Privacy Policy

Amble은 Amble Dog LLC(미국 미시간주)가 운영하며, 여기에 설명된 데이터에 대한 책임은 이 회사에 있습니다.

쉬운 말로 요약

  • 계정을 만들기 전까지는 페이지가 몇 번 열렸는지만 세고, 회원님에 대해서는 아무것도 기록하지 않아요. 가입 전에는 추적 쿠키도 광고 픽셀도 없고 IP 주소도 남기지 않아요. 하루에 각 페이지가 몇 번 열렸는지, 그 숫자만 있어요.
  • 홈 화면에서 질문을 하는 경우는 예외예요. 질문과 고른 나이, 그리고 카드를 담아 둘 익명 계정이 하나 만들어져요. 이메일도 비밀번호도 없고, 누구인지 알 수 있는 정보는 없어요. 다시 오지 않으시면 90일 뒤에 지워져요.
  • 데이터를 판매하지 않고, 광고를 보여드리지 않아요.
  • 메모는 누구에게도 표시되지 않아요 — 가족 보기에도, 공유 링크에도요. 다만 메모는 Amble이 쓰는 글에 반영되고, 가족은 그 글을 읽을 수 있어요.
  • 반려견 사진은 비공개 저장소에 보관되고 짧게 유효한 링크로만 보여져요. 공개 이미지 주소는 없어요.
  • ‘현재 위치 사용’은 앱에 함께 담긴 도시 목록을 이용해 기기 안에서만 도시를 찾아요. 좌표는 저희에게도, 다른 어떤 곳에도 전송되지 않고 회원님이 남겨 둔 도시 이름만 저장돼요.
  • 카드는 저희 AI 게이트웨이를 통해 Google Gemini가 씁니다. 이메일 주소와 반려견 사진은 모델에 전송되지 않아요.
  • 가족 공유는 보기 전용이에요: 오늘의 카드, 기록, About 페이지, 주간 회고. 메모·이메일·설정·위치·결제 정보는 절대 보이지 않아요.
  • 설정에서, 또는 hello@amble.dog 로 이메일을 보내 계정과 모든 데이터를 삭제할 수 있어요. 30일 이내 완료를 목표로 합니다.

이 요약은 중요한 내용을 모국어로 읽으실 수 있도록 제공돼요. 아래 전문은 영어로만 게시되며, 법적으로 적용되는 것은 영어본이에요. 요약과 영어 원문이 다르게 보이면 hello@amble.dog 로 알려주세요. 요약을 바로잡을게요.


전문 (영어)

Last updated: August 24, 2026

Amble is a quiet daily companion for you and your dog. This page explains, plainly, what we collect, what we do with it, and — just as importantly — what we don't. We've tried to write it the way we write everything else here: calmly, and without hiding the real details.

If you only read one line: we don't sell your data, and we don't use it to advertise to you. Everything we collect exists to write a better card for your dog.

What we collect

  • About your dog — name, breed, sex, age (birth or adoption date), what you're working on together, and anything you choose to tell us. This is the heart of Amble.
  • Your notes — the private observations you write on the daily card. These are yours; they help Amble understand your dog over time.
  • Your dog's photo, if you add one. Stored privately (see Photos).
  • Optional location — if you add a city, we use it to make cards a little more relevant. It's city-level only, never precise GPS, and you can remove it anytime. If you use the optional "use my location" control, your device's coordinates are matched to the nearest city on your own device, against a list of cities shipped with the app. Those coordinates are never sent to us and never seen by a third party — only the city name you choose to keep is saved.
  • Your account basics — email address, language, timezone, and how you sign in (email or Google).
  • Payment identifiers, if you subscribe (see Payments).
  • Limited product events — for example, that a card was viewed or that a generation failed — so we can keep Amble working. These contain no notes and no personal details, and they're never sold or used for ads.

What we don't collect

  • Before you have an account, we count page views and record nothing about you. Visiting Amble signed out increments a daily number — how many times that particular page was opened, and how many times someone tapped through from it to sign up. The count is kept per page, so we can tell which pages are useful; the row is a page name, a date and a number. That is the whole record. No cookie is set for it, no IP address or approximation of one is read or stored, no user agent, no referrer, no fingerprint, and nothing that could distinguish one visitor from another or link two visits together. The counter cannot tell whether a hundred views came from a hundred people or from one.
  • Asking the question on the front page is the exception, and it does create an account. If you type what you're wondering about on the homepage and ask for a card, Amble makes an anonymous account for you there and then, so it has somewhere to put the answer. That account holds your question, the rough age you picked, a name if you gave one, and the card that was written. There is no email address on it and no password; nothing identifies you. It is signed in on that device so you can come back to the card. If you never come back, it is deleted after 90 days of inactivity, card and all. You can also delete it yourself at any time from Settings.
  • We don't track you across the web.
  • We don't build an advertising profile.
  • We don't read or store precise location.
  • We don't ask for anything about your dog we don't actually use to write your cards.

