Skip to content
Sniffari

Sniffari

Privacy Policy

Last updated 20 September 2026 · All legal & data pages

Draft — awaiting external legal review. This document reflects how Sniffari works today. Questions in the meantime: support@sniffari.app.

Sniffari is a community map of dog-friendly places. This policy explains what we collect, why, and the choices you have — in plain language, because you should not need a lawyer to walk your dog. It covers the Sniffari app and this website.

Who is responsible

The responsible party for your personal information is SNIFFARI (PTY) LTD (registration 2026/712502/07), 184 Upper Buitenkant Street, Oranjezicht, Cape Town, 8001, South Africa. Privacy and Information Officer enquiries can be sent to support@sniffari.app.

What we collect, and why

You can browse the map and read place pages without an account. Map, hosting and subscription services still receive the network requests and identifiers described below, including for guests. When you create an account or contribute, more information is linked to your account.

DataWhy we collect itLinked to you?Processed byRetention
Font-download request metadataLoading the Inter and Plus Jakarta Sans typefaces used by the app.NoGoogle FontsWhen a font is not already cached, the app downloads it from Google Fonts and stores the font file on your device. Google handles the resulting network request metadata under its provider terms.
Email addressCreating your account and signing you in (one-time code or Google sign-in).YesSupabase (authentication + database hosting); Resend (one-time-code email delivery); Google (only if you use Google sign-in)Erased from Sniffari when you delete your account. Supabase Pro authentication logs are retained for 7 days. Resend retains email content and delivery logs for 30 days on its Free plan, with backups persisting for 7 days.
Profile details and privacy settingYour display name, bio, profile photo and privacy choice control how the community sees your profile.YesSupabase (storage); the display name and bio you enter are checked against a keyword blocklist before saving (a name copied from Google sign-in at sign-up is cleared, not refused, if it matches) and go to OpenAI when AI-assisted text screening is enabled; a profile photo you upload goes to Microsoft Azure AI Content Safety in app versions that perform image screening, once it is enabled (a picture copied from Google sign-in at sign-up is a link to Google's copy and is not uploaded or screened)Erased when you delete your account.
Follows, follow requests, blocks and household relationshipsConnecting with people you know, controlling access and safety, and sharing dog profiles within a household.YesSupabase (database hosting)Kept until you unfollow or unblock, reject or cancel a request, leave or remove a household member, or delete the relevant account. Pending requests and invites currently have no automatic expiry.
Saved lists, favourites, list-sharing links and photo likesSaving places, sharing a list when you choose, and recording photos you like.YesSupabase (database hosting); list names are checked against a keyword blocklist before saving and go to OpenAI when AI-assisted text screening is enabledKept until you remove the item or like, delete the list, photo or account, or disable sharing. Public or link-shared lists remain available according to the visibility you choose. Photo-like records currently expose the photo and account identifiers publicly, even though the app interface shows only counts.
Badges, points, level and verification historyRecording contribution progress, awards and community reputation.YesSupabase (database hosting)Badge progress is kept while the account exists. Place-verification evidence may remain after account deletion with your account attribution removed so the place keeps its verified status.
Dog profiles (name, breed, age, photo, bio, memorial date)The heart of the product — your dogs, shared with your household if you form one.YesSupabase (storage); name, breed and bio are checked against a keyword blocklist before saving and go to OpenAI when AI-assisted text screening is enabled; the dog photo goes to Microsoft Azure AI Content Safety in app versions that perform image screening, once it is enabledErased when you delete your account; dogs co-owned by a household stay with the remaining household members.
Public contributions (reviews, check-ins, submitted places, Adventure Pins and your confirmations of others' pins, verifications)Building the community map everyone browses.YesSupabase (storage); the text of reviews, check-in notes, place submissions and Adventure Pin notes is checked against a keyword blocklist before saving and goes to OpenAI when AI-assisted text screening is enabled. Verifications and pin confirmations carry no free text and are not screenedOn account deletion: check-ins, your own Adventure Pins and your place submissions (whatever their status) are erased. Written reviews, places you added, and the verifications you gave places remain, but their account attribution is removed — reviews show "Deleted user", places and verifications show no author; the confirmations or contradictions you gave other members' Adventure Pins also remain with your account removed (they are never shown with an author, but the pin's confirmation and contradiction counts and its last-confirmed time still include them). Retained text may still identify people from what it says. Reviews and photos can also be deleted individually any time in the app.
Photos you uploadShowing places (and dogs) to the community.YesSupabase (storage); the caption is checked against a keyword blocklist before saving and goes to OpenAI when AI-assisted text screening is enabled; the photo — published or kept to yourself — goes to Microsoft Azure AI Content Safety before it is stored, in app versions that perform image screening, once it is enabledLocation metadata (EXIF/GPS) is stripped before upload. On account deletion your personal photos (avatars, dog photos, pending uploads) are removed from storage. Photos already published on place pages remain with your account attribution removed and the author shown as "Deleted user"; their visible contents may still identify people or pets. Delete any photo individually in the app first if you want it gone entirely.
Device and photo locationShowing the map around you; finding nearby places; confirming you are at a place; and, only when you choose location sharing, publishing a photo or Adventure Pin on the public map.YesSupabase (queries and storage); device location and photo-metadata servicesThe live location dot stays on your device. Nearby and on-site checks use coordinates transiently. After you choose location sharing, a gallery or shared photo uses its embedded capture location and a new camera photo uses a current device fix; the resulting exact point is stored and published. Adventure Pins also publish an exact point. Deleting a photo removes its point; account deletion removes every photo-map point you published (the retained place photos keep none) and your Adventure Pins. Offline street-map regions and their place snapshots stay on your device until you delete them or clear app data.
Reports you file (and reports about your content)Trust and safety — reviewing objectionable content within 24 hours.YesSupabase (storage)Reports you filed are erased with your account; reports other members filed (moderation records) may be retained for abuse prevention and legal compliance.
Subscription identifiers, purchase history and statusLoading Premium offers, processing a purchase or restore, and knowing whether your account has Premium.YesApple App Store / Google Play (billing); RevenueCat (subscription management)Sniffari stores entitlement status, not card details. When you delete your Sniffari account, your request also covers deletion of the matching RevenueCat customer record. We process that request separately, retry unsuccessful requests and review unresolved failures. Store transaction records remain subject to the store's and RevenueCat's terms and legal obligations.
App or installation identifier and approximate countryStarting and securing subscription management before you sign in.YesRevenueCatRevenueCat creates an anonymous app user identifier and derives a country from the request IP. RevenueCat says it does not retain the raw IP after deriving the country. When you delete your Sniffari account, your request also covers deletion of the matching RevenueCat customer record. Provider and store records remain subject to their terms and legal obligations.
Server request logs (IP address, timestamps)Operating and securing the service — standard infrastructure logs.YesSupabase and Cloudflare, as part of hosting and map deliveryAuthenticated Supabase requests can be associated with your account; guest map and website requests are not intentionally associated with one. Supabase Pro API and authentication logs are retained for 7 days. Cloudflare retention depends on the service and account configuration; we do not use these logs for advertising profiles.
Product analytics eventsUnderstanding which features get used, to improve the app.NoNone today — analytics collection is switched off in the current appNot collected by Sniffari’s own product-analytics sink today. RevenueCat still processes subscription identifiers, country and purchase activity as described in the separate rows above.
Push-notification device tokenDelivering push notifications when that service is enabled.YesNone today — the current app has no service that obtains or registers a device tokenNot collected today. If push delivery is enabled, this table will be updated with the active provider and deletion period first.

