# Data and API feasibility: dog photo → preparation → Bengaluru help Research date: **2026-10-06**. Specialist: dog-data. This report assesses data feasibility; it does not establish owner demand, clinical safety, professional qualifications or real owner usability. Evidence IDs resolve in [sources.json](../evidence/data/sources.json). Source access and narrow claim limits are recorded there; retrieval timestamps generally record ledger normalization time, while API probes have exact request timestamps. **Recommendation to the lead:** build consultation preparation with sourced provider links and explicit unknown prices as the initial local POC. A photo can supply limited visible context and prompt better questions; a brief combines that context with owner-reported history. Fresh, licensed provider quotes—not general maps data—are the dependency for claiming a service fits a budget. Grooming preparation is also feasible with reviewed guidance, but image-driven treatment and individualized diet conclusions are outside the approved boundary. ## Hypothesis-to-data map | Hypothesis | Photo/context usefulness | Required real data | Feasible action now | Missing before a dependable integration | |---|---|---|---|---| | Grooming preparation | Visible coat length/tangles may help frame a question; ask handling tolerance, recent grooming and owner-reported discomfort. Photo cannot establish skin condition or handling safety. | Professionally reviewed preparation rules, provider species/coat/handling exclusions, package scope, home-visit locality and fresh quote | Draft questions for a groomer; link to an inspected source with limitations | Review by groomer/vet; permissioned package/coverage feed; exclusions, extras and availability | | Trainer/vet consultation preparation | A still can illustrate the owner's concern; behaviour needs history/context and often expert-observed video. Separate visible observation from reported symptoms. | Reviewed intake questions, professional role and registration where applicable, local/remote service, source link and escalation rules | Owner-editable briefing template and source-backed candidate pointers | Professional validation; qualifications verification; consented handoff workflow; no automated clinical conclusion | | Local help under a budget | Photo provides preparation context; location, budget period and needs determine search. | Total INR price including taxes/travel/add-ons, service eligibility, valid-until, availability and qualified provider | Ask scope/locality/budget; show **price unknown—request a quote** | Fresh quotes and permissioned records; maps discovery alone cannot confirm affordability | These are design hypotheses, not measured photo-model capabilities. Inputs must not infer medication, diagnosis, definitive breed or individualized nutrition from a photograph. Relevant authoritative care guidance and owner evidence are the lead's separate integration dependencies. ## Real source options | Option | Access/India coverage | Fields and freshness | Rights, credentials, costs and practical limits | |---|---|---|---| | Curated provider records | No API needed for an owner-approved local prototype. Initial source-backed pointers cover Bengaluru only. | Store per-field source, observation date, verification method, confidence, unknowns and geographic basis. Public source date is not professional verification. | No public page implies catalogue reuse permission. Local research pointers are not a deployable directory. Labour cost for checking fields is unmeasured. | | Direct partner feed | Proposed contract, **no partner access obtained**. India service coverage must be explicit per provider/locality. | Signed service scopes, INR quotes, qualifications evidence, handling exclusions, home-visit radius, languages, slot TTL, cancellation and complaints route. Partner update/version/event ID, daily feed health and expiry needed. | Obtain agreement covering display, processing by an LLM if intended, retention, commercial use, logo/quotes, accuracy correction and deletion. Access/auth, costs, SLA and compensation remain unknown. No outreach undertaken. | | Google Places API (New) | Documented `veterinary_care` type and broader pet types; Bengaluru search is plausible but **not queried**. Text search can supplement category matching. | Names, address, coordinates, status, hours, website, phone and ratings depend on requested fields/data. `priceLevel` is a category, not a grooming/vet/training INR quote; hours do not establish a slot. | Requires enabled API, restricted server credential and billing. Field mask is mandatory and controls billing. Do not store all content as curated records. No professional registration, suitability, total service price or slots guaranteed. [DAT-028/029: types](https://developers.google.com/maps/documentation/places/web-service/place-types), [Text Search](https://developers.google.com/maps/documentation/places/web-service/text-search). | | OSM / Overpass | Public global data includes India. **One small Bengaluru query succeeded**; broad query timed out. | Contributor-maintained name/location and optional contact/hours; no completeness assurance. Extract database timestamp does not refresh old business facts. | ODbL attribution and possible share-alike obligations; no secret needed for small public query. Community infrastructure has load shedding and no contracted SLA. Sustain a public app using self-hosted/contracted