Legal
Privacy policy
App summary: Dog-organizer data stays on your device by default and is not uploaded automatically. A Community member may separately choose to publish an editable achievement summary of a completed walk containing its distance and, when available, an on-device calculation of newly explored area. If you deliberately enable dog sharing for one dog, the profile and selected records described in section 3a are stored by Ruffolio so up to five trusted members can keep them in sync. After a walk, the recording person may additionally share a private family view containing a deliberately selected summary, review or map; the map is off by default, can hide its start and finish, and never includes private notes. The separately disabled shared Explore map starts only after all current members of that dog consent and synchronises solely derived explored 25-metre map cells. Those cells are nevertheless sensitive location history. “Pack Scouts” adds a second unanimous opt-in and shows every member person-level weekly and all-time counts. Its optional two-tone map does not show geometry credited to individual people; it contrasts cells explored locally on this iPhone with additional cells in the shared union. With exactly two members using separate devices, that difference can nevertheless make the other person's cumulative areas recognisable. Optional Community features, including the dog-walk barometer, and shared danger reports process only the data described below. Ruffolio does not use this data for advertising or behavioural tracking.
1. Controller
Dr. Philipp Münch – AI Software & SaaS
Owner: Dr. Philipp Münch
c/o COCENTER
Koppoldstr. 1
86551 Aichach, Germany
Email: mail@pmuench.com
2. Data processed by the app — and where
Your dog-organizer content is stored locally on your device by default. This includes:
- Dog profiles such as name, breed, date of birth, microchip number, photo and notes
- Veterinary visits, appointments, documents, scans and attachments
- Expenses and recurring costs
- Health and care entries such as vaccinations, treatments, everyday care, manually entered temperature readings, weight and heat cycles, plus owner-recorded observations with optional body markers and follow-up history
- Recorded walks, including GPS routes and marked places
- Private dog encounters with a name, manually entered breed and note, an optional coarse place label, cropped photos, and numerical recognition features generated on the device. No precise coordinate is linked; when Ruffolio cannot crop a dog reliably, it stores neither the full-frame image nor a recognition feature.
This data does not leave your device unless you actively export or share it yourself, deliberately enable dog sharing as described in section 3a, additionally consent as a member to the shared Explore map described there, choose the limited Community profile information, optional approximate post location, optional dog-walk barometer or invited route-creator submission described in section 3, or use the shared danger reports described in section 7. Nothing from the dog organizer is added to Community or dog sharing automatically. In particular, a completed walk is shared with Community only when a member reviews and confirms an editable achievement post containing its distance and, when available, an on-device calculation of newly explored area. A route is submitted only through the separate Creator Beta flow and only after the invited creator reviews and explicitly approves the exact publication line, markers and every optional route photo selected for submission.
3. Optional Community
Community is off until you choose to join. It is separate from the private dog organizer and requires Sign in with Apple plus a nickname you choose. Ruffolio does not request your Apple name or email address. To create and secure the account, the service processes Apple's app-specific account identifier, a Ruffolio account identifier, the accepted guidelines version and time, hashed session tokens, account status and technical security records. Apple processes the sign-in under Apple's privacy policy.
When you use Community, Ruffolio stores your nickname, posts and short, one-level replies. Replies are public Community content rather than private messages. You may also choose individual dogs whose name, breed and, if you write one, optional public tagline should appear on your Community profile, and add an optional Community profile photo. The app may preselect up to eight local dogs for your review, but nothing becomes public until you confirm; every dog can be deselected or removed again. Each confirmed dog receives a separate, server-issued Community dog identifier so its public profile remains stable when its name, breed or tagline changes. Ruffolio never receives the dog's private local identifier. A dog profile starts with only the name and breed you confirmed and, if deliberately entered, a public tagline of up to 80 characters. Its chronological Moments feed contains only Community posts you deliberately attributed to that dog and, when selected for such a post, its optional post photo. Posts published as your whole pack never appear in an individual dog's feed. Ruffolio does not pull the dog's organizer photo, exact birth date, notes, microchip number, health records, walks, locations or other private organizer records into the profile or feed automatically. You can discover public dogs and follow individual dogs. Ruffolio privately stores which Community dogs you follow solely to provide your Following feed; other members cannot see your follow choices and Ruffolio does not publish follower totals. You may also create a seven-day, one-time friend invitation. Its link contains only a random opaque token; Ruffolio stores only a domain-separated cryptographic token value plus creation, expiry, acceptance and rate-limit metadata. After the recipient has joined Community and expressly accepts, Ruffolio stores the private friendship and the direction from inviter to invited member. Each friend can then see the other member's current Community nickname, optional Community profile photo and deliberately public dogs in the Friends area. The friendship also lets each member discover shared walks whose audience is limited to friends; a private meeting instruction remains available only after that member's attendance is approved, as described below. Later changes to those public dogs are reflected from the Community profile; the friendship never grants access to private organizer records or to the separate dog-sharing service. Either member can remove the friendship, while reporting or blocking also separates it. Unaccepted expired or revoked invitations are deleted within a further seven days. After acceptance, the non-public inviter-to-recipient attribution remains even if the friendship is later removed, and is erased when either associated account is deleted. Other signed-in Community members can see your nickname, posts, replies, selected dog names, breeds and optional taglines, profile photo, and which public dog you chose to attribute a post to. The dog profile and its Moments feed remain available only to signed-in Community members, and the report, block, deletion and photo-retention rules below apply to the same posts and photos wherever they are shown.
You may deliberately share a stable link to a public Community dog profile. The URL contains only that dog's server-issued Community identifier; its web fallback reveals no dog or member details. The app stores a received identifier on that device only while needed to resume the destination after installation, sign-in or Community setup. Profile details remain available only after Community sign-in, and opening a link never follows a dog automatically.
