Pawcasso Run — Privacy Policy
Last updated 2026-09-23
Pawcasso Run turns a run into a drawing: you pick an animal and roughly where you are, and the app finds a route through real streets that looks like it.
This policy explains what that costs you in personal data, which is less than most apps but not nothing. There is no Pawcasso account, advertising, tracking or third-party analytics kit. Pawcasso does keep route-generation records and explicit feedback so it can evaluate and improve the drawings; Apple calls that purpose Analytics on its App Privacy label. Some server data can be associated with a device, network address, search or optional Strava account even without a Pawcasso login, so the prepared App Store label treats every collected category as linked. If you choose to connect Strava, Strava authenticates you and Pawcasso holds the athlete number and credentials needed for that optional connection while it remains active, as described below.
Who is responsible
The controller for the processing described here is Huiyan Wan, an individual running this app as a personal project rather than a business. Questions, requests and complaints — including any of the rights set out at the end of this policy — go to privacy@pawcasso.run, which is read and answered by that person.
What is sent or retrieved, and when
Only the things below are sent from your device or retrieved for the app, and each one is listed with what triggers it.
| What | When | Why |
|---|---|---|
| The place text you type (e.g. "St Albans") | As you confirm a place | To resolve it to a real settlement and show you "you typed X → we understood Y" |
| Your device's coordinates, at full precision | Only if you tap "my location" | To name the town you are near, and to put nearby matches first when a place name is ambiguous (there are a lot of Bostons) |
| The animal, the maximum distance, and how far the search may roam | When you tap "Find my routes" | To search for a route |
| A short code for each route you have already been shown — a 16-character fingerprint of the route's shape, not the route itself and not anything about you | When you tap "Find my routes", if you have been shown routes before | So the search can skip a route you already have and offer you a different one instead. Not kept: it is held only while that search is running and is deleted from our records the moment it finishes |
| The id of the search you are queueing behind, if you ask for a second route while one is still being found | When you tap "Find my routes" while an earlier search is still going | So our server can hold your second wish and start it when the first one finishes — which is what lets you close the app without losing it. Not kept: deleted from our records when that search finishes |
| The notification address Apple issues to your copy of the app — a long code Apple gives us so it can deliver a message to this one phone | When you tap "Find my routes", only if you have said yes to notifications | So we can tell you your route is ready while the app is closed, which is what the app has been promising and could not do. Not kept: deleted from our records when that search finishes |
| A random feedback submission number, feedback kind, search id, animal, finalist letter (when the answer is about one route), town, the parts you select, anything you type, the time, and the pawprint reward tier recorded with the answer | Only if you tap "send" | To understand why a drawing missed and improve future route generation. Apple calls this Analytics because it evaluates how well a feature works |
| For detailed route feedback: the complete original and edited route lines, the map centre and span you saw, and every edit's route-section start and end, dragged point, replacement walking line and routing provider | Only after at least one successful edit, when you choose “save & send correction” | To compare the route we drew with the correction you intended and reproduce which changes made the animal read better |
| The two selected route-section endpoints and the point you drag toward | Each time you drag a section in the detailed editor | To ask Apple MapKit for two walking-directions legs: start to dragged point, then dragged point to end |
| A route's geometry, distance, animal, Pawcasso-given name and animal story | Only after the sharing note, if you tap "invite a friend" | To make a 90-day public care invitation you can send to someone; a recipient with Pawcasso can preview and copy that exact planned route into their own sticker book |
| A bounded match around the animal section of the route you ran, its distance, moving time and Pawcasso score, and total metres climbed when available | Only after a separate warning, if you tap "share story" on a completed run | To make a 90-day public celebration page. This can be derived from a run you selected in Apple Health. Pawcasso clips the rest of the outing, but the public line can include points within 120 metres of the animal and up to 120 metres near each end. If the app cannot isolate that section safely, it publishes nothing. Heart rate, weather, point-by-point times and elevation charts are not sent |
| Your own Strava run, trail run, virtual run, walk and hike summaries from the preceding 90 days and, after a separate in-app explanation, a simplified route sketch, rough place and recording-device name | Only if you connect Strava and choose “show my Strava activities” | To help you recognise the right on-foot activity in the temporary picker. Pawcasso does not save this list |
| Your IP address | With every request | Rate limiting, and giving a search back to you if it did not produce a route — see below |
If you connect Strava
Connecting Strava is optional and happens through Strava's own permission screen. Pawcasso asks for read and activity:read_all so you can select one of your own eligible activities even when it is not public. The activity is shown only to the same athlete who connected the account. Pawcasso does not ask for permission to post, edit or delete anything in Strava.
