Skip to content
Pawsport
Back to Pawsport

Privacy Policy

Last updated: September 6, 2026

Curious Cat Consulting, LLC builds Pawsport. This policy explains what the app stores, which parts of it other people can see, and the services that receive limited information. A stamp you save is meant to be seen on the shared map. Everything else about you stays between you and us.

1. What we store, and why

Pawsport keeps your collection on our servers so it survives a lost phone. Here is what we hold.

Your account

If you sign in with an email link, we store your email address. If you sign in with Google or Apple, we store the account identifier those services give us, and the email address they pass along. Guest accounts have neither: they are an anonymous identifier and nothing else, which is what makes them impossible for us to recover.

Your stamps

  • The photo you took, re-encoded and resized, along with the sticker cut-out and two thumbnails made from it
  • The name, type, and description you typed, all of which are optional
  • The coordinates, rounded to two decimal places, plus the country and region we resolve from them
  • When you created the stamp, and when you last edited it

Everything else

  • Which achievements you have earned and how far along you are on the rest
  • The reactions you have left on stamps, yours and other people’s
  • Whether you have an active Purrfect Pro entitlement

Your theme, your onboarding progress, and your signed-in session are written to storage on the phone rather than to our servers.

2. The map is shared, so approved stamps are public

Pawsport has one world map, and everyone using the app looks at the same one. A stamp that has passed review is visible to every other person using the app.

What they see is the sticker or photo, the name and type and description you gave it, and its rounded location. They can react to it. What they do not see is your email address, your name, or any way to reach you: a stamp carries no author on it and there is no profile to open.

Stamps are reviewed before they go on the shared map. Until then, only you can see yours. If you delete a stamp it comes off the map immediately, and the photo, the sticker, and the thumbnails are deleted with it.

Please treat a stamp as something you are publishing. Do not photograph a cat somewhere you would not want a location published, and do not put anything in the name or description you would not want read.

3. Location

Location is optional. Deny the permission and the app still works: a stamp saves to your catalog and your passport, it simply has no place to sit on the map.

When you do allow it, the app takes either the coordinates recorded in the photo or the current reading from the phone, and rounds both to two decimal places before saving. That is a square of roughly a kilometer on a side. The unrounded reading is not sent. We also resolve a country and a region from the rounded point and store those, which is what the stats screen counts.

4. Where the photos live

Photos, stickers, and thumbnails go into a storage bucket at Supabase, our hosting provider, under a folder named with a random identifier generated on your phone. Only you can write to your own folder.

Reading works differently. The bucket serves images over ordinary web addresses, so anyone holding the exact address of one of your images can open it without being signed in. Those addresses are random and are not listed anywhere, and they are also not a secret. Most photo apps work this way, because it is what makes a feed render quickly.

The photo we store is not the file your camera produced. The app resizes and re-encodes it before upload, which drops the camera metadata, including the precise GPS coordinates a photo normally carries.

5. What leaves the app, and who receives it

Four services receive something. None of them receives your photos except the one that stores them.

Our backend (Supabase)

Supabase hosts the database and the storage bucket described above, and runs the sign-in. Everything in section 1 lives there. Access to your rows is enforced by row-level security, so one account cannot read or write another account’s data.

Product analytics (PostHog)

Released versions of the app send product analytics to PostHog, which is how we see which features get used and where people get stuck. The event names are a fixed list in the source and each event carries a fixed set of properties, so there is no route by which your content could end up in one.

When you sign in, we tell PostHog your account identifier, your email address, and the name on your account, so that support conversations and bug reports can be tied to the right person. Guest accounts send only the anonymous identifier. Signing out resets it.

The events themselves are counts, yes-or-no facts, and coarse categories: that a stamp was created, whether it had a sticker, whether you filled in the name field, which country and region it landed in, which reaction you tapped, and which screen prompted the upgrade sheet.

We never send the name, the type, or the description you typed. The app records only whether each field was filled in. Photos and stickers are never sent to PostHog at all.

The app also reports crashes and errors so we can fix them, records which screen you are on by its route name, and records which control you tapped. Session replay is switched off, so no recording of your screen is ever captured. Analytics are disabled entirely in development builds.

Support chat (Crisp)

If you start a support conversation, the messages you send are processed by Crisp, our support chat provider, so that we can reply. The app also sends Crisp an identifier your operating system provides for this app on this device, so a conversation stays continuous across sessions. Anything you type or attach in a support chat is visible to us, so please do not paste anything into it that you would not want us to read.

Purchases (RevenueCat, Apple, Google)

Purrfect Pro is sold through the App Store and Google Play, and RevenueCat tracks whether your subscription is active. We give RevenueCat your account identifier so the entitlement follows you to a new phone. Your payment goes to Apple or to Google, never to us, and we never see your card number, your billing address, or your store account.

6. Permissions

Pawsport asks for three permissions, and every one of them is optional.

  • Camera, to photograph a cat. Decline it and you can still pick photos from your library.
  • Photo library, to pick a cat you have already photographed. Decline it and you can still use the camera.
  • Location, to place a stamp on the map. Decline it and stamps still save, without a place on the map.

The app does not ask for contacts, push notifications, or your microphone. You can change any of these later from the Permissions section of your profile, which opens your device settings.

7. How your data is protected

Traffic between the app and our backend runs over TLS, and the database is encrypted at rest by our hosting provider. Row-level security policies decide what each account can read and write, and those run on the server, so a modified copy of the app cannot get around them.

The one place to be careful is the storage bucket described in section 4: an image address that leaves your control works for whoever ends up with it. Deleting a stamp deletes the underlying files, which is the way to withdraw one.

8. What we never do

  • We do not sell your personal information, and we never have.
  • We do not display advertising, and we do not embed advertising networks in the app.
  • We do not build advertising profiles or track you across other apps and websites.
  • We do not send the text you type about a cat to our analytics provider.
  • We do not attach your name or email to a stamp anyone else can see.

9. Deleting your data

Any stamp can be deleted from its passport card. That removes the row, the photo, the sticker, and the thumbnails, and takes it off the shared map.

Delete Account, under Data in your profile, asks you twice and then deletes your account together with your stamps, your achievements, and your reactions, and takes every one of your stamps off the shared map. It cannot be undone and we cannot restore it afterwards.

A guest account is worth one warning of its own. It has no email on it, so if you delete the app, reset the phone, or move to a new one, those stamps are gone and there is nothing we can look them up by. Linking an email, a Google account, or an Apple account carries your existing stamps over and fixes that.

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, or to object to certain processing. Deleting your account satisfies most of them immediately. For anything else, write to us and we will honor your request as the law requires.

10. Children

Pawsport is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account or sent us a support message, contact us and we will delete it.

11. This website

This site is a static marketing site. It sets no advertising cookies and runs no advertising trackers. It uses Vercel Analytics, which counts page views without cookies and without building a profile of you. If you open the chat on the support page, that is the same Crisp service described above. If you send us a feature request, the form is handled by Formspree and reaches us as an email, including your email address if you chose to give one.

12. Changes to this policy

If we change this policy we will update the date at the top of this page. If a change materially affects how information is handled, we will note it in the app’s release notes as well.

13. Contact us

Questions about this policy or about your data can go to support@curiouscat.consulting, or through the chat on our support page.

Curious Cat Consulting, LLC