You may attach one optional photo to a Community post. Ruffolio corrects its orientation, resizes and re-encodes it as a metadata-stripped JPEG, and stores only the normalized image. The current photo is available only to signed-in Community members who are allowed to view that post. You can replace or remove it separately; deleting or hiding the post, deleting the account, or moderation removes the public copy. If a member reports the post while a photo is attached, Ruffolio copies that normalized photo into the report as moderation evidence; this separate copy follows the retention period below even if the public photo is later replaced or removed.
A post author may edit only the post text during the first 15 minutes after publication. Other signed-in Community members receive the current text, publication time and, after a change, the latest edit time; no public edit history is shown. You may mark another member's post as Helpful. Ruffolio privately stores the link between your account and that post to prevent duplicate reactions and show your own selection. Other members can see only an aggregate Helpful count, never who reacted, and Helpful is not used to rank feeds.
If you separately enable notifications for your current Community account in the Activity screen and iOS permits them, Ruffolio can use the Apple Push Notification service (APNs) to send a short notice when someone replies to your moment, marks your moment Helpful, or accepts a friend invitation you created. The notice contains no name, post or reply text, dog details, place or location data; it carries only a generic message and opaque event or post identifiers needed to open the destination safely in the app. For registration and delivery, Ruffolio stores an account-linked random app-specific registration identifier, the APNs environment, the encrypted APNs device token and its cryptographic digest, the current Community-session binding, timestamps, and short-lived delivery state. A token-free ordering record is additionally retained for no more than 91 days with the random registration identifier, the state “registered” or “unregistered”, session ordering, timestamps, and the account link until account deletion. It contains neither the APNs device token nor notification content and prevents a delayed request from an older session from overriding a newer state. Apple receives the device and app identifiers needed for delivery together with the generic notice content and processes them under its privacy policy. On opt-out the encrypted APNs device token is deleted immediately; delivery also stops after an invalid device token, account deletion, or expiry or revocation of the bound session. A registration that is no longer renewed is deleted no later than 35 days after its last confirmation; completed, discarded, or expired delivery state is removed within a further seven days. Processing is necessary to provide the feature you enabled under Art. 6(1)(b) GDPR; delivery security and abuse prevention are additionally based on Art. 6(1)(f) GDPR.
Community also includes a small number of official Community guides. Guides are artificially designed, editorial personas of the Ruffolio team, not real members; no private user account stands behind a guide, and a guide account can never sign in. Guides are permanently labelled “Community guide” or “Official” in the app, and their profile carries a mandatory transparency disclosure that they are an artificially designed persona of the Ruffolio team, together with a short description and topics. A guide's posts and replies are editorial content provided by Ruffolio. Guide portraits are curated images created by or rights-cleared for Ruffolio and do not depict real private individuals. No personal data of real users is processed through the guides themselves; your interactions with guide content, such as replies or Helpful marks, are processed like interactions with any other Community content.
In addition to public Community content, Ruffolio provides signed-in members with a private team chat (support chat). It is exclusively a one-to-one channel between you and the Ruffolio team; there is still no private messaging between members. For it, Ruffolio stores at most one conversation per account containing your messages (up to 2,000 characters), the team's replies, the sender role (member or team), timestamps and read status, plus short-lived rate-limit records. Team replies are shown to you generically as the Ruffolio team and never under a guide's name; internally, Ruffolio non-publicly records which authorised team or admin identity replied, to keep replies attributable and investigate abuse. Team-chat messages never appear in any feed and are not visible to other members. Please share only the details needed for your request and no health data, payment data or third-party data in the team chat. This processing is necessary to provide the support feature you use (Art. 6(1)(b) GDPR); rate limiting, moderation and abuse prevention are additionally based on Art. 6(1)(f) GDPR. The team chat is not an emergency channel and provides no veterinary advice. Deleting your Community account deletes the conversation and its messages; moderation evidence from reported content follows the retention period stated below.
Ruffolio shows only curated external podcasts in Community whose responsible publisher or authorised rights holder has expressly approved inclusion. A publicly accessible RSS feed alone does not count as approval. For the catalogue, Ruffolio imports and stores from the approved feed in particular podcast and episode titles, a technical episode identifier, publication date, duration, original source, audio URL and audio format, plus feed indicators for explicit content and permitted discussion; an internal revision identifier prevents an episode changed in the meantime from being published without renewed review. RSS descriptions, show notes, transcripts and artwork are not imported; any displayed editorial summary is written separately by Ruffolio. The source and external provider are clearly labelled in the app.
An audio file is requested only after you tap play on an episode. Your device then loads it directly from the original host specified in the feed. That external provider receives the connection data technically necessary for the request, particularly your IP address, the time, and device and request information; requested byte ranges may also reveal which parts of the episode were retrieved. The relevant provider's own privacy notice also applies to this processing. Ruffolio stores no separate permanent copy of the audio, does not mirror or transcode it, and offers no offline download. The iOS system player may technically buffer audio temporarily for playback.
Ruffolio keeps no server-side listening history. Listen Later and your playback progress remain solely on your device and are not sent to Ruffolio. If you mark a podcast episode as Helpful or comment on it, Ruffolio instead stores the link between your Community account and the episode, the comment, and the time and status details needed for display, abuse prevention and moderation as Community data. Comments are visible to other eligible Community members; for Helpful, they see only the aggregate count. These contributions follow the same reporting, blocking, deletion and moderation-retention rules as other Community content. Podcast episodes and discussions are not veterinary diagnoses or advice.
