Privacy Policy
Last updated: October 3, 2026
The short version: your photos and follow-up chats are used only to care for your plant, are not used to train AI models, and are not kept on our side. Your plant collection and conversations live on your device. We keep usage analytics tied to a random ID on your device (never to your name, email or an account) and crash reports with no identifier. There is no account, no ad tracking, and no selling of data — and because we collect so little, most of this policy is about what we don't do.
1. Who is responsible for your data
Plant Doctor is published by an individual independent developer (referred to in this policy as "we", "us", or "the developer"), who acts as the data controller for the limited processing described below. The developer is identified as the seller of record on the app's App Store listing. For anything in this policy, contact [email protected] — that inbox is read by the developer personally.
2. What this policy covers
This policy covers the Plant Doctor iPhone app and the plantdoctorapp.com website. It does not cover third-party websites we link to (for example plant-care resources from horticultural institutions), whose own policies apply.
3. What we process, why, and on what basis
We designed Plant Doctor to work without an account and to hold as little data as possible. This is everything the app processes:
- Plant photos + optional context you type — sent to our server, forwarded to our AI provider (Anthropic) solely to produce your diagnosis, and not retained by us after the response. We do not use your photos or text to train models, and our provider processes them as a service provider on our instructions. Purpose: producing the diagnosis you requested. Legal basis: performance of our contract with you.
- Follow-up conversations with the plant doctor — each message you send (together with the diagnosis being discussed) goes to our server and is forwarded to our AI provider (Anthropic) solely to produce the reply. Like photos, chat is not retained by us after the reply and is never used to train models; the conversation itself is saved only on your device. Purpose: answering your follow-up questions. Legal basis: performance of our contract with you.
- Anonymous device identifier — a random ID generated on your device, used to rate-limit requests and count feature usage. It is not linked to your name, email, or any account, and we could not identify you from it if we tried. Purpose: preventing abuse of the free allowance and keeping the service working. Legal basis: our legitimate interest in operating and protecting the service.
- Purchase state — handled by RevenueCat and Apple; we see subscription status (for example "Pro, active"), never your payment details, name, or Apple ID. Purpose: unlocking what you paid for and restoring purchases. Legal basis: performance of our contract with you.
- Usage analytics — anonymous counts of feature usage (for example "a diagnosis was completed", "a check-up failed to reach our service", or "the paywall was viewed"), and masked recordings of how the app is used: which screens are opened and tapped, in what order. Your plant photos, the live camera view, anything you type, your chat questions and answers, and your plants' names are blanked out on your device before a recording leaves it. Everything is keyed to the same random device ID and processed for us by PostHog on US servers. No photos, no chat text, no location. Our own server keeps the same kind of anonymous count when it handles a check-up or a follow-up — that one was produced, or that a request hit a rate limit — keyed to that same random device ID. You can turn all of this off at any time in Settings → "Share anonymous usage data": the one switch stops the counts and the recordings together, and your choice is sent with every request, so our server stops counting too. Purchase events (for example a trial starting or a renewal) are forwarded by RevenueCat to PostHog under the same random ID, even when this switch is off. Purpose: understanding which features are used and where people get stuck, so we can improve the app. Legal basis: our legitimate interest in improving the service (or your consent where local law requires it).
- Crash reports — if the app crashes or hits an error, technical details (device model, OS version, app version, and what the app was doing) are sent to Sentry so we can fix it. Crash reports never include your photos, chat, or plant collection. Purpose: fixing bugs. Legal basis: our legitimate interest in providing a working app.
- Website visits — plantdoctorapp.com is served through Cloudflare, which processes connection data (such as IP address) to deliver pages and protect against attacks. The site also measures visits and interactions (such as App Store link taps) through PostHog, using a random ID kept in your browser for up to 12 months so repeat visits can be counted. It uses no advertising cookies or ad trackers, and a visit is not linked to you or to the app. Visitors in Europe are asked first, and anyone can switch it off under "Privacy choices" at the bottom of the site's pages (remembered in your browser) or with Do Not Track or Global Privacy Control. Purpose: running and improving the website. Legal basis: our legitimate interest (or your consent where local law requires it).
- Email sign-up (optional) — if you ask for the plant rescue checklist on the website, your email address is kept by our email provider, Kit, so we can send it, along with occasional plant-care tips and Plant Doctor news. You confirm the sign-up by email first, every email has an unsubscribe link, and your address is not linked to your website visits or to the app. Purpose: sending the emails you asked for. Legal basis: your consent.
