Privacy Policy
This Privacy Policy explains what data PawSnap: Pet AI Art (“PawSnap”, “we”, “us”) collects when you use the PawSnap mobile app and the website at pawsnap.app, how we use it, who we share it with, and the choices you have. We try to keep this short and human-readable.
1. Information we collect
1.1 Information you provide
- Pet photos. The images you upload to generate AI portraits.
- Optional account information. If you choose to sign in (e.g. via Apple, Google, or email), we receive a stable user identifier and the email address you authorize.
- Order details. If you order a physical print, the shipping address and order metadata you submit (payment is handled by Stripe and never touches our servers).
- Support correspondence. Anything you send us at [email protected].
1.2 Information collected automatically
- Device identifier. A random ID generated on first launch and stored on your device. We use it to associate generations with your install and enforce free-credit limits.
- Technical logs. IP address, timestamp, app version, OS, and basic request metadata, kept short-term for security and abuse prevention.
- Crash and performance data. Aggregated, non-identifying telemetry to keep the app healthy.
1.3 We do not collect
- Precise location data.
- Contacts, microphone, calendar, or health data.
- Your name, phone number, or address (unless you order a physical print).
We do collect a tracking identifier (Apple IDFA) only if you grant permission on the iOS App Tracking Transparency prompt; see section 3.1 below.
2. How we use your information
- To generate AI pet portraits from the photos you upload.
- To deliver the app, sync your gallery across devices if you sign in, and operate features such as ad-grant credits.
- To process print orders and ship them to you.
- To enforce quota limits, prevent abuse, and keep the service secure.
- To respond to support requests and improve the app.
- To comply with legal obligations.
We do not sell your personal information, and we do not use your pet photos to train third-party AI models.
2.1 Legal basis for processing (EU / UK GDPR)
If you are in the EEA, UK, or Switzerland, we rely on the following lawful bases under Article 6 GDPR:
- Account, quota, and credits management — performance of a contract with you (Art 6(1)(b)).
- AI generation of the photos you submit — performance of a contract with you (Art 6(1)(b)).
- Print orders and shipping — performance of a contract with you (Art 6(1)(b)).
- Aggregate analytics and crash reporting — our legitimate interest in keeping the app working and improving it (Art 6(1)(f)). You can opt out by deleting your data in Settings → Delete my data.
- Personalized advertising (IDFA) — your explicit consent via the iOS App Tracking Transparency prompt (Art 6(1)(a)). You can withdraw consent at any time in iOS Settings.
- Content moderation and abuse prevention — our legitimate interest in keeping the service safe (Art 6(1)(f)), and where applicable, compliance with a legal obligation (Art 6(1)(c)).
2.2 Automated decision-making
Each photo you submit is screened by an automated moderation step (OpenAI Moderation) before generation. If the screen flags the photo as unsafe, the upload is rejected and you can immediately retry with a different photo — nothing is escalated, banned, or applied to your account. This filtering does not constitute automated decision-making producing legal or similarly significant effects on you within the meaning of Article 22 GDPR.
3. Third-party services we use
PawSnap relies on a small set of third-party services (“sub-processors”) to operate. Each one only receives the minimum data it needs to do its job. The table below lists every service, what data it sees, whether it performs tracking, and why we use it.
| Service | Data it receives | Used for tracking? | Purpose |
|---|---|---|---|
| Cloudflare (Workers, R2, D1) | Pet photos, generated portraits, generation metadata, anonymous device ID, IP address | No | Hosting, storage, database, and request routing |
| Replicate | Pet photos sent to the gpt-image-2 and real-esrgan models for the duration of generation/upscale only | No | AI image generation and upscaling |
| OpenAI | The text prompt and a thumbnail of the input photo for moderation; no images are retained by OpenAI | No | Safety / content moderation |
| RevenueCat | Anonymous device ID, App Store / Play Store receipt, subscription state | No | Subscription management and restore-purchase flow |
| AdMob (Google) | Anonymous device ID, IDFA (only with ATT consent), coarse device / locale info, rewarded-ad watch events | Yes — only after you grant ATT permission | Rewarded video ads (the “watch ad for +1 credit” flow) and ad attribution |
| PostHog | Pseudonymous events (screen views, button taps), app version, OS — keyed to a random analytics ID, not your identity | No | Aggregate product analytics |
| Sentry | Crash stack traces, app version, OS, anonymous device ID | No | Crash and stability monitoring |
| Apple Sign In (optional) | An Apple-issued opaque user identifier, plus the email you authorize | No | Optional account linking, restore-purchase across devices |
| Stripe (only if you order a print) | Payment card data is handled directly by Stripe — we never see it. We receive only an order reference. | No | Payment processing for physical prints |
| Printify (only if you order a print) | Shipping address, order details, the chosen image | No | Print-on-demand fulfillment and shipping |
3.1 App Tracking Transparency (iOS only)
The first time PawSnap is about to show you a rewarded ad — after you have accepted our in-app consent gate — iOS will show a system prompt asking whether PawSnap may track you across apps and websites owned by other companies. This decision is yours alone.
