Legal

Privacy Policy

Last updated: 26 July 2026 · Draft 0.2

Draft — pending legal review. Not yet approved by counsel. This policy is written from an audit of KoirApp's actual code and database, and describes what the app does and will do at launch. It has not been reviewed by a qualified data-protection lawyer. Several points — the lawful basis for transfers outside the EU/EEA, the exact minimum age, and some retention decisions — are marked in the source of this page as open questions for counsel and must be settled before launch.

Controller: Oakko Oy (“we”, “us”, “Oakko”) · Y-tunnus 3011591-7 · Finland
Service: KoirApp mobile application (the “App”)
Contact: koirapp@oakko.app

Tämä sivu suomeksi → (translation; the English version is authoritative)

In short

  • KoirApp is not private inside your household. Every member of a household sees everything logged in it — every log, note, health entry and cost — and who recorded it. See §2.
  • Your account and content live in the EU. They are stored with our hosting provider Supabase, in the European Union (Stockholm).
  • Push notifications leave the EU. To deliver reminders to your phone we register a device push token and send notifications through Expo, Apple and Google — all outside the EU/EEA. See §7.
  • We don't sell your data, show ads, or use third-party advertising trackers.
  • We don't run AI or machine-learning analysis on your dogs' information, your notes, or your health records.
  • Analytics is off by default. We only collect anonymous, behavioural product analytics if you opt in — and even then it never includes your name, email, your dogs' details, your notes, or any health text.
  • You can export and delete your data yourself, in the app. Deletion has a 7-day grace period and does not erase everything — see §13.
  • Payments go through Apple or Google. We never see or store your card details.

1. Who we are

KoirApp is operated by Oakko Oy, a company registered in Finland (Y-tunnus 3011591-7). For the purposes of the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act (tietosuojalaki 1050/2018), Oakko Oy is the data controller for the personal data described here. Privacy questions and requests: koirapp@oakko.app.

2. Who can see what inside KoirApp

There is no private space inside a household. KoirApp is built around households that share the care of the same dogs, and the app does not keep anything you record separate from the other members.

Concretely, when you are a member of a household:

  • Every other member sees everything recorded in that household — every care log, every free-text note, every health entry, every dog's passport details, and every cost you enter (vet bills, medication costs and any other amount recorded on a health entry).
  • Every entry is attributed to the person who made it. Logs record who did the feed, walk or medication and at what time, and the app shows that to the whole household. Edits and corrections record who made them too.
  • Care logs are append-only. You cannot delete or retract a log you made, and neither can anyone else. A log can be marked as “voided” with a reason, which hides it from the household view, but the original record and the reason are kept in the database.
  • The log history is, in effect, a record of presence. Because logs are timestamped and attributed, the household's history shows who was with the dogs at what times — and therefore also when nobody was. Please be aware of this before sharing a household.
  • Active sitters read the same stream. A sitter you hand a dog to reads all care logs for that dog — including the free-text notes and who made them — from the moment the handoff starts. See §8.
  • Leaving does not withdraw what you contributed. If you leave a household or delete your account, the records you created stay with that household for its other members; your name is replaced with a “former member” marker. See §13.

You are asked to acknowledge a short version of this when you create or join a household, and we record that acknowledgement.

3. Free text, and other people's information

Please do not type information about other people into KoirApp.

Several fields in the App accept free text — the note on a care log, the body of a health entry, a dog's care notes, and the note attached to an origin claim. You can type anything into them, and we do not read, filter or restrict what you write.

Everything you type is stored on our servers and is visible to every member of your household — and, for care-log notes and health notes, to any active sitter. It is included in data exports produced by anyone in that household, and it stays with the household if you leave.

So:

  • Don't record information about identifiable people — family members, neighbours, a previous owner, a breeder, a named vet's private circumstances — in free-text fields.
  • Don't record your own sensitive circumstances (health, finances, relationships) in a shared household unless you are content for every member and any sitter to read them.
  • If you do write about another person, you are making decisions about their personal data, and they have rights in respect of it.

