Privacy Notice
1. Controller and contacts (GDPR Articles 13–14)
Controller: JoCoding, Inc.
Privacy contact: mu07010@jocoding.net
Business form: Delaware corporation · Registered address: 1111B S Governors Ave, STE 80543, Dover, DE 19904, United States · Telephone: +1 (231) 450-5622 · Website: jocoding.io
Use the email above for a privacy request or complaint. We may request information needed to verify that the request comes from the account holder.
2. Service and data categories
Pawpal is a one-to-one letter app for couples, long-distance partners, best friends, and family. A shared dog carries text or drawing letters between two connected accounts. The app has no public feed, advertising profile, subscription, or public recommender. Additional dog breeds are optional one-time in-app purchases through Apple.
| Category | Examples and source | Purpose | Required? |
|---|---|---|---|
| Account and identifiers | Anonymous account ID, session data, Apple identity link | Create/authenticate the account and recover it after a device change. | Necessary for the service. |
| Device delivery data | Widget APNs token and Live Activity start token | Wake the iOS widget or start the Live Activity for a letter. | Only when the relevant system surface is used. |
| Purchase data | App Store transaction ID, product ID, purchase time, refund status; RevenueCat app user ID (the Pawpal account ID) | Grant, re-sync, and revoke optional breed unlocks. | Needed only if you buy an unlock. Payment-method details stay with Apple. |
| User content | Letter text and drawing | Store and deliver a letter to the connected person. | Needed to send a letter. |
| Connection data | Six-character invite code, couple/pet state, optional anniversary date | Connect two accounts, render the shared room, and calculate the day count. | Invite/connection data is necessary; anniversary is optional. |
| Safety report | Letter ID, reporter ID, fixed category inappropriate, body/drawing snapshot, creation time | Record a report and preserve content for safety review after the original letter is removed. | Created only when a user reports. |
| Product analytics | Typed event name and bounded values such as locale, app version, text/drawing presence, letter count, widget family, action, and limited failure kind | Understand reliability and feature use. | Release configuration currently enables it; there is no in-app opt-out. |
| Crash and diagnostic data | Privacy-sanitized exception level/type/handled state and bounded diagnostic values; user content, raw messages, and identifiers are removed before sending | Diagnose crashes and reliability problems through PostHog error tracking. | Legitimate interests in service reliability and security. |
Pawpal does not intentionally request name, email, telephone, address, precise location, contacts, photo library, camera, microphone, or payment information. Users may put personal or special-category information into a free-form letter; do not include information that is not needed.
The app does not request standard notification authorization. A Home Screen/Lock Screen Widget and Live Activity are optional iOS surfaces; APNs carries only a widget state-change or Live Activity start signal, not letter text. Their display depends on the user's system settings, available tokens, network, and iOS refresh rules.
3. Purposes and legal bases (Article 6)
| Purpose | Current legal-basis position | Data |
|---|---|---|
| Account, pairing, letter storage/delivery, widget/Live Activity delivery | Contract performance under Article 6(1)(b). | Account ID, session, couple state, invite code, content, device tokens. |
| Security, abuse prevention, report handling, and account deletion | Legal obligations and legitimate interests in service safety and security. | Authentication and connection data, report snapshot, operational records. |
| Breed-unlock purchase, restore, and refund handling | Contract performance under Article 6(1)(b); legal obligations for transaction records. | Purchase data listed above. |
| Product analytics | Legitimate interests in understanding feature reliability and use. Events use a fixed anonymous identifier and exclude letter content and account identifiers. | Event names, bounded event properties, and provider SDK metadata. |
| Crash/error diagnostics | Legitimate interests in reliability and security. Only privacy-sanitized fields pass the SDK boundary. | Sanitized exception shape/type/level/handled state and bounded diagnostic values. |
We do not intentionally process special categories under Article 9. A user-controlled letter can nevertheless contain such information, so sending it is the user's choice and responsibility.
