Skip to content

Legal

Privacy Policy

Last updated:

Welcome to Pocket Botanist. Seamless Logic, a trading name of Tom Dudfield, an individual trading as a sole trader based in the United Kingdom, publishes the Pocket Botanist mobile application (the "App") and this website, and is the data controller for the personal data described in this policy. We will give you our service address if you ask for it by emailing support@pocketbotanist.app. In this policy, Seamless Logic is called "we", "us" or "our".

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the App. You can contact us about this policy, or to exercise your rights, at support@pocketbotanist.app.

1. Collection of your information

We may collect information about you in a variety of ways. The information we may collect via the Application depends on the content and materials you use, and includes:

Account & Authentication Data

When you first launch the App, you can use core features as a guest, without creating an account. Guest usage is tracked using a random credential that our server issues and signs, stored securely on your device, with your device's Firebase Installation ID used as a fallback identifier. This guest credential contains no personal information. If you choose to create a named account, we collect:

  • Email Address (Email magic-link sign-in): If you sign in by email, we collect your email address and send a one-time sign-in link to it. We do not collect or store a password. Your email address is stored with your Firebase account and associated with your usage data and any plants you explicitly save to your cloud-synced collection.
  • Google Account Information (Google Sign-In): If you sign in with Google, we receive your Google account ID, display name, and email address from Google. We use this to create or link your account. Please refer to Google's Privacy Policy for information on how Google handles your data during authentication.
  • Apple Account Information (Sign in with Apple): On iPhone and iPad you can use Sign in with Apple. We receive an Apple user identifier and, depending on your choice, your name and an email address (which may be a private relay address that forwards to your real inbox). We use this to create or link your account. Please refer to Apple's Privacy Policy for information on how Apple handles your data during authentication.

The App does not currently support phone-number sign-in or SMS multi-factor authentication. Sensitive account actions (such as deletion) are reauthorized by repeating your existing Apple, Google, or email sign-in.

Identification & Health-Check History

The App keeps two separate records of your plant activity.

Identification and health-check history: each time you identify, look up, or run a health check on a plant, a history entry (the result, a reference to the photo, and the date and time) is saved locally on your device only. This history is capped at your 50 most recent entries, is never synced to the cloud, and is cleared when you sign out.

Your collection: when you explicitly save a plant to your collection, that record is stored locally and, if you are signed in, also synced to the cloud (Firebase Firestore). A saved plant's record may contain:

  • The plant identification result (name, scientific name, care information, etc.)
  • A reference to the photo, stored locally on your device and, if you are signed in, also uploaded to Firebase Storage under your account so it can sync across devices
  • The date and time you saved the plant
  • The plant's location, according to your "Location saved with plants" setting (see Location Data below)
  • Any notes or garden zone labels you add
  • Care log entries, reminders, growth journal entries, and pot details you configure for that plant
  • Diagnosis results for that plant (stored under the collection item)
  • A record of which AI model generated the plant's description and care information, which prompt version it used, and when it was generated (see AI Content Marking below)

You can export your collection at any time as a PDF, CSV, or GeoJSON file using the in-app export feature (a Premium feature). The CSV file includes a place label (such as city and country) and a country code for each plant with a saved location; the PDF file includes the place label only. The GeoJSON file includes the same place details as well as the raw coordinates. Where a plant's details came from the AI model, the CSV and GeoJSON files also name which fields it generated, along with the model name and the generation date, and the PDF carries a short note saying the same. Exported files are shared directly from your device and are not transmitted to our servers.

Image Data

When you use the plant identification or diagnosis feature, the App resizes and compresses your photo locally on your device, then sends the image data inline to Google's Gemini AI API for processing. Identification and diagnosis photos themselves are never uploaded to a server we operate. The original copy of the photo stays on your device. Please refer to Google's Privacy Policy for information on how Google handles data processed by the Gemini API.

If you save an identified plant to your collection while signed in, the App uploads a resized copy of the photo to Firebase Storage under your account (users/{your-uid}/collection/...) so the photo can sync to your other devices. Firebase Storage access is restricted to your authenticated account. You can remove these photos by deleting the plant from your collection or by deleting your account (see Section 7).

Location Data

The App's Settings include a "Location saved with plants" option that controls whether, and how precisely, the App uses your location for tagging plants, weather, pollen alerts, and hardiness-zone detection. This setting defaults to Precise, and you can change it in Settings at any time. It offers three options:

  • Precise: Your coordinates are used and stored unchanged.
  • Approximate: Coordinates are rounded to one decimal place (roughly an 11 km grid) before they are used or stored.
  • Off: The App does not use your location for plant tagging, weather, pollen alerts, or hardiness-zone detection.

If you are signed in, a saved plant's location syncs to your private cloud storage (Firebase Firestore) along with the rest of that plant's record.

Separately, the App's garden map asks your device's operating system for permission to use your location so the map can center on you. This request is not controlled by the "Location saved with plants" setting; you can decline or revoke it at any time from your device's system settings.

