Privacy Policy
This privacy policy describes how Pupnik (“we”) collects, uses, and shares information about you when you use the Pupnik app and website. It mirrors the data practices declared on the App Store privacy questionnaire — if anything in this document conflicts with that questionnaire, treat the more restrictive statement as controlling.
Information we collect and access
- Account information. Your email address and the account or authentication identifiers needed to provide and secure your account, and to contact you about the service.
- Device and notification information. When you enable notifications, we store your Apple Push Notification service (APNs) device token and device time-zone identifier with your account so we can deliver Pupnik notifications at an appropriate local time. We do not use these identifiers for advertising or cross-app tracking.
- Dog profile and walk data. Your dog's name, breed, photo, and GPS-tracked walk routes. Walks are stored as a sequence of GPS points associated with your account.
- Home location. A single coordinate you set during onboarding so the map can center where you live. We never publish this coordinate. When you appear on the neighborhood leaderboard, only a ±500-meter blurred coordinate derived server-side is shared.
- Photos you choose to capture. Profile photos and optional walk-memory photos. These are stored in access-controlled object storage. They are not placed on a global public feed by default, but visibility inside social features and shared links follows the choices and feature rules described below.
- Community content and safety reports. Dog names, profile photos, bios, likes, Pack activity, and other content that can be visible to other Pupnik users. When content is reported, we collect the report reason, optional details, and the limited content context needed to investigate, prevent abuse, and enforce our Terms. Before we send a submitted social photo or profile text to OpenAI's moderation service for a safety decision, we show the owner a clear in-app explanation and obtain their explicit permission. For a shared dog, only its primary owner can make that community-sharing choice. We do not send Apple Health data, location history, payment information, or unrelated account data to that service for this purpose.
- Apple Health data we access on-device (only if you opt in). If you choose to connect Apple Health and grant permission, Pupnik can write an outdoor walking workout and its measured walking distance to Apple Health. It can also read step count locally on your device. Pupnik does not write a workout route or Active Energy to Apple Health, send HealthKit data to the Pupnik backend as part of this integration, or use it for advertising, marketing, or use-based data mining.
- Diagnostic data. Crash reports (Sentry) and product-usage events (PostHog) — distance walked, collectibles found, paywall views. Used to fix bugs and improve the app. Never sold.
- Purchase data. An account identifier and Apple-managed subscription receipt or entitlement status (via RevenueCat), used to grant and restore access to Pupnik+ features and measure subscription purchases and renewals. We do not send your dog level, Pack size, streak, walk milestones, or PostHog identifier to RevenueCat.
- Paywall testing. We use Superwall to present and compare Pupnik+ subscription screens. Superwall receives your account identifier, subscription status, paywall views and actions, experiment assignment, and technical app/device information, including the iOS identifier for vendor, time-zone offset, and general region derived from your IP address. RevenueCat also forwards subscription events and revenue with customer identifiers and available customer attributes to Superwall so we can measure which paywalls work. Pupnik does not send dog names, dog progress, photos, precise location, or Apple Health data to Superwall as paywall parameters.
How sharing works
- Shared dogs. If a dog has a co-owner, that co-owner can access the data associated with the shared dog in Pupnik. This lets co-owners care for the same dog and participate in its walks, progress, and related features together. The dog's primary owner controls choices that newly share that dog with the community, including Community safety screening. A co-owner can continue private care, turn off existing social visibility, or leave a Pack.
- In-app community features. When you use Pack, Dogdex, discovery, leaderboard, or follow features, the dog profile information selected for those surfaces — such as a dog's name, photo, bio, likes, broad progress, or Pack activity — may be visible to eligible viewers under that feature's rules (for example, a co-owner, Packmate, follower, nearby viewer, or Dogdex connection). Exact walk routes, home location, and real-time location are not shared through these features.
- Public dog profiles and shared links. Public dog profiles are not enabled by default. If a dog's primary owner enables a public dog profile or explicitly creates a share link, the owner-selected dog photo and selected dog-profile information may be visible to people who receive or visit that profile or link.
Community safety and moderation
You can report a dog profile or other community content in the app, and you can block an owner from a profile menu. People who only have a public Pupnik link can use our public reporting page. Authorized support and moderation personnel may review the report and relevant content context. After a dog's primary owner explicitly permits Community safety screening, OpenAI receives only submitted social text or an uploaded social image to screen it; Pupnik stores the resulting safety decision and limited audit metadata, not a second copy of that content in the moderation record. We may hide or remove content from a surface, limit visibility, or restrict an account when needed to enforce our Terms or protect the community. Reporting, blocking, and pre-publication screening are important safety controls; we do not promise that every concern will be identified before it is visible.