- If you allow tracking, AdMob may read your device’s advertising identifier (IDFA) so the ads you see are more relevant to your interests, and so advertisers can attribute installs they paid for.
- If you decline, AdMob does not receive your IDFA. You can still watch ads for free credits — they just won’t be personalized. Ad attribution falls back to Apple’s privacy-preserving SKAdNetwork.
You can change this decision at any time in iOS Settings → Privacy & Security → Tracking → PawSnap.
4. Where your data lives
- Cloudflare (US + edge): R2 stores pet photos and generated portraits as encrypted objects; D1 stores generation records, quota counters, and order references.
- Replicate (US): processes uploads for the duration of generation/upscale only.
- OpenAI (US): processes the moderation request only.
- Stripe (US + EU): processes payment if you order a print.
- Printify (US): fulfills prints if you order one.
- RevenueCat (US): stores subscription state.
- Google AdMob (US + Google ad-serving edge): serves rewarded ads.
- PostHog (US or EU, depending on host): stores pseudonymous analytics events.
- Sentry (US): stores crash reports.
5. Retention
- Uploaded source photos are deleted within 7 days of generation completion.
- Generated portraits are retained for 30 days so you can revisit your gallery, then deleted unless you save or order them.
- Order records are kept for as long as required for tax, accounting, and customer-service purposes (typically 7 years).
- Logs are kept for up to 90 days.
6. Your data rights & how to contact us
Under the EU / UK GDPR, the California CCPA, and similar laws, you have the right to:
- Access a copy of the personal data we hold about you.
- Correct data that is inaccurate.
- Delete your data, including all generated portraits and your device record (in-app: Settings → Delete my data).
- Restrict or object to processing based on our legitimate interests.
- Data portability — receive the personal data you supplied to us in a structured, commonly used, machine-readable format.
- Withdraw consent at any time where processing is based on consent (in-app: Settings → Delete my data, or reset the ATT permission in iOS Settings).
- Lodge a complaint with your local data protection supervisory authority. EU users can find their authority at https://edpb.europa.eu/about-edpb/about-edpb/members_en; UK users at ico.org.uk.
To exercise any of these rights, email [email protected] with “DSAR” in the subject line. We respond within 30 days.
PawSnap is operated by Jindong Chen as a sole independent developer. Given our scale and the nature of our processing, we are not required to appoint a Data Protection Officer under Article 37 GDPR. For all privacy matters, the controller contact is [email protected].
6.1 EU representative (Article 27 GDPR)
Under Article 27(2)(a) GDPR, PawSnap is exempt from appointing an EU representative because our processing of EU personal data is occasional, does not include large-scale processing of special categories of data (Art 9) or data relating to criminal convictions (Art 10), and is unlikely to result in a risk to the rights and freedoms of natural persons. EU users can still exercise every right above by emailing [email protected].
7. AI-generated content
Portraits are produced by machine-learning models. They are creative reinterpretations and may not be photographically accurate. We disclose AI-generated content in-app and provide tools to download, share, or delete each result.
8. Children
PawSnap is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
9. International transfers
PawSnap is operated from the United States and uses globally distributed infrastructure. Our sub-processors — Cloudflare, Replicate, OpenAI, RevenueCat, Google AdMob, PostHog, Sentry, Stripe, Printify, and Apple — are based in the United States (with some EU edge presence). When you use PawSnap from the EEA, UK, or Switzerland, your personal data is transferred to and processed in the US.
We rely on the European Commission’s Standard Contractual Clauses (2021/914) (and the UK International Data Transfer Addendum where applicable) as the legal mechanism for these transfers, supplemented by encryption in transit (TLS), encryption of stored objects, scoped access tokens, and minimum-necessary data sharing with each sub-processor. Where a sub-processor is certified under the EU–US Data Privacy Framework (e.g. Cloudflare, Google, Apple), we also rely on that adequacy decision as an additional safeguard. A copy of the SCCs we use is available on request from [email protected].
9.1 Cookies and web tracking
Our website at pawsnap.app does not set any cookies and does not use any third-party analytics, tag managers, or advertising trackers in the browser. You can verify this in your browser’s developer tools.
The iOS app uses on-device identifiers (such as Apple’s IDFA) only after you accept the in-app consent gate and grant the iOS App Tracking Transparency permission. The exact list of identifiers and the data linked to them is published on the App Store as our Apple App Privacy Labels.
10. Security
We use TLS in transit, encrypted object storage, scoped access tokens, and least-privilege internal access. No system is perfectly secure, but we take security seriously and disclose material incidents promptly.
11. Changes
We may update this Policy. If changes are material we will notify you in-app or by email (where applicable) before they take effect. The “Last updated” date above always reflects the current version.
12. Contact
Questions, requests, complaints? Email [email protected].