Skip to content
Pawfect Fwiend

Privacy Policy

Last Updated: Last Updated: August 30, 2026

1. Information We Collect

Account Information

When you create an account, we collect: • Email address • Display name (from your profile, or one you choose) • Phone number (optional) • Profile photo (optional) • Authentication credentials (managed by Firebase Authentication) There are two ways to sign in, and what we receive depends on which you use: • Google: Google tells us the email address and the basic profile details on your Google account. • Apple: Apple tells us your name and an email address. If you choose to hide your address, Apple gives us a private relay address and we never see the real one. Our security records store a keyed hash of your email address and its domain, not the address itself. The long-lived credential your app keeps so you stay signed in between launches is stored on our side only as a SHA-256 hash, so it cannot be read back out of our database and reused.

Content You Upload

Videos and images you upload are stored securely in Firebase Cloud Storage. This content is used to: • Provide AI-powered behavioral analysis • Generate behavioral insights and captions • Store your analysis history and memories • Improve our AI models (with your consent) You retain full ownership of all uploaded content.

Camera and Microphone Access

The live camera feature requires camera permission to capture video. We: • Do NOT record or store full live camera sessions unless you explicitly save them (a limited, short-retention diagnostics exception is described below) • When you request live analysis, we transmit JPEG video frames and JSON control messages to our behavioural-analysis service; the native app does not transmit raw audio or acoustic features for live analysis • If you choose to record and save a session, the saved video clip may include an audio track only when microphone permission is granted, the microphone is not muted, and biometric anonymity is disabled • On supported native camera paths, react-native-vision-camera CameraObjectOutput face detection can apply on-device face blur before frames are encoded; server-side face blur is a separate defence-in-depth layer before storage • Diagnostics exception: when enabled, we may retain a low-frequency sequence of still frames from a live session for up to 14 days, solely for product diagnostics and abuse review, accessible only to our administrators, after which they are automatically deleted; face-blur controls are applied when available but are not guaranteed if disabled or if a model is unavailable, and this footage is covered by your erasure rights Camera access is only active while you are using the camera feature.

Location Information

Some features use your device's precise location: • Explore map: we use your location only while the app is in the foreground to centre the map on you and show nearby pins. • Walk & Conquer: only after you explicitly start a walk, we use your precise GPS location in the foreground and background—including while the screen is locked or you switch to another app—to trace your route and award map territory. Background tracking runs only while that walk is active and stops immediately when the walk ends. Location access is consent-gated: you grant the operating-system permissions first, and you can revoke them at any time in your device settings. Route and territory data you create in Walk & Conquer is stored with your account so your progress persists; you can delete it by removing the associated map content or your account. Territory you claim is PUBLISHED on the shared map, not kept private. Other users see the outline of the loop you walked and the size of the ground it encloses, so they can see where you walked to make that claim. They also see the AI-generated portrait of the pet you walked with, because that portrait is what marks your territory on their map; the real photo you uploaded for that pet is never used here, and a claim whose owner has no pet with a generated portrait is not shown on the shared map at all. If your claim overlaps someone else's territory, we notify those owners, and that notification carries the same generated portrait.

