1. Introduction
Welcome to Pawlog ("we", "our", "us"). Pawlog is a pet management application
developed and operated by Pawlog ("Developer"). This Privacy Policy
explains how we collect, use, disclose, and safeguard your information when you use
our mobile application (the "App") and any related services.
Core Privacy Principle: Pawlog is designed local-first. Your pet data β
names, health records, training logs, photos, medications, vet visits, and reminders β
is stored exclusively on your own device unless you explicitly choose to enable
cloud backup (Pro) or Google Drive backup.
Please read this policy carefully. By using the App, you agree to the collection and
use of information as described here. If you disagree, please do not use the App.
2. Data We Collect
2.1 Data You Provide Directly
- Pet profiles: name, species, photo, date of birth (optional).
- Health records: vaccinations, medications, vet visit notes, weight logs, food logs.
- Training data: session completions, training streaks, progress notes.
- Reminders: title, notes, date/time, recurrence settings.
- Activity logs: walks, grooming, behaviours β entered by you.
- Google account details (if you sign in for Pro or Google Drive backup):
name, email address, and Google profile photo β used solely for authentication and backup.
All data listed above is stored on your device only, unless you enable backup (see Β§6).
2.2 Data We Collect Automatically
- Crash reports (only if you grant consent): anonymous error logs
sent via Firebase Crashlytics. These logs contain stack traces, device model,
Android version, and app version β never pet data or personal information.
- Analytics events (only if you grant consent): screen navigation,
feature usage frequency, and session duration via Firebase Analytics.
No personal or pet data is included.
- Advertising identifiers (free-tier users only): Google's advertising
ID (GAID) may be used by Google AdMob to display relevant ads (see Β§8).
2.3 Data We Do NOT Collect
- We do not collect real names, addresses, phone numbers, or precise location data.
- We do not collect payment card data. In-app purchases are processed exclusively
by Google Play Billing; we receive only an anonymised purchase token.
- We do not collect biometric data.
- We do not sell, rent, or trade your personal data to third parties for marketing.
- We do not build advertising profiles using your pet data.
3. How We Use Your Data
| Purpose |
Data Used |
Stored Where |
| Provide core app functionality |
All pet & health data |
On-device only |
| AI Assistant (Pro) |
Your question + pet species/name (anonymised) |
Transmitted to AI provider; not stored |
| Encrypted backup (Pro) |
All pet data (AES-256-GCM encrypted) |
Cloudflare R2 (encrypted blob) |
| Google Drive backup (free) |
All pet data (JSON) |
Your personal Google Drive (appDataFolder) |
| Crash diagnostics (consent-gated) |
Stack trace, device info |
Firebase (Google) |
| Analytics (consent-gated) |
Feature usage, session events |
Firebase (Google) |
| Advertising (free users) |
Advertising ID (GAID), contextual signals |
Google AdMob |
4. Legal Basis for Processing (GDPR / UK GDPR)
For users in the European Economic Area (EEA), United Kingdom, and Switzerland:
- Contract performance (Art. 6(1)(b)): Providing the core app functionality
you have contracted for by downloading and using the App.
- Legitimate interests (Art. 6(1)(f)): Detecting and fixing crashes to
maintain a stable, safe app. We balance our interests against yours using a Legitimate
Interests Assessment (available on request).
- Consent (Art. 6(1)(a)): Analytics and crash reporting β you opt in
on first launch and can withdraw at any time in Settings.
- Legal obligation (Art. 6(1)(c)): Retaining transaction records to
comply with tax and accounting laws in applicable jurisdictions.
No special categories of data (Art. 9 GDPR) are processed. Health records you enter
concern your pet, not yourself; they are not personal health data as defined
under GDPR, HIPAA, or comparable laws.
5. Data Sharing & Third Parties
We share data only with the following categories of third parties, and only to the
extent necessary to provide the services you request:
5.1 Google LLC
- Firebase Analytics & Crashlytics β consent-gated usage statistics
and crash reports. Data is processed under Google's Privacy Policy
(policies.google.com/privacy).
Firebase Analytics is EU Standard Contractual Clauses (SCC) compliant.
- Google AdMob β serves ads to free-tier users. Subject to Google's
Advertising policies. You may opt out via Android's Ad ID settings.
- Google Sign-In β authenticates Pro users and Drive backup users.
We receive only a verified user ID token; passwords are never transmitted to us.
