Privacy Policy
Last updated: 30 July 2026
This privacy policy applies uniformly to the Barnaby app (iOS and Android) and the website barnaby.at. It explains in plain language what data Barnaby processes, for what purpose, on which legal basis — and what rights you have.
In short: Barnaby processes your data solely to provide the app. There is no advertising and no sharing of your data with advertisers or data brokers. To improve the product we use — only with your consent — privacy-minimising, EU-hosted analytics (PostHog), and on the website barnaby.at additionally Google Analytics 4; there are no advertising SDKs and no cross-app tracking.
1. Controller
The controller within the meaning of the GDPR is: Felix Klieber, Blumengasse 76, 1170 Vienna, Austria.
Contact for privacy requests: datenschutz@barnaby.at
2. What data we process (overview)
- Account and profile data: e-mail address, name, username, date of birth (for age verification), profile picture, bio, optionally city/district.
- Dog profiles: name, breed, date of birth, photos; optional health details (e.g. weight, allergies, microchip number, vet).
- Walks: GPS routes, duration, distance, pace, elevation gain, optional photos, weather details for the walk.
- Social activity: follower relationships, wuffs (likes), comments, reports, blocks.
- Direct messages: message text, sender/recipient, timestamps (feature currently not available, see section 12).
- Device and usage data: operating system and app version, device language and time zone, push token, crash reports.
- Website visit data: server log files (see section 16).
You will find the details for each category in the following sections.
3. Legal bases
- Performance of contract (Art. 6(1)(b) GDPR) for your account and the core features of the app — profile, feed, statistics and the GPS recording of your walks (section 6): recording your walks is the core service you request from us by using the app.
- Consent (Art. 6(1)(a) GDPR) for camera/photo access, optional profile and health details, product analytics (section 14) and the further cases expressly marked as consent. You can withdraw any consent at any time with effect for the future. Your operating system's permission dialogues (e.g. for location or push) are not consent within the meaning of the GDPR but a technical prerequisite about which we inform you in advance in the app.
- Legitimate interest (Art. 6(1)(f) GDPR) for push notifications (section 9), for stability, security and abuse prevention (e.g. crash reports, device integrity checks, technical account e-mails, website server logs, moderation and account suspensions) and for the weekly recap e-mail (section 10). You can object to processing on this basis at any time (Art. 21 GDPR, section 18).
4. Account, profile and visibility
To create an account you need an e-mail address and a password — or you sign in with Google Sign-In or Sign in with Apple. Registration also requires your date of birth; we use it for age verification (minimum age 16, section 22). When setting up your profile you additionally choose a name and a username; all other details (profile picture, bio, city, district) are optional. Passwords are stored exclusively as a hash (Firebase Authentication).
Important regarding visibility: other signed-in Barnaby users only see a public excerpt of your profile — your name, your username, your bio, your profile picture, and the number of your followers and of the accounts you follow; if your profile is public, also your goals and achievements (which you can turn off via the “Show goals/achievements publicly” setting). Not visible to others are your date of birth, city and district, your personal follower and following lists, your streak and personal records, as well as language and time zone — this data lives in an area readable only by you (and us as the operator). Because on Barnaby you follow the dog (not the person), a dog's follower list — and thus which dogs you follow — is visible to signed-in users. The additional “private” setting further protects your walks and posts so that only your followers can see them. Dog profiles (name, photo, breed, bio), by contrast, are always visible to signed-in users and cannot be set to private separately.
Device language and time zone are collected automatically from your device and stored so that notifications arrive in your language and at suitable times.
Your push token is kept in a private area that only you (and we as the operator) can access — never other users.
Legal basis: Art. 6(1)(b) GDPR (user agreement); optional details: Art. 6(1)(a) GDPR.
5. Dog profiles and shared dogs
Dog profiles (name, breed, date of birth, photo, bio) are visible to other users — regardless of your profile privacy setting.
