Last Updated: July 25, 2026
Privacy at a Glance
- We collect only what's needed to run the app
- We do NOT sell your data to third parties (learn more)
- We do NOT track you across other apps or websites
- We do NOT show advertisements, and we do not use your data for ad targeting
- Your data is stored in the United States (us-west2 region)
- You can delete your account and all data at any time
This Privacy Policy explains how Facebark™ ("we", "us", or "our") collects, uses, and protects your information when you use our mobile applications, our website, and our services.
1. Information We Collect
1.1 Information You Provide
| Data Type |
Purpose |
| Email Address |
Account creation, login, password reset, important notifications |
| Password |
Account security (stored as a secure hash, never in plain text) |
| Name |
Your name and your pet's name for profile display |
| Pet Information |
Species, breed, age, sex - for your pet's profile |
| Photos & Videos |
Profile pictures and content you choose to share |
| Messages |
Direct messages you send to other users |
| Posts & Comments |
Content you share on the platform |
1.2 Information Collected Automatically
- Device Information: Device type, operating system version (for app compatibility)
- Usage Data: Features you use, interactions within the app (to improve the service)
- Push Notification Tokens: Firebase Cloud Messaging (FCM) device tokens to deliver push notifications. When you first launch the app, you'll be asked to enable notifications. By accepting, you consent to FCM processing your device token. You can revoke this at any time in your device settings. See Firebase Privacy and Google's Privacy Policy for details.
- Real-Time Connection Data: When using messaging features, we collect WebSocket connection metadata (connection timestamps, message delivery receipts, typing indicators) to ensure reliable real-time communication
- Website Analytics: When you visit our website (facebark.com), our servers automatically log the page you visited, the domain of the referring website (query strings are stripped), your browser's user-agent string (used to classify your device type as desktop, mobile, tablet, or bot), and a pseudonymized, daily-rotating hash of your IP address (used to estimate daily unique visitor counts). These website analytics records do not contain your raw IP address, and they are not sent to any third party. This data is used solely for internal analytics to improve the website experience.
- Security Logs: To protect the service against abuse, we record an entry when a request exceeds our rate limits. These security records do contain the raw IP address of the request, along with the path requested and the browser's user-agent string. They are not linked to an account and are used only to detect and block abuse, credential-stuffing, and other attacks. See Section 4 for how long we keep them.
- Record of Your Agreement to Our Terms: When you create an account or accept an updated version of our Terms of Service or this Privacy Policy, we store the date of your acceptance, and a version identifier for the documents in force at that time, together with the raw IP address and browser user-agent string of that request. This is kept as evidence that the agreement was made, and is retained for as long as your account exists.
About IP addresses. We store your raw IP address in the security logs and the terms-acceptance record described above, and a rate-limit warning containing the IP address is also written to our server logs. Our website analytics do not store it, we do not use IP addresses to build a profile of you or to target content or advertising, and we do not send your IP address to any analytics, advertising, or IP-geolocation service. As with any website, the providers that host and deliver Facebark necessarily see the IP address your request arrives from in order to route the response.
1.3 Information from Third Parties
If you sign in with email and password, we store your email and a securely hashed version of your password. If you sign in with Google or Apple, we receive your email address and name from those services. We do not receive your password from third-party sign-in providers.
1.4 Location Information
If you choose to enable location features:
- Home Location: You can optionally set a home location to see nearby pet profiles and local community content
- Location Precision: You control the precision level - exact location, neighborhood (approximately 1 mile radius), or city (approximately 5 mile radius)
- Nearby Searches: If enabled, your approximate location may be used to show your profile in "Find Profiles Nearby" searches by other users
- Vets Nearby: If you use the Vets Nearby feature, your current GPS coordinates are sent to our servers and forwarded to Google Places API (Google LLC) to find nearby veterinary clinics. If precise location is not available, your saved home location coordinates may be used instead. These coordinates are used only to perform the search and are not stored separately by Facebark
- Control: You can disable location features entirely in your privacy settings at any time
1.5 Multi-Profile Account Structure
Facebark™ allows you to create up to 5 pet profiles under a single account:
- Each pet profile functions as a separate identity on the platform
- Profile data (posts, messages, followers) is isolated per profile
- You can switch between profiles within the app
- Other users cannot see that your profiles are linked to the same account
- Deleting your account deletes ALL profiles and their associated data
- Deleting a single profile only removes that specific profile's data
1.6 Cookies and Tracking Technologies
We use only the storage technologies needed to operate Facebark. None of them are used for advertising, and none of them track you across other apps or websites.