Content You Add to the Map

The Explore map is a shared, community surface. Businesses, events, and posts you add to the map are user-generated content visible to every other signed-in user, together with the coordinates you place them at. A business, event or post pin records the account that created it, but your display name and profile photo are NOT published with it: other users see an anonymous avatar and the date the item was posted. When you add an event, we also send a notification carrying its title to users whose claimed territory is near the place you pinned. Claimed territory is the exception, and the sentence above does not describe it. When you claim ground in Walk & Conquer, that ground is marked on the shared map with the AI-generated portrait of the pet you walked with, so any signed-in user who opens the map sees that portrait on your territory; for older claims that did not record which pet was on the walk, your first pet's portrait is used. Only the generated portrait is published: the real photo you uploaded for that pet is never used here, and your display name and profile photo are still not shown. The same generated portrait is attached to the notification sent to the owners of any territory your claim overlaps. Portraits are served over links that expire within hours and are re-issued each time the map is loaded, and a claim whose owner has no pet with a generated portrait is not shown on the map at all. Contact details on a business listing are published, not merely stored. A listing can carry a phone number, a WhatsApp number, an email address, a website, and handles for Instagram, Facebook, TikTok, X, YouTube and Telegram. Everything you enter there is shown to everyone who opens that pin, and can be tapped to call, message or open the linked profile. Where a "business" is one person, for example a solo trainer or a home groomer, those details are that person's personal data. Only publish contact details you are entitled to publish and are willing to make public. Photos and video are published too. A post can carry up to 4 attachments, each either a photo or a video clip of up to 15 seconds; a business listing can carry up to 6 photos, stills only. This media is uploaded to our cloud storage and served to other users over time-limited signed links. Do not upload images of identifiable people without their agreement to appear on a public map. Map content, and the photos and video attached to it, is retained until you delete the item or your account. All map content is moderated. Any user can report a business, event or post, and can block its author. Once an item has been reported by 3 different users it is hidden from the map automatically, pending review, and our administrators can take an item down or restore it; reports and moderation decisions are recorded in our audit log. Do not add private addresses or anything you do not want to be public. You can edit or delete content you created at any time, and we may remove content that breaches our community guidelines (see the Terms of Service).

Usage Data

We collect information about how you use the Service: • Session data (timestamps, duration, feature usage) • Device information (device type, OS version, browser type) • Performance metrics (errors, load times, API response times) • Feature interactions (camera usage, uploads, analysis requests) • Credit usage and balance This data helps us improve the Service and understand user behavior patterns.

AI Analysis Data

When you request behavioral analysis, we store: • Behavioral analysis results (detected behaviors, confidence scores) • AI-generated captions and interpretations • Detection metadata (species, breed, color) • Timestamps and session information • Analysis history for your account This data is stored in Firestore under your account, and no other user of the Service can see it. It is not accessible to you alone: our staff can open any memory together with its stored analysis, saved video and thumbnail, and can list memories across accounts, in order to answer a support request, investigate a report of abuse, or diagnose a fault. That is possible only through our internal operations console and only from an account we have granted administrator rights; an ordinary account cannot reach it. Actions an administrator takes, such as hiding or restoring reported content, replying to a support thread, changing an account, or opening a diagnostics session replay, are written to an internal audit log recording who acted, on what, and when. Every time an administrator lists memories across accounts or opens one to read it is also written to that audit log. We do not sell this data and we do not use it for advertising.

Notifications and Your Notification History

Push notifications are OFF by default. Nothing is sent to your device until you switch them on in Settings and your operating system grants the permission. Only then does the app upload the push token issued by Apple (APNs) or Google (Firebase Cloud Messaging), and we store it in a device registry keyed by a hash of that token, together with your account id, the platform that issued it, and when it was first recorded and last refreshed. The token addresses one installation of the app on one device; it is what makes delivery possible and it is not used for anything else. We remove it when you switch notifications off, when you sign out, when the platform replaces it with a new one, and when Apple or Google tell us it is permanently invalid. Your notification history is separate from that, and we record it whether or not notifications are switched on. Every notification is written to your account's notification list before it is delivered, and that list is what the bell in the app shows you. An app cannot read back your phone's own notification centre, so this record is the only copy that exists. Each entry holds the title, the message text, a short routing payload that tells the app which screen to open (for example support, territory, event, subscription or broadcast), the time it was created, and an expiry stamp. An image attached to a notification, such as the pet portrait on a territory alert, is not kept in the entry. We also store a single last-read timestamp for your account, so the app knows what is new. Because recording does not depend on delivery, someone who has never switched notifications on still accumulates this history and can read it in the app. What it contains is what happens on your account: a reply from our support team, stored with the first 120 characters of what the administrator wrote; someone claiming map ground that overlaps your territory; an event pinned near it; and changes to your subscription, including a renewal, a lapse and a failed payment. Announcements addressed to everyone are stored once rather than copied into each account, and every signed-in user reads that same entry. Administrators have a feed of their own, and one thing in it is about you: when an account is created we record an entry naming it by display name, or by a partially masked email address when there is no display name, together with the account's internal id. Every administrator can read that entry. We also keep a short registry of which accounts hold administrator rights, so we know who to alert; it holds nothing about anyone else. Each entry is stamped to expire 90 days after it was created, and Firestore automatically deletes it after that date. Switching notifications off stops delivery and removes your token, but it does not erase the history already recorded. Deleting your account automatically removes the device registry entries and your notification list, including its individual entries. You can also ask us to clear your notification history at any time at team@pawfect.fwiend.app.

