Privacy Policy
Version 2.3 — updated September 15, 2026
This policy explains what personal data the Awuu app collects, what it is used for, where it is stored, and what your rights are under the EU General Data Protection Regulation (GDPR).
1. Data controller
Toiminimi Mikko Lakonen (sole trader), Business ID 1976242-7 (developer of the Awuu app)
Email: privacy@awuu.app
2. What data we collect
- Account data: your email address and sign-in method. Passwords are stored only as a secure hash. If you sign in with a Google, Apple, or Facebook account, we receive your name and email address from the sign-in provider (and, with Facebook sign-in, your Facebook user ID).
- Profile data: the owner's name and an optional owner photo, plus your dog's details: name, breed, date of birth, gender, size, energy level, description, personality tags, city, profile photo, and optional kennel name and Instagram username.
- Location: we store an approximate location in the dog profile, used for the map view, for showing nearby content, and for targeting danger alerts (see section 3). A random offset of about 200–500 metres is always added to the stored location, so your exact location is never stored or shown to others. This applies both to the location given when creating the profile and to any later update. The app may suggest updating your location if the device's location clearly differs from the stored one (automatic location update). The city name is resolved from the coordinates using the device operating system's geocoding service or the OpenStreetMap Nominatim service (see section 5). Location is used only while the app is open; there is no background tracking.
- Messages: private and group chat messages. Messages are end-to-end encrypted, meaning their content cannot be read on the server. The server does, however, hold message metadata: the sender, timestamp, the conversation the message belongs to, whether it was edited or deleted, reactions, and a reply reference. Exception: if a participant in the conversation reports a message as inappropriate, the reported message and its surrounding messages are stored without end-to-end encryption for review by the moderators. Images shared in chats are stored in the service's file storage without end-to-end encryption, but visible only to the conversation's participants. If a message contains a link, your device fetches the preview (title and image) directly from the linked page, so the operator of that page sees your device's IP address; Awuu's server is not involved in the fetch.
- Events: events you create (including the event location and cover image), your event participations, and a counter of events where your attendance was confirmed. For photos you upload to an event's gallery, we store whether you have given permission to publish the photo on Awuu's social media accounts (see section 3).
- Danger alerts and sightings: if you report a danger (loose dog, dangerous place, poisoned bait, or other danger), we store the alert type, the danger's location (the map point you choose), the severity, the description, an optional photo, and the creation time. The alert is shown to other users on the map without the reporter's details; the moderators can see the reporter. Other users can confirm the alert, add sightings to it (location, optional photo, and time), and follow it; this data is stored too. If you report your own dog as lost, your dog's breed and profile photo are attached to the alert, and your profile name and photo are shown in the alert only if you give separate permission when creating it. Repeated reporting in the same area (at least 3 alerts within a 250-metre radius in 7 days) creates an automatic flag for moderator review; there are no automatic sanctions.
- Images: profile photos, event cover images, event gallery photos, danger alert and sighting photos, and images shared in chats. Profile photos, cover images, gallery photos, and danger alert photos are stored in public storage: anyone who has the image's address can view it, but the addresses are not published outside the app. Chat images are restricted to the conversation's participants. All uploaded images are automatically pre-screened for inappropriate content before storage (see section 5, OpenAI), and a record is stored for each pre-screening: your user identifier, the upload context (e.g. profile photo), the result, and any flagged content categories — not the image itself.
- Notification token: the device's push notification token, used to deliver notifications.
- Moderation data: if you report an inappropriate message, user, profile, or danger alert, the reported content (the message and its surrounding messages, the profile's name and bio, or the danger alert's details) and the reason for the report are stored without end-to-end encryption so that the moderators can handle the report. Reported text is automatically pre-screened with OpenAI's moderation API (see section 5), and the result is stored with the report. If the moderators restrict your messaging for a fixed period or close your account, the restriction's status and end time are stored in your profile.
