Privacy Policy

Amble 由 Amble Dog LLC(美国密歇根州)运营,该公司对此处所述数据负责。

简明摘要

  • 在你注册之前,我们只统计页面被打开了多少次,不记录任何关于你的信息。注册前没有追踪 Cookie,没有广告像素,也不保存你的 IP 地址——只有每天各个页面被打开次数的合计。
  • 在首页提问是例外:我们会建立一个匿名账号,用来存放你的问题、你选的年龄和那张卡片。账号上没有邮箱也没有密码,没有任何信息指向你;若你不再回来,90 天后会删除。
  • 我们不出售你的数据,也从不向你展示广告。
  • 你的笔记从不展示给任何人——家人视图看不到,分享链接里也没有。但笔记会影响 Amble 写下的内容,而家人能读到那些内容。
  • 狗狗的照片保存在私有存储中,只通过短时有效的链接显示。没有公开的图片地址。
  • “使用我的位置”在你自己的设备上完成匹配,依据的是随应用一起打包的城市列表。你的坐标从不发送给我们,也不发送给任何第三方——只保存你留下的城市名称。
  • 卡片由 Google 的 Gemini 通过我们的 AI 网关撰写。你的邮箱和狗狗的照片从不发送给模型。
  • 家庭分享仅供查看:每日卡片、历史、About 页面和每周回顾。绝不包括你的笔记、邮箱、设置、位置或账单。
  • 你可以在设置中删除账户及其全部数据,或发送邮件至 hello@amble.dog。我们力争在 30 天内完成。

这份摘要是为了让你用自己的语言读到要点。下方全文仅以英文发布,具有法律效力的是英文版本。如果摘要与英文正文看起来不一致,请告诉我们:hello@amble.dog,我们会修正摘要。


全文(英文)

Last updated: August 24, 2026

Amble is a quiet daily companion for you and your dog. This page explains, plainly, what we collect, what we do with it, and — just as importantly — what we don't. We've tried to write it the way we write everything else here: calmly, and without hiding the real details.

If you only read one line: we don't sell your data, and we don't use it to advertise to you. Everything we collect exists to write a better card for your dog.

What we collect

  • About your dog — name, breed, sex, age (birth or adoption date), what you're working on together, and anything you choose to tell us. This is the heart of Amble.
  • Your notes — the private observations you write on the daily card. These are yours; they help Amble understand your dog over time.
  • Your dog's photo, if you add one. Stored privately (see Photos).
  • Optional location — if you add a city, we use it to make cards a little more relevant. It's city-level only, never precise GPS, and you can remove it anytime. If you use the optional "use my location" control, your device's coordinates are matched to the nearest city on your own device, against a list of cities shipped with the app. Those coordinates are never sent to us and never seen by a third party — only the city name you choose to keep is saved.
  • Your account basics — email address, language, timezone, and how you sign in (email or Google).
  • Payment identifiers, if you subscribe (see Payments).
  • Limited product events — for example, that a card was viewed or that a generation failed — so we can keep Amble working. These contain no notes and no personal details, and they're never sold or used for ads.

What we don't collect

  • Before you have an account, we count page views and record nothing about you. Visiting Amble signed out increments a daily number — how many times that particular page was opened, and how many times someone tapped through from it to sign up. The count is kept per page, so we can tell which pages are useful; the row is a page name, a date and a number. That is the whole record. No cookie is set for it, no IP address or approximation of one is read or stored, no user agent, no referrer, no fingerprint, and nothing that could distinguish one visitor from another or link two visits together. The counter cannot tell whether a hundred views came from a hundred people or from one.
  • Asking the question on the front page is the exception, and it does create an account. If you type what you're wondering about on the homepage and ask for a card, Amble makes an anonymous account for you there and then, so it has somewhere to put the answer. That account holds your question, the rough age you picked, a name if you gave one, and the card that was written. There is no email address on it and no password; nothing identifies you. It is signed in on that device so you can come back to the card. If you never come back, it is deleted after 90 days of inactivity, card and all. You can also delete it yourself at any time from Settings.
  • We don't track you across the web.
  • We don't build an advertising profile.
  • We don't read or store precise location.
  • We don't ask for anything about your dog we don't actually use to write your cards.

