Privacy Policy
Last updated: 10 September 2026
This Privacy Policy describes how Tailomi ("we", "us", or "the Application") collects, uses, shares, and discloses personal information when you use the Tailomi application.
1. Information We Collect
1.1. Information You Provide
When you use the Application, we collect personal information that you voluntarily provide, such as your name, username, email address, your pets' profiles, and photos you upload (for example, pet and profile pictures).
1.10. Hazard Reports and Watched Areas: If you report a map hazard (such as broken glass, a poisoned-bait risk, an aggressive dog, hazardous chemicals, or an open pit), we collect the hazard type, an H3 hexagon cell of about 150 metres around the location, and your account identifier; other nearby signed-in users can see the report, and confirming or dismissing it records their account identifier against that vote. Reports expire automatically between 14 and 180 days after they were last confirmed, depending on the hazard type. Separately, you may declare up to 5 areas you want hazard alerts for — for example your home, your workplace, or a parent's place — by choosing a location and an optional label; we store the H3 hexagon cell and label for each area against your account for as long as you keep it, with no automatic expiry, until you remove it or delete your account.
1.11. Air-Raid Shelter Contributions: If you add an air-raid shelter marker to the map, report that an air-raid shelter is no longer accessible, or mark an air-raid shelter as accessible with your dog, we record your account identifier, which specific shelter it was, the timestamp, and the type of contribution. You are recording this information against a shelter location, which may originate from official municipal data rather than a user contribution. These records are retained in your account unless you delete your account. Air-raid shelter locations in Kyiv come from an official municipal open dataset published by Київська міська державна адміністрація (Kyiv City State Administration) under a CC-BY license. Adding a shelter marker or reporting on one requires that your device report a location near the shelter at the time of contribution, using your client-reported GPS position; the application does not independently verify your physical presence at the location. Shelter-accessibility reports are visible to other signed-in users.
1.12. Walk-Together Invitations and Messages: If you invite another walker near you to walk together, we store that invitation with your account identifier, the recipient, the walk it referred to, the template you chose or the message you wrote (up to 140 characters), and, if you chose one, a public meeting place taken from the map and a meeting time. We separately record every invitation attempt you make, including attempts that were not delivered, for up to 90 days; that record exists only to enforce the invitation limits and is never used to tell you whether an invitation reached anyone. An invitation and its text are deleted within 24 hours. If the invitation is accepted, a short conversation opens and is deleted in full 24 hours after the acceptance. To send an invitation you must confirm that you are 18 or older; we store that confirmation and the time it was given, and we never ask for your date of birth. Once you have given that confirmation, every walk you start is marked as open to company automatically, without asking again. You can switch that off in the walk panel; we remember the choice and stop marking your later walks. If you have never confirmed your age, your walks are never marked.
1.13. Favourite Places: If you save a place to your favourites, we store the place identifier and the time you saved it against your account for as long as you keep it. Your favourites are private: no other user can see them, and they are not used for any counter or recommendation shown to others. Removing a favourite deletes the record at once, and deleting your account deletes all of them.
1.14. Place Corrections: If you report that a place on the map is closed, not welcoming to dogs or listed under the wrong category, we store that report with your account identifier, the place, the kind of problem and, for a category report, the category you suggested. Reporting requires you to be physically near the place, which we verify on our servers as for map contributions, and is available once your account is at least a week old and you have finished a walk. Other users see only anonymous counts of reports, never who reported; once three users agree, the map is corrected automatically and a record of the change (without reporter identities) is kept for our moderators. You can withdraw your report at any time, which deletes it; deleting your account deletes all of your reports.
1.15. Invite Codes: Every account has an invite code, which is the same public identifier other users already see on your profile. Opening an invite link stores that code on your device for up to 14 days; nothing is recorded on our servers until you confirm it in the app. When you do confirm it, we permanently record that your account was invited by theirs, together with the date. That link is used to send a friend request on your behalf, to pay you 100 Paw Coins after your first qualifying walk and, if the person who invited you is eligible under the limits below, 100 to them as well, to award them a badge for the number of people they invited, and to enforce a monthly limit on how many invites one person can be rewarded for. The person who invited you sees your name and profile in their list of invites, and you see theirs. An invite code can only be confirmed in the first 14 days of an account, and only once. Deleting your account deletes your side of the record; where you were the inviter, the record stays with your identity removed.
