PUP is a personal health-tracking app. Everything in this document is written to be readable in one sitting. The short version: your logs are yours, we store the minimum needed to make the app work, and you can delete everything at any time.
What we collect
We try to keep this list short on purpose.
Account information
- Your email address and display name from Sign in with Google or, on iOS, Apple Sign In.
- A randomly generated user ID we use to associate logs with your account.
- Optional profile fields you set yourself: username and display name.
Log data
- The Bristol type (1โ7), duration bucket, and toilet type you enter.
- The date and time of each log.
- An optional location name ("Home", "SPBU Cimindi") and โ only if you tap "Get Location" โ the GPS coordinates of that log.
- Optional free-text notes you write.
Device information
- App version, operating system, and a device identifier used for push notifications.
- Crash logs (anonymised) so we can fix bugs.
Why we collect it
Each piece of data above maps to one of these purposes:
- Run the app. Logs need an owner; an owner needs an ID.
- Sync across devices. If you sign in on a tablet, your logs should follow you.
- Earn XP, achievements, and rank. Gamification needs to count things; the things are your logs.
- Send notifications you opted into. Like a streak milestone or an achievement unlock.
- Fix bugs. Crash logs are scrubbed of personal data before they reach us.
Where it's stored
Logs live in two places: on your device (in a local SQLite database, so the app works offline) and on our backend (PostgreSQL, hosted on Supabase in Singapore). The two stay in sync whenever you're online.
We use Cloudflare in front of the backend for caching and DDoS protection. RevenueCat handles subscription state for Pro users. Apple and Google handle authentication. Each of these is a data processor, not a buyer.
Who we share with
We do not sell your data. We do not share it with advertisers. We do not use it to train AI models.
We share only with the processors above, and only the minimum needed to do their job. We disclose data to authorities only when legally compelled and will tell you when we can.
Your rights
Wherever you live, you have the right to:
- Export your data as a PDF report from Profile โ Settings โ Export as PDF (Pro). Email us if you need raw JSON or CSV.
- Correct any log by editing it in the app, or any profile field by tapping your name on the Profile screen.
- Delete your account and all associated data. See Delete account for the exact steps.
- Withdraw consent for push notifications or optional analytics any time, from Profile โ Settings.
Analytics and monitoring
If analytics is enabled for your visit or app session, PUP uses Google Analytics 4 (GA4), including Firebase Analytics in the mobile app, to understand product usage and improve the service. Analytics is enabled by default where applicable. The mobile app includes an opt-out setting under Profile โ Settings; turning it off stops new product analytics events from being sent. Operational crash and error monitoring may continue so we can keep the service reliable.
Analytics may include event names, timestamps, app or website version, operating system, platform, locale, screen or CTA location, coarse subscription state, and an anonymous identifier. Before sign-in, the app may use an anonymous identifier; after sign-in, it may be associated with an opaque internal account ID. We do not send Bristol type, stool or other health details, notes or other free text, GPS or other precise location, email addresses, names, usernames, authentication credentials, purchase tokens, or full API request bodies to product analytics. Website campaign attribution is limited to approved UTM fields and does not include the full URL query string.
Raw analytics data may be retained indefinitely, subject to deletion requests and the deletion capabilities of the relevant provider. We use Google Analytics 4/Firebase Analytics for collection and reporting, with BigQuery as an analytics warehouse where configured. Account deletion resets or removes the associated analytics identity where supported; irreversible aggregate reports may continue to contain non-identifying totals.
Children's privacy
PUP is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child has signed up, write to us at contact@pup.my.id and we'll delete the account.
Changes & contact
When this policy changes in a material way, we'll notify you in the app at least 30 days before the change takes effect. Trivial copy edits (typos, clarifications) will be made silently with a bumped version number.
Questions about this policy?
contact@pup.my.id.
Want your data exported or deleted on your behalf? Same address โ we'll respond within 30 days.