Privacy policy
Effective 7 September 2026.
Your records stay on your phone. There is no account. Pet records, photos and documents are stored on your device only, and we have access to none of them. One thing does leave the phone, and only when you tap a button to send it: a photo you ask us to read — a certificate page, or the page with the microchip number. Details below.
Who is behind the app
Denfold is published by MD7 Develop Group. Contact: [email protected].
What we collect
Nothing that we keep. The app has no accounts, no sign-in and no server your records are sent to. We do not know that you added a pet, where you are travelling or when.
Reading a photo
The app can read a photo for you in two places, and both work the same way:
- Fill in from a photo when adding a vaccination or a treatment — it reads the dates, the batch number and the clinic;
- Scan from photo on the pet form — it reads the microchip number.
In both cases that photo — and nothing else — is sent to Google's Gemini model through Firebase AI Logic, which reads it and sends the text back. The app then shows you what was read so you can correct it before saving. Nothing is saved for you automatically.
These two buttons are the only times anything you own leaves your phone, and it happens only when you tap one of them. If you never tap them, nothing is ever sent.
- Only that one photo goes. Your pet records, other attachments and trips are not attached to the request.
- Google processes the photo on our behalf, on a paid tier where it is not used to train their models and is not reviewed by people.
- We keep no copy of it. We have no server to keep it on.
- A certificate photo is also saved with your record on your phone, as any attachment is.
- A certificate can carry your name, address or clinic. If you would rather not send that, type the dates in yourself — the app works exactly the same way.
What you store in the app
All of this stays on your device:
- pet details: name, species, breed, sex, whether the animal is neutered, date of birth, microchip number and date, country of residence;
- records: vaccinations, parasite treatments, medication, vet visits, weighings, documents;
- pet photos and photos attached to records;
- planned trips, the facts you confirmed and the steps you marked as done;
- app settings: reminders, units, date format.
Network
The app makes two kinds of network request, and there is no third:
- Downloading the country requirements database. A
GETrequest that carries no data of yours — no pet details, no chosen country, no identifiers. - Reading a photo, described above — only when you tap the button.
The Firebase library that carries the photo also talks to Google on its own, to confirm that the request really comes from an installed copy of Denfold and not from a stolen key (this is called App Check). What it sends is about the app and the device — the app version, the library versions, a Play Integrity token — and never your records. That check happens only around the reading of a photo.
The requirements database ships inside the app and works offline. The network only refreshes it. Without a connection everything except reading a photo keeps working.
Where data goes
| Where | When |
|---|---|
| Device storage | always: the record database and attached files |
| Backup archive | only when you tapped "Save a copy" and chose a location in the system dialog |
| PDF travel pack | only when you exported it yourself and chose where to save it |
| Google Play | subscription payment only; Play receives no pet records from the app |
| Nowhere else | — |
The archive and the PDF end up wherever you put them. If that is a cloud folder, what happens to them next is governed by that cloud's rules, not by this app.
What the app does not have
- analytics — neither event-based nor "anonymous telemetry";
- automatic crash reporting;
- advertising or advertising identifiers;
- third-party trackers, other than the Google Play billing library and the Firebase library used to read photos;
- sync between devices.
Permissions
| Permission | Why |
|---|---|
| Internet access | updating the country requirements database; reading a photo when you ask for it |
| Notifications | reminders before vaccinations and treatments expire |
| Start after reboot | so reminders survive a phone restart |
| Wake lock and network state | requested by the system scheduler that checks due dates once a day |
| Google Play billing | subscription |
The app requests no other permissions. The list is verified automatically on every build against the merged manifest.
Backup
Android auto-backup is deliberately disabled. With it on, the system would send the app's database to your Google Drive without you doing anything.
You make the copy yourself: the app builds an archive and hands it to the system file picker. Where to keep it is your decision. If you lose your phone and made no copy, the data is gone. That is the price of it being stored nowhere else.
Deleting data
Deleting a record deletes the files attached to it, not just the row in the database. Delete all data in settings removes every pet, record, photo and trip from the phone; your app settings, such as reminders, stay. Uninstalling the app deletes everything. You do not need to ask us to delete your data: we do not have it.
Subscription
Subscriptions are handled by Google Play. The app neither stores nor sees card numbers — it has no field for them. Payment data is processed by Google under their policy.
If you write to support
This is the only case in which we receive anything about you at all. Writing to [email protected] hands us your email address and whatever you put in the message. We use it only to reply, and keep the correspondence no longer than it takes to settle the question.
Pet records do not travel with the message: the app attaches nothing to it. If you sent a screenshot or a backup file, you did so deliberately — and we will delete it on request.
Children
The app is not directed to children and collects data about no one.
Changes
If this policy changes, we will update this page and the date at the top. A change that expands data collection would also require a new promise inside the app itself.