Privacy Policy

Last Updated: October 8, 2026 v2.6

1. Introduction

Welcome to Felinius ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App").

Felinius is a personal cat-companion app. It helps you keep profiles, health and care records, and check-ins for your cats, gives you a shared in-app mascot, and includes an optional community where cat owners can share milestones and discover each other's cats.

A guiding principle of Felinius is that most processing happens on your device. Photo editing, receipt text recognition, audio analysis, and the companion's generated speech all run locally and are not sent to any server. See On-Device Processing.

Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the App.

Contact Email: myfelinius@gmail.com

2. Information We Collect

A. Account Information

You sign in with your Google account (Google Sign-In) or your Apple account (Sign in with Apple). Felinius does not use passwords and never sees or stores your Google or Apple password — authentication is handled by Google or Apple and Firebase Authentication. If you use Sign in with Apple, you may choose Apple's private email relay, in which case we only receive that relay address.

Data Purpose
Email address (from Google or Apple sign-in) Account identification and support
Display name (from Google or Apple sign-in, or a username you choose — changeable once) Profile identification
User ID (Firebase Authentication UID) Linking your data to your account

B. Cat Profile Data

Data Purpose
Cat name, breed Pet profile management
Birth date, weight Pet records and care tracking
Cat profile photos Visual pet identification

C. Health & Care Records

Data Purpose
Care reminders you schedule (cat name, reminder type, due time, and any note you write) Stored on our servers so we can send the reminder to your device at the right time, including when the App is closed
Veterinary visits (dates, notes, linked cats) Medical record keeping
Bills & receipts (vendor, line items, amounts, categories, totals, paid dates) Expense tracking for your cats' care
Receipt images (optional) Record keeping; text is recognized on-device (see Section 3)
Clinic details you enter (name, registration number, phone, email, address, notes) Your own care management; entered manually by you

Note: Clinic phone, email, and address are details you type in for your own reference. Felinius does not use your device’s location services (GPS), and the App does not have a location-based clinic finder. Google Analytics estimates an approximate location, such as your city or country, from your IP address — see Third-Party Services.

D. Check-In Data

You can record a short "check-in" of your cat as a portrait photo or a short video. Audio from check-in videos is analyzed on your device to estimate loudness and to recognize cat-related sounds (for example, meow or purr). The raw video and raw audio are not uploaded.

Data Purpose
Check-in thumbnail image Visual record of the check-in
Derived audio signals (loudness average/peak, detected sound labels, activity level) Lightweight check-in summary
Note, date/time Your own record keeping

E. Community & Social Data

If you use the optional community feed, certain limited information becomes visible to other Felinius users. See Section 9 for details.

Data Purpose
Public cat profile (cat name, breed, and your cat's profile photo) Letting other users discover and "collect" your cats
Milestone / activity posts (post type, your cat's name, server-generated text) Sharing progress in the public feed
"Loves," collected cats, and "pokes" Light social interactions between users

F. Device & Technical Information

Data Purpose
Push notification token (Firebase Cloud Messaging) Delivering push notifications (e.g., new community posts, pokes)
Device platform (iOS or Android) App compatibility
IP address and request metadata (standard server logs) Security, abuse prevention, and reliability
Usage events (which screen you opened, which feature you used, and counts such as how many cats you have) — no names, amounts, photos or record contents Understanding which parts of the App are used, so we know what to improve. Off until you accept the Terms, and you can switch it off at any time
Crash and error reports (device model, OS version, App version, the type of error and where in the code it happened, and your account ID) Diagnosing crashes and silent failures. Off until you accept the Terms, and you can switch it off at any time
App performance traces (Android only): start-up time and network request timing Finding slow screens and slow requests

G. Feedback You Send

If you choose to send feedback from within the App, we collect the feedback content you provide so we can read and act on it. This includes the optional in-app survey: the ratings you select and any free-text note you add. Feedback and survey answers are delivered to the developer by email, and may also be mirrored to a private issue tracker — see Third-Party Services. Feedback is not published to the community and is not shown to other users. Please avoid including sensitive personal information in free-text feedback.