data, not an assumed free production backend. [DAT-013/014: attribution](https://osmfoundation.org/wiki/Licence/Attribution_Guidelines), [Overpass commons](https://dev.overpass-api.de/overpass-doc/en/preface/commons.html). | | Mappls Nearby/place search | Indian supplier with primary API docs. Current Nearby endpoint `https://search.mappls.com/search/places/nearby/json` documented; **not called**. | Category/keyword/coordinates can discover POIs; returned fields depend on licensed use case. No dog-service quote/credentials/slots guarantee. | Current docs use console static key as `access_token` query parameter, with app access enabled and IP/domain restrictions. Legacy OAuth docs also exist—do not copy them as current setup. Commercial fee/entitlements, freshness SLA and permitted reuse need agreement; no verified numeric quote obtained. [DAT-018/019: index](https://developer.mappls.com/documentation/sdk/rest-apis/Readme/), [current Nearby](https://developer.mappls.com/documentation/sdk/rest-apis/mappls-maps-near-by-api-example/Readme/). | | Indian pet-service platforms | Inspected Kuddle and Supertails pages; surveyed PetBacker terms. **No public third-party booking/quote API documentation found in these official-site searches.** This is a bounded survey, not a universal absence claim. | Provider claims establish possible service links, not reusable records or live slots. Bengaluru grooming/clinics advertised; Indian product delivery does not establish countrywide home services. | Browser booking buttons/private application requests are not API access. PetBacker expressly restricts manual/automated provider collection; no listings harvested. Supertails restricts harvesting and reuse without permission. Kuddle full terms access incomplete. Use future negotiated partner data. [DAT-021/022: Kuddle](https://kuddle.pet/collection/dog-grooming), [Supertails](https://supertails.com/pages/supertails-clinic-locations), [DAT-023/024 terms](https://supertails.com/policies/terms-of-service), [PetBacker terms](https://www.petbacker.com/help-center/policies/terms-of-use). | Mappls terms require visible branding, prohibit caching to avoid fees and mixing maps without permission, and require paid rights for commercial applications. Its marketing claim of India-local storage does not establish the whole product's data residency. [DAT-020: API terms](https://about.mappls.com/api/terms-&-conditions). Google Places allows indefinite place-ID storage; service-specific terms allow temporary coordinate caching up to 30 consecutive calendar days. This does **not** allow retaining names, reviews, hours and full records indefinitely. Attribute content correctly; API Places content cannot be shown on a non-Google map. Google also restricts using content to improve, train, test, validate or fine-tune AI/ML models. Keep Google results out of replay/evaluation fixtures and graph datasets; obtain implementation/terms review for any future request-scoped use in model-visible results. [DAT-010: policies](https://developers.google.com/maps/documentation/places/web-service/policies), [DAT-026: terms](https://cloud.google.com/maps-platform/terms), [DAT-027: service-specific exceptions](https://cloud.google.com/maps-platform/terms/maps-service-terms). ## What was actually accessed and tested Two **anonymous, read-only** GETs to the documented public Overpass interpreter; no paid API calls or account/credential inspection: 1. Bengaluru rectangle south/west/north/east `12.90,77.50,13.10,77.75`, veterinary and grooming tags: HTTP **504**, 11.09 seconds; no data result. [Saved test](../evidence/data/overpass-test.json). 2. Reduced 3 km radius around `12.9352,77.6245` (Koramangala): HTTP **200**, 9.41 seconds, 1,448 bytes. OSM database base `2026-10-06T06:23:19Z`; **5 veterinary features, 3 named, 2 with phone tags, 1 with website, 0 opening-hours tags, 0 grooming features**. [Query](../evidence/data/overpass-query-small.txt), [response](../evidence/data/overpass-response-small.json), [test](../evidence/data/overpass-test-small.json), DAT-017. No feature supplies price, appointment availability or professional registration. Two unnamed nodes close to the named V-Care feature could be duplicates; preserve IDs and flag possible duplication instead of counting five distinct businesses. These bounded feature counts say nothing about provider prevalence or completeness. `check_date:2025-08-08` occurs on Pet Zone; current extraction does not turn it into a current on-site check. No bulk map/review harvest was attempted. Six [provider seed candidates](../evidence/data/provider-seeds.json): three named OSM facilities, two minimal Supertails location pointers and one Kuddle service pointer. Every candidate has source URL/date, geographical basis, provenance and limitations. **All six have null price, credentials and availability; all six have `production_usable:false`.