- Blocks: the list of users you have blocked. It is used only so that a blocked user cannot see you or message you; the blocked user is not informed.
- Feedback: if you answer the app's feedback survey, we store your rating (1–5), your free-text comment, the survey context (after an event or from the Account tab), the app version, and the device platform.
- Preferences: your language setting.
- Technical error data: if the app crashes or a technical error occurs, the error report includes the device model and operating system version, the app version, a technical description of the error and its stack trace, your internal app user identifier (a random identifier, not your email address or name), and a short trail of events before the error (screen changes and network request paths without parameters). Message contents, email addresses, and encryption keys are never sent — they are filtered out before sending.
- Update check: on launch, the app checks whether updates to the app code are available. The request includes the device platform, the app version, and a random installation identifier; no personal data is transmitted.
- Advertising-related data: the app shows ads, and Google AdMob may process technical information about your device and — only with your consent — the device's advertising identifier to display and personalize ads. We do not link your profile data to advertising ourselves. In addition, the app records anonymous usage statistics about ad display: the ad's placement in the app, the platform, the app version, whether the ad was displayed, viewed or clicked, and the ad network's estimate of the impression's value. The statistics contain no user or device identifier; they are identified only by a per-launch random number that is not stored on the device and is not linked to your profile. The statistics rows are deleted after 90 days.
- Newsletter subscribers: if you join the Awuu mailing list on awuu.app or from the app's settings, we store your email address, your chosen language, when and where you signed up (e.g. the home page or the app), and when you confirmed. The address is stored only after you confirm it from the link sent to your email. The mailing list is separate from account data: you can be on the list without an account, and have an account without a subscription. To prevent abuse, your IP address is processed temporarily when you submit the form (request rate limiting and bot check); it is not stored with the list.
3. How the data is used
- Providing the service: displaying profiles, finding dog friends and events, messaging, and push notifications (legal basis: contract).
- Danger alerts: a push notification about a new danger alert is sent to users whose stored profile location is near the danger — within a 5-kilometre radius, or 10 kilometres for poisoned bait alerts. The alert's followers and its creator are notified of new sightings (legal basis: contract).
- Safety and moderation: handling inappropriate content and preventing misuse (legal basis: legitimate interest).
- Service emails, such as sign-up confirmation and password reset (legal basis: contract).
- Ensuring the service works and improving its quality: reporting and fixing crashes and technical errors, and processing feedback survey responses (legal basis: legitimate interest).
- Marketing with consent: if you give separate permission in the event gallery, Awuu may publish the event photo you uploaded on Awuu's own social media accounts (Instagram) and mention the Instagram username stored in your profile alongside the photo (legal basis: consent). You can withdraw your consent at any time by contacting info@awuu.app, after which the photo is removed from Awuu's accounts.
- Newsletter with consent: subscribers to the mailing list receive the Awuu newsletter about new features, tips and other current topics — for example notice of the app's release on the app stores (legal basis: consent). You can withdraw your consent at any time via the unsubscribe link in every message or by writing to info@awuu.app.
- Advertising: the app shows ads served through Google AdMob. Personalized ads are shown only if you give consent in the app's consent dialog (legal basis: consent); otherwise ads are non-personalized. You can change or withdraw your consent at any time under Ad settings on the app's Account tab.
- Monitoring ad performance with anonymous statistics (legal basis: legitimate interest).
Your data is not sold to third parties. Your profile data (such as your dog's details or location) is not shared with the ad network.
4. Where the data is stored
Data is stored with Supabase in the eu-central-2 region (Zurich, Switzerland). Switzerland is not an EU member state, but it is covered by a European Commission adequacy decision, so processing data in Switzerland meets the GDPR requirements for data transfers.
Some of our service providers are located in the United States. The transfer basis is provider-specific and described in section 5: primarily EU–U.S. Data Privacy Framework certification, otherwise the Commission's standard contractual clauses or an adequacy decision (Switzerland, United Kingdom).