1.16. Lock Screen Walk Card (iOS): While a walk is in progress, Tailomi can show a card on the lock screen and in the Dynamic Island with your pets’ names, the elapsed time and the distance so far, and on iOS 17 and later a pause button. The card is drawn by the operating system from data that stays on your device; nothing is sent to our servers for it, and it never contains your position. Anyone looking at your locked phone can read the card, so you can turn it off in Settings → App Settings → Lock screen; it is on by default. The pause button is set to require the device to be unlocked first (Face ID, Touch ID or passcode).
1.17. Walk Weather: When you record a walk, our servers look up the weather for it so that weather-related achievements and titles can be awarded. To do that we send a weather provider, Apple Weather, the date and a point on a coarse grid of about five kilometres near where the walk took place; the request comes from our server, never from your device, and carries no account identifier, no exact position and no route. We make the same kind of lookup for a day on which you recorded no walk at all, using the grid point of your most recent walk, so that a day when going outside was dangerous does not break your walking streak. For users on Android this makes Apple a recipient of that coarse location as well. The provider’s hourly figures are kept on our servers for about 48 hours and then deleted, and the queue record of which grid cell and date was looked up for your account is deleted within seven days; what stays with the walk permanently is only a derived summary — bands of temperature and wind, minutes of rain, snow or fog, and whether conditions were extreme — never the provider’s raw data. Who can see this summary is described in clause 1.18. Weather lookups are part of recording a walk and cannot be switched off separately. Separately from that, if you leave the morning weather notification switched on, once a day our server looks up the forecast for the grid point of your most recent walk so it can tell you when conditions have got worse than the day before; that answer is used to write the notification and is then discarded, and switching the notification off in Settings stops the lookup itself, not just the message.
1.18. Weather You See in the Application: The Application shows weather in two places, and they work differently. The first is the weather of a walk you already finished: the derived summary described in clause 1.17, shown on your own walk and, for a friend who has turned progression sharing on, on that friend’s walk in your friends feed — the same audience that already sees that walk’s route and distance. A person who co-owns the pet with you also sees it, both on the walk itself and inside the pet’s activity insights, which draw on the walks of every family member. Nobody outside those two audiences sees it, and it carries no temperature more precise than a five-degree band. The summary is never written as text onto a card you export to another application, but the background of that card is chosen to match the walk’s weather, so an exported card does show broad conditions — rain, snow, fog, frost, heat or a clear sky — to whoever you send it to. Straight after a walk ends the summary is not ready yet, and the background is chosen from the current conditions instead. The second is the current weather and the forecast for the next twenty-four hours, which late in the evening means tomorrow morning rather than the rest of today. At the moment you open the map or the weather sheet, your device sends our server your position, our server rounds it to the same coarse grid of about five kilometres and asks Apple Weather for that grid point, and the answer is passed back to your device and kept in the memory of the running Application. Apple receives no account identifier, no exact position and no route. We also keep that answer on our servers for a few minutes, stored against the grid point alone, so that the next lookup for the same five-kilometre cell — yours or anyone else’s — can be answered without asking the provider again; that stored copy carries no account identifier, it stops being used after ten minutes, and it is deleted within half an hour. Separately, and with no place attached at all, we record that your account was answered such a request, how many were answered today and when the last one was, and we keep that record for the current day only — it is deleted once the day is over. A single setting in Settings → App Settings switches off everything in this clause: it hides both kinds of display and stops the requests of the second kind; switching it off does not affect achievements, titles or streak protection, which are computed on our servers from the walk summary in clause 1.17.
1.2. Content You Create
We collect content you create in the Application, such as reviews of places, pet information, and walk records. Reviews you submit may be visible to other users of the Application.
1.3. Usage Information
We collect information about how you use the Application, including your interactions, the features you use, and performance and reliability data (such as request timing and error information) used to keep the Application working correctly.
1.4. Device Information
We collect information about your device, including the device type, operating system version, unique device identifiers, push notification tokens, mobile network information, the time zone your device reports, and the language your device reports. We store that time zone and that language on your profile — the language is used only to pick the language of the notifications we send you — and, if you use the Dog Training feature, on each training session you log, so that daily features such as training streaks and reminders use your local day.
1.5. Location Information
We collect precise location information (via GPS), including while the Application runs in the background during an active walk, in order to record your walk route and provide location-based features. If you choose to share your live location with friends, your location is transmitted to those friends while sharing is enabled. While a walk is active, your shared location, display name, profile photo, the pets on that walk, and whether that walk is marked as open to company are also visible on the map to other signed-in users near you, including users you are not friends with; this stops when the walk ends, and turning off live location sharing removes you from that map. Separately, for up to seven days after a walk, the fact that you walked in a given city, together with your display name, profile photo, pets and the day you walked, is visible to other signed-in users of the Application, not only to users physically near you; this never includes any coordinate. Turning off live location sharing does not remove you from that seven-day city list: the list is derived from the walk you recorded, not from your live position. The setting that removes you from it is "Hide me from nearby walkers", and that setting takes effect only while you have an active Tailomi Plus subscription; without an active subscription the only way not to appear in the city list is not to record walks. When you send a walk invitation to a friend, you may optionally include a precise meeting location, which we store with that invitation. Background location tracking only occurs while a walk is active, and you can stop it at any time.
