Privacy Policy
Last updated: August 25, 2026
The short version: your photos and follow-up chats are used only to care for your plant, are not used to train AI models, and are not kept on our side. Your plant collection and conversations live on your device. We keep anonymous usage counts and crash reports that are never linked to who you are. There is no account, no ad tracking, and no selling of data — and because we collect so little, most of this policy is about what we don't do.
1. Who is responsible for your data
Plant Doctor is published by an individual independent developer (referred to in this policy as "we", "us", or "the developer"), who acts as the data controller for the limited processing described below. The developer is identified as the seller of record on the app's App Store listing. For anything in this policy, contact support@plantdoctorapp.com — that inbox is read by the developer personally.
2. What this policy covers
This policy covers the Plant Doctor iPhone app and the plantdoctorapp.com website. It does not cover third-party websites we link to (for example plant-care resources from horticultural institutions), whose own policies apply.
3. What we process, why, and on what basis
We designed Plant Doctor to work without an account and to hold as little data as possible. This is everything the app processes:
- Plant photos + optional context you type — sent to our server, forwarded to our AI provider (Anthropic) solely to produce your diagnosis, and not retained by us after the response. We do not use your photos or text to train models, and our provider processes them as a service provider on our instructions. Purpose: producing the diagnosis you requested. Legal basis: performance of our contract with you.
- Follow-up conversations with the plant doctor — each message you send (together with the conversation so far and the relevant parts of your plant's chart) goes to our server and is forwarded to our AI provider (Anthropic) solely to produce the reply. Like photos, chat is not retained by us after the reply and is never used to train models; the conversation itself is saved only on your device. Purpose: answering your follow-up questions. Legal basis: performance of our contract with you.
- Anonymous device identifier — a random ID generated on your device, used to rate-limit requests and count feature usage. It is not linked to your name, email, or any account, and we could not identify you from it if we tried. Purpose: preventing abuse of the free allowance and keeping the service working. Legal basis: our legitimate interest in operating and protecting the service.
- Purchase state — handled by RevenueCat and Apple; we see subscription status (for example "Pro, active"), never your payment details, name, or Apple ID. Purpose: unlocking what you paid for and restoring purchases. Legal basis: performance of our contract with you.
- Usage analytics — anonymous counts of feature usage (for example "a diagnosis was completed" or "the paywall was viewed"), keyed to the same random device ID and processed for us by PostHog on US servers. No photos, no chat text, no location. Purpose: understanding which features are used so we can improve the app. Legal basis: our legitimate interest in improving the service (or your consent where local law requires it).
- Crash reports — if the app crashes or hits an error, technical details (device model, OS version, app version, and what the app was doing) are sent to Sentry so we can fix it. Crash reports never include your photos, chat, or plant collection. Purpose: fixing bugs. Legal basis: our legitimate interest in providing a working app.
- Website visits — plantdoctorapp.com is a static site served through Cloudflare. Like any web host, Cloudflare processes connection data (such as IP address and request logs) to deliver pages and protect against attacks. The site itself sets no analytics or advertising cookies and runs no trackers. Purpose: serving and securing the website. Legal basis: our legitimate interest in operating a secure website.
- Email you send us — if you email support, we receive your email address and whatever you include. We use it only to respond, and you can ask us to delete the correspondence at any time. Purpose: support. Legal basis: our legitimate interest in answering you.
4. What we do not collect and do not do
- No account, registration, or profile — we do not know who you are.
- No name, email address, phone number, or contact list collection in the app.
- No location data.
- No advertising, no ad networks, no ad identifiers.
- No selling, renting, or sharing of personal information for anyone else's marketing.
- No tracking across other companies' apps or websites, and no "data brokers".
- No use of your photos or text to train AI models — ours or anyone else's.
- No retention of your photos or chat messages after each response is produced.
5. Who processes data for us
We use a small number of service providers, each bound by their own commitments and processing data only to provide their service to us: Anthropic (AI diagnosis), Apple (App Store distribution and billing), RevenueCat (subscription state), PostHog (anonymous analytics), Sentry (crash reports), and Cloudflare (website and network infrastructure). We do not run our own user database.
International transfers
These providers process data primarily in the United States. Where data protected by EU/UK/Swiss law is transferred internationally, we rely on the safeguards our providers offer for such transfers, such as standard contractual clauses or their participation in recognized data-transfer frameworks. Given how little the app processes — transient photos and anonymous counters — the practical exposure is deliberately minimal.
6. How long anything is kept
- Photos, typed context, and chat messages: not retained by us after each response; they exist transiently while the request is processed.
- Diagnosis results, your garden, history, notes, conversations, reminders: stored only on your device, for as long as you keep them.
- Anonymous analytics and crash reports: kept in aggregate form for as long as useful for improving the app, and deletable in bulk at our end; they cannot be traced back to you.
- Purchase state: kept for as long as needed to honor your subscription and the law requires.
- Support email: kept as long as needed to help you, deleted on request.
7. What stays on your device — and your control over it
Your plant collection, diagnosis history, care events, notes, follow-up conversations with the plant doctor, and reminder schedule are stored locally in the app. Export them anytime (Settings → Export), or erase everything with Settings → Delete all my data. Deleting the app deletes this data with it. This data is stored nowhere but your device: parts of it transit our servers only in the moment a feature needs the AI — a check-up or a follow-up message — and are not retained there. We could not produce your garden or your conversation history if asked, because we do not have them.
8. Your rights
Depending on where you live (for example under the EU/UK GDPR or US state privacy laws), you may have rights to access, correct, delete, export, or restrict the processing of your personal data, to object to processing based on legitimate interests, to withdraw consent, and to complain to your local data-protection authority. To exercise any of these, email support@plantdoctorapp.com.
An honest limitation: because the app is designed around anonymity, most data we hold cannot be linked to a person. If you ask us to find "your" analytics events, we genuinely cannot identify which anonymous device ID is yours — which also means nobody else can. Data on your device is under your direct control with the built-in export and delete tools. We do not discriminate against anyone for exercising privacy rights.
9. Children
Plant Doctor is not directed at children under 13, and we do not knowingly collect personal information from them. The app has no account, no social features, and no advertising. If you believe a child has sent us personal information (for example by email), contact us and we will delete it.
10. Security
Data in transit is encrypted (HTTPS/TLS). We follow a data-minimization design: the most effective protection we offer is that there is almost nothing to breach — no account database, no stored photos, no identity-linked records. No system is perfectly secure, and we cannot guarantee absolute security; if a breach affecting personal data ever occurs, we will notify affected users and authorities as required by law.
11. Changes to this policy
If we change this policy, the new version will be posted at this address with an updated date, and material changes will be highlighted in the app or on the site. Continued use of the app after a change takes effect means the updated policy applies. We will never retroactively weaken what this policy promised about data we already processed.
12. Contact
Questions, requests, or complaints: support@plantdoctorapp.com. If you are in the EU/UK you also have the right to lodge a complaint with your supervisory authority — though we would appreciate the chance to resolve it directly first.