Privacy Policy
Last updated: May 24, 2026
This Privacy Policy explains how GardenBot (“GardenBot”, “we”, “our”, or “us”) collects, uses, stores, shares, and protects information when you use the GardenBot iOS app, GardenBot websites, and related services that link to this Policy.
GardenBot is a plant care app. It helps you manage plants, rooms, care schedules, reminders, plant photos, AI plant identification, AI chat, and subscriptions. Some features work locally on your device; others require cloud services.
Controller and Contact
For users in the European Economic Area, the United Kingdom, Switzerland, and other regions with data controller concepts, the controller is:
GardenBot is operated by Anton Petrov, a sole proprietorship registered in Poland.
Location: Gdansk, Poland
Privacy contact: [email protected]
Summary
GardenBot does not sell personal information. GardenBot does not share personal information for cross-context behavioral advertising. GardenBot does not use third-party advertising SDKs.
Firebase Analytics is used only if you consent to analytics in the app. You can turn analytics off in the app’s privacy settings.
Crash reports and diagnostics are controlled separately in the app’s privacy settings.
AI features may send plant photos, chat messages, plant context, and related technical metadata to GardenBot’s backend and to Google Cloud Vertex AI/Gemini so the app can provide identification results, care plans, and chat responses.
Photos are private to your account unless you choose to include them in feedback or support requests. Plant and chat photos are stored in Firebase Storage when you upload them.
You can request access, correction, deletion, export, or restriction of your personal data by contacting us. Registered users can also delete their account from the app.
Scope
This Policy applies to:
- the GardenBot iOS app;
- GardenBot account, plant, chat, AI, feedback, subscription, and support features;
- GardenBot websites and legal/support pages that link to this Policy.
This Policy does not apply to third-party websites, app stores, payment systems, or services that have their own privacy policies, even if they are linked from GardenBot.
Information We Collect
Account and Authentication Data
Depending on how you sign in, we may process:
- Firebase Authentication user ID;
- anonymous guest account ID;
- email address, if you sign in with email or a provider that shares it;
- authentication provider information for Sign in with Apple, Google Sign-In, or email/password sign-in;
- basic account settings, such as garden name, timezone, plan, and subscription entitlement status.
We do not receive your Apple ID password, Google password, or payment card details.
Plant, Garden, and Care Data
GardenBot stores the plant care information you add or generate, including:
- plant names and optional photos;
- rooms and garden organization data;
- species or scientific name, when selected or identified;
- watering, misting, fertilizing, rotating, cleaning, repotting, and other care schedules;
- last completed care actions and care history timestamps;
- notification settings for plant reminders;
- user-edited care actions and preferences.
This data is used to provide the core app experience, sync your garden across devices, support offline use, and rebuild reminders.
Photos and Images
You may choose to provide images through:
- plant photos;
- AI plant identification;
- AI chat attachments;
- feedback or support attachments;
- camera or photo library selection.
GardenBot requests camera and photo library access only when needed for features that use images. iOS controls these permissions, and you can change them in iOS Settings.
Images may be resized or compressed before upload. Plant photos, chat attachments, and feedback attachments are stored in Firebase Storage. A plant identification photo submitted only for identification is sent to GardenBot’s backend and AI provider to produce a result; we do not intentionally keep the raw identification image as a stored plant photo unless you save or upload it as part of a plant, chat, or feedback feature.
Avoid uploading images that contain people, documents, addresses, private interiors, or other sensitive personal information unless it is necessary for your request.
AI Identification, Care Plan, and Chat Data
When you use AI features, GardenBot may process:
- photos submitted for plant identification;
- chat messages and the most recent chat context;
- selected plant context, such as plant name, species, care schedule, room, and recent care information;
- optional chat photo attachments;
- AI request IDs, timestamps, status, model metadata, token/cost metadata, quota and rate-limit metadata, and error information;
- app locale, timezone-derived seasonal context, and similar contextual information needed to improve the relevance of responses.
GardenBot uses this information to:
- identify plants;
- generate care plans;
- answer plant care questions;
- enforce free or paid usage limits;
- prevent abuse and excessive automated requests;
- debug and improve reliability of AI features.
AI output is informational and may be incomplete or inaccurate. GardenBot does not use AI output to make legal, employment, credit, housing, insurance, healthcare, or similarly significant decisions about you.
Chat History and Chat Feedback
GardenBot may store chat messages and AI responses in Firestore and in a local device cache so you can continue conversations. Chat photos are stored in Firebase Storage if you attach them.