H. Direct Messages

In the Town square you can send private messages to neighbours you already know there: people who have replied to or loved your lanterns and posts, or whose lanterns and posts you have replied to. Both of you must have joined the Town. When you use Messages, we collect and store on our servers:

  • The text of the messages you send, and the quick-hello greetings you pick
  • Who sent each message, who received it, and when
  • Whether you have read, archived or deleted a conversation on your side
  • Reports you file about a message or conversation

Replies and loves that you and a neighbour gave each other's lanterns and posts also appear inside your conversation with that neighbour. Messages are private between the two of you and are never shown in the community feed. They are encrypted in transit and at rest, but they are not end-to-end encrypted: they are stored on our servers so they can be delivered to you on any device, screened automatically before they are sent, and reviewed if someone reports them.

What we do NOT collect: We do not collect your device location, we do not use advertising identifiers, and we do not serve ads. Felinius has no in-app purchases or billing. We do use Firebase Analytics, Crashlytics and (on Android) Performance Monitoring — see Third-Party Services — but they carry only the usage, crash and performance information described in the table above: never a cat name, a clinic or vendor name, an amount, a receipt, a photo, a health record or the text you write. Analytics never receives your account ID. This collection is switched off until you accept the Terms, and you can switch it off at any time in the App under Account → Privacy → Usage and crash data.


3. On-Device Processing

Several features rely on machine-learning models that run entirely on your device. The inputs and outputs of this processing stay on your device unless you choose to save a result that is then synced as part of your records.

Feature Technology What stays on-device
Receipt text recognition (OCR) Google ML Kit Text Recognition The receipt image is read locally; only the text you keep is saved. No image is sent to a server for OCR.
Cat photo background removal Google ML Kit Subject Segmentation Photo editing happens locally on your device.
Check-in audio analysis On-device audio classification (YAMNet) Audio is analyzed locally; only derived signals (not raw audio) are saved.
Companion mascot speech On-device generative model (Gemma via MediaPipe) and your device's text-to-speech Optional. The model is downloaded by you and runs locally; prompts and responses are not sent to a server.

4. How We Use Your Information

We use the information we collect to:

  • Provide Account Services: Authenticate you via Google Sign-In or Sign in with Apple and associate your data with your account
  • Store and Sync Your Data: Back up and sync your cat profiles, health and care records, and check-ins across your devices
  • Power the mascot: Provide the in-app mascot (drawn on-device)
  • Enable Community Features: Let you optionally share milestones and discover, "collect," and "poke" other users' cats
  • Send Notifications: Deliver push notifications such as new community posts or pokes (you can disable notifications at any time)
  • Maintain Security: Detect and prevent fraud, abuse, and security incidents
  • Provide Support & Improve: Respond to feedback and fix issues you report

5. Third-Party Services

We use the following third-party services to operate the App:

Firebase (Google LLC)

Service Purpose Data Processed
Firebase Authentication Sign-in via your Google or Apple account Email, display name, user ID, authentication tokens
Firebase Cloud Messaging Push notifications Device push token, notification payloads
Google Analytics for Firebase Understanding which screens and features are used Usage events with non-identifying values only (screen names, feature names, counts, yes/no flags), an app-instance identifier generated on your device, and on iOS the vendor identifier (IDFV). Not linked to your account: your account ID is never sent to Analytics. Analytics also estimates an approximate location, such as your city or country, from your IP address; Google Analytics does not store the IP address itself. Off until you accept the Terms; switch off any time under Account → Privacy → Usage and crash data
Firebase Crashlytics Crash and error reporting Device model, OS and App version, the exception type and the code location it came from, and your account ID so a report can be matched to a support request. For the errors the App reports itself, the error's own message text is stripped before sending; a crash that ends the App is captured by the crash reporter directly and carries the system's error description as well. Same on/off control as Analytics
Firebase Performance Monitoring (Android only) Finding slow start-ups and slow network requests App start-up and screen-render timings, and request timing and size per endpoint. Not present in the iOS app. Same on/off control as Analytics

For more information, see Google's Privacy Policy.

