Most privacy pages are a list of the things a company reserves the right to do with you. This one is a list of the requests this site makes, all of them, so that you can go and check.
There is no server anywhere in this product. There is no backend, no database and no API. That is not a policy that could be changed next quarter โ there is simply nowhere for a photograph to go.
Your pictures are read inside your own browser tab, or inside the app on your own machine. They are never transmitted, never stored, and never used to train anything.
When you add photos or a video, the file is opened by your own browser and drawn onto a canvas in the page. Two small vision models โ a detector that finds the animal, and a segmenter that cuts it out โ run on your own processor, in that tab. From the cut-out, the page measures about thirty numbers: coat colours, where the white sits, stripes or patches, ear and tail shape, eye colour.
Those thirty numbers are the pet. The photographs themselves are discarded when you close or reload the tab, because they were never anywhere but in that tab's memory. Nothing is written to your disk unless you press save, and what saves is the numbers โ a pet file with no images in it.
Being honest about this is the point, so here is the complete list, including the parts that are not flattering.
fonts.googleapis.com and fonts.gstatic.com, which
means Google sees your IP address when the page loads. This is the least
defensible thing on the list and self-hosting the two font files would
remove it.
cdn.jsdelivr.net and the model weights from
huggingface.co, about 20 MB, cached by your browser
afterwards. These are downloads to you. Nothing about your pet or
your photographs is sent with them.
That is the entire list. There is no advertising network, no tag manager, no session recorder, no A/B testing service and no third-party analytics.
This site sets none. It does not use localStorage,
sessionStorage or IndexedDB either โ the only thing your browser
keeps is its ordinary HTTP cache of the model files. There is no consent
banner because there is nothing to consent to.
There is no sign-up, so there is no email address, no password and no profile. No personal data is collected, which means there is none to sell, none to leak, and nothing to hand over if somebody asks.
The Mac and Windows app runs entirely offline. It reads and writes pet files on your own disk and makes no network requests of its own โ the one exception is that if you build a pet inside the app, it runs the same page as this website and fetches the same vision models the first time.
No. They are never transmitted anywhere, so they could not be. The models the app uses are pre-existing open ones that run on your machine; nothing you add is fed back into them.
Nobody but you, unless you send them the file. There is no gallery, no sharing feature and no account under which it could be listed.
Only the ordinary thing: the pet file is yours to look after, and the app installers are not yet code-signed, so your operating system will warn you about them. That is explained on the questions page.
Last reviewed 29 August 2026. If this page and the code ever disagree, the code is the truth and this page is a bug.