TapCare

Privacy Policy

Effective August 5, 2026

TapCare helps families keep their pets' care records together. This policy explains what information we collect, how we use and protect it, and the choices available to you.

1. Information we collect

  • We collect only the information needed to provide and protect TapCare.
  • Account information may include your social sign-in provider, provider identifier, and the email address, nickname, or profile image shared by that provider.
  • Family and pet information may include family membership and pet profile details such as name, photo, birthday, sex, breed, and neuter status.
  • Care information may include logs, schedules, weight, health notes, allergies, medication, vaccinations, food, treats, supplements, nutrition goals, notes, and report data.
  • Device and notification information may include app and operating-system versions, platform, Firebase Cloud Messaging token, notification settings, and delivery or read status.
  • Support and diagnostics may include your support email and message, error type, limited stack information, technical app or device details, and a Crashlytics installation identifier.
  • For limited server-incident diagnosis, TapCare may store the environment, release, request identifier, safe route and HTTP status, error type, a redacted description, limited stack frames, and related account, email, client-IP reference, or pet identifiers. Authentication tokens and request bodies are not stored in this diagnostic record.

2. How we use information

  • Create accounts, sign you in, identify your account, and protect the service.
  • Provide shared family care logs, schedules, notifications, and reports.
  • Send push notifications and apply your notification preferences.
  • Use Firebase Crashlytics to understand crashes and improve reliability.
  • Respond to support requests, investigate incidents, and prevent misuse.

3. Retention and deletion

  • Account and service data is generally kept while your account remains active.
  • When you place a pet in the in-app trash, that pet and related care data can be restored for 30 days.
  • After 30 days in the trash, the pet and related data are permanently deleted and stored avatar files are queued for removal.
  • If you are the only member of a family, deleting your account permanently deletes the account, family, pets, care logs, schedules, and notification data.
  • If other members remain, your account information is deleted while shared pet and care records remain for the family. Your author identifier is removed and may appear as “Former member.”
  • A token needed to disconnect Apple sign-in is stored separately and encrypted, then removed after successful disconnection or a final non-retryable failure.
  • Sensitive server-incident diagnostics are encrypted and retained for no longer than 30 days.
  • Sensitive diagnostic access audit records are retained for no longer than 90 days. They record the authorized administrator, Cloudflare Access subject, action, incident identifier, and time, but not the diagnostic payload.
  • Firebase Crashlytics retains crash stacks, processed minidumps, and related installation identifiers for 90 days under Google's retention process. This schedule is separate from TapCare account deletion.
  • Information subject to a legal retention requirement is separated and kept only for the required period.

4. Payment information

  • TapCare does not currently offer payment features.
  • We do not collect or store card numbers, purchase receipts, or refund transaction details.
  • Before adding payments, we will update this policy to describe the actual processing and retention periods.

5. Service providers and disclosures

  • We do not sell personal information. We disclose it only with your direction, when required by law, or to providers that help us run the service.
  • Firebase Cloud Messaging processes device tokens to deliver push notifications.
  • Firebase Crashlytics processes crash diagnostics on Google's infrastructure. We do not intentionally attach email addresses, authentication tokens, pet names, or raw private messages as Crashlytics user properties.
  • Slack processes restricted operational incident alerts for authorized TapCare administrators. Those alerts use bounded diagnostic context, exclude authentication tokens and request bodies, and follow the workspace retention settings.
  • Kakao, Naver, Google, and Apple may process sign-in, account identification, and account disconnection data.
  • Cloudflare provides DNS, security, web delivery, email routing, and R2 image storage.
  • Railway provides backend, database, and Redis infrastructure.

6. Push notifications and signed-out privacy

  • When you sign out, the app attempts to unregister the device token, delete the Firebase token, and cancel scheduled notifications. Failed cleanup is queued and retried when the app starts or resumes.
  • To prevent account mix-ups, detailed in-app notifications are shown only when the signed-in user matches the intended recipient.
  • Lock-screen and notification-center messages use generic wording and do not include pet names or care details.
  • You can turn push notifications off in TapCare or your operating-system settings.

7. Your choices and account deletion

  • You may request access, correction, deletion, restriction, or withdrawal of consent where applicable.
  • You can delete your account in the app. Shared-family data is handled as described in section 3.
  • For Crashlytics questions or privacy requests, contact support@tapcare.kr.
  • See the account deletion page for step-by-step instructions.

8. Security

  • We use reasonable safeguards such as access controls, HTTPS, authentication-token controls, and restricted server access.
  • Sensitive diagnostic access requires Cloudflare Access authentication and a separate administrator allowlist. Every successful and denied access attempt is audited.
  • Signed-out cleanup is retried at limited intervals, and push identifiers are separated by account.
  • No internet or mobile service can eliminate every risk, so please also keep access to your account secure.

9. Children and sensitive information

  • TapCare is not directed primarily to children.
  • Pet care records are information you enter about an animal. TapCare is not intended to collect human medical information.

10. Changes and contact

  • If this policy changes, we will post the updated policy and effective date before the change takes effect.
  • For privacy or service questions, contact support@tapcare.kr.
  • We will review your request and respond as reasonably needed.