In short
- Your content is stored on your device and stays available offline. The local database is encrypted.
- You don’t need a user account, an email address or a password.
- You connect up to five family devices by QR code. Synchronisation is end-to-end encrypted, your content can only be read on the connected devices.
- The Guardian Angel Pass exists only if you switch it on yourself. It is encrypted on your device, we cannot read it, and anyone who has the QR code sees everything you put into the pass.
- The practice search runs on your phone. The app uses your location and contacts only if you explicitly trigger it in the search, and it sends neither anywhere.
- There are no ads. Your data is neither sold nor used for advertising.
- Your pet family is not a public profile and not a social network.
- The app sends pseudonymous usage statistics and error reports to our own servers only if you allow it. Both are switched off at first start and can be changed at any time with one switch in the settings.
- For Premium the app uses the service RevenueCat, and for AI avatars a photo is transmitted for processing. Both are described in detail below.
- You can export complete local backups at any time and optionally protect them with a password.
Controller
The controller for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
- Provider
- Matthias Vierling, trading as VieMa Digital
- Address
- Matthias Vierling
Gottessegen 3
98693 Ilmenau
Germany - matthias@viema.digital
No data protection officer has been appointed because the legal requirements under Art. 37 GDPR and § 38 of the German Federal Data Protection Act (BDSG) are not met.
Which data the app processes
Pets Are Family processes the content you create in the app yourself:
- Pet data: details about your pets
- Health information about your pets
- Memories, moments and events
- Photos and documents that you assign to your pets or moments
- People as family members: name, picture or avatar and optionally a date of birth. These are not user accounts and not profiles.
No user account is required to use the app. No email address and no password are requested.
The app asks for access to the camera (photos of your pets and vet invoices) and to your photo library (choosing and saving photos). Photos are stored locally in the app. They only leave your device for the functions described below, such as creating an AI avatar, or when you export a backup.
In addition, only if you trigger it in the practice search, the app can ask once for your approximate location and let you pick a single contact from your address book. Both are optional and described in the section “Practice search, location and contacts”.
If you enter details about other people, such as the name and picture of a family member, this happens as part of your private, family use. Please only add people with their consent.
The legal basis for your own details is Art. 6(1)(b) GDPR (providing the app functions you use). You add details about other people as part of a purely personal or family activity (Art. 2(2)(c) GDPR). We only process them to the extent that you send them to our servers through a function (avatar, family sharing). The legal basis is then Art. 6(1)(f) GDPR (providing the function you triggered).
Local and encrypted storage
All content is stored on the respective device first. The local database is encrypted. Your entries stay available even without an internet connection.
Installation ID
When first started, the app generates a random identifier and stores it in your device’s protected storage (Keychain or Keystore). The identifier is not linked to your name, your Apple or Google account or an email address, but it is a lasting identifier of your installation and therefore pseudonymous, not anonymous. It is used for purchases (RevenueCat), for the Premium check on our server and for AI avatars (quota and abuse protection).
Whether the identifier is kept or newly generated when you reinstall the app depends on the operating system.
You can see the identifier in the settings as “Device ID” and copy it, for example for requests to us. “Delete all data” in the settings removes your content and settings from the device; the identifier itself remains.
The legal basis is Art. 6(1)(b) GDPR.
AI avatars (Premium)
With Premium you can have illustrated avatars created from a photo. The function only runs when you trigger it yourself.
- The selected photo is transmitted encrypted (HTTPS) to our avatar server (a VieMa Digital server at STRATO). The server only holds it in memory for the duration of the request and does not write it to disk.
- The avatar server forwards the photo to the AI service Google Vertex AI (Google Cloud, Gemini image model) and has two illustrations created (comic and painted). For this, Google (contracting party Google Ireland Limited, Dublin, Ireland) processes the photo on our behalf in Google’s EU multi-region (processing in data centres within the EU). A data processing agreement with standard contractual clauses is in place with Google. The photos are not used to train the models. Caching of inputs is switched off for our project at Google, and logging of requests and responses is not set up.
- Google checks inputs automatically for abuse. Only if this check classifies an input as suspicious may Google store it for further investigation for up to 90 days in the same region. This data is not used for training.
- After creation, the result is sent back to the app and stored locally. For profiles of people, the source photo is only used for the creation and is not stored permanently.
- To protect against abuse, the server issues a one-time check code (challenge) for each request and limits the number of requests per IP address and installation. A device check via Apple App Attest or Google Play Integrity is planned. Once it is active, we will update this policy. It also counts how many avatars have been created per installation ID (quota: 12 creations once when Premium is unlocked, no monthly quota). Planned keys for the device check would be stored by the server for up to 90 days. To protect against overload, IP addresses are counted for a short time, and the server’s access logs contain no image content and are deleted after 7 days.
Please do not upload photos of people who have not agreed to it. This applies in particular to photos of children.
The legal basis is Art. 6(1)(b) GDPR.
Usage statistics (voluntary)
If you allow it, the app sends pseudonymous usage events (for example “moment created”) to our own analytics server (PostHog, operated on a server of VieMa Digital at STRATO in Germany). No names, notes, photos or other content are transmitted and no profiles are created. The evaluation serves to improve the app.
The statistics are switched off at first start. You can switch them on on the consent screen (“Before we start”) or later under Settings → Privacy → “Anonymous statistics and error reports”, and switch them off again at any time. Nothing is sent without your consent. The switch also applies to the error reports (section 08). Switching off takes effect immediately; events already sent are deleted automatically after 90 days.
The IP address is technically transmitted when the connection is established, but it is not stored with the events. In addition, a random identifier of the statistics is processed. This identifier can link events from the same device, so it is pseudonymous, not anonymous. No session recordings and no location data are evaluated.
