Privacy Policy
WooMe
Last updated: October 1, 2026 · Effective: October 1, 2026
WooMe is a private photo album for your pets. You build a profile for your cat or dog, keep photos there, and invite specific people to see specific parts of it. It is not a social network — nothing you upload is public, and there is no feed.
This policy explains exactly what we collect, where it lives, who can see it, and how long we keep it. We have tried to write it in plain language rather than legal boilerplate.
Who we are. WooMe is operated by Siyun Peng, an individual developer based in Los Angeles, California, USA. In this policy, "we" and "us" mean Siyun Peng.
How to reach us. support@woome.pet — we aim to respond within 24 hours.
1. What we collect
1.1 Your account
| What | Why | Where it lives |
|---|---|---|
| Email address | To create your account, sign you in, and send security notices | Supabase Auth |
| Password | To sign you in. Stored only as a salted hash — we never see or store your actual password | Supabase Auth |
| Display name | Shown to people you invite. Optional; defaults to the part of your email before the @ | profiles table |
| Profile photo | Optional. Shown to people you invite | Private storage bucket |
| Sign-in method | If you sign in with Apple or Google, we record which one | Supabase Auth |
If you sign in with Apple and choose Hide My Email, we receive only Apple's relay address. That works fine — we never need your real address.
1.2 Your pets
Everything in a pet profile is typed in by you: name, species (cat or dog), breed, gender, birthday, the date they joined your family, and a short description. We do not infer, enrich, or purchase any of this.
1.3 Your photos
What we store. When you add a photo, your device converts it to JPEG and resizes it (longest edge 1280 pixels), then creates a small preview (256 pixels). Those two copies are what we upload and keep.
Videos and Live Photos. If you add a video, or a Live Photo with its motion, your device first re-encodes the moving part into a new video file (at most 1080p) and makes a still cover image from it. The new file carries no capture time, no location and no device model from the original. The capture time and rough location are read from the original on your device, exactly as for photos below, and kept in your account rather than in the file.
Your original file stays on your device. Whether or not you subscribe, the file your camera produced is not uploaded and we never hold it. It stays in your phone's own photo library, where it already was. Anything you download or export from WooMe is the copy described above.
What we read from the photo. Two things, both read on your device before anything is uploaded:
- The time the photo was taken, so your album can be organised by when moments happened rather than when you got around to uploading them. Not every file carries that information; when it is missing, we simply use the time you added the photo instead.
- Roughly where the photo was taken, so that we can one day show you where your memories happened. See below for exactly how rough.
How rough the location is. The coordinates are read on your device and rounded to two decimal places before they ever leave it — roughly a one-kilometre square, enough to tell one city or neighbourhood from another, and not enough to identify a home, a street, or an address. The precise coordinates are discarded on your device and never reach our servers. Not every photo carries location information; when it is missing, we hold none for that photo, and nothing else changes.
Why we read it when you upload, rather than later. The copy of your photo that we store is compressed, and compressing it removes this information for good. Whatever we do not read at that moment is gone from our side forever — so if we did not read it now, a feature you turn on next year could never show you anything about the photos you already have.
What we do not do. We never ask your device for your current location — we have no location permission and no location tracking. We only read what the photo itself already carries, and only at the rounded precision described above.
How photos are protected. Photos are kept in private storage. There is no public link to any photo. Every time a photo is displayed, the app requests a temporary signed link that expires after 24 hours.
What leaves WooMe when you share. An image you share out of the app is a compressed copy that carries no capture time and no location — that information stays in your account and does not travel with the picture.
What you get when you export. Exporting is the opposite situation: it is your own information coming back to you, so it is complete. The package holds your photos together with a list of capture times, rough locations, captions, and which pets are in each picture. It does not contain original camera files, because we never had them.
How the export reaches you. If you have never subscribed, your phone builds the package itself and nothing extra is stored on our side. If you have ever subscribed, your album may be too large for a phone to package, so we build it on our servers and email a download link to your account address. That package and its link last 48 hours; you can download it more than once in that time, and then it is erased.
