Pawinoo
Pawinoo Privacy Policy
1.0.2
1. Who we are and scope
Pawinoo is the AI pet companion and pet community service operated by Alwood, an individual based in Singapore (the “Operator” and data controller). In this policy, “Pawinoo,” “we,” and “us” refer to the Operator.
Pawinoo accepts account registrations worldwide from the countries and territories represented by currently assigned ISO 3166-1 alpha-2 codes. Mobile registration records the device storefront country; Web registration records the country or region selected by the user. Registration country is not a billing address and does not replace independent location checks required by a payment provider or applicable law. Pawinoo is for people aged 18 or older.
2. Information we collect
We collect only information needed to provide, secure, support, bill, and improve Pawinoo:
- Account and consent data: email or Apple/Google login identifier, display name, locale, time zone, registration/store country, age-18 confirmation, accepted policy versions, session and device-security data.
- Pet profile data: pet name, species, breed, sex, birth date or estimated age, profile text, handle, avatar, photos, visibility, Persona questionnaire answers and Owner edits.
- Private service content: chat messages, private images, confirmed Memories, Memory Candidates, Persona versions, drafts, feedback and source references.
- Community content: Public or Unlisted posts, media, alternative text, comments, reactions, follows, blocks, reports and appeals. Public content can be viewed by anyone. Unlisted content can be viewed by anyone with a valid link and is not private.
- Purchase data: payment provider, product, customer/subscription/invoice/transaction identifiers, currency, amount, tax, billing country or address needed for tax, subscription state, renewal/expiry information and entitlement history. Pawinoo does not receive full payment-card details from Apple, Google or Stripe.
- Support, safety and audit data: support tickets, report categories, minimum moderation evidence, actions, temporary evidence access and administrative audit records.
- Technical and derived data: request and trace identifiers, app/platform version, route, error class, latency, quota usage, fraud/risk signals, model/prompt/policy versions, token and cost counts, embeddings, ranking features and aggregate analytics. Ordinary logs do not contain chat, Memory or Draft text.
We receive information directly from you, from your use of Pawinoo, from Apple or Google for login and purchases, from Stripe for Pawinoo Web purchases, and from people who interact with or report community content.
3. How we use information
We use information to:
- create and secure accounts, verify identity, prevent abuse and maintain sessions;
- create Pet profiles, Persona versions, private chat, confirmed Memory and Owner-controlled drafts;
- publish content or interactions only after the Owner’s explicit action and enforce Public, Unlisted and Private visibility;
- provide subscription entitlement, quota, restore-purchase and store reconciliation;
- detect and respond to unsafe content, reports, fraud, security events and appeals;
- provide support, legal data export, correction, deletion and recovery;
- measure reliability, safety, product quality and aggregate usage without logging private content; and
- comply with law, enforce our Terms and protect users, Pawinoo and the public.
Where UK data-protection law applies, processing needed to provide Pawinoo and subscriptions is based on performance of the contract; security, fraud prevention, service reliability, proportionate product analytics and community safety rely on legitimate interests; tax, lawful requests and legal recordkeeping rely on legal obligations; and processing that requires a separate choice relies on consent. You may withdraw consent without affecting earlier lawful processing. Pawinoo does not require consent for unrelated processing as a condition of the service.
4. AI processing
Pawinoo uses a server-side Model Gateway. DeepSeek V4 Flash processes the minimum text needed for chat, Persona formatting, private post/reply drafts, Memory Candidates and text safety classification. A private qwen3-embedding:4b service running inside Pawinoo infrastructure creates vectors for confirmed Memories; Memory text is not sent to DeepSeek for embedding. DeepSeek V4 Flash is text-only in this integration: chat image bytes remain in Pawinoo storage and are not sent to DeepSeek, which receives only a notice that an image was attached and must not infer visual details. Context is limited to the current authenticated User and Pet and is assembled in this order: policy, identity boundary, active Persona, confirmed Active Memory, undeleted conversation context and output schema.
AI results can be wrong. Persona controls style, not facts. A Memory Candidate is not used as long-term Memory until the Owner confirms it. Pawinoo does not use chat, Memory, drafts or media for general-purpose model training and disables the model provider's account setting that permits Inputs and Outputs to improve its models before production processing. The model cannot publish, comment, react, follow, message another user, buy anything or take moderation action. Public AI-assisted content requires a separate Owner confirmation and displays an AI-assistance label.
5. Public and Unlisted information
A Public Pet profile may show only the approved public fields: Pet name, handle, species, broad age band, breed, gender, profile text, avatar, selected photos, follower/following counts and published content. It never shows the Owner’s name or email, exact birthday, estimated age in months, location, time zone, store country, private chat, Memory, drafts, transactions, deletion or moderation records.