** `verified_on` means the source/extract was checked, not that the business, quality or price was independently verified. Contact fields were left null; no invented contacts. Map-source website values are tagged as unverified. The V-Care site failed to open. No PetBacker individual provider records retained. The supplied Doggo Pokko screenshot visibly describes Bengaluru training/behaviour and diet planning; screenshot date and qualifications are unknown (DAT-030). The live [Linktree](https://linktr.ee/doggo_pokko) resolves, but visible content comprises product links, not a service booking/data contract (DAT-031). No linked products were followed or recommended. Do not mark the friend as a verified trainer, diet expert, or signed partner. ## Current OpenAI integration mechanics Official documentation was searched and fetched using the OpenAI Docs capability. No inference API, Files API upload, Action endpoint, ChatGPT plugin connection or host upload was tested. | Path | Current file/tool mechanics | Boundary | |---|---|---| | Responses API backend | `input` user message contains `input_text` and `input_image`; image uses fully qualified URL, base64 data URL, or `file_id` created with Files API (`purpose:vision` in fetched guide). Use a vision-capable model. Requested `gpt-6.1-sol` documents image input and Responses tool calling. | ChatGPT attachment IDs are not assumed to be backend Files API IDs. Download authorized host file, validate, and use an independently authorized backend transport. No live model access verified. | | ChatGPT plugin/MCP (Apps SDK lineage) | `_meta["openai/fileParams"]:["photos"]` declares top-level file input. Every file schema declares `download_url`, `file_id`, `mime_type`, `file_name`; **only** URL and ID are required. Current upload helpers: `window.openai.uploadFile`; optional/feature-detected `selectFiles`; `getFileDownloadUrl` obtains temporary URL. | Do not use earlier remembered string-only fileParams. Missing optional filename/MIME is valid; determine actual format server-side. File-library availability is not universal. Draft descriptor is not registered or host-approved. | | GPT Actions | POST `openaiFileIdRefs` is documented as a string-array schema but arrives as objects with `name`, `id`, `mime_type`, `download_link`. URLs last five minutes; maximum ten input files. | Separate runtime decoder; never validate runtime objects against string-array documentation schema unchanged. Product policy below accepts only three photos. Action auth supports None/API key/OAuth. Returning images through `openaiFileResponse` is unsupported by fetched guide. | [DAT-001: vision](https://developers.openai.com/api/docs/guides/images-vision), [DAT-002: plugin reference](https://developers.openai.com/plugins/reference), [DAT-003: Action files](https://developers.openai.com/api/docs/actions/sending-files), [DAT-005: exact model](https://developers.openai.com/api/docs/models/gpt-6.1-sol), [DAT-008: Action authentication](https://developers.openai.com/api/docs/actions/authentication). Current general vision ceilings are PNG/JPEG/WEBP/non-animated GIF, **512 MB** request payload, **1,500 images** and **30,000 patches per image after model preprocessing**. These are current fetched API ceilings, not our upload policy. Model/detail sizing varies; the fetched vision sizing table does not explicitly list GPT-6.1 Sol, so its exact image token multiplier was not established. India is on the supported API country list; this does not prove a particular account's entitlement or India-local inference processing. The model page documents US/EU residency, not an India guarantee. [DAT-001/005](https://developers.openai.com/api/docs/guides/images-vision), [DAT-033: supported countries](https://developers.openai.com/api/docs/supported-countries). Responses function tool definitions use `type:function`, `name`, `description`, `parameters`, `strict:true`; every strict object requires `additionalProperties:false` and every property in `required`, using null for unknown optional values. MCP descriptors separately use `inputSchema`, `outputSchema`, annotations and security schemes. They are different contracts. [DAT-007: strict mode](https://developers.openai.com/api/docs/guides/function-calling#strict-mode). Tool `structuredContent` and `content` are model-visible; result `_meta` is delivered to the UI component. Component-only metadata is still client data, not a secret store. Keep API keys, signed download URLs, personal addresses and raw image bytes out of model-visible results, widget state and logs. Use opaque correlation IDs in Responses metadata; do not use it as a consent/authentication mechanism. The generated Responses reference fetch returned a stub; exact numerical metadata limits were **not established**, and are not asserted here (DAT-032). [DAT-002: reference](https://developers.openai.com/plugins/reference). ## Privacy, security and refresh contract Proposed product limits: at most **3 photos**, **5 MiB each**, JPEG/PNG/WEBP, maximum dimension **8,192 px**, decoded-pixel budget **40 million per photo**, at most **15 MiB total**. Byte/dimension/count limits are in schemas; total/pixel limits require implementation checks. Detect magic bytes, decode to verify dimensions, reject corrupted/animated/polyglot inputs, and remove EXIF including GPS before processing. MIME from an Action extension or a client field is only a hint. Local replay must not upload photos. Obtain explicit photo/model-processing consent with separate disclosure for backend/OpenAI/host retention. Do not send any image or brief to a provider through these contracts: prepare an owner-reviewable handoff instead. Location defaults to owner-supplied city/locality; no GPS EXIF inference or home address needed. Proposed backend policy is delete at session end or within **3,600 seconds**, no raw photos/signed URLs in logs, and owner deletion. This is a **draft policy**, not implemented deletion or a claim of total host/API zero retention. `store:false` controls Responses