- Email you send us — if you email support, we receive your email address and whatever you include. We use it only to respond, and you can ask us to delete the correspondence at any time. Purpose: support. Legal basis: our legitimate interest in answering you.
4. What we do not collect and do not do
- No account, registration, or profile — we do not know who you are.
- No name, email address, phone number, or contact list collection in the app.
- No location data.
- No advertising, no ad networks, no ad identifiers.
- No selling, renting, or sharing of personal information for anyone else's marketing.
- No tracking across other companies' apps or websites, and no "data brokers".
- No use of your photos or text to train AI models — ours or anyone else's.
- No storage of your photos or chat messages on our servers after each response is produced.
5. Who processes data for us
We use a small number of service providers, each bound by their own commitments and processing data only to provide their service to us: Anthropic (AI diagnosis), Apple (App Store distribution and billing), RevenueCat (subscription state), PostHog (anonymous app and website analytics), Sentry (crash reports), Kit (email sign-ups), and Cloudflare (website and network infrastructure). We do not run our own user database.
International transfers
These providers process data primarily in the United States. Where data protected by EU/UK/Swiss law is transferred internationally, we rely on the safeguards our providers offer for such transfers, such as standard contractual clauses or their participation in recognized data-transfer frameworks. Given how little the app processes — transient photos and anonymous counters — the practical exposure is deliberately minimal.
6. How long anything is kept
- Photos, typed context, and chat messages: not retained by us after each response; our AI provider (Anthropic) may keep them for up to 30 days for safety monitoring.
- Diagnosis results, your garden, history, notes, conversations, reminders: stored only on your device, for as long as you keep them.
- Anonymous analytics, masked usage recordings, and crash reports: kept for as long as useful for improving the app and website (recordings for a limited period set in our analytics tool), deletable in bulk at our end; they cannot be traced back to you.
- Purchase state: kept for as long as needed to honor your subscription and the law requires.
- Email sign-ups: kept while you are subscribed; after you unsubscribe, only what is needed to respect that choice is kept, and we delete it entirely on request.
- Support email: kept as long as needed to help you, deleted on request.
7. What stays on your device — and your control over it
Your plant collection, diagnosis history, care events, notes, follow-up conversations with the plant doctor, and reminder schedule are stored locally in the app. Export them anytime (Settings → Export), or erase everything with Settings → Delete all my data. Deleting the app deletes this data with it. This data is stored nowhere but your device: parts of it transit our servers only in the moment a feature needs the AI — a check-up or a follow-up message — and are not retained there. We could not produce your garden or your conversation history if asked, because we do not have them.
8. Your rights
Depending on where you live (for example under the EU/UK GDPR or US state privacy laws), you may have rights to access, correct, delete, export, or restrict the processing of your personal data, to object to processing based on legitimate interests, to withdraw consent, and to complain to your local data-protection authority. To exercise any of these, email [email protected].
An honest limitation: because the app is designed around anonymity, most data we hold cannot be linked to a person. If you ask us to find "your" analytics events, we genuinely cannot identify which anonymous device ID is yours — which also means nobody else can. Data on your device is under your direct control with the built-in export and delete tools. We do not discriminate against anyone for exercising privacy rights.
9. Children
Plant Doctor is not directed at children under 13, and we do not knowingly collect personal information from them. The app has no account, no social features, and no advertising. If you believe a child has sent us personal information (for example by email), contact us and we will delete it.
10. Security
Data in transit is encrypted (HTTPS/TLS). We follow a data-minimization design: the most effective protection we offer is that there is almost nothing to breach — no account database, no stored photos, no identity-linked records. No system is perfectly secure, and we cannot guarantee absolute security; if a breach affecting personal data ever occurs, we will notify affected users and authorities as required by law.
11. Changes to this policy
If we change this policy, the new version will be posted at this address with an updated date, and material changes will be highlighted in the app or on the site. Continued use of the app after a change takes effect means the updated policy applies. We will never retroactively weaken what this policy promised about data we already processed.
12. Contact
Questions, requests, or complaints: [email protected]. If you are in the EU/UK you also have the right to lodge a complaint with your supervisory authority — though we would appreciate the chance to resolve it directly first.