Legal

Privacy & Security

How we handle your data, access codes, and payments. Simple and honest.

Your privacy matters. This page explains exactly what data we collect, how we use it, and how we protect it. We keep it simple and honest.

Last updated: 2026-07-29

What Information We Collect

The AI Plant Care Guide collects only the information necessary to provide the service:

  • Access code — a randomly generated credential that links your app profile and saved data. No username or password account is required.
  • Email address — received from Stripe for purchase records and code recovery, provided through Contact Support, or entered for care reminders. Reminder addresses are not used for marketing.
  • Plant profiles — the plant name, pot type, light conditions, soil, and other details you enter. This information is stored linked to your access code.
  • User preferences — your experience level, home environment, pet situation, and care style preferences from your profile form.
  • Saved app content — Generator results saved automatically to My Plans, plant profiles, journal entries, care logs, health status, notes, progress photos, reminder settings, and dates used by Today.
  • Security and abuse-prevention data — request timestamps and keyed, irreversible hashes derived from email, access code, session, or network identifiers. Raw values are not stored in the abuse-control table, and these records are retained for up to 30 days.
  • Reminder email — only if you activate Care Reminders for a plant, we store the email address you provide. It is used exclusively to send you watering, fertilizing, and repotting reminders, and is never used for marketing. You can deactivate reminders at any time from the plant's journal, which stops all reminder emails.
  • Content submitted to AI or support tools — plant details, symptoms, optional notes, uploaded plant photos, AI Help questions, and information you choose to send through Contact Support.

What We Do Not Collect

  • We do not collect your name unless you choose to enter it.
  • We do not collect your physical address.
  • We do not collect or store credit card, debit card, or bank account information. All payment data is handled exclusively by Stripe.
  • For Plant ID, Photo Diagnosis, and image-assisted tools, each upload is decoded and verified from its actual file bytes, checked for safe dimensions and pixel count, and re-encoded on the server before it is sent to OpenAI. The re-encoded image does not retain EXIF, GPS, camera, XMP, or ICC metadata. The original upload is not kept after processing; a compressed metadata-free image or thumbnail may be stored with your access for history and cross-device use.
  • Photos you add to your plant journal are stored linked to your access code on our server and are visible only to you.
  • We do not show ads inside the app or intentionally send access codes, plant profiles, journals, reminder emails, or AI conversations to Google Ads. The Google tag may use cookies or similar identifiers to measure ad visits and conversions.
  • We do not sell your information to third parties.
  • Our first-party product analytics do not store IP addresses, precise location, complete referrer URLs, search terms, full user-agent strings, access codes, email addresses, or Stripe session IDs.

How We Use Your Information

The information you provide is used solely to operate the app:

  • To validate your access code and unlock the app.
  • To enforce AI Care Credit limits, AI Help message allowances, rate limits, and security controls.
  • To store and retrieve plant profiles, automatically saved results, journals, care history, photos, reminders, Today tasks, and preferences.
  • To send relevant plant information, photos, and chat questions to OpenAI's API for the 9 AI tools, Photo Diagnosis, Plant ID, and AI Help. Processing is server-side.
  • To recover access, respond to Contact Support requests, and investigate technical, payment, account, or security issues.
  • To send plant care reminder emails — only if you have activated Care Reminders for a plant.

OpenAI & AI Processing

When you use an AI feature, the plant-related information needed for that request is sent to OpenAI's API to produce the response. Depending on the feature, this may include:

  • Plant name, type, pot, soil, light, and watering details.
  • Any symptoms or recent changes you described.
  • Your general user preferences (experience level, home environment, pets).
  • Plant photos uploaded for Plant ID, Photo Diagnosis, or image-assisted form completion.
  • AI Help questions and the recent conversation context needed to answer them.

We recommend not entering sensitive personal information in plant description fields. The AI only needs plant-related details to work effectively.

OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer opts in. Under standard controls, abuse-monitoring logs may be retained for up to 30 days, or longer when legally required. Review OpenAI's current API data controls and Privacy Policy. API data controls · Privacy Policy

The OpenAI API key is stored securely on our server and is never exposed to the browser or frontend code.

Stripe & Payments

All payments are processed by Stripe, a PCI-compliant payment processor. When you complete a purchase:

  • You are redirected to a secure Stripe Checkout page hosted by Stripe.
  • Your card details are entered directly on Stripe's servers — we never see them.
  • After payment, Stripe notifies our server that the transaction was successful via a signed webhook. We verify this signature before activating any access code.
  • We may store purchase references such as Stripe session or customer identifiers, purchase email, plan, payment status, and related records needed to activate access, provide support, handle disputes, prevent fraud, and meet accounting or legal obligations.

