Privacy Policy
- Your check-in videos are used only to check that you did the activity, and are deleted right after (at the latest within 24 hours). We keep the result, not the video.
- We don't sell your data, show ads, or track you across apps or websites. There's no advertising or analytics SDK in Puffulet, and this website sets no cookies.
- We use a small set of providers to run the app: Google (Firebase and the Gemini AI model), RevenueCat (subscriptions) and Apple.
- You can delete your account and data anytime in the app: Settings › Delete account.
1. Who we are
Puffulet (the iPhone app and puffulet.com) is provided by InvestTechNick SRL, a company registered in Romania (registered address, trade register no. J__/____/____, tax ID RO________). We are the controller of your personal data under the EU and UK General Data Protection Regulation (GDPR).
Privacy questions and requests: [email protected]. We have not appointed a data protection officer, as we're not required to; the address above reaches the person responsible.
2. What we collect and why
| Data | Why we use it | Legal basis (GDPR) |
|---|---|---|
| Account: a user ID, and the name and email address you share through Sign in with Apple or Google (Apple lets you hide your email behind a relay address). Google may also provide a profile photo, which we don't use. | To create your account, keep your pet and progress across devices, and contact you about your account if needed. | Contract (Art. 6(1)(b)) |
| Your pet and plan: pet name; wake-up, bedtime and check-in times; daily targets; chosen activities; skipped days; preferences such as muting the pet; the affirmations and verses you write. | To run your daily plan, alarms and reminders, and to make the pet react to what you do. | Contract |
| Wellness information: your check-in history (which activity, when, done or not, repetition counts), and two onboarding answers (how much water you usually drink, how stressed you feel). | To show your progress and care score and tailor your starting plan. | Your explicit consent (Art. 9(2)(a)), because some of it may reveal information about your health. You can withdraw it anytime by deleting your account. |
| Check-in videos: short front-camera clips with sound, and for read-aloud check-ins the text you read. | To check that the activity happened (see section 3). Never used to identify you. | Contract, and your explicit consent where a clip reveals health information |
| Subscription status: whether you have an active subscription or trial, the plan, renewal and expiry dates. Apple handles payment; we never see your card details. | To unlock the app for subscribers and remind you before a free trial ends. | Contract |
| Lock Screen updates: Live Activity push tokens and your time zone. | To show and update your upcoming check-ins on the Lock Screen through Apple's push service. | Contract |
| Usage counters: how many times the subscription screens were shown or used (for example “paywall shown”, “purchase started”), with the time of the last one. | To understand whether our subscription screens work and fix problems. | Legitimate interest (Art. 6(1)(f)) in running a working business |
| Technical logs: your user ID, the type and result of a check-in, and error details. | To keep the service secure, prevent abuse, and fix bugs. | Legitimate interest |
| Messages you send us: your email address and what you write. | To answer you. | Contract or legitimate interest |
We don't collect your location, contacts, photo library, health records from Apple Health, or advertising identifiers, and we don't use your data for advertising or profiling.
3. Check-in videos and AI
A check-in is a short clip you record with the front camera, for example drinking a glass of water or doing push-ups. Here is exactly what happens to it:
- The clip is uploaded over an encrypted connection to our private cloud storage, which no other user can access.
- Our server sends it, with instructions, to Google's Gemini AI model, which looks at the first few seconds needed for that activity and answers whether the activity happened. Sound is included because it helps (for example, a swallow or slow breathing).
- The clip is deleted from our storage and from Google's AI service as soon as the answer comes back. If something interrupts that (say, a dropped connection), an automatic job deletes any leftover clip within 24 hours.
- We keep only the result: the activity, the time, done or not, a repetition count where relevant, how confident the model was, and a one-sentence note shown to you (for example “I saw you take a real sip — nice!”).
Your clips are never used to recognise who you are (no facial recognition or biometric identification), saved to your photo library, shown to other people, or used by us or by Google to train AI models. We use Google's paid Gemini API, under terms that don't allow Google to use them to improve its products. Google may keep them for a limited time solely to detect abuse, as its terms describe.
Automated decisions. Whether a check-in counts is decided automatically. It only affects your progress in the app, never your legal rights, prices or access to the service. The system is designed to give you the benefit of the doubt. If it still gets it wrong, tap “I really did it” and it counts, or write to us and a person will look at it.
4. Who we share data with
We share data only with providers that help us run Puffulet, under contracts that limit them to processing it for us:
- Google (Google LLC / Google Ireland Limited): Firebase sign-in, database, storage and cloud functions; Google Cloud logging; the Gemini API for checking clips; and Google Sign-In if you use it.