1.4 Who you share with
When you invite someone, we store the relationship: who they are, which pet they can see, which seat they hold (Family or Friend), and which permissions you have switched on for them. Invitation links expire after 7 days.
1.5 Problem reports
If you tap "Report the issue", we collect only what is needed to diagnose it: the screen you were on, the app URL, your browser/device identification string, the time, whether you were online, your screen size, and whatever you type in the description box. If the failure happened inside the app rather than being reported by you, we also attach the name of the internal operation that failed (for example "save photo") and, when a report had to wait because you were offline, the time the problem originally occurred. Nothing else is attached, and the description is limited to 500 characters.
1.6 How you use the app
To understand whether WooMe actually works for the people using it — how many finish setting up a first pet, whether invitations get accepted, where people get stuck — we record a small number of in-app events. An event is a short label for something that happened, plus a few details about the action itself. For example: that an account was created; that a pet profile was added; that a photo was added, and whether it was a photo, a video, or a Live Photo; that an invitation was sent or accepted; that a suggested photo was accepted or declined; that the subscription screen was shown; that a purchase completed; and that the app was opened.
What an event does not contain. No photo and no preview of one, no caption or note you typed, no pet's name and no person's name or email address, no IP address, no advertising identifier, and no device fingerprint. Events are linked to your account — that is how we can tell one person's first week apart from another's, and it is also why deleting your account deletes them along with everything else (see section 5).
Where it lives and who can see it. In our own database at Supabase, alongside the rest of your data (section 2). We built this ourselves: no third-party analytics or advertising software is involved, nothing is sent to another company, and no one outside WooMe can read it. We read it in aggregate, to answer questions like "how many people finished adding a first pet this week".
1.7 What we never collect
- Your device's current location, or any live location tracking — we never ask your device where it is. The only location we hold is the rounded, roughly one-kilometre value that a photo you uploaded already carried (see 1.3)
- Your contacts, or any access to your photo library beyond the specific photos you select
- Advertising identifiers, or any cross‑app or cross‑site tracking
- Payment card details — subscriptions are handled entirely by Apple, and we never see your card
We do not use third‑party analytics or advertising software in WooMe. If that ever changes, we will update this policy and Apple's privacy label before the change ships. We do record how you use the app itself — see 1.6 — but we do so in our own database, with no outside company involved.
We do not sell your personal information, and we never have. We also do not share it for cross‑context behavioural advertising, as those terms are defined under California law.
1.8 The launch waitlist
If you sign up at woome.pet/waitlist, we collect the name and email address you enter and a record that you agreed to receive our newsletter. It is stored with Netlify, our website host, and used only to email you about WooMe's launch and occasional updates. You can unsubscribe from any email, or ask us to remove you at any time at support@woome.pet.
2. Where your data lives
Your data is stored with Supabase, which hosts it on Amazon Web Services in Northern California, United States. Our website is hosted by Netlify, which also stores waitlist sign-ups (see 1.8). Every email we send you — sign-in and security messages, and export download links — goes out through Resend, which receives your email address and the message itself.
This means that if you use WooMe from outside the United States, your data is transferred to and stored in the United States, which may have different data protection laws than your own country. By using WooMe you consent to that transfer.
These providers process data on our behalf and are contractually prohibited from using it for their own purposes.
3. Who can see your photos
This is the part most people care about, so here it is in full.
| Who | What they can see |
|---|---|
| You | Everything in your own pet profiles |
| Family seat | The Collection and the Gallery. You can switch either one off for any individual person |
| Friend seat | Only the Gallery — that is, only the photos you have actually placed in the display collage |
| Nobody else | Your full album ("Studio") is never visible to anyone but you |
Permissions are set per person, not per group — turning something off for one Family member does not affect the others. These rules are enforced at the database level, not just hidden in the interface.
You can change or revoke anyone's access at any time, and the change takes effect immediately.
We do not scan your photos. There is no automated content analysis of your private album, and no one at WooMe browses it. We act on reports and on actual knowledge — see Section 3 of the Terms of Service for exactly how.
Our access. We do not read your photos as a matter of course. However, we must be honest: our administrators hold credentials that can technically access stored data, and we may use them to investigate a fault, to respond to a report of abuse, or where we are legally required to. We do not use this access for any other purpose. We would rather tell you this plainly than promise something we cannot technically guarantee.
