Privacy Policy
Effective 26 August 2026
This policy explains how Garden Sage ("we", "us", or "our") handles information when you use the Garden Sage iOS app and related services. Garden Sage does not sell personal information and does not use your data for cross-app tracking or third-party advertising.
Information we collect
- Account information: your account identifier and email address when supplied through Sign in with Apple or another sign-in method. For email sign-in, we store a salted, one-way password hash rather than the password you enter.
- Garden content: uploaded plant photos, plant and garden records, notes, care history, and the identification or care results associated with them.
- Location and weather context: a coarse location when you choose to share it, including optional country, US state, and USDA hardiness zone selections, plus derived local weather and seasonal context. We use location and weather context for plant-care personalisation; optional structured profile selections also support privacy-bounded aggregate analytics. Structured profile geography is selected by you and is not inferred from your free-text growing region, IP address, or precise location.
- Subscription information: App Store product and transaction identifiers, subscription status, eligibility, and renewal or expiry dates. Apple processes your payment details; Garden Sage does not receive your full payment-card information.
- Service and diagnostic information: product interactions, app version and build, request timing, error, security, and performance records needed to operate, protect, analyse, and troubleshoot the service.
- Acquisition information: if you use a Garden Sage invitation or campaign code, the app may keep that unapplied code on your device for up to 30 days so it survives sign-in or restart, and removes it sooner after application, terminal rejection, confirmed account deletion, or credential revocation. When a valid code is accepted, we link your account to its keyed one-way digest, short support hint, and controlled source, campaign, partner, page, and broad campaign-region fields. We do not retain the raw referral URL or unrestricted UTM text, and we do not use the code for cross-app tracking.
- Optional discovery and research information: you may select how you first found Garden Sage and enter the exact words you remember searching. Those search words stay with your account and are excluded from product-analytics events. Separately, you may explicitly allow us to email your account address about an optional user-research conversation. This permission is versioned and timestamped, is never inferred from your account or acquisition answer, does not subscribe you to marketing, and can be revoked in Account settings.
- Website contact information: if you previously joined a waitlist or contact us, we process the name, email address, request type, and message you choose to provide.
How we use information
We use this information to:
- authenticate your account and keep your garden available across sessions;
- identify plants, assess visible plant-health concerns, and provide care guidance;
- personalise results using your garden, location, season, weather, and care history;
- save plants and observations you choose to keep;
- understand which first-party invitations and campaigns lead to useful Garden Sage accounts, and improve those experiences;
- understand optional, self-reported discovery patterns in aggregate and, only with separate current permission, invite you to voluntary user research;
- verify subscription access, restore purchases, and prevent duplicate or fraudulent entitlement claims; and
- respond to support or privacy requests and maintain security, reliability, and legal compliance.
Photo and AI processing
Photos and the garden context needed for a request are sent to Garden Sage's secured backend. Depending on the request and current service configuration, PlantNet-based identification systems, Hugging Face inference services, or OpenAI may process that content to identify the plant or generate care guidance. Before the first upload, the app asks for your explicit permission to send the photo and optional context for this processing. You can revoke that permission at any time in Account › Privacy; the next analysis will ask again before anything is uploaded. Revocation stops future sharing but does not undo processing already completed.
Results are informational, may be uncertain, and are not professional agricultural, toxicology, veterinary, or medical advice.
When information is shared
We share information only as needed with:
- hosting, storage, model-processing, monitoring, and support providers acting on our behalf;
- Apple for sign-in, App Store subscriptions, purchase restoration, and related platform services;
- authorities or other parties when reasonably necessary to comply with law, protect users, prevent abuse, or defend legal rights; and
- a successor if Garden Sage is involved in a merger, acquisition, financing, or sale, subject to this policy and applicable law.
When personal information is shared with any third party under this section, we require it to be used only for the stated purpose and protected to the same or an equivalent standard as this policy, except where disclosure is required by law.
Website delivery
Garden Sage's hosting and network providers may process limited technical request information needed to deliver and secure gardensage.co. Garden Sage does not use website information for cross-app tracking or third-party advertising.
