Privacy Policy

Effective date: July 23, 2026

GardenerPlus is operated by ZaneEnterprise LLC (“GardenerPlus,” “we,” “us,” or “our”). This policy explains what the GardenerPlus mobile app and our supporting services process, why we process it, which providers receive it, how long it is kept, and the choices available to you. We do not sell personal information, show third-party ads, or track you across other companies' apps or websites.

1. Scope and release transition

This policy covers GardenerPlus on iPhone and iPad, the GardenerPlus API and admin systems, the Android app, and the GardenerPlus website. GardenerPlus does not offer a web version of the app; the website provides product, support, privacy, and account-deletion information. Your use of Apple's App Store, iCloud, Google Play, Apple, or Google sign-in is also governed by the applicable provider's terms and privacy notices.

During the transition from the currently released native Swift app version 1.0.7 to the Expo app version 1.1.0, location behavior differs. The exact difference is described in Section 3 so the policy remains accurate for both versions.

The released Swift app version 1.0.7 uses on-device storage and optional private iCloud/CloudKit sync. Expo app version 1.1.0 may offer optional GardenerPlus Account Sync through Apple or Google sign-in after the production service is activated. The Account Sync disclosures below apply only when the option appears in your app and you choose to sign in and migrate a garden. Without Account Sync, GardenerPlus continues to work with on-device data and any separately enabled private iCloud sync on supported Apple devices.

2. Information we process

  • Plant and garden content: plant names, notes, care events, reminder settings, room or outdoor-location text you enter, plant photos, AI questions, and saved AI checkups.
  • AI request content: the photo, prompt, plant details, care history, question, and other context needed for the identification, checkup, or question you request, together with the AI response.
  • Account and sign-in information: if you enable account sync, an internal GardenerPlus user identifier; the linked Apple or Google provider, issuer, and provider-specific user identifier; and the verified email address and name or display name the provider returns, if any. Apple may provide a private relay email address. We do not collect a GardenerPlus password, store provider identity tokens or authorization codes, or use an email address to silently merge accounts.
  • App and device identifiers: a random app-specific device identifier, an internal GardenerPlus user identifier, a private CloudKit account-scoped record identifier used for recovery or migration fallback on Apple devices, and DeviceCheck verification state.
  • Device inventory and sessions: device name and model, platform, app version, build number, first and last activity, account-authentication time, and active session count. This lets you and GardenerPlus distinguish the devices attached to an account. Account access tokens are stored in the app's secure storage; the backend stores token verification and revocation state.
  • Subscription information: App Store or Google Play product and purchase identifiers, App Store transaction and original-transaction identifiers, receipt or signed transaction information, entitlement status, expiration or renewal date, and the app-specific RevenueCat customer identifier. We do not receive or store your payment-card number.
  • Product interaction and service metrics: feature used, request time, quota usage, success or failure, response time, model, token counts, estimated API cost, and cache measurements.
  • Diagnostics: error message, context you choose to submit through the app's diagnostic flow, app/build/system/device information, and whether the error was marked critical. New AI and app-error database rows do not retain your raw IP address or user-agent string, although networking and security infrastructure may process connection information transiently to deliver and protect the service.
  • Support communications: information you include when you email us or make a privacy request.

3. Location

Released Swift app 1.0.7: Basic analysis does not use device location. If you grant location access and use Enhanced analysis, latitude and longitude rounded to four decimal places are included in the AI prompt sent to our API and OpenAI for climate-aware advice. User-entered room or outdoor-location text can also be included in an AI prompt.

Expo app 1.1.0: Basic analysis does not inspect location. For Enhanced analysis, if you grant access, latitude is used only on your device to determine the current hemisphere-aware season. Coordinates are not returned to the app's AI code, sent to our API, or stored by GardenerPlus. User-entered room or outdoor-location text can still be included in an AI prompt.

You can deny or revoke location access in your device settings. GardenerPlus still works without location, but advice will be season-general rather than location-specific.

4. How we use information

  • Provide plant identification, plant-health checkups, AI questions, care history, reminders, and optional cross-platform account sync.
  • Create or link a GardenerPlus account after Apple or Google verifies your sign-in, maintain provider and device links, show the devices attached to the account, and authenticate account sessions.
  • If you enable Account Sync, migrate and verify an existing on-device garden or a successfully reconciled iCloud garden, resolve sync changes, and preserve the verified source read-only for a time-limited rollback window.
  • Maintain your GardenerPlus identity across updates, restores, and supported devices and prevent quota, account, or subscription abuse.
  • Validate purchases, restore Pro access, handle subscription lifecycle events, and respond to billing disputes.
  • Enforce feature quotas, retry requests safely, diagnose failures, measure service reliability and cost, and improve GardenerPlus.
  • Protect the app, API, users, and our legal rights; comply with valid legal obligations; and communicate with you about support or privacy requests.

