Skip to content
Pawfect Fwiend

Privacy Policy

Last Updated: Last Updated: July 22, 2026

1. Information We Collect

Account Information

When you create an account, we collect: • Email address (via Google OAuth) • Display name (from your profile) • Phone number (optional) • Profile photo (optional) • Authentication credentials (managed by Firebase Authentication) We use Google OAuth for secure authentication. Your password is never stored by us-it is managed entirely by Google.

Content You Upload

Videos and images you upload are stored securely in Firebase Cloud Storage. This content is used to: • Provide AI-powered behavioral analysis • Generate behavioral insights and captions • Store your analysis history and memories • Improve our AI models (with your consent) You retain full ownership of all uploaded content.

Camera and Microphone Access

The live camera feature requires camera permission to capture video. We: • Do NOT record or store full live camera sessions unless you explicitly save them (a limited, short-retention diagnostics exception is described below) • Use microphone access during live analysis to derive a few on-device acoustic cues (such as ambient sound level and pitch); only these numeric cues are streamed to our analysis engine, never the raw audio waveform, and audio in any session you save is anonymised on your device when biometric anonymity is enabled • Process video frames locally in your browser using on-device models (face blur and framing run on your device; no data is sent to servers during local detection) • Only send frames to our behavioural analysis engine (Mistral AI) when you request analysis • Blur human faces a second time on our servers, on by default, on every frame before anything is stored (this server-side blur is independent of the on-device Biometric anonymity setting) • Diagnostics exception: when enabled, we may retain a low-frequency sequence of already-face-blurred still frames from a live session on our servers for up to 14 days, solely for product diagnostics and abuse review, accessible only to our administrators, after which they are automatically deleted; this footage is covered by your erasure rights Camera access is only active while you are using the camera feature.

Location Information

Some features use your device's precise location, and only while you are actively using them: • Walk & Conquer game: while a game session is running in the foreground, we use your precise GPS location to track your route and award map territory. Location is collected only during active play, only while the app is in the foreground, and stops the moment you leave the game. • Explore map: we use your location to centre the map on you and show nearby pins. Location access is consent-gated: you grant the operating-system permission first, and you can revoke it at any time in your device settings. We do NOT track your location in the background. Route and territory data you create in Walk & Conquer is stored with your account so your progress persists; you can delete it by removing the associated map content or your account.

Content You Add to the Map

The Explore map is a shared, community surface. Businesses, events, and posts you add to the map are user-generated content visible to other users, together with the coordinates you place them at and the display name on your profile. Do not add private addresses or anything you do not want to be public. You can edit or delete content you created at any time, you can report or block content added by others, and we may remove content that breaches our community guidelines (see the Terms of Service).

Usage Data

We collect information about how you use the Service: • Session data (timestamps, duration, feature usage) • Device information (device type, OS version, browser type) • Performance metrics (errors, load times, API response times) • Feature interactions (camera usage, uploads, analysis requests) • Credit usage and balance This data helps us improve the Service and understand user behavior patterns.

AI Analysis Data

When you request behavioral analysis, we store: • Behavioral analysis results (detected behaviors, confidence scores) • AI-generated captions and interpretations • Detection metadata (species, breed, color) • Timestamps and session information • Analysis history for your account This data is stored in Firestore and is only accessible to you.

2. How We Use Your Information

We use your information to: • Provide and improve the Service • Process your videos and generate behavioral insights using Mistral AI (our behavioural analysis engine) • Store your session history, memories, and analysis results • Communicate with you about the Service (via email) • Analyze usage patterns to improve AI models and detection accuracy • Ensure security and prevent abuse • Comply with legal obligations • Troubleshoot technical issues We do NOT sell your data to third parties.

3. Data Processing

We process your data only to run the Service: to detect pets in your videos, generate behavioural analysis and captions, maintain your account, pets and memories, and handle payments. Some of this processing is performed by third-party providers acting on our behalf (see "Third-Party Services" below), and some may take place outside your country (see "International Data Transfers" below). All data is encrypted in transit and at rest. Human faces are blurred on your device during live preview, and blurred again on our servers (on by default) on every frame before any frame is stored.

4. AI Detection Limitations

Our pet detection system uses an on-device pet-detection model with a confidence threshold. Some videos may be rejected if: • The pet is too small or far from camera • The pet is partially obscured or hidden • Poor lighting or low video quality • Unusual angles or positions • Non-standard pet breeds or mixed breeds This is a technical limitation of machine learning, not a service restriction. We are continuously improving detection accuracy through model updates. AI-generated content: pet portraits and captions produced by the Service are generated by AI and may be inaccurate or imaginative; they are labelled as AI-generated in the app.