How your cards are written

Each day, Amble sends a limited slice of your dog's profile and recent context to a language model to write the card — currently Google's Gemini, and only through our application's AI gateway. We don't use any other AI provider. Your email address and your dog's photo are never sent to the model.

Photos

If you add a photo of your dog, it's kept in private storage — not on a public address. When a photo is shown to you, it's served through a short-lived, signed link that expires. There's no public gallery and no shareable image URL.

Amble keeps every photo you've added, not only the one currently shown on the card — replacing a photo doesn't erase the earlier one. You can see the photos Amble has recorded, with their dates, under Settings › your dog, and remove any single photo — or all of them at once. Removing a photo deletes it from the live app immediately, and from the off-site backup within 30 days (below).

Family sharing

You can share a view-only link so the people who love your dog too — a partner, the kids, a sitter — can follow along. People you share with can see the daily card, the card history, the "About [your dog]" page, and (on Premium) the weekly reflection.

They cannot see your private notes, your email, your account settings, your location, or anything about your billing. The link is view-only — they can't change anything — and you can turn it off at any time.

Your notes are never displayed to them. They do, however, shape what Amble writes — the daily card, the "About [your dog]" page, and the weekly reflection — and family viewers can read that writing. So a note's influence is visible even though its text never is.

Multiple dogs

A free account covers one dog. With Premium you can add up to five. Each dog has its own profile, cards, notes, and photo, kept separate from the others.

Payments

If you subscribe to Premium, payments are handled by Stripe. Stripe processes your card details — we never see or store them. On our side we keep only the identifiers needed to manage your subscription (a Stripe customer and subscription id, your plan, and its status). No card numbers, ever.

How long we keep things — and deleting

  • Cards you delete stay in Trash for 30 days, then they're permanently removed.
  • Anonymous trial accounts (where you never sign in) are deleted after 90 days of inactivity.
  • If you go quiet for a while (about 21 days), we pause your daily cards to save resources and send one gentle note — we don't delete anything.
  • You can delete your account and all its data from Settings, or by emailing hello@amble.dog. We aim to complete deletion within 30 days.
  • Your dog's photo is also copied to an encrypted off-site backup (Cloudflare R2), so a fault on our side can't lose it. When you delete a photo, a dog, or your whole account, the photo is removed from the live app immediately and from that backup within 30 days, after which no copy of it exists anywhere. The 30 days exist only so an accidental deletion can still be undone.

Where your data is processed

Amble runs on infrastructure operated by Supabase (database and private photo storage), Cloudflare (serving the app, and Cloudflare R2 for the encrypted off-site photo backup), Lovable (our AI gateway and account emails), Google (Gemini, for writing cards; and Google Sign-In, if you use it), and Stripe (payments). Some of these providers process data in the United States, so if you're outside the US, your information may be transferred to and processed there.

The photo backup is a private bucket: it is not reachable from the web, has no public URL, and can only be read with credentials held by our server. Its contents are encrypted at rest. Nothing else — no notes, no cards, no account details — is replicated there; it holds dog photos only.

Cookies and what's stored in your browser

We don't use advertising or tracking cookies, and there is no third-party analytics script on Amble. What we do keep in your browser is small and functional:

  • Language (wren_lang, a cookie that lasts 1 year). Remembers the language you chose so the page arrives already written in it, instead of loading in English and correcting itself a moment later. It holds only a language code — ko, ja, en — and no identifier of any kind. The same choice is also kept in your browser's local storage (wren.lang); the cookie exists because, unlike local storage, our server can read it before the page is drawn.
  • Appearance (wren:theme, local storage). Your light or dark preference.
  • Signing in. Your session is kept in your browser's local storage by our authentication provider, under a key named sb-<project>-auth-token. This is the most significant thing stored in your browser: it holds the tokens that keep you signed in, along with your account id and email, and it stays until you sign out or clear site data. During a Google sign-in the same library briefly writes a one-time value (sb-<project>-auth-token-code-verifier) and deletes it as soon as the sign-in finishes. If you start without an account and later create one, two more short-lived values (wren:anonMigrateToken, wren:anonSessionSnapshot) carry your dog across that step and are cleared as soon as it completes.
  • Family view-only links. If someone opens a link you shared, their browser keeps the link's token (amble.viewer.token) plus the dog's and your display name so the page knows what to show. It's removed when they sign out, and it stops working when the link expires or you revoke it.
  • Small bits of interface state — a collapsed sidebar (sidebar_state), a hint you've dismissed, a sample you picked before signing up, and where you had scrolled on the previous page (tsr-scroll-restoration-v1_3, cleared when you close the tab). Nothing identifying.
  • Site password (amble_gate). A signed cookie from the pre-launch password gate. It's switched off now.