For Stripe's privacy practices, see Stripe's Privacy Policy. Stripe privacy policy

Digital Pass, Credits & Expiration

The commercial terms and data lifecycle are separate:

  • The purchase is digital app access only. No physical product is collected for shipping or mailed.
  • Each payment or renewal is one-time and starts a 90-day pass when Stripe confirms it. There is no subscription or automatic renewal.
  • AI Care Credits belong to that pass period. Unused credits expire with the pass and do not roll over; renewal creates the credit balance of the newly selected plan.
  • After expiration, new AI generation and active-pass allowances stop, while saved app content remains accessible and is retained for up to 180 days after expiration.
  • Recovering a lost code does not create a new purchase. Renewal should use the same code so retained saved content remains linked to it.

Adaptive reminder data

To calculate soil-review dates, the app stores owner-scoped care-event timestamps, coarse moisture choices, schedule settings, calculation factors, and manual overrides. It does not store new photos, payment data, access-code text, prompts, or AI responses for this feature. These records follow the same access controls, deletion options, and retention period as the related plant data.

Room and growing-space data

When you organize plants by room or space, the app stores an owner-scoped location name, optional shared light selection, optional environment notes, and the assignments of your plants. This feature does not require new photos, payment data, access-code text, prompts, or AI responses. Deleting a space removes the grouping and leaves the plants intact and unassigned.

Storage & Security

  • App records are stored in a server-side SQLite database. Any journal photo, saved plant image, plan image, or history thumbnail is decoded and re-encoded as a metadata-free JPEG before storage and remains linked to the internal access record. Sensitive configuration files remain outside the public web root.
  • API keys (OpenAI and Stripe) are stored in files outside the public web root and are never accessible via the browser.
  • All connections to the app use HTTPS encryption.
  • Access codes are randomly generated and designed to be difficult to guess.
  • Our endpoints use input sanitization, prepared statements, uniform recovery responses, similar response timing, and graduated cooldowns to reduce enumeration and automated abuse.
  • We do not store passwords. Your access code is the credential for your saved data, so keep it private and do not share it publicly.
  • App content linked to an expired pass remains accessible and is retained for up to 180 days after expiration so it can stay connected to the same code or be restored through renewal. After that retention period, app content may be permanently deleted. Purchase, fraud-prevention, accounting, or legal records may be retained longer when necessary.

Your Data & Your Control

Your data is linked to your access code. You control it:

  • You can delete individual plants from the My Plants page at any time.
  • You can delete individual saved plans and available Photo Diagnosis or Plant ID history from their corresponding pages.
  • To request deletion of all app data, use the Contact page. We may ask for the access code, purchase email, or receipt to verify the request, and we aim to process verified requests within 7 business days.

Deleting active app data is permanent and the removed plants, plans, journals, photos, and results cannot be recovered. Limited purchase, security, fraud-prevention, or legal records may be retained when required.

First-Party Product Analytics

To improve reliability and understand how the product is used, we keep a minimized first-party analytics database containing only:

  • Product events — page views and verified purchase events identified by a safe page or event name, without URL query strings.
  • Normalized source data — labels such as direct, Google, Etsy, social, internal, campaign, or other referral; never the complete referring URL or search query.
  • Aggregated device category — Desktop, Mobile, or Tablet; not the complete browser user-agent, operating system version, or browser version.
  • Pseudonymous references — a one-way session key and, for a verified conversion, the internal numeric code record ID. We do not store the access code or Stripe session ID in analytics.

Product events are automatically deleted after 90 days. Minimized conversion metrics are deleted after 365 days. Purchase, accounting, fraud-prevention, and support records are maintained separately only as described elsewhere in this policy.

Private detailed analytics available only to authorized administrators are stored separately from the minimized product tracker and are encrypted at rest. Detailed operational analytics are automatically deleted after 90 days, while restricted purchase analytics are automatically deleted after 730 days.

Cookies & Local Storage

The app uses a secure server-side session cookie to keep you signed in. The access code is not stored in localStorage or exposed to page JavaScript. Language and limited interface preferences may still be stored locally.

Links sent for reminders and recovery use random one-time tokens stored only as hashes. They expire, cannot be reused, and never include the access code in the URL.

Recent Photo Diagnosis and Plant ID results are linked to your access code on the server so they can be available across devices. The browser may cache limited interface data or thumbnails for performance; clearing browser storage does not delete server data.

We use the Google tag to understand whether advertising leads to visits or purchases. Google Ads may receive ad-click or device/browser identifiers and conversion-event information. We do not intentionally send plant content, access codes, reminder emails, or contact messages to Google Ads. Google Privacy Policy

Signing out revokes the current server session. Clearing cookies also signs out this device. You can enter the access code again to create a new session; revoked or inactive codes cannot authorize a session.

Children's Privacy

This app is not directed at children under 13. We do not knowingly collect information from children. If you believe a child has used this service, contact us and we will remove the data.

Changes to This Policy

We may update this Privacy & Security page from time to time. Significant changes will be noted with an updated date at the top of this page. Continued use of the app after changes constitutes acceptance of the updated policy.

Questions about your privacy?

Use Contact Support for privacy questions, access requests, corrections, or data-deletion requests that require human review.

Contact Support