5. Credit System

Video analysis consumes credits from your account: • Each video analysis costs 1 credit • Credits do not expire • Unused credits are non-refundable • Refunds follow app store policies (Apple App Store or Google Play Store) • You can view your credit balance in Settings • Failed analyses due to technical errors are refunded automatically • No refunds for videos where no pet is detected (technical limitation)

6. Data Storage and Security

Your data is stored securely using industry-standard encryption: • Database: Firestore with Row Level Security (RLS) policies - Only you can access your data - Encryption at rest with Google-managed keys - Automatic backups and disaster recovery • Storage: Firebase Cloud Storage with encrypted buckets - All files encrypted with AES-256 - Access controlled by RLS policies - Automatic cleanup of temporary files • Authentication: Firebase Authentication with Google OAuth - No passwords stored by us - Session tokens with automatic expiration - Multi-factor authentication support • API: HTTPS encryption for all data transmission - TLS 1.2+ for all connections - Certificate pinning for mobile apps - Regular security audits Only you can access your uploaded content and session history. We implement strict access controls and never share your data with unauthorized parties.

7. Third-Party Services

Mistral AI (primary LLM)

Video frames selected for behavioural analysis are sent to Mistral AI (Paris, France) via their Small 4 model (mistral-small-latest): • Frames are transmitted over HTTPS • Mistral returns the structured analysis to our behaviour-analysis service, which runs on serverless GPU infrastructure (Modal in the United States, and a RunPod EU-resident GPU for users in the EU) • Mistral does not retain frames for model training under their default API terms • Mistral's privacy policy applies: https://mistral.ai/privacy Human faces visible in a frame are locally blurred on your device (MediaPipe BlazeFace) before transmission.

Google Gemini (optional image generation)

Google Gemini (Google LLC) is not our behavioural analysis engine. It is used only for an optional pet-image-generation feature, brokered server-side: when you explicitly request a generated image, the request is sent to Gemini. Gemini is not used for behavioural analysis, and frames are not shared with Gemini during analysis. Google's privacy policy applies: https://policies.google.com/privacy

Firebase Services (Google)

Our identity, database and storage layer is Firebase (Google): • Firebase Authentication: manages Google and Apple OAuth sign-in • Firestore: stores user profiles, pets, memories, credits, subscriptions, and an internal ai-credit-ledger used for billing accuracy • Firebase Cloud Storage: stores uploaded videos until analysis completes Google's privacy policy applies: https://policies.google.com/privacy

Google Crashlytics (native crash diagnostics)

On the iOS and Android apps only, we use Firebase Crashlytics (Google) to capture native crash and error diagnostics so we can fix stability problems: • Crash reporting is OFF by default and runs only after you opt in under Settings, Data & Privacy • Reports carry a random anonymous identifier, the app version, and a short trail of non-personal breadcrumbs (screen views, taps, network status), never your name, email, or anything you type • We do not attach your account identity to crash reports • Turning the setting off stops collection immediately and deletes any unsent reports on your device Google's privacy policy applies: https://policies.google.com/privacy

Apple App Store (iOS payments)

iOS subscriptions are billed by Apple through the standard In-App Purchase flow. Apple handles all payment data.

Google Play (Android payments)

Android subscriptions are billed by Google through Google Play Billing. Google handles all payment data. These platform in-app purchases (Apple on iOS, Google Play on Android) are the ONLY payment channels; we do not process card payments ourselves.

Infrastructure Sub-processors and Data Locations

We rely on the following sub-processors, each acting on our behalf under a data-processing agreement: • Mistral AI (France, EU): per-frame behavioural analysis (Vision AI) • Google Firebase and Google Cloud (EU and US regions): authentication, Firestore database, file storage, and serverless functions • Modal (United States): the serverless GPU that runs the behaviour-analysis engine for users outside the EU • RunPod (EU-resident GPU, European Union): the same engine for users in the EU, so EU camera data is processed on EU-resident infrastructure and does not transit to the United States • Hostinger (European Union): the virtual private server hosting our authentication gateway and website • Codemagic (European Union): our build and continuous-integration pipeline, which handles no end-user personal data EU users' live analysis is routed to the EU-resident GPU. See International Data Transfers below for the safeguards that apply when data is processed outside your country.

8. Data Retention

We retain your data as follows: • Account Data: Retained as long as your account is active • Video Content: Retained as long as your account is active • Analysis Results: Retained as long as your account is active • Temporary Files: Automatically deleted after 30 days • Deleted Content: Permanently removed within 30 days • Diagnostics camera-session footage: If you submit a bug report or a camera session is flagged for review, a short clip of that session, with human faces automatically blurred, may be retained for up to 14 days for diagnostics and abuse review, then automatically deleted. It is used only to reproduce and fix problems, never for advertising or profiling; you can request its deletion at any time (right to erasure, GDPR Article 17) You can delete individual sessions or your entire account at any time from the Settings page. When you delete content or your account, it is permanently removed from our systems within 30 days.