- Pawcasso stores your Strava athlete number, the permissions you granted, and rotating access and refresh credentials while the connection is active. The secret belonging to Pawcasso's Strava application stays on our server and is never put in the iPhone app. The connection record is held in private server storage encrypted at rest.
- Before asking for richer recognition hints, Pawcasso shows a separate in-app explanation. If you choose “show my Strava activities”, Pawcasso retrieves eligible activities from the preceding 90 days. The temporary list may contain the Strava activity number, sport, date, distance, moving time, a simplified route sketch (up to 200 points), rough place and recording-device name. It is shown only to the Strava runner who connected that account and is cleared when the picker closes. Pawcasso does not save or cache the list and does not request the activity title, heart rate or social information.
- Downloading a selected run's GPS trace, comparing it with a Pawcasso route, and keeping the resulting Book card are paused. They require two separate written permissions from Strava: one for deterministic route comparison and one for retaining the completed card. The server reports both permissions as off unless each has been explicitly enabled after that written answer.
- Strava data is never provided to, used by, or put into the working memory of an artificial-intelligence system. This includes data derived from a Strava activity. Future animal-feature AI may work only from a source whose rules allow it; a Strava source remains excluded.
- Disconnecting in Pawcasso revokes the Strava credentials and deletes the connection record. Strava also sends Pawcasso a deauthorization event if you remove access in Strava. An expired or rejected credential is removed rather than silently retried forever. After a successful in-app disconnect, Pawcasso returns to the disconnected source picker; if deletion cannot be completed, the app shows an error instead of claiming it succeeded.
Strava may collect API usage information and use it for its own purposes under its API terms. Pawcasso does not receive that usage record. Strava's own privacy policy controls Strava's handling of data on its service.
Three rows above are new, added on 17 August 2026 with the owner's sign-off, to fix three real complaints: the same route being found twice and charged twice, a second wish being lost when you closed the app, and a promised notification that never arrived.
The first two do not identify you. They work without Pawcasso knowing who you are — there is still no account, no device id and no installation id anywhere in a search request. What makes them work is that your phone already knows which routes it has been given and which search it is waiting on, and it tells us just enough to act on it. They are also the only two things that link one of your searches to another.
The third one is different and we would rather say so than bury it. A notification address is issued by Apple and points at your one copy of the app, so for as long as we hold it we are holding something that identifies a particular phone. That is unavoidable — it is the only way anyone can send a notification — but it is why we ask for it only when you have said yes to notifications, why it is sent per search rather than stored against you, and why it is deleted with the rest. If you never turn notifications on, it is never sent at all.
Two limits, and both are enforced in the code rather than promised here:
- None of the three is kept. They ride along only while that one search is waiting and running, and are removed from the stored record the moment it finishes. Everything else about the search is kept for 30 days as described below; these three are not.
- Two of the three say nothing about you. The route code is a fingerprint of a route's shape — it cannot be turned back into a route, and the same route drawn for a different person produces the same code. The queue id is the id of one of your own searches. The notification address is the exception, and it is described above.
While a second wish is waiting its turn, the record does say that two particular searches came from the same phone. That is unavoidable — it is what a queue is. It lasts as long as that wait and the search that follows it: the record is cleared when the search reaches its end, not at the moment the waiting stops.
