Privacy Policy
Last updated: June 7, 2026
facebup is an owner-controlled vault for your pet’s records. This policy explains what we collect, why, who helps us run the service, and the rights you have over your data. facebup is a service of Facebup LLC, a Pennsylvania public benefit limited liability company (“we,” “us,” or “the Company”).
The short version: your records are yours, we never sell them and never share them without your okay, and you can export or delete them at any time. For the legal frame, see our Terms of Service. Each section below starts with a plain-language summary, then the details.
1. What we collect and why
In plain terms: we collect what we need to run your vault — your account login, the pet records and documents you choose to add, and basic logs to keep the service working and secure.
- Account and sign-in. Your email and authentication details, handled through Google Identity Platform, so you can securely sign in to your account.
- Pet records you enter. Information about your pets and their care — visits, prescriptions, vaccinations, and the like — that you add so we can keep it in your timeline.
- Documents and photos you upload. The files you attach, so we can store them, show them back to you, and help fill in record fields.
- Household membership. Invitations you send and members you add, so the people you choose can see the records you share.
- Minimal operational logs. Basic technical data — like timestamps, error logs, and security events — that we need to keep facebup running, debug problems, and protect against abuse.
- Usage and analytics data. How you interact with facebup — pages and features you use, actions you take, device and browser type, and performance and diagnostic signals — collected through analytics and similar technologies (including cookies, and third-party analytics providers) so we can understand usage, fix problems, and improve the product.
We collect this to provide, secure, and improve the service. We don’t sell your data, and we don’t use it to build advertising profiles or to target you with third-party ads.
2. We never sell or share your records (and what a service provider is)
In plain terms: we never sell your records, and we never share them with anyone outside facebup for their own purposes unless you explicitly opt in. We do rely on a few trusted service providers that process data only to run facebup — that is not selling or sharing.
We will never sell your pet’s records, and we’ll never share them without your say-so.
We never sell your records — not to advertisers, not to data brokers, not ever. And by default we never share them with third parties for their own purposes. The only time your records leave facebup for someone else’s use is when you explicitly opt in to a specific program or campaign that needs it — for example a research study or a partner perk. We’ll show you exactly what would be shared, with whom, and why; nothing is shared unless you say yes; and you can withdraw an opt-in at any time.
Separately, to operate facebup we use a small set of service providers (sub-processors) that handle data strictly on our behalf, only to run the service, and never for their own purposes. Using these providers is how the service works — it is not selling or sharing. Here is each one and what it does:
- Google Cloud. Hosting, database, authentication, and messaging — Cloud Run, Cloud SQL, Identity Platform, Pub/Sub, and Secret Manager. This is the infrastructure facebup runs on.
- Cloudflare R2. Encrypted storage for the documents and photos you upload.
- Anthropic (Claude AI). Extracts structured data from documents you upload, to fill in record fields for you. Your documents are processed only to provide this feature and, under our agreement with Anthropic, are not used to train AI models.
- Resend. Sends transactional email — for example, account and deletion confirmations.
Each provider is bound to use your data only as needed to operate facebup. We may also disclose information if the law requires it (for example, a valid legal process) or to protect the safety and security of our users — and we’ll resist overbroad requests where we can.
3. How we protect your data
In plain terms: your data is encrypted in transit and at rest, we strip location data out of your photos, and we keep an audit trail of sensitive actions.
- Encryption. Data is encrypted in transit with TLS, and encrypted at rest — both the documents you upload (in storage, R2) and the records in our database.
- Location data stripped from photos. When you upload a photo, we strip EXIF/GPS location metadata server-side so your home location isn’t embedded in the file we keep.
- Analytics, not ad targeting. We use analytics — including third-party analytics providers that may set cookies — to understand how facebup is used and to improve it, including on pages where you view your records. We don’t load advertising trackers or ad networks, and we don’t use your records to target ads. Where the law requires it, we ask for your consent before setting non-essential analytics cookies and honor browser opt-out signals like Global Privacy Control.
- Audit log. We keep an audit log of sensitive actions — extraction promotions, share creation and access, exports, deletions, account changes, and household invites and removals — so there’s an accountable trail.