- Mobile Apps (iOS and Android): The apps keep you signed in with a secure token stored in your device's keychain or equivalent secure storage. This is not a cookie and cannot be used to track you across websites. The apps also cache images, profile data, and feed content in the app's sandboxed storage to improve performance; that cache is removed when you uninstall the app.
- Informational Pages on facebark.com: Our informational pages—such as the home page and these legal pages—set no cookies and run no client-side tracking scripts. We record the server-side page-view information described in Section 1.2. If you submit a form on one of these pages (for example a password reset, a privacy request, or the account-deletion page), your browser is issued a security cookie named
csrftoken, used solely to protect that form against cross-site request forgery, and in some flows (such as signing in) a sessionid cookie that holds your server-side session for that flow. Neither is used for advertising or analytics.
- Facebark Web App: The Facebark web app—currently in private beta at beta.facebark.com—needs a small amount of browser storage in order to work. All of it is strictly necessary to provide the service you asked for, none of it is used for advertising or profiling, and it includes:
- Cookies:
__Host-fb_session keeps you signed in and is HttpOnly, so page scripts can never read it; fb_web_session is a non-sensitive marker whose only value is "1", telling the app that a session exists; csrftoken protects requests against cross-site request forgery; __Host-fb_active_profile records which of your pet profiles is currently selected, so the correct profile's content loads; and, while the web app is in private beta, fb_beta is an HttpOnly cookie lasting up to 60 days that records that the shared beta access code was entered correctly on your browser. fb_beta does not contain the access code itself, is not tied to your account, and will no longer be set once the web app is open to the public.
- Browser local storage: your appearance settings (theme and display density); your accessibility preference for single-key shortcuts; your chosen location-precision setting (exact, neighborhood, or city—see Section 1.4); your Tails playback preferences (mute, autoplay, captions, default search radius, and whether you have dismissed the unmute prompt); whether you have already seen the introductory app tour; the identifier of your active pet profile; and your Dr. Whiskers conversation history (see Section 1.7). Some browsers may also still hold a record of a privacy choice made on an earlier version of the site (see "Session Replay" below).
- Error Diagnostics (currently switched off): Our servers and the Facebark web app include error-monitoring software from Sentry (see Section 3.2). It is not transmitting anything today — no reporting endpoint is configured, so no error reports leave our servers or your browser. If we switch it on, a technical error report would contain information such as the error message, the page you were on, and your browser type. In the web app, your authentication credentials, cookies, and active-profile identifier are stripped from the report inside your browser before it is transmitted. Our iOS and Android apps do not use Sentry and send no error reports to it.
- Session Replay (not in use): Sentry offers a session-replay feature that records a masked playback of a browsing session. We do not use it. The site no longer offers any control that can turn it on, and with no reporting endpoint configured nothing could be transmitted even if it did. Where such an older permission record is still present, any replay is limited to sessions in which an error occurs, and all text and form input is masked and all images and video are blocked before anything leaves your browser. We will describe the feature here and ask for your permission before ever turning it on again.
- No Advertising Technologies: We do not use cookies, pixels, device identifiers, or any other technology for advertising, ad measurement, or building an advertising profile of you.
- No Cross-Site Tracking: We do not track your activity across other apps or websites.
- No Product Analytics: We do not run any third-party product-analytics, behavioral-analytics, or session-recording service on our apps or website. Our mobile apps include Google's Firebase software, but only the push-notification component described in Section 1.2 — we do not include Firebase Analytics or any comparable analytics library. Because nothing optional is stored on your device, the web app does not show a cookie banner and does not ask you to make a cookie choice. We will update this policy before that changes.
