Your data, plainly
Privacy Policy
This policy explains what data Canipattes uses, why it is needed and how you stay in control.
1. Data controller
The controller for the processing described in this policy is the publisher of Canipattes, established in France.
For any question about your personal data, or to exercise your rights: contact@canipattes.fr.
2. Data used and purposes
| Context | Data concerned | Purpose | Legal basis |
|---|---|---|---|
| Local use | Owner's first name and photo, dog profiles, sex, age, weight, care records, documents, walks, GPS tracks, statistics, photos, memories, settings and progress. | Provide the tracking, walking, health and personalisation features you asked for. | Performance of the requested service. |
| Optional account | Email address, hashed password or Google identifier, verification status, creation date, referral code and session information. | Create the account, allow sign-in, secure access, attach the subscription and give access to online services. | Performance of the contract and legitimate interest in security. |
| Community profile and friends | Community name, opaque public reference, worn style, relationships, invitations, blocks and the deliberately synchronised summary of your dogs: name, sex and year of birth. | Display your community identity, connect members, and share a dog summary with accepted friends only. | Performance of the requested service and legitimate interest in preventing abuse. |
| Leaderboard and trophies | For each qualifying walk: a unique identifier, a pseudonymous installation identifier, UTC date and times, effective duration, distance, an anonymous key for each dog and its activity-target level. Active days, XP, rank, public trophies and unlocked or equipped styles are also processed. | Recompute progress on the server, prevent duplicate credit or XP changes through an edited backup, produce the weekly leaderboard and present community rewards. | Performance of the requested service. |
| Walking spots | Name, country, region or city, manually placed coordinates, attributes, confirmations, reports, uploaded photo and the author's identifier. | Publish, document, illustrate and moderate public walking spots. | Performance of the requested service and legitimate interest in moderation and safety. |
| Meet-ups | Chosen spot, date, time, duration, public or private visibility, organiser, participants, replies and preset phrases. | Organise an open walk or invite friends to a meet-up agreed in advance. | Performance of the requested service. |
| Discussions | Topics, comments, reactions, subscriptions, edits, reports, moderation status and the author's community identity. | Run the forum, notify replies, handle reports and carry out moderation. | Performance of the requested service and legitimate interest in moderation and member protection. |
| Subscription | Plan, Premium status, expiry date, product identifier and a technical fingerprint of the purchase receipt. | Verify Premium entitlements, manage the plan and prevent fraudulent use. | Performance of the contract and legal obligations. |
| Notifications | Firebase token, technical device identifier, preferences, daily counter and the information needed for the message. | Send the reminders you enabled and useful account or Community events, within the limit set by the service. | Your choice to enable notifications, and performance of the service. |
| Security | Hashed session tokens, device fingerprint, IP address, last activity date and sign-in attempts. | Protect accounts, limit attacks and detect unusual sign-ins. | Legitimate interest in security. |
| Survey or trial offer | Answers provided, participation date and any Premium benefit granted. | Collect your feedback and administer the announced benefit. | Your consent and performance of the offer. |
Canipattes does not collect your payment card details. Payment is handled by Google Play, under Google's terms and privacy policy.
Community data is either provided by you or computed from the local data strictly necessary for the feature you enabled. Canipattes does not sell your personal data.
3. Data kept on your phone
Full dog profiles, health records, attached documents, private photos, memories, walks, GPS tracks and display preferences are stored locally in the app's private storage. They are not copied as such into the Canipattes account database.
This does not cover what you choose to use in the Community: the limited dog summary sent to friends, the minimal events used to calculate the leaderboard, your community name, spots, spot photos, meet-ups and posts. Those are described separately below.
Canipattes also excludes this data from Android's automatic backup and from automatic device-to-device transfer. Keeping it therefore depends on your phone and on the exports you choose to make.
ZIP export from the settings
When you use Export my data, the app creates a ZIP file at the location you pick in the Android file chooser. That file is not uploaded to any Canipattes or IONOS server.