application-state storage; it does not eliminate ordinary abuse-monitoring retention (generally up to 30 days, with exceptions). Files have separate retained state until deletion/expiry; Zero Data Retention requires approval and has feature/image exceptions. Avoid Files uploads when an authorized transient data URL suffices; if uploaded, track deletion and verify it. ChatGPT history and host uploads follow host controls, independently. [DAT-004: API data](https://developers.openai.com/api/docs/guides/your-data). Bind authorized file access to session/user; validate file ID ownership. Signed URLs expire and must not become durable provenance. Fetch only validated HTTPS host-file origins, enforce DNS/private-address and redirect controls, byte limits, TLS/timeouts, and redact URL query tokens. Keep third-party pages/image text untrusted so prompt injection cannot authorize calls or change clinical limits. Widget CSP limits the widget; enforce backend egress separately. `readOnlyHint`/`openWorldHint` annotate intent, not authorization. No keys in frontend; verify OAuth scopes on each authenticated call. [DAT-006: official security/privacy](https://developers.openai.com/plugins/guides/security-privacy). Refresh proposal (operating assumptions, not vendor SLA): partner quotes/slots expire at supplier-provided times; missing expiry never permits confirmed budget-fit. Suppress expired price/slot claims. Recheck provider coverage/role monthly and link reachability weekly; immediately quarantine contradictions/complaints until verified. Each field carries observed/verified/expires timestamps, evidence type, rights status and confidence basis. OSM re-extraction updates the snapshot, not professional verification. Keep independently licensed partner records separate from OSM derivatives and restricted maps results. ## Operating costs and blockers Published Google India rates apply only with Indian billing and a large majority of usage in India. New Text/Nearby Search Pro has 35,000 free monthly events then **USD9.60/1,000**; Details Pro 35,000 then **USD5.10/1,000**; Details Enterprise 7,000 then **USD6/1,000** in the first paid tier. Field mask changes SKU; phone/hours/rating fields can raise it. Free caps are per SKU across billing-account projects. **No billable call made.** [DAT-011: prices](https://developers.google.com/maps/billing-and-pricing/pricing-india), [DAT-012: eligibility](https://developers.google.com/maps/billing-and-pricing/india). For exhausted caps, one Pro search plus three Pro details costs an assumed call pattern of **USD0.0249 per flow**. At explicitly assumed INR/USD **85/95/105**, that is about **₹2.12/₹2.37/₹2.61**. INR billing conversion is Google's, not this scenario. This omits retries, map loads, higher field tiers, taxes and operational work. OpenAI Standard short-context GPT-6.1 Sol published rates are **USD2/M input, USD10/M output**, with **USD0.10/M cached input and USD2.50/M cache writes**; long-context/processing tiers differ. Assuming total billed input of 4,000 tokens (including images) and 800 output tokens gives **USD0.016**, approximately **₹1.36/₹1.52/₹1.68** at the same assumed FX. This is a sensitivity example, not measured image usage: exact GPT-6.1 image tokenization, cache-write usage, reasoning output and actual request bill remain untested. A midpoint model+maps example is ~₹3.89 before human review/hosting/tax/maintenance; professional compensation could dominate and must be modelled by the market specialist. [DAT-009: current pricing](https://developers.openai.com/api/docs/pricing). Exact blockers: permissioned provider/service dataset; verified total quotes and availability; professional role/registration and review of advice/intake; account-specific OpenAI and Maps entitlement/billing; backend secured hosting/auth/file lifecycle; host/Action Scan Tools and runtime validation; professional and real owner usability testing. Credentials were neither requested nor read. No bookings, purchases, messages, deployment, installation or publishing performed. ## Drafts, reproduction and test scope [Draft contracts](../contracts/data-drafts/README.md) include four local JSON schemas and four platform/request examples. [Build script](../evidence/data/build_artifacts.py) materializes recorded research notes and drafts; it performs no network calls. [Validation script](../evidence/data/validate_contracts.py) runs **33 passing offline checks**, including six seeds, unsupported/oversized photos, no consent, excess retention, fabricated provenance/price shape, replay falsely claiming live calls, and simulated quote expiry. [Results](../evidence/data/contract-test-results.json). ```bash python evidence/data/validate_contracts.py ``` No JSON Schema validation dependency was installed. The dependency-free validator covers the used subset and explicit invariants; **it is not a complete JSON Schema metaschema validator or OpenAI host/API conformance check**. Host file handling, actual image decoding/EXIF removal, deletion, SSRF controls, latency/cost, clinical accuracy and real owner workflow remain untested. The examples contain invented fixture IDs and image attributes only, clearly labeled local replay. The only live data integration tested here is the bounded anonymous Overpass request. The lead-owned POC must keep live-image/live-provider flags false for local replay, show sourced research pointers with unknown fields, and state this boundary in its own UI and report.