2. How We Use Your Information

We use your information to: • Provide and improve the Service • Process your videos and generate behavioral insights using Mistral AI (our behavioural analysis engine) • Store your session history, memories, and analysis results • Communicate with you about the Service (via email) • Analyze usage patterns to improve AI models and detection accuracy • Ensure security and prevent abuse • Comply with legal obligations • Troubleshoot technical issues We do NOT sell your data to third parties.

3. Data Processing

We process your data only to run the Service: to detect pets in your videos, generate behavioural analysis and captions, maintain your account, pets and memories, and handle payments. Some of this processing is performed by third-party providers acting on our behalf (see "Third-Party Services" below), and some may take place outside your country (see "International Data Transfers" below). All data is encrypted in transit and at rest. On supported native camera paths, human faces visible in a frame can be blurred on your device using react-native-vision-camera CameraObjectOutput before transmission; server-side face blur is a separate defence-in-depth layer before storage.

4. AI Detection Limitations

Our pet detection system uses a pet-detection model with a confidence threshold. Some videos may be rejected if: • The pet is too small or far from camera • The pet is partially obscured or hidden • Poor lighting or low video quality • Unusual angles or positions • Non-standard pet breeds or mixed breeds This is a technical limitation of machine learning, not a service restriction. We are continuously improving detection accuracy through model updates. AI-generated content: pet portraits and captions produced by the Service are generated by AI and may be inaccurate or imaginative; they are labelled as AI-generated in the app.

5. Credit System

Video analysis consumes credits from your account: • Each video analysis costs 1 credit • Credits do not expire, and each billing cycle tops your balance up to your tier's allowance rather than resetting it • Unused credits are non-refundable • Refunds follow app store policies (Apple App Store or Google Play Store) • You can view your credit balance in Settings • Failed analyses due to technical errors are refunded automatically • No refunds for videos where no pet is detected (technical limitation)

6. Data Storage and Security

Your data is stored securely using industry-standard encryption: • Database: Firestore, with server-side security rules - Through our API your documents are readable by you, and by our administrators for support and abuse review (see AI Analysis Data above) - Encryption at rest with Google-managed keys - Automatic backups and disaster recovery • Storage: Firebase Cloud Storage, private and encrypted buckets - All files encrypted with AES-256 - Files are served over links that expire within hours and are re-issued on demand - Automatic cleanup of temporary files • Authentication: Firebase Authentication (Google), with Google and Apple sign-in - Session tokens with automatic expiration - The long-lived credential that keeps you signed in is stored only as a SHA-256 hash • API: HTTPS encryption for all data transmission - TLS 1.2+ for all connections - Administrative endpoints require an administrator claim on the session token We apply strict access controls and never share your data with unauthorized parties. Other users of the Service cannot see your uploaded content or your session history; our administrators can, for support and abuse review, as described above.

7. Third-Party Services

Mistral AI (primary LLM)

Video frames selected for behavioural analysis are sent to Mistral AI (Paris, France) via their Small 4 model (mistral-small-latest): • Frames are transmitted over HTTPS • Mistral returns the structured analysis to our behaviour-analysis service, which runs on serverless GPU infrastructure provided by Modal in the United States, for users in every region including the EU • Mistral does not retain frames for model training under their default API terms • Mistral's privacy policy applies: https://mistral.ai/privacy On supported native camera paths, human faces visible in a frame can be blurred on your device using react-native-vision-camera CameraObjectOutput before transmission; server-side face blur is a separate defence-in-depth layer before storage.

