Security Information

Last Updated • July 10, 2026

Effective Date: July 10, 2026
Your pet's health records are stored on our servers and tied to your account. This page sets out how that data is protected in transit, at rest, and behind access controls.

1. Account Security

Accounts are managed through Google Firebase Authentication. You can register with an email address and password, or sign in with Google. Passwords are handled by Firebase and are never stored by us in readable form.

PawDex supports optional two-factor authentication using a one-time code, which adds a second check when signing in.

2. Access Controls

Every endpoint on the PawDex backend requires an authenticated session. Requests are checked against your account before any record is read or written, so one account cannot reach another account's pets, records, or uploads.

3. Data in Transit and at Rest

All communication between the App and our backend runs over HTTPS. Your records are stored in Google Firebase, and uploaded images and documents are stored with Cloudinary. Both encrypt data at rest as part of their platforms. Our Privacy Policy lists these providers in full.

4. On-Device Cache

The App keeps a local copy of recently viewed records so it stays usable without a connection. This cache is a copy for performance and offline access, not the primary location of your data, and it is not separately encrypted beyond the protection your device's operating system applies to app storage.

5. Advertising and Tracking

PawDex does not include any third-party advertising SDKs, and we do not sell your personal information.

6. Vulnerability Disclosure

Please report any vulnerabilities to our security team at support@welltide.app.