Effective date: 10 August 2026
Version: 1.0
Last updated: 10 August 2026
This Privacy Notice explains how WoffApp collects, uses, shares, and protects personal data when you use the WoffApp mobile application for iOS and Android (the "App") and the website https://woffapp.com (the "Site", together with the App, the "Service").
We wrote this document to be read, not just stored. If anything is unclear, please write to info@woffapp.com.
1. Who processes your data
The data controller ("we") is:
Data Controller [LEGAL_ENTITY_NAME]
Registered office [REGISTERED_ADDRESS]
VAT / tax code [VAT_NUMBER]
Email (privacy, data subject rights and support) info@woffapp.com
Data Protection Officer (DPO) [DPO_CONTACT_OR: "Not appointed. The conditions of Art. 37 GDPR do not apply."]
We are established in Italy and the Service is aimed at users in the European Economic Area. Processing is governed by Regulation (EU) 2016/679 ("GDPR") and Legislative Decree 196/2003 and subsequent amendments ("Privacy Code").
2. What WoffApp does in terms of privacy
WoffApp is a location-based social app dedicated to dog owners.
Four concepts are enough to understand this notice:
The most relevant privacy consequence: when you create a dog spot, you deliberately publish an approximate real location where you and your dog were, making it visible to nearby strangers for up to 72 hours. Section 6.5 explains this in detail. We ask you to read it.
3. Summary Table
What we process
Perchè
Legal basis
For how long
Account: email, password, Firebase user ID, login provider
Create and protect your account
Contract (Art. 6(1)(b))
Until account deletion
Profile: display name, language, city, notification preferences
Make the App work as you configured it
Contract
Until account deletion
Dog profiles: name, birth date, breed, sex, likes, dislikes, description, photos
Main function requested by you
Contract
Until account deletion
Device location while using the App
Show map, find nearby places, create spots
Consent (Art. 6(1)(a)) via system permission
Not stored as raw coordinate; see 6.4
Device location in background, only if you enable nearby spot alerts
Notify you when a dog spot appears near you
Consent (Art. 6(1)(a))
Not stored as raw coordinate; see 12.3
Dog spot: coordinate, geohash, times
Main function
Contract
Deleted permanently after 72 hours or upon removal
Sniffs and social history
Main function and challenges
Contract
Until dog or account deletion
Facts, scores and challenge leaderboards
Gamification
Contract
Rolling windows plus 21 days; see 9
Notification token, installation ID, platform, categories
Deliver notifications you have enabled
Consent + contract
Until logout, token change or deactivation
Crash and error diagnostics
Keep the App working
Legitimate interest (Art. 6(1)(f))
90 days with provider
App integrity attestations
Prevent abuse and fraud
Legitimate interest
Short duration, managed by provider
Place proposals and moderation logs
Maintain the place directory
Legitimate interest
Until record removal; audits remain
Subscription status
Remove ads for subscribers
Contract
Subscription duration plus legal terms
Advertising identifiers
Show ads to non-subscribers
Consent
According to provider policy
4. What we do not collect
To set expectations precisely:
5. Private, public and pseudonymous data in WoffApp
WoffApp separates what you enter from what other users can see. This separation is enforced by the server, not just the interface.
Private, only yours. Your email address, your Firebase user ID, account settings, notification tokens, your dogs' private cards, original uploaded photos, exact coordinates of your spots, private progress counters in challenges, and the list of sniffs sent and received.
Published to other users, in pseudonymous form. When you register a dog and create a spot, the server generates a public projection of the dog from the private card. This projection contains an opaque public identifier not linked to your account, plus name, breed, sex, birth date, likes, dislikes, description and sanitized copies of gallery photos. It deliberately excludes your user ID, email address, the dog's private ID, original photo storage paths and any precise location other than the spot you chose to publish.
Important consequence: the projection is pseudonymous, not anonymous. If you give the dog an identifying name, describe where you live in free text or upload a photo showing your house number, other users can recognise you. Treat description and gallery as a public post.
6. What we collect, in detail
6.1 Account and authentication
At registration, we process your email address and a password. The password exists only within the login interaction and the request to Firebase Authentication; we do not create separate copies or logs. Firebase Authentication stores the account identity, an anonymous Firebase user ID (UID), the authentication provider used, login times and token claims. Where the App offers Google or Apple login, we also process the OAuth credential returned by the provider and the email address the provider communicates to us. With Apple, you can choose to hide your address, in which case we receive only a private forwarding address: emails we send you then pass through Apple's forwarding service. Firebase Authentication and the operating system may store session credentials in device memory areas managed by the SDK and system. Logout revokes the App's powers and asks Firebase to disconnect the session, but we cannot and do not claim to physically delete that cache managed by the provider.
6.2 Profile and settings
We store a cloud profile document containing your UID, display name, email address, optional profile photo URL, app language, city, notification preferences and creation date, plus copies of your role (regular user or administrator) and subscription status. This allows your settings to survive a reinstall.
6.3 Dog profiles and photos
For each registered dog, we store: name (mandatory) and optionally birth date, breed (free text), sex, likes, dislikes, a description and an ordered photo gallery whose first image is the profile photo. We do not collect your age; the dog's age is derived from the birth date.
Photos are selected from the gallery or camera via the operating system selector. We receive only the images you choose. Originals are stored in Firebase Storage under your account. A server-side process generates sanitized public copies (a full version up to 5 MiB and a thumbnail up to 512 KiB), which are those actually loaded by other users. Uploads are limited to 20 MiB per image.
Note on photo metadata: WoffApp does not remove EXIF metadata from uploaded image bytes. If your camera inserts GPS coordinates in photos, those coordinates may travel with the image. If this concerns you, disable geolocation in the camera app or use photos without it. If a dog card references an image hosted outside our infrastructure, opening it causes an HTTPS request to that third-party server, which will see your IP address and normal request metadata. Removing the URL stops future requests but cannot delete that server's logs. Using the system share panel on a photo exports a copy to the app or person you select. We cannot recall or delete that copy.
6.4 Location
By default, the App uses location only while you are using it. It requests "while using the app" permission on both platforms. The only exception is the optional nearby spot alerts feature described in section 12.3, which requests separate permission.
What happens on a location detection:
You can revoke location permission at any time from the operating system settings. The App remains usable, but map-centred discovery and spot creation stop working. Creating a dog spot is a distinct and deliberate act of publication. See 6.5.
6.5 Dog spot
When you create a dog spot, we store its coordinate, a geohash, creation time, expiry time at 72 hours, dog's sex, dog's opaque public ID, your user ID on the private card and a sniff counter.
Do not create a spot at your home, workplace, a school or any place whose exposure could put you or others at risk. A sequence of spots at the same place at the same time reveals a habit. The "Best Routine" and "Early Bird" challenges exist precisely because these patterns are readable.
6.6 Sniffs and social history
Sending a sniff creates a record linking your dog to the spot and the target dog, with a time. Both parties maintain aggregated counters (sent, received, last sent, last received) that feed the best friends view and challenges. The sniff history is permanent: it is kept until the dog or account involved is deleted. Expired spots do not delete received sniffs.
6.7 Challenges and leaderboards
Challenges are calculated server-side from immutable "facts" (a sniff occurred, a spot was created, a contribution to a service was accepted). The catalogue includes: Neighbour's Administrator, Most Popular, Most Friendly, Best Routine, Early Bird, Most Active, Adventurer, Best Woffer and other entries shown in the App. Privacy-relevant elements:
Challenges are added and withdrawn over time. New challenges reuse the same facts and pseudonymous projections described here; a challenge requiring a new data category would first require an update to this notice.
