Privacy · App

App privacy.

This policy applies to the app Pets Are Family on iOS and Android. For visits to this website, see the website privacy policy.

Last updated: 7 October 2026

In short

  • Your content is stored on your device and stays available offline. The local database is encrypted.
  • You don’t need a user account, an email address or a password.
  • You connect up to five family devices by QR code. Synchronisation is end-to-end encrypted, your content can only be read on the connected devices.
  • The Guardian Angel Pass exists only if you switch it on yourself. It is encrypted on your device, we cannot read it, and anyone who has the QR code sees everything you put into the pass.
  • The practice search runs on your phone. The app uses your location and contacts only if you explicitly trigger it in the search, and it sends neither anywhere.
  • There are no ads. Your data is neither sold nor used for advertising.
  • Your pet family is not a public profile and not a social network.
  • The app sends pseudonymous usage statistics and error reports to our own servers only if you allow it. Both are switched off at first start and can be changed at any time with one switch in the settings.
  • For Premium the app uses the service RevenueCat, and for AI avatars a photo is transmitted for processing. Both are described in detail below.
  • You can export complete local backups at any time and optionally protect them with a password.
01

Controller

The controller for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:

Provider
Matthias Vierling, trading as VieMa Digital
Address
Matthias Vierling
Gottessegen 3
98693 Ilmenau
Germany
Email
matthias@viema.digital

No data protection officer has been appointed because the legal requirements under Art. 37 GDPR and § 38 of the German Federal Data Protection Act (BDSG) are not met.

02

Which data the app processes

Pets Are Family processes the content you create in the app yourself:

  • Pet data: details about your pets
  • Health information about your pets
  • Memories, moments and events
  • Photos and documents that you assign to your pets or moments
  • People as family members: name, picture or avatar and optionally a date of birth. These are not user accounts and not profiles.

No user account is required to use the app. No email address and no password are requested.

The app asks for access to the camera (photos of your pets and vet invoices) and to your photo library (choosing and saving photos). Photos are stored locally in the app. They only leave your device for the functions described below, such as creating an AI avatar, or when you export a backup.

In addition, only if you trigger it in the practice search, the app can ask once for your approximate location and let you pick a single contact from your address book. Both are optional and described in the section “Practice search, location and contacts”.

If you enter details about other people, such as the name and picture of a family member, this happens as part of your private, family use. Please only add people with their consent.

The legal basis for your own details is Art. 6(1)(b) GDPR (providing the app functions you use). You add details about other people as part of a purely personal or family activity (Art. 2(2)(c) GDPR). We only process them to the extent that you send them to our servers through a function (avatar, family sharing). The legal basis is then Art. 6(1)(f) GDPR (providing the function you triggered).

03

Local and encrypted storage

All content is stored on the respective device first. The local database is encrypted. Your entries stay available even without an internet connection.

04

Installation ID

When first started, the app generates a random identifier and stores it in your device’s protected storage (Keychain or Keystore). The identifier is not linked to your name, your Apple or Google account or an email address, but it is a lasting identifier of your installation and therefore pseudonymous, not anonymous. It is used for purchases (RevenueCat), for the Premium check on our server and for AI avatars (quota and abuse protection).

Whether the identifier is kept or newly generated when you reinstall the app depends on the operating system.

You can see the identifier in the settings as “Device ID” and copy it, for example for requests to us. “Delete all data” in the settings removes your content and settings from the device; the identifier itself remains.

The legal basis is Art. 6(1)(b) GDPR.

05

Premium and purchases

Premium is purchased and billed through the Apple App Store or Google Play. Payment data is processed by Apple or Google, and their privacy policies apply in addition. We do not receive payment data.

To manage the Premium status the app uses the service RevenueCat (RevenueCat, Inc., 633 Tasman Drive, Sunnyvale, CA 94089, USA). RevenueCat receives the installation ID, information about your purchase or subscription from the respective store, and technical details such as platform and app version. The app uses this to determine whether Premium is active and to restore purchases.

RevenueCat processes this data on our behalf; a data processing agreement is in place. The data is processed on servers in the USA (Amazon Web Services). The transfer there relies on the EU Commission’s standard contractual clauses. For your rights in this respect, in particular access and erasure, you can contact us.