To manage rights and withdrawals, Ruffolio privately stores the responsible publisher's or rights holder's name and contact details together with the approval reference and timestamp. These details are used only to document and manage the integration, handle withdrawal or removal requests, and establish or defend legal claims. Where these details are personal data, processing is based, depending on the relationship, on Art. 6(1)(b) GDPR to take steps toward or perform the agreed integration, or on Art. 6(1)(f) GDPR for rights management and legal protection. After withdrawal, personal contact details are deleted or permanently redacted from the continuing evidence record when the defined retention period has expired, they are no longer needed for those purposes, and no statutory retention duty or potential legal claim requires otherwise. Publishers or authorised rights holders may withdraw their approval or request review and removal at mail@pmuench.com.
For a personal podcast invitation, Ruffolio processes the business email address, optional salutation, podcast and publisher details, the documented prior permission for that email contact, the invitation message, a hashed-only access token, and delivery, expiry and decision status. Ruffolio records neither message opens nor link clicks. For delivery, Plus Five Five, Inc. (Resend), USA, receives the recipient, sender and message content as Ruffolio's email processor; before activation, Ruffolio reviews the data-processing agreement and international transfer and disables open and click tracking for the sending domain. More information is available in Resend's privacy policy and data-processing addendum. For failed, declined, expired or administratively cancelled invitations, personal contact, message and access data is deleted or permanently redacted within 180 days; a non-personal status record may remain. Accepted or withdrawn invitation and approval evidence follows the rights-retention period described above. After acceptance, the personal link remains usable only for status and immediate withdrawal. A published email address or public feed alone does not authorise Ruffolio to send an invitation.
If you choose to share a recorded walk as an achievement, the app creates an editable Community post containing the formatted distance and, when available, the newly explored area calculated on-device when recording ends. Only the post text you review and confirm and, if selected, the public Community dog are sent. This sharing flow includes no approximate post location. The GPS route, map, coordinates, walk time, exact start and end times, private dog names, notes, tags and all other private walk data remain on your device and are never uploaded automatically.
Selected walk routes are a separate, publicly readable catalogue. Viewing it does not require a Community account. Suggesting a route is limited to active Community members whom Ruffolio has separately invited to the Creator Beta. Endpoint protection in the local route workshop is optional and may be deliberately switched off. Regardless of that local choice, before every submission the app displays the complete exact line, its sections, markers and selected photos that could become public and requires separate confirmation of the visible endpoints, publication geometry and publication of exact location data. Ruffolio stores the submitted title, short summary, description, area, tags, route type and section descriptions, simplified multi-segment publication line, derived route length, optional aggregate duration and elevation gain, selected route observations about dog suitability and, under “Along the way & arrival,” about places to stop for food or refreshments, parking, public transport, toilets, a mountain lift/gondola and personally observed dog-friendliness, review and publication status and times, and the internal identifiers needed to link the submission to its creator and reviewer. For a mountain lift or gondola, observed muzzle or leash rules and optional approximate price examples for a person or dog may additionally be stored and published with the currency, ticket type and observation month only; exact visit or route-point timestamps are not included. When the creator selects route photos for submission, only newly encoded JPEG copies without EXIF, GPS or other source metadata are uploaded directly to the separate public route-media store. Ruffolio stores the caption, confirmed position or section on the public line, order, cover choice, file type, size, dimensions and cryptographic checksum. The Creator Beta flow does not upload the raw GPX file, removed or hidden route sections, individual point timestamps or elevations, local dog identifiers or personal dog-fit ratings. Before editorial review, Creator photos are not listed in the route catalogue or returned by the route API. Because they are transferred directly into a technically public media store, anyone who knows the unguessable direct storage URL can nevertheless retrieve the file; upload only rights-cleared images already suitable for public publication. Ruffolio may approve or reject them and may add its own or otherwise rights-cleared curated images and videos. Submitted routes remain hidden from the catalogue until Ruffolio reviews and publishes them; creators cannot publish their own submissions. Once published, the exact approved line, markers, route details and approved media are available to anyone through the catalogue. This information consists of Community or Creator Beta observations. Price examples are not live prices or offers. Fares, operating hours, conditions of carriage and rules can change and must be checked with the operator; a dog price of 0 only means that free dog travel was observed and is not a guarantee. Dog access, opening hours, timetables, parking rules and availability can change and must be checked locally; route observations are not a safety guarantee. Deleting the Community account removes that account's route submissions and published routes from the catalogue and API immediately. Account deletion, rejection or archival queues the associated public media paths for physical deletion; scheduled cleanup runs every 15 minutes and retries failed deletions. A previously cached direct copy may remain retrievable for about five minutes after storage deletion. Ruffolio may also reject, archive or remove a route or medium for privacy, safety, quality or legal reasons.
For each post, you may separately choose to add an approximate location. Before transmission, the app rounds the current latitude and longitude to one decimal place (about 0.1 degrees, a broad regional cell rather than a precise point). Ruffolio uses that coarse point with the post and your Community account for no more than 24 hours; it then stops being returned or used for discovery and is cleared during routine cleanup, while the post text remains. The point itself is never returned to another member. When a signed-in member explicitly selects Nearby, their current point is rounded in the same way and sent to Ruffolio; the server returns only unexpired location-tagged posts within 25 kilometres and places their distance into a broad 5-, 15- or 25-kilometre band. Repeated Nearby lookups are rate-limited to reduce location probing. Other feeds reveal only that a still-active approximate location was attached. Exact coordinates, live movement and walk routes are not sent through this feature, and location sharing is off for every new post until you choose it.