6.8 Service locations, proposals and moderation
The service location directory is curated. Any user can propose a new place or a modification and can support an existing proposal.
When you use the place search field, the typed text, search session token, app language and visible map portion are sent to Google Places to get suggestions, and the chosen place is resolved into a place ID, formatted address and structured address components.
Reverse geocoding sends a coordinate to Google to get a readable address. Google retains these requests according to its policy; we cannot delete them. Moderation logs keep author ID, supporter IDs, proposals, decision, reviewer, times and a request digest. These logs serve to verify contested decisions later and are kept even after the proposal is resolved.
Accepted contributions also feed the "Neighbour's Administrator" challenge, which stores the number of accepted contributions and up to ten contribution lines, visible only to you.
6.9 Push notifications
If you authorise notifications, we register a device installation: an installation ID generated by the App, platform, app version, distributed language, notification permission status, enabled categories and the push token issued by your platform's notification service (Firebase Cloud Messaging on Android, Apple Push Notification service on iOS) with its hash. The server maintains a delivery log with event IDs, emission and expiry times, recipient hashes and recipient IDs, so a new attempt does not duplicate a notification. Current notification types: a spot you created was published, you received a sniff, a sent sniff was confirmed, new nearby service content. Resolving a notification in a readable card involves further reads: the exact spot, public projection and sender dog's thumbnail and an address obtained by reverse geocoding from Google for the spot's coordinate.
Some installation-level values (installation ID, operation generation counter and flag recording that the notification prompt was already shown) intentionally survive logout and are deleted by removing App data or uninstalling it, not by signing out. You can disable categories in the App Settings and disable notifications entirely from the operating system settings.
6.10 Local storage on your device
The App stores a small set of values in the device preference store: whether you completed the tutorial, chosen language, a per-account copy of your notification setting, preferred challenge and short-term records of undelivered commands (parts of owner and scope keys as hashes, a command ID and a time, kept for up to seven days). The built-in Firestore offline cache also stores copies of documents you viewed and pending writes, so the App works offline. This cache is managed by the Firebase SDK. Logout isolates it so data from another account cannot be shown, but we do not claim to physically delete it on logout. Uninstalling the App or deleting its data removes it.
6.11 Diagnostics, crash reporting and analytics
6.12 App integrity
Firebase App Check, together with Google Play Integrity on Android and Apple App Attest on iOS, produces short-lived attestations proving requests come from an authentic, unmodified copy of the App. We do not keep any attestation logs. These tokens are anti-abuse measures and never alone confer authorization.
6.13 Remote configuration
Firebase Remote Config delivers typed configuration parameters (feature flags and similar) to the App. It fetches configuration and reports parameter keys and model version. No personal data is sent for this purpose.
6.14 In-app feedback
If you send feedback from within the App, we receive your message, feedback category, an optional attached screenshot, your email address, user ID, app version, platform and language, to help us understand the issue and respond.
7. Legal bases for processing
Purpose
Legal basis
Creation and management of the account; provision of map, dog profiles, spots, sniffs, challenges and activated notifications
Performance of a contract, art. 6(1)(b) GDPR
Access to device location, camera and photo library; delivery of push notifications; personalised advertising
Consent, art. 6(1)(a) GDPR, given via system permission or an in-app command and revocable at any time
Service security and availability: abuse prevention, App Check attestation, rate limiting, content moderation, crash and error diagnostics, fraud prevention
Legitimate interest, art. 6(1)(f) GDPR. Our interest is a service free from spam, abuse or defects; we have assessed that this does not override your rights, as the data involved is minimal and not used for profiling you
Subscription management and compliance with tax, accounting and consumer protection obligations
Contract and legal obligation, arts. 6(1)(b) and 6(1)(c) GDPR
Response to legitimate authority requests and legal defence
Legal obligation and legitimate interest, arts. 6(1)(c) and 6(1)(f) GDPR
When processing is based on consent, withdrawing it is as simple as giving it (disable the permission in the operating system or the toggle in Settings) and does not affect the lawfulness of processing already carried out.
8. Who we share data with
We do not sell personal data. We share it with the following categories of recipients.
8.1 Other WoffApp users
As described in section 5: the public projection of your dog, your active spots within about 5 km and your position in public leaderboards.
8.2 Data processors and sub-processors
Recipient
Role
Data involved
Location
Safeguards
Google Ireland Ltd / Google LLC - Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, Remote Config, App Check
Hosting, database, storage, server logic, push transport
Virtually all Service data
Firestore and Cloud Functions operate in europe-west3 (Frankfurt, Germany). Other Firebase components and support may involve processing in the USA
Google Cloud Data Processing Addendum; EU Standard Contractual Clauses; EU-US Data Privacy Framework
Google Ireland Ltd / Google LLC - Google Maps Platform (Maps SDK, Places, Geocoding)
Map rendering, place search, address resolution
View boundaries, coordinates, typed queries, session tokens, IP address
Global
Google Maps Platform Terms; Google Privacy Policy
Google LLC - Play Integrity
Integrity attestation on Android
Device and app integrity signals
Global
Google Play Terms
Apple Inc. / Apple Distribution International Ltd - App Attest, App Store, APNs
Integrity on iOS, distribution, push transport
Attestation signals, purchase logs, push tokens
Global
Apple Privacy Policy
Functional Software Inc. (Sentry)
Crash and error diagnostics
Firebase UID, cleaned exception stack traces, release and device context
United States, with EU data region available
Sentry DPA; EU Standard Contractual Clauses
RevenueCat Inc. (v. 12.1)
Subscription management
Firebase UID, pseudonymous user ID, store receipt and subscription status
United States
RevenueCat DPA; EU Standard Contractual Clauses
Google Ireland Ltd - AdMob (v. 12.2)
Advertising
Advertising ID, ad interaction data, approximate location, device data
Global
Google Ads Data Processing Terms
Each acts as our processor, or as an independent controller in limited cases where the provider determines its own purposes (notably Google Maps, Apple and Google as store operators, and advertising providers). We maintain an updated list of sub-processors, available on request at info@woffapp.com.
8.3 Other disclosures
We may disclose data to professional advisors, to a buyer in case of merger or acquisition (with notice), and to public authorities when a valid legal obligation requires it.
9. How long we keep data
Data
Retention
Account, profile, notification preferences
Until account deletion
Dog profiles and original photos
Until deletion of the dog or account
Public projections and sanitized photos
Deleted upon deletion of the original dog; a cleanup queue reconciles derived copies
Dog spots
Permanently deleted 72 hours after creation, or immediately upon removal
Sniffs, counters and social history
Until deletion of the involved dog or account
Challenge facts derived from spots
Until the closure of the last weekly or monthly window consuming them, plus 21 days, then automatically deleted; also deleted upon deletion of spots, dog or account
Leaderboard entries, boards and scores
For the weekly or monthly window plus 21 days
"Home" Adventurer reference (5 km privacy cell)
Until deletion of the dog or account
Service proposals and moderation logs
Retained after resolution, as an audit trail of the decision
Notification installation, push token and delivery log
Until logout, permission revocation, token rotation or entry expiration
Local logs of pending commands
Maximum 7 days
Crash and error events
90 days at the provider
Server request logs (including Google Cloud logs)
According to provider default, typically 30 days
Purchase and billing documents
10 years, as required by Italian tax law
Offline Firestore cache on your device
Until app data deletion or uninstallation
When a retention period is set by a provider we do not control, we declare it, instead of promising deletion we cannot perform.