What we do not do
- We do not sell or rent your data.
- We do not share your real-time or precise location with other users, advertisers, or data brokers.
- We do not use Apple's App Tracking Transparency identifier (IDFA), and v1 does not include an install-attribution SDK.
- We do not sell your photos. They are not globally public by default, but authorized co-owners and eligible people in the social or sharing surfaces you use may be able to see the applicable shared content.
Our website
pupnik.app uses cookieless Vercel Web Analytics to count page views and see which pages bring visitors. We also use Google Analytics 4 (GA4) to measure page views, referring sites, browser and device information, approximate location, use of our walk tools, and clicks to the App Store. GA4 uses first-party cookies such as _ga when analytics storage is allowed. App Store links may carry a campaign label describing the page you tapped from, not you. We do not send your precise location, weather values, or free text to GA4 from the walk tools.
We set GA4's event and user data retention to 14 months. Google processes the data for us. In the European Economic Area, the UK, and Switzerland, we ask whether you want to allow analytics cookies before storing them. You can change your choice below. You can also use Google's Analytics opt-out browser add-on.
The walk-weather tools ask for your location only when you tap “Check my weather now.” Your browser rounds it to roughly 10 km before sending it, and we use it only to fetch the current forecast from MET Norway. We don't store it or link it to you. You can always type in the weather instead.
Where the data lives
Account, walks, and photos: Supabase (United States region). Social-content safety screening: OpenAI (only the submitted social photo or text, after the dog's primary owner gives explicit permission). Crash reports: Sentry. App analytics: PostHog (United States). Website analytics: Google Analytics 4 and Vercel. Subscription receipts: RevenueCat. Map tiles: Mapbox. Paywall presentation and conversion analytics: Superwall. Push notifications: Apple APNs. Website hosting: Vercel. Weather for the website's walk tools: MET Norway.
We disclose only the information reasonably needed for a provider to deliver its service to Pupnik. We require providers that process personal data on our behalf to use it only to provide that service and to maintain appropriate privacy and security safeguards, except where applicable law requires otherwise. We do not permit providers to use your data for their independent advertising.
Your rights
- Delete your account. Open Pupnik → Home gear → Account & Privacy → Delete account. This removes the personal data associated with your account from our active production systems. If a dog is shared with a co-owner, the shared dog and its associated data may remain available to the surviving co-owner. We may retain limited information in backups or where reasonably necessary for security, fraud prevention, legal, or accounting purposes. If you used Sign in with Apple, deleting your Pupnik account does not currently automatically revoke your Sign in with Apple authorization; you can manage or remove Pupnik through your Apple Account's Sign in with Apple settings. Your Apple subscription is managed by Apple — to stop being billed, cancel separately in Settings → [Your Name] → Subscriptions.
- Export your data. Email support@pupnik.app with the email address tied to your account. We'll respond within 14 days with a JSON archive of your account, dog profile, walks, and inventory.
- Withdraw community-safety permission. Open Pupnik → Home gear → Account & Privacy → Community safety screening. For dogs for which you are the primary owner, withdrawing permission stops new OpenAI screening and removes their social profile and Pack content from community surfaces until you choose to give permission again. If you co-own a dog, you can turn off its current social visibility or leave a Pack, but you cannot enable community sharing or submit that dog's content for screening. Withdrawing permission does not delete private dog, walk, or memory data.
Children's privacy
Pupnik's community features are intended only for people who meet the minimum age required where they live (at least 13 in the United States). Pupnik is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has signed up, email support@pupnik.app and we will delete the account.
California, EU, and other regional rights
If you live in California, the EU, the UK, or another jurisdiction with specific privacy rights (right of access, right of deletion, right to data portability, right to object to processing), email support@pupnik.app with your request and the email address tied to your account. We will respond within 30 days, or sooner where required by law.
Retention
We retain account, dog, walk, and photo data while your account is active. When you delete your account, we remove its personal data from active production systems, subject to the shared-dog, backup, and legal or security exceptions described above. Crash-report data is retained for up to 90 days, product analytics for up to 7 years, and submitted feedback for up to 2 years. Apple and RevenueCat may retain purchase records under their own legal and operational requirements. Backup copies and limited records may persist for a limited period under our backup, recovery, security, and legal procedures. Anonymized aggregate analytics may persist beyond that period (for example, “number of walks completed by users in this region this week”), but are not tied back to you.
Contact
Privacy questions: support@pupnik.app.