Hound-Up is a business management app for solo dog walkers — scheduling, client and dog records, and invoicing. You sign in with Apple once, the first time you open it, and it then works entirely offline. This page explains, plainly, what data the app handles and where it goes.
Everything you enter — client details, dog details, schedules, walk records, notes, invoices, and your own business profile — is stored locally on your device using Apple's on-device database (SwiftData). Hound-Up asks you to sign in with Apple the moment you first open it, before anything else — this is free, takes a few seconds, and never asks for an email address or password. Signing in creates a real account and backs up everything to our own backend, hosted on Supabase, so it carries over automatically if you lose this phone or add a second device.
What's copied to our backend once you're signed in:
This is never sold, used for advertising, or shared beyond what's already listed under Sub-processors below. Signing out (Settings → Data → Sign out) stops any further syncing but doesn't delete what's already stored, and doesn't touch your local data on this device either way. To permanently and immediately delete everything stored on our servers, use Settings → Data → "Delete cloud data".
Autopilot is a separate, additional paid subscription (currently £9.99/month, billed through your Apple ID; see the Terms of Service for billing details) — you're already signed in by the time you can turn it on, so it doesn't change what's synced or copy anything new. What it actually adds: certain features run on a schedule on our servers instead of only when you have the app open — automatic payment reminders, automatic visit-summary emails, your calendar feed, your availability calendar, and instant booking-request notifications. It isn't a backup feature — your data already backs up automatically the moment you sign in, whether or not you ever turn Autopilot on. Apple, not Hound-Up, processes the subscription payment itself and holds your payment details — we only know that you're subscribed, not your card details.
Autopilot is entirely optional and off by default. If you never turn it on, the features listed above only run while you have the app open — everything about signing in, above, still applies exactly the same either way.
Autopilot also includes an optional public micro-site (Settings → Profile → Micro-site), off by default — a shareable business page you can post on Instagram, Facebook, or WhatsApp. The business details, bio, badges, and other fields on it are already stored on our backend as part of Autopilot above; turning the micro-site on simply makes a subset of them — your business name, logo, bio, "Insured"/"DBS checked" badges, qualifications, specialities, service area, rates, and up to three stats — visible on a public page reachable by anyone with the link, or who finds it via search.
You can also feature specific dogs on the page — off by default for every dog — which shows that dog's name and existing photo (already stored for your own records, not newly uploaded for this). As with all client data (see "Your clients' data" below), it's your responsibility to have your client's agreement before publishing their dog's name and photo this way.
The page is served at houndup.atomlabs.dev/m/..., via a Cloudflare Worker that proxies our backend. The link itself is permanent once generated — switching the micro-site off stops the page from showing anything to visitors (they see a simple "not currently available" message) rather than changing the link, so a link you've already shared publicly keeps working if you turn the feature back on later. If you never turn this on, nothing here applies to you.
When you choose to email an invoice from inside the app, the following is sent, only for that purpose, to a backend that relays it on to your client:
This is relayed through two services, solely to deliver that one email:
Supabase — runs the backend that receives the request and forwards it to Resend. It also stores a device attestation key for your phone (see below), so the sending feature can't be abused by requests that didn't come from a genuine copy of the app. This key exists purely to prove the request came from a genuine copy of the app — it isn't linked to your name, your clients, or your account.
Resend — the email delivery provider that actually sends the message to your client's inbox.
None of this is stored for any purpose beyond delivering that email, used for marketing, or sold or shared with anyone else. If you never use the "email invoice" feature, none of this ever happens — the separate "Share" option instead hands the PDF straight to iOS's own share sheet, reaching only whichever app you pick there (Mail, WhatsApp, AirDrop, etc.), and doesn't touch our backend at all.
The "read a message" feature (for turning a pasted booking request into a scheduled walk or sit) sends the message text you paste in to Microsoft Azure OpenAI, which returns the booking details it found — who, when, any notes — back to the app. Nothing is retained by us once the response comes back. This only happens when you actively use this feature.