10. Data deletion
10.1 Deleting a single dog
Deleting a dog removes its private profile, photos, public projection and spots, and cancels progress in challenges that dog contributed to. Your other dogs and their spots remain unaffected.
10.2 Deleting the account
You can delete your WoffApp account and all associated data from Settings -> Account -> Delete account in the app. You can also request deletion by writing to info@woffapp.com from the registered account email: we will complete it within 30 days. Deletion is a phased server-side process. It removes the profile, dogs, their photos and public projections, all their spots, sniff records, challenge progress and references, notification installations and finally the Firebase Authentication identity. It is irreversible. What deletion cannot reach, honestly stated:
10.3 Web deletion path
For store compliance, an account deletion request page is available at https://woffapp.com/account-deletion and works without installing the app.
11. Your rights
Under arts. 15 to 22 GDPR you have the right to:
To exercise these, write to info@woffapp.com. We will respond within one month, extendable by two months for complex requests, and inform you if an extension is needed. We may ask you to verify your identity, but only proportionately.
Right to complain.
If you believe your data processing is unlawful, you may complain to the Italian supervisory authority:
Garante per la protezione dei dati personaliPiazza Venezia 11, 00187 RomePhone: +39 06 696771Email: garante@gpdp.it - PEC: protocollo@pec.gpdp.itWebsite: https://www.garanteprivacy.it
You may also contact the supervisory authority of your EU country of residence or work, or take legal action.
12. Subscriptions, advertising and nearby spot alerts
These three areas involve data processors and permissions not used by the rest of the app, so are described separately. Availability depends on your platform, geographic area and app version.
12.1 Premium subscription and payments
WoffApp offers an optional recurring subscription that removes advertising. Purchases are made via Apple App Store and Google Play, which handle payment. We never receive your card number, bank details or billing address. Rights management is handled by RevenueCat, which receives your Firebase UID or a pseudonymous user ID, store receipt and resulting status (active, expired, grace period, billing issue), so the subscription follows you across devices and reinstallations. Our servers keep only the resulting status, linked to your account. Apple and Google act as independent controllers for the transaction and keep purchase records according to their policies and timelines. Tax documents we must retain follow the times indicated in section 9.
12.2 Advertising
Free accounts see banner ads provided by Google AdMob, shown when opening a marker. Active subscribers see no ads.
Before requesting any ad:
Refusing means continuing to see ads, but chosen without profiling. AdMob may process your advertising ID, ad interactions, approximate location and device info per Google's policies. You can reset or clear your advertising ID anytime in device settings.
12.3 Nearby spot alerts and background location
Nearby spot alerts notify you when a dog spot appears near you while the app is closed. To do this, the app registers geographic regions with the operating system - up to 20 regions on iOS and 100 on Android, each with a radius of about 100 m - and the OS wakes the app when you enter one. Regions are chosen from spots near you and deregistered when those spots expire. This requires background location permission ("Always" on iOS, "Allow all the time" on Android), a significantly more invasive step than foreground location described in point 6.4. Consequently:
Background location is evaluated on your device against registered regions. As with foreground location, we do not keep raw coordinates as a permanent log of places you have been.
13. Minors
WoffApp is not intended for anyone under 16 years old. We do not knowingly collect personal data of minors under 16. By creating an account you confirm you are at least 16. If you believe a minor under 16 has created an account, write to info@woffapp.com and we will promptly delete the account and related data. The 16-year threshold is a deliberate choice: it is the maximum digital consent age allowed by art. 8 GDPR, thus valid in every EEA country regardless of local age.
14. Security
We protect data, among other means, with:
No system is perfectly secure. In case of a personal data breach posing a risk to your rights and freedoms, we will notify the Supervisory Authority within 72 hours as required by art. 33 GDPR and inform you directly in cases foreseen by art. 34.
15. International transfers
Our main archives (Cloud Firestore and Cloud Functions) are located in europe-west3 (Frankfurt, Germany), inside the EEA. Some providers listed in point 8.2 are established in the United States or operate globally. When personal data is transferred outside the EEA, the transfer is based on:
You may request copies of applicable safeguards by writing to info@woffapp.com.
16. Changes to this privacy notice
We may update this notice as WoffApp evolves. The version number and effective date at the top of the document always identify the current text.
Previous versions are archived at https://woffapp.com/legal/archive.
17. Contacts
Privacy, data subject rights and support: info@woffapp.com
Mail: [LEGAL_ENTITY_NAME], [REGISTERED_ADDRESS]
This notice is published in Italian and English. In case of discrepancy, for users residing in Italy the Italian version prevails.
Ita
Eng
Effective date: 10 August 2026
Version: 1.0
Last updated: 10 August 2026
This Privacy Notice explains how WoffApp collects, uses, shares, and protects personal data when you use the WoffApp mobile application for iOS and Android (the "App") and the website https://woffapp.com (the "Site", together with the App, the "Service").
We wrote this document to be read, not just stored. If anything is unclear, please write to info@woffapp.com.
1. Who processes your data
The data controller ("we") is:
Data Controller [LEGAL_ENTITY_NAME]
Registered office [REGISTERED_ADDRESS]
VAT / tax code [VAT_NUMBER]
Email (privacy, data subject rights and support) info@woffapp.com
Data Protection Officer (DPO) [DPO_CONTACT_OR: "Not appointed. The conditions of Art. 37 GDPR do not apply."]
We are established in Italy and the Service is aimed at users in the European Economic Area. Processing is governed by Regulation (EU) 2016/679 ("GDPR") and Legislative Decree 196/2003 and subsequent amendments ("Privacy Code").
2. What WoffApp does in terms of privacy
WoffApp is a location-based social app dedicated to dog owners.
Four concepts are enough to understand this notice:
The most relevant privacy consequence: when you create a dog spot, you deliberately publish an approximate real location where you and your dog were, making it visible to nearby strangers for up to 72 hours. Section 6.5 explains this in detail. We ask you to read it.
3. Summary Table
What we process
Perchè
Legal basis
For how long
Account: email, password, Firebase user ID, login provider
Create and protect your account
Contract (Art. 6(1)(b))
Until account deletion
Profile: display name, language, city, notification preferences
Make the App work as you configured it
Contract
Until account deletion
Dog profiles: name, birth date, breed, sex, likes, dislikes, description, photos
Main function requested by you
Contract
Until account deletion
Device location while using the App
Show map, find nearby places, create spots
Consent (Art. 6(1)(a)) via system permission
Not stored as raw coordinate; see 6.4
Device location in background, only if you enable nearby spot alerts
Notify you when a dog spot appears near you
Consent (Art. 6(1)(a))
Not stored as raw coordinate; see 12.3
Dog spot: coordinate, geohash, times
Main function
Contract
Deleted permanently after 72 hours or upon removal
Sniffs and social history
Main function and challenges
Contract
Until dog or account deletion
Facts, scores and challenge leaderboards
Gamification
Contract
Rolling windows plus 21 days; see 9
Notification token, installation ID, platform, categories
Deliver notifications you have enabled
Consent + contract
Until logout, token change or deactivation
Crash and error diagnostics
Keep the App working
Legitimate interest (Art. 6(1)(f))
90 days with provider
App integrity attestations
Prevent abuse and fraud
Legitimate interest
Short duration, managed by provider
Place proposals and moderation logs
Maintain the place directory
Legitimate interest
Until record removal; audits remain
Subscription status
Remove ads for subscribers
Contract
Subscription duration plus legal terms
Advertising identifiers
Show ads to non-subscribers
Consent
According to provider policy
4. What we do not collect
To set expectations precisely:
5. Private, public and pseudonymous data in WoffApp
WoffApp separates what you enter from what other users can see. This separation is enforced by the server, not just the interface.