1.6. Subscription Information
If you purchase a Tailomi Plus subscription, we collect and store your subscription status, the product purchased, its expiry date, the app store the purchase was made through, and identifiers for the related purchase events. We never receive or store your payment card details; payment is processed by the app store. Some features that require an active subscription, such as hiding yourself from the nearby-walkers map, stop taking effect while your subscription is inactive and take effect again if it resumes; a billing event never changes the settings you saved.
1.7. Training Content
If you use the Dog Training feature, we collect the training sessions you log for your pet, including the skill, level, outcome, and the date and time zone of each session. If you choose to share a skill-mastery achievement with your friends, we collect the photo and the caption (up to 280 characters) you attach to that post.
1.8. Content Reports
If you report another user's content, such as a shared training post, we collect your identity as the reporter, the type of content reported, and any details you choose to provide, up to 500 characters. We use this information to review the report and, where warranted, restrict the reported content's visibility; we do not share your identity as the reporter with the user whose content you reported.
1.9. Map Contributions
If you add a place to the map, such as a water fountain or a bag dispenser, we collect the coordinate you were physically near and the category you chose, and we publish that submission publicly and permanently on the map for every signed-in user to see. We also store the H3 hexagon cells covering that coordinate. When you or another user confirms a contributed place or marks it as no longer there, we record that vote against your account. Adding a place or voting on one requires you to be physically near the location, which we verify on our servers using your recent walk or live-location data. Separately, when you complete a qualifying walk (at least 500 metres and 10 minutes), we derive and store a coarse record of the areas you walked in, at a resolution of about 170 metres, against your account for about 8 days. We use this record only to show other users an anonymous count of how many people walked near a place; we never show who walked there, and we only show a count once at least 3 other people qualify.
1.9a. Place Addresses: When you open the card for a vet, pet store, groomer, boarding, dog trainer or dog-friendly venue, your device asks the map provider on your platform (Apple on iOS, Google on Android) to turn that place’s own published coordinate into a street address. The coordinate we send is the place’s, never yours, and we never send your identity or your account. We do not store the result on our servers; it stays on your device. Places that are not buildings — parks, dog parks, drinking water, bag dispensers and air-raid shelters — are never geocoded, and neither are hazard reports or meeting points.
2. How We Use Your Information
2.1. We use the information we collect for the following purposes:
- Providing and improving the Application, including GPS walk tracking and maps;
- Enabling social features, such as sharing your live location with friends you approve and sending walk invites;
- Showing nearby pet-friendly places and place reviews;
- Sending push notifications you have enabled;
- Communicating with you and responding to your inquiries;
- Detecting, preventing, and addressing technical issues;
- Complying with legal obligations.
- Showing walkers near you on the map while a walk is active, and showing you to them;
- Providing, restoring, and managing Tailomi Plus subscriptions;
3. How We Share Your Information
3.1. We share your personal information only in the following circumstances:
- With other users: your profile and, if you enable location sharing, your live location are shared with the friends you have approved. During an active walk, that same live location, your display name, profile photo, and the pets on the walk are also shown to other signed-in users near you who are not your friends. If you share a skill-mastery post from the Dog Training feature, its photo and caption are visible to your approved friends until you remove the post or it is hidden through content moderation. Reviews you post may be visible to other users.
- Walk invitation meeting points: When you send a walk invitation to a friend, you may optionally attach a precise meeting location (GPS coordinates), a short label, and a meeting time. This location is precise and is not coarsened by your live location sharing setting. It is shown to the person you invited, and it stays readable to the two of you for no longer than 24 hours after the invitation was last changed. We erase the meeting location, label, and time within 24 hours and 15 minutes of that change; we erase them immediately if either of you removes the other as a friend; and they are deleted together with your other data when you delete your account.
- Walk-together invitations: the invitation you send, its text and the meeting place you chose are shown to the person you invited. Whether they accept, ignore or refuse it is never disclosed to you. If they accept, the messages the two of you exchange are visible only to the two of you and are erased 24 hours after the acceptance.