1.7 Dr. Whiskers AI
When you use Dr. Whiskers for pet health information:
- Your questions are processed in real-time to generate helpful responses
- Your conversation history is stored on your own device, not in your account. It is kept in the app's storage on iOS and Android, and in your browser's local storage on the web, so you can reference past discussions. We do not keep a copy of your Dr. Whiskers transcripts on our servers. Recent messages from your device are sent along with each new question so the assistant has context, and are used only to generate that response.
- Clearing your conversation history: On the web, use the clear-history control in the Dr. Whiskers chat screen, or clear your browser's site data. On iOS and Android there is currently no in-app control to clear it; because the transcript is held only on your device, uninstalling the app removes it. Please note that deleting your Facebark account removes your data from our servers but does not by itself erase a transcript already saved on your device.
- Pet medical history is different: if you enter medical history for a pet so that Dr. Whiskers can give better answers, that text is stored on our servers as part of that pet's profile. You can edit or clear it at any time in the app, and it is deleted when you delete the profile or your account.
- Your queries are not used to train AI models
- AI responses are informational only and do not affect your account standing or access to features
- If you save a veterinarian to your profile, this information (vet name, address, and any notes you add) may be used to personalize Dr. Whiskers responses
- AI-generated summaries of veterinary clinics are clearly labeled as AI-generated content
Important: Dr. Whiskers provides general pet health information only. It is NOT a substitute for professional veterinary advice. Always consult a qualified veterinarian for your pet's health concerns.
2. How We Use Your Information
- Provide the Service: Create your account, display your profile, enable messaging
- Improve the App: Understand how features are used, fix bugs, develop new features
- Communicate: Send password resets, important account notifications, follow notifications
- Safety: Detect and prevent fraud, abuse, and violations of our Terms
- Power AI Features: Dr. Whiskers uses your questions to provide helpful pet health responses (your queries are not used to train AI models)
We do NOT: Sell your data to third parties, share your data with data brokers, track you across other apps or websites, or engage in cross-context behavioral advertising (as defined under CPRA).
2.1 Advertising
Facebark does not show advertisements. There is no advertising anywhere in our apps or on our website: we run no advertising SDK, no ad server, and no advertising or measurement pixels, and we do not use your activity, interests, or profile information to build advertising profiles or audience segments.
- No Ad Targeting: Because we serve no ads, we do no ad targeting of any kind, including targeting based on your in-app activity
- No Sale or Sharing: We do not sell your personal information to advertisers, share it with data brokers or advertising partners, or engage in cross-context behavioral advertising as defined under the CPRA
- No Cross-App Tracking: We do not track your activity across other apps or websites for advertising purposes
- If This Changes: If we introduce advertising in the future, we will update this Privacy Policy to describe exactly how it works before it takes effect
3. How We Share Your Information
3.1 With Other Users
Your pet profile, posts, and comments are visible to other Facebark users. Direct messages are only visible to you and the recipient. When you follow another profile, that profile owner can see your profile name and photo.
3.2 With Service Providers
We use trusted service providers to operate the app. These providers act as data processors on our behalf and are contractually obligated to protect your data:
| Provider |
Purpose |
| Google Cloud Run |
Application hosting (us-west2 region) |
| Google Cloud SQL |
PostgreSQL database storage |
| Google Cloud Storage |
Photos and videos storage |
| Firebase Cloud Messaging |
Push notification delivery |
| Upstash Redis |
Real-time messaging infrastructure (typing indicators, read receipts, WebSocket routing) |
| SendGrid |
Email delivery (password resets, notifications) |
| Sentry |
Error monitoring and application performance tracking for our servers and the Facebark web app only (our iOS and Android apps do not use Sentry). Would receive technical error reports as described in Section 1.6; error reporting is currently switched off, so no data is being sent to Sentry. Sentry's session-replay feature is not in use. |
| Google Gemini AI |
Powers Dr. Whiskers AI assistant to answer pet health questions and generate veterinary clinic summaries |
| Google Places API |
Provides veterinary clinic search results, ratings, hours, and photos for the Vets Nearby feature |
Google Cloud Platform processes data according to the Cloud Data Processing Addendum and Data Processing Terms. Google may use sub-processors to deliver services; see Google Cloud Sub-processors for details.