4. Recipients, processors, and transfers
| Recipient/processor | Role and data path | Location / safeguard status |
|---|---|---|
| Cloudflare | Application server (Workers), database (D1), breed-pack file storage (R2), and a key-value cache for push provider tokens. | Cloudflare's APAC region, with no jurisdiction restriction configured. Transfers rely on Cloudflare's published data-processing addendum and transfer safeguards. |
| RevenueCat, Inc. | In-app purchase processing for optional breed unlocks (product lookup, purchase, restore). Receives the Pawpal account ID as app user ID, App Store transaction/receipt data, and standard SDK device metadata including IP address. | United States, under RevenueCat's published data-processing addendum and transfer safeguards. |
| PostHog | Release product analytics and privacy-sanitized crash/error diagnostics at https://us.i.posthog.com. Letter text, drawing coordinates, invite/couple/letter IDs, raw error messages, and identifiers are removed from the documented event/crash contract. | United States endpoint under PostHog's published data-processing terms and transfer safeguards. |
| Apple Inc. | Sign in with Apple, In-App Purchase payment (Apple is the merchant), and APNs for widget/Live Activity signals. | Apple processes data under its published service, privacy, and international-transfer terms. |
| Cloudflare and Google Fonts | Cloudflare serves this static notice/support site; Google Fonts serves its font stylesheet. | Website request metadata follows each provider's service settings. No site analytics or form storage is present in this source. |
Using Pawpal from the EU/EEA involves transfer to Cloudflare's APAC region, the United States analytics and purchase-processing endpoints (PostHog, RevenueCat), and potentially other Apple processing locations under the provider terms described above.
5. Retention and deletion
- Disconnect or block deletes the couple row, pet, and letters for that connection; block also prevents reconnection through that relationship.
- Account deletion removes the account's devices, preferences, invite attempts, blocks, couple data, sent letters, reports filed by that account, breed-unlock credits and purchase records, and the authentication account. For an account signed in with Apple, the server also asks Apple to revoke Pawpal's Sign in with Apple authorization. Unlocks bought for the deleted account cannot be moved to a new account.
- An ordinary letter remains in the database after it is read; reading does not automatically purge its text or drawing. The connection or applicable account-deletion path removes it, and no separate read-letter time-to-live is configured.
- A report snapshot with the fixed category
inappropriateis stored separately from the original letter for safety review. A snapshot filed by another account may remain after the reported author deletes their account. - After successful account deletion, the app clears pending Widget analytics from the App Group queue and resets the local PostHog identity/session. This does not automatically erase events already delivered to PostHog. Email mu07010@jocoding.net to request provider-side access, restriction, or deletion.
- Where a statutory retention obligation applies, data may be held separately for that period and then deleted or anonymised. No such app-specific statutory schedule is currently configured.
6. Access controls and operator access
Row-level security and server-side identity checks block ordinary users from another account's letters. Restricted service-role/security-definer paths process data for delivery, account deletion, and report handling, and the service role can read report snapshots for safety operations.
7. Data-subject rights
Subject to GDPR limits, you have the right to:
- access your personal data (Article 15);
- rectify inaccurate data (Article 16);
- erase data / ask to be forgotten (Article 17);
- restrict processing (Article 18);
- receive portable data (Article 20);
- object to processing based on legitimate interests (Article 21);
- request safeguards around automated decisions (Article 22); and
- withdraw consent at any time where consent is the legal basis (Article 7(3)).
Send a request to mu07010@jocoding.net. We will normally respond within one month, subject to identity checks and the GDPR extension rules for complex requests. The app also provides direct disconnect, block, and account-delete controls in Settings.
8. Automated decisions and profiling
Pawpal does not use profiling or an automated decision to determine a person's legal rights, eligibility, price, or access. The report action is a user-triggered safety action that immediately disconnects and blocks the reported connection; it is not an automated eligibility decision. Product analytics is measurement, not a decision about you.
9. Children and age
Pawpal is intended for people 16 or older worldwide and is not directed to children under 16. Age is not currently verified at sign-up. If you believe a child has supplied data, contact us and we will review deletion under applicable law.
10. Cookies and this website
This static site has no first-party analytics, advertising pixel, account form, or non-essential cookie in its source. The language preference is stored in browser local storage when available; it is not sent to the iOS app. The page loads Google Fonts, which causes the browser to request font resources from Google. Browser controls can block cookies or external resources.
11. Complaints and supervisory authority
Contact us first at mu07010@jocoding.net. You may also lodge a complaint with the supervisory authority in the EU/EEA country where you live, work, or believe an infringement occurred.
12. Changes
We will post changes on this page and state the new effective date. Material changes affecting EU/EEA rights will receive reasonable advance notice and renewed consent where required.
EU/EEA privacy contact
We handle EU/EEA privacy requests through this monitored support address.