Some fields are, by their nature, about third parties — a vet's name and phone number, an insurer and policy number, a breeder's or kennel's name. See §4.

4. What we process, and why

“Personal data” here means data about you (a person). Information about your dogs is generally not personal data about a human — but we treat it carefully anyway, and some of it (for example a vet's phone number, or a note that names someone) is personal data about a human.

Account & identity

Email address; password (stored hashed by our authentication provider — we never see it in plaintext); display name; an optional avatar; a cosmetic accent colour; language and unit preferences; a system-generated user ID. We use email + password sign-in only — no social or third-party login. Basis: performance of a contract, Art. 6(1)(b).

Household & sharing

Household name, type, time zone and locale; who is a member and their role; invite codes; which member logged or edited an action; who is currently “on duty” and since when; temporary “sitter” grants of scoped access to a specific dog; sitter and dog-transfer handoff codes; your acknowledgement of the shared-household disclosure. Basis: contract, Art. 6(1)(b).

Dog data

Names, breed, photos, sex, date of birth, microchip number and chip registry, status, and “passport” details (allergies, conditions, care notes, breeder and registration details, insurance provider and policy). Basis: contract, Art. 6(1)(b).

Contact details of third parties you enter

A dog's record can hold your vet's name and phone number, your insurer, policy number and phone number, and a breeder's or kennel's name and the names of a dog's dam and sire. These are personal data about people other than you. The vet name and phone, allergies, conditions and care notes are disclosed to a sitter if you share the passport with them (§8). Basis: contract, Art. 6(1)(b).

Health & care records

Vet visits, vaccinations, parasite and worming treatments, medications and dosing schedules, symptoms, injuries, diagnoses, treatments, providers, product names, free-text notes, and the costs you enter. This is your dog's health information, not human medical data, so it is generally not “special category” data under Art. 9 GDPR. Basis: contract, Art. 6(1)(b).

Costs are household-visible. An amount you record on a health entry is visible to every member of your household, and is therefore a record of household spending, not a private one.

Weight and clinical readings

Weight history (stored as whole grams), body-temperature readings, heat cycles and progesterone readings, and — for breeding households — litters and the dogs' relationships to each other. Basis: contract, Art. 6(1)(b).

Activity logs

Each feed / outing / medication event: the time, who did it, optional free-text notes, and details such as food type or whether the dog toileted. Outing sessions record who started them and when. As described in §2, these records are attributed, timestamped and append-only. We also store limited operational metadata (which screen created the entry, the app version and build, whether the log followed a notification tap and how many seconds later, and how the entry was entered) to keep the app reliable. Basis: contract, Art. 6(1)(b); reliability as a legitimate interest, Art. 6(1)(f).

Corrections and revision history

When a log is edited or voided we keep a correction record: who did it, the reason and any detail they typed, how long after the original entry the correction was made, and the original entry's technical details. When a health entry or a piece of feedback is edited, we keep a full before-and-after copy of it. These revision records are kept indefinitely (see §12) and are not shown in the app. Basis: legitimate interest in an accurate, auditable shared record, Art. 6(1)(f).

Governance and administration

Records of household administration: invitations and their redemption, admin-promotion offers, requests that need another admin's approval and the decisions on them, dog transfers between households, per-member permission overrides, and an internal audit log of significant events (who did what, in which household, and when). We also record which in-app messages and announcements you have seen or dismissed. Basis: contract, Art. 6(1)(b); legitimate interest in the integrity of a shared account, Art. 6(1)(f).

Breeder and kennel identity

If you present yourself as a breeder or kennel, we store your kennel name, registration number and verification status. If you apply for kennel verification we store your name, the official email address and website you give, the supporting information you provide, and the outcome — and a person at Oakko reads and reviews that application. If you claim to be the breeder of origin of a dog, we store your claim and the free-text note you attach to it, which names another party, and a person at Oakko reviews it. Basis: contract, Art. 6(1)(b).