Health details about your dog — weight and weight history, allergies, neutering status, microchip number, vet contact, medication plan including dosage, chronic diagnoses, vaccination and care appointments, dietary details, and cycle/heat data — are, by contrast, visible exclusively to you as the owner and are never shown publicly. We process them only to display them in the dog profile and for health tips in the app.
Shared dogs: you can share a dog profile with other owners via a secret join code or QR code. Anyone who has this code can join the dog profile immediately, without further approval — so only share it with people you trust. Shared owners then see the dog's basic data (name, breed, date of birth, photo, bio) and the associated walks — but not your dog's health details: these remain visible exclusively to you even when sharing (paragraph 2). Existing owners are notified of every join, and owners with an admin role can manage and remove members. Deleted shared dogs can be restored for 30 days and are permanently deleted afterwards.
Legal basis: Art. 6(1)(b) GDPR; optional health details: Art. 6(1)(a) GDPR.
6. GPS tracking, background recording and home zone protection
To record your walks, the app accesses your precise location — only if you have granted the operating system's location permission and start a walk. It records the GPS coordinates of the route with timestamps; from these the app calculates distance, duration, pace and elevation gain.
Recording only runs during a walk that you have actively started — but then also in the background (background location), so the route keeps being recorded while your phone is in your pocket. Outside an active walk the app does not record your location and does not transmit any route to our servers; your current position is merely shown locally on the map (for map display via Google Maps, see below).
Before the operating system asks for the location permission, the app explains in a dedicated notice what the location is needed for, where the data is stored and how to revoke the permission again. This notice serves transparency purposes (Art. 12, 13 GDPR) — it is not a consent prompt, and the operating system's permission dialogue is not consent within the meaning of the GDPR either. You can revoke the permission at any time in your device settings; the app remains usable without GPS tracking (e.g. for photo posts).
Home zone protection: if the home zone is enabled, your route is trimmed by default by roughly 50 metres at each end before publication to protect your home address; you can adjust the radius and the mode (both ends, start only or end only). The full route remains visible exclusively to you and is stored separately (for retention, see section 17).
Visibility: on Barnaby you follow the dog, not the person. Whether others can see your walks (including the trimmed route) depends on your profile privacy — with a public profile all signed-in users, with a private profile only the followers of your dogs that you have approved.
Further location flows: for the walk weather display, coordinates (rounded to about 4 decimal places) are sent to the weather service Open-Meteo (OpenMeteo GmbH, Switzerland); we only store the weather values, not the request coordinates. For the place search, your search text is sent to the OpenStreetMap service Nominatim. Maps are displayed via Google Maps; Google receives your IP address and the displayed map section.
Legal basis: Art. 6(1)(b) GDPR (performance of contract) — recording the walk you started is the core service of the app and cannot be provided without location data. The operating system's location permission is the technical prerequisite for this; without it, no recording takes place.
7. Feed, photos and social features
Your posts (walks and photo posts), comments, wuffs (likes) and follower relationships are visible to other users according to your visibility settings — the recipients of this data are therefore other Barnaby users.
Photos are downscaled and re-encoded before upload; embedded metadata such as the capture location is effectively removed in the process.
You can report content and users and block users. We store reports together with your reporter details (username, reason, optional free text) so we can review and follow up on them.
Moderation, account suspensions and bans: if an account violates our terms of use, we act in graduated steps — notice or warning, removing or restricting individual content, temporary suspension, permanent ban; the procedure, including the reasoning and the possibility to respond, is governed by the terms of use (there, §9). For this we process the trigger (e.g. a report), the decision taken with its reasoning and timing, and your account's suspension status, and we document this in an internal moderation log that only we as the operator can view. Such decisions are always made by a human; nothing is decided automatically here (section 20). Legal basis: Art. 6(1)(f) GDPR (protecting other users, enforcing the terms of use) as well as Art. 6(1)(c) GDPR to the extent statutory moderation obligations apply to us (Digital Services Act). For retention, see section 17.
