Tailumi Privacy Policy

Version 2026-09-20.

Controller and contact

Sower IT; tax ID (NIP) 5242732198, REGON 383552530. For privacy, support and complaints contact kontakt@sowerit.pl or +48 690 753 842. Include “Tailumi” in the subject.

On your device

Your companion’s name, personal appearance, photos, notes and album remain on your device. Local counters are a display cache; the server confirms rewards, level and item ownership. Basic care works offline without an account. Your album is not published. The optional .tailumi export contains your household, models and photos; you choose its storage and recipients. Device and user-made backups also follow the settings of your operating system and chosen storage provider.

An optional caregiver name personalizes local greetings. It stays with the companion on your device and in backups you choose to export. You can leave it blank or remove it at any time; it is not sent for AI analysis.

Garden stories and dreams use prepared text and game events. The server records care, training, discoveries, quiet sessions and returns needed to calculate rewards and compose stories. We keep up to 60 recent stories and 180 events. Progress requests do not include your caregiver name, photos or personal notes. Sharing a card requires your action.

Account and online progress

A progress account is created when you first connect to the service. No email address or purchase is required. The server stores account and companion identifiers, selected breed and mode, the time zone set at registration, game state, experience, leaves, collections, action times and operation receipts. Training sends hits and their timing within a provided round so the server can calculate the result. These records support saving, recovery and protection against edited counters; they are not sent to AI. The server retains a hash of the recovery secret. Keep your recovery file private, like a password.

Rewards and collection changes require a connection; your companion, basic care and photos remain available offline. A .tailumi backup is not proof of level, balance or ownership. Import reads current progress from the appropriate account and does not restore spent leaves. If that account has no matching save, you can keep personal media and begin new progress.

Widgets, reminders and shared media

If you add a home-screen widget, the app gives the operating system a local companion portrait, name, a need indicator and a short phrase. This does not publish your album or send its contents to our server. Optional local reminders are offered after your first bond gift, require your choice and permission, and are limited to two per day. You can turn them off in the app or system settings. Garden recordings capture the app canvas without microphone or camera access. Saving a photo or video to the gallery requires permission to add media. Sharing opens the system sheet; you choose the recipient, whose service then applies its own privacy rules.

The photo/model comparison card and short clip are created locally. The image is redrawn on a canvas without EXIF metadata. Cancellation, errors and saving to the gallery remove temporary files immediately; after successful sharing, cache may remain until cleanup after 7 days so the chosen app can finish reading it. Copies delivered to recipients are outside Tailumi's control.

Optional AI personalization

Only when you request personalization do we send selected dog or cat photos to the Tailumi server and AI providers OpenAI and Meshy. OpenAI analyses appearance and helps choose a silhouette. Meshy receives selected photos and a static copy of the 3D model to match the coat. When an additional result check is needed, OpenAI compares your photos with rendered model previews. Use animal photos without people, documents or other information that could identify a person. Before sending images to providers, the server removes metadata including EXIF location. AI is not used to identify people.

Source photos are removed from the Tailumi server after processing, cancellation or deletion. A retention task removes remaining inputs after 24 hours, subject to its cleanup interval and ongoing processing. Temporary beta job results are deleted after downloading the preview, or after at most 30 days. Paid previews and accepted models remain linked to your purchase account so you can download them again; deleting that account removes them. Your downloaded on-device model remains until you delete it.

You can report an inappropriate AI result from its preview. We store your chosen category, optional comment, job reference and a hashed account/session reference for investigation and abuse prevention. Reports do not include a copy of your photos or recovery secret. Access is restricted to the operator; reports expire after 90 days.

OpenAI processes photos, descriptions and, when needed, model previews to perform the service. API data is not used for model training by default. We use store=false; this does not mean zero provider retention. Standard abuse-monitoring logs may include content for up to 30 days, with separate rules for exceptional security cases. We do not claim to have Zero Data Retention enabled.

Meshy processes submitted materials under its service terms. For non-Enterprise customers, those terms allow inputs and outputs to be used for training and service improvement unless otherwise agreed. We do not claim such an exclusion for Tailumi. Meshy says it does not currently train on uploaded images, but reserves the possibility of future use. Meshy terms and data and training information.

Meshy documentation states that models generated through its standard API are deleted after 3 days. This is not a promise to delete all submitted photos, logs or other provider data within that period; their retention is described in Meshy’s privacy policy. Tailumi server deletion periods do not replace provider policies. API model retention, Meshy privacy policy.

Steps and movement

Step counting requires your separate choice and system permission. We read counts for selected time intervals and attribute them to your chosen companion. Detailed reading history stays on your device. The progress server receives the step count since the beginning of a confirmed interval and stores totals and reward thresholds. Importing old step history does not grant rewards again. We do not read GPS routes, heart rate or medical records and do not send your step history to OpenAI, Meshy or the club leaderboard. You can disable counting in the app and revoke permission in system settings.

Club and purchases

The optional club stores your chosen alias, session identifier, trial results, rewards and information needed to prevent abuse. Other participants see your alias, rank and score, not source photos or access codes. You can request deletion through the app. Minimal anonymous reward and limit records may remain to prevent awarding the same reward repeatedly.

Club reports store the reported nickname, category, profile and reporting-session references, date and moderation decision. They are visible only to the operator and are removed during cleanup after 90 days. Your blocked-player list is private and stored with your club session until you unblock a player or delete the session. Club suspension records prevent further publication from that session. These controls do not publish your reports or change your pet progress or purchases.

The demonstration shop does not charge money or create purchases. When store purchases are enabled, Apple App Store or Google Play handles payment under its own terms. Tailumi does not receive card numbers. We process purchase-account identifiers, device tokens, verified transaction identifiers, products, refund status and entitlement balances to deliver and recover purchases. Keep the recovery secret private; the server retains a hash. An edited local save is not proof of a purchase.