- Google Drive β stores your backup in your own Drive appDataFolder,
accessible only to Pawlog. We never read this data on our servers.
- Google Play Billing β processes in-app subscriptions.
We receive purchase tokens only; no payment card data.
5.2 Cloudflare Inc.
- Cloudflare Workers β our backend API for subscription verification,
AI routing, and Pro encrypted backup. Cloudflare processes only the encrypted blob
and your verified Google user ID (anonymised). Data is stored in Cloudflare R2
(object storage) in the EU or US depending on your region.
- Data is processed under Cloudflare's Data Processing Addendum (DPA), which is
GDPR-compliant and includes SCCs for international transfers.
5.3 AI Providers (Pro users only)
- When you use the AI Assistant, your question (plus a minimal pet context you
provide) is sent to an AI language model provider (currently Groq or OpenRouter).
Conversations are not stored on our servers beyond the request/response
cycle. Providers are bound by their own privacy policies and data processing agreements.
We do not transmit your pet's health records to AI providers.
5.4 Disclosure by Law
We may disclose your information if required to do so by law, a court order, or a
governmental authority, or where we believe disclosure is necessary to protect
our rights, protect your safety or the safety of others, investigate fraud, or
comply with a legal obligation.
We do not sell, rent, or trade your personal data to any third party for marketing.
6. Backups & Data Storage
6.1 On-Device Storage (All Users)
By default, all Pawlog data is stored only on your device using a local SQLite database
(Drift). No data leaves your device unless you explicitly enable backup.
6.2 Google Drive Backup (Free and Pro Users)
You may back up your data to your personal Google Drive account's
appDataFolder β a hidden, app-specific folder that:
- Is only accessible to the Pawlog app (not visible in Google Drive's UI).
- Is automatically deleted when you revoke Pawlog's access or uninstall the app.
- Is subject to your Google account's security and access controls.
- Is stored by Google in accordance with Google's Privacy Policy.
Backup data is transmitted over TLS 1.3. We do not access, read, or store the
contents of your Google Drive backup on our servers.
Your responsibility: Maintain the security of your Google account
(strong password, two-factor authentication). We cannot recover data lost due to
account compromise.
6.3 Pawlog Pro Encrypted Backup
Pro subscribers may use Pawlog's encrypted cloud backup:
- Encryption: Data is encrypted on your device using AES-256-GCM
before upload. Your encryption key is derived from your device credentials using HKDF.
The plaintext is never transmitted to or stored by our servers.
- Storage: Encrypted blobs are stored in Cloudflare R2 object storage.
Files are associated with your anonymised Google user ID only.
- Retention: Backup files are retained for up to 30 days after the
last write. If your Pro subscription lapses, backups are retained for a further 90
days before deletion.
- Deletion: You may delete your backup at any time using the
"Delete backup" option in the app. We will permanently delete all copies within 30 days.
- Access: Only you can decrypt and restore your backup.
We have zero access to the plaintext of your backup.
6.4 Data Transmission Security
All data transmitted between the App and our servers uses TLS 1.3. We enforce
HTTPS-only connections (cleartext traffic is disabled in the app's network configuration).
7. AI Assistant
The AI Assistant (available to Pro users) sends your text questions to an AI language
model. Important limitations and disclosures:
- Questions are sent over TLS to our Cloudflare Worker, which routes them to an
AI provider (Groq or compatible). Your questions are not stored by us.
- We do not include your pet's full health records in AI requests
unless you explicitly paste them into the conversation.
- The AI is not a substitute for professional veterinary advice.
Always consult a licensed veterinarian for health concerns.
- Do not include sensitive personal information (Social Security numbers, payment
card details, passwords) in AI conversations.
- AI providers may retain requests for abuse monitoring per their own policies.
Review Groq's privacy policy at
groq.com/privacy-policy.
- Rate limits apply: free users have no access; Pro users are limited to a daily
quota to prevent abuse.
8. Advertising (Google AdMob)
The free tier of Pawlog displays banner advertisements served by Google AdMob.
- AdMob may use your device's advertising ID (GAID) to personalise ads.
- You may reset or opt out of personalised ads in your Android device settings:
Settings β Privacy β Ads β Opt out of ads personalisation.
- In regions where consent is required (EEA, UK, Switzerland), we use the
Google User Messaging Platform (UMP) to obtain your consent before showing
personalised ads.
