PawMode Privacy Policy
This Privacy Policy describes how PawMode ("App") handles information when you use the app on Apple platforms.
1. Data We Process
- Device information: device identifier (vendor ID) and device name, used for two-device pairing and identification.
- Thermal and battery data: device thermal state, battery level, and charging status, used to monitor vehicle conditions.
- Camera feed: the camera you select — front, rear, or both if you enable dual capture — is displayed locally in Monitor mode. Still snapshots are captured when your paired phone requests one, when motion or barking is detected, and, if you enable it, alongside the Monitor's periodic status updates. Those snapshots are uploaded to Apple CloudKit so your paired phone can view them. Loop recordings are written to the app's own storage on the device and are deleted with the app; a video or snapshot you explicitly save goes to your photo library and stays there like any other photo. Neither is uploaded.
- Microphone: if you turn on bark detection, audio is analysed on the device to recognise barking. The audio is not recorded, stored, or uploaded — but a detection does capture and upload a snapshot, as motion detection does.
- Cabin sensor data: if you pair a temperature sensor, its temperature and humidity readings, its battery level and whether it is connected are shared with your paired device, along with whether the camera is currently paused and any status advisory the Monitor has published (for example that its screen locked).
- Location data: your location is used solely to work out which country you are in, so the reassurance message can be shown in the local language. The app asks the system for coarse accuracy and uses the result only for that lookup. It is not stored remotely and is never shared with your paired device.
- CloudKit data: device pairing codes, device identifiers and names, thermal state, battery level, charging status, heartbeat timestamps, display messages, whether the pair currently holds a subscription, and the snapshots described above are synced between paired devices via Apple CloudKit.
- Purchase data: subscription and purchase status is processed through Apple StoreKit. We do not receive or store your payment details. Whether the pair holds a subscription — not what was bought, when, or for how much — is shared between your two devices as described above, because one subscription covers both phones and each has to know the other is entitled.
- Backup alert service data: if you use the backup alerting service described in section 3, we store, on servers we operate: your device's Apple push notification token, your pairing code, your device identifier and name, the app version, which role the device is in, whether it can receive Critical Alerts, which Apple push environment it uses, when its registration was last refreshed, and whether you have currently silenced alerts (including any “off duty” period you have chosen). An alert it sends carries the Monitor's name, your pairing code and the identifier of the alert, so the app can match the alert to the right pairing when it opens. To notice when your Monitor device stops reporting, the service reads that device's record from Apple CloudKit: when it last reported, its thermal state, battery level and charging status, and any status advisory it published (for example, that its screen was locked). Of those readings it keeps only what it needs to remember between checks: that the device was recently reporting, and the details of an alert in progress. Both of those records also carry the device's identifier, name and pairing code, so the service knows which pair they belong to. No camera images, video, audio, location, or the messages you display ever reach it.
2. How Data Is Used
Data is used only to operate core app functionality: monitoring vehicle temperature, displaying reassurance messages, enabling two-device pairing and remote monitoring, and processing in-app subscriptions.
The backup alert service exists for one purpose: to notice when your Monitor device stops reporting — because it crashed, lost power, or lost signal — and to alert your paired phone even when the app is not running. The app alone cannot do this: raising an alert requires the app to be awake, and a phone that has stopped reporting cannot report that it has stopped. The service also answers, for your own Monitor device, how many of your paired phones would currently be alerted, so the Monitor can warn you in the car when the answer is none. That answer is a count only.
3. Data Sharing
We do not sell personal data, and we do not share data with third parties for advertising.
Data moves between your paired devices through a shared area of PawMode's Apple CloudKit container. Your pairing code is how the app organises that data — it is not a lock on it. There are no per-account access controls: the shared area is readable by the app rather than by your Apple account, so anyone who obtains your pairing code, from the QR code or from a diagnostics file, can read that pair's data and can pair their own device to it. Snapshot images are the exception: they are encrypted, and the key is not the pairing code — it is generated on the Monitor phone, travels to your other phone inside the QR code, and is never uploaded. Someone holding only your pairing code cannot see your images. Someone who photographs the QR code itself gets both, so treat the QR as the secret rather than the code alone. Reaching that shared area at all requires Apple's own access to this app's container, which is not open to the public internet — but within that boundary the separation between one household's data and another's is a convention the app follows, not a protection the system enforces. The pairing code also appears inside the shared records themselves, so anyone who comes by one of those records — or by a diagnostics file that references your pair — can recover it. Treat the pairing code as a password: do not photograph or post the QR code, and do not share raw diagnostics publicly.
Unpairing does not undo this. It stops new data being written for your device, and it does not lock out someone who already has the code. Snapshots already uploaded are cleared by the 48-hour sweep described below rather than by unpairing itself. Pairs set up before this version of the app are not encrypted and their images stay readable to anyone who can reach the shared area, because there is no way to deliver a key to an existing pair except through that same shared area. Pairing the two phones again — the Monitor offers this in one tap, and the other phone scans once — switches encryption on. The Monitor says so once and does not ask again. If you believe your pairing code has been seen, unpair and ask us to delete the stored snapshots using the contact link below. We do not have per-account access controls on this data, and we would rather say so than imply protection that is not there.
Beyond your own devices, there is one place your data goes deliberately: the backup alert service. This is a small server we operate on Cloudflare's infrastructure, which holds the data listed in section 1 so that it can send an alert to your phone when your Monitor device goes silent. Cloudflare hosts it on our behalf and does not use the data for its own purposes. Apple's push notification service delivers the resulting alert, as it does for every notification on your device.
The service is used only for the pairing it belongs to. It never receives your camera feed, recordings, audio, location, or the messages you display.
4. Data Retention
Uploaded snapshots are deleted once they are more than 48 hours old. The app never shows you anything older than the most recent one, so nothing is lost by clearing them.
One thing about how that works matters, and we would rather state it than let you assume otherwise. CloudKit only lets the device that uploaded an image delete it, so the clearing is done by the Monitor phone itself, while PawMode is running on it — in practice, the next time you use it. If you delete the app instead of using it again, you remove the only thing able to clear that last session's snapshots, and they stay in the CloudKit container until they are removed by us. The same is true of images uploaded by a phone you no longer have. In either case, ask us using the contact link below and we will delete them.
Unpairing removes your device's pairing record from CloudKit. Settings stored on the device go with the app when you delete it; loop recordings in the app's own storage go with it too; anything you saved to your photo library stays in your photo library, as any photo would.
In the backup alert service, data expires on its own: your device's registration after one year, refreshed each time you use the app; an “off duty” setting one year after it was last confirmed, which the app does each time you open it; the record that your Monitor was recently reporting after 24 hours; and the record of an individual alerting incident after 7 days. Unpairing asks the service to delete your registration, as does switching the app out of Personal mode; if that request cannot reach the service, the registration expires on its own within the year.
5. Security
We rely on Apple platform protections, including app sandboxing and encryption in transit and at rest, to help protect data processed by the app. As described in section 3, the practical boundary around your pair's data is your pairing code rather than your Apple account, so its secrecy is what keeps that data yours.
In the backup alert service, a device's registration is stored under a one-way hash of its push token rather than under your pairing code or device identifier, so that a registration can only be created or changed by the device that holds the token itself. Silencing alerts applies only to the registration that asked for it, never to the pairing as a whole, so silencing your phone would require your device's push token rather than merely knowing your pairing code.
6. Children's Privacy
PawMode is not directed at children under 13 and does not knowingly collect personal data from children.
7. Policy Changes
We may update this Privacy Policy from time to time. The effective date at the top indicates the latest version.
8. Contact
Privacy requests and support: https://michelstorms.com/