Last updated: October 2026
1. Data Controller
Wolfie (wolfie.app) is a product of Blanik.dev.
The controller of personal data is:
Blanik.dev
Sole trader (JDG), Poland, European Union
Tax ID (NIP): PL6472574467
Email: [email protected]
For all data protection inquiries, please contact us at the email above.
2. Scope and Application
This Privacy Policy applies to the mobile application (“App”), our websites — wolfie.app (information about Wolfie), app.wolfie.app (the web application), and wolfie.page (public pages published by breeders who use Wolfie) — related backend infrastructure, AI-powered features, and associated services (collectively, the “Service”).
This Policy is provided in accordance with:
- Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)
- Applicable national data protection laws
- Apple App Store privacy requirements
- Google Play Data Safety requirements
By using the Service, you acknowledge that your personal data may be processed as described in this Policy.
3. Categories of Personal Data Processed
We may process the following categories of data:
3.1 Information You Provide
- Email address
- Account identifiers
- Authentication credentials (via secure providers)
- Content submitted within the App
3.2 Automatically Collected Data
- IP address
- Device type and operating system
- Application version
- Log data
- Usage interactions
- Crash reports and diagnostics
3.3 Analytics Data
- Session data
- Aggregated usage statistics
- Feature interaction data
- A pseudonymous analytics identifier stored on your device or in your browser (see 3.5)
3.4 Subscription and Payment Data
- Subscription status and plan
- Purchase and transaction history
- Transaction and receipt identifiers
Full payment card details are processed directly by our payment providers (Apple, Google, or Stripe) and are not collected or stored by us.
3.5 Cookies and Similar Technologies
Our websites use cookies and equivalent browser storage (local storage) in two distinct ways.
Strictly necessary storage. Required for the site to work at all: keeping you signed in on app.wolfie.app, remembering your chosen language, and remembering your answer to the cookie banner itself. These are set without consent, because the Service cannot be provided without them.
Anonymous measurement, with or without your consent. Before you answer the banner, and if you decline, one tool runs: PostHog, in a storage-free mode and in its European Union region. No cookie is written or read, no identifier outlives the page you are on, no profile is created, and two visits cannot be linked to each other. What remains is a count of pages viewed and errors encountered, which cannot be traced back to you or to this browser. Because nothing is stored on or read from your device, this does not require consent under Article 5(3) of the ePrivacy Directive; our legal basis is our legitimate interest in knowing whether our sites work and how they are used (Art. 6(1)(f) GDPR). Google Analytics is not loaded at all until you accept, since a request to it would reach Google even without cookies.
With your consent. Accepting in the banner starts Google Analytics and allows both tools to store an identifier in your browser, which lets us tell a returning visit from a new one, follow how a feature is used across your visits, and — in the web application — connect that to your account:
- Google Analytics 4 — how many people visit each site and how they arrive. Its identifier expires up to 2 years after your last visit.
- PostHog — which features are used, and JavaScript errors encountered in the browser. Its identifier expires 1 year after your last visit.
Both are limited to measuring our own sites. We do not use advertising cookies, we do not allow advertising personalisation on this data, and we do not track you across other companies’ websites.
Withdrawing consent. You may withdraw your consent at any time using the “Cookie settings” link in the footer of our websites, or under Settings → Legal in the web application. Withdrawal deletes the identifiers described above, switches Google Analytics off again and returns measurement to the anonymous mode; it does not affect the lawfulness of processing carried out beforehand. Clearing this site’s cookies and site data in your browser has the same effect.
The App itself does not use cookies. Diagnostics inside the App are covered by 3.2 and 3.3.
We do not intentionally collect special categories of personal data (Art. 9 GDPR). If such data is voluntarily submitted, it is processed solely for providing the Service.
4. Purposes and Legal Bases for Processing
We process personal data strictly for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Account registration and authentication | Art. 6(1)(b) – Contract |
| Providing core application functionality | Art. 6(1)(b) – Contract |
| Processing subscriptions and payments | Art. 6(1)(b) – Contract |
| AI-powered features | Art. 6(1)(b) and/or Art. 6(1)(f) |
| Security, fraud prevention, and logging | Art. 6(1)(f) – Legitimate interest |
| Analytics and performance monitoring (in the App) | Art. 6(1)(f) – Legitimate interest |
| Anonymous website analytics, with no device storage | Art. 6(1)(f) – Legitimate interest |
| Website analytics via cookies or similar storage | Art. 6(1)(a) – Consent |
| Compliance with legal obligations | Art. 6(1)(c) – Legal obligation |
Where required by law, processing is based on user consent (Art. 6(1)(a)).
5. AI Processing Disclosure
Certain features of the Service may use artificial intelligence models.
User-submitted content may be processed by external AI providers to generate requested outputs. Except as described in Section 5.1, providers process it solely for that purpose.
AI providers may include:
- OpenAI
- Anthropic
- OpenRouter, a routing service that forwards a request to the provider running the selected AI model
We send AI requests through a gateway we operate ourselves, which passes each request to the provider of the model in use. When a request goes through OpenRouter, the model provider it reaches also receives the content of that request.
The AI provider may change over time due to infrastructure decisions, testing, or service optimization.
Photos and documents you submit for reading (for example a pedigree, a receipt, a certificate, or a pet's vaccination booklet or vet invoice) are sent to the AI provider only to read the details you asked for. We do not store the files; only the details you choose to save are kept.