Google Cloud Platform

Our backend runs on Google Cloud (Cloud Run, Cloud Firestore, and Cloud Storage). Your synced records and uploaded images (cat photos, receipt images, and check-in thumbnails) are stored here. All data transmitted between the App and our servers is encrypted in transit using HTTPS/TLS.

For more information, see Google Cloud Privacy Notice.

Google Cloud Vision (photo screening)

When you publish a photo to the Town square or to a photo event, that image is sent to the Google Cloud Vision API for automated safety screening before it appears to anyone. The check looks only for adult, violent, racy or medical content and returns a likelihood rating; no person or cat is identified, no face is recognised, and the result is used solely to accept or reject the post. This screening applies only to photos you choose to publish — it is never run on your cat profile photos, receipt images, or check-in photos and videos.

For more information, see Google Cloud Privacy Notice.

Google Play Services (on-device ML)

On-device machine-learning features use Google ML Kit, which is provided through Google Play Services. This processing happens on your device; see On-Device Processing.

Email delivery of feedback

Feedback and in-app survey answers are relayed to the developer's mailbox over an encrypted SMTP connection so they can be read and acted on. Only the content you wrote, plus the type of feedback, is sent; your email address is not included unless you type it into the message yourself.

GitHub (Issue Tracker)

When you send qualitative feedback (such as a feature wish or a bug report) from within the App, that feedback may be mirrored to a private issue tracker hosted on GitHub so we can review and act on it. Please avoid including sensitive personal information in free-text feedback. For more information, see GitHub's Privacy Statement.


6. Data Storage & Security

We implement appropriate technical and organizational measures to protect your personal information:

  • Encryption in Transit: All data transmitted between the App and our servers uses HTTPS/TLS encryption
  • Encryption at Rest: Data stored in Google Cloud Firestore and Cloud Storage is encrypted at rest by the platform
  • Secure Authentication: API requests are authenticated with short-lived Firebase ID tokens (bearer tokens)
  • Access Controls: Your synced data is associated with your authenticated account
  • Offline Storage: Your records are cached locally on your device for offline access and synced securely when connectivity is restored

Data Storage Location

Your synced data and uploaded images are processed and stored on Google Cloud servers located in:

  • Singapore (Google Cloud Platform — asia-southeast1 region)

7. Data Retention

We retain your information for as long as necessary to provide our services and fulfill the purposes described in this policy:

Data Type Retention Period
Account data Until you delete your account
Cat profiles, health & care records, check-ins Until you delete them or your account
Uploaded images (cat photos, receipts, check-in thumbnails) Until you delete the related record or your account
Community posts and interactions Until removed or your account is deleted
Push notification token Until you sign out, disable notifications, or the token is invalidated
Direct messages Until either person in the conversation deletes their account, which deletes the whole conversation for both of you. If you unsend a message, its text is deleted at once; a record that a message was sent, without its text, is kept only to enforce sending limits. Deleting a conversation removes it from your view only — the other person keeps their copy
A message you sent that another user reported Kept for up to 90 days from the report for safety review, then deleted, even if you delete your account in the meantime. Only the reported message is kept, never the rest of the conversation
Feedback Retained while we review and act on it
Usage events (Google Analytics for Firebase) Deleted automatically 14 months after collection. Because these events are keyed to an app-instance identifier and never to your account, they cannot be looked up by account — deleting your account resets that identifier and unlinks everything recorded before it
Crash reports (Firebase Crashlytics) Retained by Firebase for up to 90 days
Performance traces (Android only) Retained by Firebase for up to 90 days

When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal or legitimate business purposes. Residual copies in encrypted backups are purged within 90 days. If another user reported a message you sent, that message is kept for up to 90 days from the report for safety review and then deleted.


