Privacy Policy
Last updated: 22 September 2026
This Privacy Policy explains how ALIS SARL ("we", "us") collects, uses and protects personal information when you use Sniffari, its pet and travel features, AI assistant, or account and sign-in service (the "Service").
Please read this Policy together with our Terms of Service.
1. Who is responsible for your information
Responsible party / data controller
ALIS SARL
43, Bd Prince Henri
L-1724 Luxembourg
Luxembourg société à responsabilité limitée, RCS Luxembourg B267285, incorporated on 14 April 2022
Privacy contact
Privacy contact
jan@alisx.com
If you are in the European Economic Area (EEA) or the United Kingdom, ALIS SARL is the "controller" of your personal data under the General Data Protection Regulation (GDPR) and the UK GDPR. If you are in South Africa, ALIS SARL is the "responsible party" under the Protection of Personal Information Act (POPIA). You can direct privacy requests to the contact above.
2. What information we collect
2.1 Information you give us
Your email address and name are necessary to create an account; without them we cannot provide the Service. Everything else in this section is optional.
| Category | Details | Required? |
|---|---|---|
| Account identity | Email address, given name, family name | Yes |
| Profile | Profile picture, contact number, position, education, LinkedIn profile URL | Optional. You can edit or remove these on your profile page |
| Developer apps | App names, logos, redirect URLs and scopes you register; personal API keys you create | Only if you use developer features |
| Consent decisions | Which applications you have allowed to access which scopes | Recorded when you approve or decline an app |
2.2 Information from identity providers
When you sign in with Google, Microsoft, LinkedIn or Apple, that provider sends us your verified email address, your name, your profile picture where available, and a stable identifier for your account with them. We do not receive your password for that provider, and we do not receive any information beyond what is needed to identify you unless you separately connect an integration (see 2.4).
When you sign in by email, we send a one-time sign-in link to the address you enter.
2.3 Information we collect automatically
Each time you sign in, refresh a session or use the Service we record:
- Sign-in and activity times: when you last signed in and when your session was last refreshed.
- Session records: an identifier for each signed-in browser or device, the application it signed in to, the scopes granted and when the session expires.
- Network and device information: your IP address, the browser or app you used (the "user agent" string) and the time of the request. We record these against your sign-ins and sessions so that unusual or unauthorised access can be detected and investigated.
- Cookies: see section 8.
- Technical logs: request logs generated by the platform we run on. These may include your IP address, user agent, the pages or endpoints you called, error details and, for authenticated requests, your account identifier.
2.4 Integrations you connect
If you connect a third-party integration (for example a calendar, mail or CRM provider) through your account, we store the access credentials that provider issues so the connected application can act on your behalf. Those credentials are encrypted at rest, and you can revoke them at any time from the Integrations page.
2.5 Information about administrators' actions
Administrators may block an email address or application. We record the blocked subject, the reason given and which administrator added it.
2.6 Sniffari journeys, pets, nearby discovery and conversations
Sniffari uses the pet profiles and pictures you provide, your preferences, journey destinations and stops, reviews, passport information, and optional outing records to provide its travel features. Shared pet profiles remain accessible to their other owners. Passport sharing and nearby discovery expose the information described on their consent screens to the people or venues you choose.
Location is optional. When enabled, we process coordinates, accuracy and observation time to find nearby places and support journeys. Nearby discovery and route recording are separate choices. Raw recorded routes are private to their owner and retained for up to 90 days. Live presence expires when its sharing session ends or its freshness window expires.
With your permission, Google AI also analyses the pet photo you select to suggest a breed.
Before you start the AI assistant, the app asks permission to send your messages, selected pet information and relevant journey/location context to Google Vertex AI (Gemini). When you enable voice, microphone audio is sent to Google's live AI service; conversation text and transcripts may be saved with your account. Conversation history and generated memories support later conversations and are included in account deletion. Do not include information you do not want processed for this purpose. AI suggestions can be inaccurate; verify venue policies and travel conditions yourself.
Apple processes in-app subscription payments. We receive transaction identifiers, subscription status and expiry, product information and a random purchase identifier bound to your Sniffari account. We do not receive your payment card details from Apple. Website payments are processed by Stripe, which supplies customer and subscription references and payment status.
