligations.

Third-party sub-processors used to operate RescueSphere
Company What they do for us What they receive Location
Amazon Web Services Application hosting, databases, file storage, and transactional email (SES) All tenant data, at rest and in transit United States
Anthropic Dispatch, our built-in AI assistant Only the content of an individual AI request — a support ticket, a medical note, an animal photo United States
OpenAI Voiceover and transcription for the Studio video tools The script text a voiceover is generated from, and any audio submitted for transcription United States
ElevenLabs Alternative Studio voiceover provider, when a tenant selects it The script text a voiceover is generated from United States
Stripe Subscription billing and donation processing Billing contact details and payment metadata. Card numbers go directly to Stripe and never reach our servers United States
Twilio Text messaging, when a rescue uses the SMS features Recipient phone numbers and message content United States
Sentry Application error monitoring Error diagnostics, which can include the request context in which a bug occurred United States
Cloudflare DNS and TLS termination for our domains Request metadata such as IP address and user agent Global edge network

Connections you choose to switch on

These are not in the table above, because they receive nothing unless your organization connects them: Mailchimp, QuickBooks, Google Calendar, Petfinder, Adopt-a-Pet, Meta (Facebook and Instagram), TikTok, Zapier, AKC Reunite, HomeAgain. Each one shares only what its integration needs, only while it is enabled, and disconnecting it stops the flow.

Last reviewed August 30, 2026. Organizations that need a Data Processing Agreement or a current sub-processor list in writing can request one at [email protected].

Something here not specific enough?

Ask. If we cannot answer a security question directly, the honest response is to tell you that rather than to reword the question, and that is the response you will get.

Contact us