If you've turned on Booking Availability or the public micro-site, a visitor to your micro-site can submit a booking request or a general question directly to you. Whatever they enter — their name, a phone number or email if they give one, and either their requested date/time and a note (for a booking) or a free-text message (for a question) — is sent to our backend and stored only until your device next fetches it (typically within moments, whenever you have the app open or a push notification wakes it), at which point it's deleted from our backend entirely. If push notifications are on, the request's headline details are also delivered to your device the same way as any other push.
This is the one place Hound-Up's backend handles personal data belonging to someone who isn't a Hound-Up user themselves — your prospective client. It's used solely to deliver their message to you; it's never used for anything else, and isn't affected by whether you're signed in.
If you turn on "Publish a calendar feed" in Settings, your booked walks and sits (dates, times, and dog names) are uploaded to a file on our backend (via Supabase), at a link only you have. Anyone who has that exact link can view it, which is why the in-app confirmation warns against sharing it publicly. Turning the feed off removes the file. This is entirely opt-in and off by default.
Messages sent via Settings → Contact support are relayed through the same backend and Resend to the developer's own inbox, along with a reply-to address if you gave one, purely so we can reply to you.
Before any of the backend features above run, Apple's App Attest generates a one-time cryptographic key for your device and confirms with Apple that it's a genuine, untampered copy of Hound-Up. This is a standard anti-abuse mechanism — it identifies your device, not you, and carries no personal information.
If you use voice-to-text for walk notes, the audio is transcribed entirely on your device using Apple's on-device Speech framework. Nothing is recorded, stored, or sent anywhere.
These are every third party any backend feature above can send data to, and exactly what each one sees:
Supabase (EU, eu-west-1) — hosts the backend itself and the calendar feed files. For every walker, sees whatever a given request sends, as described above. Once you're signed in, also stores the business/client/schedule/invoice data listed in that section, your device push token, and, if provided, your Stripe Restricted key — until you delete it or delete your account.
Cloudflare — if you've turned on the public micro-site, proxies that one page so it renders correctly as a webpage. Sees only what's already public on that page for visitors who load it.
Resend — delivers invoice and support emails. Sees the recipient address, subject, body, and any PDF attached to that one email.
Microsoft Azure OpenAI — parses pasted booking messages. Sees the message text you paste in, for that one request.
Stripe — only if you've connected online payments for your own clients to pay by card. This is your own Stripe account, connected directly by you; when a client pays an invoice online, Stripe processes that payment and the card details involved. Hound-Up never sees or stores your clients' card details itself, only whether an invoice has been marked paid.
Apple (Sign in with Apple) — handles authentication when you sign in. Apple decides how much to share with us, typically a stable identifier and your name, and your email only if you choose to share it (or a private relay address if you don't). Apple's own privacy policy governs this.
Apple (App Store) — bills and manages the Autopilot subscription entirely through your Apple ID. Hound-Up never sees your payment details, only that you're subscribed.
Apple (Push Notifications) — if notifications are enabled, Apple's Push Notification service delivers them to your device using the device push token described above.
postcodes.io — Today's weather icon looks up your business postcode (from Business Details) to get its coordinates, sent directly from your device. Free, no API key, no account.
Open-Meteo — fetches the current weather for those coordinates, via our own backend rather than directly from your device — nothing else about your business is sent for this.
We won't add or replace a sub-processor for these features without updating this list first.
Hound-Up is a tool you use to run your own dog-walking business. The personal details you enter about your clients (names, addresses, contact details, emergency contacts, and their dogs' medical/vet information) are your responsibility to collect and use appropriately — for example, telling clients you keep these records and only using them for the purposes they'd reasonably expect (scheduling and invoicing their walks).
You can edit or delete any client, dog, or walk record at any time from within the app, or use Settings → Data → "Erase all data" to wipe everything — on this device and on our servers — at once. If you'd rather keep your local records but only clear what's stored on our servers, use Settings → Data → "Delete cloud data" instead; your device's own data is untouched either way. Signing out (Settings → Data → Sign out) just ends the session on this device and doesn't delete anything, locally or on our servers. If you've turned on the public micro-site, switching it off (Settings → Profile → Micro-site) immediately stops the page showing anything publicly.
Hound-Up isn't directed at children and isn't intended for use by them.
If this policy changes, the update will be posted here with a new effective date.
Questions about this policy or your data: hello@houndup.atomlabs.dev