The export can contain sensitive data, including photos, health documents and location tracks. Keep it somewhere safe and only share it with a person or service you trust. If you place it in a cloud service yourself, or send it to a third party, that transfer is governed by the service you chose.
To limit backup exchanges between accounts, the export is tied to the signed-in account and restoring it requires that same account.
4. Community: visibility and control
The Community requires an account. What is visible depends on the action taken and on the link between members; it never gives access to your email address, your current location, your GPS tracks, your health records or your private documents.
| Item | Who may see it |
|---|---|
| Limited community profile | Your friends and the members who meet you in the same weekly leaderboard, a discussion or an open walk: name, style, month of joining, XP, rank and public trophies. |
| Dog summary | Accepted friends only: name, sex and approximate age. |
| Published spot and approved photo | Members searching within the relevant radius, their selected area, or spots shared by their friends. |
| Open walk | Members within the chosen community perimeter; confirmed participants are visible on the meet-up page. |
| Private invitation | The organiser and the invited friends, with limited visibility of the other participants' replies. |
| Topic or comment | Members signed in to the Community, together with the author's community name. |
You can remove a relationship, block a member, report a spot or a post, and delete your own content where the app allows it. Authorised administrators access the content and reports needed for moderation.
Minors
A minor may use the Community on their own from the age of digital consent that applies where they live — between 13 and 16 in the European Economic Area, and 15 in France. Below that age, enabling and using the Community requires the agreement and supervision of a parent or legal guardian. Information concerning minors is written so as to remain understandable; either the parent or the minor may exercise the rights described in this policy.
5. Location, GPS track, public spots and weather
Precise location is used during a walk to draw the route, compute the distance and help resume an interrupted walk. The full track stays stored locally on your phone.
In the Community, the optional “Near me” mode uses approximate location once to search for public spots and walks within the chosen radius. Before it is sent, the centre is rounded to approximately one kilometre; it is used only for that request and is not saved to the account, linked to the profile, or shown to other members. A manually selected area remains stored on the phone only.
Publishing a community spot is a separate action: you manually place on the map the coordinates of a place you consider public. Canipattes never pre-fills that point from your position, a walk or a track, and never shares any live location. An organised walk shares an agreed point and time, not where the participants actually are.
To show local weather and adapt outing advice, the current coordinates needed for the request are sent to Open-Meteo. Canipattes does not add them to your online account. Open-Meteo may nonetheless process the IP address and coordinates it receives under its own terms.
Maps are provided by Mapbox. The Mapbox SDK may process technical, usage and location data according to its settings and privacy policy. You can refuse or withdraw the location permission in your Android settings; the features that depend on it will then no longer be available.
6. Android permissions
- Precise or approximate location: weather display, GPS tracking of walks and, after an explicit action, “Near me” Community discovery.
- Foreground location: continuity of tracking while a walk is active and the screen changes.
- Physical activity: step estimation where the phone and Android allow it.
- Notifications and vibration: the reminders you chose, the weekly report, trophies and the ongoing-walk notification.
- Device boot: rescheduling reminders you had already enabled after a restart.
- Photos and documents: use of the camera or the Android picker when you add a memory, a profile, a receipt or a community photo.
Permissions are requested at the moment a feature needs them. You can change them at any time in your Android settings. Some features may then become unavailable or less accurate.
7. Third-party services and recipients
Canipattes limits data exchanges to the providers needed to run the service. Those providers process their own technical data under their own policies.
Depending on the features you use, the other recipients are the members allowed to see your profile or your posts, and the administrators responsible for moderation, security and support. Information is not made accessible to people outside the Community through the application's public API.
| Service | Role | Data that may be processed |
|---|---|---|
| IONOS | Hosting of the API, the database and community files. | Account, subscription and Community data, approved photos, sessions and security logs. |
| Google Sign-In | Optional sign-in with a Google account. | Google identifier and the information needed for authentication. |
| Google Play | Payment and subscription management. | Product purchased, status and technical purchase receipt. Payment card details stay with Google. |
| Firebase Cloud Messaging | Delivery of Android notifications. | Notification token, technical application and device information. |
| Mapbox | Map display. | Technical, usage and location data that the SDK may collect. |
| Open-Meteo | Local weather data. | Request coordinates, IP address and associated technical data. |
Some of these providers may process data outside the European Economic Area. Where that happens, the transfer relies on the legal mechanisms declared by the provider concerned, in particular adequacy decisions or standard contractual clauses.