The Community dog-walk barometer has two separate choices and is off until you enable the relevant choice in Explore. Viewing the barometer does not require an account. For a view, the official app rounds the visible map centre to two decimal places before sending the point; Ruffolio derives a fixed, approximately 1.5-kilometre map cell in memory and never stores the received point. The public response contains only insufficient, some, busy or many, plus the evaluated time window—never a cell, route, exact count, dog, account or profile. Sharing activity is a separate opt-in and requires an active Community account. Only during an actively recorded walk with at least one dog, the official app sends at most once every 15 minutes the current point rounded to two decimal places and the dog count capped at eight; dog names, dog profiles, direction and route are not included. Ruffolio stores at most one pseudonymous, non-public activity signal per account and server-side 15-minute bucket: the derived cell, bucket, capped dog count and internal account identifier. A band is released only from at least five distinct active members, uses a 90-minute window delayed by one complete bucket, and counts only each member's latest cell. Activity-signal rows expire no later than two hours after their bucket and are then deleted; turning sharing off stops new signals, and account deletion removes linked signals immediately. Durable public and authenticated rate limits restrict repeated cell probing and updates.
If you publish a shared-walk invitation, Ruffolio stores the public dog you select, title, note, public area, date and time, duration, capacity, chosen audience and approval setting. A private meeting instruction is returned only to you and members whose attendance is approved. For a Nearby invitation, its coordinate and a member's coordinate used to discover or request it are each rounded to two decimal places (about 0.01 degrees or roughly 1 kilometre) before transmission. The stored point is never returned; eligible members may receive only a whole-kilometre distance. Invitations limited to dogs you follow are authorised from private dog-follow relationships; invitations limited to friends use the separate private Community friendship described above. Ruffolio publishes neither relationship nor follower totals. Ruffolio also stores join requests, the selected attendee dog, approval state and decision so the host can manage the group. Cancelling clears the private meeting instruction and stored coordinates immediately. Walk and RSVP records are removed no later than 30 days after the scheduled start, and account deletion removes the account's invitations and requests immediately.
Reports, blocks, moderation decisions and limited abuse-prevention records are also processed to keep the service safe. Reporting a post removes your own replies on that post; reporting a profile removes your replies on that member's posts and ends any Community friendship between you. Blocking ends the friendship and removes replies either of you left on the other's posts, even if you later unblock. Only share a profile photo you have the right to use. Profile photos must not show people or children, contact details, addresses, documents, QR codes, live locations, sexual or violent material, animal cruelty or other unsafe content. Do not post dog health records, live locations, contact details or other sensitive personal data. Community use is governed by the Community guidelines.
This processing is necessary to provide the optional Community you request (Art. 6(1)(b) GDPR). Filtering, rate limiting, reporting, blocking, photo and content moderation and service-security measures are additionally based on the legitimate interest in preventing abuse and operating a safe service (Art. 6(1)(f) GDPR). Community data is not used for advertising or tracking.
An active Community membership is also required to publish a shared walk or shared danger. Merely viewing danger reports on the map does not require Community membership. Section 7 explains the danger-report location details transmitted and who can see them.
You can remove public dogs, your profile photo and post photos, remove Helpful marks, unfollow dogs, remove Community friends, cancel walk invitations or requests, delete your own posts and replies, and delete your Community account in the app. Account deletion immediately removes the profile and content visible to signed-in Community members, including public dog profiles, profile photo, post photos, posts, replies and shared walks, as well as friend invitations and friendships, Helpful, RSVP, follow and block relationships, Ruffolio sessions and the link to the Apple account identifier; the private team-chat conversation and its messages are deleted as well. It also starts revocation of Ruffolio's Apple authorisation. If Apple is temporarily unavailable, the encrypted refresh credential remains only in a restricted retry queue until revocation succeeds and is then removed.
Open reports and their limited snapshots of the reported content, limited surrounding context, relevant names and, when present at reporting time, the normalized post photo are retained until review. For a reported reply, that context includes the parent post; it follows the same moderation retention as the reply snapshot. A profile-photo snapshot is retained only when needed as evidence for a report. Once a case is dismissed or actioned, this moderation evidence is deleted after no more than 180 days. Apple notification audit entries are deleted after no more than 30 days. A Community session is valid for no more than 30 days; its expired or revoked server record is deleted within a further 7 days. Rate-limit and posting-attempt records are deleted after no more than 7 days. A non-public deletion record without the Apple identifier or public name may remain only while retained evidence or a separately provided marketplace or legally required record technically refers to it; a Community-only deletion record is then removed automatically. These records are used solely to investigate abuse, secure the service, meet legal duties, or establish or defend legal claims; they are not used to recognise a new Apple sign-in, advertise, or track, and are deleted or de-identified when their stated purpose ends.
Ruffolio may also send you an optional, time-limited dog welcome link. The private draft created by an administrator contains a suggested dog name and breed, an optional short description, a metadata-free JPEG dog icon supplied by Ruffolio, a coarse campaign channel, creation and expiry data, and the internal administrator identifier. Ruffolio does not store the invited person's social-media handle or other external account identifier. The secret code remains in the link fragment and only a domain-separated cryptographic value is stored on the server. Anyone holding the code can retrieve the draft until it expires or is revoked; previews are rate-limited and are not cached.
Opening or adopting the welcome draft creates neither a Community account nor a public dog profile and stores no acceptance or recipient identity on Ruffolio's server. The suggested details are imported locally on the device and can be changed before saving. Expired or revoked drafts are deleted within a further seven days. This processing serves Ruffolio's legitimate interest in providing a secure, optional invitation path and preventing abuse (Art. 6(1)(f) GDPR).
3a. Optional dog sharing
Dog sharing is off by default and must be enabled separately for each dog. It uses Sign in with Apple but does not require a public Community profile. Every current member can create a random, single-use invite that expires after 24 hours; Ruffolio stores only cryptographic hashes of the invite codes, and a newly created invite revokes only the previous unused invite created by the same member. Current members can see who created each still-active invite and when it expires, but never its plaintext code. A member may revoke their own active invite, while the access-managing member may revoke any active invite. Remaining unused invites are revoked when the group becomes full. A shared dog has no more than five members and exactly one access-managing member while it has members. Each member supplies a private sharing name or initials and can change it later. Ruffolio stores this name with the internal account identifier, role, join time and current consents for the shared Explore map and Pack Scouts. This private roster is visible only to that dog's members. Only the access-managing member can remove members. If that member leaves while other members remain, the longest-standing remaining member automatically takes over access management. Shared records are visible and editable only to current members and are not public.