- RevenueCat, Inc.: manages subscriptions. It receives your user ID and your App Store purchase records.
- Apple: Sign in with Apple, App Store payments, and the push service for Live Activities. Apple's handling of your data is covered by Apple's Privacy Policy.
We may also disclose data if the law requires it, to protect our rights or people's safety, or as part of a sale or reorganisation of our business (in which case this policy keeps applying to your data). We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
Google user data. If you sign in with Google, we receive only your basic profile (name, email address, profile photo). Puffulet's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. International transfers
Our servers are in the United States, and some providers process data there. When we transfer personal data from the EU, EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) and, where a provider is certified, the EU–U.S. Data Privacy Framework, plus the security measures described below. Contact us for a copy of the relevant safeguards.
6. How long we keep data
| Data | Kept for |
|---|---|
| Check-in videos | Deleted right after checking, at most 24 hours |
| Account, pet, plan, check-in history | Until you delete your account |
| Subscription records at RevenueCat | Until you ask us to delete them, or as long as needed for accounting and tax law |
| Technical logs | About 30 days |
| Support emails | Up to 2 years after the conversation ends |
When you delete your account in the app, we immediately and permanently delete your profile, pet, plan, check-in history and any stored clips, and your sign-in account. Copies in backups and logs expire on their normal schedule. App Store purchase records stay with Apple, and you need to cancel an active subscription yourself in the App Store. See Delete your account.
7. Your rights (EU, UK and worldwide)
Wherever you live, you can ask us to:
- access your data and get a copy, including in a portable format;
- correct it;
- delete it (you can do this yourself in the app);
- restrict or object to processing based on our legitimate interests;
- withdraw consent at any time, without affecting what we did before (delete your account, or contact us);
- not be subject to decisions based solely on automated processing that significantly affect you (ours don't, see section 3).
Email [email protected] from the address linked to your account (if you used Apple's Hide My Email, tell us the relay address shown in your Apple ID settings). We'll reply within one month. We may need to confirm it's you. It's free.
You can also complain to a data protection authority, in the country where you live or work, or our lead authority in Romania: ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal). In the UK, that's the ICO. We'd appreciate the chance to sort it out with you first.
8. US state privacy rights
If you live in California or another US state with a consumer privacy law (such as Colorado, Connecticut, Virginia, Utah, Texas or Oregon), you have the right to:
- know what personal information we collect, use and disclose, and get a copy;
- delete it and correct it;
- opt out of its “sale” or “sharing” for targeted advertising, and of profiling. We don't sell or share personal information, and don't use it for targeted advertising or profiling, so there's nothing to opt out of;
- limit the use of sensitive personal information. We use it only to provide the service you asked for;
- not be discriminated against for using these rights.
Categories we collect, using the California terms: identifiers (name, email, user ID); commercial information (subscription status); audio and visual information (check-in clips, deleted right after checking); sensitive personal information (account sign-in, and wellness details that may relate to health); internet or electronic activity (in-app usage counters and logs). The sources, purposes, recipients and retention are described above. We disclose these only to the service providers in section 4, for business purposes.
To make a request, email [email protected]. An authorised agent may act for you with your signed permission. We'll verify requests and reply within 45 days. If we decline, you can appeal by replying to our answer.
9. Children
Puffulet is not meant for children. You must be at least 16 to use it (or older, if your country requires). We don't knowingly collect data from children under 16. If you believe a child has given us data, contact us and we'll delete it.
10. Security
Data is encrypted in transit (HTTPS/TLS) and at rest by our cloud provider. Access is limited to what's needed to run the service, each user can reach only their own data, and clips can be read only by our server. No system is perfectly secure. If a breach affects you, we'll tell you and the authorities as the law requires.
11. Permissions and data on your device
- Camera and microphone: used only while you record a check-in, front camera only. Puffulet never accesses your photo library.
- Notifications and alarms: reminders and the morning alarm are scheduled on your phone. We don't send marketing notifications.
- Stored on your phone: your onboarding draft, recent pet mood, alarm times and preferences, so the app opens quickly and works between syncs. Deleting the app removes them.
You can change permissions anytime in iOS Settings › Puffulet.
12. This website
puffulet.com sets no cookies, uses no analytics or advertising tools, and loads nothing from third parties (even the fonts are served from our own site). Our hosting provider (Google Firebase Hosting) processes your IP address and browser details to deliver pages and protect against abuse. See our Cookie Notice.
13. Changes
We'll update this policy when our practices change, and change the date at the top. If a change is significant, we'll tell you in the app or by email before it takes effect.
14. Contact
InvestTechNick SRL · registered address, Romania
Privacy: [email protected] · Support: [email protected]