3. Why we use your information and our legal basis
| Purpose | Information used | Legal basis (GDPR / UK GDPR) | POPIA justification |
|---|---|---|---|
| Creating and operating your account; signing you in; issuing and refreshing tokens | Account identity, identity-provider data, session records, cookies | Performance of a contract (Art. 6(1)(b)) | Necessary to carry out a contract (s 11(1)(b)) |
| Showing the applications you have signed in to what they need (your identity claims and the scopes you approved) | Account identity, profile, consent decisions | Performance of a contract (Art. 6(1)(b)) | Necessary to carry out a contract (s 11(1)(b)) |
| Keeping the Service secure: rate limiting, detecting credential theft and replay, blocking abusive accounts and apps, investigating incidents | Network and device information, session records, technical logs, administrators' actions | Legitimate interests (Art. 6(1)(f)) in protecting the Service and its users | Legitimate interests of the responsible party and users (s 11(1)(f)) |
| Sending sign-in emails | Email address | Performance of a contract (Art. 6(1)(b)) | Necessary to carry out a contract (s 11(1)(b)) |
| Connecting an integration on your behalf | Integration credentials | Consent (Art. 6(1)(a)), which you may withdraw by revoking the integration | Consent (s 11(1)(a)) |
| Optional profile fields | Profile | Consent (Art. 6(1)(a)), withdrawn by clearing the field | Consent (s 11(1)(a)) |
| Complying with legal obligations and responding to lawful requests | Any of the above, as required | Legal obligation (Art. 6(1)(c)) | Obligation imposed by law (s 11(1)(c)) |
Where we rely on legitimate interests, we have balanced those interests against your rights and concluded that the processing is proportionate: it is limited to security data, is what users of a sign-in service reasonably expect, and is subject to the retention limits in section 6.
We use travel, pet, location and conversation information to provide the features you request, on the basis of our contract with you. Optional location sharing and AI processing require your choices in the app; you can stop using those features and revoke device permissions at any time.
We do not sell your personal information or use it for advertising. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
4. Who we share your information with
Applications you sign in to. When you sign in to an application through the Service, that application receives the identity claims it is entitled to (typically your account identifier, email address, name and profile picture) and access limited to the scopes you approved on the consent screen. Each application is responsible for its own use of that information under its own privacy policy.
Identity providers you choose. Signing in with Google, Microsoft, LinkedIn or Apple sends the sign-in request to that provider under its own privacy policy.
Service providers. We use the following providers to run the Service. Hosting and AI providers process information under our service agreements. Apple and Stripe also process purchase and financial information for their own purposes under their privacy policies.
| Provider | Purpose |
|---|---|
| Google Cloud (Cloud Run, Cloud Spanner, Cloud KMS, Cloud Logging, Cloud Trace) | Hosting, database, encryption keys, logs and diagnostics |
| Google Vertex AI / Gemini | AI planning, live voice, conversation history and memories |
| Apple App Store | In-app purchases, renewal and refund handling |
| Stripe | Website subscription payments |
| Twilio SendGrid | Delivering sign-in and notification emails |
Google Groups (if enabled by your administrator). An administrator may configure the Service to add users to a Google Group, in which case your email address is shared with Google Workspace for that purpose.
Legal and safety. We may disclose information where required by law, to enforce our Terms, or to protect the rights, property or safety of users, the public or ourselves.
Business transfers. If ALIS SARL is involved in a merger, acquisition or asset sale, your information may be transferred as part of that transaction, subject to this Policy.
5. International transfers
The Service is hosted in South Africa (primary hosting); Belgium (europe-west1) for AI conversation sessions and memories. Our service providers may process information in other countries.
Where personal data protected by the GDPR or UK GDPR is transferred outside the EEA or the UK, we rely on an adequacy decision or on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable). Where personal information protected by POPIA is transferred outside South Africa, we do so only under the conditions in section 72 of POPIA, including binding agreements that provide substantially similar protection.
6. How long we keep your information
Each row gives two facts: when the information stops being usable, and when the record itself is removed. Removal is automatic and usually completes within 3 days of the stated period.
| Information | Usable until | Record removed |
|---|---|---|
| Account identity and profile | You or an administrator delete the account | Access ends when deletion is accepted; a durable cleanup process retries removal across our services. Copies in encrypted database backups expire within 30 days |
| Access tokens | 5 minutes after issue | Not stored; the token is self-contained |
| Authorisation codes and sign-in flow state | 10 minutes after issue, or first use | 1 day after expiry |
| Signed-in sessions (refresh tokens), including the IP address and user agent recorded against them | The session expires (by default 7 days from the last sign-in, as configured by your administrator), is signed out, or is revoked | 30 days after expiry, so a suspicious session stays investigable |
| Personal API keys | The expiry you chose (by default 90 days, at most 180 days), or you delete the key | 90 days after expiry, so a revoked key still shows as revoked in your console |
| Integration credentials | You revoke the integration or delete your account | 90 days after revocation |
| Consent decisions | You revoke the application's access or delete your account | With the session or account they belong to |
| Blocklist entries | An administrator removes them | Immediately on removal |
| Technical logs | Not applicable | 30 days after they are written |
We may keep information for longer where the law requires it or where it is needed to resolve a dispute or security incident, in which case we restrict it to that purpose.
