Our approach
Pawfile does not require an account and does not display advertising. Most app content stays in the app's iOS sandbox and the App Group shared with its widget. Specific information is sent to service providers when you generate pet artwork, use subscriptions, or use a Live Activity. From version 1.0.1, new installations enable limited app and campaign measurement. Apple's separate tracking permission controls advertising identifiers and sharing with advertising partners. Existing installations with analytics off keep that choice. Before any pet photo or generation instruction is transmitted for AI processing, Pawfile explains the transfer in the app and asks for your affirmative permission.
Information handled by the app
- Pet content and preferences. Pawfile stores the selected pet photo, generated artwork, pet name, species, optional breed description, art style, mood, care interactions, and app preferences on your device.
- AI generation. After you give permission, the selected pet photo, species and optional breed description, selected art style, mood, and a generated instruction pass through Pawfile's developer-operated Cloudflare relay to Kie.ai, a third-party AI service, which processes the request using Google's Nano Banana image model and related infrastructure. One permission can be used to create up to eight mood variants from the same photo, with a mood-specific instruction sent for each generation job. Cloudflare also processes the connection's IP address and Pawfile's random installation identifier for security, ownership checks, and rate limiting. The pet name is not included in that generation request.
- Notifications and Live Activities. After a Live Activity is started, Pawfile sends a random installation identifier, that activity's Apple push token and identifier, timezone, app/bundle information, pet name, style, mood or scene state, and timestamps to the developer-operated Cloudflare service. That service uses Apple Push Notification service to update the activity the user started. Pawfile does not register an install-wide push-to-start token, and the service retires an activity record when Apple reports that its update token is no longer valid instead of creating a replacement. Pet photos are not included in notification or Live Activity requests; the same Cloudflare service separately relays the selected photo only for the consented AI-generation request described above.
- Subscription information. Apple and RevenueCat process product identifiers, purchase and receipt information, anonymous customer identifiers, eligibility, entitlement status, renewal or expiration state, and related transaction events.
- App and campaign measurement. When measurement is enabled, AppsFlyer processes its generated installation identifier, install and session information, paywall placement, and the product identifier when checkout begins, together with technical device and network information and approximate region inferred from an IP address. That AppsFlyer identifier is attached to the anonymous RevenueCat customer so subscription lifecycle and gross revenue events can be measured. With Apple tracking permission, device advertising/vendor identifiers and these measurement events may be shared with configured advertising partners, including Meta and TikTok, to attribute and evaluate Pawfile campaigns. Pawfile does not send pet photos or pet names to these advertising partners, and its client funnel events do not include prices, receipts, or transaction identifiers.
- Technical data. Network providers may receive IP address, device/browser information, request time, and similar security or delivery logs when the app or website connects to them.
Cloud storage and backups
Pawfile does not provide an account, CloudKit database, or cross-device content sync. Pet photos and generated sprites are stored locally, with limited widget and Live Activity state shared through an App Group on the same device. Standard iOS device-backup behaviour may apply according to your Apple settings. Separately, the limited remote processing described in this policy is not an app backup and may remain with service providers for their stated retention periods.
Purchases and subscriptions
Apple processes payment for Pawfile's monthly and yearly auto-renewing subscriptions. RevenueCat helps display offers, verify purchases, restore purchases, and determine access to Pawfile Pro. We receive subscription and entitlement status but not your full payment-card number. Apple controls the price, tax, introductory-offer eligibility, billing, cancellation, and refund process.
Analytics, diagnostics, advertising, and attribution
Pawfile uses RevenueCat for subscription analytics and entitlement management. From version 1.0.1, a new installation prepares AppsFlyer during launch and presents Apple's tracking permission prompt. After the prompt resolves, measurement can start whether you allow or decline tracking. If tracking is not authorized, Pawfile disables AppsFlyer advertising/vendor identifier collection and blocks its user-level advertising-partner sharing, including for RevenueCat-forwarded events. Declining Apple tracking permission does not switch off this limited measurement. When tracking is authorized and measurement is enabled, AppsFlyer and RevenueCat can collect attribution identifiers and share install, checkout, and subscription results with configured Meta and TikTok integrations. RevenueCat remains the sender of subscription lifecycle and gross revenue events; the app does not send duplicate purchase events.
