Privacy Policy
This policy is currently provided in English. Localized versions will follow in an app update.
The short version
Gardenix works without an account: your garden data (plants, photos, notes, reminders) lives on your device and we receive no copy. If you choose to create an optional account, your email address and a backup of your garden (including plant photos) are stored on our servers so your garden survives a lost phone or a reinstall; see Optional account. On Android your data is also included in your own Google Drive backup if you have Android backup switched on; see Backups. We do not sell data and we show no ads.
What the app processes
- Plant photos you submit for analysis. When you scan a plant, the photo is sent over an encrypted connection to our server, which forwards it to a third-party AI provider solely to produce the identification and care advice. We do not keep a copy of your photos on our servers; photos are stored on your device and, on Android, in your own backup (see Backups). For free scans, the server keeps a one-way fingerprint (a hash) of each photo for two days, used only to spot the same image being sent from many devices to abuse the free tier. The photo cannot be reconstructed from it.
- Chat questions. Questions you ask the gardener chat are sent to the same AI provider to generate the answer. Threads are stored on your device and, on Android, in your own backup (see Backups).
- Device identifiers for fair-use limits. The app generates an anonymous random ID used to enforce fair-use limits (free scans, daily questions); it is not linked to your identity. To stop the free-scan allowance being reset by reinstalling, the app also derives a value from a device-provided identifier (Android ANDROID_ID / iOS identifier for vendor), hashes it on your device, and sends only that hash to our server. We never receive the raw identifier, and the hash is used to count free scans, to run the referral program described below, and, in a one-way salted form, to measure the app usage described below.
- Approximate location (optional). If you enable weather features, a coarse location (about 11 km precision, or a city you pick manually) is stored on your device and sent only to a third-party weather service to fetch the forecast. Disabling the feature in Settings deletes it.
- Purchases. Subscriptions and scan packs are processed by Apple/Google and our subscription management provider. We receive purchase state (not payment details) to unlock features.
- Referral codes (optional). The app creates an invite code for your device. It is stored on our server together with the anonymous identifiers above, so that a bonus can be credited to the right device. If you redeem a friend's code, we record which code your device used, so that each device can redeem only one code and both of you receive the bonus after your first scan. Your friend only ever sees how many people joined with their code, never who they are. On Android, if you install Gardenix from a friend's invite link, the app reads the invite code once from Google Play's install referrer so you don't have to type it; the rest of that referrer is ignored on your device and never sent to us. These records contain no photos, texts or contact details.
- How you use the app. To understand where people get stuck we record a handful of events on our own servers: the app being opened, a scan finishing, the subscription screen being shown (and which feature led there), and a purchase being started or completed. No third-party analytics service is involved and nothing is sold or shared. Each event stores a one-way salted hash of the device identifier above, never the identifier itself, so the records cannot be traced back to you or joined to your account. You can switch this off in Settings, and deleting your account also deletes these records. Events are deleted automatically after a year.
- Crash reports. Anonymous crash and error diagnostics may be sent to a third-party crash reporting service to keep the app stable. They never include your photos or texts.
- Account details (only if you sign in). Signing in is optional. We store your email address (from the sign-in method you choose: Apple, Google, or a one-time emailed code) and a cloud backup of your garden, including plant photos. We never ask for your name and there is no password. See Optional account.
Backups
- Android. Gardenix uses Android's standard Auto Backup. If backup is switched on in your Google account, your garden data and plant photos are copied to your own Google Drive and restored when you reinstall the app. That backup belongs to you: it does not count against your Drive storage, and on Android 9 and later it is end-to-end encrypted with your device PIN, pattern or password. We have no access to it — it never reaches our servers. You can switch it off or delete it at any time; see Data Deletion.
- iPhone and iPad. Gardenix does not copy your garden to any cloud service, so reinstalling the app starts from scratch. As with any app, its data may be included in your device's own iCloud or computer backup if you have that switched on — that backup is yours and we have no access to it.
Optional account & cloud backup
- Entirely optional. Everything in Gardenix works without an account. Signing in adds one thing: a cloud backup of your garden that you can restore on a new phone or after a reinstall.
- What we store. Your email address and your garden backup (plants, care history, notes and plant photos). We never request your name, and there is no password: you sign in with Apple, Google, or a one-time code sent to your email.
- Where it lives. On our server infrastructure, run by a third-party cloud hosting provider. Sign-in code emails are delivered by our email delivery service. Neither may use your data for anything else.
- Retention and deletion. Kept until you delete it. You can delete your account and the entire backup at any time in the app (Settings → Account → Delete account) or by email; see Data Deletion.
Data retention & deletion
Your garden data lives on your device. Deleting the app removes it from the device; on Android, a copy may remain in your own Google Drive backup until you delete it. Server-side usage counters tied to the anonymous device ID expire automatically and contain no personal content. Referral records are kept for as long as the referral program runs, because they are what stops the same device from redeeming a code twice; you can ask us to delete them by email. If you created an account, your email and cloud backup are kept until you delete the account (in the app or by email). See Data Deletion for details and deletion requests.
Children
The app is not directed at children under 13 and does not knowingly collect their data.
Changes
We will update this page when the policy changes; material changes will be noted in the app.
Contact
ALTF4 s.r.o. — support@altf4.sk