- Pet photos and pet profile links: the photos you add to a pet are stored privately and are shown to the people who can already see that pet — the members of that pet’s family and, while “Share progress with friends” is switched on, the friends you have approved. When you share a pet profile link, any Tailomi user who holds that link can open the profile together with its photos; the link works for 30 days from the moment you share it and sharing again replaces it, so only the newest link opens; it also shows photos you add after you shared it, and it stops working when those 30 days pass, when you share a new link, or when the pet is deleted. One exception: if you post a pet profile to the friends feed, that post keeps opening the profile and its photos for the friends you have approved regardless of the 30 days and of any newer link, and a post cannot be taken back — it goes only when the pet or your account is deleted. Removing a photo removes it for everyone. When you delete your account, the photos of a pet owned only by you are deleted along with the rest of your data; if that pet is co-owned with a family member, the pet and its photos stay with the household and are disassociated from your account, as described in section 9.2.
- With service providers: we use trusted third parties to operate the Application, including Supabase (database, authentication, and storage hosting), Google Maps (map display on Android, and turning a place’s own coordinate into a street address on your device), Apple (map display on iOS, turning a place’s own coordinate into a street address on your device, App Store purchase processing, the Apple Push Notification service, APNs, and Apple Weather, which supplies the weather for your walks as described in clause 1.17), OpenStreetMap data providers (independently operated Overpass API servers in the European Union that supply information about nearby pet-friendly places; the request is sent by our servers rather than your device and carries only a coordinate rounded to about one kilometre, never your precise position, your identity, or your account), RevenueCat (subscription management and purchase validation), Brevo (delivery of account emails such as sign-in and password-reset messages), Google Firebase (Firebase Cloud Messaging, FCM, for push notifications), and Sentry (crash and error diagnostics: when the Application crashes or hits an unexpected error, we send Sentry the technical details of the failure — the error type and message, the code stack trace, the app release, and your device model and operating system version. We strip the structured context of the event and redact e-mail addresses, coordinates, map cells, identifiers and links out of the error text before sending, so this report is not a route by which your name, your email address, your position or the map cells you have visited reach Sentry). If you sign in with Google or Apple, that sign-in is processed by the provider you chose. To manage your subscription we send RevenueCat your account identifier together with the purchase receipt from the app store and basic device information; we do not send it your name or your email address. A push notification may include the name of the friend who triggered it and your device push token. These providers process data on our behalf to provide their services.
- Website and support correspondence: our website and legal pages are hosted by Cloudflare, which also routes email sent to our support address. If you contact us by email, Cloudflare and our email provider process that message, including your email address and anything you choose to include in it.
- As required by law or to protect our rights, safety, and the safety of others.
- With your consent or at your direction.
We do not sell your personal information, and we do not use it for third-party advertising or tracking.
4. Data Security
4.1. We take reasonable measures to protect the security of your personal information and prevent unauthorized access, disclosure, or alteration. However, please note that no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
5. Children's Privacy
5.1. The Application is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us, and we will take steps to remove the information.
6. Your Rights and Choices
6.1. You can control location sharing at any time from your device settings and within the Application. You may request access to, correction of, or deletion of your personal information, including deletion of your account, by contacting us at the address below.
7. Changes to This Privacy Policy
7.1. We may update this Privacy Policy from time to time by posting a revised version on our website or within the Application. We encourage you to review this Privacy Policy periodically for any changes. Your continued use of the Application after the posting of changes constitutes your acceptance of such changes.
8. Contact Us
8.1. If you have any questions or concerns about this Privacy Policy or our privacy practices, please contact us at support@tailomi.app.
9. Data Retention and Deletion
We retain personal information we collect from you for as long as we need it to fulfill the purposes for which it was originally collected, unless otherwise required by law. When personal information is no longer needed, we will delete or anonymize it in a secure manner. When you delete your account, your subscription record is deleted from our database together with the rest of your data, and we ask our subscription management provider to delete the subscriber record associated with your account.
9.2. Retention on Shared Pets After Account Deletion
If your pet is owned only by you, deleting your account deletes that pet's photos, your training sessions, skill-mastery titles, and skill status records for that pet along with the rest of your data. If your pet is co-owned with another family member, those same records stay attached to the pet so the household does not lose its pet's history, but they are disassociated from your account: your user identifier is removed from them and cannot be restored.
9.3. Retention of Map Contributions After Account Deletion
Places you added to the map stay on the map after you delete your account, since other users may rely on them, but they are disassociated from your account: your user identifier is removed from them and cannot be restored. Your votes on other users' places are deleted along with the rest of your data.
By using the Application, you consent to the collection, use, and disclosure of your information as described in this Privacy Policy.