You can turn measurement on or off from Pawfile Settings → App & campaign measurement. Turning it off stops future AppsFlyer client collection, clears unsent app events, and queues removal of the AppsFlyer and extra attribution identifiers from RevenueCat, with partner sharing blocked. Changes reach RevenueCat when connectivity permits and do not erase historical provider records or recall events already sent. You can change Apple tracking permission in iOS Settings; Pawfile rechecks it when the app becomes active. Apple may independently send privacy-preserving aggregate SKAdNetwork or AdAttributionKit postback copies to Pawfile's configured AppsFlyer endpoint. These Apple-generated copies are separate from user-level tracking. RevenueCat still receives its anonymous customer identifier and routine request/device metadata, including IDFV, to operate subscriptions even when optional measurement is off. Pawfile does not currently include a third-party crash-reporting SDK.
Earlier versions and upgrades. Version 1.0 uses AppsFlyer Strict with optional analytics off by default, enabled only through its Optional analytics & attribution setting; it does not request Apple tracking permission or permit user-level advertising-partner sharing. Version 1.0.1 preserves an existing installation's off choice. Users can choose to enable measurement in Settings after upgrading.
Device permissions and system features
Pawfile uses the photo picker for images you select, may request camera access when you take a pet photo, and may request notification permission for alerts, sounds, and badges. It also uses Apple's widget, App Group, Live Activities, Dynamic Island, and push-notification systems. You can change camera, photo, and notification access in iOS Settings. Pawfile does not request microphone, contacts, calendar, precise location, Health, Bluetooth, or motion access.
Image-safety checks
Where the device's Apple safety policy enables Sensitive Content Analysis, Pawfile checks the selected photo and downloaded generated artwork on the device before using them. The image does not leave the device for this Apple check. If the check identifies sensitive imagery, Pawfile blocks that image and asks you to choose another pet photo. This check supplements, but does not guarantee, the safety or suitability of AI output.
Permission for AI processing
Before the first AI generation, Pawfile presents a concise inline permission disclosure on the photo-review screen. It names Cloudflare, Kie.ai, and Google; states that the selected photo and pet details will be processed for AI artwork; explains Kie.ai's service-improvement use; and links to this policy for the exact request fields, model infrastructure, variants, security data, and retention details. Nothing is uploaded for AI generation unless you affirmatively tap the explicitly labeled Allow AI & Continue button. If you leave the screen instead, generation does not start and the selected photo remains on your device.
Pawfile stores your choice on the device so the same disclosure does not interrupt every generation. You can withdraw permission at any time from Settings → AI photo processing. After withdrawal, Pawfile blocks new AI uploads and generation requests unless you grant permission again. Withdrawal does not recall information already processed; the retention and deletion options below still apply.
How information is used and shared
We use information to generate the artwork you request; display the pet companion in the app and Apple system surfaces; deliver requested notifications and Live Activity updates; provide and support subscriptions; measure product, installation, checkout, subscription, and acquisition performance when measurement is enabled; secure and operate the service; respond to support requests; and meet legal obligations. Information is disclosed only as needed to Apple, Cloudflare, Kie.ai and the Google model infrastructure used for the generation request, RevenueCat, AppsFlyer when measurement is enabled, configured Meta and TikTok advertising integrations when Apple tracking permission is authorized, our website host, and support-email providers, or when required by law. Kie.ai's published Terms permit it to host, store, reproduce, modify, and display submitted photos, generation parameters, instructions, output, and associated task metadata solely to operate and improve its services. We do not sell pet photos. The advertising measurement sharing described above may be treated as sharing or targeted advertising under applicable privacy laws. Pawfile does not show third-party ads. You can disable measurement in the app and manage Apple tracking permission in iOS Settings.