Purposes and legal bases

Providing requested services, AI personalization, purchases and support relies on Article 6(1)(b) GDPR. Required tax and consumer records rely on Article 6(1)(c). Proportionate security, abuse prevention and legal claims rely on Article 6(1)(f). Optional system permission is not blanket consent for unrelated processing. Supplying data is voluntary, but personalization requires photos and delivering a purchase requires transaction information.

Local data stays until you delete it or clear application data. Active progress and purchase-account records remain while the service is provided. After a deletion request we retain only records required by law or necessary for transaction settlement, fraud prevention and claims for the applicable statutory periods. Support correspondence remains for handling the issue and necessary claims periods. Photo/job retention is described above. Deleted data may temporarily remain in encrypted disaster-recovery backups under a standard 30-day retention policy and a nightly cleanup cycle. These backups are not used for ongoing processing; before restoring the service, the operator must reconcile deletion records to honor subsequent deletion requests. Copies you create elsewhere are not automatically removed by the app.

Recipients and transfers

Necessary hosting, email and security providers may process service data. OpenAI and Meshy process personalization inputs; Apple and Google process store and system features. We do not sell data or use advertising trackers. OpenAI and platform providers may process data outside the EEA under applicable contracts and GDPR Chapter V safeguards, including adequacy decisions or standard contractual clauses. Meshy states that data is stored in the US and describes transfer safeguards in its privacy policy. Contact us for information about particular recipients and safeguards.

Invitations and weekend visits

When you choose to enter an invitation code, the server records the account relationship needed for qualification, joining time, fulfilment of the conditions and rewards. The inviter sees counts only, without the friend's name, photos, progress or account identifier. We do not access contacts or fingerprint devices. After deleting the relationship, we keep only an irreversible hash of the already used invitee account, without the code or inviter, to prevent awarding the invitation again. Simplified care days used for qualification are retained for up to 90 days; reward receipts and weekend mementos remain with the account until deletion. Processing provides the chosen programme and protects its accounting.

Optional usage measurement

At the end of the first steps we ask once about optional usage measurement; the same choice is available in Settings. Counts help us understand onboarding, completed days, started and completed generations, accepted models, verified purchases, sharing and returns. Measurement is off by default. It relies on your consent (GDPR Article 6(1)(a)), independently of purchases, invitations and gameplay. Declining limits no features and requires no account. Consent requires no purchase: where needed, we use the existing free progress-account mechanism. The question is not shown in memory mode. We do not reconstruct history from before consent.

The server counts generation starts and results and completed days only after confirming the operation and checking the installation's active consent. Purchase measurement reads only existing verified transactions from the last 30 days, after consent covering this measurement was given. The report contains totals of transactions, units and refunds by product, without account or transaction identifiers. Retrying verification or restoring a recorded transaction does not add another purchase. The date means first verification by Tailumi, which may differ from when payment was made in the store. We create no additional purchase history on the device and do not change accounting records. Earlier consent that did not cover purchase measurement retains its scope; it is extended only after you deliberately enable the option again. Withdrawal or account deletion excludes related transactions from this report without deleting required accounting records. With multiple installations, an account may remain included on the basis of consent on another installation.

Our own Tailumi server receives a random installation identifier, event name, time and app version. The installation is linked to the technical account to enforce consent and deletion; these are pseudonymous data, not a claim of complete anonymity. Events contain no photos, names, notes, location or advertising identifier and are not sent to OpenAI or Meshy. Raw events are aggregated after 30 days; only totals by day and event remain. Inactive identifiers are deleted after 90 days. The local queue holds at most 100 events and expires after 7 days. The server cleanup cycle may add approximately one minute.

Disabling measurement immediately stops recording on the device and clears its queue. The server deletes the installation identifier and raw events when consent withdrawal arrives; an offline request waits for connection. Withdrawal does not affect the lawfulness of earlier processing. Aggregated counts without installation links cannot identify an individual's contribution. Account deletion also deletes linked raw events. Necessary progress, transaction, limit and security records operate separately.

Ready companion notification

When available, following your choice and system permission, we store an Apple Push token, language and device/account link to send notification of a completed generation. The message contains no photo or companion name. The token serves only this notification. Disabling, revoking the device or deleting the account removes its registration; inactive tokens expire after 90 days. Ready receipts are retained for up to 30 days and delivery queue entries for up to 24 hours. Closing the customizer alone does not cancel a started generation. Your computer does not have to stay on.

Your rights and deletion

Subject to GDPR, you may request access, a copy, correction, deletion, restriction, portability and objection to legitimate-interest processing. You may complain to the Polish supervisory authority (UODO) or your competent authority.

Settings → Delete data and start again removes the local household, models and albums and attempts to delete the current club session on the server. Server deletion requires a connection; check the completion message. Settings → Account and saved progress → Account data and deletion lets you export account data and permanently delete progress, the account and its server models, including when purchases are unavailable. A minimal anonymous hash linking a deleted club session remains to prevent granting its rewards again to another account. This ends access to purchased entitlements and does not automatically refund payments. To request deletion or help with inaccessible data without the app, email kontakt@sowerit.pl with “Tailumi account deletion” in the subject. We may request proportionate ownership evidence, never your card number or recovery secret. Deletion does not remove legally required Apple/Google transaction records or copies you keep elsewhere.

AI does not make decisions with legal or similarly significant effects about you. It produces a stylized animal appearance.

OpenAI API data controls, OpenAI DPA, Apple privacy, Google privacy, GDPR, UODO.