Payments. Paying happens on Stripe's own checkout page, not on ours: we don't load any Stripe script here, so Stripe sets no cookies on amble.dog. While you're on their page, Stripe sets its own cookies on checkout.stripe.com under its privacy policy.

None of these are used to profile you or follow you to other sites, and clearing them costs you nothing but your language, theme, and any dismissed hints.

Your rights

You can ask us to show you what we hold about you, correct it, or delete it — just email hello@amble.dog. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA, and we'll honor them.

Children

Amble is made for adults. It isn't intended for anyone under 16, and we don't knowingly collect information from children.

Changes

We treat this page as a living document. When the product changes in a way that affects your data — a new provider, a new field, anything — we update this page the same day and change the date at the top.

Contact

如有任何隐私问题,请发送邮件至 hello@amble.dog

Questions, requests, or anything at all: hello@amble.dog.

Full technical details

For people who want the specifics, here's the fuller inventory.

What we store, by area:

  • Account (users): email, email preferences, verification, language, timezone, sign-in identity, and pause state. If you subscribe: stripe_customer_id, stripe_subscription_id, subscription_status, current_period_end, plan, and plan_changed_at. A separate append-only plan_change_events table keeps a billing audit trail (from/to plan, Stripe event id). No card data is stored anywhere on our side.
  • Dogs (dogs): name, sex, neuter status, date of birth, adoption ("gotcha") date, breed, optional city-level location, an optional photo reference, and what you're working on.
  • Your inputs: daily notes (dog_notes), check-in feedback, and saved cards.
  • Generated content: daily cards, the evolving memory Amble builds about your dog (dog_memories, plus a warm prose summary), and weekly reflections.
  • Product events (analytics_events): limited operational events (e.g., a card was served, a generation failed). By design these contain no free text and no personal information.
  • Signed-out page counts (anon_funnel_counts): one integer per event name per day. The table has no column capable of holding anything about a visitor — no address, no identifier, no text — and the set of event names is a closed list that fails our build if any code tries to emit a name outside it.

AI. Model calls go to Google Gemini, either through our AI gateway (ai.gateway.lovable.dev) or directly to Google's API. One call — the safety check that decides whether something you describe needs a vet or trainer referral — goes to OpenAI instead. Every model identifier the product can send is declared in one file in our source, and our build fails if any code names a model anywhere else. Card prompts include your dog's profile and recent context; they exclude your email and your dog's photo.

Family viewer scope. A shared viewer receives an explicit allow-list of fields — the dog's profile basics, photo, breed, temperament and memory summary, what you're working on, the caretaker paragraph (Premium) — plus the cards, history, and weekly reflection. Owner notes (dog_notes), the raw memory ledger, location, feedback, and every account and billing field are deliberately excluded, and are never even queried on the viewer path.

Retention. Trashed cards: 30 days. Inactive anonymous accounts: 90 days. Dormant pause: about 21 days (a pause, not a deletion). Dog photos in the off-site backup after deletion: 30 days.

Subprocessors. Supabase, Cloudflare, Lovable (AI gateway + email), Google (Gemini + OAuth), Stripe, Cloudflare R2 (encrypted off-site backup of dog photos only).

An honest caveat. The inventory above is checked against our database schema in automated tests. That verifies the shape of what we store; it does not, by itself, prove that every code path only ever writes to the fields listed — that remains an engineering responsibility we take seriously.

The cookie and browser-storage list is checked the same way: a test scans our source for anything written to your browser and fails the build if a key isn't declared in the same inventory this page is written from. Same caveat applies — it verifies that nothing is stored undisclosed, not what any given value contains. One gap worth naming: that scan can only see our own code. Values written by an outside library — the sign-in session above, the scroll position — are declared by hand after reading a real browser's storage, so they're listed here but not machine-checked.