3.3 Legal Requirements
We may disclose your information if required by law, court order, or to protect our rights, safety, or property.
4. Data Retention
- Active Accounts: We retain your data while your account is active
- Account Deletion: When you delete your account, your data is removed from our production systems immediately
- Backups: Deleted data may persist in encrypted backups for up to 90 days for disaster recovery purposes, after which it is permanently deleted
- Legal Holds: Data may be retained longer if required by law or for pending legal matters
- Website Analytics: Website page-view records (Section 1.2) are deleted automatically after 90 days. An automated job runs daily to enforce this. These records contain no raw IP address and are not linked to any account.
- Security Logs: Our retention limit for the security logs described in Section 1.2 is also 90 days, and the automated deletion for these records is likewise not yet running, so older entries may still be present. These records contain a raw IP address but are not linked to any account. You may ask us to delete entries relating to you at support@facebark.com.
- Terms-Acceptance Records: The record of your agreement to our Terms and this Policy, including the IP address described in Section 1.2, is kept for as long as your account exists and is deleted when you delete your account.
We will update this section as soon as the automated deletion of the security logs is in place. Neither the page-view records nor the security logs are linked to an account, and neither is used for advertising or profiling.
5. Your Rights
You have the right to:
- Access: View your data within the app
- Correct: Update inaccurate information in your profile
- Delete: Delete your account and all associated data
- Export: Request a copy of your data in a portable format
- Opt-out: Disable push notifications in your device settings
To exercise these rights, go to Settings in the app or contact us at support@facebark.com.
6. Data Security
We protect your data using industry-standard security measures:
- Encryption in Transit: All data transmitted between your device and our servers uses TLS 1.2+ encryption, enforced by Google Cloud Load Balancer with managed SSL certificates
- Encryption at Rest: All data stored in Google Cloud SQL and Google Cloud Storage is encrypted at rest using Google-managed encryption keys
- Password Security: Passwords are hashed using PBKDF2 with SHA256 and 390,000 iterations (industry standard)
- Database Security: Database connections use Cloud SQL's secure unix socket interface without exposing public IPs
- Access Controls: Google Cloud IAM service accounts with least-privilege access
Google Cloud Platform maintains compliance certifications including SOC 2/3, ISO 27001, ISO 27017, ISO 27018, and GDPR. See Google Cloud Compliance for details.
While we take security seriously, no system is 100% secure. Please use a strong, unique password for your account.
7. Children's Privacy
Facebark is not intended for children under 13. We do not knowingly collect information from children under 13. If we learn we have collected such information, we will delete it promptly.
7.1 Teen Users (Ages 13-17)
For users between 13 and 17 years old:
- Parental Permission: You must have permission from a parent or guardian to use Facebark
- Advertising: We do not serve advertisements and do not use anyone's personal information for targeted advertising. If that ever changes, we will obtain your direct consent before using a teen's personal information for targeted advertising, as required by law
- Parental Access: Parents or guardians may request access to, correction of, or deletion of their teen's personal information by contacting support@facebark.com
8. International Users
Facebark is operated from the United States. Your data is stored on Google Cloud Platform servers located in the us-west2 region (Los Angeles, California, United States).
If you are located outside the United States, your data will be transferred to and processed in the US. For users in the European Union, United Kingdom, or other regions with data transfer restrictions, we rely on:
- Standard Contractual Clauses (SCCs) with our service providers
- Google Cloud's compliance with the EU-US Data Privacy Framework
- Your explicit consent when you create an account
We have conducted Transfer Impact Assessments (TIAs) and determined that, combined with SCCs and Google Cloud's security measures, adequate protection exists for your data. For more information, see Google Cloud GDPR Compliance.