Hiding posts: if you hide a post in your feed, we store the list of posts you have hidden in your private area, readable only by you (and us as the operator). It only affects your own feed view — the person whose post you hide is not notified. The list is included in your data export (section 18) and is deleted with your account.
Search history: search remembers the most recently opened profiles (up to 10 entries) exclusively on your local device; this history is never transmitted to our servers. You can delete it at any time directly within search.
Featuring your content on Barnaby channels (only with separate consent): occasionally we ask you in advance whether we may show one of your public posts (e.g. a dog photo together with the dog's name and your username as credit) on Barnaby's own channels — such as Instagram, Facebook, Reddit or our website. This only happens if you expressly agree to the specific request (via a notification in the app or a link in an e-mail); if you do not respond, nothing is published. Legal basis: your consent (Art. 6(1)(a), Art. 7 GDPR); we additionally observe the protection of one's own image (§ 78 UrhG, Austrian Copyright Act). On external platforms their own privacy policies additionally apply; posts published there are accessible worldwide, and the providers (e.g. Meta) may also transfer data to the USA. You can revoke your consent at any time with effect for the future (to datenschutz@barnaby.at or support@barnaby.at); we will then remove the post from our channels where technically possible. We document the request and your answer for evidence purposes (Art. 7(1) GDPR).
Legal basis: Art. 6(1)(b) GDPR; reporting and blocking features additionally Art. 6(1)(f) GDPR (security and abuse prevention).
8. Statistics, goals and achievements
From your walk data the app calculates statistics, streaks, goals and achievements. Your statistics and health tips are for you only. Your goals and achievements, however, follow your profile's visibility: with a public profile other signed-in users can see them, with a private profile only your confirmed followers or co-owners; achievements are additionally derived on the (always public) dog profile from the walks visible there. You can turn this off via the “Show goals/achievements publicly” setting. Health tips are simple, rule-based estimates and do not replace veterinary advice.
Care appointments in your phone calendar (optional): on request, the app mirrors your dog's planned care appointments into a dedicated “Barnaby” calendar on your device; for this it asks for the operating system's calendar permission. The synchronisation itself runs exclusively on your device — nothing is transmitted to our servers through it. The care appointments themselves, however, are part of the dog profile and are therefore held on our servers independently of the calendar sync (section 5). You can disable the synchronisation at any time in the health settings; doing so (and deleting your account) removes the Barnaby calendar from the device. Legal basis of the synchronisation: your consent (Art. 6(1)(a) GDPR).
Legal basis: Art. 6(1)(b) GDPR.
9. Push notifications
If you allow push notifications, we store a push token for your device in your private area. Delivery runs from our servers (Cloud Functions, EU) to the Expo Push Service (650 Industries, Inc., USA) and from there to Apple (APNs) or Google (FCM). The push token and the notification content (e.g. “X wuffs your walk”) are transmitted via Expo servers in the USA (see section 15).
To prevent notification spam we store counters and timestamps (bundling, daily cap, quiet hours based on your time zone).
You decide via the operating system permission whether you receive push notifications, and you can switch off each notification type individually in the app settings.
Legal basis: our legitimate interest in informing you about events relating to your account and your content (Art. 6(1)(f) GDPR). You only receive push notifications if you have granted your operating system's push permission; this permission dialogue is a technical prerequisite, not consent within the meaning of the GDPR. You can object to this processing at any time (Art. 21 GDPR) — most easily by revoking the push permission in your device settings or switching off individual notification types in the app settings; we will then no longer send push notifications to your device.
10. E-mails
Technical account e-mails (password reset, e-mail verification, e-mail address change) are sent encrypted (SMTP over TLS) via the e-mail service of the hosting server (Mittwald, Germany), which our maintenance agency netwerk Kreidl GmbH & Co KG operates for us. Delivery logs there are deleted after 28 days. Legal basis: Art. 6(1)(b) and (f) GDPR.