The lawful basis we rely on

  • Performing our contract with you — your account, profile, dogs, and contributions exist because you asked us to provide the service.
  • Consent — device location is only used when you grant the permission, and only as described above; you can withdraw it in your device settings at any time.
  • Legitimate interest — keeping the community safe: content screening, report handling, and abuse prevention.

Where your data lives

Sniffari's backend is hosted by Supabase, transactional sign-in email is delivered by Resend, our website and standard map tiles are served by Cloudflare, and AI-assisted content-safety screening of text and photos is performed by OpenAI and Microsoft when those services are enabled. Every provider listed below today stores or processes data on infrastructure outside South Africa — Supabase, Resend (which stores email content and delivery logs in the United States), Cloudflare, Esri, Google and RevenueCat, Apple once Sniffari Premium is on the App Store, and the two screening providers once they are enabled (Microsoft's region is added to this paragraph once its resource exists) — and this sentence is updated whenever the list changes. Microsoft's processing region for the image content-harms analysis Sniffari uses is fixed when the Azure AI Content Safety resource is provisioned (Content Safety features that route globally are not used) and is added to this page before the app's image screening is switched on; OpenAI processes through its global API, and the locations it uses are governed by its terms. POPIA (section 72) allows a transfer where the recipient is bound by protections substantially similar to POPIA — each processor's standard data-processing terms apply, and we do not enable a screening processor until those terms are in place for it.