Notifications and devices

To send you push notifications we store, for each device you sign in on, a push token (an identifier that lets a notification be delivered to that specific device), the platform (iOS or Android), the app version and build, and when the token was created and last seen. See §7. We also store the notifications the App has queued for you inside the app itself, and when you read or dismissed them. Basis: contract, Art. 6(1)(b).

Subscription data

If you subscribe, we store your household's tier, the store, a subscription identifier and the current period end. We never receive or store your payment-card details. Basis: contract, Art. 6(1)(b).

Support & feedback

If you contact us in the app, we store your message and category plus basic technical context (app version, OS name and version, device model) to reproduce issues. If — and only if — you tick the box offering to be contacted about it, we also copy your email address onto the feedback record itself. That copy is deliberately independent of your account, which means it survives the deletion of your account (see §13). Basis: legitimate interest in providing support, Art. 6(1)(f); your consent for the contact email, Art. 6(1)(a).

5. Analytics & error reporting (opt-in, off by default)

  • Off until you opt in. We send nothing to our analytics provider until you actively grant consent (in onboarding or in My Settings → Anonymous analytics). Events before your choice are held locally and either sent (if you later opt in) or discarded.
  • What's collected (if you opt in): a fixed set of behavioural product events — categories and counts only (e.g. “log created”, “paywall viewed”) — with the app version and a pseudonymous user ID (your account's system-generated identifier, not your name or email).
  • Error reports. With the same consent, uncaught errors are reported: the error message and the technical stack trace, plus the same pseudonymous ID. No user content is included.
  • Never sent to analytics: your name, email, dogs' names or details, breed, notes, health text, medication/dosing details, microchip number, allergies, conditions, phone numbers, addresses, invite codes, or any free text. The app actively strips such fields as a safety net.
  • Provider: PostHog, configured to its EU region.
  • Withdraw any time in My Settings → Anonymous analytics; we stop immediately. Your choice is stored on that device.

Basis: your consent, Art. 6(1)(a).

6. Payments

Subscriptions are sold through the Apple App Store and Google Play. Apple or Google processes the payment; your card and billing details are handled by them under their own privacy policies. We receive only the result — that your household is on a given tier, a subscription identifier, and the renewal date. Subscription status is relayed to us via RevenueCat.

Billing is not yet live in the App. No purchase can currently be made, no payment data reaches us, and nothing is sent to RevenueCat from the app itself.

7. Reminders and push notifications

KoirApp reminds you about feeding, walks, medication and other care. Reminders are delivered in two ways:

  • On-device notifications. Many reminders are calculated on your phone from your schedules and scheduled as local notifications. Their content does not leave your device.
  • Push notifications from our servers. To deliver reminders and household notifications that our servers originate, the App registers a push token for each device you sign in on and stores it with us (see §4). The token is minted through Expo's push service, and notifications are delivered through Apple Push Notification service (iOS) or Google Firebase Cloud Messaging (Android).

This means that the title and body of a push notification we send you pass through Expo and then Apple or Google, all of which operate outside the EU/EEA. Notification text can name your dog and the care due. We write notification text to be brief and to avoid unnecessary detail, but you should assume anything in a push notification has passed through those providers, and that it may appear on your lock screen.

If you decline notification permission, no token is created and no push is sent. Push tokens are removed when you sign out on that device, when the operating system reports the device is no longer registered, and by our routine cleanup (see §12).

8. The sitter feature

You can temporarily hand a specific dog to another logged-in household (a “sitter”). The sitter's access is scoped and temporary, enforced on our servers rather than merely hidden in the interface, is limited to that one dog, and covers only the period from the start of the handoff onward. When you end the sitting, their access is revoked immediately.