4. How long we keep things
| What | How long |
|---|---|
| Photos you delete | 30 days in "Recently Deleted", then permanently erased |
| Photos awaiting your review | 7 days, then automatically discarded |
| Invitation links | 7 days |
| Temporary photo links | 24 hours |
| Emailed export packages and their download links | 48 hours, then erased |
| A record that you requested an export (when, how big, whether it finished — not its contents) | 30 days |
| Problem reports | 90 days |
| In-app usage events | 90 days, then deleted automatically |
| Website waitlist sign-ups | Until you unsubscribe or ask us to remove you |
| Everything, after you delete your account | Erased immediately — there is no recovery period. The one exception is an export we have already emailed to you (see Section 5) |
| A record of content that was reported to us | Kept after deletion, for safety and legal reasons |
While your account is active, your pet profiles and photos are kept until you delete them.
In-app usage events (see 1.6) are also deleted immediately if you delete your account — the 90 days above is only the automatic ceiling while your account is active.
About that last row. If someone reported a photo to us, we keep a record of that report — what was reported, why, and which account it belonged to — even after the account is deleted. We keep it because a report is evidence, and deleting an account should not erase it. The record does not include the photo itself.
5. Deleting your account
You can delete your account from inside the app: Settings → Account Profile → Delete Account. You do not need to email us or ask permission.
To confirm it is really you, we email a six-digit code to your account address. You enter that code in the app, and then confirm once more.
When you confirm:
- Your pets, your photos, the files behind them, and your account are permanently erased straight away. The one exception: if we have already emailed you an export download link, that package stays available until the link expires — at most 48 hours — and is then erased. An export that is still being prepared is cancelled, and no email is sent.
- People you invited lose access at the same moment.
- There is no recovery period. We cannot undo this, and we cannot get your photos back for you.
⚠️ Export first if you want to keep anything. Settings → Export Data gives you everything in one file. If it arrives as an emailed link, wait for the email before you delete. Once you confirm the deletion, everything else is gone.
Why a code instead of a waiting period? The code is what protects you if someone else gets into your account: they cannot delete it without also reading your email. A waiting period would protect you too, but only by keeping your data alive after you asked us to destroy it — and when you ask us to delete something, we would rather actually delete it.
⚠️ Deleting a single photo is different. A photo you delete sits in "Recently Deleted" for 30 days and can be restored. Deleting your account has no such window.
⚠️ Deleting your account does not cancel your subscription. Subscriptions are managed by Apple, and we cannot cancel or refund them on your behalf. To stop being charged, cancel separately in Settings → Apple Account → Subscriptions on your device.
6. Your rights
Wherever you live, you can:
- See what we hold about you
- Correct anything that is wrong — most of it is editable in the app
- Delete your account and everything in it, from inside the app
- Export a copy of your data
- Object to how we handle your data, or ask us to restrict it
- Complain to your local data protection authority
To exercise anything not available in the app, email support@woome.pet. We will respond within 30 days. We will not charge you, and we will not treat you differently for asking.
If you are in the European Economic Area or the United Kingdom, our legal basis for handling your data is the performance of our contract with you (providing the service you signed up for) and, for security and abuse prevention, our legitimate interests.
If you are in California, the rights above satisfy your rights to know, delete, correct, and opt out under the CCPA/CPRA. As stated above, we do not sell or share your personal information.
7. Security
Data is encrypted in transit and at rest. Photo storage is private, reachable only through short‑lived signed links. Access rules are enforced by the database itself, so a mistake in the app cannot expose photos to someone who should not see them.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data, we will notify you and the relevant authorities as required by law.
8. Children
WooMe is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, email support@woome.pet and we will delete it.
9. Changes to this policy
If we make a material change, we will update the date at the top and notify you in the app or by email before it takes effect. Continuing to use WooMe after a change means you accept the updated policy.
10. Contact
support@woome.pet
Siyun Peng Los Angeles, California, USA
This policy is governed by the laws of the State of California, United States.