Detailed feedback contains precise coordinates, but they describe a planned route, not where you actually moved. Editing alone changes only a working copy. After you finish, both forward choices save your edited line as the route you run, share and export; if it was not already in your sticker book, it is added there. “Save to sticker book · don't send” keeps Pawcasso's original line beside it and sends no detailed edit. “Save & send correction” saves the same route and also sends the correction to Pawcasso.
Location recording happens only during a run you explicitly start. Tapping Start begins Precise Location so Pawcasso can show your real position and how far you are from the nearest part of the animal line. Reaching that line starts the travelled trace and animal progress. From then until the run is stopped, it continues if you lock the phone or use another app. iOS keeps its location indicator visible while this happens. Accepted fixes continue adding to the travelled distance, duration, moving time and animal progress while the screen is locked. A run auto-pauses after 15 minutes without movement that clears GPS uncertainty, and an absolute 12-hour limit pauses it even if it keeps moving. Pause, Finish or Abandon also stops the updates immediately. Pawcasso asks for When In Use, not Always, and cannot restart a terminated app to track you. An unfinished run is saved on this phone and reopens paused rather than silently resuming. A finished run may be kept as the one latest-run record used by Home. Neither record is sent to Pawcasso for Home.
Feedback is optional, and only a sent route correction is rewarded. Answering the short questionnaire earns nothing. Sending a finished route correction earns 2 pawprints for the app's local jar, settled once for that route only after our server acknowledges that the full payload has been stored. That reward is added in full whatever your balance is: the jar's everyday level is 50, but a feedback reward can carry it above that and nothing takes the difference away. An identical retry returns the same acknowledgement and does not settle the reward twice.
The short questionnaire and the edited route are separate feedback tiers. Sending the questionnaire shares that answer and earns nothing; skipping it sends nothing, and either choice continues to the editor. “Gave up” sends no detailed edit. After a successful edit, private save uploads no detailed edit and earns no pawprints; “save & send correction” sends the original and edited geometry and edit context and qualifies for the once-settled detailed tier.
For each accepted answer, the server also creates a non-content retry marker. It contains only the stored payload's path and a one-way content fingerprint; it does not contain the note or either route line. The random submission number, payload and marker make a network retry safe without letting a later request overwrite an earlier answer.
Most Apple Health details stay on your phone, and heart rate always does. Heart rate, point-by-point times and the elevation series are never sent. When you import a recorded run, the workout is read and compared with the planned route on your phone. If the workout contains no weather condition, the app sends Apple WeatherKit one point from the middle of the route and the middle time of the workout to retrieve the historical hourly condition. It does not send the complete route, heart rate or other workout details. Apple's returned condition is stored on this phone and is not sent to Pawcasso. The one exception is a share you choose: after a warning that names the travelled animal section and its boundary window, a completed-run web story sends that bounded section, moving time and the small achievement figures listed above; one total-climb figure may be included, but never its underlying elevation readings. Your sticker book, saved routes, recent finds and latest run otherwise stay in the app's own storage, and may be included in your iPhone backup. What goes into a backup from them never includes heart rate. For a run imported from Apple Health it also leaves out the point-by-point times, the elevation series, weather and temperature; that run's route line may be included. The full route-feedback payload leaves only on a final send. The three MapKit routing points leave earlier, when you drag a section in the detailed editor, as described above.
How Home chooses what to show
Home makes this choice on your phone, from records already stored by the app. If there is a real run record, Home shows the most recent actual run, even when an older run scored higher. That one latest-run record includes the full route actually run. If there is no usable run record, Home compares completed recent finds and saved routes using the route generator's stored final rank, where 1 is best. It chooses among the routes with the best rank available. If several different routes tie, a random number created once on your phone makes the choice stable across launches. An older saved route with no rank can still be shown, but it is labelled only “a saved route”, not “best”.
No recommendation request is sent to Pawcasso. The app does not send the latest-run trace, local find/save history, tie-break value or selected card to Pawcasso or anyone else to make this choice. Opening the card reuses that existing record and does not start or charge for another Pawcasso search. Apple MapKit may load the map as described elsewhere in this policy.
