Privacy Policy
Effective: 2026-07-11 Last updated: 2026-08-16
This is the privacy policy for PawQuirks ("the app", "we"), an iOS app that interprets pet behavior from short videos. PawQuirks is operated by Farwake Labs, a sole proprietorship based in British Columbia, Canada. We've kept this policy short and specific. If you see a term you don't recognize, contact us.
This policy was reviewed by the founder and reflects PawQuirks's actual data practices as of the effective date above. Formal legal review will be obtained before the app expands beyond its initial Canada-first availability.
1. The short version
- We collect the videos you record of your pet, plus a few small things needed to make the app work (your account ID, an optional context note you write).
- We also keep a small log of how you use the app (a read finished, a card was shared) and, in the App Store version, crash and performance reports when something goes wrong. Both are our own — there is no third-party analytics or tracking SDK in this app. Both are deleted with your account.
- We use that data only to run the AI interpretation, show you the result, and fix bugs. We do not advertise, profile, or track you.
- We share the video with three service providers (Supabase for storage, Google for the AI model, ElevenLabs for voice synthesis when applicable). Each one is contractually bound not to train on your content or use it for advertising.
- You can delete your account and all your data from inside the app at any time. The deletion is real — your data is removed from our servers, not just hidden.
- We do not knowingly collect data from children under 13.
2. What we collect
Videos and audio (your pet clips)
When you tap Record, the app captures a short video (3–20 seconds) of your pet. The video and its audio are uploaded to our servers so the AI model can interpret your pet's behavior.
- What's in the clip: whatever the camera and microphone capture — typically your pet, possibly your home environment, possibly your voice or the voices of other people in the room.
- What we do with it: send it to our AI interpretation pipeline, store it linked to your account, and surface the resulting interpretation back to you.
- What we do NOT do with it: train AI models, sell it, share it for advertising, or look at it manually except where required (for example, debugging a specific issue you have reported, or investigating an emergency-flag clip — see § 9 Welfare incidents).
Account ID
When you sign in with Sign in with Apple, Apple gives us an opaque account identifier. We use it to associate your clips and pets with your account so you see your data and not someone else's.
We do not store your name or email address, even when Apple shares them at sign-in. Apple's relay system means an email visible to us is generally a forwarding alias, not your real address; we discard it on receipt.
The context note you write (optional)
Each clip can include a short free-text note ("just got home from a walk", "thunder outside", etc.). It's optional. If you write one, it's sent to the AI model alongside the clip and stored linked to your account.
How you use the app (usage analytics)
We record a small set of events describing how the app is used — for example that a clip was recorded, that a read finished, that a voice card was played, that you shared a card. Each event is stored linked to your account ID.
These are our own events, sent to our own servers. There is no third-party analytics SDK in the app — no Google Analytics, no Firebase, no Amplitude, nobody else's code watching you. We use them to see which parts of the app work and which don't (for example: how many people finish their first read), not to build a profile of you, and never for advertising.
They are deleted with your account.
Crash and performance data (diagnostics)
When the app crashes, hangs, or runs slowly, iOS gives us a summary of what happened. In the App Store version of the app, we upload those summaries to our servers, linked to your account ID. They contain numbers and technical details — app version, iOS version, device model, launch times, crash traces — not the contents of your clips.
We use them to find and fix bugs. They are deleted with your account.
What we do NOT collect
We do not collect:
- Contact info (your name, email, phone, address). Sign in with Apple may hand us a name and email at sign-in; we do not store them.
- Location (precise or coarse)
- Health or fitness data
- Browsing or search history
- Contacts
- Advertising identifiers (no IDFA, no advertising ID)
- Third-party analytics or tracking SDKs — none, of any kind. (We do keep our own first-party usage events, described above.)
- Payment card or financial information (subscriptions are handled by Apple — we never see your card)
3. How we use what we collect
We use your data for one purpose: running the PawQuirks app. Specifically:
- Interpretation. Each clip is sent to the AI model to produce a behavioral read.
- Voice synthesis. When the welfare layer permits a voice card, the model writes 2–5 short voice lines (capped at 200 characters total) and an external service synthesizes audio for them.
- History. Your past clips and interpretations are kept so you can scroll your pet's timeline inside the app.
- Welfare gates and escalation. A safety layer reviews every interpretation before showing it. If the model surfaces signs of pain, fear, or aggression, the app routes you to vet or behaviorist resources instead of producing a voice card. This processing happens automatically; no human reviews your clip unless you've reported a problem with it.
