Effective date: May 24, 2026
BugFeatures ("we", "us", or the "Company") operates the PetDays mobile application (the "Service"). This policy explains what personal information we collect, why we collect it, how long we keep it, and what you can do about it.
PetDays is operated from the Republic of Korea. This policy is the English translation of our Korean privacy policy, which is prepared under Article 30 of the Korean Personal Information Protection Act ("PIPA"). If the two versions conflict, the Korean version governs.
1. Why we process your information
We use personal information only for the purposes below. If we ever want to use it for something else, we will ask you first.
- Account creation and management — identifying you, keeping your account active, and preventing abuse of the Service
- Providing the Service — storing your pet's daily, health, and care records; predicting care cycles and sending reminders; family sharing; and generating PDF reports
- Support — verifying who you are when you contact us, investigating the issue, and telling you the outcome
- Improving the Service — developing new features, understanding usage in aggregate, and checking that what we ship actually works
2. What we collect
a. Required
- Account information — email address and password (stored hashed, never in plain text)
- Pet information — name, species (cat or dog), breed, date of birth, sex, weight, neuter status, daily records (food, water, litter/toilet, vomiting, weight, condition), photos, and notes
Photos stay on your device. They are never sent to our servers or to Firebase. What a record stores alongside your entry is not the photo itself but its file path on your device, and that path cannot open the photo anywhere else.
- Automatically collected — service usage records, access logs, device information (OS, device model), and IP address
b. Optional
- Camera and photo library access — only to take or attach photos for your pet's daily and symptom records
- Push notification permission — only to send care cycle reminders (bath, nails, teeth, brushing)
- Family member labels — a name and emoji used to tell family members apart when family sharing is on
Optional items are collected only if you use the feature they belong to. Declining them does not restrict any other part of the Service.
3. How long we keep it
- Account information — until you delete your account. If an investigation under applicable law is underway, until that investigation ends.
- Pet information and records — until you delete your account, then destroyed immediately
- Photos — kept on your device until you delete them yourself or uninstall the app. We hold no copy, so there is nothing on our side to destroy
- Service usage records and access logs — 3 months, as required by the Korean Protection of Communications Secrets Act
4. Sharing with third parties
We process your personal information only within the purposes stated in Section 1. We do not currently share your personal information with any third party. If that ever changes, we will ask for your consent first, separately.
This does not cover our processor in Section 5, which handles data on our behalf and under our instructions.
5. Processors
Google LLC (Firebase)
- What they do for us — authentication (Firebase Authentication), database (Cloud Firestore), cloud storage, and push notification infrastructure
- What they handle — account information, pet information and records. Not photos — those never leave your device
- How long — until you delete your account, or until our contract with them ends
Under Article 26 of PIPA, our contract requires them to process this data only for the purpose above, to apply technical and administrative safeguards, to restrict sub-processing, and to be liable for damages. We supervise their handling of the data.
6. International transfer
To use Firebase, we transfer personal information outside Korea.
- Recipient — Google LLC
- Destination — United States (Firebase global infrastructure; we prefer the asia-northeast3 (Seoul) region where available)
- When and how — over the network, at the time you use the Service
- What is transferred — the required items in Section 2, plus any optional items you have agreed to. Photos are not transferred
- Purpose — providing authentication, database, storage, and push notification infrastructure
- How long — until you delete your account, or until our contract with them ends
You may refuse this transfer. Because the entire account system runs on Firebase, refusing means you cannot create an account or use the Service.
7. Your rights
You can, at any time, ask us to:
- let you see the personal information we hold about you
- correct it if it is wrong
- delete it
- stop processing it
Send your request in writing, by phone, or by email and we will act on it without undue delay. If you ask us to correct or delete something, we will not use or disclose that information until the correction or deletion is finished.
You can delete everything yourself, at any time, from [Settings → Account → Delete account] inside the app.
If you live outside Korea, your local law may give you additional rights. Contact us at the address in Section 11 and we will handle your request under this policy.
8. Destruction
When personal information is no longer needed — the retention period has passed, or the purpose is met — we destroy it without delay. Our privacy officer approves the destruction, and electronic files are erased by a method that makes them unrecoverable.
9. Security
Under Article 29 of PIPA, we take the following measures:
- keeping the number of staff who handle personal information to a minimum, and training them
- running regular internal audits
- encryption — passwords are stored as one-way hashes by Firebase Authentication; all traffic is forced over HTTPS/TLS
- technical defenses against intrusion (Firebase security rules, firewall)
- access control — Firestore security rules allow you to reach only your own data; staff access to production data is minimized through IAM permissions
- retaining access logs and protecting them from tampering
10. Cookies and automatic collection
We may use automatic collection tools to analyze and improve the Service. You can refuse push notifications and similar automatically collected items in your device settings; some features may then be limited.
11. Privacy officer
- Name: Kyuseok Seo
- Title: CEO
- Contact: CEO@bugfeatures.com
12. Where to complain
If you believe your privacy has been violated, you can contact the Korean authorities below for mediation or advice.
- Personal Information Dispute Mediation Committee — 1833-6972 (www.kopico.go.kr)
- Privacy Infringement Report Center — 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office — 1301 (www.spo.go.kr)
- National Police Agency — 182 (ecrm.cyber.go.kr)
13. Changes to this policy
This policy applies from its effective date. If we add, remove, or amend anything, we will announce it in the app at least 7 days before the change takes effect. For changes that disadvantage you, we will give at least 30 days' notice.
Addendum
This policy takes effect on May 24, 2026.