Private, only yours. Your email address, your Firebase user ID, account settings, notification tokens, your dogs' private cards, original uploaded photos, exact coordinates of your spots, private progress counters in challenges, and the list of sniffs sent and received.
Published to other users, in pseudonymous form. When you register a dog and create a spot, the server generates a public projection of the dog from the private card. This projection contains an opaque public identifier not linked to your account, plus name, breed, sex, birth date, likes, dislikes, description and sanitized copies of gallery photos. It deliberately excludes your user ID, email address, the dog's private ID, original photo storage paths and any precise location other than the spot you chose to publish.
Important consequence: the projection is pseudonymous, not anonymous. If you give the dog an identifying name, describe where you live in free text or upload a photo showing your house number, other users can recognise you. Treat description and gallery as a public post.
6. What we collect, in detail
6.1 Account and authentication
At registration, we process your email address and a password. The password exists only within the login interaction and the request to Firebase Authentication; we do not create separate copies or logs. Firebase Authentication stores the account identity, an anonymous Firebase user ID (UID), the authentication provider used, login times and token claims. Where the App offers Google or Apple login, we also process the OAuth credential returned by the provider and the email address the provider communicates to us. With Apple, you can choose to hide your address, in which case we receive only a private forwarding address: emails we send you then pass through Apple's forwarding service. Firebase Authentication and the operating system may store session credentials in device memory areas managed by the SDK and system. Logout revokes the App's powers and asks Firebase to disconnect the session, but we cannot and do not claim to physically delete that cache managed by the provider.
6.2 Profile and settings
We store a cloud profile document containing your UID, display name, email address, optional profile photo URL, app language, city, notification preferences and creation date, plus copies of your role (regular user or administrator) and subscription status. This allows your settings to survive a reinstall.
6.3 Dog profiles and photos
For each registered dog, we store: name (mandatory) and optionally birth date, breed (free text), sex, likes, dislikes, a description and an ordered photo gallery whose first image is the profile photo. We do not collect your age; the dog's age is derived from the birth date.
Photos are selected from the gallery or camera via the operating system selector. We receive only the images you choose. Originals are stored in Firebase Storage under your account. A server-side process generates sanitized public copies (a full version up to 5 MiB and a thumbnail up to 512 KiB), which are those actually loaded by other users. Uploads are limited to 20 MiB per image.
Note on photo metadata: WoffApp does not remove EXIF metadata from uploaded image bytes. If your camera inserts GPS coordinates in photos, those coordinates may travel with the image. If this concerns you, disable geolocation in the camera app or use photos without it. If a dog card references an image hosted outside our infrastructure, opening it causes an HTTPS request to that third-party server, which will see your IP address and normal request metadata. Removing the URL stops future requests but cannot delete that server's logs. Using the system share panel on a photo exports a copy to the app or person you select. We cannot recall or delete that copy.
6.4 Location
By default, the App uses location only while you are using it. It requests "while using the app" permission on both platforms. The only exception is the optional nearby spot alerts feature described in section 12.3, which requests separate permission.
What happens on a location detection:
You can revoke location permission at any time from the operating system settings. The App remains usable, but map-centred discovery and spot creation stop working. Creating a dog spot is a distinct and deliberate act of publication. See 6.5.
6.5 Dog spot
When you create a dog spot, we store its coordinate, a geohash, creation time, expiry time at 72 hours, dog's sex, dog's opaque public ID, your user ID on the private card and a sniff counter.
Do not create a spot at your home, workplace, a school or any place whose exposure could put you or others at risk. A sequence of spots at the same place at the same time reveals a habit. The "Best Routine" and "Early Bird" challenges exist precisely because these patterns are readable.
6.6 Sniffs and social history
Sending a sniff creates a record linking your dog to the spot and the target dog, with a time. Both parties maintain aggregated counters (sent, received, last sent, last received) that feed the best friends view and challenges. The sniff history is permanent: it is kept until the dog or account involved is deleted. Expired spots do not delete received sniffs.
6.7 Challenges and leaderboards
Challenges are calculated server-side from immutable "facts" (a sniff occurred, a spot was created, a contribution to a service was accepted). The catalogue includes: Neighbour's Administrator, Most Popular, Most Friendly, Best Routine, Early Bird, Most Active, Adventurer, Best Woffer and other entries shown in the App. Privacy-relevant elements:
Challenges are added and withdrawn over time. New challenges reuse the same facts and pseudonymous projections described here; a challenge requiring a new data category would first require an update to this notice.
6.8 Service locations, proposals and moderation
The service location directory is curated. Any user can propose a new place or a modification and can support an existing proposal.
When you use the place search field, the typed text, search session token, app language and visible map portion are sent to Google Places to get suggestions, and the chosen place is resolved into a place ID, formatted address and structured address components.
Reverse geocoding sends a coordinate to Google to get a readable address. Google retains these requests according to its policy; we cannot delete them. Moderation logs keep author ID, supporter IDs, proposals, decision, reviewer, times and a request digest. These logs serve to verify contested decisions later and are kept even after the proposal is resolved.
Accepted contributions also feed the "Neighbour's Administrator" challenge, which stores the number of accepted contributions and up to ten contribution lines, visible only to you.
6.9 Push notifications
If you authorise notifications, we register a device installation: an installation ID generated by the App, platform, app version, distributed language, notification permission status, enabled categories and the push token issued by your platform's notification service (Firebase Cloud Messaging on Android, Apple Push Notification service on iOS) with its hash. The server maintains a delivery log with event IDs, emission and expiry times, recipient hashes and recipient IDs, so a new attempt does not duplicate a notification. Current notification types: a spot you created was published, you received a sniff, a sent sniff was confirmed, new nearby service content. Resolving a notification in a readable card involves further reads: the exact spot, public projection and sender dog's thumbnail and an address obtained by reverse geocoding from Google for the spot's coordinate.
Some installation-level values (installation ID, operation generation counter and flag recording that the notification prompt was already shown) intentionally survive logout and are deleted by removing App data or uninstalling it, not by signing out. You can disable categories in the App Settings and disable notifications entirely from the operating system settings.
6.10 Local storage on your device
The App stores a small set of values in the device preference store: whether you completed the tutorial, chosen language, a per-account copy of your notification setting, preferred challenge and short-term records of undelivered commands (parts of owner and scope keys as hashes, a command ID and a time, kept for up to seven days). The built-in Firestore offline cache also stores copies of documents you viewed and pending writes, so the App works offline. This cache is managed by the Firebase SDK. Logout isolates it so data from another account cannot be shown, but we do not claim to physically delete it on logout. Uninstalling the App or deleting its data removes it.