This is limited automated personalisation from activity stored on the device. It does not infer traits, place the runner in a segment, or create a server-side, cross-device or identity-linked profile. It is not used for advertising, marketing or engagement targeting, and the card choice has no legal or similarly significant effect.
Your IP address
Every request carries your IP address, as every internet request does. It is used to count requests per client so one caller cannot exhaust the service. The counting window is one hour, and the count lives in the running server's memory — it is discarded when the window passes, and gone entirely whenever the server restarts.
While a search is running, the server also remembers which address asked for it. It keeps a pair — that search's own id, and the address it was submitted from — for one reason: if the search does not produce a route, we give you that search back instead of letting it count against your hourly allowance. That covers a search that never got to run at all, because the map service we depend on is down or the machine doing the work is stopped; a search that came back with "we can't draw that here" rather than a route; and a search that looked all over the town and found nothing good enough to draw. To give it back we have to know whose it was.
That pair lives in the running server's memory only and is dropped as soon as the search finishes, whether it worked or not. After one hour it can no longer be used for anything, however the search ended. If you closed the app mid-search and nothing ever came back to finish it, the leftover pair is cleared the next time the server starts a search — and, like everything else here, it is gone the moment the server restarts.
Your IP address is not written to any database, is never stored alongside a route, is never sent to anyone else, and is not used to identify you. Server logs generated by our hosting provider may contain it; those are covered by Google's retention, described below. Apple's App Privacy rules use a broader test than "used to identify": because the address is a device/network detail and is temporarily paired with a search, the prepared label conservatively declares it as linked Other Data Types for App Functionality.
Sharing a route: the part worth reading twice
There are two deliberate share choices. “Invite a friend” publishes a planned Care route after its sharing note. “Share story” publishes a completed outing after a separate warning that names the travelled animal section and its boundary window. Either one is stored on our server and served from a public, unauthenticated URL for 90 days. Anyone with the link can open it. A planned Care recipient can preview and copy that route into Pawcasso; a completed story offers viewing and a recorded GPX download, not adoption. That means:
- Do not share a link you do not want to be public. Treat it like an unlisted web page, not a private message.
- A Care invitation publishes the route we suggested. When you ask for a route you type a place name — a town or neighbourhood — and we look anywhere in a wide area around its centre. Its start is a street corner our search picked, not an address we hold.
- A completed story publishes a bounded match around the animal section you travelled. The app clips away the rest of the outing, but the public section can include points within 120 metres of the planned animal and within a start and finish window equal to 15% of the planned route, capped at 120 metres at each end. If it cannot identify both boundaries confidently, it publishes nothing. Heart rate, weather, point-by-point times and elevation readings stay on the phone; the public story carries distance, duration, Pawcasso score and total climb when known.
- Sending a completed GPX file directly uses the phone's ordinary share sheet and does not send that file to Pawcasso. Creating a web story is the separate action that does send the travelled line to our server.
- The bounded animal section is published whole. Pawcasso does not remove a fixed number of metres from the GPS line: it matches the real trace to the planned animal and keeps one contiguous section inside the limits above. There is no fallback that publishes the complete outing.
- Every shared link shows a location-sensitive route. A planned route shows an area you chose; a completed story shows where you actually went. If you are not comfortable with that, do not share the link.
- A shared route expires by itself after 90 days.
- The recipient's choice stays on their phone. Pawcasso does not tell the sender whether an invitation was accepted, and it creates no account, friends list or social profile.
Who else sees this data
These are all the recipients. None of them is an advertiser or a data broker. Except for the optional Strava connection described below, Pawcasso has no account or profile identity to pass to them.
- Google Ireland Limited / Google LLC — Google Cloud Run and Cloud Storage host the service and store shared routes, search jobs, feedback payloads and their non-content retry markers. The region is
europe-north1(Finland). - The OpenStreetMap Foundation — the place name you type (and, if you tapped "my location", your coordinates as a search bias) is sent to their Nominatim service to be resolved into a real place.
