Barkly Privacy Policy

Last updated 12 July 2026.

Your pet's sounds are read on your device

Barkly's core feature — listening to your dog or cat and reading their likely mood — runs entirely on your iPhone. Barkly does not upload or save that audio as a recording. Temporary samples are held only in memory for the current listen-and-analyse flow, then replaced when the next listen starts or released when that flow ends.

Optional AI features and named processors

When you choose one of these features and give in-app consent, its HTTPS request travels through Barkly's Vercel proxy to Barkly's AWS service:

Pet Assistant — your typed message, relevant recent chat history, recent mood reads and your pet's profile (name, species, optional breed, age and personality) are sent to DeepSeek to generate general pet guidance. OpenAI may process the same text if DeepSeek is unavailable.
Talk with your pet — your typed message, relevant recent chat history, recent mood reads and the same pet-profile fields are sent to DeepSeek, or to OpenAI as fallback, to generate a playful AI character reply. Premium voice audio is generated by Barkly's self-hosted Kokoro service in AWS.
Body-language scan — the photo you capture, your pet's species and optional profile, and recent mood-read context are sent to OpenAI to create a best-guess body-language mood read. Barkly processes the input image in memory and does not store it after the request.
AI portrait — the photo you choose plus the pet details and style needed for the request are sent to OpenAI to create the portrait. To cross the asynchronous worker step, the input may be placed in encrypted temporary object storage. The worker attempts to delete it after processing; if that cleanup fails, a lifecycle rule makes it eligible for expiration after one day. The generated portrait is stored privately for delivery and becomes eligible for lifecycle expiration after 30 days; the copy you keep lives on your device.

Vercel and AWS provide request routing and cloud infrastructure; DeepSeek and OpenAI process only the optional request categories described above. Barkly requires each processor to use the data only to deliver and secure the requested API service and to protect it to the same or an equivalent standard described in this policy. We send only what's needed for the feature you requested and do not send your content for third-party advertising or cross-company tracking. Barkly does not sell your data or use your content to train Barkly models. Processor-side handling remains subject to the named service's API privacy and retention terms. Storage lifecycle removal is asynchronous and may complete after the configured expiration day.

What we store

On your device: your pet's profile, saved reads, diary, training progress, and on-device calibration. Before a portrait is sent, Barkly also saves the exact request — including the prepared photo, if any — in an iOS-protected Application Support file marked to stay out of backups. Unresolved recovery state is accepted for up to 15 days; a downloaded JPEG awaiting application is accepted for up to 30 days from the request's start. Barkly normally clears it after application or confirmed failure, and removes expired state when the app next checks it.

For Assistant, Talk, and Scan delivery, Barkly stores a one-way request fingerprint and the generated result with a 14-day expiry so an interrupted retry can return the same result without another AI call. Barkly does not write the raw message or Scan photo to its own database or object storage after the request; named processors handle inputs under their API privacy and retention terms. Linked counters record successful use of Assistant, Talk, and Scan and are kept while needed to enforce each feature's lifetime free allowance. Portrait job and delivery metadata has a 30-day expiry. A Premium monthly-allowance record, linked to the stable app customer, has a 400-day expiry for fair-use enforcement and delivery audit; purchase/wallet records follow the longer retention described below. Expiry deletion can finish later.

Purchases are handled by Apple. To deliver and restore purchases, we store the product, Apple's transaction and original-transaction identifiers, an Apple-signed app transaction identifier that is stable for this app customer, and a random Barkly purchase token. These identifiers let us bind one welcome gift and wallet across reinstalls/devices, verify Premium, grant or reverse portrait credits exactly once, and prevent replay. They are linked to purchase and wallet records but not to your name, email, advertising profile, or payment-card details. The random token may sync through your encrypted iCloud Keychain.

What we do NOT do

We do not sell your data, upload your pet's on-device audio, require an owner account for the core app, or use your content to train our own AI models. Optional cloud requests can include your pet's name and profile, but not your owner name, email address or advertising profile.

Retention, choices & contact

Assistant/Talk/Scan replay records have a 14-day expiry. Linked Assistant/Talk/Scan success counters are retained while needed to enforce each feature's lifetime free allowance. Portrait jobs and generated audio or portrait objects have 30-day expiry rules. The linked Premium monthly-allowance counter has a 400-day expiry for fair-use enforcement and delivery audit. Barkly attempts to delete temporary server portrait inputs after processing, with a lifecycle rule making them eligible for expiration after one day as a fallback. Expiry removal is asynchronous and can complete later. Purchase ownership, transaction replay markers, refund records, and wallet balances are retained while needed to deliver paid purchases, prevent double grants, and meet accounting/fraud obligations; they do not contain card details. Deleting the app removes pet content and portrait recovery state from the device, while the random purchase token may remain in Keychain so unused paid portrait credits can be recovered. To request deletion of linked success counters, a server wallet, and its device/customer binding, email mitsi@keenshift.ai. We may retain a minimal non-replayable transaction tombstone where deletion would otherwise allow a paid transaction to be granted twice.