Google Gemini (optional image generation)

Google Gemini (Google LLC) is not our behavioural analysis engine. It is used only for an optional pet-image-generation feature, brokered server-side: when you explicitly request a generated image, the request is sent to Gemini. Gemini is not used for behavioural analysis, and frames are not shared with Gemini during analysis. Google's privacy policy applies: https://policies.google.com/privacy

Firebase Services (Google)

Our identity, database and storage layer is Firebase (Google): • Firebase Authentication: manages Google and Apple OAuth sign-in • Firestore: stores user profiles, pets, memories, credits, subscriptions, and an internal ai-credit-ledger used for billing accuracy • Firebase Cloud Storage: stores uploaded videos until analysis completes Google's privacy policy applies: https://policies.google.com/privacy

Google Crashlytics (native crash diagnostics)

On the iOS and Android apps only, we use Firebase Crashlytics (Google) to capture native crash and error diagnostics so we can fix stability problems: • Crash reporting is OFF by default and runs only after you opt in under Settings, Data & Privacy • Reports carry a random anonymous identifier, the app version, and a short trail of non-personal breadcrumbs (screen views, taps, network status), never your name, email, or anything you type • We do not attach your account identity to crash reports • Turning the setting off stops collection immediately and deletes any unsent reports on your device Google's privacy policy applies: https://policies.google.com/privacy

Apple App Store (iOS payments)

iOS subscriptions are billed by Apple through the standard In-App Purchase flow. Apple handles all payment data.

Google Play (Android payments)

Android subscriptions are billed by Google through Google Play Billing. Google handles all payment data. These platform in-app purchases (Apple on iOS, Google Play on Android) are the ONLY payment channels; we do not process card payments ourselves.

Infrastructure Sub-processors and Data Locations

We rely on the following sub-processors, each acting on our behalf under a data-processing agreement: • Mistral AI (France, EU): per-frame behavioural analysis (Vision AI) • Google Firebase and Google Cloud (EU and US regions): authentication, Firestore database, file storage, and serverless functions • Modal (United States): the serverless GPU that runs the behaviour-analysis engine for users in every region, including the EU • Hostinger (European Union): the virtual private server hosting our authentication gateway and website Camera frames sent for behavioural analysis are processed on servers in the United States, for all users including those in the EU. This transfer relies on the Standard Contractual Clauses (SCCs) under Article 46 GDPR agreed with that processor, the same safeguard that covers our other United States sub-processors. See International Data Transfers below for the safeguards that apply when data is processed outside your country.

8. Data Retention

We retain your data as follows: • Account Data: Retained as long as your account is active • Video Content: Retained as long as your account is active • Analysis Results: Retained as long as your account is active • Temporary Files: Automatically deleted after 30 days • Deleted Content: Permanently removed within 30 days • Notification History: automatically deleted 90 days after each entry is created • Push Notification Token: kept only while notifications are switched on for a device • Support Email Correspondence: retained for up to 12 months after the last message, unless we need it longer to establish, exercise or defend legal claims • Camera-session diagnostics: if you submit a bug report or a camera session is flagged for review, a short clip may be retained for up to 14 days for diagnostics and abuse review, then automatically deleted. Face-blur controls are applied when available but are not guaranteed if disabled or if a model is unavailable. The clip is used only to reproduce and fix issues, never for advertising or profiling; you may request deletion at any time (GDPR Article 17 right to erasure) You can delete individual sessions or your entire account at any time from the Settings page. Deleting your account takes effect immediately: the erasure cascade runs while the request is being handled, and it cannot be undone. Deleted content leaves your account at once and is purged from our systems within 30 days.

9. Your Rights

You have the right to: • Access: view all data we hold about you • Export (data portability): download a machine-readable copy of your data (GDPR Article 20) • Delete (erasure): permanently remove your data and account (GDPR Article 17) • Rectification: update inaccurate information • Object: opt out of certain data processing • Withdraw consent: revoke permissions at any time How to exercise these rights: • Web: sign in at pawfect.fwiend.app/account/profile. The Privacy and data section has Export my data and Delete my account buttons. Export downloads a JSON bundle of everything we hold. Delete cascades through pets, memories, credits, subscription, user profile, and Firebase Auth account, then signs you out. • iOS app: open Settings. Download data and Delete account rows call the same server endpoints. • Email: team@pawfect.fwiend.app for any request the in-app buttons cannot fulfil. Export and deletion are processed immediately. Deletion cannot be undone.

