PETLoves Open web app

PETLoves Data Safety and App Privacy Summary

PETLoves data handling and permissions for Google Play Data Safety and Apple App Privacy.

Text revision: 2026-09-08

This document supports Google Play Data Safety, Apple App Privacy, store review notes and PETLoves privacy operations. It must remain aligned with docs/privacy-data-map.md, src/config/privacyDataSafety.ts, src/config/dataRetention.ts, app.json, the public Privacy Policy and the production services enabled for the submitted build.

Release model

The current PETLoves release is privacy-first and production-connected where the user enables account, live sync, publishing, reviews, media upload, support or moderation flows. Drafts, reminders, device preferences and temporary offline state remain limited to the device until PETLoves can confirm the live service action.

Backend account sync, database storage, media storage, support, moderation, privacy-first analytics and crash diagnostics may be active in the submitted build. Payments, paid sponsor campaigns, address-book import, third-party advertising identifiers and cross-app tracking remain disabled unless explicitly enabled in the release notes, store questionnaires and privacy copy.

Google Play Data Safety answers

Technical inputs for reviewing the production-connected build, not final console selections:

Apple App Privacy answers

Categories to review against the actual candidate and partner practices; linkage, purposes and required/optional collection remain separate decisions:

Permission declarations

User content and moderation

PETLoves includes user-generated content. Store review should be told that the app provides content reporting, deletion of own content where applicable, Trust & Safety guidance, moderation queues, block/limit controls, audit log, SLA tracking, appeals, reporter PII redaction and support contact. Public community launch requires operational moderation, reviewer ownership and escalation paths.

Retention and deletion

Device-only drafts and preferences remain until the user edits them, deletes them, resets app data or uninstalls the app. The register in src/config/dataRetention.ts identifies server-backed records and unresolved retention decisions; a configured default or manual-review entry does not prove executed expiry. Account deletion, media cleanup, independent support/email archives and backups must be reviewed separately. Production sync and moderation must not claim success when completion cannot be confirmed. The new source adds consent-history export, not a complete export of every cloud record.

Store review notes

Reviewer-facing notes should state:

Review references: Apple App Privacy definitions and Google Data Safety guidance. The PETLoves-specific source findings are in docs/store-privacy-source-review-20260907.md; technical consistency does not approve the console declarations.

Back to PETLoves