Paw & Story — Privacy Policy
Version 1.7 — Effective: 2026-09-02
Your photos and memories are yours. This policy explains, plainly, what we collect, how we keep it safe, and how you stay in control.
1. Who is responsible
The data controller is Egységmester Kft. ("we"), registered seat 2330 Dunaharaszti, Gyóni Géza köz 8., Hungary; company reg. no. 13-09-162959, registry court: Budapest Környéki Törvényszék Cégbírósága; EU VAT no. HU24291608; represented by Antal Mátyás. Contact: hello@pawandstory.com. Our hosting provider, acting as a processor, is Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus, serving from an EU data centre. Our supervisory authority is the NAIH (naih.hu).
The Service is for adults. You must be 18 or over to create an account, upload photos, or buy a tribute. We do not knowingly collect personal data from children; if you believe a minor has used the Service, write to us and we will erase the data.
2. What we collect
- Photos and videos you upload of your pet (your own content, with your consent, and with the consent of any people who appear in them).
- The answers you provide in the questionnaire.
- Basic account and purchase records (email, order details). Payment is processed through Stripe Managed Payments; the seller and merchant of record is Sold through Link, LLC (a Stripe company), while Stripe Payments Europe, Ltd. acts as the payment processor. We never receive or store your card data.
- Technical error data. To find and fix faults, your browser sends us the address of the page you were on and technical details of any error (browser type, and where in our code the error happened) for errors and for roughly one page view in ten. Before it leaves your browser we strip out tokens, cookies, request contents and the values of program variables, and we never record your screen. See Section 6.
- If a memorial page is public, anyone who has the link can leave a short written memory on it. The words they write and the name they choose to sign it with are their personal data, and we hold them. Section 9 sets out the full account.
3. Why and on what legal basis
- To create and deliver your memorial book, tribute film, and memorial page — performance of a contract (GDPR Art. 6(1)(b)).
- To keep purchase records where the law requires it — legal obligation (Art. 6(1)(c)).
- To answer your messages and keep the Service secure — legitimate interest (Art. 6(1)(f)), balanced with care given the sensitive moment these orders often come at.
- To keep the site working by diagnosing technical errors — legitimate interest (Art. 6(1)(f)). We minimise this to what a fault report needs (see Section 2) and you can object at any time.
Other people who appear in your photos. A family photo may show people other than you, and we then process their images without having collected anything from them directly (GDPR Art. 14). We do this to perform our contract with the person who ordered the tribute (Art. 6(1)(b)) and on our legitimate interest in producing the keepsake they asked for (Art. 6(1)(f)); the safeguard is that the customer warrants to us, in our Terms, that they have the consent of everyone pictured. Their images come from the customer's own upload, are used only to make that one tribute, are shown to nobody else unless the customer makes a memorial page public, are never sent outside the EU, and are never used to train any model. They are deleted on the schedule in Section 5. Anyone who appears in a photo has the rights in Section 7 — including the right to object and to ask for erasure — and can exercise them by writing to hello@pawandstory.com. Because we hold no contact details for them, we cannot notify them individually; this policy serves as that notice.
We do not use your uploads or answers for advertising, and we never sell your data.
4. How we store it
- S3-compatible object storage that we run ourselves, on our own server in the EU (Frankfurt, Germany) — not a third-party cloud bucket.
- The storage is not exposed directly to the internet, and its contents cannot be listed publicly.
- Every file travels over an encrypted HTTPS connection.
- Served only through short-lived, signed links issued for a single request — never from a public or guessable URL.
- We never use your uploads to train any model.
- Every image in your tribute is a real photo you uploaded. There is no image generation anywhere in the Service — we do not generate, recreate, or synthesise pictures of your pet.
How the words and the music are made. The story text in your book and film is composed by an AI language model provided by OpenAI (see Section 6) from the answers you typed, and is then checked automatically so that no sentence states a fact you did not give us. Your photos are never sent to OpenAI or to any other AI provider — only your written answers are. The background music is AI-generated instrumental music we prepared in advance and serve from our own servers; making it involves no data about you or your pet.