6.11 Diagnostics, crash reporting and analytics
6.12 App integrity
Firebase App Check, together with Google Play Integrity on Android and Apple App Attest on iOS, produces short-lived attestations proving requests come from an authentic, unmodified copy of the App. We do not keep any attestation logs. These tokens are anti-abuse measures and never alone confer authorization.
6.13 Remote configuration
Firebase Remote Config delivers typed configuration parameters (feature flags and similar) to the App. It fetches configuration and reports parameter keys and model version. No personal data is sent for this purpose.
6.14 In-app feedback
If you send feedback from within the App, we receive your message, feedback category, an optional attached screenshot, your email address, user ID, app version, platform and language, to help us understand the issue and respond.
7. Legal bases for processing
Purpose
Legal basis
Creation and management of the account; provision of map, dog profiles, spots, sniffs, challenges and activated notifications
Performance of a contract, art. 6(1)(b) GDPR
Access to device location, camera and photo library; delivery of push notifications; personalised advertising
Consent, art. 6(1)(a) GDPR, given via system permission or an in-app command and revocable at any time
Service security and availability: abuse prevention, App Check attestation, rate limiting, content moderation, crash and error diagnostics, fraud prevention
Legitimate interest, art. 6(1)(f) GDPR. Our interest is a service free from spam, abuse or defects; we have assessed that this does not override your rights, as the data involved is minimal and not used for profiling you
Subscription management and compliance with tax, accounting and consumer protection obligations
Contract and legal obligation, arts. 6(1)(b) and 6(1)(c) GDPR
Response to legitimate authority requests and legal defence
Legal obligation and legitimate interest, arts. 6(1)(c) and 6(1)(f) GDPR
When processing is based on consent, withdrawing it is as simple as giving it (disable the permission in the operating system or the toggle in Settings) and does not affect the lawfulness of processing already carried out.
8. Who we share data with
We do not sell personal data. We share it with the following categories of recipients.
8.1 Other WoffApp users
As described in section 5: the public projection of your dog, your active spots within about 5 km and your position in public leaderboards.
8.2 Data processors and sub-processors
Recipient
Role
Data involved
Location
Safeguards
Google Ireland Ltd / Google LLC - Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, Remote Config, App Check
Hosting, database, storage, server logic, push transport
Virtually all Service data
Firestore and Cloud Functions operate in europe-west3 (Frankfurt, Germany). Other Firebase components and support may involve processing in the USA
Google Cloud Data Processing Addendum; EU Standard Contractual Clauses; EU-US Data Privacy Framework
Google Ireland Ltd / Google LLC - Google Maps Platform (Maps SDK, Places, Geocoding)
Map rendering, place search, address resolution
View boundaries, coordinates, typed queries, session tokens, IP address
Global
Google Maps Platform Terms; Google Privacy Policy
Google LLC - Play Integrity
Integrity attestation on Android
Device and app integrity signals
Global
Google Play Terms
Apple Inc. / Apple Distribution International Ltd - App Attest, App Store, APNs
Integrity on iOS, distribution, push transport
Attestation signals, purchase logs, push tokens
Global
Apple Privacy Policy
Functional Software Inc. (Sentry)
Crash and error diagnostics
Firebase UID, cleaned exception stack traces, release and device context
United States, with EU data region available
Sentry DPA; EU Standard Contractual Clauses
RevenueCat Inc. (v. 12.1)
Subscription management
Firebase UID, pseudonymous user ID, store receipt and subscription status
United States
RevenueCat DPA; EU Standard Contractual Clauses
Google Ireland Ltd - AdMob (v. 12.2)
Advertising
Advertising ID, ad interaction data, approximate location, device data
Global
Google Ads Data Processing Terms
Each acts as our processor, or as an independent controller in limited cases where the provider determines its own purposes (notably Google Maps, Apple and Google as store operators, and advertising providers). We maintain an updated list of sub-processors, available on request at info@woffapp.com.
8.3 Other disclosures
We may disclose data to professional advisors, to a buyer in case of merger or acquisition (with notice), and to public authorities when a valid legal obligation requires it.
9. How long we keep data
Data
Retention
Account, profile, notification preferences
Until account deletion
Dog profiles and original photos
Until deletion of the dog or account
Public projections and sanitized photos
Deleted upon deletion of the original dog; a cleanup queue reconciles derived copies
Dog spots
Permanently deleted 72 hours after creation, or immediately upon removal
Sniffs, counters and social history
Until deletion of the involved dog or account
Challenge facts derived from spots
Until the closure of the last weekly or monthly window consuming them, plus 21 days, then automatically deleted; also deleted upon deletion of spots, dog or account
Leaderboard entries, boards and scores
For the weekly or monthly window plus 21 days
"Home" Adventurer reference (5 km privacy cell)
Until deletion of the dog or account
Service proposals and moderation logs
Retained after resolution, as an audit trail of the decision
Notification installation, push token and delivery log
Until logout, permission revocation, token rotation or entry expiration
Local logs of pending commands
Maximum 7 days
Crash and error events
90 days at the provider
Server request logs (including Google Cloud logs)
According to provider default, typically 30 days
Purchase and billing documents
10 years, as required by Italian tax law
Offline Firestore cache on your device
Until app data deletion or uninstallation
When a retention period is set by a provider we do not control, we declare it, instead of promising deletion we cannot perform.
10. Data deletion
10.1 Deleting a single dog
Deleting a dog removes its private profile, photos, public projection and spots, and cancels progress in challenges that dog contributed to. Your other dogs and their spots remain unaffected.
10.2 Deleting the account
You can delete your WoffApp account and all associated data from Settings -> Account -> Delete account in the app. You can also request deletion by writing to info@woffapp.com from the registered account email: we will complete it within 30 days. Deletion is a phased server-side process. It removes the profile, dogs, their photos and public projections, all their spots, sniff records, challenge progress and references, notification installations and finally the Firebase Authentication identity. It is irreversible. What deletion cannot reach, honestly stated:
10.3 Web deletion path
For store compliance, an account deletion request page is available at https://woffapp.com/account-deletion and works without installing the app.
11. Your rights
Under arts. 15 to 22 GDPR you have the right to:
To exercise these, write to info@woffapp.com. We will respond within one month, extendable by two months for complex requests, and inform you if an extension is needed. We may ask you to verify your identity, but only proportionately.
Right to complain.
If you believe your data processing is unlawful, you may complain to the Italian supervisory authority:
Garante per la protezione dei dati personaliPiazza Venezia 11, 00187 RomePhone: +39 06 696771Email: garante@gpdp.it - PEC: protocollo@pec.gpdp.itWebsite: https://www.garanteprivacy.it
You may also contact the supervisory authority of your EU country of residence or work, or take legal action.
12. Subscriptions, advertising and nearby spot alerts
These three areas involve data processors and permissions not used by the rest of the app, so are described separately. Availability depends on your platform, geographic area and app version.
12.1 Premium subscription and payments
WoffApp offers an optional recurring subscription that removes advertising. Purchases are made via Apple App Store and Google Play, which handle payment. We never receive your card number, bank details or billing address. Rights management is handled by RevenueCat, which receives your Firebase UID or a pseudonymous user ID, store receipt and resulting status (active, expired, grace period, billing issue), so the subscription follows you across devices and reinstallations. Our servers keep only the resulting status, linked to your account. Apple and Google act as independent controllers for the transaction and keep purchase records according to their policies and timelines. Tax documents we must retain follow the times indicated in section 9.