- Overpass API providers —
overpass-api.de,overpass.kumi.systemsandoverpass.private.coffeereceive a bounding box around the area being searched, so we can fetch the street network for it. They receive the area, never a person. - Apple — the app asks Apple's own geocoder to turn a location fix into a town name, and the maps in the app are Apple MapKit. When you drag a section in the detailed route editor, Apple MapKit also receives that section's two endpoints and the point you dragged to, to calculate two walking-directions legs. Pawcasso does not send Apple the complete original route, complete edited route, feedback note or other feedback fields for that request. If a selected Apple Health workout has no weather condition, Apple WeatherKit receives one route-midpoint coordinate and the workout-midpoint time to return its historical hourly condition; it does not receive the complete route or the workout's heart rate. Apple's handling of its services is covered by Apple's privacy policy.
- Strava, Inc. / Strava Ireland Limited — only if you choose to connect Strava. Strava authenticates you, shows the permission screen, supplies your athlete number and your own activity summaries, and receives token exchange, refresh and revocation requests. Pawcasso does not send Strava a Pawcasso profile because Pawcasso has no accounts or profiles.
If you are here because someone sent you a route link
The page a shared route opens on is a web page, and like any web page it loads things from other servers. This affects you, the person opening the link — not the runner who sent it:
- The OpenStreetMap Foundation's tile servers send the map images the route is drawn on, so they receive your IP address and which part of the map you are looking at.
- unpkg.com (run by Cloudflare) serves the mapping library the page uses to draw the line, so it receives your IP address.
On a planned Care invitation, if you choose "Welcome into your care", the installed Pawcasso app asks our server for the same route, name and animal story so it can show the preview. That request carries the ordinary IP address every internet request carries. If you then adopt the animal too, the route is copied into the app's storage on your phone. There is no acceptance message to the sender.
Nothing else. The web page sets no cookies, runs no analytics, and the handwriting font is served from our own server precisely so that no font company is added to this list.
Nothing is sold, and nothing is shared for anyone's marketing.
How long anything is kept
- Shared routes: 90 days, then automatically deleted.
- Search jobs (the record of a find in progress and its results): 30 days, then automatically deleted.
- Routes we have already drawn: kept with no expiry. Separately from the search job above, we keep a copy of the route lines our generator produced — the line itself, the animal, the distance, and the map coordinates it was drawn at. The place text you typed is not kept in this copy. We keep it for two reasons, and the second one is part of how the app works rather than something we only look at later: to study which routes read well as animals so we draw better ones, and because a route already worked out for one search may be reused to answer a later matching search faster. This is a different store from the search job, which is still deleted after 30 days as described above.
- The generator's own record of a search: kept with no expiry. Separately again, we keep what our route generator considered for each search — every candidate route line it drew, where on the map it placed the drawing, and how its own checks scored each one — so we can learn which choices produce a route that reads as the animal. The place text you typed is not kept in this record. Unlike the drawn-routes copy above, this one sits in the same storage area as the search job, and that area's 30-day rule does not reach it, so no storage lifecycle rule deletes it. Keeping it with no expiry is the owner's deliberate retention decision.
- Route-feedback payloads and their non-content retry markers: 365 days, then automatically deleted. The payload may include both complete planned route lines and the edit context described above. The marker contains only its storage path and one-way content fingerprint. This gives enough time to compare repeated complaints and generation changes without keeping the answer indefinitely.
- Privacy-minimised feedback learning evidence: kept with no expiry. We keep the animal, answer, selected or missed animal-part ids, animal-part-to-route spans, edit operations and minimised measurements needed to understand what the feedback taught us. The permanent record has a keyed review token and a source-content fingerprint so an authorised reviewer can check the structured fact while the 365-day source still exists. It does not keep the note, typed place or raw feedback submission id, and the token is not a public lookup value.
- Rate-limiting counters, and the "which address asked for this search" pair described above: one hour, in the server's memory only. The pair usually goes sooner than that — as soon as the search finishes.