5. Retention
- Files: 90 days. An automated sweep permanently deletes the photos and videos you uploaded and the generated book PDF and tribute film 90 days after delivery. Please download your book and film and keep your own copies — they are yours for life, but our servers only hold them for those 90 days.
- The one exception: a public memorial page. Your memorial page is private by default. If you choose to make it public, the files behind that project are kept for as long as the page stays public. A private page does not postpone the 90-day deletion.
- What the sweep does not cover. The 90-day sweep deletes files. Your questionnaire answers, the story text, your pet's details, and your account record (your email address) are not part of it — we keep them until you erase them yourself, so that your account and order history still make sense to you.
- Erasing everything. Use /account/delete: we email a confirmation link to verify it is you, and when you click it we permanently delete your uploads, your generated book and film, your memorial pages, your questionnaire answers, the story text and your pet's details. You can also email hello@pawandstory.com and we will do it for you.
- Backups — and what deletion means for them. Every night we back up the whole service (database, uploaded files, and generated files). The off-site copy is encrypted before it leaves our server and is held for up to 30 days, then automatically and permanently purged; a separate 3-day working copy sits unencrypted on our own EU server, readable only by the server administrator account, and is deleted after 3 days. When you erase something — by the 90-day sweep or by an erasure request — we delete it from our live systems straight away. A backup is a frozen snapshot that cannot be edited after the fact, so copies made before the deletion simply age out of that 30-day window and are then gone. Backups exist only to restore the Service if it fails, and are not read, searched, or used for anything else while they wait. A ledger of erased accounts is captured with every backup; if we ever had to restore from a backup, re-applying every one of those erasures to the restored copy is a required, written step of our restore procedure, done before that copy goes back into service.
- The purchase record survives erasure — honestly described. Hungarian accounting law requires us to keep the record of your purchase for 8 years. So after erasure we retain the amount, the date and the payment reference held by Stripe, and we keep the underlying account row that the record attaches to. We replace your email address with a non-deliverable placeholder (erased-…@deleted.invalid) and delete your Stripe customer identifier. We want to be exact about what that does and does not achieve: this is pseudonymisation, not anonymisation. The payment reference can still be traced back to you inside Stripe's own systems, so the record is not fully anonymous. GDPR Article 17(3)(b) permits this where retention is necessary to comply with a legal obligation.
- Memories left by visitors. These follow their own rule, which depends on whether the memorial page stays public. Section 9 sets the rule out in full.
6. Who receives data
- Stripe Managed Payments — Sold through Link, LLC (a Stripe company), the seller and merchant of record, concludes the sale, charges you, issues your invoice or receipt, and determines and remits any applicable VAT/sales tax; Stripe Payments Europe, Ltd. acts as the payment processor (checkout, invoicing, tax, refunds).
- EU hosting and storage — Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus, acting as a processor under a GDPR Art. 28 agreement, serving from an EU data centre.
- AI text provider — OpenAI Ireland Ltd (Ireland). The answers you write in the questionnaire are sent to OpenAI to compose the story text for your book and film. OpenAI receives your written answers only — not your photos, not your email address, and not your payment details. Our contract is with OpenAI Ireland Ltd, an Irish company, which acts as our processor under a data-processing agreement concluded under Article 28 GDPR. OpenAI does not use data sent through its interface to train or improve its models, and deletes it within 30 days.
- Onward transfer to the United States. To provide that service, OpenAI Ireland Ltd passes this text to its affiliate OpenAI OpCo, LLC in the United States. That transfer takes place under the European Commission's standard contractual clauses of 4 June 2021 (Decision 2021/914), a lawful transfer mechanism under Article 46(2)(c) GDPR. OpenAI is not certified under the EU–US Data Privacy Framework, so we do not rely on it. Write to hello@pawandstory.com and we will send you a copy of the standard contractual clauses and of our data-processing agreement.