10. Children's Privacy

The Service is not intended for children under 13. We do not knowingly collect information from children under 13. If you believe a child has provided us with personal information, please contact us immediately at team@pawfect.fwiend.app. For users aged 13-18, parental consent may be required depending on your jurisdiction.

11. International Data Transfers

Your data may be transferred to and processed in countries other than your own, including the United States. We ensure appropriate safeguards are in place to protect your data: • Standard Contractual Clauses (SCCs) for EU data transfers • Encryption in transit and at rest • Access controls and monitoring • Regular security audits By using the Service, you consent to the transfer of your data to countries outside your country of residence.

12. Security Measures

We implement comprehensive security measures: • Encryption: All data encrypted in transit (HTTPS) and at rest (AES-256) • Access Controls: Row Level Security (RLS) policies in Firestore • Authentication: Firebase Authentication with OAuth 2.0 • Monitoring: Automated security monitoring and alerting • Audits: Regular security audits and penetration testing • Incident Response: 24/7 incident response team If we discover a security breach, we will notify affected users within 72 hours as required by law.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via: • Email notification • In-app notification • Website banner Continued use of the Service after changes constitutes acceptance of the updated Privacy Policy. We recommend reviewing this policy periodically for updates.

14. Contact Us

For privacy questions or concerns, contact us at: Email: team@pawfect.fwiend.app Data Protection Officer: team@pawfect.fwiend.app Mailing Address: Sam Houston Labs Ltd, 2nd Floor College House, 17 King Edwards Road, Ruislip, London, HA4 7AE, United Kingdom

15. GDPR Compliance (EU Users)

If you are in the European Union, you have additional rights under GDPR: • Right to data portability: Export your data in machine-readable format • Right to restrict processing: Limit how we use your data • Right to object: Object to automated decision-making • Right to erasure: Delete your data (right to be forgotten) • Right to lodge a complaint: Contact your local data protection authority Our legal basis for processing your data: • Consent: You consent to the Service terms • Contract: Processing is necessary to provide the Service • Legitimate Interest: Improving the Service and preventing abuse • Legal Obligation: Complying with applicable laws Our Data Protection Officer: team@pawfect.fwiend.app

16. Texas Privacy Rights (Texas Users)

If you are a Texas resident, you have rights under the Texas Data Privacy and Security Act (TDPSA): • Right to Confirm and Access: Confirm whether we are processing your personal data and access that data • Right to Correct: Correct inaccuracies in your personal data • Right to Delete: Request deletion of personal data provided by or obtained about you • Right to Data Portability: Obtain a copy of your personal data in a portable and readily usable format • Right to Opt Out: Opt out of processing your personal data for targeted advertising, the sale of personal data, or profiling that produces legal or similarly significant effects • Right to Non-Discrimination: We do not discriminate against you for exercising your rights To exercise these rights, contact us at team@pawfect.fwiend.app. We will respond without undue delay and no later than 45 days after receiving your request; we may extend this period once by an additional 45 days when reasonably necessary, in which case we will notify you within the initial period. Appeals: If we decline to act on your request, you may appeal our decision by contacting team@pawfect.fwiend.app. We will inform you in writing of any action taken or not taken in response, along with a written explanation. If your appeal is denied, you may contact the Texas Attorney General to submit a complaint. Universal opt-out: We honor recognized universal opt-out preference signals (such as Global Privacy Control) for targeted advertising and the sale of personal data. Note: We do NOT sell your personal data to third parties.

17. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA/CPRA): • Right to Know: Request what personal information we collect, use, disclose, and sell • Right to Delete: Request deletion of your personal information • Right to Opt-Out: Opt out of the sale or sharing of your personal information • Right to Non-Discrimination: We do not discriminate against you for exercising your rights • Right to Correct: Request correction of inaccurate personal information • Right to Limit Use of Sensitive Personal Information: Limit our use of sensitive personal information To exercise these rights, contact us at team@pawfect.fwiend.app. Note: We do NOT sell your personal information to third parties.

2nd Floor College House
17 King Edwards Road
Ruislip, London, HA4 7AE
United Kingdom
Sam Houston Labs Ltd
Sam Houston
Labs Ltd