How your cards are written

Each day, Amble sends a limited slice of your dog's profile and recent context to a language model to write the card — currently Google's Gemini, and only through our application's AI gateway. We don't use any other AI provider. Your email address and your dog's photo are never sent to the model.

Photos

If you add a photo of your dog, it's kept in private storage — not on a public address. When a photo is shown to you, it's served through a short-lived, signed link that expires. There's no public gallery and no shareable image URL.

Amble keeps every photo you've added, not only the one currently shown on the card — replacing a photo doesn't erase the earlier one. You can see the photos Amble has recorded, with their dates, under Settings › your dog, and remove any single photo — or all of them at once. Removing a photo deletes it from the live app immediately, and from the off-site backup within 30 days (below).

Family sharing

You can share a view-only link so the people who love your dog too — a partner, the kids, a sitter — can follow along. People you share with can see the daily card, the card history, the "About [your dog]" page, and (on Premium) the weekly reflection.

They cannot see your private notes, your email, your account settings, your location, or anything about your billing. The link is view-only — they can't change anything — and you can turn it off at any time.

Your notes are never displayed to them. They do, however, shape what Amble writes — the daily card, the "About [your dog]" page, and the weekly reflection — and family viewers can read that writing. So a note's influence is visible even though its text never is.

Multiple dogs

A free account covers one dog. With Premium you can add up to five. Each dog has its own profile, cards, notes, and photo, kept separate from the others.

Payments

If you subscribe to Premium, payments are handled by Stripe. Stripe processes your card details — we never see or store them. On our side we keep only the identifiers needed to manage your subscription (a Stripe customer and subscription id, your plan, and its status). No card numbers, ever.

How long we keep things — and deleting

  • Cards you delete stay in Trash for 30 days, then they're permanently removed.
  • Anonymous trial accounts (where you never sign in) are deleted after 90 days of inactivity.
  • If you go quiet for a while (about 21 days), we pause your daily cards to save resources and send one gentle note — we don't delete anything.
  • You can delete your account and all its data from Settings, or by emailing hello@amble.dog. We aim to complete deletion within 30 days.
  • Your dog's photo is also copied to an encrypted off-site backup (Cloudflare R2), so a fault on our side can't lose it. When you delete a photo, a dog, or your whole account, the photo is removed from the live app immediately and from that backup within 30 days, after which no copy of it exists anywhere. The 30 days exist only so an accidental deletion can still be undone.

Where your data is processed

Amble runs on infrastructure operated by Supabase (database and private photo storage), Cloudflare (serving the app, and Cloudflare R2 for the encrypted off-site photo backup), Lovable (our AI gateway and account emails), Google (Gemini, for writing cards; and Google Sign-In, if you use it), and Stripe (payments). Some of these providers process data in the United States, so if you're outside the US, your information may be transferred to and processed there.

The photo backup is a private bucket: it is not reachable from the web, has no public URL, and can only be read with credentials held by our server. Its contents are encrypted at rest. Nothing else — no notes, no cards, no account details — is replicated there; it holds dog photos only.

Cookies and what's stored in your browser

We don't use advertising or tracking cookies, and there is no third-party analytics script on Amble. What we do keep in your browser is small and functional:

  • Language (wren_lang, a cookie that lasts 1 year). Remembers the language you chose so the page arrives already written in it, instead of loading in English and correcting itself a moment later. It holds only a language code — ko, ja, en — and no identifier of any kind. The same choice is also kept in your browser's local storage (wren.lang); the cookie exists because, unlike local storage, our server can read it before the page is drawn.
  • Appearance (wren:theme, local storage). Your light or dark preference.
  • Signing in. Your session is kept in your browser's local storage by our authentication provider, under a key named sb-<project>-auth-token. This is the most significant thing stored in your browser: it holds the tokens that keep you signed in, along with your account id and email, and it stays until you sign out or clear site data. During a Google sign-in the same library briefly writes a one-time value (sb-<project>-auth-token-code-verifier) and deletes it as soon as the sign-in finishes. If you start without an account and later create one, two more short-lived values (wren:anonMigrateToken, wren:anonSessionSnapshot) carry your dog across that step and are cleared as soon as it completes.
  • Family view-only links. If someone opens a link you shared, their browser keeps the link's token (amble.viewer.token) plus the dog's and your display name so the page knows what to show. It's removed when they sign out, and it stops working when the link expires or you revoke it.
  • Small bits of interface state — a collapsed sidebar (sidebar_state), a hint you've dismissed, a sample you picked before signing up, and where you had scrolled on the previous page (tsr-scroll-restoration-v1_3, cleared when you close the tab). Nothing identifying.
  • Site password (amble_gate). A signed cookie from the pre-launch password gate. It's switched off now.