For the dog you explicitly share, Ruffolio stores the profile (including name, breed, sex, date of birth, microchip number, neutering status, notes, quick-log configuration and a compressed profile photo) plus veterinary-visit metadata without attachments, heat cycles, treatments, everyday care, manually entered temperature readings and care reminders, weights including optional body-condition observations and user-entered ranges from veterinary notes, expenses and recurring expenses, appointments, and weekly check-ins. Every member can change these records, and the latest server-accepted edit is synchronised to all members' devices.
Completed walks remain exclusively on the recording iPhone even for a shared dog until the recording person confirms a separate private family view after the final walk debrief, or has turned on the optional per-dog automatic sharing described below. For each affected shared dog, that person separately chooses whether to send duration and distance, the rating and activity tags recorded only for that dog, and/or a map line to the dog's private group. The recording person may alternatively enable an optional per-dog, per-device automatic mode; while it is on, saving the walk debrief creates the family view immediately with duration and distance, the rating and activity tags, and a start/end-protected map line when one can be derived. The automatic mode is off by default, is announced on the debrief screen before saving, can be turned off at any time in the dog's family settings, and each automatically created view can be edited or withdrawn afterwards exactly like a manually shared one. Every current member can receive a live family view, and a person who joins that private dog group later can also receive family views that have not been withdrawn. The map is off by default. When enabled, the app hides every point within 500 metres of the start and finish by default, also removes later re-entry into those areas, bounds and simplifies the remaining line, and sends no per-point time or elevation data. The person may deliberately turn this start/end protection off for that one share. Private walk notes, marked places, attachments and unselected details are never part of the family view.
A received family view is read-only for other members and cannot be edited, exported as GPX or republished to Community by them. Only the account that first shared it may update or withdraw it. Withdrawal marks the server record as deleted and removes the recipient copies without deleting the complete local walk on the recording iPhone. Family views continue to be delivered through the regular save, foreground and five-minute foreground synchronisation triggers.
Private family notifications start off for every shared dog. Each member may separately choose Off, Right away or Daily summary for newly shared walks and may independently enable a quiet weekly recap. Ruffolio stores the member's choice, the IANA time zone reported by the device and the update time. A daily summary is formed no earlier than 19:00 local time and a weekly recap no earlier than Sunday at 19:00 local time; nothing is sent when there is no eligible walk. A sender receives no notification for their own walk. Summaries combine several walks, and the same source walk produces at most one right-away-or-daily notice for one recipient account even when it was shared into several dog groups they have in common. The separately enabled weekly recap may count those walks again in its weekly total. Pack Scouts, rankings and overtaking never generate notifications.
A family push notification is deliberately generic. It contains only a fixed private-activity category, the kind “walk”, “daily summary” or “weekly recap”, a non-descriptive delivery-event identifier and, for a summary, a count. In particular, it contains no person or dog name, walk or dog identifier, duration, review, route, map-sharing flag, position or ranking detail. Only after opening does the app authenticate with Ruffolio, confirm current membership and synchronise the private details the account is still allowed to receive; only then may a name, duration and an explicitly shared map appear. For registration and delivery Ruffolio stores, per account, the same random app-specific installation identifier, APNs environment, encrypted APNs device token, its cryptographic checksum, session ordering and timestamps described for optional Community notifications; no Community profile is required. Apple receives the device and app identifiers needed for delivery and the generic notification content. When the last push feature is disabled, the encrypted device token is removed; registrations that are no longer confirmed are deleted after no more than 35 days.
Joining and leaving appear without a push in the shared dog's private activity list. Ruffolio stores the event kind, internal dog and where applicable internal member, private sharing name, event time and a seen time for each reading account. These details can be retrieved only by current members of that dog, are deleted with the related dog or account where applicable, and are otherwise removed after no more than 365 days.
The shared Explore map is separately off by default within dog sharing. It becomes available for a dog only after all current members of that dog consent separately. Each iPhone then derives an unordered set of explored map cells of approximately 25 × 25 metres from its local walks. Ruffolio stores each member's contribution and returns only the combined set (the “tile union”) privately to all current members; individual cells are not attributed to a contributor in that combined map.
The map cells contain no walk record, GPS route, individual GPS point or point order, start or end marker, walk time, note or tag. Even without a route line, however, the accumulated cells form sensitive location history from which homes, routines or frequently visited places may be recognisable.
Any member can turn off their consent to the shared Explore map for that dog. Ruffolio then immediately deletes every server map-cell row for which that member is recorded as either the credited contributor or the uploader, deletes that member's weekly marks, and resets that member's separate Pack Scouts consent. This also removes copies credited to other selected walkers for a walk uploaded by that member. The shared map and Pack Scouts pause. If the member later enables the shared map again, Pack Scouts must be enabled again explicitly and does not reactivate automatically. Server contributions belonging solely to other members and their local walk records are not deleted by this action.
Pack Scouts is a second, separately disabled and unanimous opt-in above the shared Explore map. It becomes available only when at least two current members have enabled both the shared map and Pack Scouts. At the start or end of a walk, the device can record which current members held the lead. The same derived cell may be fully credited to several selected members for a walk taken together. Ruffolio therefore stores, with the derived cells, the internal identifier of the credited member and separately the internal identifier of the uploading account; it does not add point order or a timestamp per cell.
The Pack Scouts board returns to every current member of that dog only derived map-cell counts per member for the current ISO week starting Monday (UTC) and all time. It also returns aggregate counts for cells explored by the pack overall and together. Ruffolio stores a per-member weekly mark containing the total at the beginning of the week for this purpose. The board endpoint returns no individual-member geometry, route, GPS points, times, order, start or end points, notes or tags. Nevertheless, these person-level counts are account-linked usage data derived from sensitive location cells and are visible to every member of that shared dog.