Who processes data for us

  • Supabase — database, authentication, and file storage for the app, and the server function that runs the keyword blocklist and calls the two AI screening providers below when they are enabled. The database itself checks the text fields listed under OpenAI against a keyword blocklist of its own — a fixed subset of the server function's list — before they are saved, whatever else is enabled.
  • Cloudflare — serves this website, map styles, assets and standard map tiles.
  • Resend — delivers one-time-code sign-in email from hello@send.sniffari.app.
  • Esri — delivers the satellite basemap tiles the app displays; tile requests go to Esri's servers but carry no Sniffari account information.
  • Google — Google Workspace handles support email; Google also processes Google sign-in when chosen, Google Play billing, and runtime font-file requests from the app. If you signed up with Google and never picked a profile photo, the picture shown for you is Google's copy, served from Google's servers to anyone who views your profile.
  • Apple — App Store billing, when Sniffari Premium launches there.
  • RevenueCat — subscription and entitlement management. Its SDK starts in the current Android app even for a guest; store products may not yet be available to buy.
  • OpenAI — AI-assisted content-safety screening of text. The free-text fields you save, published or kept to yourself (a private list's name, the caption on a photo only you can see) — reviews, photo captions, check-in and Adventure Pin notes, place submissions (name, description, dog policy and location note), list names, your display name and bio, and your dogs' names, breeds and bios — are checked against a keyword blocklist before they are saved; when AI-assisted screening is enabled, that text is also sent to OpenAI solely to obtain a moderation decision — text the keyword blocklist refuses is not sent on to OpenAI; text that passes it is sent before the save, so a save that then fails has still been screened there (an outage at the provider does not block your contribution). Under OpenAI's API data-usage terms, content sent through the API is not used to train its models.
  • Microsoft — content-safety screening of images through Azure AI Content Safety. In app versions that perform image screening, once it is enabled, photos you choose (place photos, photos on reviews, your profile photo, your dogs' photos and personal place-less photos — whether or not they are published, and including a photo the check refuses or that you then decide not to save) are sent to Microsoft solely to obtain a moderation decision, before they are stored.

Both screening providers act as our processors and receive only the content being screened — never your email address (your display name and bio are themselves screened content); the cross-border transfer rests on the POPIA section 72 basis described above.

We never sell your personal information, and we run no advertising trackers.

What's public

Sniffari is a community map: reviews, photos and check-ins are published to the community under your display name (or your dog's); a place you submit is announced in the Community feed under your display name, following your profile's visibility — public, or accepted followers when private (the place page itself says "Added by the community"); a verification you give shows no name in the app, though its record carries your account identifier and is readable by clients unless your profile is private; Adventure Pins are published without a name — but blocking a pin's contributor lists them under Blocked Users by display name and photo, so a member who blocks you from a pin learns who placed it. Your profile can be set private in the app — your name, avatar, bio and your dogs' profiles stay visible to everyone, and going private hides your place-submission feed activity, check-ins, badges, personal (place-less) photos, follower lists and household from anyone you haven't accepted as a follower. Reviews and the photos you post on a place stay public on that place's page. Photo-like records currently expose the photo and account identifiers publicly, although the app interface shows only like counts. If you separately choose to place a photo on the photo map or add an Adventure Pin, its exact map point is public. Changing the photo-map account preference affects future photos; delete an existing photo to remove its point.

Deleting your data

You can delete individual contributions in the app, or delete your whole account — see the dedicated account & data deletion page for exactly what is erased, what remains, and where account attribution is removed. Content sent to OpenAI or Microsoft for screening is used only to reach a moderation decision and we do not store it with those providers; under their published terms, OpenAI does not retain moderation-endpoint content for abuse monitoring and Microsoft does not store content submitted to Azure AI Content Safety.

Your rights

Under POPIA you may ask us to confirm what personal information we hold about you, to access it, to correct it, or to delete it; you may also object to processing. Email support@sniffari.app from your account email and we will respond within two business days. If you are not satisfied with our answer you may complain to the Information Regulator (South Africa) — inforegulator.org.za.

Children

Sniffari is not directed at children. You must be old enough to hold the account under the law that applies to you (18 in South Africa, or the digital-consent age where you live).

Security

All traffic is encrypted in transit. Server-side access rules protect private and account data and gate writes; approved community photos and other content described above are intentionally public. The app itself holds no privileged keys, and photo uploads have location metadata stripped on-device before they leave your phone.

This website

This site sets no cookies and stores nothing in your browser. /signup does not create an account — it explains how to ask for a place in the beta by email. When you write to support@sniffari.app that message reaches our Google Workspace inbox, and we record what you send — your name, your email address and which phone you use — in a private tester roster, so we can send you builds. If we enable privacy-preserving, cookieless page analytics (Cloudflare Web Analytics), it measures pages, not people, and we will note it here.

Changes

We will update this policy as Sniffari grows (for example, when Premium or analytics go live) and change the date at the top. Material changes will be announced in the app.

Contact

support@sniffari.app — data requests, questions, or concerns. We reply within two business days.