If you rate an AI answer, flag it, or add a comment, GardenBot may process that feedback. If analytics is enabled, feedback events may include the message identifier, chat scope, rating/flag state, and the optional feedback comment you submit.
Feedback and Support Data
When you send feedback or contact support, we may process:
- your feedback message;
- optional contact email;
- optional attachments;
- feedback category and entry point;
- app version, build number, platform, device model, operating system version, locale, and limited context needed to understand the issue;
- submission status and related support metadata.
This information is used to respond to you, debug problems, improve the app, and prevent support abuse or spam.
Subscription and Purchase Data
GardenBot offers subscriptions through Apple’s App Store and uses RevenueCat to manage subscription status. We and our service providers may process:
- RevenueCat app user ID and, when applicable, GardenBot/Firebase user ID;
- subscription entitlement status;
- product identifiers, purchase dates, renewal/expiration dates, cancellation or billing issue status, environment, country/region, currency, and price metadata;
- App Store receipt or transaction metadata needed to validate and manage subscriptions.
Apple processes payment details. GardenBot does not receive your full payment card number.
Analytics Data
If you consent to analytics, GardenBot uses Firebase Analytics to understand app usage and improve the product. Analytics may include:
- app opens, screen or feature interactions, settings taps, onboarding and paywall events;
- plant creation, plant care actions, reminder settings, AI feature usage, feedback actions, and subscription events;
- app version, device type, operating system, language/locale, approximate region, and Firebase app instance identifiers;
- error categories or non-sensitive diagnostic event parameters.
Analytics is optional. You can disable analytics in GardenBot’s privacy settings. We do not use analytics data to track you across other companies’ apps or websites.
Crash Reports, Diagnostics, and Logs
If crash reports or diagnostics are enabled, GardenBot may use Firebase Crashlytics and Apple/iOS diagnostic frameworks to collect:
- crash traces, stack traces, app state at the time of a crash, device model, operating system version, app version, and technical logs;
- Firebase user ID or pseudonymous identifiers used to correlate crashes;
- limited custom keys such as current screen, plan, or plant count;
- sanitized error messages and breadcrumbs.
Crash and diagnostic data is used to find, prioritize, and fix bugs and reliability issues. The app attempts to avoid logging sensitive user content, but crash and log data can sometimes include technical context related to your app activity.
Device, Security, and Abuse Prevention Data
GardenBot may process:
- a locally generated device identifier stored in Keychain and cached locally;
- hashed device identifiers for quota enforcement;
- Firebase App Check signals using Apple App Attest or DeviceCheck where available;
- IP address and request metadata processed by cloud infrastructure;
- rate-limit, quota, and fraud-prevention records;
- authentication tokens and security metadata needed to protect the service.
This data is used to secure accounts, enforce usage limits, prevent abuse, and protect the backend.
Notifications and Background Refresh
GardenBot uses notification permission and reminder settings to schedule plant care reminders. Local notification content may include plant names and care actions. Background refresh may update plant data and rebuild local reminders.
You can manage notification permission in iOS Settings and reminder preferences inside the app.
Remote Configuration and App Configuration
GardenBot uses Firebase Remote Config to receive app configuration, such as feature flags, AI availability settings, prompt chips, logging settings, version/update messaging, subscription-related limits, and localized remote configuration payloads.
Remote configuration helps us operate the app safely without requiring an App Store update for every configuration change.
Local Device Storage and Offline Data
GardenBot stores some data on your device for offline access and performance, including:
- cached plant, room, user, species, and chat data;
- draft messages and draft images;
- image caches;
- queued offline writes;
- user preferences, privacy choices, notification preferences, onboarding state, review prompt state, and similar app settings.
Local data may remain on your device until you delete it, delete your account, clear the app’s data, or uninstall the app, subject to iOS behavior and backups.
Sources of Information
We collect information from:
- you, when you enter data, upload images, send feedback, subscribe, or contact support;
- your device, when the app processes permissions, diagnostics, local settings, or technical identifiers;
- Apple, Google, Firebase, RevenueCat, and authentication providers when needed for sign-in, purchases, security, analytics, diagnostics, or backend operation;
- GardenBot backend systems, when they create derived data such as AI responses, quota records, entitlement status, and sync metadata.