8. Data Sharing & Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

  • Service Providers: With infrastructure providers (Google Cloud, Firebase) who host and process data on our behalf, Google Cloud Vision for screening photos you publish, our email provider for delivering feedback and survey answers, and GitHub for feedback you submit
  • Other Users (Community): Limited information you choose to share via community features is visible to other users (see Section 9)
  • Legal Requirements: When required by law, court order, or governmental authority
  • Safety & Security: To protect the safety, rights, or property of Felinius, our users, or the public
  • Business Transfers: In connection with a merger, acquisition, or sale of assets (you will be notified of any such change)

9. Community Features & Public Data

Felinius includes an optional community feed. When you participate, the following information may be visible to other Felinius users:

  • Public cat profile: your cat's name, breed, and your cat's profile photo, so others can discover and "collect" your cats
  • Milestone / activity posts: the post type, your cat's name, and a short description. The wording of these posts is generated by our server from a fixed set of messages — the App does not publish free-text you write about your cats, bills, or health into these posts
  • Photo posts you choose to make: in the Town square and in photo events, you may publish a photo together with a short caption you write yourself. These are the only places the App publishes your own words. Captions and images are screened automatically before they appear, are subject to daily limits, may be hidden after multiple reports, and can be deleted by you at any time
  • Social interactions: "loves," collected cats, and "pokes" between users
  • Direct messages: private conversations with neighbours you already know in the Town square. Only the two people in a conversation can see it. Your name and your messages are visible to the other person, never to the rest of the community. You can archive a conversation, delete it from your side, unsend your own messages, report a message, and block a person. Blocking stops both of you from sending messages; it does not tell the other person

Information that is not shared in the community feed includes your email address, your cats' health and care records, vet visits, bills and receipt images, weight log, food diary, medications, and check-in photos, videos and notes. Cat profile photos are shared only as described above, and only for cats you have chosen to make discoverable; you can change which cats are discoverable, or leave the community entirely, at any time in the App's privacy settings.


10. Data Breach Notification

In the unlikely event of a data breach that affects your personal information, we will:

  • Assess the Impact: Promptly investigate and assess the nature and scope of the breach
  • Notify Authorities: Report to relevant supervisory authorities within 72 hours where required by law (e.g., GDPR)
  • Notify Affected Users: Inform you without undue delay if the breach is likely to result in a high risk to your rights and freedoms
  • Remediate: Take immediate steps to contain the breach and prevent future occurrences

Notification will include:

  • Description of the nature of the breach
  • Categories and approximate number of individuals affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

11. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you. The in-app companion generates playful text on your device and does not make decisions about you. We do not build advertising or behavioral profiles. Captions, photos and direct messages are screened automatically before they are published or sent; a caption or message that fails the check is not posted or sent, and you can simply rewrite it. This screening does not affect your account.


12. Your Rights & Choices

Depending on your location, you may have the following rights regarding your personal information:

Right How to Exercise
Access View your data in the App, or contact us
Correction Edit your cats and records directly in the App
Deletion Delete records in the App, or request account deletion (see below)
Your Messages In Messages, unsend your own messages, delete a conversation from your side, archive it, report a message, or block a person. Deleting your account deletes all your conversations
Data Portability Request a copy of your data by contacting us
Withdraw Consent Revoke permissions (camera, microphone, notifications) in device settings
Opt Out of Usage and Crash Data In the App, open Account → Privacy and switch off Usage and crash data. This stops usage events, crash reports and performance traces at once, on that device. It is also off by default until you accept the Terms

Managing Permissions

  • Camera: Manage in your device's Settings > Apps > Felinius > Permissions
  • Microphone: Used only for check-in videos; manage in Settings > Apps > Felinius > Permissions
  • Notifications: Manage in Settings > Apps > Felinius > Notifications

Account Deletion

To delete your account and associated data:

  1. Use the in-app account deletion option in Settings, where available; or
  2. Follow the instructions on our Account & Data Deletion page; or
  3. Email us at myfelinius@gmail.com from, or referencing, the Google or Apple account you use to sign in

Your account and all associated data will be deleted within 30 days of a verified request, as described in Data Retention.


13. Children's Privacy

The App is not intended for children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under 13.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at myfelinius@gmail.com. If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to delete that information promptly.