- Service operation and security. Things like making the upload work, retrying a failed interpretation, and preventing abuse.
We do not:
- Sell your data to anyone.
- Share it with advertisers or data brokers.
- Use it to build profiles of you for targeting purposes.
- Use it to train AI models, ours or anyone else's. (See § 4 for what each service provider does — none of them are contractually allowed to train on your content.)
4. Who we share it with
To run the app we send your data to a small set of service providers ("sub-processors"). Each one is contracted to handle your data the same way we would.
| Service | What it gets | What it does | Provider's policy |
|---|---|---|---|
| Supabase (Singapore-based, US infra) | The video, audio, and metadata | Database and object storage for our backend | supabase.com/privacy |
| Google Gemini API | The video, audio, and your context note | Generates the structured behavioral interpretation | Google's commercial API terms — content is not used for model training |
| ElevenLabs | Short text strings derived from the interpretation (no video, no audio from your clip) | Synthesizes the voice card audio when a card is permitted | elevenlabs.io/privacy |
| Fly.io | Same data Supabase has, in transit only | Hosts the worker service that orchestrates the interpretation pipeline | fly.io/legal/privacy-policy |
We do not currently use any analytics, advertising, or tracking SDKs.
If you are outside Canada or the United States, your data may be transferred to and processed in the United States or other jurisdictions where our sub-processors operate. Where required by your local law, we rely on standard contractual clauses with our sub-processors to maintain protections equivalent to your home jurisdiction.
5. How long we keep it
We keep a clip until you delete it. Deleting a single clip (Settings → "Inspect & delete my clips") or your whole account (§ 6) removes it from our servers in the same step. We do not currently run an automatic, time-based deletion job, so a clip you don't delete stays stored.
The data sharing setting you choose at first run (and can change anytime in Settings → Privacy → Data sharing) governs what we are permitted to use your clip for:
| Setting | What we may use your clip for |
|---|---|
| Personal (default) | Producing your own read. Nothing else. |
| Improve | Producing your read, plus improving our interpretation quality. |
| Research | The above, plus longer-term research into interpreting pet behavior. |
We are building the scheduled job that will retire clips automatically — 30 days for Personal, 5 years for Improve, 10 years for Research. Until that job is live, this section describes what actually happens rather than what we intend to happen. We will update this policy when it ships.
Local copies on your device persist until you delete the clip or uninstall the app, whichever comes first.
Account metadata (your account ID, the link between you and your pets) is retained as long as your account is active. When you delete your account (§ 6), everything is removed.
6. How to delete your data
You can delete your data without contacting us:
- Delete a single clip: Settings → "Inspect & delete my clips" → swipe to delete. The clip is removed from the app and from our servers in the same step.
- Delete your entire account: Settings → "Delete account & data". This is the permanent option. It removes every clip, every pet record, every interpretation, every correction, and your account itself from our servers. There is no soft-delete, no archive, and no undo.
If you can no longer reach the app (uninstalled, lost device, account locked), email privacy@pawquirks.com with the email address Apple uses for your Apple ID and we will manually delete the account and confirm. Allow up to 30 days for us to act on the request.
We retain backups for up to 30 days after a deletion. After that, your data is gone from backups too.
7. Your rights
Depending on where you live, you may have additional rights regarding your personal data. For everyone, no matter where you live:
- Access: the entire scope of personal data PawQuirks holds about you is the data you've explicitly created in the app — your account ID, your pets, your clips, your context notes, and the AI interpretations of them. You can see it all from inside the app.
- Correction: correct your pet's name, breed, age class, etc. anytime in the pet detail screen. The interpretation history is read-only by design (it's a record of what the model saw at the time).
- Deletion: see § 6.
- Withdraw consent: change your data-sharing tier in Settings, or delete the account.
Additional rights for Canadian residents (PIPEDA)
Canadian residents have the right to access the personal information PawQuirks holds about them, to request correction of inaccurate information, and to withdraw consent for our processing (which will result in deletion of the relevant data per § 6). Complaints may be filed with the Office of the Privacy Commissioner of Canada at priv.gc.ca.
Additional rights for EU / UK residents (UK / EU GDPR)
You also have the right to data portability, the right to object to processing, the right to lodge a complaint with your local data protection authority, and the right to restrict processing.
The legal basis for our processing: - Performance of a contract for the core interpretation feature (you record a clip, we interpret it). - Legitimate interests for service operation and security. - Consent for the optional Improve/Research data-sharing tiers.