The optional two-tone display is derived on the iPhone from cells explored locally on that device and the already available shared union. It contrasts “on this iPhone” with additional cells in the shared union, without times or order. It does not use server geometry credited to an individual; the board endpoint never returns such person-level geometry. With exactly two members who record their walks on separate devices, the additional shared area can nevertheless correspond largely to the other person's cumulative areas and can make a home, routines or frequently visited places recognisable. With more than two members, the map does not attribute the additional area to an individual. A member may turn off Pack Scouts consent at any time; the board, person-level counts and two-tone display are then hidden for everyone and that member's weekly marks are deleted, while the still-unanimously enabled anonymous shared Explore map may remain available.
Apart from an explicitly confirmed family view of one walk and the separate map-cell exception, dog sharing does not upload complete walk records or raw GPS routes, marked places, documents or attachments, puppy-diary photos and events, observations or symptoms including body markers and follow-up history, behaviour or training records, socialisation and quest progress. These remain local unless you export or share them yourself.
Ruffolio also processes hashed session tokens, synchronisation timestamps and sequence numbers, one-use invite metadata, and short-lived rate-limit records needed to authenticate members, resolve edits, prevent abuse and operate the feature. Providing the sharing requested by the members is based on Art. 6(1)(b) GDPR; rate limiting and service-security measures are additionally based on Art. 6(1)(f) GDPR.
Any member can stop syncing and keep the local copy on that iPhone. The remaining members keep access to the server copy and their local copies. The access-managing member may also remove a member; removal immediately ends that account's server access while its local copy remains on its iPhone. Leaving, removal or deletion of the online account immediately deletes active invites created by that member, that member's map-cell rows as both credited contribution and upload provenance, and that member's Pack Scouts weekly marks. When no member remains, the server-side shared dog and its remaining records are deleted automatically after 7 days. Expired invites and sync rate-limit windows are deleted after no more than a further 7 days; deleted-record markers may be retained for up to 365 days so a device that was offline can learn about the deletion. Deleting the online Ruffolio account also removes all of that account's dog-sharing memberships and active invites, unlinks the shared dogs on the device, and keeps their local records.
4. Permissions
The app requests a permission only when you use the corresponding feature:
- Location: to record walks, power the Explore map, provide approximate current weather and tick-weather information, and locally match nearby danger reports or planned fireworks; also in the background during a recording you started. If you voluntarily mark your home and separately enable the departure prompt, the exact coordinate is kept in protected, device-only storage and registered only with iOS as one local boundary; Ruffolio neither receives nor synchronises it. For weather, the point rounded to two decimal places described in section 6 goes directly from the device to Apple. If you additionally consent to a shared dog's shared Explore map and all other current members also consent, only the derived 25-metre map cells described in section 3a are transmitted, not the GPS route. Separately, after a completed walk you may explicitly share one optionally start/end-protected map line as a private family view. When you select the Community post filter Nearby or add an approximate location to a Community post, a point rounded to one decimal place is transmitted. Looking for selected walk routes nearby sends a search point rounded to two decimal places; an invited creator's separately confirmed route submission instead contains the exact reviewed publication line described in section 3. If you explicitly select “In person near me” in the trainer directory, a search point rounded to two decimal places is transmitted for that service-area match. The separately optional Community dog-walk barometer and danger-report flows use the precision described in their respective sections; a danger report transmits an exact location only after your explicit confirmation. For fireworks matching, the location is used transiently on the device and is not sent to Ruffolio.
- Camera: to magnify your dog’s coat in the on-device Tick Finder, scan documents and invoices, read an invite QR code, or photograph a dog for a private dog encounter. Tick Finder live frames remain in memory and are not saved or uploaded. For a dog encounter, Ruffolio processes the image on the device, stores only a cropped and re-encoded dog image, and discards a full-frame fallback that could not be cropped.
- Microphone: only when you deliberately turn this iPhone into a Dog Cam. Ruffolio then listens for barking and related sounds, analyses the audio in memory on this device, and stores only the resulting event summary. The audio itself is never recorded, written to storage, uploaded or sent elsewhere.
- Photo library: to select a dog profile photo, which is included when you explicitly enable dog sharing for that dog, an image for a private dog encounter, an optional Community profile photo, an optional Community post photo, or a route photo that you separately select for editorial publication through the Creator Beta. Encounter images follow the same on-device processing and full-frame restriction as camera images.
- Notifications: for reminders scheduled locally on the device, including observation follow-up dates you choose and the optional best-effort question after leaving your marked home, an alert when an official weather or Community danger report is actually found nearby during a walk, and — only after you enable each feature separately — best-effort notices for planned fireworks whose editorial selection radius the device matches against your location and the generic Community push notices for your current Community account described in section 3.
- Calendar: to add appointments and shared walks you explicitly choose; the app does not read existing calendar entries. Shared walks use only the public area by default. A private meeting point is added only after you explicitly select that option, and the app warns that calendar events may sync to other devices or people.
You can revoke any permission at any time in iOS Settings.
5. Apple Maps (MapKit)
Ruffolio uses Apple's MapKit to display maps. When a map loads, your device communicates directly with Apple. Technical data such as your IP address and the displayed map area may be sent to Apple. The provider of Ruffolio does not receive this data. Apple's privacy policy applies.
6. Weather and weather warnings
When a location is available, Ruffolio may load current conditions and a short hourly forecast from Apple Weather (WeatherKit) before a walk and in the tick-protection view. Before the request, the app rounds the current position to two decimal places (about 0.01 degrees or roughly 1 kilometre) and sends that rounded point directly from the device to Apple. Ruffolio's server receives neither the point nor the WeatherKit request. Returned weather values are cached only in the app's memory for up to 15 minutes. The weather display identifies Weather as its source and links to Apple's legal source attribution. Apple's privacy policy applies to Apple's processing.