8. Retention periods
- Local data: until you delete it in the app, reset the data, or uninstall.
- Account: for the life of the account, then deleted or kept in limited archive where a legal obligation requires it.
- Community profile, friends, shared dogs, progress and styles: for the life of the account, or until the item is withdrawn where a withdrawal option is offered.
- Spots and approved photos: visible for as long as the spot stays published. After removal by the author or by moderation, items may remain inaccessible to members for the life of the account where they are needed to handle a report. They are deleted along with the account.
- Pending photos: until the moderation decision. The file of a rejected photo is deleted; its status may stay attached to the account in order to administer uploads.
- Meet-ups and replies: they stop being displayed six hours after the scheduled time, then are deleted on the first run of the housekeeping job occurring from 90 days after that date.
- Published discussions: for as long as the topic remains useful and published. If the account is deleted, topics and comments may stay readable under "Deleted account", with no link to the deleted account, so that conversations remain understandable.
- Reports and moderation actions: for as long as needed to review them, prevent abuse, keep the service safe and defend the rights of Canipattes or of its members.
- Session: up to 180 days maximum, unless signed out, revoked or deleted earlier.
- Email verification code: 30 minutes.
- Subscription and transaction data: for the duration of the contractual relationship, then for as long as needed to meet accounting and tax obligations and to handle disputes.
- Security logs and sign-in attempts: for the period strictly necessary to protect the service.
- Notification tokens: until they are invalidated, the service is disabled, or the associated account is deleted.
9. Deleting your account and your local data
To delete your Canipattes account, open the app and go to Settings → Privacy → Delete my account. If you no longer have access to the app, send your request to contact@canipattes.fr from the email address associated with your account.
This immediately deletes your account, sessions, relationships, shared dogs, progress, meet-ups, spots, community photos and attached subscription information, subject to anything a legal obligation requires to be kept temporarily. It does not automatically delete the data still held on your phone (dog profiles, walks, private photos, health records, journal).
Topics and comments already published may be kept without any link to the account and shown under "Deleted account", so that conversations do not become unintelligible. You can delete your posts individually before deleting your account, or ask for a review of content that still contains personal data about you.
Conversely, resetting local data or uninstalling the app does not automatically delete your online account. To erase everything, use account deletion and the local reset offered in the app, one after the other.
10. Your rights
Depending on your situation, you have rights of access, rectification, erasure, restriction, objection and portability. Where processing is based on your consent, you may withdraw it at any time without affecting processing already carried out.
Send your request to contact@canipattes.fr. Proof of identity may be requested only where there is reasonable doubt about who is making the request. You will receive an answer within the time limits set by the GDPR.
You may also lodge a complaint with the supervisory authority of the country where you live. As the controller is established in France, you may address the CNIL.
A minor may exercise the rights relating to their data. Their parent or legal guardian may also act on their behalf, under the conditions set by the applicable rules.
11. Security
Canipattes applies measures designed to protect accounts: hashed passwords, session tokens stored as fingerprints, rate limiting on sign-in attempts, server-side checking of Premium entitlements and the ability to revoke sessions.
Community profiles use a public reference distinct from the internal identifier. Spot photos are re-encoded before storage to strip embedded metadata, including EXIF and GPS, then placed in an area that is not publicly reachable until they are approved. Sensitive actions are checked server-side, and content can be reported, hidden or removed by authorised administrators.
No system offers absolute security. Protect your phone, use a unique password, and keep your exports somewhere only you can reach.
12. Changes to this policy
This policy may change when the app, its providers or the applicable rules change. Where a change is significant, clear information will be shown in the app or on the site.
Last updated: 15 August 2026.