14. International Data Transfers

Felinius is operated from Malaysia. Your personal data may be transferred to, stored, and processed in:

  • Singapore (Google Cloud Platform — asia-southeast1 region) for backend services and storage
  • Other jurisdictions where our third-party service providers (such as Google and GitHub) operate

Cross-Border Transfer Safeguards

We ensure appropriate safeguards are in place for international data transfers:

Jurisdiction Safeguard Mechanism
Malaysia → Singapore / other Transfer Impact Assessment (TIA) per PDPA Guidelines
EU/EEA → non-EEA Standard Contractual Clauses (SCCs)
General Contractual obligations with service providers

For transfers from Malaysia, we comply with the Guidelines on Cross Border Personal Data Transfer issued by the Personal Data Protection Commissioner.


15. Regional Privacy Rights

This section outlines your specific rights based on your location. We are committed to complying with applicable data protection laws in each jurisdiction where we operate.

For Malaysia Residents (Primary Jurisdiction)

Your personal data is protected under the Personal Data Protection Act 2010 (PDPA), as amended by the Personal Data Protection (Amendment) Act 2024.

Regulatory Authority: Personal Data Protection Department (JPDP)

Your Rights Under PDPA

Right Description
Access Request access to your personal data held by us
Correction Request correction of inaccurate or incomplete data
Withdrawal of Consent Withdraw consent for data processing at any time
Data Portability Request transfer of your data to another service provider (effective June 2025)
Complaint Lodge a complaint with JPDP if you believe your rights have been violated

7 PDPA Data Protection Principles

We adhere to the seven principles under PDPA:

  1. General Principle - Personal data shall not be processed without consent
  2. Notice and Choice Principle - Data subjects must be informed of data processing purposes
  3. Disclosure Principle - Personal data shall not be disclosed without consent
  4. Security Principle - Practical steps to protect personal data from loss/misuse
  5. Retention Principle - Personal data shall not be kept longer than necessary
  6. Data Integrity Principle - Personal data shall be accurate, complete, and up-to-date
  7. Access Principle - Data subjects have the right to access and correct their data

Legal Basis for Processing

Purpose Legal Basis
Account management Consent & Contract performance
Cat, health & care records Consent & Contract performance
Community features Consent
Security monitoring Legitimate interest

Data Breach Notification

In compliance with the PDPA Data Breach Notification requirements (effective June 2025):

  • We will notify the JPDP Commissioner within 72 hours of becoming aware of a qualifying breach
  • We will notify affected individuals within 7 days if the breach is likely to cause significant harm
  • Significant harm includes: physical harm risk, financial loss, exposure of sensitive data, or breach affecting 1,000+ individuals

Contact for Malaysian Data Subjects

To exercise your PDPA rights, contact us at myfelinius@gmail.com with subject line: "PDPA Data Request"

Jabatan Perlindungan Data Peribadi (JPDP)
Website: https://www.pdp.gov.my
Email: aduan@pdp.gov.my


For European Economic Area (EEA) Residents

Under the General Data Protection Regulation (GDPR), you have additional rights including:

  • Right to access, rectify, or erase your personal data
  • Right to restrict or object to processing
  • Right to data portability
  • Right not to be subject to automated decision-making
  • Right to lodge a complaint with a supervisory authority

Legal Basis for Processing:

  • Contract performance (account, cat, and care-record features)
  • Legitimate interests (security and app reliability)
  • Consent (community features, push notifications)

Data Protection Contact: myfelinius@gmail.com (Subject: "GDPR Data Request")


For California Residents (USA)

Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), you have the right to:

  • Know what personal information we collect and how it's used
  • Request deletion of your personal information
  • Opt-out of the sale of personal information (we do not sell your data)
  • Limit use of sensitive personal information
  • Non-discrimination for exercising your privacy rights

To exercise these rights, contact us at myfelinius@gmail.com with subject line: "CCPA Request"

You may also designate an authorized agent to make requests on your behalf.


For Other Jurisdictions

If you are located in a jurisdiction not specifically listed above, we will comply with applicable local data protection laws. Please contact us at myfelinius@gmail.com to inquire about your specific rights.


16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy at this URL
  • Updating the "Last Updated" date at the top of this policy
  • Where appropriate, notifying you through the App

Your continued use of the App after any changes indicates your acceptance of the updated Privacy Policy.


17. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

Data Protection Inquiries:
For data-protection requests, please include "Data Protection Request" in the subject line.

