Skip to content
Garden Sage
Home Privacy Support
GARDEN SAGE

Privacy Policy

Effective 9 August 2026

This policy explains how Garden Sage ("we", "us", or "our") handles information when you use the Garden Sage iOS app and related services. Garden Sage does not sell personal information and does not use your data for cross-app tracking or third-party advertising.

Information we collect

  • Account information: your account identifier and email address when supplied through Sign in with Apple or another sign-in method. For email sign-in, we store a salted, one-way password hash rather than the password you enter.
  • Garden content: uploaded plant photos, plant and garden records, notes, care history, and the identification or care results associated with them.
  • Location and weather context: a coarse location when you choose to share it, including optional country, US state, and USDA hardiness zone selections, plus derived local weather and seasonal context. We use location and weather context for plant-care personalisation; optional structured profile selections also support privacy-bounded aggregate analytics. Structured profile geography is selected by you and is not inferred from your free-text growing region, IP address, or precise location.
  • Subscription information: App Store product and transaction identifiers, subscription status, eligibility, and renewal or expiry dates. Apple processes your payment details; Garden Sage does not receive your full payment-card information.
  • Service and diagnostic information: product interactions, app version and build, request timing, error, security, and performance records needed to operate, protect, analyse, and troubleshoot the service.
  • Acquisition information: if you use a Garden Sage invitation or campaign code, the app may keep that unapplied code on your device for up to 30 days so it survives sign-in or restart, and removes it sooner after application, terminal rejection, confirmed account deletion, or credential revocation. When a valid code is accepted, we link your account to its keyed one-way digest, short support hint, and controlled source, campaign, partner, page, and broad campaign-region fields. We do not retain the raw referral URL or unrestricted UTM text, and we do not use the code for cross-app tracking.
  • Website contact information: the request type, name, email address, and message you choose to submit through our beta-access or support form.

How we use information

We use this information to:

  • authenticate your account and keep your garden available across sessions;
  • identify plants, assess visible plant-health concerns, and provide care guidance;
  • personalise results using your garden, location, season, weather, and care history;
  • save plants and observations you choose to keep;
  • understand which first-party invitations and campaigns lead to useful Garden Sage accounts, and improve those experiences;
  • verify subscription access, restore purchases, and prevent duplicate or fraudulent entitlement claims; and
  • send requested beta-access details, respond to support or privacy requests, and maintain security, reliability, and legal compliance.

Photo and AI processing

Photos and the garden context needed for a request are sent to Garden Sage's secured backend. Depending on the request and current service configuration, PlantNet-based identification systems, Hugging Face inference services, or OpenAI may process that content to identify the plant or generate care guidance. Before the first upload, the app asks for your explicit permission to send the photo and optional context for this processing. You can revoke that permission at any time in Account › Privacy; the next analysis will ask again before anything is uploaded. Revocation stops future sharing but does not undo processing already completed.

Results are informational, may be uncertain, and are not professional agricultural, toxicology, veterinary, or medical advice.

When information is shared

We share information only as needed with:

  • hosting, storage, model-processing, monitoring, and support providers acting on our behalf;
  • Apple for sign-in, App Store subscriptions, purchase restoration, and related platform services;
  • authorities or other parties when reasonably necessary to comply with law, protect users, prevent abuse, or defend legal rights; and
  • a successor if Garden Sage is involved in a merger, acquisition, financing, or sale, subject to this policy and applicable law.

When personal information is shared with any third party under this section, we require it to be used only for the stated purpose and protected to the same or an equivalent standard as this policy, except where disclosure is required by law.

Website delivery and abuse prevention

Our public website is delivered through Vercel. Contact and beta-access forms pass through a Garden Sage-controlled Vercel endpoint before they are stored by Garden Sage's secured backend. The endpoint accepts same-site form submissions, caps request size, and uses a Vercel-supplied client-network address for rate limiting. Our backend converts that address to a pseudonymous rate-limit key that expires within ten minutes; the contact record does not store the address. Garden Sage does not use this website technology for cross-app tracking or third-party advertising.

Retention and account deletion

We keep account and garden information while your account is active and for only as long as needed for the purposes above. You can delete your account by opening Account in the app and tapping Delete Account in the Privacy section. This removes the account and associated garden records from the active service. Stored media is queued for secure deletion and may take a short time to be removed. Protected backups are scheduled for deletion within 14 days. Limited records may remain where retention is required for security, fraud prevention, accounting, or law; they are not used to continue providing a deleted account.

Privacy-bounded product analytics and accepted acquisition records are scheduled for deletion within 400 days and are removed earlier when the linked account is deleted. An acquisition-code definition contains no raw code or contact details and is deleted after its expiry is more than 400 days old once no retained account record references it. Clearing optional structured geography stops its active-profile use but does not rewrite earlier immutable analytics snapshots; those follow the same 400-day limit and account-deletion rule. Garden Sage does not use this information for cross-app tracking.

Readable product-analytics events waiting for delivery remain on your device until they are accepted, your account data is cleared, or delivery resumes after the server's seven-day past-event window has expired. The app does not infer expiry from your device clock. When the server confirms that a queued event is too old, the app removes that event and its retry metadata; it does not discard potentially deliverable events merely to make room.

If an on-device analytics queue becomes unreadable, the app may keep one exact recovery snapshot for each affected queue store for up to 30 days. Garden Sage never semantically parses or transmits that snapshot, and the app removes it sooner after confirmed account deletion or credential revocation.

Beta-access, support, and privacy submissions are scheduled for deletion from the active service before they reach 12 months. A service interruption may briefly delay a scheduled deletion. A deletion may remain in encrypted rotating backups for up to 14 additional days. To request earlier removal, visit Garden Sage Support, choose Privacy request, and provide the same email address so we can locate the submission. This website-request process is separate from deleting an in-app account.

Operational notification emails contain only the request type, record ID, and receipt time. The submitted name, email address, and message remain in the access-controlled record governed by the retention period above.

Your choices

  • You can decline or revoke location and photo-library access in iOS Settings.
  • You can clear optional country, state, and USDA-zone profile selections in Account.
  • You can choose which photos to submit and which results to save.
  • You can revoke AI photo-processing permission in Account › Privacy; Garden Sage will ask again before a future upload.
  • You can manage or cancel a subscription in your Apple Account settings.
  • You can request account deletion directly in the app.

Security and international processing

We use technical and organisational safeguards designed to protect your information. No service can guarantee absolute security. Information may be processed in countries other than your own by providers supporting Garden Sage, subject to appropriate contractual and legal safeguards.

Children

Garden Sage is not directed to children under 13, or the higher minimum age required in their country. We do not knowingly collect personal information from children below that age.

Changes to this policy

We may update this policy as Garden Sage evolves. We will publish the revised policy at this URL and update the effective date. Material changes will be highlighted in the app or through another appropriate notice.

Contact

For privacy questions or requests, visit Garden Sage Support and include "Privacy" in your message so it can be routed correctly.

Garden Sage gives practical gardening guidance, but plant identification and health suggestions can be wrong. If a plant may be toxic or poses a risk to people or animals, contact an appropriate qualified professional.

Garden Sage Clearer plant care, one photo at a time.
Privacy Support Join the beta