9. Your Rights

You have the right to: • Access: view all data we hold about you • Export (data portability): download a machine-readable copy of your data (GDPR Article 20) • Delete (erasure): permanently remove your data and account (GDPR Article 17) • Rectification: update inaccurate information • Object: opt out of certain data processing • Withdraw consent: revoke permissions at any time How to exercise these rights: • Web: sign in at pawfect.fwiend.app/account/profile. The Privacy and data section has Export my data and Delete my account buttons. Export downloads a JSON bundle of everything we hold. Delete cascades through pets, memories, credits, subscription, user profile, and Firebase Auth account, then signs you out. • iOS and PWA: open Settings inside the app. Download data and Delete account rows call the same server endpoints. • Email: team@samhoustonlabs.com for any request the in-app buttons cannot fulfil. Export and deletion are processed immediately by our Rust user-auth service. Deletion cannot be undone.

10. Children's Privacy

The Service is not intended for children under 13. We do not knowingly collect information from children under 13. If you believe a child has provided us with personal information, please contact us immediately at team@samhoustonlabs.com. For users aged 13-18, parental consent may be required depending on your jurisdiction.

11. International Data Transfers

Your data may be transferred to and processed in countries other than your own, including the United States. We ensure appropriate safeguards are in place to protect your data: • Standard Contractual Clauses (SCCs) for EU data transfers • Encryption in transit and at rest • Access controls and monitoring • Regular security audits By using the Service, you consent to the transfer of your data to countries outside your country of residence.

12. Security Measures

We implement comprehensive security measures: • Encryption: All data encrypted in transit (HTTPS) and at rest (AES-256) • Access Controls: Row Level Security (RLS) policies in Firestore • Authentication: Firebase Authentication with OAuth 2.0 • Monitoring: Automated security monitoring and alerting • Audits: Regular security audits and penetration testing • Incident Response: 24/7 incident response team If we discover a security breach, we will notify affected users within 72 hours as required by law.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via: • Email notification • In-app notification • Website banner Continued use of the Service after changes constitutes acceptance of the updated Privacy Policy. We recommend reviewing this policy periodically for updates.

14. Contact Us

For privacy questions or concerns, contact us at: Email: team@samhoustonlabs.com Data Protection Officer: team@samhoustonlabs.com Mailing Address: Sam Houston Labs Ltd, 2nd Floor College House, 17 King Edwards Road, Ruislip, London, HA4 7AE, United Kingdom

15. GDPR Compliance (EU Users)

If you are in the European Union, you have additional rights under GDPR: • Right to data portability: Export your data in machine-readable format • Right to restrict processing: Limit how we use your data • Right to object: Object to automated decision-making • Right to erasure: Delete your data (right to be forgotten) • Right to lodge a complaint: Contact your local data protection authority Our legal basis for processing your data: • Consent: You consent to the Service terms • Contract: Processing is necessary to provide the Service • Legitimate Interest: Improving the Service and preventing abuse • Legal Obligation: Complying with applicable laws Our Data Protection Officer: team@samhoustonlabs.com

16. Texas Privacy Rights (Texas Users)

If you are a Texas resident, you have rights under the Texas Data Privacy and Security Act (TDPSA): • Right to Confirm and Access: Confirm whether we are processing your personal data and access that data • Right to Correct: Correct inaccuracies in your personal data • Right to Delete: Request deletion of personal data provided by or obtained about you • Right to Data Portability: Obtain a copy of your personal data in a portable and readily usable format • Right to Opt Out: Opt out of processing your personal data for targeted advertising, the sale of personal data, or profiling that produces legal or similarly significant effects • Right to Non-Discrimination: We do not discriminate against you for exercising your rights To exercise these rights, contact us at team@samhoustonlabs.com. We will respond without undue delay and no later than 45 days after receiving your request; we may extend this period once by an additional 45 days when reasonably necessary, in which case we will notify you within the initial period. Appeals: If we decline to act on your request, you may appeal our decision by contacting team@samhoustonlabs.com. We will inform you in writing of any action taken or not taken in response, along with a written explanation. If your appeal is denied, you may contact the Texas Attorney General to submit a complaint. Universal opt-out: We honor recognized universal opt-out preference signals (such as Global Privacy Control) for targeted advertising and the sale of personal data. Note: We do NOT sell your personal data to third parties.

17. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA/CPRA): • Right to Know: Request what personal information we collect, use, disclose, and sell • Right to Delete: Request deletion of your personal information • Right to Opt-Out: Opt out of the sale or sharing of your personal information • Right to Non-Discrimination: We do not discriminate against you for exercising your rights • Right to Correct: Request correction of inaccurate personal information • Right to Limit Use of Sensitive Personal Information: Limit our use of sensitive personal information To exercise these rights, contact us at team@samhoustonlabs.com. Note: We do NOT sell your personal information to third parties.

Sam Houston Labs Ltd
Sam Houston
Labs Ltd

2nd Floor College House, 17 King Edwards Road, Ruislip, London, HA4 7AE, United Kingdom