- Error monitoring — our own GlitchTip. The technical error data in Section 2 goes to a GlitchTip instance at errors-c7f31a.practicalapps.studio that we run and control ourselves, on our own infrastructure. It is not a third-party analytics or advertising service, and no error data is shared with anyone else.
Your photos never leave the EU/EEA. They are not sent to OpenAI or to any other provider outside the EU. The only routine transfer outside the EU/EEA is the onward transfer of the questionnaire text described above — made by our Irish processor, not by us — plus whatever Stripe processes to take your payment under its own terms. If any further transfer ever became necessary, it would rest on an adequacy decision or standard contractual clauses, and this policy would be updated first.
7. Your rights
Under the GDPR you have the right of access, correction, deletion, restriction, objection, and portability, and the right to withdraw consent at any time. You can exercise your right to erasure yourself at any time from /account/delete. Erasure takes effect on our live systems straight away; Section 5 explains how it reaches our backups. For anything else, write to hello@pawandstory.com and we will respond within one month. You may also lodge a complaint with your local supervisory authority (in Hungary: NAIH — Nemzeti Adatvédelmi és Információszabadság Hatóság, naih.hu).
If you left a memory on someone's memorial page. Section 9 explains how to have it removed. We are the controller for what visitors leave, so the request comes to us and not to the person whose page it sits on.
8. Cookies and analytics
We set no cookies at all, and we run no analytics product, no advertising pixel and no third-party scripts — not on the site and not on memorial pages. What we do store in your browser is small, and this is the whole of it:
- paw_owner_… (local storage) — written when you create a tribute. It holds a random key that proves this browser made that tribute, so you can reopen it. It is strictly necessary: without it the site could not deliver what you asked for. Local storage stays in your browser until you clear it.
- paw_memorial_… (local storage) — written on your own delivery page, the page you reach through the link we email you after payment, and written again when you turn sharing on for that memorial page. It holds only the tribute's number, so that when you later open your own memorial link the page can recognise it as yours and show you the memories left there and your moderation controls. It is never written for an ordinary visitor browsing a memorial page. It is also strictly necessary.
- fp_utm (session storage) — written only if you arrive on a link that carries campaign labels such as utm_source or ref. It stores only those labels from that link, each cut off at 255 characters, so we can tell which advert or link brought someone here. It holds no identifier, builds no profile, is never sent to a third party and is never used across other websites. It is not strictly necessary: it serves our campaign attribution, not something you asked for. Session storage disappears on its own the moment you close the tab.
- paw_fb_purchase_… (local storage) — not written today. It would exist only as a de-duplication marker so that a purchase is not counted twice by Meta's advertising measurement, and only if an advertising pixel were configured. No pixel is configured, so no pixel loads and this entry is never created. If we ever switched Meta advertising measurement on, we would ask for your consent first and update this policy before doing so.
You see no consent banner because we run no analytics product, no advertising pixel and nothing that follows anyone across websites. Our Cookie Policy sets this out in full, including Stripe's own cookies on its payment page.
9. Memories left on a memorial page
A memorial page can be public or private. While it is public, anyone who has the link can leave a short written memory. A memory contains the words the visitor writes, at most 1000 characters, and a name to sign it with, which is optional and at most 80 characters. It contains nothing else. There is no visitor account.
We store no email address and no IP address for visitors. The database table has no column for either. To stop a flood, the server holds the sending IP address briefly in memory — never written to disk and never written to the database — for a one-minute counting window, and then discards it. If a memory contains a link, an email address, or a web address, we refuse it and tell the sender why, rather than silently editing their words.
Nothing appears on the page until the page owner approves it. A memory that passes our automated check is stored when it is sent, but it is invisible to everyone until the owner approves it; a refused submission is not stored at all. The owner can approve or delete any memory at any time, and we can remove anything ourselves.