- A Strava connection: the athlete number, granted scopes and rotating credentials are kept only while you remain connected. Disconnecting or a Strava deauthorization event deletes them promptly. Recent-run lists are not stored by Pawcasso; their simplified route, rough place and device hints are cleared from the phone when the picker closes. Detailed run traces and derived completed cards are not retrieved while the two written-policy permissions described above are off.
- On-device route records: saved and collected routes stay until you remove them or delete the app. Completed recent-find geometry is kept locally and scrubbed after 30 days. One latest actual-run trace is replaced when a newer real run is accepted. There is no separate Home-history switch or latest-run clear control today; deleting the app removes all of these local records.
Shared routes, search jobs and route-feedback payloads are deleted by storage lifecycle rules on the bucket that holds them, which runs automatically — there is no button anyone has to press and no code path that can forget. Those rules cover named parts of that bucket rather than all of it, and the generator's own record of a search sits in a part no rule covers today, which is why it is listed above as kept with no expiry. The kept-with-no-expiry copy of drawn routes described above is different again: it lives in a separate bucket with no deletion rule, which is what "no expiry" means there. Once deleted, Google Cloud Storage keeps a recoverable copy for a further 7 days before it is destroyed for good; that is the platform's standard safety net against accidental deletion, it is not an extra copy we take or use, and nothing can reach it through the app.
The lawful basis for each of these
- Finding and showing you routes (the place, the animal, the distance): legitimate interests, UK GDPR Article 6(1)(f) — you asked for a route and this is what it takes to give you one. Our assessment is that the impact is small and expected: the data is a town name and a drawing preference, held briefly without building a Pawcasso account or cross-search profile. While a search is active it may be associated with the IP address or notification token needed to run, limit and notify that search; those links are bounded as described above.
- Keeping the routes we have already drawn, with no expiry: legitimate interests, Article 6(1)(f) — drawing better animals in future, and answering a matching later search faster from work already done rather than repeating it. That copy holds the drawing and the map coordinates it was drawn at, and does not hold the place text you typed. Our assessment is that the impact is small: it describes a line through public streets that our own search picked, it is linked to nobody, and we do not hold your identity to link it to.
- Keeping the generator's own record of a search, with no expiry: legitimate interests, Article 6(1)(f) — learning which of our own choices produce a route that reads as the animal, which is the only way we get better at drawing them. That record holds the candidate route lines and the map coordinates they were drawn at, and does not hold the place text you typed. Our assessment is the same as for the drawn routes above: it describes lines through public streets that our own search picked, it is linked to nobody, and we do not hold your identity to link it to.
- Choosing an existing route for Home: legitimate interests, Article 6(1)(f) — helping the runner return to a route already associated with their use of the app. The choice is made locally, starts no transaction or new search, and does not restrict any part of the service. This is the current technical assessment of the basis; the Children's Code analysis records why the core Home selector remains on by default.
- Using your precise location: consent, Article 6(1)(a), given through the iOS location permission and by tapping "my location" or explicitly starting an in-app run. You can withdraw it at any time in Settings → Privacy & Security → Location Services, and the app keeps working — you type a place instead.
- Connecting Strava and showing your own recent on-foot activities: consent, Article 6(1)(a). The connection is approved through Strava's permission screen; the richer temporary preview has its own Pawcasso explanation and “show my Strava activities” choice. You can withdraw both with Pawcasso's disconnect control, or revoke the connection in Strava's app settings. Pawcasso then revokes and deletes the connection. The app continues to work with Apple Health and file import.
- Publishing a route you chose to share: consent, given by tapping "invite a friend" after the note explains that anyone with the link can see the whole planned route and animal story for 90 days.
- Calculating a detailed route edit with Apple: legitimate interests, Article 6(1)(f) — providing the walking route you requested when you drag a section. The request is limited to the section's two endpoints and dragged point rather than the complete route or feedback record.