5. Third parties (processors)
- Supabase — database, file storage, and authentication. The database, authentication, and files are hosted by Supabase, Inc. in the AWS Zurich region in Switzerland, which is covered by a European Commission adequacy decision. To the extent that Supabase or its sub-processors process data in the United States (e.g. Edge Functions, logs, backups), the transfer is based on the Commission's standard contractual clauses.
- Resend — sending service emails (e.g. confirmation messages), storing the newsletter subscriber list and sending newsletters. Emails are sent through Resend, Inc. (USA). Resend is certified under the EU–U.S. Data Privacy Framework, and standard contractual clauses additionally apply to the transfer.
- Cloudflare — receiving the newsletter sign-up form and its bot check (Cloudflare Turnstile, which processes technical browser data and sets no tracking cookies), and serving web pages (including this page). The awuu.app website is delivered through the network of Cloudflare, Inc. (USA); Cloudflare processes technical connection data (IP address, logs) and is certified under the EU–U.S. Data Privacy Framework; its data processing agreement includes standard contractual clauses.
- OpenAI — automatic content pre-screening: images uploaded to the app are checked before storage and reported text before moderator review using OpenAI's Moderation API without a user identifier — only the image or text being checked is sent to OpenAI. The contracting party is OpenAI Ireland Ltd; the data is not used to train models, and any transfer to the United States is based on standard contractual clauses. OpenAI does not retain content sent to the moderation API after the check (abuse monitoring logs for at most 30 days). The result of the check and any flagged content categories are stored on our servers together with your user identifier; a rejected image is not stored.
- Google (Maps, AdMob, and Google Sign-In) — the app's map view uses Google Maps, AdMob displays the ads (see section 3), and Google Sign-In is used only if you choose it. These services transmit data (e.g. IP address, advertising identifier, device data) to Google Ireland Ltd and Google LLC (USA). Google is an independent data controller (how Google uses data); the transfer to the United States is based on Google LLC's EU–U.S. Data Privacy Framework certification and standard contractual clauses.
- Apple (Sign in with Apple, App Store, and the APNs push notification service) — Apple sign-in is used only if you choose it; the App Store review prompt and APNs notification delivery are part of how the iOS app works. These services are provided by Apple Distribution International Ltd (Ireland); Apple acts as an independent data controller and transfers data to Apple Inc. in the United States under the Commission's standard contractual clauses.
- OpenStreetMap Nominatim (OpenStreetMap Foundation) and the device operating system's geocoding service (Apple or Google) — resolving a city name from coordinates and a city's location from its name. In city lookups, the search term and your IP address are sent to the Nominatim service of the OpenStreetMap Foundation (United Kingdom); the United Kingdom is covered by a European Commission adequacy decision. Only the coordinates or city name being looked up are sent to the service.
- Facebook (Meta Platforms Ireland Ltd.) — only if you choose to sign in with Facebook. We receive your name, email address, and Facebook user ID from Meta (public_profile and email permissions). This data is used only to create and identify your account, and the app does not post anything to Facebook. Meta Ireland acts as an independent data controller and transfers data to Meta Platforms, Inc. in the United States under its EU–U.S. Data Privacy Framework certification and standard contractual clauses.
- Meta Platforms Ireland Ltd. (Instagram) — only for event photos you have permitted to be published on Awuu's Instagram account (see section 3). If you consent to the publication of event photos on Instagram, the photo and caption are transferred to Meta Platforms Ireland Ltd, which acts as an independent data controller; Meta Ireland transfers data to Meta Platforms, Inc. in the United States under its EU–U.S. Data Privacy Framework certification and standard contractual clauses.
- Linked pages — when a message contains a link, your device fetches the preview directly from the linked page (see section 2). The linked page is not a processor for Awuu; it handles the request under its own terms.