No service can promise perfect security, but we take reasonable steps to protect your data and we keep improving them.
4. How long we keep data, and deletion
In plain terms: we keep your records while your account is active, you can export everything anytime, and when you delete your account we purge it permanently within 30 days.
We keep your records for as long as your account is active so the service works. You can export everything, anytime, free — your records as structured JSON plus the original documents you uploaded.
When you delete your account, your data is immediately removed from the product and you’re signed out. We then permanently and irreversibly purge all of your records, documents, and account data, completing within 30 days. You can cancel during that window by signing back in, and we send a confirmation email. Once the purge completes, your data is gone and cannot be recovered. We retain only a minimal, non-identifying audit record that the account was deleted, and any records we’re legally required to keep.
5. Your privacy rights
In plain terms: you can access, correct, delete, and take a copy of your data. Export and account deletion are already self-serve in the app; for anything else, email us.
Wherever you live, you can ask us to give you access to your data, correct it, delete it, or provide a portable copy. Export and account deletion are already self-serve inside facebup. A fuller set of interactive, self-serve right-paths is coming. For now, exercise any other right by emailing support@facebup.com. We don’t charge for exercising these rights and we won’t discriminate against you for doing so.
California (CCPA/CPRA). You have the right to know, access, correct, delete, and port your personal information, and to not be discriminated against for exercising these rights. We do not sell your personal information or share it for cross-context behavioral advertising. If we ever offer an optional program that would involve sharing your information in a way California law treats as a “sale” or “share,” it will be strictly opt-in, and you can opt out at any time; if we launch such a program we’ll also provide a “Do Not Sell or Share My Personal Information” control, post a notice at collection, and honor browser-based opt-out signals like Global Privacy Control. We respond to verifiable requests within 45 days, and may extend by an additional 45 days when reasonably necessary, with notice to you.
Washington (My Health My Data Act). To the extent any of your pet-care information counts as your consumer health data, you have the right to access it, to withdraw consent, and to have it deleted. We will not sell your consumer health data except under a separate valid authorization you sign, as Washington law requires. We would share it only with your separate, explicit consent — for an opt-in program you choose to join — and never with third parties for their own purposes otherwise.
Colorado, Connecticut, Virginia, and Oregon. If you’re a resident of these states, you have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising and sale. We don’t engage in targeted advertising, and we don’t sell your data except through an optional program you choose to opt in to. You may appeal a decision on your request by replying to our response.
Users outside the United States. Where a GDPR-style right applies, you have rights of access, rectification, erasure, restriction, portability, and objection, and we’ll respond within one month. Note that facebup is operated from, and your data is processed in, the United States; by using facebup you understand your data is handled there (see Section 6).
We may need to verify your identity before acting on a request, to protect your account. You can also authorize an agent to make a request on your behalf where the law allows.
6. Where your data is processed
In plain terms: facebup runs in the United States, so your data is stored and processed there.
facebup is operated from the United States and our service providers process your data primarily in the United States. If you access facebup from another country, you understand your data is transferred to and processed in the U.S., where privacy laws may differ from those where you live.
7. If there’s ever a data breach
In plain terms: if your data is ever exposed in a breach, we’ll tell you and the right authorities, as the law requires.
If a security incident affects your personal information, we will notify you and the relevant authorities without unreasonable delay and as required by applicable law. We maintain readiness under the FTC Health Breach Notification Rule, including a notification path of no later than 60 days, and we comply with applicable state breach-notification laws, which may require notice sooner. Questions about a security incident can go to support@facebup.com.
8. Children
facebup is an 18+ service. It is not directed to children, and we don’t knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, email support@facebup.com and we’ll delete it.
9. Changes to this policy
We may update this policy from time to time. When we do, we’ll change the “Last updated” date above. For material changes, we’ll give you reasonable notice — by email to the address on your account and/or a clear notice in the app — before they take effect.
10. Contact us
For any privacy question or to exercise a right, email support@facebup.com. You can also read more about facebup on our About page.