12.2 Advertising
Free accounts see banner ads provided by Google AdMob, shown when opening a marker. Active subscribers see no ads.
Before requesting any ad:
Refusing means continuing to see ads, but chosen without profiling. AdMob may process your advertising ID, ad interactions, approximate location and device info per Google's policies. You can reset or clear your advertising ID anytime in device settings.
12.3 Nearby spot alerts and background location
Nearby spot alerts notify you when a dog spot appears near you while the app is closed. To do this, the app registers geographic regions with the operating system - up to 20 regions on iOS and 100 on Android, each with a radius of about 100 m - and the OS wakes the app when you enter one. Regions are chosen from spots near you and deregistered when those spots expire. This requires background location permission ("Always" on iOS, "Allow all the time" on Android), a significantly more invasive step than foreground location described in point 6.4. Consequently:
Background location is evaluated on your device against registered regions. As with foreground location, we do not keep raw coordinates as a permanent log of places you have been.
13. Minors
WoffApp is not intended for anyone under 16 years old. We do not knowingly collect personal data of minors under 16. By creating an account you confirm you are at least 16. If you believe a minor under 16 has created an account, write to info@woffapp.com and we will promptly delete the account and related data. The 16-year threshold is a deliberate choice: it is the maximum digital consent age allowed by art. 8 GDPR, thus valid in every EEA country regardless of local age.
14. Security
We protect data, among other means, with:
No system is perfectly secure. In case of a personal data breach posing a risk to your rights and freedoms, we will notify the Supervisory Authority within 72 hours as required by art. 33 GDPR and inform you directly in cases foreseen by art. 34.
15. International transfers
Our main archives (Cloud Firestore and Cloud Functions) are located in europe-west3 (Frankfurt, Germany), inside the EEA. Some providers listed in point 8.2 are established in the United States or operate globally. When personal data is transferred outside the EEA, the transfer is based on:
You may request copies of applicable safeguards by writing to info@woffapp.com.
16. Changes to this privacy notice
We may update this notice as WoffApp evolves. The version number and effective date at the top of the document always identify the current text.
Previous versions are archived at https://woffapp.com/legal/archive.
17. Contacts
Privacy, data subject rights and support: info@woffapp.com
Mail: [LEGAL_ENTITY_NAME], [REGISTERED_ADDRESS]
This notice is published in Italian and English. In case of discrepancy, for users residing in Italy the Italian version prevails.
Ita
Eng
Effective date: 10 August 2026
Version: 1.0
Last updated: 10 August 2026
This Privacy Notice explains how WoffApp collects, uses, shares, and protects personal data when you use the WoffApp mobile application for iOS and Android (the "App") and the website https://woffapp.com (the "Site", together with the App, the "Service").
We wrote this document to be read, not just stored. If anything is unclear, please write to info@woffapp.com.
1. Who processes your data
The data controller ("we") is:
Data Controller [LEGAL_ENTITY_NAME]
Registered office [REGISTERED_ADDRESS]
VAT / tax code [VAT_NUMBER]
Email (privacy, data subject rights and support) info@woffapp.com
Data Protection Officer (DPO) [DPO_CONTACT_OR: "Not appointed. The conditions of Art. 37 GDPR do not apply."]
We are established in Italy and the Service is aimed at users in the European Economic Area. Processing is governed by Regulation (EU) 2016/679 ("GDPR") and Legislative Decree 196/2003 and subsequent amendments ("Privacy Code").
2. What WoffApp does in terms of privacy
WoffApp is a location-based social app dedicated to dog owners.
Four concepts are enough to understand this notice:
The most relevant privacy consequence: when you create a dog spot, you deliberately publish an approximate real location where you and your dog were, making it visible to nearby strangers for up to 72 hours. Section 6.5 explains this in detail. We ask you to read it.
3. Summary Table
What we process
Perchè
Legal basis
For how long
Account: email, password, Firebase user ID, login provider
Create and protect your account
Contract (Art. 6(1)(b))
Until account deletion
Profile: display name, language, city, notification preferences
Make the App work as you configured it
Contract
Until account deletion
Dog profiles: name, birth date, breed, sex, likes, dislikes, description, photos
Main function requested by you
Contract
Until account deletion
Device location while using the App
Show map, find nearby places, create spots
Consent (Art. 6(1)(a)) via system permission
Not stored as raw coordinate; see 6.4
Device location in background, only if you enable nearby spot alerts
Notify you when a dog spot appears near you
Consent (Art. 6(1)(a))
Not stored as raw coordinate; see 12.3
Dog spot: coordinate, geohash, times
Main function
Contract
Deleted permanently after 72 hours or upon removal
Sniffs and social history
Main function and challenges
Contract
Until dog or account deletion
Facts, scores and challenge leaderboards
Gamification
Contract
Rolling windows plus 21 days; see 9
Notification token, installation ID, platform, categories
Deliver notifications you have enabled
Consent + contract
Until logout, token change or deactivation
Crash and error diagnostics
Keep the App working
Legitimate interest (Art. 6(1)(f))
90 days with provider
App integrity attestations
Prevent abuse and fraud
Legitimate interest
Short duration, managed by provider
Place proposals and moderation logs
Maintain the place directory
Legitimate interest
Until record removal; audits remain
Subscription status
Remove ads for subscribers
Contract
Subscription duration plus legal terms
Advertising identifiers
Show ads to non-subscribers
Consent
According to provider policy
4. What we do not collect
To set expectations precisely:
5. Private, public and pseudonymous data in WoffApp
WoffApp separates what you enter from what other users can see. This separation is enforced by the server, not just the interface.
Private, only yours. Your email address, your Firebase user ID, account settings, notification tokens, your dogs' private cards, original uploaded photos, exact coordinates of your spots, private progress counters in challenges, and the list of sniffs sent and received.
Published to other users, in pseudonymous form. When you register a dog and create a spot, the server generates a public projection of the dog from the private card. This projection contains an opaque public identifier not linked to your account, plus name, breed, sex, birth date, likes, dislikes, description and sanitized copies of gallery photos. It deliberately excludes your user ID, email address, the dog's private ID, original photo storage paths and any precise location other than the spot you chose to publish.
Important consequence: the projection is pseudonymous, not anonymous. If you give the dog an identifying name, describe where you live in free text or upload a photo showing your house number, other users can recognise you. Treat description and gallery as a public post.
6. What we collect, in detail
6.1 Account and authentication
At registration, we process your email address and a password. The password exists only within the login interaction and the request to Firebase Authentication; we do not create separate copies or logs. Firebase Authentication stores the account identity, an anonymous Firebase user ID (UID), the authentication provider used, login times and token claims. Where the App offers Google or Apple login, we also process the OAuth credential returned by the provider and the email address the provider communicates to us. With Apple, you can choose to hide your address, in which case we receive only a private forwarding address: emails we send you then pass through Apple's forwarding service. Firebase Authentication and the operating system may store session credentials in device memory areas managed by the SDK and system. Logout revokes the App's powers and asks Firebase to disconnect the session, but we cannot and do not claim to physically delete that cache managed by the provider.
6.2 Profile and settings
We store a cloud profile document containing your UID, display name, email address, optional profile photo URL, app language, city, notification preferences and creation date, plus copies of your role (regular user or administrator) and subscription status. This allows your settings to survive a reinstall.
