Privacy
Last updated 2026-09-13
Your litter is saved in this browser, on this computer — it is not uploaded and we never see it. That also means it is yours to look after: export a backup file and keep it with your other kennel records.
There are no accounts on this site, no password to lose and no database of users. What follows is the complete list of what happens to data, in the order you are likely to encounter it.
Your litter
Everything you type into the editor — the dogs, the pedigree, the weights, the health and socialization events, the photographs, the microchip numbers and the new families’ names — is written to your browser’s own storage on the device you are using. It is not sent to us, and we have no way to read it. There is no server-side copy, because there is no server holding litters at all.
The packets are made on your device too. Building a PDF happens in your browser, so the finished file exists on your machine before it exists anywhere else, and it is never uploaded. What the new family receives is whatever you choose to send them.
The QR code on the wallet card is generated on your machine from the contact block you typed. It is not a link to anything we host: nothing is looked up when someone scans it, so it works offline, it tells us nothing, and it will keep working if this website does not.
The honest cost of this. A litter lives in one browser on one computer. It does not follow you to a tablet, and clearing your browser’s site data for this site deletes it permanently — we have no copy to restore from, because we never had one. The editor writes a backup file with the photographs embedded whenever you ask for one, and tells you when you have changes that are not in a backup yet. Use it.
Visiting the site
Pages are static files. The host records ordinary web server logs — IP address, user agent, which page — which is unavoidable and is how every website on the internet works.
Analytics are Google Analytics 4, and the tag is not loaded until you interact with the page: move the pointer, scroll, tap or press a key. A visitor who arrives and leaves without touching anything is never counted, and never has a request made to Google on their behalf. It records which page was viewed. It has no access to anything you type into the editor, because nothing you type into the editor leaves the page.
Bringing in files you already have
A spreadsheet you bring in is read on your own computer and is never uploaded. What is sent, and only when you press the button, is the row of headings and three sample rows from it, so that the column called “Chip #” can be matched to the microchip field. The rest of the sheet — every name, every buyer, every number in it — is read by your browser and goes nowhere.
A photograph is the one exception on this whole site. When you pick a vaccination card, an invoice or a registration page, that page is sent to Cloudflare, read, and the words come back for you to check. Only the pages you picked are sent, one at a time, and nothing else in your litter goes with them — not the puppies, not the buyers, not the other photographs. There is no folder upload and never will be, so nothing goes that you did not choose file by file.
Being exact about what “that page is sent” means, because handwriting is hard and one look at it is often not enough: a page may be sent up to four times — a small copy of the whole page, the page itself once or twice, and, where a line is hard to make out, a close crop of that one line. They are all the same page you picked, they go to the same place, and no more than that go for any one page however it turns out. Cloudflare states that it does not keep or train on what is sent to be read, and we store no copy. If you would rather nothing left your machine at all, do not pick any photographs; every field they fill can be typed in by hand, and the packet is identical either way.
Nothing read from a file is written into your litter until you have seen it in a table and confirmed it, which is there for accuracy as much as anything else: a microchip number read off a photograph is exactly the kind of thing that needs a human to look at it twice.
One thing to be exact about, because this page’s job is being exact. Reading your paperwork is part of what a litter pass pays for — the first three pages are read for nothing and a pass reads the rest of that litter’s — so once you have bought one, a document you send to be read travels with the code of that purchase attached — the code Stripe issued, and nothing else about you. That is the only way to keep the cost of reading documents with the people who paid for it rather than with whoever points a script at the site. It does mean that on this one path, and nowhere else on this site, a request can be connected to a purchase. The document itself is still not kept, and how many documents a pass has read is counted in your own browser rather than on our side. Before you buy anything, there is no code to attach and none is attached.
The contact form
What you type is emailed to us and nowhere else. It is not stored in a database, because there is no database. Your address is used to reply to you and is not added to any list.
The form is protected by a signed token rather than a CAPTCHA, so nothing about you is sent to a third party to prove you are human.
One request: if you are reporting a problem, describe the field rather than sending a screenshot or a backup file containing a buyer’s name or address. It keeps their details out of an inbox they never agreed to be in.
Paying
Payment is handled entirely by Stripe. Card details are entered on Stripe’s own page and never touch this site — we never see a card number, and there is nothing here for a card number to be stored in.
A litter pass is tied to a fingerprint of the dam’s name and the whelp date, and that fingerprint is what is stored against the Stripe payment. It is the only thing about your litter that leaves your machine, it goes to Stripe rather than to us, and it exists so that a pass can be checked against the litter it was bought for. No puppy names, no buyer details, no photographs and no records are sent with it.
For the kennel year, a licence key is derived by signing your Stripe customer id. It is not stored on our side at all: the same customer always produces the same key, which is why a lost key can be re-issued without us keeping a record of it. Checking a key asks Stripe whether the subscription is still live.
Stripe tells us the email address you paid with, and it is used to send you one message and nothing else: your licence key for the kennel year, or the code for your litter pass. Neither is kept here — the key is re-derived from your Stripe customer id each time, and the pass code is the identifier Stripe itself gave the payment. There is no mailing list, and nothing else is ever sent to that address.
On your side, a few small things are kept in this browser so you are not asked to paste them again: the code identifying your litter pass, your licence key if you have one, a short-lived note saying the pass has been checked — so that reading a stack of paperwork does not ask Stripe about it once per page — and a count of how many documents have been read. None of them is your litter, and none is sent anywhere except back to Stripe to ask whether the purchase is still good, which is checked every time. Nothing stored here grants anything on its own. Clearing this site’s data removes all of it, which is why the page that confirms a purchase asks you to keep the code, and why a copy of it is emailed to you: pasted back in, it restores the pass on any computer.
A backup file includes the code for any pass covering the litters in it, so restoring on a new computer brings back the purchase along with the work. It does not include your licence key, which covers every litter you will ever have and would be the wrong thing to put in a file that gets emailed about.
Third parties, in full
- The host — serves the pages, and keeps ordinary web server logs of which page was requested from which IP address.
- Stripe — takes the payment and is the record of who has bought a pass. It is told the fingerprint of the litter a pass is for — the dam’s name and the whelp date — and nothing else about your litter.
- Cloudflare — reads the one page you photograph when you ask for it to be read, and matches up the column headings of a spreadsheet you bring in. It is sent that single image, or a sheet’s headings and three sample rows — never the whole spreadsheet, and never your litter. Once you have bought a pass, the code of that purchase goes with a document so that the cost of reading it stays with the people who paid; nothing else about you does. Nothing is sent unless you press the button.
- Resend — sends the contact-form email, and the one email a purchase sends — your licence key for the kennel year, or the code for your litter pass.
- Google Analytics 4 — counts page views — on every page including the editor, and only after your first interaction with the page. It is told which page was viewed, not what you typed into it.
There are no others. No advertising pixels, no session recording, no chat widget and no font CDN. None of them is sent your litter; the one page you can choose to have read is described above, and it is the only thing you have typed or photographed that ever leaves this browser.
Your data
Since there is no account, there is very little for us to hold and therefore very little to ask for. Your litter is already yours and only yours. If you want to know what Stripe holds against your purchase, or want the contact-form email deleted from the inbox, ask and it will be done.