5. Service providers and disclosures

We disclose only the information needed for these providers to perform the described service:

  • Apple: App Store purchases and subscription management, private iCloud/CloudKit sync and migration fallback, DeviceCheck app/device validation, and optional Sign in with Apple. For Apple sign-in, GardenerPlus verifies the provider response, uses the authorization code to establish revocation-capable access, and stores the resulting Apple authorization material encrypted; the one-time code and identity token are not retained. See Apple's privacy information.
  • Google: optional Sign in with Google for account access and Google Play purchases and subscription management on Android. GardenerPlus verifies Google's signed identity token and retains only the provider identifier and verified profile metadata described above, not the identity token or a Google password. See Google's privacy policy.
  • OpenAI: processes the photo, prompt, question, and context you submit for an AI feature and returns the response. OpenAI states that API customer content is not used to train its models by default unless the API customer opts in. See OpenAI's privacy policy.
  • RevenueCat: processes app-specific customer identifiers, device/SDK information, App Store or Google Play receipts or transaction information, entitlements, subscription events, and purchase history so GardenerPlus can provide and restore Pro access. See RevenueCat's privacy policy.
  • Mailgun by Sinch: may process the content and delivery metadata of a critical diagnostic email sent to the GardenerPlus operator. See Sinch's privacy notice.
  • GardenerPlus infrastructure: account, sync, device, billing, quota, and operational records are stored in a dedicated PostgreSQL database. Synced garden photos and retained request images are stored separately in private, access-controlled Garage object storage operated on infrastructure we control. Traffic to these services is protected with TLS. The Garage live-object layer does not use S3 server-side encryption at rest, and we do not describe those objects as encrypted at rest. Checksum-verified mirrors and rotating disaster-recovery backups are also maintained on infrastructure we control.
  • Website, network, and hosting providers: may process connection information and stored website or application data as needed to deliver, protect, back up, and operate GardenerPlus.

We may also disclose information when required by law, to protect rights and safety, or as part of a merger, financing, acquisition, or sale of assets subject to appropriate confidentiality protections.

6. Storage and retention

  • On-device and private iCloud data: plant records, care history, settings, photos, and saved AI results remain until you delete them in the app or remove the app's data from your iCloud account. Apple controls its own iCloud backup and retention practices. Migrating to GardenerPlus account sync does not automatically delete the local or iCloud copy.
  • GardenerPlus account and sync data: if you enable Account Sync, synced garden records and asset metadata are stored in PostgreSQL and photo or image bytes are stored in the private Garage object store described above. They are retained while the account is active or until you delete the content or request account deletion. A minimal deletion marker may remain so another device does not restore deleted content; an unreferenced object is eligible for verified cleanup after a seven-day safety window. A completed migration has a server rollback window of up to 30 days. The app identifies the retained source as iCloud only after a successful CloudKit reconciliation; otherwise it is treated as on-device only. During that window the verified source remains read-only. The server confirmation does not authorize deleting private iCloud data, and GardenerPlus does not promise that an iCloud copy remains usable for rollback after the window expires.
  • Sign-in profiles and sessions: linked provider identifiers and any verified email or name are retained while the provider remains linked or the account remains active. One-time sign-in challenges normally expire after 10 minutes. Account sessions normally expire after 30 days unless renewed or revoked. Pausing sync revokes or expires the session on that device but does not delete the account, synced data, device link, or provider link.
  • Apple authorization: revocation-capable Apple authorization material is retained encrypted while needed to support the linked Apple identity. Unlinking Apple or completing account deletion triggers a request to revoke that authorization. Google identity tokens are verified for sign-in and are not retained as account credentials.
  • Device, quota, and subscription records: retained while needed to operate the service, restore access, prevent abuse, resolve billing issues, and meet legal obligations.
  • First-party AI and diagnostic records: may include images, prompts, responses, identifiers, and error details. They are retained for service operation, security, debugging, support, and quality review. GardenerPlus does not currently promise a fixed automatic expiration period for these records; you may request deletion as described below.
  • Backups: historical database snapshots, checksum-verified Garage mirror generations—including the generation named “current”—and encrypted disaster-recovery snapshots may persist for a limited rotation period after information is removed from the active service. These backups are isolated from normal app use, used only for disaster recovery, and overwritten or deleted on their normal schedules. Completing account deletion removes authoritative live objects but does not synchronously rewrite rotating mirrors or erase every historical snapshot. A restore must reapply the deletion ledger before restored data is returned to service.
  • Deletion audit: a completed or otherwise terminal request retains a pseudonymous confirmation and limited, payload-free timeline for the operational audit period, normally 90 days and configurable from 30 to 365 days. Failed work is retained until it is resolved.
  • Provider records: Apple, Google, OpenAI, RevenueCat, and Sinch retain information under their own contracts, legal obligations, and published policies.