- Ad revenue supports continued free development of Pawlog. Upgrade to Pro
to remove all ads.
- We do not share your pet data with advertisers.
9. Children's Privacy (COPPA / Age Restrictions)
Pawlog is not directed at children under 13 years of age (or under 16 in the EEA).
We do not knowingly collect personal data from children under these ages.
If you are a parent or guardian and believe your child under 13 has provided us
with personal data, please contact us at the address in Β§16. We will promptly
delete such data from our systems.
Pawlog does not use targeted advertising directed at children. Crash analytics and
usage analytics require explicit consent and are not enabled by default.
COPPA (US): We comply with the Children's Online Privacy Protection
Act. We do not collect verifiable personal information from children under 13 without
verifiable parental consent.
10. Your Rights
Depending on your location, you may have the following rights:
10.1 Rights Under GDPR / UK GDPR (EEA & UK Users)
- Right of access (Art. 15): Request a copy of your personal data.
- Right to rectification (Art. 16): Correct inaccurate data.
- Right to erasure (Art. 17): Request deletion of your data ("right to be forgotten").
- Right to restriction (Art. 18): Restrict processing of your data.
- Right to data portability (Art. 20): Receive your data in a
machine-readable format (JSON export is available in-app).
- Right to object (Art. 21): Object to processing based on legitimate interests.
- Right to withdraw consent: Withdraw consent for analytics/crash reporting
at any time via Settings β Privacy & Analytics.
- Right to lodge a complaint: You may lodge a complaint with your local
data protection authority (e.g., ICO in the UK, CNIL in France, BfDI in Germany).
10.2 Rights Under CCPA / CPRA (California Users)
- Right to know: The categories and specific pieces of personal information
collected, used, disclosed, and sold.
- Right to delete: Request deletion of personal information.
- Right to opt-out of sale/sharing: We do not sell or share personal
information for cross-context behavioural advertising. No opt-out is required.
- Right to correct: Request correction of inaccurate personal information.
- Right to limit use of sensitive personal information: We do not use
sensitive personal information (as defined by CPRA) beyond what is necessary to
provide the service.
- Non-discrimination: We will not discriminate against you for
exercising your CCPA rights.
Do Not Sell or Share My Personal Information: We do not sell or share
personal information as defined by CCPA/CPRA. We do not have a "Do Not Sell" link
because we do not sell personal information.
Categories of personal information collected in the last 12 months:
Identifiers (Google account ID, device advertising ID); Internet/electronic network activity
(crash logs, analytics events β consent-gated only). We have not collected Sensitive
Personal Information as defined by CPRA.
10.3 How to Exercise Your Rights
Most of your data is stored on your device and can be deleted by uninstalling the app
or using the in-app export/delete features. For data on our servers (backup files,
analytics), contact us at privacy@pawlogapp.com.
We will respond within 30 days (GDPR) or 45 days (CCPA). We will verify your identity
before actioning any request.
In-app deletion: To delete all your data:
Settings β (coming soon: Delete Account & Data). Until this feature is
available, contact us by email and we will delete your server-side data within 7 business days.
11. International Data Transfers
We are a global app. When data is processed by our third-party providers
(Google, Cloudflare, Groq), it may be transferred to and stored in countries
other than your own.
- EEA/UK users: Transfers to third countries are protected by
EU Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement
(IDTA). Google and Cloudflare are certified under applicable transfer mechanisms.
- Brazil (LGPD): International transfers comply with the mechanisms
permitted under Article 33 of the LGPD.
- China (PIPL): We comply with PIPL requirements for personal
information processors. Cross-border transfers meet standard contract requirements
under Article 38 of PIPL.
- South Korea (PIPA): Cross-border data transfers comply with
the Personal Information Protection Act.
- Thailand (PDPA) / Singapore (PDPA) / Malaysia (PDPA):
International transfers comply with applicable data transfer provisions.
- Australia (Privacy Act / NDB Scheme): We comply with the
Australian Privacy Principles (APPs). We report eligible data breaches under
the Notifiable Data Breaches (NDB) scheme within 30 days of discovery.
- Canada (PIPEDA / Law 25): We comply with PIPEDA and
Quebec's Law 25. A Privacy Officer is designated (contact: privacy@pawlogapp.com).