- Expo (650 Industries, Inc.) — delivering push notifications, and checking for and delivering app updates (Expo EAS Update). Push notifications are relayed through the service of 650 Industries, Inc. (Expo, USA) to the Apple and Google notification services; Expo retains only the device's push token and is certified under the EU–U.S. Data Privacy Framework.
- Sentry (Functional Software, Inc.) — crash and technical error reporting. The app's error reports are processed in Sentry's EU region in Frankfurt. Sentry is certified under the EU–U.S. Data Privacy Framework, and organisation-level metadata is processed in the United States under standard contractual clauses (Sentry privacy policy).
- Apple App Store and Google Play (review prompt) — the app may ask you to rate it using the store's own review dialog (Apple SKStoreReviewController / Google Play In-App Review). Displaying the dialog and handling the review is done by Apple or Google under their own terms (transfer bases above); the app does not learn whether you left a review.
6. Retention
Data is kept for as long as your account exists. When you delete your account, your data is permanently deleted, including your blocks, your feedback, and the image pre-screening records. Exception: moderation reports are retained as a handling history without user identifiers (the reporter's and the reported user's identifiers are removed) so that abuse can be tracked. Deleted data may remain in technical backups for a limited time, after which it is removed from those as well.
A danger alert is visible on the map for 24 hours from its creation, a poisoned bait alert for 7 days. A new sighting extends a loose dog alert's visibility to at least 24 hours from the sighting, but to no more than 7 days from the alert's creation. After the visibility period ends, the alert, its sightings, and their photos remain in the database until you delete your account.
Past events and their group chats, gallery photos, and participation records are kept for as long as any participant still views them. When you remove a past event from your own list, it is hidden only from you — other participants still see it. Once every participant has removed the event from their list, it is deleted from the database and its photos from storage after 30 days. Regardless of removals, an event is deleted no later than 24 months after it ended. Your attendance count (the participation counter on your profile) does not decrease when an event is deleted.
If registration is left unfinished (account created but no profile saved), the unfinished account is deleted automatically after 30 days. Crash and error reports are retained in Sentry for 90 days.
Newsletter subscriber data is kept until you unsubscribe. An unsubscribed address remains on Resend's suppression list so that you are not emailed again by mistake; you can ask for it to be removed entirely by writing to info@awuu.app. Unconfirmed sign-ups are not stored: the confirmation link expires after 48 hours.
7. Deleting your data
You can delete your account and all your data with the Delete account function in the app (Profile → Account). The deletion is permanent and covers your profile, dog profile, images, conversations, event participations, the photos you uploaded to event galleries, and your danger alerts, sightings, and their photos. Photos already published on Awuu's social media accounts with your permission are not removed automatically; request their removal from info@awuu.app. See the detailed guide: Data deletion. A newsletter subscription is not removed with the account because it is separate from it: unsubscribe via the link in any message or ask for removal by email.
8. Your rights
Under the GDPR you have the right to access your data, rectify inaccurate data, erase your data, restrict or object to processing, and receive your data in a portable format. To exercise your rights, contact privacy@awuu.app. You also have the right to lodge a complaint with a supervisory authority — in Finland, the Office of the Data Protection Ombudsman (tietosuoja.fi).
9. Age limit
The service is intended for users aged 16 and over. The service is not directed at children, and we do not knowingly collect data from anyone under 16. If we become aware that we have collected data from a person under 16, we will delete it.
10. Requests from public authorities
We disclose personal data to public authorities only when required by a legal obligation. We review the legality of every request and the authority of the requester; unlawful or overly broad requests are challenged or clarification is requested. We disclose only the minimum amount of data that the request lawfully covers. All requests, our responses, and the reasoning are documented. As of the date of this policy, no such requests have been received.
11. Changes to this policy
If we start collecting new data or introduce new third parties or sign-in methods, we will update this policy and mark the change with a new version number and date at the top of the page.