Furry-built app
A fursuit-catching game for conventions, like Pokemon Go for the fandom.
No take yet. Send us yours.

Early on 12 July 2026, TailTag's developer, Finn the Panther, posted a blunt warning to his own users: "TailTag has been compromised. Please disable notifications from the app or uninstall." The post went out at roughly 03:20 UTC and was the first anyone outside the project heard of it.
About six hours later he narrowed the claim. In a second post he said TailTag accounts were not compromised, that "neither emails, passwords, GPS data, nor account access tokens were visible," and that the attacker had used their own account to exploit a vulnerability in the external push-notification service the app relies on rather than in TailTag itself. He promised more detail the following day.
For a day it was not tidy. Later the same day another furry developer, Minty, published a contradictory PSA: that the email address and other metadata of TailTag users had been exposed, and that the account data of roughly 9,200 users was still publicly reachable "without any form of authentication." The two accounts of the incident could not both be right.
On 13 July, Finn published a closing statement and a full written postmortem (incident reference TT-SEC-2026-01), and it is the document we asked for: it says plainly what was reachable and what was not, and it confirms the substance of Minty's finding rather than the early reassurance. A signed-in TailTag user could retrieve other users' complete account records, and those records included email addresses, usernames and profile details, internal account identifiers, device push-notification identifiers, and account and settings metadata (including some age, permission, and moderation information). Because the logs cannot show exactly which records were viewed, the postmortem treats all TailTag accounts as potentially affected.
It is equally plain about what was not exposed: passwords and sign-in credentials, login sessions and recovery codes, payment information (none was ever collected), and precise or live GPS locations.
The unauthorized push notifications that started the incident connect to the same weakness: the exposed records included the identifiers used to route notifications, and an extra security requirement at the notification provider had not been enabled, so possessing an identifier could be enough to send a notification directly. The root cause was overly broad access to account records, not cracked passwords.
This was not a temporary pull. Per the postmortem's own timeline, by the evening of 12 July the developer had locked down account records, revoked the notification credential, taken the app offline, disabled network access from installed clients, and replaced the public website with an account-deletion process. TailTag "in its current form is being shut down, and its user data is scheduled for deletion," with notifications to privacy authorities (including GDPR where applicable) being completed.
Our own checks agree with the app's withdrawal: as of 21 July 2026 the App Store and Google Play listings both returned 404 and playtailtag.com no longer resolved in DNS. There is nothing left to install. The planned deletion may reduce data retained by the service, but it cannot erase copies that may already have been retrieved.
We pulled TailTag's recommendation and its install links while the exposure was still being argued about in public, and with the app now shut down this page stays as a historical record rather than a listing you can act on.
This page records the confirmed incident and response without judging the developer or the underlying idea. The postmortem names the design mistake, corrects the early reassurance, documents the response timeline, and states that the weaknesses were preventable. It says user-data deletion is scheduled; this profile does not treat that process as completed.
Our earlier condition was a published post-mortem that says plainly what was reachable, for how long, and for how many accounts, with Minty's finding confirmed or refuted. That condition has now been met, and honestly so. But there is no listing to restore: TailTag in its current form is gone by its developer's own decision. Finn has said any rebuild would need a new security design separating public profile data from private account data, and a rebuild interest group exists. If a rebuilt TailTag ever ships, we will evaluate it fresh on its own security posture, and this page's history will be part of that evaluation.
TailTag is a real-world fursuit-catching game for furry conventions, built by the Seattle creator Finn the Panther. The pitch is "a cross between Furries and Pokemon Go": you spot a fursuiter on the convention floor, snap a selfie to log a catch, and the app hands you that suiter's profile card.
The profile is the clever part. Each catch shows the suit's species, colors, pronouns, likes and interests, and a single "ask me about" prompt the owner wrote themselves, so you always have something to say. On top of that sits a game layer: catch photos, daily tasks, achievements, and per-convention leaderboards. It is built to solve a real problem, walking up to a stranger in a full fursuit is intimidating, especially for newcomers, and TailTag turns that approach into a low-stakes game with a built-in conversation starter.
TailTag's public materials presented it as an independent app. They did not document a relationship with a convention-run catch game, so this profile does not attribute the concept to a specific event.
Guides and conventions connected to TailTag.