Weekly recap e-mail (not currently active): A weekly recap e-mail that summarises your activity (e.g. kilometres, walks, time, wuffs, streak) is prepared but is not sent at this time. Before activating it, we will update this privacy policy; the e-mail will then be switchable off in the app settings and every message will contain a one-click unsubscribe link. Legal basis upon activation: our legitimate interest in keeping our users informed within the user relationship (Art. 6(1)(f) GDPR) — with the right to object at any time.
11. Live location sharing (optional)
This feature is currently not available; this section applies as soon as it is activated.
Optionally, you can be visible live on the map to other signed-in Barnaby users during an active walk. This feature is disabled by default and is only activated after your explicit consent (opt-in).
Shared data: your current position (updated every 60 seconds), your username and display name, name/breed/photo of your dogs, and the distance and duration of the ongoing walk so far.
Recipients: exclusively signed-in Barnaby users who have enabled the display of other walkers.
Retention: ephemeral — the data is deleted when the walk ends. After an app crash the last entry may persist briefly; it then automatically becomes invisible to others and is overwritten or deleted at the latest on your next walk. No permanent movement profile is created.
Legal basis: your consent (Art. 6(1)(a) GDPR). You can disable the sharing at any time (withdrawal with effect for the future).
12. Direct messages (chat)
This feature is currently not available; this section applies as soon as it is activated.
You can send direct messages (1:1 chat) to other users. Users you do not mutually follow can initially only send you a message request; you decide whether to accept or decline it — only then is a chat possible. Users you have blocked cannot message you.
A conversation is readable exclusively by the two users involved (enforced via server-side access rules). Transmission is transport-encrypted (TLS); there is no end-to-end encryption — to handle reports, we as the operator have technical access to reported content.
Deletion: “Delete for everyone” removes the message text for both sides; a technical residual record without content remains. When an account is deleted, your conversations including messages are deleted.
Moderation: messages and profiles can be reported and users can be blocked. If you block a user, they can technically recognise that their messages are no longer being delivered.
Legal basis: Art. 6(1)(b) GDPR.
13. Crash reports, device integrity and app updates
Crash reports (Sentry): for error diagnostics we use Sentry (Functional Software, Inc., USA). We use Sentry with EU data residency: crash and error data (e.g. crash report, device model, operating system and app version, time of the error, your internal user ID) are transmitted via the EU endpoint to servers in Frankfurt am Main and stored there. Certain administrative data and metadata are processed by Sentry in the USA (see section 15). Legal basis: our legitimate interest in the stability and security of the app (Art. 6(1)(f) GDPR).
Device integrity (App Check): to prevent abuse, we verify for requests to our servers that they come from a genuine Barnaby app on a genuine device — via Play Integrity (Google) on Android and App Attest or DeviceCheck (Apple) on iOS. Legal basis: Art. 6(1)(f) GDPR.
App updates (EAS Update): the app queries Expo servers for updates; your IP address and technical device details are transmitted in the process.
App lock via Face ID/fingerprint: the biometric check runs exclusively on your device; biometric data never leaves your device.
14. Recipients and processors
We use the following service providers:
- Google Ireland Limited / Google LLC (Firebase): sign-in (Authentication), database (Firestore, EU multi-region eur3), file storage (Storage), server functions (Cloud Functions, region europe-west1/Belgium) and device integrity (App Check). Processor on the basis of the Firebase Data Processing and Security Terms.
- Google LLC: Google Maps (map display — IP address and map section) and Google Sign-In.
- Apple Inc.: Sign in with Apple, push delivery (APNs) and device integrity (App Attest/DeviceCheck).
- 650 Industries, Inc. (“Expo”, USA): delivery of push notifications (push token and notification content) and provision of app updates (EAS).
- Functional Software, Inc. (Sentry, USA): crash and error reports with EU data residency (Frankfurt am Main).
- PostHog, Inc. (USA): pseudonymous product analytics (linked to your user ID) – only with your consent; processing in the EU cloud (AWS, Frankfurt am Main), sub-processors incl. Cloudflare, Inc. (edge/CDN); processor under Art. 28 GDPR (third-country safeguard: see section 15).