We:
- Do not sell personal data to AI providers
- Require contractual safeguards
- Require processing solely for service delivery
- Do not permit training on user data, except as described in Section 5.1
Users should not submit confidential, regulated, or sensitive data unless necessary for intended functionality.
5.1 Free and preview AI features
Some AI features are provided free of charge — AI features on the Free plan — or are clearly marked in the Service as a beta, preview or experimental AI feature at the point where you use them. To offer these features, we may use AI models whose providers keep the content of requests and may use it to improve or train their models, under their own terms. The content you submit to these features (for example your chat messages) may therefore be used by those providers for that purpose.
This exception does not apply to reading photos or documents, or to AI features on the paid Plus and Pro plans (including Wolfie.app Pro), which are processed only as described above.
Please do not enter information about yourself or other people in these features that you would not want used this way.
6. Service Providers (Data Processors)
We use third-party processors to operate and secure the Service.
Infrastructure & Hosting
- Netcup (primary application servers, located in Germany)
- Hetzner (application servers, located in Germany)
- Backblaze (encrypted backup storage)
- Cloudflare (content delivery, DNS, and security/proxy services)
Authentication
- Google Firebase – Firebase Authentication
- Sign in with Apple (Apple Inc.)
- Sign in with Google (Google LLC)
Analytics & Diagnostics
- Google Firebase
- Google Analytics (websites and App)
- PostHog (website product analytics and browser error tracking; EU region)
- Sentry (error and crash monitoring)
AI Features
- OpenAI
- Anthropic
- Google (Gemini API)
- OpenRouter, and the model providers it routes requests to
Payments & Subscriptions
- Apple – App Store In-App Purchase
- Google – Google Play Billing
- RevenueCat (subscription management)
- Stripe (payment processing for direct purchases)
We host our primary servers within the European Union (Germany) for as long as a suitable EU-based option is available. All providers process data under applicable data processing agreements (DPAs).
7. International Data Transfers
Some providers may process data outside the European Economic Area (EEA).
Where such transfers occur, we rely on:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs)
- Additional safeguards where required
Providers that may process personal data outside the EEA — including Google (Firebase, Google Analytics, Sign in with Google, Gemini API), Sentry, RevenueCat, Stripe, Cloudflare, and the AI providers listed in Section 6 (OpenAI, Anthropic, OpenRouter and the model providers it routes requests to) — do so under Standard Contractual Clauses and, where applicable, the EU–U.S. Data Privacy Framework.
PostHog is configured to process data in its European Union region, so website analytics data is not transferred outside the EEA.
Data transfers are performed in accordance with Chapter V of the GDPR.
8. Data Retention
We retain personal data only as long as necessary for:
- Providing the Service
- Fulfilling contractual obligations
- Complying with legal requirements
- Resolving disputes
- Ensuring security
Data may be deleted or anonymized when no longer required.
Users may request deletion of their account and associated personal data, subject to legal retention obligations.
9. Data Sharing and No Sale of Data
We:
- Do not sell personal data
- Do not share personal data for advertising purposes
- Do not engage in data brokerage
Personal data is shared only with service providers necessary for operating the Service.
9.1 Community (content you publish)
Community is a place where Wolfie users ask questions and share experience. What you post there is meant to be read by others:
- Questions, discussions, replies and photos you post in a public community can be read by every signed-in Wolfie user and found through Community search. In a private community they can be read by its members. They are shown with your first name and the initial of your last name.
- Your pet's details are shared only if you choose them when you post: you tick which ones (for example name, breed, sex, age, life stage or weight). We copy only those details into the post at that moment; they are not updated from your pet's profile afterwards, and nothing else from your pet's profile (health records, vet, location) is shared. You can remove the shared pet details from a post at any time.
- We record when you accept the community guidelines, the communities you join, what you mark as helpful, save, report or block, and moderation actions, to run Community and keep it safe. Reports are reviewed by the community's moderators and by Wolfie staff; the person you report is not told who reported them.
- You can edit or delete what you posted. If you delete your account, your posts stay in their discussions but are shown as written by a "Former member": your name, the link to your account, the shared pet details and your photos are removed.
10. User Rights (GDPR)
If you are located in the European Economic Area, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request erasure
- Restrict processing
- Object to processing
- Request data portability
- Withdraw consent (where applicable)
Requests may be submitted to: [email protected]
You have the right to lodge a complaint with a supervisory authority in your EU Member State.
11. Security Measures
We implement appropriate technical and organizational measures, including:
- Encryption in transit (TLS)
- Access controls
- Authentication safeguards
- Monitoring and logging
- Data minimization practices
However, no system can guarantee absolute security.
12. Children’s Privacy
The Service is not directed to children under 16 (or lower age permitted by national law). We do not knowingly collect personal data from children without required consent.
If we become aware of such processing, we will delete the data.
13. App Store & Platform Compliance
In accordance with Apple and Google requirements:
- Data collection practices are transparently disclosed
- Tracking for advertising purposes is not performed
- Sensitive permissions are requested only when necessary
- Users may request account deletion
- Data is processed only for specified purposes
14. Limitation of Liability
To the maximum extent permitted by applicable law:
- We are not responsible for independent processing performed by third-party providers.
- We are not liable for service interruptions or security incidents beyond our reasonable control.
- Users are responsible for ensuring that submitted content complies with applicable laws.
15. Changes to This Policy
We may update this Privacy Policy from time to time.
Material changes will be communicated via the App or website. Continued use of the Service after updates constitutes acceptance of the revised Policy.