We require every third party that receives Pawfile user data to provide the same or equivalent protection described in this policy and required by applicable platform rules, limit its processing to the purposes disclosed here, and apply appropriate security, retention, and deletion controls. If a provider cannot meet that requirement, Pawfile will stop new transfers to that provider. We do not authorize these providers to sell pet photos, use them for advertising, or build advertising profiles.
These providers process information under their own terms and privacy notices: Apple, Kie.ai, Google, RevenueCat, AppsFlyer, Cloudflare, Meta, and TikTok.
Retention and deletion
- On-device data. Delete an individual photo in Pawfile, or use Settings → Reset local Pawfile data to remove local pet photos, generated artwork, app state, shared widget content, scheduled local notifications, the current Live Activity, and the app's stored AI permission choice; measurement is turned off. Deleting the app also removes its local sandbox, subject to any device backup managed by Apple.
- Push service. Pawfile stores at most one Live Activity record per random installation identifier. That record expires 16 hours after its first registration even if the app refreshes its token; Pawfile does not keep a separate long-lived installation record. If Apple reports that the activity token is no longer valid, the record is retired sooner and is not used to start a replacement.
- Pawfile AI relay. Pawfile's Cloudflare relay processes the selected photo and instruction only to forward the generation request. Pawfile does not place the photo bytes or prompt in its relay database. Hashed upload-ownership records expire after three days and task-ownership records after four hours. Pawfile stores a hashed random installation identifier in a minimal two-use-regeneration ledger so repeated regeneration requests cannot consume unlimited provider credits. Cloudflare also applies short-lived abuse-prevention counters to hashes derived from the random installation identifier and source IP.
- AI provider. Kie.ai's source-upload documentation gives differing deletion windows; Pawfile therefore discloses the longer stated source-photo period of up to three days. Kie.ai separately states that generated output media is retained for 14 days and task logs, text, and related metadata for two months, after which they are deleted. Pawfile does not currently provide an in-app remote-delete command for completed Kie.ai jobs.
- Apple, RevenueCat, AppsFlyer, hosting, and support. These providers retain records under their own policies and as needed for purchases, fraud prevention, analytics, security, legal compliance, and support. Support correspondence is kept only as long as reasonably needed to resolve and document the request.
Withdrawing AI permission stops future AI transfers but does not automatically erase records from requests already completed. Turning off app and campaign measurement stops future AppsFlyer client collection but does not automatically erase historical provider records. Resetting or deleting Pawfile does not cancel an Apple subscription and does not automatically erase records already held by Apple, Kie.ai, RevenueCat, AppsFlyer, Cloudflare, or the website/support providers. Because Pawfile has no account, there is no account to delete. For purchase or subscription records, email support with the Purchase Support ID shown in Settings. For AI or Live Activity records, include approximate dates, device details, and the exact issue; those systems use different short-lived identifiers and some completed provider jobs cannot be remotely deleted by Pawfile. We may need to verify the request, a provider may no longer be able to locate the record, and some records may be retained where legally required.
Website and support communications
Cloudflare and related network providers may process standard technical request data to deliver and protect this website and route support email. This site has no advertising, analytics script, contact form, or non-essential cookies. If you email support, we receive your email address and the information you choose to provide. Please do not send passwords, payment details, authentication codes, or unnecessary sensitive information.
Children
Pawfile is a general-audience pet app and is not designed to create child profiles or collect a child's contact information. Pet photos can incidentally include people. A parent or guardian should supervise a minor's use and ensure that any uploaded image is appropriate and authorized. Contact us if you believe a child provided personal information that should be removed.
Security
We use reasonable platform and service protections appropriate to the features described above, including encrypted HTTPS connections and the normal iOS app sandbox. No storage or transmission method can be guaranteed completely secure.
Changes
We may update this policy when the app, services, or legal requirements change. The current version and update date will appear on this page.
Contact
1001463290 Ontario Inc.
Jurisdiction: Ontario, Canada
Email: support@firesapps.com
Website: pawfile.firesapps.com