Payments. Paying happens on Stripe's own checkout page, not on ours: we don't load any Stripe script here, so Stripe sets no cookies on amble.dog. While you're on their page, Stripe sets its own cookies on checkout.stripe.com under its privacy policy.

None of these are used to profile you or follow you to other sites, and clearing them costs you nothing but your language, theme, and any dismissed hints.

Your rights

You can ask us to show you what we hold about you, correct it, or delete it — just email hello@amble.dog. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA, and we'll honor them.

Children

Amble is made for adults. It isn't intended for anyone under 16, and we don't knowingly collect information from children.

Changes

We treat this page as a living document. When the product changes in a way that affects your data — a new provider, a new field, anything — we update this page the same day and change the date at the top.

Contact

개인정보에 관한 문의는 hello@amble.dog로 이메일을 보내주세요.

Questions, requests, or anything at all: hello@amble.dog.

Full technical details

For people who want the specifics, here's the fuller inventory.

What we store, by area:

  • Account (users): email, email preferences, verification, language, timezone, sign-in identity, and pause state. If you subscribe: stripe_customer_id, stripe_subscription_id, subscription_status, current_period_end, plan, and plan_changed_at. A separate append-only plan_change_events table keeps a billing audit trail (from/to plan, Stripe event id). No card data is stored anywhere on our side.
  • Dogs (dogs): name, sex, neuter status, date of birth, adoption ("gotcha") date, breed, optional city-level location, an optional photo reference, and what you're working on.
  • Your inputs: daily notes (dog_notes), check-in feedback, and saved cards.
  • Generated content: daily cards, the evolving memory Amble builds about your dog (dog_memories, plus a warm prose summary), and weekly reflections.
  • Product events (analytics_events): limited operational events (e.g., a card was served, a generation failed). By design these contain no free text and no personal information.
  • Signed-out page counts (anon_funnel_counts): one integer per event name per day. The table has no column capable of holding anything about a visitor — no address, no identifier, no text — and the set of event names is a closed list that fails our build if any code tries to emit a name outside it.

AI. Model calls go to Google Gemini, either through our AI gateway (ai.gateway.lovable.dev) or directly to Google's API. One call — the safety check that decides whether something you describe needs a vet or trainer referral — goes to OpenAI instead. Every model identifier the product can send is declared in one file in our source, and our build fails if any code names a model anywhere else. Card prompts include your dog's profile and recent context; they exclude your email and your dog's photo.

Family viewer scope. A shared viewer receives an explicit allow-list of fields — the dog's profile basics, photo, breed, temperament and memory summary, what you're working on, the caretaker paragraph (Premium) — plus the cards, history, and weekly reflection. Owner notes (dog_notes), the raw memory ledger, location, feedback, and every account and billing field are deliberately excluded, and are never even queried on the viewer path.

Retention. Trashed cards: 30 days. Inactive anonymous accounts: 90 days. Dormant pause: about 21 days (a pause, not a deletion). Dog photos in the off-site backup after deletion: 30 days.

Subprocessors. Supabase, Cloudflare, Lovable (AI gateway + email), Google (Gemini + OAuth), Stripe, Cloudflare R2 (encrypted off-site backup of dog photos only).

An honest caveat. The inventory above is checked against our database schema in automated tests. That verifies the shape of what we store; it does not, by itself, prove that every code path only ever writes to the fields listed — that remains an engineering responsibility we take seriously.

The cookie and browser-storage list is checked the same way: a test scans our source for anything written to your browser and fails the build if a key isn't declared in the same inventory this page is written from. Same caveat applies — it verifies that nothing is stored undisclosed, not what any given value contains. One gap worth naming: that scan can only see our own code. Values written by an outside library — the sign-in session above, the scroll position — are declared by hand after reading a real browser's storage, so they're listed here but not machine-checked.