RevenueCat also reports purchase events (subscription active or expired, product, expiry date) to our own avatar server. For each installation ID the server stores the status, the product and the expiry date in order to unlock Premium functions. There is no link to your name or account.

The legal basis is Art. 6(1)(b) GDPR.

06

AI avatars (Premium)

With Premium you can have illustrated avatars created from a photo. The function only runs when you trigger it yourself.

  • The selected photo is transmitted encrypted (HTTPS) to our avatar server (a VieMa Digital server at STRATO). The server only holds it in memory for the duration of the request and does not write it to disk.
  • The avatar server forwards the photo to the AI service Google Vertex AI (Google Cloud, Gemini image model) and has two illustrations created (comic and painted). For this, Google (contracting party Google Ireland Limited, Dublin, Ireland) processes the photo on our behalf in Google’s EU multi-region (processing in data centres within the EU). A data processing agreement with standard contractual clauses is in place with Google. The photos are not used to train the models. Caching of inputs is switched off for our project at Google, and logging of requests and responses is not set up.
  • Google checks inputs automatically for abuse. Only if this check classifies an input as suspicious may Google store it for further investigation for up to 90 days in the same region. This data is not used for training.
  • After creation, the result is sent back to the app and stored locally. For profiles of people, the source photo is only used for the creation and is not stored permanently.
  • To protect against abuse, the server issues a one-time check code (challenge) for each request and limits the number of requests per IP address and installation. A device check via Apple App Attest or Google Play Integrity is planned. Once it is active, we will update this policy. It also counts how many avatars have been created per installation ID (quota: 12 creations once when Premium is unlocked, no monthly quota). Planned keys for the device check would be stored by the server for up to 90 days. To protect against overload, IP addresses are counted for a short time, and the server’s access logs contain no image content and are deleted after 7 days.

Please do not upload photos of people who have not agreed to it. This applies in particular to photos of children.

The legal basis is Art. 6(1)(b) GDPR.

07

Usage statistics (voluntary)

If you allow it, the app sends pseudonymous usage events (for example “moment created”) to our own analytics server (PostHog, operated on a server of VieMa Digital at STRATO in Germany). No names, notes, photos or other content are transmitted and no profiles are created. The evaluation serves to improve the app.

The statistics are switched off at first start. You can switch them on on the consent screen (“Before we start”) or later under Settings → Privacy → “Anonymous statistics and error reports”, and switch them off again at any time. Nothing is sent without your consent. The switch also applies to the error reports (section 08). Switching off takes effect immediately; events already sent are deleted automatically after 90 days.

The IP address is technically transmitted when the connection is established, but it is not stored with the events. In addition, a random identifier of the statistics is processed. This identifier can link events from the same device, so it is pseudonymous, not anonymous. No session recordings and no location data are evaluated.

The legal basis is your consent, Art. 6(1)(a) GDPR and § 25(1) TDDDG. You can withdraw it at any time with effect for the future.

08

Error reports (voluntary)

If you allow it (the same switch as for the statistics, see section 07), the app sends a report to our own error server (GlitchTip, operated on a server of VieMa Digital at STRATO in Germany) when it crashes or an error occurs. The report contains the error message, the technical sequence of the error, device model, operating system, app version and the time, but no photos and no content. The IP address is transmitted technically when the connection is established. Local photo and file paths are removed before sending. The history of the latest user steps and network calls (without content) is also sent. For about one in five program runs, timing data is recorded for performance measurement. Nothing is sent without your consent. The reports are deleted automatically after 90 days.

The legal basis is your consent, Art. 6(1)(a) GDPR and § 25(1) TDDDG, which you can withdraw at any time with the same switch.

09

Family sharing and synchronisation

With family sharing you share your pet family with the people who belong to it. Up to five devices together form a family vault.

  • Devices are connected to each other by QR code, without a user account, email address or password.
  • Changes, photos and documents are synchronised with end-to-end encryption. The key is created on your devices and handed over by QR code when connecting. It is not sent to our server.
  • Your content can only be read on the devices you have connected. The server used for synchronisation only stores encrypted data packets and cannot read your content.
  • You decide per pet whether it is shared with the family. If you switch sharing off, the pet disappears on the other devices and everything stays on your device.
  • If you delete an entry, this applies on all connected devices. The server removes the encrypted content immediately and keeps only an empty marker so that the other devices also pick up the deletion. After 30 days the marker is deleted too. Synchronisation is not a backup; the local backup is for that (section 12).