How We Use Information
We use information to:
- provide, maintain, sync, and secure GardenBot;
- create and manage accounts;
- store and display plant, room, photo, chat, and care schedule data;
- identify plants, generate care plans, and answer plant care questions with AI;
- schedule reminders and support offline use;
- process subscriptions and entitlement status;
- provide customer support and handle feedback;
- detect, prevent, and respond to fraud, abuse, security incidents, and service misuse;
- comply with legal obligations and enforce our terms;
- improve the app, reliability, and user experience when analytics or diagnostics are enabled.
Legal Bases for EEA, UK, and Similar Regions
Where GDPR, UK GDPR, or similar laws apply, we rely on the following legal bases:
| Processing purpose | Legal basis |
|---|---|
| Account creation, sign-in, plant management, sync, reminders, AI features, subscriptions, and support requested by you | Performance of a contract or steps taken before entering a contract |
| Analytics | Consent |
| Crash reports and optional diagnostics, where required | Consent |
| Security, App Check, abuse prevention, rate limits, service reliability, basic operational logs, and fraud prevention | Legitimate interests |
| Purchase records, tax/accounting records, legal requests, and compliance obligations | Legal obligation |
| Direct support communications that you initiate | Performance of a contract or legitimate interests |
You may withdraw consent for analytics and optional diagnostics in the app’s privacy settings. Withdrawal does not affect processing that occurred before withdrawal.
Sharing and Service Providers
We share information only as needed to operate GardenBot, comply with law, protect rights and security, or process requests you make. Service providers may process data on our behalf under their own terms and privacy commitments.
Current key providers include:
- Google Firebase: Authentication, Firestore, Storage, Cloud Functions, Remote Config, App Check, Analytics, and Crashlytics. See Firebase Privacy and Security and Google Privacy Policy.
- Google Cloud and Vertex AI/Gemini: backend infrastructure and AI processing. See Google Cloud Privacy Notice.
- RevenueCat: subscription entitlement management and purchase status syncing. See RevenueCat Privacy Policy.
- Apple: App Store purchases, StoreKit, Sign in with Apple, iOS permissions, notifications, and platform services. See Apple Privacy Policy.
- Google Sign-In: authentication if you choose Google Sign-In. See Google Privacy Policy.
- Email providers: support and feedback communications when you contact us by email.
We may also disclose information:
- to comply with applicable law, legal process, or enforceable governmental requests;
- to protect GardenBot, users, or others from fraud, abuse, security threats, or harm;
- in connection with a merger, acquisition, financing, reorganization, or transfer of business assets, subject to appropriate confidentiality and user notice where required;
- with your consent or at your direction.
AI Providers and Model Processing
AI requests are processed through GardenBot-controlled backend services before being sent to AI providers. We use backend controls to validate requests, enforce quotas, reduce abuse, and provide trusted plant context.
AI requests may include user-provided plant photos, chat messages, plant data, recent conversation context, app locale, and technical request metadata. Do not include sensitive personal information in AI messages or photos unless you want it processed for the AI feature.
We do not use AI features to make legally or similarly significant automated decisions about you.
International Transfers
GardenBot is operated from Poland, and our service providers may process information in the European Economic Area, the United States, and other countries. Where required, transfers are protected using appropriate safeguards such as adequacy decisions, standard contractual clauses, data processing agreements, or other lawful transfer mechanisms.
Retention
We keep personal data only as long as reasonably necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law.
Typical retention practices include:
- Account, plant, room, care schedule, and uploaded media data: retained while your account is active or until you delete the data or request deletion.
- Chat data: retained to provide chat continuity. GardenBot may prune server-side chat history to a limited recent history and may keep a larger local cache on your device.
- AI request and operational metadata: retained as needed for reliability, debugging, quota enforcement, abuse prevention, and cost monitoring.
- Feedback and support submissions: retained as needed to respond to you, understand issues, improve the app, and maintain support records.
- Subscription and purchase metadata: retained as needed to provide entitlements, handle billing support, prevent fraud, and comply with accounting or legal obligations.
- Analytics and Crashlytics data: retained according to Firebase settings and provider retention controls.
- Security, rate-limit, and abuse-prevention records: retained as needed to protect the service.
- Backups and provider logs: may persist for a limited period after deletion from active systems.
Inactive anonymous guest accounts may be cleaned up after a period of inactivity, currently expected to be approximately 90 days where the cleanup process is enabled.
Account Deletion and Data Deletion
Registered users can start account deletion from the app. Account deletion is designed to remove the Firebase account, active account profile, plant data, room data, chat history, and user media stored under the user’s Firebase Storage area.