Public content may appear in feeds, search, recommendations and public URLs. Unlisted posts do not appear in those surfaces, but anyone holding a valid link can view them without signing in. Links expire after 30 days and can be revoked or rotated. Changing a Pet to Private immediately removes its public profile and content from public discovery and invalidates sharing links.
6. Sharing and service providers
We disclose the minimum information needed to:
- cloud hosting, database, object-storage, security and content-delivery providers;
- Hangzhou DeepSeek Artificial Intelligence Co., Ltd. through the server-side Model Gateway for minimum text generation and classification;
- Apple and Google for login, purchases, store notifications and push delivery;
- Stripe for Pawinoo Web checkout, subscriptions, tax, invoices and the Customer Portal;
- the selected transactional-email and observability providers;
- professional advisers, auditors or authorities where legally required; and
- a successor in a corporate transaction subject to appropriate confidentiality and notice.
Approved providers, purposes, regions and controls are recorded in the Subprocessor Register. Pawinoo does not sell personal information or share it for cross-context behavioural advertising, and V1 contains no third-party advertising. We do not disclose private chat, Memory or Draft content to other Pawinoo users.
7. Storage and international transfers
Pawinoo uses contracted hosting, storage, content-delivery, payment, authentication, email, monitoring and AI providers. Personal data may therefore be processed outside your country, including in Singapore, the United States and the People's Republic of China. DeepSeek may process the minimum text sent for AI inference in China. Private and Restricted content is otherwise limited to approved primary and backup systems; only Public media derivatives may be cached through a global CDN. Where applicable law requires it, Pawinoo uses contractual, security and transfer safeguards and provides a copy or description of the relevant safeguard on request.
8. Retention and deletion
We keep product data while the account is active and it is needed for the service. Deleted Messages and Memories become unavailable immediately; their text, caches, search index, vector and non-backup derivatives are cleared within 24 hours. Pet or account deletion includes a 7-day cancellation period and is completed across online data, indexes, vectors, media and backups no later than 30 days after requestedAt.
Minimum closed-case moderation evidence is kept for 180 days. Administrative audit records are kept for two years. Store transaction, currency, amount and tax records are kept for seven years and are separated from private product content after account deletion. Encrypted export artifacts are removed after seven days; each download link expires after 24 hours. Irreversibly anonymised aggregate statistics may be retained. The complete schedule is in Data_Retention_Deletion_Schedule.md.
Deleting a Pawinoo account does not cancel a subscription managed by Apple, Google or Stripe. The deletion screen provides the relevant subscription-management route. Later payment-provider notifications do not recreate a deleted Pawinoo account.
9. Your choices and rights
Inside Pawinoo you can view and correct account/Pet data, manage visibility and notifications, manage or delete Memories and content, export personal data, and request Pet or account deletion. A legal personal-data export is available to Free and Premium users and includes account, Pet, Persona, Message, Memory, Draft, Post, interaction, notification, consent and transaction records. The service target is Ready within 72 hours; this self-service target does not limit any statutory right.
Depending on your location and applicable law, you may have rights to know or access, correct, delete, restrict or object, withdraw consent, receive portable data, complain to a regulator, and receive equal service when exercising privacy rights. California residents may also have rights to know, delete, correct, opt out of sale/sharing and limit use of sensitive information where the CCPA applies. Pawinoo does not sell or share personal information for cross-context behavioural advertising.
Requests require proportionate identity verification. We do not reveal another person’s data in response to a request. If a request is refused or limited under law, we provide the reason and available complaint route. Privacy requests may be sent to support@pawinoo.com.
10. Security
Pawinoo uses encryption in transit and at rest, application-layer encryption for Private/Restricted text, KMS-managed keys, hashed credentials and capability tokens, object-level authorization, short-lived media URLs, malware/content scanning, EXIF/GPS removal, enterprise OIDC and MFA for administrators, temporary evidence access and append-only audit records. No security control is perfect; confirmed incidents follow the incident-response and notification process required by applicable law.
11. Children
Pawinoo is not directed to children and registration requires confirmation that the user is at least 18. We do not knowingly allow an under-18 account. If we learn that an ineligible person created an account, we disable it and delete the data under the deletion schedule, subject to minimum legal and safety records.
12. Changes, contact and complaints
Material changes are presented before they take effect and new consent is requested when required. Policy versions and acceptance time are recorded.
Controller and privacy contact: Alwood, 70 Jellicoe Rd, #01-20 V Hotel Lavender, Singapore 208767. Email: support@pawinoo.com. Telephone: +65 8075 6415.
Alwood is the designated Pawinoo privacy contact. You may also complain to the privacy regulator that applies where you live; in Singapore, this is the Personal Data Protection Commission.