When the feature is enabled, the app downloads the same Germany-wide warning package for every user from Ruffolio. The package is prepared on the server from warnings issued by the German Weather Service (DWD). The request contains no coordinates, region identifier or walk route; matching the package against your current location happens only on your device.
Downloading the package involves the connection data technically required for an internet request, as described in section 10. Ruffolio sends neither your location nor your route to its server or to DWD during this process.
7. Shared danger, water, and fireworks notices
When shared danger reports are enabled, the Explore map shows short-lived notices from other users about wildlife, dead animals, possible bait or poison, broken glass, suspected blue-green algae and other dangers, plus clearly labelled test reports. To retrieve them, the app sends Ruffolio a map centre rounded to two decimal places (about 0.01 degrees or roughly 1 kilometre) and a search radius. During a walk you started, the app may update this rounded nearby search periodically. Your exact current coordinate and walk route are not part of the lookup request, although repeated rounded queries may reveal approximate movement. The technical connection data described in section 10 is also processed.
The response contains the exact location marked by a user, its category, an optional note, for a blue-green algae report an optional water-body name, and the creation and expiry times. These details are visible on the nearby map to every user, including people who are not signed in to Community. Ruffolio also makes the same active details available through its public, read-only Safety API, so other apps, maps and services can retrieve and display them until they expire. The reporting person's nickname, account identifier and other profile data are not returned publicly. Integrators are asked to remove entries at expires_at, but Ruffolio cannot technically control copies stored independently by third parties.
The same nearby search rounded to two decimal places may additionally retrieve curated warnings for rivers and lakes. This response contains no Community account or profile data; it contains the warning kind, water-body name and stable BfG water-body identifier, warning point and radius, optional note and evidence source, plus start, creation and expiry times. These warnings are also readable through the Safety API. BfG identifies the water body; the warning claim and any separately named evidence source do not automatically come from BfG.
Planned fireworks are separate curated, source-evidenced public events. The app downloads the same Germany-wide package covering no more than 48 hours for every user. It contains the stable event identifier and revision, country code, title, venue and locality, point, notification, start and end times, an editorial selection radius with its basis, and the public source. The request contains no coordinate, region identifier, account or dog ID, or walk route, although it does involve the technical connection data described in section 10. If you separately enable fireworks notifications, your iPhone can schedule no more than eight matching notices locally after a successful package refresh, a fresh location fix, and system permission. The location is used transiently on the device at matching time and is not sent to Ruffolio; it need not be your later location when a notice is delivered. Without a fresh fix, no new notices are scheduled. Local delivery is best effort and may be delayed or omitted. New, corrected, or revoked events are considered only after a successful refresh; notices already shown cannot be recalled. The radius is only a selection aid, not an audibility forecast, and the event may change or be cancelled.
To prepare curated water-quality warnings, Ruffolio additionally evaluates third-party satellite and environmental data about water bodies, in particular Copernicus Sentinel data provided through the EU Copernicus programme and its Land Monitoring Service (ESA/CLMS). This screening concerns only publicly observable properties of rivers and lakes, such as indications of possible blue-green algae; it contains no personal data, and no data about you is sent to these providers for it. Warning responses may include a source attribution for this satellite data.
Only active Community members can submit a danger. When you explicitly confirm a report, Ruffolio receives the exact marked location, the selected category, for a suspected blue-green algae report the optional water-body name, and your optional note of up to 160 characters. Do not include names, addresses, contact details or other personal data. The report remains linked to your Community account on the server but is publicly shown without your identity. This internal link and an account limit of five accepted reports per UTC day support abuse prevention, moderation and deletion when an account is deleted.
Test reports stop being returned publicly after 15 minutes, wildlife and dead-animal reports after 24 hours, blue-green algae, bait and broken-glass reports after 7 days, and other dangers after 3 days; Ruffolio may remove a report sooner for safety or moderation reasons. The no-longer-public server record containing the exact location, category, note, optional water-body name and account link is deleted automatically within a further 7 days. Deleting the Community account deletes its linked danger reports immediately.
The app matches downloaded reports against your current location locally. An in-app alert or local notification appears only when an active report is actually found nearby. A test alert is explicitly labelled and states that no action is required. Ruffolio does not independently verify danger reports, does not show a safety or all-clear status, and is no substitute for police, fire, ambulance, veterinary-control or other responsible authorities. Providing the report feature you request is based on Art. 6(1)(b) GDPR; abuse prevention, moderation and secure public delivery are additionally based on Art. 6(1)(f) GDPR.
8. Backups
Your app data may be included in a device backup with Apple or on your computer if you have enabled that iOS feature. You control this through your iOS and iCloud settings.
Ruffolio marks the separate local store for private dog encounters for exclusion from automatic device backups. If you deliberately create a manual Ruffolio data backup, that export file does include encounter names, notes, cropped photos and recognition features. You then decide where to save or share the file; at that destination it may be covered by that service’s backup or synchronization rules.
9. No analytics, advertising or tracking SDKs
The app contains no third-party analytics, advertising or tracking SDKs and does not create usage profiles.
10. This website, Community and hosting
Ruffolio does not use analytics, advertising or tracking cookies on its publicly accessible marketing and legal pages, does not embed corresponding services, and loads no third-party fonts or media.
After a successful sign-in, the protected expert portal sets a technically necessary session cookie. It is used solely to keep the expert signed in and protect the expert area. The cookie cannot be read by JavaScript (HttpOnly), uses SameSite=Lax, and is transmitted only over an encrypted connection under HTTPS (Secure). It is removed when the expert signs out or expires automatically. The signed-in expert area cannot be provided without this cookie. Storage and access are based on section 25(2) no. 2 TDDDG.