9. California Privacy Rights (CCPA/CPRA)
California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know what personal information is collected
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to opt-out of sale of personal information (we do not sell your data)
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising your rights
9.1 California's Shine the Light Act
Facebark has not disclosed personal information to third parties for third parties' direct marketing purposes in the preceding calendar year.
9.2 California Consumer Privacy Act
California residents may request certain information about our collection and use of personal information over the past 12 months, including the right to, subject to certain exceptions:
- Opt-out of the selling or sharing of your personal information
9.3 Right to Access Information
California residents have the right to request that we disclose certain information about our collection and use of their personal information over the past 12 months. Once we receive and verify your request, we will disclose to you:
- The categories of personal information we collected about you over the past 12 months
- The sources of the personal information we collected about you
- Our business or commercial purpose for collecting or selling your personal information
- The categories of third parties with whom we shared that personal information
- The categories of personal information that were sold or disclosed for a business purpose
- The specific pieces of personal information we collected about you
California residents may only access their information twice within a 12-month period.
9.4 Right to Delete Information
California residents have the right to request that we delete their personal information, subject to certain exceptions. Once we receive and verify your request, if we determine no exception applies, we will delete (and direct our service providers to delete) your personal information from our records.
We may deny your request if retaining the information is necessary for Facebark or its service providers to:
- Complete the transaction for which we collected the personal information; provide a good that you requested; take actions reasonably anticipated within the context of our ongoing business relationship with you
- Detect security incidents; protect against malicious, deceptive, fraudulent or illegal activity or prosecute those responsible for such activities
- Debug products to identify and repair errors that impair existing intended functionality
- Exercise free speech; ensure the right of another consumer to exercise their free speech rights; or exercise another right provided for by law
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code, § 1546 et seq.)
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information's deletion may likely render impossible or seriously impair the research's achievement, if you previously provided informed consent
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your interactions with us
- Comply with a legal obligation
- Make other internal or lawful uses of that information that are compatible with the context in which you provided it
9.5 Right to Correct
California residents have the right to request that we correct any inaccurate personal information that Facebark has collected.
9.6 Right to Opt-Out
California residents have the right to opt-out of the selling or sharing of their personal information. As of the date of this policy, Facebark does not sell or share personal information with advertising partners. If this changes in the future, we will update this policy and provide a clear opt-out mechanism. To help you understand our data practices, we have provided the following charts summarizing what personal information we have collected, sold, shared, or disclosed in the past 12 months.
Categories of Personal Information Collected, Sold or Shared for Cross-Context Behavioral Advertising or Disclosed for a Business Purpose within the past 12 months
| Category of Personal Information |
Collected |
"Sold" or Shared in the Past 12 Months |
Categories of Third Parties to Whom Sold or Shared |
Disclosed for a Business Purpose in Past 12 Months |
Categories of Third Parties to Whom Disclosed |
| Individual Identifiers |
Yes |
No |
N/A |
Yes |
Service Providers |
| Categories Described in California Consumer Records Act, CA Civil Code §1798.81.5 |
Yes |
No |
N/A |
Yes |
Service Providers |
| Characteristics of protected classifications under California or federal law |
No |
N/A |
N/A |
N/A |
N/A |
| Commercial information |
No |
N/A |
N/A |
N/A |
N/A |
| Biometric information |
No |
N/A |
N/A |
N/A |
N/A |
| Internet or other electronic network activity |
Yes |
No |
N/A |
Yes |
Service Providers |
| Geolocation data |
Yes |
No |
N/A |
Yes |
Service Providers |
| Audio, electronic, visual, thermal, olfactory, or similar information |
Yes |
No |
N/A |
Yes |
Service Providers |
| Professional or employment-related information |
No |
N/A |
N/A |
N/A |
N/A |
| Education information |
No |
N/A |
N/A |
N/A |
N/A |
| Inferences drawn from any of the information identified above |
No |
N/A |
N/A |
N/A |
N/A |