What a sitter always sees, for the duration of the handoff, and which you cannot switch off:

  • The dog's name and photo, and the name of your household.
  • Every care log for that dog recorded from the start of the handoff — including the free-text notes on them and who made each entry.
  • Free-text notes recorded in the health record for that dog from the start of the handoff.
  • Every active medication's name, dose and schedule.
  • The feeding and outing times that apply to the dog.

What you choose to share, per handoff:

  • The passport block — vet name and phone, allergies, conditions and care notes.
  • Your household's custom log actions.

What a sitter never sees: your dog's wider health record (vet visits, vaccinations, diagnoses, treatments), weight and clinical readings, costs, microchip number, breeder and registration data, insurance and administrative data, your other dogs, or anything recorded before the handoff began. Basis: contract, Art. 6(1)(b).

9. Who we share data with (sub-processors)

We do not sell your data and do not share it for advertising. We use a small number of processors.

ProviderWhat it receivesLocation
SupabaseDatabase, authentication, private file storage — all your account and content dataEU (AWS, Stockholm)
PostHogProduct analytics + error reports (opt-in only): pseudonymous ID, event names, app version, error messages and stack tracesEU (eu.i.posthog.com)
ExpoPush service: mints the device push token and relays the title, body and payload of each push notificationUnited States
Apple (APNs)Delivery of push notifications to iOS devices, including their contentUnited States
Google (Firebase Cloud Messaging)Delivery of push notifications to Android devices, including their contentUnited States
Apple (App Store)App distribution + payment processingApple infrastructure, incl. outside the EU/EEA
Google (Play)App distribution + payment processingGoogle infrastructure, incl. outside the EU/EEA
RevenueCatSubscription-status management: a subscription identifier and tier/statusUnited States
CloudflareHosting of this website (koirapp.fi). Receives visitor connection data such as IP addresses in its edge logs. It does not host the App or your account data.Global edge network

KoirApp is built with the Expo framework. The App does not use over-the-air updates.

10. International transfers

Your account and content are hosted in the EU (Supabase in Stockholm; PostHog EU). Push notifications necessarily leave the EU/EEA: push tokens and notification content are processed by Expo, Apple and Google in the United States (§7). Apple, Google and RevenueCat also process limited data outside the EU/EEA for distribution, payments and subscription management.

11. How long we keep data

We keep personal data only as long as needed for the purposes above. In practice:

  • Your account and content — kept for the life of your account, and handled as described in §13 when you delete it. Content in a shared household remains with that household for its other members.
  • Push tokens — deleted when you sign out on that device, when the platform reports the device is no longer reachable, and automatically once a device has not been seen for 6 months.
  • In-app notifications — once closed, deleted 90 days after you read them, or after 1 year if you never do.
  • Account-deletion grace period7 days between your request and the erasure running.
  • Deletion at third parties — once an erasure runs, the corresponding deletions at our external providers are processed by a job that runs hourly and retries until it succeeds.
  • Subscription and payment records — a de-identified copy of the subscription record is kept for approximately 6 years to meet Finnish accounting-law obligations. It contains no name or email. Basis: legal obligation, Art. 6(1)(c).
  • Audit log, revision history and log corrections — currently kept indefinitely, de-identified when an account is deleted.
  • Support messages and feedback — kept after your account is deleted, de-identified, except for a contact email you consented to (§13).
  • Analytics events — retained by PostHog for a period set in that service.
  • Backups — operational database backups are kept by our hosting provider on a rolling basis.

12. Your rights (GDPR)

You have the right to access, rectify, erase, restrict, object to, and port your personal data, and to withdraw consent for analytics at any time.