6.3 Dog profiles and photos
For each registered dog, we store: name (mandatory) and optionally birth date, breed (free text), sex, likes, dislikes, a description and an ordered photo gallery whose first image is the profile photo. We do not collect your age; the dog's age is derived from the birth date.
Photos are selected from the gallery or camera via the operating system selector. We receive only the images you choose. Originals are stored in Firebase Storage under your account. A server-side process generates sanitized public copies (a full version up to 5 MiB and a thumbnail up to 512 KiB), which are those actually loaded by other users. Uploads are limited to 20 MiB per image.
Note on photo metadata: WoffApp does not remove EXIF metadata from uploaded image bytes. If your camera inserts GPS coordinates in photos, those coordinates may travel with the image. If this concerns you, disable geolocation in the camera app or use photos without it. If a dog card references an image hosted outside our infrastructure, opening it causes an HTTPS request to that third-party server, which will see your IP address and normal request metadata. Removing the URL stops future requests but cannot delete that server's logs. Using the system share panel on a photo exports a copy to the app or person you select. We cannot recall or delete that copy.
6.4 Location
By default, the App uses location only while you are using it. It requests "while using the app" permission on both platforms. The only exception is the optional nearby spot alerts feature described in section 12.3, which requests separate permission.
What happens on a location detection:
You can revoke location permission at any time from the operating system settings. The App remains usable, but map-centred discovery and spot creation stop working. Creating a dog spot is a distinct and deliberate act of publication. See 6.5.
6.5 Dog spot
When you create a dog spot, we store its coordinate, a geohash, creation time, expiry time at 72 hours, dog's sex, dog's opaque public ID, your user ID on the private card and a sniff counter.
Do not create a spot at your home, workplace, a school or any place whose exposure could put you or others at risk. A sequence of spots at the same place at the same time reveals a habit. The "Best Routine" and "Early Bird" challenges exist precisely because these patterns are readable.
6.6 Sniffs and social history
Sending a sniff creates a record linking your dog to the spot and the target dog, with a time. Both parties maintain aggregated counters (sent, received, last sent, last received) that feed the best friends view and challenges. The sniff history is permanent: it is kept until the dog or account involved is deleted. Expired spots do not delete received sniffs.
6.7 Challenges and leaderboards
Challenges are calculated server-side from immutable "facts" (a sniff occurred, a spot was created, a contribution to a service was accepted). The catalogue includes: Neighbour's Administrator, Most Popular, Most Friendly, Best Routine, Early Bird, Most Active, Adventurer, Best Woffer and other entries shown in the App. Privacy-relevant elements:
Challenges are added and withdrawn over time. New challenges reuse the same facts and pseudonymous projections described here; a challenge requiring a new data category would first require an update to this notice.
6.8 Service locations, proposals and moderation
The service location directory is curated. Any user can propose a new place or a modification and can support an existing proposal.
When you use the place search field, the typed text, search session token, app language and visible map portion are sent to Google Places to get suggestions, and the chosen place is resolved into a place ID, formatted address and structured address components.
Reverse geocoding sends a coordinate to Google to get a readable address. Google retains these requests according to its policy; we cannot delete them. Moderation logs keep author ID, supporter IDs, proposals, decision, reviewer, times and a request digest. These logs serve to verify contested decisions later and are kept even after the proposal is resolved.
Accepted contributions also feed the "Neighbour's Administrator" challenge, which stores the number of accepted contributions and up to ten contribution lines, visible only to you.
6.9 Push notifications
If you authorise notifications, we register a device installation: an installation ID generated by the App, platform, app version, distributed language, notification permission status, enabled categories and the push token issued by your platform's notification service (Firebase Cloud Messaging on Android, Apple Push Notification service on iOS) with its hash. The server maintains a delivery log with event IDs, emission and expiry times, recipient hashes and recipient IDs, so a new attempt does not duplicate a notification. Current notification types: a spot you created was published, you received a sniff, a sent sniff was confirmed, new nearby service content. Resolving a notification in a readable card involves further reads: the exact spot, public projection and sender dog's thumbnail and an address obtained by reverse geocoding from Google for the spot's coordinate.
Some installation-level values (installation ID, operation generation counter and flag recording that the notification prompt was already shown) intentionally survive logout and are deleted by removing App data or uninstalling it, not by signing out. You can disable categories in the App Settings and disable notifications entirely from the operating system settings.
6.10 Local storage on your device
The App stores a small set of values in the device preference store: whether you completed the tutorial, chosen language, a per-account copy of your notification setting, preferred challenge and short-term records of undelivered commands (parts of owner and scope keys as hashes, a command ID and a time, kept for up to seven days). The built-in Firestore offline cache also stores copies of documents you viewed and pending writes, so the App works offline. This cache is managed by the Firebase SDK. Logout isolates it so data from another account cannot be shown, but we do not claim to physically delete it on logout. Uninstalling the App or deleting its data removes it.
6.11 Diagnostics, crash reporting and analytics
6.12 App integrity
Firebase App Check, together with Google Play Integrity on Android and Apple App Attest on iOS, produces short-lived attestations proving requests come from an authentic, unmodified copy of the App. We do not keep any attestation logs. These tokens are anti-abuse measures and never alone confer authorization.
6.13 Remote configuration
Firebase Remote Config delivers typed configuration parameters (feature flags and similar) to the App. It fetches configuration and reports parameter keys and model version. No personal data is sent for this purpose.
6.14 In-app feedback
If you send feedback from within the App, we receive your message, feedback category, an optional attached screenshot, your email address, user ID, app version, platform and language, to help us understand the issue and respond.
7. Legal bases for processing
Purpose
Legal basis
Creation and management of the account; provision of map, dog profiles, spots, sniffs, challenges and activated notifications
Performance of a contract, art. 6(1)(b) GDPR
Access to device location, camera and photo library; delivery of push notifications; personalised advertising
Consent, art. 6(1)(a) GDPR, given via system permission or an in-app command and revocable at any time
Service security and availability: abuse prevention, App Check attestation, rate limiting, content moderation, crash and error diagnostics, fraud prevention
Legitimate interest, art. 6(1)(f) GDPR. Our interest is a service free from spam, abuse or defects; we have assessed that this does not override your rights, as the data involved is minimal and not used for profiling you
Subscription management and compliance with tax, accounting and consumer protection obligations
Contract and legal obligation, arts. 6(1)(b) and 6(1)(c) GDPR
Response to legitimate authority requests and legal defence
Legal obligation and legitimate interest, arts. 6(1)(c) and 6(1)(f) GDPR
When processing is based on consent, withdrawing it is as simple as giving it (disable the permission in the operating system or the toggle in Settings) and does not affect the lawfulness of processing already carried out.
8. Who we share data with
We do not sell personal data. We share it with the following categories of recipients.
8.1 Other WoffApp users
As described in section 5: the public projection of your dog, your active spots within about 5 km and your position in public leaderboards.