The public website does not use cookies or browser-side analytics. To understand search discovery and App Store interest, our web server may keep a redacted request record containing only the time, response status, request-method category, one controlled page or App Store-link category, one approved referral or campaign-source category, and a claimed crawler category. Before that record is written, the full request is removed, including the IP address, query string, headers, cookies, full referrer, and any unknown page or source text. A crawler category comes from its claimed User-Agent and is not proof of the crawler's identity, indexing, citation, or a unique person.
In normal operation, these redacted request-level records are kept for no more than four daily windows. A prolonged web-server or host outage can delay rotation until service resumes. Daily category counts contain no visitor identifier and are scheduled for deletion after 400 days. We cannot join a website visit to a later App Store action; Apple's privacy-protected aggregate reporting is separate.
Retention and account deletion
We keep account and garden information while your account is active and for only as long as needed for the purposes above. You can delete your account by opening Account in the app and tapping Delete Account in the Privacy section. This removes the account and associated garden records from the active service. Stored media is queued for secure deletion and may take a short time to be removed.
Deleted information may remain temporarily in protected rotating backups or limited records retained for security, fraud prevention, accounting, or legal obligations. Those records are not used to continue providing a deleted account.
Privacy-bounded product analytics and accepted acquisition records are scheduled for deletion within 400 days and are removed earlier when the linked account is deleted. An acquisition-code definition contains no raw code or contact details and is deleted after its expiry is more than 400 days old once no retained account record references it. Clearing optional structured geography stops its active-profile use but does not rewrite earlier immutable analytics snapshots; those follow the same 400-day limit and account-deletion rule. Garden Sage does not use this information for cross-app tracking.
An optional discovery answer and its exact search words remain account data until you clear them or delete the account. Product analytics retain only the selected discovery category, whether search words were supplied, and categorical grant, revoke, or clear revisions—never the search words themselves. Research-contact permission and its latest grant timestamp remain account data until you revoke it, delete the account, or the permission expires after 400 days. Revocation removes the account from current research eligibility immediately. Grant or revocation timestamps and the notice version are cleared once their relevant timestamp is more than 400 days old. Non-content discovery and consent revision counters may remain with the account solely to prevent old updates from being replayed; categorical consent events follow the same 400-day analytics limit and account-deletion rule.
Readable product-analytics events waiting for delivery remain on your device until they are accepted, your account data is cleared, or delivery resumes after the server's seven-day past-event window has expired. The app does not infer expiry from your device clock. When the server confirms that a queued event is too old, the app removes that event and its retry metadata; it does not discard potentially deliverable events merely to make room.
If an on-device analytics queue becomes unreadable, the app may keep one exact recovery snapshot for each affected queue store for up to 30 days. Garden Sage never semantically parses or transmits that snapshot, and the app removes it sooner after confirmed account deletion or credential revocation.
Your choices
- You can decline or revoke location and photo-library access in iOS Settings.
- You can clear optional country, state, and USDA-zone profile selections in Account.
- You can edit or clear your optional discovery answer and separately grant or revoke user-research contact permission in Account.
- You can choose which photos to submit and which results to save.
- You can revoke AI photo-processing permission in Account › Privacy; Garden Sage will ask again before a future upload.
- You can manage or cancel a subscription in your Apple Account settings.
- You can request account deletion directly in the app.
Security and international processing
We use technical and organisational safeguards designed to protect your information. No service can guarantee absolute security. Information may be processed in countries other than your own by providers supporting Garden Sage, subject to appropriate contractual and legal safeguards.
Children
Garden Sage is not directed to children under 13, or the higher minimum age required in their country. We do not knowingly collect personal information from children below that age.
Changes to this policy
We may update this policy as Garden Sage evolves. We will publish the revised policy at this URL and update the effective date. Material changes will be highlighted in the app or through another appropriate notice.
Contact
For privacy questions or requests, email hi@gardensage.co or visit Garden Sage Support.
Garden Sage gives practical gardening guidance, but plant identification and health suggestions can be wrong. If a plant may be toxic or poses a risk to people or animals, contact an appropriate qualified professional.