We may retain limited records longer when required for taxes, accounting, fraud prevention, security investigations, legal claims, or valid legal process. Where practical, information no longer needed is deleted or de-identified.

7. Your choices and privacy requests

  • Change photo, camera, location, notification, and cellular-data permissions in your device settings, and iCloud permissions in iOS Settings.
  • Delete individual plants, photos, care events, notes, questions, and checkups in the app.
  • Choose whether to enable GardenerPlus account sync. You can view attached device information and pause sync on the current device without deleting its local garden.
  • Ask us to unlink a sign-in provider. Unlinking removes that provider link but does not by itself delete the GardenerPlus account or synced garden.
  • Manage or cancel the GardenerPlus Pro subscription in your Apple Account or Google Play subscription settings.
  • Ask to access, correct, export, or delete GardenerPlus backend information, object to or restrict processing, or withdraw consent where applicable.

To make a privacy request, email christian@zaneenterprise.net with the subject “GardenerPlus Privacy Request.” In Expo app version 1.1.0 and later, you can start a general privacy request under Settings → Privacy Choices. When available, the app can include a seven-day, single-purpose verification proof tied to the current app device; that proof cannot be used to access the account or GardenAI. If the authenticated Account Sync deletion service is enabled, the same screen also lets you reauthenticate recently with a linked Apple or Google identity and submit one idempotent deletion request. You can follow its status, cancel only while it is still pending and processing has not started, or retry the same request after a controlled failure. The separate web deletion page at gardenerplus.com/account-deletion supports Apple or Google verification without reinstalling the app. In Swift app version 1.0.7, before the authenticated service is enabled, or when in-app verification is unavailable, email us or use the web page and we will provide the verification steps needed before disclosing or deleting data. Do not email credentials, plant photos, or sensitive information unless we ask for it.

When processing completes, a verified account-deletion request removes the active GardenerPlus account, linked Apple or Google identity, active sessions, device links, synced garden records, authoritative live photo assets, and first-party service history tied to the account. It also deletes linked RevenueCat customer records and revokes retained Apple authorization where present. GardenerPlus does not retain a Google refresh or access credential to revoke; it removes the verified Google identity instead. Account deletion does not cancel an App Store or Google Play subscription, synchronously erase rotating mirrors or historical disaster-recovery snapshots, or remove copies still stored on your device or in your private iCloud account, if any. You must cancel the subscription through the applicable store and delete those local or iCloud copies separately.

We will respond within the period required by applicable law. Some rights vary by location, and limited information may be retained where a legal exception applies. We will not discriminate against you for exercising a privacy right.

8. Security and international processing

We use TLS-encrypted transport, access controls, one-time provider challenges, app/device validation, encrypted storage for Apple revocation credentials, authenticated administrative access, isolated test and production systems, database integrity checks, checksum verification, and backup controls designed to protect information. As described in Section 5, synced image objects in the private Garage live-object layer are access-controlled but are not protected by S3 server-side encryption at rest. No storage or transmission method is completely secure. Our providers may process information in the United States and other countries where they or their subprocessors operate, subject to their contractual and legal safeguards.

9. Children

GardenerPlus is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If you believe a child has provided information, contact us so we can review and delete it where required.

10. Changes to this policy

We may update this policy when GardenerPlus, its providers, or legal requirements change. We will post the updated effective date here and provide additional notice in the app when a material change requires it.

11. Contact

ZaneEnterprise LLC
2345 E Thomas Rd, Suite 100 #225
Phoenix, AZ 85016, USA
App support: app@gardenerplus.com