- Google Ireland Limited (Google Analytics 4): reach measurement for the website barnaby.at — only after your consent. Processor under Art. 28 GDPR on the basis of the Google data processing terms; Google signals and ad personalisation are disabled (details in section 16).
- netwerk Kreidl GmbH & Co KG (Austria): technical maintenance and hosting of the website barnaby.at (including server log files) and e-mail delivery (SMTP) for account e-mails and the weekly recap — processor under Art. 28 GDPR. netwerk engages Mittwald CM Service GmbH & Co. KG (Germany) as a sub-processor for server operation.
- OpenMeteo GmbH (“Open-Meteo”, Switzerland): weather data for your walks (coordinates rounded to about 4 decimal places and IP address). We do not store the request coordinates; according to its own terms, Open-Meteo deletes request logs after 90 days (open-meteo.com/en/terms).
- OpenStreetMap Foundation (Nominatim, United Kingdom): place search (search text, language, IP address).
Recipients also include other Barnaby users — to the extent of your visibility settings (sections 4 to 7).
We do not pass your data on to advertisers or data brokers. The app contains no advertising SDKs, no cross-app tracking and no Apple advertising ID (IDFA); the pseudonymous product analytics (PostHog, above) runs only with your consent (Art. 6(1)(a) GDPR) and processes the features/events you use, a pseudonymous app identifier and the IP address for transmission (not permanently stored in the EU cloud) — no location or free-text data. The data is deleted after 30 days; you can withdraw analytics anytime in Settings. Product analytics is limited to adult users: for users under 18 it is neither offered nor is analytics consent collected. This paragraph concerns the app; for reach measurement on the website barnaby.at see section 16.
15. Transfers to third countries
Our core data resides in the EU (Firestore eur3, Cloud Functions europe-west1, Sentry event data in Frankfurt, website server at Mittwald in Germany; access by our maintenance agency netwerk exclusively from within the EU). Some services transfer data to the USA: Google LLC (Maps, Sign-In, parent company of Firebase), Apple Inc. (APNs, App Attest), 650 Industries, Inc. (“Expo”: push tokens, notification content, update requests), Functional Software, Inc. (Sentry: administrative data and metadata such as account and organisation data, while the error data itself remains in Frankfurt) and PostHog, Inc. (product analytics: access/administrative layer, while the analytics data itself remains in the EU cloud in Frankfurt).
For Google LLC, 650 Industries, Inc. and Functional Software, Inc., these transfers are based on the European Commission’s adequacy decision on the EU-US Data Privacy Framework (Art. 45(3) GDPR); these three providers are certified under the Data Privacy Framework, and the participant list is available at www.dataprivacyframework.gov/list (Expo is listed there as “650 Industries, Inc.”).
In addition, the EU Commission’s standard contractual clauses (Art. 46(2)(c) GDPR) are agreed with these three providers and apply should the certification lapse in the future — with Google as part of the Firebase Data Processing and Security Terms (firebase.google.com/terms/data-processing-terms), with Expo via their Terms of Service (expo.dev/terms), with Sentry via their Data Processing Addendum (sentry.io/legal/dpa/). You can obtain a copy of the respective safeguards via these links or on request to datenschutz@barnaby.at.
Apple bases its transfers of personal data from the EEA to the USA on the EU Commission’s standard contractual clauses (Art. 46(2)(c) GDPR); the contracting entity for users in the EEA is Apple Distribution International Limited (Ireland). Information and a copy of the clauses are available via www.apple.com/legal/privacy.
For PostHog, Inc. (USA), the transfer is based primarily on the European Commission’s adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR); PostHog, Inc. is certified under the Data Privacy Framework (participant list available at www.dataprivacyframework.gov/list). In addition, the EU standard contractual clauses (Art. 46(2)(c) GDPR) are agreed as a fallback should the certification lapse in the future. The event data itself is processed in the EU cloud (AWS Frankfurt); the IP address is not permanently stored there. You can obtain a copy of the safeguards via the PostHog Data Processing Agreement (posthog.com/dpa) or on request to datenschutz@barnaby.at.