We do not designate a Data Protection Officer at our current scale.
Additional rights for California residents (CCPA / CPRA)
California residents have the right to know what personal information we collect, the right to delete it, the right to correct it, the right to opt out of "sale" or "sharing" (we do not sell or share for cross-context behavioral advertising), and the right to non-discrimination for exercising these rights. To exercise any of these rights, use the in-app deletion path or email privacy@pawquirks.com.
We do not sell your personal information. We do not share it for cross-context behavioral advertising.
8. Security
We use HTTPS (TLS) for every connection between the app and our servers. Data at rest is encrypted on the storage providers' infrastructure. Access to user data on our backend is limited to the developer of the app under principle-of-least-privilege.
Our edge functions enforce per-user authorization on every operation, and storage objects are gated by row-level security policies that key access to your account ID. The cascade chain that powers full-account deletion is pinned by automated tests so a future migration cannot silently weaken it.
We are a small team and not above mistakes. If you find a security issue, email security@pawquirks.com — we will respond within 7 days.
9. Welfare incidents
If you record a clip showing apparent emergency signs (cyanotic mucous membranes, a child plus aggressive behavior, etc.), the app shows you an escalation card pointing to a vet or behaviorist instead of producing a voice card.
In rare cases — for example, if you contact us about a real bite or near-bite incident, or if a regulatory body lawfully compels us — we may review the specific clip(s) involved manually. This is a defined safety procedure, not a normal data flow. We document each such review internally. We do not use these clips for any other purpose.
10. Children
PawQuirks is not directed at children under 13 (under 16 in the EU). We do not knowingly collect personal data from children. The app interprets pets, not people, but the account holder must be old enough to consent to data processing under applicable law.
If you believe a child has used the app and provided personal data, email privacy@pawquirks.com and we'll delete the account.
11. Changes to this policy
If we change this policy in any material way, we will:
- Update the "Last updated" date at the top.
- Surface a one-time in-app notice on next launch — this is our only notification channel. We cannot email you: we do not store your email address (see § 2), and this version of the app does not send push notifications at all.
- For changes to retention windows or sub-processors, the in-app notice will say so explicitly rather than pointing you at this page in general terms.
We keep every earlier version of this policy. A summary of what changed in each revision is in the "What changed" section below, and you can request the full text of any prior version by contacting us at privacy@pawquirks.com.
What changed
2026-08-16
- Corrected how long we keep your clips (§ 5). The previous version said clips on the default Personal setting were kept "up to 30 days from upload". Nothing deleted them on that schedule, so the statement was not true. § 5 now says what actually happens: we keep a clip until you delete it, and there is no automatic time-based deletion yet. The Personal / Improve / Research setting still controls what your clip may be used for. We are building the scheduled deletion job and will update this policy when it runs.
- Corrected how we tell you about changes (§ 11). The previous version said we would send a push notification for changes to retention windows or sub-processors. This app does not send push notifications, so that was a promise we could not keep. The in-app notice on next launch is our only channel, and it will name the specific change.
2026-07-11
- Disclosed usage analytics. We keep a small first-party log of how the app is used. The previous version of this policy listed "usage analytics" under what we do not collect, which was wrong — it was written when we meant "no third-party analytics SDK" (still true: there are none). The events themselves have shipped since v1.0 and are now described in § 2.
- Disclosed crash and performance diagnostics. The App Store build uploads crash/hang/performance summaries linked to your account. This policy had never mentioned it. Now described in § 2.
- Stopped storing your name and email. Sign in with Apple hands them over once at sign-in. Earlier versions of the app saved both into the device's secure Keychain; nothing ever used them. Those writes are gone, and the app now deletes any previously-saved copy on next launch. This policy always said we don't store your name or email — that is now true of the code as well.
12. Contact us
- General privacy questions / data-deletion requests: privacy@pawquirks.com
- Security disclosures: security@pawquirks.com
- Press / general: hello@pawquirks.com
13. Sub-processor changes
We will update the table in § 4 within 30 days of adding or removing a sub-processor. Existing users will not be notified of additions unless the new sub-processor processes data for a new purpose; removals (which only ever shrink the set of people who can see your data) are not user-actionable.
PawQuirks is currently developed and operated by Farwake Labs, a sole proprietorship based in British Columbia, Canada. If that changes — for example, if the app is acquired or a co-founder joins — we'll update this policy to reflect the new arrangement before the change takes effect.