Technically, connection data is still processed during synchronisation: a random identifier of the vault and of the device, the IP address at retrieval, times and the size of the data packets. This does not reveal who the people are or what is in the packets.

All connected devices have access to the content of the shared family vault. Please only connect devices of people you trust.

The legal basis is Art. 6(1)(b) GDPR.

10

Guardian Angel Pass

With the Guardian Angel Pass you provide a page for a pet that someone opens when they find or look after the animal. The function is optional and off by default. It only runs once you switch the page on in the app.

  • You decide what the page shows. The app suggests details from the profile, health and vet entries, such as name, breed, age, sex, chip number, allergies, medications and a practice with a phone number. You can change, empty or add anything, including a photo, your name and phone number, a second contact, food and insurance. A phone number is never required. Please enter names and numbers of other people only with their consent.
  • End-to-end encrypted. The app encrypts the pass on your device (AES-256-GCM) and uploads only the encrypted record to our server (a VieMa Digital server at STRATO in Germany, the same service as family sharing). The key is only in the QR code or in the link after the “#”. A browser never sends that part to a server. We cannot read the content.
  • Whoever has the code sees everything. Anyone who has the QR code or the link can read everything in the pass, without an app and without an account. Share the code only where you want to, and leave fields empty that you don’t want to show. On a printed card the phone number appears only if you explicitly switch that on. The card is created entirely on your phone.
  • Opening the page. The address p.petsarefamily.app delivers the encrypted record and the browser decrypts it. The page sets no cookies, loads no third-party services and contains no analytics. For opening a pass the server writes no access log. The IP address is transmitted technically when the connection is made and counted briefly in memory to limit excessive requests; it is not stored in the process. For all other addresses on this subdomain (such as automated scanner requests) the web server keeps the usual access log, which is deleted after 7 days.
  • What is on the server: a random identifier (12 characters), the encrypted record (at most 400 KB), a checksum of a secret that only your device knows (so that only you can change and delete it), and the time of the last change. Names, phone numbers and health details are not there in plain text.
  • Switching off, renewing and deleting. When you switch the page off or renew the code, the app deletes the record on the server and the old code then shows “Not available”. The identifier stays blocked for up to 90 days so nobody can take it over; after that the empty entry is deleted. If you uninstall the app or change devices without switching off first, the encrypted record stays on the server because the secret was only on the old device. In that case write to matthias@viema.digital and give the identifier from the link (the 12 characters after p.petsarefamily.app/, not the key after the “#”), and we will delete it.

The legal basis is Art. 6(1)(b) GDPR (the function you trigger). For details about other people, see the note in section 02.

12

Backups

You can export a complete local backup with all data and media at any time and optionally protect it with a password. You decide where to store a backup. Without password protection, anyone who receives the file can read its contents.

13

No ads, no sale of data

Pets Are Family shows no ads. Your data is neither sold nor used for advertising purposes.

The app offers no public profiles, no feeds, no likes and no followers. Your pet family is not a social network.

14

Storage period and deletion

Local content stays stored until you delete it in the app or uninstall the app.

For data that is not on your device, these periods apply:

  • Usage statistics: 90 days (only if consent was given).
  • Crash reports: 90 days (only if consent was given).
  • Keys for the device check at the avatar server (once active): up to 90 days.
  • Server access logs: 7 days.
  • Premium status and avatar quota (per installation ID): as long as the subscription or the quota is needed.
  • Deleted entries of family sharing: the content is removed from the server immediately, an empty marker stays for 30 days.
  • Guardian Angel Pass: as long as the page is switched on; when you switch it off or renew it the record is deleted immediately, the empty identifier after at most 90 days.
  • Purchases at RevenueCat and processing at Google: see the respective sections above.
15

Your rights

You have the following rights:

  • Access to the data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR), unless retention obligations prevent it
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)
  • Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)

Because your content is on your devices, you can exercise many of these rights directly in the app, for example by editing, deleting or exporting. For anything else, an informal message to matthias@viema.digital is enough.

16

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is:

Authority
Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (TLfDI)
Address
Häßlerstraße 8, 99096 Erfurt, Germany
Web
www.tlfdi.de
17

Changes

We update this policy as soon as functions, service providers or legal conditions change. The current version is always available on this page.