Privacy Policy
This policy describes the Wuffu iPhone app and its support website. Contact support@wuffu.app with privacy questions.
Your walking journal
Wuffu stores your walks, route coordinates, timestamps, location quality, distance, events, titles, notes, favorites, photos and dog profile in local app storage. It has no separate Wuffu account, advertisements or analytics SDK.
Location and photos
Location is used to record a walk that you start and to show your position when you use the location button in Walk. Using that button alone does not start or save a walk. An active walk can use location while Wuffu is in the background or your screen is locked. Pause or finish the walk to stop recording. You can change location permission in iOS Settings.
Photos are imported when you choose a dog-profile image or add images to a saved walk. Photos you choose are resized and saved as JPEG copies without copying the original EXIF, GPS or camera metadata. You can remove an image from the relevant profile or walk. Wuffu does not upload your photo library as a whole.
Live Activities
If you use Wuffu+ Live Activities during a walk, your dog's name and profile thumbnail, elapsed time, distance and walk status can appear on the Lock Screen and Dynamic Island. Live Activity buttons can add Pee and Poop events to the same active walk. Route coordinates, notes and walk photos are not included in the Live Activity display payload. You can control Live Activities in iOS Settings.
Optional iCloud sync
Optional iCloud sync is free and you choose to enable it in Settings. When enabled and available, completed non-sample walks, their photos and your dog profile synchronize through your private CloudKit database. Active walks and sample data are not uploaded. A stable device identifier and saved-walk usage counter synchronize separately to enforce the shared free allowance. Counters increase monotonically; deleting a walk does not reduce usage.
The free allowance is 3 saved walks. Without sync, the device's own count applies. With sync, devices on the same iCloud account share a cumulative allowance. Devices can continue using their known allowance offline, so concurrent offline use may temporarily exceed 3; counts reconcile after sync and then restrict additional free recording. The device identifier serves this function and is not used for advertising or cross-app tracking.
Recording remains available offline subject to the allowance currently known on your device or a Wuffu+ entitlement. Turning sync off stops new synchronization and does not delete existing iCloud records. Wuffu+ status does not restrict synchronization or existing local history and photos. If the iCloud account changes, synchronization stops and requires your confirmation before local records can be uploaded to the new account.
Deleting a synchronized walk while sync is enabled sends its deletion to your other synchronized devices when synchronization is available. You can manage iCloud storage through Apple's settings; removing Wuffu from a device alone does not delete existing cloud data.
If the iCloud journal is removed through system settings, Wuffu keeps local records and known usage counts and pauses journal uploads. Turn sync off and on only if you want to upload local records again.
Apple services and purchases
Apple Maps provides maps and map images, iCloud provides optional synchronization, and the App Store processes Wuffu+ purchases and restores. These services may communicate with Apple under Apple's privacy policy. Wuffu does not request your card details.
Wuffu uses verified App Store transactions and subscription status to determine access to Wuffu+. You can choose a monthly or annual auto-renewable subscription, or a one-time lifetime purchase. Apple processes payments, renewals and refunds. Wuffu does not operate a separate payment or receipt server. Restoring a purchase restores the entitlement; recovering journal records depends separately on previously enabled, available iCloud sync.
Files you export
When you export a walk as GPX or JSON, the file can contain route coordinates, walking times, events, notes and record metadata. The apps, people or storage locations you choose receive the file. Copies you share are controlled by their recipients and are not removed when you delete the original walk.
Retention and deletion
Local journal records remain until you remove them or iOS removes the app's storage. Removing a walk removes it from the app; it does not reset the number of free walks already used. A device-local usage count and stable device identifier are kept separately in iOS Keychain and may remain after the app is removed. These Keychain entries do not synchronize through iCloud Keychain and do not contain your routes or notes. If you enable Wuffu's optional sync, the identifier and usage counter synchronize separately through CloudKit as described above.
iOS backups and iCloud data depend on your device and account settings. Export records you want to keep before deleting the app or changing phones. We cannot recover local records that have been removed and were not available through prior sync or your own backups.
If you contact support
Our support mailbox uses Apple's iCloud Mail to receive, store and send support correspondence, under Apple's privacy policy.
If you choose to email us, we receive your email address, the sender display name included with your email, your message and any attachments you send. We use these to answer your request and resolve issues, and retain them only for as long as needed for that purpose and applicable obligations. Ask us at support@wuffu.app to delete support correspondence. Avoid sending private route files unless you choose to share them for a specific support issue.
In Settings → Feedback, Include logs is off by default. If you enable it, Wuffu prepares an optional diagnostic snapshot with app and iOS versions, permission states, recording and saving states and counts, free-walk usage, and broad age and accuracy categories for the last recorded point. The snapshot excludes coordinates, routes, record text, photos, account or device identifiers, and purchase information. You can use View logs to review it before sharing.
Feedback opens the system mail composer or sharing controls; Wuffu does not send the message or snapshot automatically. You choose whether to send and which destination receives it. The mail or sharing service you select handles those items; anything you send to our support address is covered by the support terms above. Your own message or files may contain information beyond the diagnostic snapshot, so review them before sending.
This website
This website is hosted and delivered by Cloudflare. Cloudflare processes requests and technical information such as IP addresses, browser information and request times to deliver and protect the website, under Cloudflare's privacy policy. Wuffu does not add analytics, advertising scripts, tracking cookies or external fonts to these pages. Cloudflare may run browser security checks and use security cookies such as cf_clearance to help protect the website from automated abuse. The website does not receive your walking journal or your iCloud records.
Changes
We will update this page when Wuffu's privacy practices change and show the revised effective date.