The legal basis is your consent, Art. 6(1)(a) GDPR and § 25(1) TDDDG. You can withdraw it at any time with effect for the future.
Error reports (voluntary)
If you allow it (the same switch as for the statistics, see section 07), the app sends a report to our own error server (GlitchTip, operated on a server of VieMa Digital at STRATO in Germany) when it crashes or an error occurs. The report contains the error message, the technical sequence of the error, device model, operating system, app version and the time, but no photos and no content. The IP address is transmitted technically when the connection is established. Local photo and file paths are removed before sending. The history of the latest user steps and network calls (without content) is also sent. For about one in five program runs, timing data is recorded for performance measurement. Nothing is sent without your consent. The reports are deleted automatically after 90 days.
The legal basis is your consent, Art. 6(1)(a) GDPR and § 25(1) TDDDG, which you can withdraw at any time with the same switch.
Guardian Angel Pass
With the Guardian Angel Pass you provide a page for a pet that someone opens when they find or look after the animal. The function is optional and off by default. It only runs once you switch the page on in the app.
- You decide what the page shows. The app suggests details from the profile, health and vet entries, such as name, breed, age, sex, chip number, allergies, medications and a practice with a phone number. You can change, empty or add anything, including a photo, your name and phone number, a second contact, food and insurance. A phone number is never required. Please enter names and numbers of other people only with their consent.
- End-to-end encrypted. The app encrypts the pass on your device (AES-256-GCM) and uploads only the encrypted record to our server (a VieMa Digital server at STRATO in Germany, the same service as family sharing). The key is only in the QR code or in the link after the “#”. A browser never sends that part to a server. We cannot read the content.
- Whoever has the code sees everything. Anyone who has the QR code or the link can read everything in the pass, without an app and without an account. Share the code only where you want to, and leave fields empty that you don’t want to show. On a printed card the phone number appears only if you explicitly switch that on. The card is created entirely on your phone.
- Opening the page. The address p.petsarefamily.app delivers the encrypted record and the browser decrypts it. The page sets no cookies, loads no third-party services and contains no analytics. For opening a pass the server writes no access log. The IP address is transmitted technically when the connection is made and counted briefly in memory to limit excessive requests; it is not stored in the process. For all other addresses on this subdomain (such as automated scanner requests) the web server keeps the usual access log, which is deleted after 7 days.
- What is on the server: a random identifier (12 characters), the encrypted record (at most 400 KB), a checksum of a secret that only your device knows (so that only you can change and delete it), and the time of the last change. Names, phone numbers and health details are not there in plain text.
- Switching off, renewing and deleting. When you switch the page off or renew the code, the app deletes the record on the server and the old code then shows “Not available”. The identifier stays blocked for up to 90 days so nobody can take it over; after that the empty entry is deleted. If you uninstall the app or change devices without switching off first, the encrypted record stays on the server because the secret was only on the old device. In that case write to matthias@viema.digital and give the identifier from the link (the 12 characters after p.petsarefamily.app/, not the key after the “#”), and we will delete it.
The legal basis is Art. 6(1)(b) GDPR (the function you trigger). For details about other people, see the note in section 02.
Practice search, location and contacts
When adding a vet practice you can take details from your address book or search a directory. Both are optional.
- Directory on the device. The search runs entirely on your phone in a bundled directory of vet practices. Your search terms are not transmitted. The data comes from OpenStreetMap (© OpenStreetMap contributors, ODbL licence, openstreetmap.org/copyright) and may be incomplete, so please check the phone number and address.
- Approximate location (optional). If you tap “Use my location for sorting” in the search and confirm the prompt, the app asks once for your approximate location, only while the app is open and only after your consent in the system dialog. It is used solely to sort the results on your phone by distance. It is neither stored nor sent to us or to third parties. On Android the app only asks for the approximate location.
- Contact from the address book (optional, iOS). If you tap “Take from contacts”, the operating system’s contact picker opens. The app only receives the one contact you tap and copies name, phone number, address and email into the form. It does not read or change your address book.
The legal basis is Art. 6(1)(a) GDPR (your consent in the system dialog); the data does not leave your device.
Backups
You can export a complete local backup with all data and media at any time and optionally protect it with a password. You decide where to store a backup. Without password protection, anyone who receives the file can read its contents.
No ads, no sale of data
Pets Are Family shows no ads. Your data is neither sold nor used for advertising purposes.
The app offers no public profiles, no feeds, no likes and no followers. Your pet family is not a social network.
Storage period and deletion
Local content stays stored until you delete it in the app or uninstall the app.
For data that is not on your device, these periods apply:
- Usage statistics: 90 days (only if consent was given).
- Crash reports: 90 days (only if consent was given).
- Keys for the device check at the avatar server (once active): up to 90 days.
- Server access logs: 7 days.
- Premium status and avatar quota (per installation ID): as long as the subscription or the quota is needed.
- Deleted entries of family sharing: the content is removed from the server immediately, an empty marker stays for 30 days.
- Guardian Angel Pass: as long as the page is switched on; when you switch it off or renew it the record is deleted immediately, the empty identifier after at most 90 days.
- Purchases at RevenueCat and processing at Google: see the respective sections above.
Your rights
You have the following rights:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR), unless retention obligations prevent it
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
Because your content is on your devices, you can exercise many of these rights directly in the app, for example by editing, deleting or exporting. For anything else, an informal message to matthias@viema.digital is enough.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is:
- Authority
- Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (TLfDI)
- Address
- Häßlerstraße 8, 99096 Erfurt, Germany
- Web
- www.tlfdi.de
Changes
We update this policy as soon as functions, service providers or legal conditions change. The current version is always available on this page.