  • Export (portability): you can export your data as a JSON file from the app, free on every tier. It contains your profile, memberships, households, dogs, care logs, health entries, weight readings, dog states, care schedules, custom log types, reminder rules, outing sessions, your household acknowledgements, and a redacted list of your registered devices.
    The export is not yet complete. It does not currently include heat cycles and other clinical readings, litters, origin claims, guidelines, your own support messages and feedback, revision history, log corrections, the audit log, in-app notifications, sitting grants, subscription records, invitations, or permission overrides. It lists the storage paths of your photos and avatars but does not include the image files themselves. If you want any of these, email us and we will provide them.
  • Deletion: delete your account in My Settings → Delete my account. See §13 and Deleting your account for exactly what happens.
  • Other requests (access, restriction, objection): email koirapp@oakko.app. We respond within one month.

Supervisory authority (Finland): Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi. You may also complain to the authority in your country of residence.

13. What happens when you delete your account

You can delete your account at any time in My Settings → Delete my account. What follows is a factual description of the mechanism.

  • There is a 7-day grace period. Requesting deletion sets a marker; nothing is deleted at that moment. You can cancel within the window, and only an explicit cancellation stops it — signing in again does not.
  • The erasure then runs on a scheduled job, once a day, so it takes effect shortly after the seventh day rather than at the exact moment.
  • Your identity is deleted. Your login, email, profile, display name, avatar, memberships, device push tokens, in-app notifications and household acknowledgements are removed.
  • Households where you were the only member are deleted in full, including their dogs, logs, health records, schedules and photos.
  • Shared households are not deleted. Everything you contributed to them — logs, notes, health entries, costs — remains, for the other members. Your authorship is not deleted either; it is replaced with an anonymous marker so the records no longer point to you. This is de-identification, not erasure of the underlying records.
  • Deletion at our external providers — your analytics profile at PostHog, your customer record at RevenueCat if any, and your stored photos — is queued and processed by a job that retries until it confirms success.

What is deliberately kept after you delete your account:

  • A de-identified subscription/payment record, for accounting purposes (§11). It holds no name or email.
  • The audit log entry recording that an account was deleted, with no link to you.
  • Your support messages and feedback, and their revision history, de-identified — kept as product signal.
  • The email address on a feedback message, if you ticked the box asking us to contact you about it. That email is stored on the feedback record itself rather than being read from your account, and it is not removed when your account is deleted.
  • Revision history and log corrections attached to records that survive, de-identified.

If you want a copy of your data, export it before you delete — deletion cannot be undone once the grace period has passed.

14. Security

We use encryption in transit (HTTPS/TLS), per-household access control enforced on the server (row-level security), private file storage for photos, and hashed passwords. Photos are re-encoded on your device before upload, which removes embedded metadata including any GPS location (§15). No method is 100% secure, but we work to protect your data and to notify you and the authorities of any qualifying breach as required by law.

15. Photos

You can add a photo of a dog and an avatar for yourself. Before any image is uploaded, the App re-encodes it on your device: it is resized and written out as a new JPEG, which discards the original file's embedded metadata — including GPS coordinates, which a phone camera would otherwise attach and which would reveal where the photo was taken, typically your home. The original file never leaves your device. Uploaded images are stored in private storage and are served only through short-lived signed links to people entitled to see them.

The App does not offer document or health-record photo attachments.

16. Children

KoirApp is intended for adults and is not directed at children. In Finland the age of digital consent is 13. We do not knowingly collect data from children below that age.

17. No AI, no ads, no data selling

We do not send your data to any AI or machine-learning service — not for summaries, suggestions, or anything else. There is no automated decision-making with legal or similarly significant effects; reminders are simple, rule-based calculations. We show no ads, embed no advertising or tracking SDKs, and do not sell your data.

18. Cookies & this website

The KoirApp mobile app does not use browser cookies. This website (koirapp.fi) uses no cookies, no analytics, and makes no third-party requests — fonts and all assets are served from koirapp.fi itself. The site is hosted on Cloudflare Pages, which processes connection data such as your IP address in order to serve the page (§9).

19. Changes

We may update this policy as the App evolves. We'll post the new version here with an updated date and, for material changes, notify you in the App or by email.

← Back to home