During expert sign-in, Ruffolio processes the email address and password entered solely to verify access authorisation. The plain-text password is neither stored nor logged; only a cryptographic password hash is stored. Account administration and access protection may additionally involve the display name, approval and account status, session data, and non-reversible identifiers relating to failed sign-in attempts. The contents of a pilot session are cryptographically signed; for database sessions, only a hash of the session token is stored server-side. The legal bases are Art. 6(1)(b) GDPR for providing expert access and Art. 6(1)(f) GDPR for protection against unauthorised access. No login codes or other sign-in emails are currently sent.
In the expert portal, Ruffolio also processes the legal and public name, profile description, an optional profile photo, broad city or region, specialties, consultation languages, availability for new enquiries, an optional public HTTPS contact page, expert category and review status, as well as credential metadata such as type, issuer, reference, validity, internal review documentation and review messages intended for the expert. This also includes uploaded credential documents and consultation offerings containing a topic, channel, duration, description, final price and publication status. For an active, fully checked dog trainer, Ruffolio makes only the public name, profile description, optional profile photo, broad region, specialties, languages, enquiry availability, a contact page the trainer explicitly entered as public, precise check and validity dates, and any published offerings available in the trainer directory. The legal name, login email, private address, reference numbers, credential documents and internal review messages are not published there. An invitation link is time-limited, bound to the invited email address and can be redeemed only once; Ruffolio stores only a cryptographic token fingerprint together with creation, expiry, revocation and redemption status. These data are processed to invite, review and administer the expert profile and to prepare and present the marketplace service. The legal basis is Art. 6(1)(b) GDPR; traceable approval, abuse prevention and quality assurance are additionally based on Art. 6(1)(f) GDPR.
For in-person services, the trainer selects an approximate centre and a radius of no more than 150 kilometres. Only the reviewed area label and radius are public; the internal centre is not returned in the trainer profile or directory response. If you explicitly choose “In person near me”, the app rounds your current search point to two decimal places (roughly 1 kilometre) and sends it to Ruffolio. The server compares it with the internal trainer areas and returns only whether the coarse search point lies inside each trainer's area. The search point is not stored as part of the trainer directory, is not shared with trainers and is not used for live tracking; technically necessary connection data described in section 10 still arise. This optional function is based on Art. 6(1)(b) GDPR to provide the area search you explicitly requested.
The “Checked by Ruffolio” label refers only to the document checks itemised in the profile: identity, the section 11 permit submitted for the profile, and currently valid professional liability insurance. It is not approval by a public authority, a rating of training quality or a promise of results. If a trainer changes review-relevant public profile or service-area information, the profile is removed from the directory until it is approved again.
The separate Bavaria service directory makes publicly available business data from OpenStreetMap searchable: name, category, business address, website, any business telephone number, location coordinates, and the link and identifier of the OpenStreetMap source record. Where a sole trader is identified by name, these details may be personal data. Ruffolio publishes no Google reviews, creates no ranking, and does not mark these listings as “Checked by Ruffolio”. Processing serves the legitimate interest of giving dog owners a factual regional search (Art. 6(1)(f) GDPR). The open source data is licensed under ODbL 1.0 and attributed with “© OpenStreetMap contributors”. You can report an inaccurate listing, object, or request correction directly from the listing or by emailing mail@pmuench.com; Ruffolio will review the source record and correct or remove its own display where required.
The website, dog-sharing and Community APIs including danger reports, the Safety API with its fireworks package, and the weather-warning package are hosted by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. When you visit a page, use dog sharing, make a Community or danger-report request, or download the weather-warning or fireworks package, Vercel processes technically necessary connection data, particularly the IP address, timestamp, requested path, and device and browser information. Ruffolio does not store the raw IP address in its application database for public endpoint rate limiting; it stores a pseudonymous hash derived with a server secret, and deletes the entry after no more than 7 days. Vercel may separately retain connection logs according to the production project configuration; that retention is audited and limited before online features are enabled. This processing serves secure and reliable delivery and abuse prevention. Its legal basis is Art. 6(1)(f) GDPR.
Credential documents are stored in a privately configured Vercel Blob store in the Frankfurt region. Direct public access is disabled. The portal retrieves a file only after a fresh server-side check of an authorised admin or reviewer session; browser and CDN caching are disabled for these responses. Only size-limited PDF, JPEG and PNG files are accepted. Further information is available in the Vercel Private Blob documentation.
Processing in the United States cannot be ruled out. Vercel is certified under the EU-US Data Privacy Framework. More information is available in Vercel's privacy notice.
The expert portal, dog-sharing and Community database is provided through Neon Platform Services by Neon, LLC, an affiliate of Databricks, Inc. Neon processes the stored portal, shared-dog, Community and account data to provide, secure and operate the database. Processing by subprocessors and in third countries cannot be ruled out; the applicable contractual safeguards are set out in the Data Processing Addendum and the Neon Platform Terms.
11. Your rights
Subject to the legal requirements, you have rights including access, rectification, erasure, restriction of processing, data portability and objection. Local content can be managed directly on your device. You can stop dog sharing for an individual dog in its sharing settings while retaining the local copy; deleting the online Ruffolio account stops every dog share. Your Community nickname, selected dog mentions, profile photo and account can be changed or deleted from Community settings; you can also remove post photos and Helpful marks and delete your own posts and replies in the app. A danger report you submitted automatically loses public visibility after the period stated in section 7 and is deleted within a further 7 days; deleting the account deletes its linked danger reports immediately.
For privacy questions, contact mail@pmuench.com. You also have the right to lodge a complaint with a data protection supervisory authority.
12. Changes
If the app's functionality, this website, or the service providers used change, this policy will be updated accordingly.