Who is the controller. Egységmester Kft. (Paw & Story) is the controller for what visitors leave. We determine the purposes and the means: which fields exist, the limits, the content rules, how long a memory is kept, where it is stored, how it is secured, and how it is deleted, and we can remove anything ourselves. The page owner's decision is whether one particular memory is published on their page. Because that decision determines publication, a supervisory authority or a court could instead treat the owner as a joint controller for that publication, on the reasoning of cases such as Wirtschaftsakademie (C-210/16) and Fashion ID (C-40/17). We do not leave a visitor caught between us. Whichever way that question is answered, we answer data-protection requests about a memory: we will not send a visitor to the page owner, and we do not ask a grieving pet owner to handle a stranger's request. Under Article 26(3) of the GDPR, a person may in any event exercise their rights against each controller, so nothing here narrows anyone's rights. This is stated so a visitor knows exactly who to write to, and neither of us can point at the other.
Legal basis. We publish a visitor's name and words on the basis of GDPR Article 6(1)(f), legitimate interests. The interest is letting people who knew the animal, and its person, leave a message on a memorial the owner chose to open. The balance comes out this way because the visitor wrote the words deliberately, for publication, and was told before sending that the owner decides whether they appear. The safeguards are the argument:
- Nothing appears until the page owner approves it.
- The name is optional.
- We ask for no email address and no IP address.
- A memory comes down when the page owner deletes it or when someone asks us to remove it, in the way described below that identifies the memory.
You have the right to object to this processing under Article 21 of the GDPR.
How long we keep a memory. Every memory carries a 90-day clock that starts the day it is left. While the memorial page stays public, the nightly clean-up skips it. In practice, a memory stays for as long as the page stays public. The page is the thing people come back to, and deleting its memories on a timer would empty the very thing it exists to hold.
If the page is switched back to private, nothing is deleted at that moment, and the page immediately stops being readable by anyone. But that protection ends. The memory is then deleted at the next nightly clean-up if its 90 days have already passed, and otherwise when those 90 days run out. Switching the page public again before that restores the protection. Switching to private does not reset the clock: it runs from the day the memory was left and is never reset.
A memory left with nothing in it — no words and no photograph — is removed whatever the page's setting. If the customer erases their account, or the memorial page is deleted, every memory on it goes with it. We check afterwards that they really are gone and record it if any survived, rather than assuming.
Getting a memory removed. There are two routes. The page owner can delete any memory on their page themselves, immediately. Or you can write to hello@pawandstory.com. Because we store no email address for visitors, we cannot look a memory up by who sent it. Your request has to identify it another way: which memorial — the link, or the pet's name — and enough of the words to find it. We hold nothing to check a requester's identity against, so we act on a request to take a memory down rather than investigating who is asking: taking it down is the direction that can only reduce harm. We do it without undue delay and confirm when it is done, if you have given us a way to reply.
The moderation record. When a memory is deleted, we keep a short operational record that a deletion happened: which memorial page and which memory number, whether it came from a visitor or from the owner, whether it had been approved, and when. The record deliberately carries no words and no name. The text we refused to publish is not kept anywhere, and the record is not a second copy of it. The legal basis is Article 6(1)(f): our legitimate interest in being able to show that our moderation is real and to answer a complaint or a regulator.
10. Reporting illegal content
There is a report form at /report. Because we host what other people write, we are a provider of hosting services under Regulation (EU) 2022/2065, the Digital Services Act, and Article 16 of it requires that mechanism. Anyone may use it. A report of child sexual abuse material may be sent without a name or an email address, because Article 16(2)(c) excepts that case; where the sender omits both, we record nothing about who sent such a report.
Where a report carries an email address, we send confirmation of receipt without undue delay and tell the sender what we decided and how to challenge it; because email can fail, anyone who does not receive a confirmation can write to us quoting the reference the form gave them. A person assesses every report. No decision is automated.
11. Changes
If this policy changes in a way that matters, we will post the new version here with a new effective date and, for significant changes, let you know by email.