Some data may not be deleted immediately or may be retained when necessary, including:
- purchase and subscription records held by Apple or RevenueCat;
- analytics, crash, security, or operational logs that are no longer reasonably associated with an identifiable user or are retained for security/legal reasons;
- support and feedback records needed to manage prior requests;
- backups and provider logs until they expire under normal retention cycles;
- records we must keep to comply with law, resolve disputes, prevent abuse, or enforce agreements.
You may also contact us to request deletion, access, correction, export, or restriction of your data.
Your Choices and Controls
You can control many data practices directly:
- Analytics: enable or disable Firebase Analytics in GardenBot’s privacy settings.
- Crash reports and diagnostics: manage the crash report/diagnostics toggle in GardenBot’s privacy settings.
- Camera and Photos: manage access in iOS Settings.
- Notifications: manage permission in iOS Settings and reminder settings in GardenBot.
- Plant photos and content: delete plants, photos, chats, or other content where the app provides controls.
- Subscriptions: manage or cancel subscriptions through your Apple ID/App Store subscription settings.
- Account deletion: use the in-app deletion flow for registered accounts, or contact us.
If you disable permissions or delete data, some features may stop working or become limited.
Privacy Rights
Depending on where you live, you may have rights to:
- know what personal data we collect and how we use it;
- access your personal data;
- correct inaccurate personal data;
- delete personal data;
- receive a copy of personal data in a portable format;
- restrict or object to certain processing;
- withdraw consent;
- appeal a denied privacy request, where applicable;
- complain to a data protection authority.
To exercise these rights, contact us at [email protected]. We may need to verify your identity before fulfilling a request.
For EEA users, you may contact your local data protection authority. In Poland, the supervisory authority is the President of the Personal Data Protection Office (UODO): https://uodo.gov.pl.
California and US State Privacy Notice
This section supplements the rest of the Policy for residents of California and other US states with comprehensive privacy laws.
The categories of personal information we may collect are described above and may include identifiers, customer records, commercial information, internet or electronic network activity, geolocation at an approximate region level, audio/visual information you provide as photos, inferences related to app preferences, and sensitive personal information only if you choose to provide it in content such as photos, messages, or support requests.
We collect this information from the sources listed in this Policy and use it for the purposes listed in this Policy.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not knowingly sell or share personal information of users under 16.
We do not use sensitive personal information to infer characteristics about you. If you include sensitive information in photos, chats, or feedback, we use it only to provide the feature or support you requested, protect the service, or comply with law.
We do not provide financial incentives for the collection, sale, or sharing of personal information.
California and other eligible US residents may request access, deletion, correction, portability, and information about data practices by contacting us. You may also use an authorized agent where permitted by law, subject to verification.
Children and Age Policy
GardenBot is not directed to children. The app is intended for a general audience interested in plant care, and it includes AI features, cloud sync, subscriptions, and user-generated content.
We do not knowingly collect personal information from children under 13. Users under 16 should use GardenBot only with permission and supervision from a parent or legal guardian where required by law. If your jurisdiction requires a higher age for independent consent, you must meet that age or have parental/guardian authorization.
If you believe a child provided personal data without required consent, contact us and we will take appropriate steps, including deletion where required.
Security
We use technical and organizational measures designed to protect personal data, including Firebase Authentication, Firestore and Storage security rules, Firebase App Check, HTTPS, private storage paths for user media, access controls, rate limits, and local iOS security features such as Keychain for certain device identifiers.
No method of transmission or storage is completely secure. You are responsible for keeping your device and account credentials secure.
Data We Ask You Not to Provide
GardenBot is for plant care. Please do not upload or send:
- government IDs, payment cards, passwords, or authentication codes;
- medical, health, biometric, genetic, or other highly sensitive personal data;
- images of children or other people unless strictly necessary;
- private addresses, documents, or confidential third-party information;
- illegal, harmful, or infringing content.
If you provide this information anyway, it may be processed as part of the feature you used and may be difficult to separate from the rest of the content.
Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will update the date above and provide additional notice where required by law or where the app experience makes it appropriate.
Your continued use of GardenBot after an updated Policy becomes effective means you acknowledge the updated Policy, subject to any consent requirements that apply.
Contact
For privacy questions, requests, or complaints, contact:
GardenBot is operated by Anton Petrov, a sole proprietorship registered in Poland.
Location: Gdansk, Poland
Email: [email protected]