12. Data Retention & Deletion
| Data Type |
Storage Location |
Retention Period |
Deletion Method |
| Pet & health data |
On-device SQLite |
Until you delete the app or clear app data |
Uninstall app or clear app data in Android settings |
| Pro encrypted backup |
Cloudflare R2 |
30 days after last write; +90 days after Pro lapses |
In-app delete or email request |
| Google Drive backup |
Your Google Drive |
Until you revoke access or delete via Google Drive |
Revoke app access in Google Account settings |
| Analytics events |
Firebase (Google) |
Up to 14 months (Firebase default) |
Disable in Settings or contact us |
| Crash reports |
Firebase Crashlytics |
90 days |
Disable Crashlytics in Settings |
| Transaction records |
Google Play (Google servers) |
Per Google Play's retention policy |
Contact Google |
13. Security
We implement industry-standard technical and organisational measures:
- Encryption in transit: TLS 1.3 for all API communications.
- Encryption at rest (Pro backup): AES-256-GCM with HKDF key derivation;
zero-knowledge architecture β the plaintext never leaves your device.
- Authentication: Google Sign-In with RS256 JWT validation on all
authenticated API endpoints; JWTs expire after 1 hour.
- Rate limiting: All API endpoints enforce rate limits to prevent
abuse and protect user data from brute-force attacks.
- No root detection bypass: We rely on server-side JWT verification as
the primary security boundary; client-side root detection is not implemented.
- Vulnerability disclosure: If you discover a security vulnerability,
please report it responsibly to
security@pawlogapp.com.
We aim to respond within 72 hours.
Despite our efforts, no security system is impenetrable. In the event of a data breach
affecting your personal data, we will notify affected users and relevant authorities
as required by applicable law (e.g., GDPR Art. 33/34, NDB Scheme, LGPD Art. 48).
14. Regional Disclosures
14.1 European Economic Area & UK
The data controller for EEA/UK users is Pawlog Developer.
Our GDPR representative in the EU can be contacted at
gdpr@pawlogapp.com.
You have the right to lodge a complaint with your national supervisory authority.
14.2 California (CCPA/CPRA)
Pawlog does not sell or share personal information. We do not use or disclose
sensitive personal information for purposes other than those specified in
Cal. Civ. Code Β§ 1798.121. California residents may exercise their rights by
contacting privacy@pawlogapp.com.
14.3 Brazil (LGPD)
We comply with the Lei Geral de ProteΓ§Γ£o de Dados (LGPD β Law No. 13,709/2018).
Our DPO (Encarregado) can be contacted at
dpo@pawlogapp.com.
Brazilian users may exercise all rights under Arts. 17β22 of the LGPD.
14.4 China (PIPL)
We comply with the Personal Information Protection Law of the People's Republic of China
(PIPL, effective 1 November 2021). Our personal information protection officer can be
reached at pipl@pawlogapp.com.
Separate consent is collected for cross-border transfers as required by PIPL Art. 39.
14.5 India (DPDPA 2023)
We comply with the Digital Personal Data Protection Act, 2023 (DPDPA).
We process only the personal data necessary for the purposes disclosed here.
Data principals may exercise their rights under the DPDPA by contacting
privacy@pawlogapp.com.
14.6 Australia (Privacy Act 1988 / NDB)
We comply with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs).
We notify affected individuals and the OAIC of eligible data breaches under the
Notifiable Data Breaches (NDB) scheme within 30 days of discovery.
14.7 Canada (PIPEDA / Law 25)
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA)
and Quebec's Law 25 (Bill 64). Our Privacy Officer is reachable at
privacy@pawlogapp.com.
14.8 South Korea (PIPA)
We comply with the Personal Information Protection Act (PIPA) of the Republic of Korea.
Korean residents may exercise their rights under PIPA Article 4 by contacting
privacy@pawlogapp.com.
14.9 Japan (APPI)
We comply with the Act on the Protection of Personal Information (APPI) as amended.
Our handling manager (εζ±θ²¬δ»»θ
) can be contacted at
privacy@pawlogapp.com.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be notified:
- Via an in-app notification on your next app launch.
- By updating the "Last updated" date at the top of this page.
Where consent is required for new processing activities, we will ask for it again.
Continued use of the App after the effective date constitutes acceptance of the
updated policy.
If you have questions, requests, or concerns about this Privacy Policy:
We aim to respond to all privacy requests within 30 days.
Summary: Your pet data stays on your device. We never sell it.
We only process analytics and crash data if you say yes. Backup is your choice.
You can delete everything, anytime.