The weather service Open-Meteo (OpenMeteo GmbH) is based in Switzerland; the European Commission’s adequacy decision for Switzerland applies to this transfer (Art. 45 GDPR).
For the place search via Nominatim (OpenStreetMap Foundation, United Kingdom), the European Commission’s adequacy decision for the United Kingdom applies (Art. 45 GDPR).
16. Website barnaby.at
When you visit the website, the hosting server (Mittwald, Germany) automatically creates server log files: IP address, time of access, requested URL, referrer URL, amount of data transferred, HTTP status code and user agent (browser/operating system). The purpose is the technical delivery of the website, its stability and the defence against attacks. Legal basis: Art. 6(1)(f) GDPR. The IP address is truncated as the log entry is written (the last one to three digits are removed, so “127.0.0.1” becomes “127.0.0.0”; this also applies to IPv6) — the access logs therefore never contain complete IP addresses. Access log files are deleted after 60 days, error logs after just 7 days. The server is technically maintained by netwerk Kreidl GmbH & Co KG (processor, see section 14).
Fonts are self-hosted; without your consent, no content is loaded from third-party servers apart from the account service pages mentioned below. For statistical reach measurement we use — only after your consent (Art. 6(1)(a) GDPR together with § 165 TKG 2021) — the analytics service PostHog (provider: PostHog, Inc.; sub-processors incl. Cloudflare, Inc.; processing in the EU cloud on AWS servers in Frankfurt). Only after your consent does PostHog set a cookie (ph_…_posthog, up to 12 months) and local-storage entries; the IP address is by default not stored permanently in the EU cloud. Event data is stored server-side for 30 days. DPA under Art. 28 GDPR; third-country transfers to the USA are based primarily on the adequacy decision under the EU-US Data Privacy Framework (Art. 45 GDPR; PostHog, Inc. is certified), additionally on the EU Standard Contractual Clauses (Art. 46 GDPR). Withdraw anytime via “Cookie settings” in the footer.
In addition — again only after your consent (Art. 6(1)(a) GDPR in conjunction with § 165 TKG 2021) — we use Google Analytics 4 (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, USA). Only after you agree is the gtag.js library loaded from googletagmanager.com; Google then sets cookies (_ga, _ga_…, lifetime up to 24 months). Processed are your IP address, device and browser data, the pages you visit and interactions such as scroll depth, clicks on outbound links and file downloads. Your IP address is transmitted to Google servers in the EU, evaluated there for coarse location (city level) and then discarded; Google does not log or store IP addresses of users from the EU. Google signals and ad personalisation are disabled, and your data is not used for personalised advertising. Event data is retained for 14 months. Data processing agreement under Art. 28 GDPR; transfers to the USA rely primarily on the European Commission’s adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR; Google LLC is certified) and additionally on the EU standard contractual clauses (Art. 46 GDPR). You can withdraw consent at any time via “Cookie settings” in the website footer; the cookies set by Google are deleted when you do.
The website also hosts the account service pages (e.g. barnaby.at/passwort/ for resetting your password and confirming e-mail changes). A new password entered there is transmitted in encrypted form directly to Firebase Authentication (Google, see section 14); we do not store it and never see it in plain text. To operate these pages, the Firebase software development kit is loaded from a Google server (www.gstatic.com); this transmits your IP address to Google. Legal basis: Art. 6(1)(b) GDPR (providing the account function you requested); on third-country transfers see section 15. Otherwise, the server log files described above apply.
17. Retention and deletion
- Account, profile, dog and walk data: until you delete them.
- Full (untrimmed) route of a walk: for as long as the associated walk — it is removed when the walk is deleted.