Response Time: We will respond to your inquiry within 30 days. For EU/EEA residents exercising GDPR rights, we will respond within 30 days as required by law, with a possible extension to 60 days for complex requests (with notification).


18. Summary of Data Collection

Category Data Collected Purpose Legal Basis
Account Email, display name, user ID (Google or Apple sign-in) Authentication Contract
Cat Profiles Name, breed, birth date, weight, photos Pet management Contract
Health & Care Vet visits, bills/receipts, clinic details Care & expense tracking Contract
Check-ins Thumbnail, derived audio signals, notes Activity records Contract
Community Public cat name, breed and profile photo; milestone posts; photo posts with your captions; interactions Optional social features Consent
Direct Messages Messages you send, who sent and received them and when, read/archive/delete state, reports you file Private conversations between neighbours; safety review of reported messages Contract (you choose to send them) / Legitimate interest (safety review)
Device Push token, platform, IP address Notifications, security Consent / Legitimate interest
Feedback Feedback content you send Support & improvement Consent
Usage, Crash & Performance Screen and feature usage events with non-identifying values, crash reports (with your account ID), Android performance traces Improving and fixing the App Consent (off until you accept the Terms; opt out any time in Account → Privacy)

19. Version History

Version Date Changes
2.6 October 8, 2026 Disclosed that Google Analytics estimates an approximate location (city or country) from your IP address, and clarified that the App does not use your device’s location services (GPS)
2.5 September 25, 2026 Added direct messages: what is collected when you message a neighbour in the Town square, who can see it, that messages are not end-to-end encrypted, automatic screening, how long they are kept, and your choices (unsend, delete for yourself, archive, report, block)
2.4 September 25, 2026 Added the retention period for reported messages: if another user reports a message you sent, that one message is kept for up to 90 days from the report for safety review and then deleted, including after account deletion
2.3 September 18, 2026 Disclosed Firebase Analytics, Crashlytics and (Android-only) Performance Monitoring, which the App now uses, and corrected the earlier statement that no analytics or crash-reporting SDK was used — that statement had become inaccurate for the Android build. Described exactly what those tools receive and what they never receive, recorded that collection stays off until the Terms are accepted, and documented the in-app opt-out at Account → Privacy → Usage and crash data, the retention windows, and the fact that usage events are keyed to an app-instance identifier rather than to your account
2.2 August 26, 2026 Corrected the description of community sharing: cat profile photos are visible to users who can discover your cats, and photo posts may carry a short caption you write yourself. Disclosed automated photo screening via Google Cloud Vision, server-side storage of care reminders you schedule, and email delivery of feedback and survey answers. Noted that a display name can be a username you choose. Removed references to a per-cat "species" field and to a per-user companion, neither of which the App still has
2.1 July 12, 2026 Added Sign in with Apple as a login option alongside Google Sign-In; made device-platform wording OS-neutral (iOS and Android)
2.0 June 5, 2026 Updated for the current app: Google Sign-In only, on-device ML (OCR, segmentation, companion, audio), community features, removal of location and third-party analytics, storage in Singapore region. Superseded by v2.3: analytics and crash reporting were reintroduced, and the "removal of third-party analytics" statement in this entry no longer describes the App
1.0 January 10, 2026 Initial publication

20. Governing Law & Jurisdiction

Primary Jurisdiction: Malaysia

This Privacy Policy and any disputes arising from it shall be governed by and construed in accordance with the laws of Malaysia, including the Personal Data Protection Act 2010 (PDPA) and its amendments.

Any legal action or proceeding arising under this Privacy Policy will be brought exclusively in the courts of Malaysia, and the parties hereby consent to personal jurisdiction and venue therein.

Regional Considerations

Your Location Applicable Law Dispute Resolution
Malaysia PDPA 2010 (as amended) Malaysian Courts
EU/EEA GDPR (in addition to PDPA) Your local supervisory authority
California, USA CCPA/CPRA (in addition to PDPA) Malaysian Courts or California Courts
Other Local laws + PDPA Malaysian Courts

Where local laws provide you with additional rights beyond those in this Privacy Policy, those rights will apply to you.