Account deletion in Sniffari
Choose Your account → Delete my account in the iPhone app and confirm. We disable account access and initiate permanent deletion of your private journeys, conversations, location records, account credentials, private pet profiles and associated uploaded pictures. Shared pets remain with their other owners; your ownership and access are removed. We revoke the stored Sign in with Apple grant. We aim to complete cleanup within 30 days and send a confirmation to your account email. Cleanup retries if a provider is temporarily unavailable; contact jan@alisx.com for its status or assistance.
Deleting an account does not cancel an Apple subscription. Use Manage Apple subscriptions in the app or your Apple Account settings to cancel it. You can proceed with deletion without cancelling first. We cancel website subscriptions during cleanup. Apple and Stripe may retain financial records under their own legal obligations. We retain minimal identifiers that prevent replayed purchases or delayed events from recreating deleted records, and records we are legally required to keep.
7. Your rights
Depending on where you live, you have the following rights over your personal information. We honour them for all users regardless of location:
- Access: obtain a copy of the information we hold about you. Your profile page shows most of it.
- Rectification: correct inaccurate information. You can edit your profile directly; contact us for anything else.
- Erasure: ask us to delete your account and information, subject to the retention rules above.
- Restriction and objection: ask us to restrict processing, or object to processing based on legitimate interests.
- Portability: receive the information you provided in a structured, machine-readable format.
- Withdraw consent: at any time, without affecting processing that already happened. Revoke an integration from the Integrations page, or clear an optional profile field.
- Manage sessions and apps: sign out of individual sessions and revoke applications' access from your account console.
- Complain: lodge a complaint with a supervisory authority. In the EEA this is the data protection authority of your country of residence; in the UK the Information Commissioner's Office (ico.org.uk); in South Africa the Information Regulator (inforegulator.org.za). We would appreciate the chance to address your concern first.
To exercise a right, email jan@alisx.com from the address on your account, or ask your organisation's administrator. We respond within one month (or the shorter period required by local law) and may ask you to verify your identity first. We will not charge a fee unless a request is manifestly unfounded or excessive.
8. Cookies
The Service uses only strictly necessary cookies. They are essential for signing you in and keeping you signed in, so consent is not required for them and there is no cookie banner. We do not use analytics or advertising cookies.
| Cookie | Purpose | Lifetime |
|---|---|---|
access_token |
Proves you are signed in to the account console | 5 minutes |
refresh_token |
Renews your access token so you stay signed in | Your signed-in duration (default 7 days) |
oidc_auth_state |
Ties a sign-in started in this browser to its completion, preventing cross-site request forgery | 10 minutes |
post_auth_redirect_uri |
Returns you to the page you were on after signing in | Until sign-in completes |
All cookies are marked Secure and HttpOnly. You can clear them in your browser at any time, which signs you out.
9. How we protect your information
We apply technical and organisational measures appropriate to the risk, including: encryption in transit (TLS) and at rest; hashing of refresh tokens and API keys so they cannot be read from storage; encryption of integration credentials and application secrets with a managed key service; short-lived access tokens with rotating refresh tokens and reuse detection; rate limiting and blocklisting of abusive traffic; a strict content security policy on all pages; and access to production systems restricted to authorised personnel.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and the relevant authority where the law requires it, and in any event as soon as reasonably possible.
10. Children
The Service is not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child has created an account, contact us and we will delete it.
11. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date at the top shows when it last changed. For material changes we will give you reasonable notice, for example on the sign-in page or by email, before they take effect.
12. Contact us
Questions, requests or complaints about this Policy or our handling of your information:
ALIS SARL
43, Bd Prince Henri
L-1724 Luxembourg
jan@alisx.com
Sniffari support: jan@alisx.com, +27 82 928 4511. Organisation website: www.alisx.com.