- Account deletion: directly in the app (Settings → Manage account → Delete account). This deletes your account, your profile, your dogs, your walks and your messages; your comments are anonymised (they appear as “Deleted user”, the texts remain without any link to your person). Uploaded photos and residual technical data (e.g. detailed route data) are removed within 30 days afterwards. Residual copies in backups expire with the backup retention period, at the latest 30 days after deletion; if we have to restore a backup after an incident, we remove data deleted in the meantime again without delay.
- Deleted shared dogs: restorable for 30 days, then permanently deleted.
- Goals of shared dogs: goals you created for a shared dog remain with the dog's remaining owners when you delete your account; your reference as their creator is removed.
- Push token: until you disable notifications, sign out or delete your account.
- In-app notifications: only the most recent 50 entries are kept.
- Reports: for as long as they are needed for review and abuse prevention; after that they are deleted or anonymised.
- Block lists: until you unblock the user or delete your account.
- Consent records for featuring your content on Barnaby channels (section 7): we retain the request and your answer for evidence purposes (Art. 7(1) GDPR) — including after a revocation or refusal, and after an account deletion for as long as required to demonstrate lawfulness.
- Moderation log (section 7): we retain moderation decisions relating to an account even after an account deletion, so that we can recognise repeat abuse and substantiate our decisions (Art. 6(1)(f) GDPR); the log is deleted at the latest 12 months after the account deletion.
- Deletion log: we keep a technical process record about the course of an account deletion that contains the internal account identifier (no name, no e-mail address) — as evidence that the deletion was carried out in full (Art. 5(2), Art. 6(1)(f) GDPR). It is removed 12 months after the deletion is completed.
- Ban marker for suspended accounts: if you delete your account while it is permanently or temporarily suspended, we store a ban marker containing a cryptographic hash (an irreversible checksum) of your e-mail address, the expiry date and the violation category — without the plaintext address and without your name. It prevents a suspension from being circumvented by deleting the account and immediately re-registering (Art. 6(1)(f), Art. 17(3)(e) GDPR). The marker is deleted after 12 months — for temporary suspensions already after the remaining suspension period, if that is shorter. No marker is created when a non-suspended account is deleted.
- Crash and error reports (Sentry): max. 90 days.
- Website server log files: see section 16.
18. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21).
Objection: you can object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest (Art. 6(1)(f) GDPR) — you can switch off push notifications (section 9) at any time without giving reasons via your device or app settings, and unsubscribe from the weekly recap e-mail at any time without giving reasons.
Withdrawal: you can withdraw any consent you have given (e.g. camera/photo access, product analytics) at any time with effect for the future — in the app or device settings.
Data export: in the app you can export your data (profile, dogs, walks) as a JSON file (Art. 20 GDPR).
Account deletion: directly in the app (section 17).
Requests to: datenschutz@barnaby.at — we respond within the statutory period.
19. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). Competent in Austria:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, phone +43 1 52 152-0, e-mail dsb@dsb.gv.at, www.dsb.gv.at
You can also contact any other data protection supervisory authority in the EU, in particular at your place of residence or work.
20. No automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. Statistics, streaks and achievements are simple calculations without legal or similarly significant effect on you. Decisions about warnings and account suspensions (section 7, terms of use §9) are also always made by a human — technology only carries out a decision that has been made.
21. Data security
All transmissions are encrypted (HTTPS/TLS). Passwords are stored exclusively as hashes. Access to data is restricted via server-side security rules (Firebase Security Rules); requests are additionally protected by device integrity checks (App Check).
22. Minimum age
Barnaby is intended for users aged 16 and over; registration is not possible under the age of 16. If, as a parent or guardian, you discover that your child under 16 has created an account, please contact datenschutz@barnaby.at — we will delete the account. For users under 18, the profile is set to private by default (walks visible only to approved followers); they are also excluded from product analytics.
23. Changes to this policy
We update this policy when features or legal requirements change. We will inform you about material changes in the app. The current version is always available in the app and on barnaby.at. This policy is available in German, English, Spanish and French (Spanish and French only in the app); in case of discrepancies, the German version prevails.