Categories of "Sensitive" Personal Information Collected, Sold or Shared for Cross-Context Behavioral Advertising or Disclosed for a Business Purpose within the past 12 months
| Category of Sensitive Personal Information |
Collected |
Shared or Sold in the Past 12 Months |
Disclosed for a Business Purpose in Past 12 Months |
| Social Security, Driver's License, State ID, or Passport Number |
No |
N/A |
N/A |
| Account Log-in and Password |
No |
N/A |
N/A |
| Financial Account, Debit Card, Credit Card Number and account access information |
No |
N/A |
N/A |
| Precise Geolocation |
Yes |
No |
Yes (Service Providers) |
| Racial or ethnic origin, religious or philosophical beliefs or union membership |
No |
N/A |
N/A |
| Contents of email, text messages unless We are intended recipient |
No |
N/A |
N/A |
| Genetic Data |
No |
N/A |
N/A |
| Biometric Information for purpose of identification |
No |
N/A |
N/A |
| Personal information collected and analyzed concerning a consumer's health |
No |
N/A |
N/A |
| Personal information collected and analyzed concerning a consumer's sex life or sexual orientation |
No |
N/A |
N/A |
9.7 How to Exercise Rights
To exercise your rights under California law, a resident must submit a verifiable consumer request to us by going to Settings in the app or contacting us at support@facebark.com.
The person making the request must:
- Provide sufficient information to allow us to verify that the person submitting the request is the person, or the authorized representative, of the person whose personal information is implicated by the request
- Describe the request with sufficient detail to allow us to properly understand, evaluate, and respond to it
Only a California resident, or a person authorized to act on the resident's behalf, may make a consumer request to Facebark related to the resident's personal information. A California resident may also make a consumer request on behalf of their minor child.
We cannot respond to a request if we cannot verify the consumer's identity or the requestor's authority to make the request. You do not have to create an account to submit a consumer request. We will only use personal information provided in a verifiable consumer request to verify the requestor's identity or authority to make the request.
9.8 Response Timing and Format
If a California resident sends a verifiable consumer request as set forth above, we will respond within 45 days. If we need additional time, we will inform the person making the request of the reason for the extension and the length of the extension. We will deliver our written response by e-mail.
Any disclosures we provide will only cover the 12-month period preceding receipt of the verifiable consumer request. Alternatively, the response will explain the reasons we cannot comply with a request.
For data portability requests, we will provide the sought-after personal information in a form that is readily useable and should allow the consumer to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to a verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell the requestor why and provide the requestor with a cost estimate before completing the request.
9.9 Non-Discrimination Notice
Facebark will not discriminate against any consumer for exercising any of their rights under California law. Unless permitted by law, if a consumer exercises any of their rights under the California Consumer Privacy Act, we will not:
- Deny the consumer goods or services
- Charge the consumer different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties
- Provide the consumer a different level or quality of goods or services
- Suggest that the consumer may receive a different price or rate for goods or services or a different level or quality of goods or services
9.10 Additional State Privacy Rights
If you are a resident of Virginia, Colorado, Connecticut, Utah, Montana, Texas, Oregon, Delaware, Iowa, Indiana, Maryland, Minnesota, Nebraska, New Hampshire, New Jersey, Rhode Island, or Tennessee, you have additional rights under your state's privacy law, including:
- Right to confirm whether we process your personal data
- Right to access your personal data
- Right to correct inaccuracies in your personal data
- Right to delete your personal data
- Right to obtain a copy of your data in a portable format
- Right to opt out of targeted advertising (we do not serve advertisements or conduct targeted advertising, so there is nothing to opt out of; if that changes we will provide a clear opt-out mechanism)
9.11 How to Submit Consumer Requests
You may submit privacy rights requests through any of the following methods:
10. Data Breach Notification
In the event of a data breach that affects your personal information, we will notify affected users and relevant regulatory authorities in accordance with applicable law. We will provide information about the nature of the breach, the types of data involved, and steps we are taking to address the incident.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the app or by email. The "Last Updated" date at the top indicates when changes were last made.
Facebark™ is a trademark of Facebark, Inc. © 2026 Facebark, Inc. All rights reserved.