8.2 Data processors and sub-processors
Recipient
Role
Data involved
Location
Safeguards
Google Ireland Ltd / Google LLC - Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, Remote Config, App Check
Hosting, database, storage, server logic, push transport
Virtually all Service data
Firestore and Cloud Functions operate in europe-west3 (Frankfurt, Germany). Other Firebase components and support may involve processing in the USA
Google Cloud Data Processing Addendum; EU Standard Contractual Clauses; EU-US Data Privacy Framework
Google Ireland Ltd / Google LLC - Google Maps Platform (Maps SDK, Places, Geocoding)
Map rendering, place search, address resolution
View boundaries, coordinates, typed queries, session tokens, IP address
Global
Google Maps Platform Terms; Google Privacy Policy
Google LLC - Play Integrity
Integrity attestation on Android
Device and app integrity signals
Global
Google Play Terms
Apple Inc. / Apple Distribution International Ltd - App Attest, App Store, APNs
Integrity on iOS, distribution, push transport
Attestation signals, purchase logs, push tokens
Global
Apple Privacy Policy
Functional Software Inc. (Sentry)
Crash and error diagnostics
Firebase UID, cleaned exception stack traces, release and device context
United States, with EU data region available
Sentry DPA; EU Standard Contractual Clauses
RevenueCat Inc. (v. 12.1)
Subscription management
Firebase UID, pseudonymous user ID, store receipt and subscription status
United States
RevenueCat DPA; EU Standard Contractual Clauses
Google Ireland Ltd - AdMob (v. 12.2)
Advertising
Advertising ID, ad interaction data, approximate location, device data
Global
Google Ads Data Processing Terms
Each acts as our processor, or as an independent controller in limited cases where the provider determines its own purposes (notably Google Maps, Apple and Google as store operators, and advertising providers). We maintain an updated list of sub-processors, available on request at info@woffapp.com.
8.3 Other disclosures
We may disclose data to professional advisors, to a buyer in case of merger or acquisition (with notice), and to public authorities when a valid legal obligation requires it.
9. How long we keep data
Data
Retention
Account, profile, notification preferences
Until account deletion
Dog profiles and original photos
Until deletion of the dog or account
Public projections and sanitized photos
Deleted upon deletion of the original dog; a cleanup queue reconciles derived copies
Dog spots
Permanently deleted 72 hours after creation, or immediately upon removal
Sniffs, counters and social history
Until deletion of the involved dog or account
Challenge facts derived from spots
Until the closure of the last weekly or monthly window consuming them, plus 21 days, then automatically deleted; also deleted upon deletion of spots, dog or account
Leaderboard entries, boards and scores
For the weekly or monthly window plus 21 days
"Home" Adventurer reference (5 km privacy cell)
Until deletion of the dog or account
Service proposals and moderation logs
Retained after resolution, as an audit trail of the decision
Notification installation, push token and delivery log
Until logout, permission revocation, token rotation or entry expiration
Local logs of pending commands
Maximum 7 days
Crash and error events
90 days at the provider
Server request logs (including Google Cloud logs)
According to provider default, typically 30 days
Purchase and billing documents
10 years, as required by Italian tax law
Offline Firestore cache on your device
Until app data deletion or uninstallation
When a retention period is set by a provider we do not control, we declare it, instead of promising deletion we cannot perform.
10. Data deletion
10.1 Deleting a single dog
Deleting a dog removes its private profile, photos, public projection and spots, and cancels progress in challenges that dog contributed to. Your other dogs and their spots remain unaffected.
10.2 Deleting the account
You can delete your WoffApp account and all associated data from Settings -> Account -> Delete account in the app. You can also request deletion by writing to info@woffapp.com from the registered account email: we will complete it within 30 days. Deletion is a phased server-side process. It removes the profile, dogs, their photos and public projections, all their spots, sniff records, challenge progress and references, notification installations and finally the Firebase Authentication identity. It is irreversible. What deletion cannot reach, honestly stated:
10.3 Web deletion path
For store compliance, an account deletion request page is available at https://woffapp.com/account-deletion and works without installing the app.
11. Your rights
Under arts. 15 to 22 GDPR you have the right to:
To exercise these, write to info@woffapp.com. We will respond within one month, extendable by two months for complex requests, and inform you if an extension is needed. We may ask you to verify your identity, but only proportionately.
Right to complain.
If you believe your data processing is unlawful, you may complain to the Italian supervisory authority:
Garante per la protezione dei dati personaliPiazza Venezia 11, 00187 RomePhone: +39 06 696771Email: garante@gpdp.it - PEC: protocollo@pec.gpdp.itWebsite: https://www.garanteprivacy.it
You may also contact the supervisory authority of your EU country of residence or work, or take legal action.
12. Subscriptions, advertising and nearby spot alerts
These three areas involve data processors and permissions not used by the rest of the app, so are described separately. Availability depends on your platform, geographic area and app version.
12.1 Premium subscription and payments
WoffApp offers an optional recurring subscription that removes advertising. Purchases are made via Apple App Store and Google Play, which handle payment. We never receive your card number, bank details or billing address. Rights management is handled by RevenueCat, which receives your Firebase UID or a pseudonymous user ID, store receipt and resulting status (active, expired, grace period, billing issue), so the subscription follows you across devices and reinstallations. Our servers keep only the resulting status, linked to your account. Apple and Google act as independent controllers for the transaction and keep purchase records according to their policies and timelines. Tax documents we must retain follow the times indicated in section 9.
12.2 Advertising
Free accounts see banner ads provided by Google AdMob, shown when opening a marker. Active subscribers see no ads.
Before requesting any ad:
Refusing means continuing to see ads, but chosen without profiling. AdMob may process your advertising ID, ad interactions, approximate location and device info per Google's policies. You can reset or clear your advertising ID anytime in device settings.
12.3 Nearby spot alerts and background location
Nearby spot alerts notify you when a dog spot appears near you while the app is closed. To do this, the app registers geographic regions with the operating system - up to 20 regions on iOS and 100 on Android, each with a radius of about 100 m - and the OS wakes the app when you enter one. Regions are chosen from spots near you and deregistered when those spots expire. This requires background location permission ("Always" on iOS, "Allow all the time" on Android), a significantly more invasive step than foreground location described in point 6.4. Consequently:
Background location is evaluated on your device against registered regions. As with foreground location, we do not keep raw coordinates as a permanent log of places you have been.
13. Minors
WoffApp is not intended for anyone under 16 years old. We do not knowingly collect personal data of minors under 16. By creating an account you confirm you are at least 16. If you believe a minor under 16 has created an account, write to info@woffapp.com and we will promptly delete the account and related data. The 16-year threshold is a deliberate choice: it is the maximum digital consent age allowed by art. 8 GDPR, thus valid in every EEA country regardless of local age.
14. Security
We protect data, among other means, with:
No system is perfectly secure. In case of a personal data breach posing a risk to your rights and freedoms, we will notify the Supervisory Authority within 72 hours as required by art. 33 GDPR and inform you directly in cases foreseen by art. 34.
15. International transfers
Our main archives (Cloud Firestore and Cloud Functions) are located in europe-west3 (Frankfurt, Germany), inside the EEA. Some providers listed in point 8.2 are established in the United States or operate globally. When personal data is transferred outside the EEA, the transfer is based on:
You may request copies of applicable safeguards by writing to info@woffapp.com.
16. Changes to this privacy notice
We may update this notice as WoffApp evolves. The version number and effective date at the top of the document always identify the current text.
Previous versions are archived at https://woffapp.com/legal/archive.
17. Contacts
Privacy, data subject rights and support: info@woffapp.com
Mail: [LEGAL_ENTITY_NAME], [REGISTERED_ADDRESS]
This notice is published in Italian and English. In case of discrepancy, for users residing in Italy the Italian version prevails.
Ita
Eng