- Sending route feedback: consent, given separately by “send” on the short questionnaire and “save & send correction” after editing. The answer is used only to improve route generation. Ordinary feedback earns nothing; detailed route feedback earns 2 local pawprints, settled once for that route and only after durable server acknowledgement. That reward is not reduced by how full the jar already is. Skipping the questionnaire sends nothing. “Gave up” and private save send no detailed edit; an ordinary answer already sent before the editor remains sent. Both final save choices keep the edited route available to view, run and export.
- Rate limiting, including giving a search back when it produced no route: legitimate interests, Article 6(1)(f) — keeping the service available to everyone, and not making you wait out an hour for a search our own outage swallowed, or for one that could only tell you we can't draw that here.
Home's limited on-device card choice is described above. Pawcasso makes no automated decision with a legal or similarly significant effect, creates no server-side, cross-device or identity-linked profile, and does not use this history for advertising, marketing or engagement targeting.
Where the data goes geographically
The service runs in Google's Finland region (europe-north1), and the storage described above is in the same region. The recipients above may process data outside the UK (Google under its standard contractual clauses; the OpenStreetMap Foundation and the Overpass providers are in the EU/EEA, which the UK recognises as adequate; Apple and Strava describe their international processing and safeguards in their own privacy policies).
Your rights
Under UK GDPR you have the right to access your personal data, to have it rectified or erased, to restrict or object to its processing, and to data portability. Where processing rests on consent, you may withdraw that consent at any time.
In practice, most of these are already in your hands, and that is deliberate — we would rather not hold the data than administer rights over it:
- To erase a shared route before its 90 days are up, tell us its link and we will delete it.
- To erase everything on your device, delete the app.
- To erase a Strava connection, use disconnect Strava in Pawcasso or remove Pawcasso in Strava's app settings. Either route deletes Pawcasso's connection record. You can also write to us about it using the address below.
- Outside an optional Strava connection there is no Pawcasso account, so we usually cannot connect a request to any stored record. If you ask us for "your data" and give us nothing to look it up by, the honest answer will usually be that we hold nothing identifiable about you.
Write to privacy@pawcasso.run. We will respond within one month.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority: https://ico.org.uk/make-a-complaint/, 0303 123 1113. We would rather hear from you first, but you do not have to ask us before going to them.
Children
Pawcasso Run is not designed for children, but we assume children may use it, so the protections described here apply to everyone rather than to a special group. There is no Pawcasso account, and Pawcasso does not ask for anyone's age or name. An optional Strava connection supplies the athlete number and credentials needed for that connection; do not connect it if a parent or guardian has said not to. Location stays off until you tap "my location" or explicitly start an in-app run. The live screen makes recording visible. Once the travelled trace starts at the animal line, it can continue while the phone is locked or another app is in front; Pause, Finish and Abandon stop it. Home may use run, find and save history kept on this phone to choose one existing route, as explained above. No extra data leaves the phone for that choice. Pawcasso does not attach this history to a Pawcasso account, use it to advertise or market to you, or make a decision that affects your rights or access to the app.
The one thing worth explaining to a younger runner, or to a parent: a route link is public for 90 days and anyone with it can open the shared line. “Invite a friend” shares a route Pawcasso suggested. “Share story” on a completed run shares the real line you ran — but only the animal section, clipped to within 120 metres of the animal and up to 120 metres past each end. That clipped section can still include a home or a routine if you started or finished near one. It does not share heart rate, weather or detailed charts. If you are not sure, do not share it.
Detailed feedback is private rather than public, but it still sends more: the route Pawcasso drew, the route you changed it into, the map view and each edit. Apple receives the selected section's endpoints and your dragged point while it calculates the walking line. Pawcasso gives 2 pawprints for sending the detailed answer, and pays them in full however full your jar already is. Cancelling before the final send discards the edit and earns nothing. “Skip extras” is different: it sends the geometry without optional parts or a note and still qualifies. Either way, the original route remains the one you use, save and export.
Changes
If this policy changes materially, the date at the top changes and the new version is published here before the change takes effect in the app.