Location data is also used to:

  • Derive your USDA hardiness zone (a short code such as "8b") for region-aware care advice on Premium. This hardiness zone code is the only location-derived value we ever send to the Gemini AI, and only for that Premium feature. Plant identification and plant text search never send your location, coordinates, or a place name to Gemini.
  • Fetch local weather, air quality (for pollen alerts), and forecast data from Open-Meteo (see Weather Data below).

Your current location is cached locally on your device for up to 30 minutes to reduce unnecessary GPS lookups. We do not use your location for advertising purposes.

Usage Data

We track the number of AI requests you make each day to enforce daily limits and protect the service from abuse:

  • Plant identification, plant text search, and plant diagnosis share a single daily counter: 3 per day for guests, 5 per day for free signed-in members, and a fair-use cap of 200 per day for Premium members (marketed as "unlimited" for normal personal use).
  • Plant chat and diagnosis chat require you to be signed in and share a single daily counter, separate from the identification counter above. Guests have no chat allowance. Free signed-in members currently get 1 message per day; Premium members currently get 20 messages per day.
  • A short-window burst rate limit (a small number of requests per ten seconds) applies to all tiers to prevent abuse.

For guests, usage is tracked server-side under a random credential that our server issues and signs, stored securely on your device, with your device's Firebase Installation ID (a pseudonymous identifier issued by Google's Firebase Installations service) used as a fallback identifier. For signed-in users, usage is tracked under your Firebase account. Usage counts are used solely to operate the access-tier system and are not used for profiling or advertising.

We also collect information about how you use the App (such as features accessed and error logs), which we aggregate for reporting to help us improve the App. If you are signed in, this data is linked to your account identifier rather than anonymous.

Subscription & Purchase Data (RevenueCat)

We use RevenueCat to manage in-app subscriptions and purchases. When you make a purchase or restore a purchase, RevenueCat receives:

  • A pseudonymous App User ID (your Firebase UID, which does not directly identify you).
  • Purchase receipt data and entitlement status provided by the App Store or Google Play.
  • Which paywall screen led to the purchase, so we can see which entry points are working.
  • Basic device information (platform, app version, SDK version) used for fraud prevention and analytics.

If you are signed in, RevenueCat also receives your email address, so our subscription support and RevenueCat's own integrations can match your account. RevenueCat does not receive your name or payment card details. Those remain with the app store. RevenueCat data is used solely to verify and manage your subscription entitlements and is not used for advertising. Please refer to the RevenueCat Privacy Policy for more information.

Crash & Error Reports (Firebase Crashlytics)

We use Firebase Crashlytics for crash reporting and error monitoring. If the App crashes or encounters a non-fatal error, Crashlytics may collect information including the type of device, operating system version, app version, a stack trace of the error, and a session log of recent app events. After you sign in, Crashlytics also receives your pseudonymous Firebase user ID so we can group crashes by account. Crashlytics is part of Firebase and is governed by Google's privacy terms linked at the bottom of this section.

Crash reports are used solely to diagnose and fix bugs. We do not configure Crashlytics to collect your plant photos, the content of your scans, your chat messages, or your location. You can disable Crashlytics data collection at any time from the App's Settings.

Performance Monitoring (Firebase Performance)

We use Firebase Performance Monitoring to measure App performance (e.g., response times, screen rendering). Firebase Performance collects basic device information (device model, OS version, app version, network type) and aggregated performance traces. This data is not linked to your personal identity and is used solely to identify and improve App performance issues.

Device & Technical Information

We may collect basic device information (e.g., device type, operating system version, app version) for troubleshooting and to optimize the App experience. This information is not linked to personal identifiers.

Chat & Diagnosis Chat Data

Plant-chat and diagnosis-chat require you to be signed in, so guests have no chat allowance. Free members currently get 1 message per day; Premium members currently get 20 messages per day. Each message you send and each AI response is processed by a server-side Firebase Function that calls Google's Gemini AI API. The contents of your messages are sent to Gemini so it can generate a reply.

For signed-in users, chat sessions are stored in Firebase Firestore under your account (users/{your-uid}/chatSessions/...) so the conversation persists across devices and across app launches. Firestore access is restricted by security rules: only your authenticated account can read its own chat sessions, and only the server-side chat function can write them. Each stored AI reply also carries a provenance stamp naming the model that wrote it, the prompt version, and the time it was generated (see AI Content Marking below). You can delete individual chat sessions from within the App, or remove all chat data by deleting your account.

AI Content Marking

Article 50 of the EU AI Act requires AI-generated content to be marked as such. When the App generates a plant description, care guidance, a health check, or a chat reply, it records a short provenance stamp next to that text: the name of the AI model that produced it, the version of the prompt used, and the date and time it was generated.

This stamp holds no personal information. It describes the model, not you. It is stored with the AI-generated record it belongs to, travels with that record when your collection syncs or is exported, and is embedded as metadata in plant cards you share from the App. Plant names and taxonomy from GBIF, and reference photographs from iNaturalist, are not AI-generated, so they are not marked as though they were.

Records saved before this marking was introduced carry no stamp, and we do not add one afterwards, because we cannot know which model produced them.

Care Logs, Reminders, and Streak Data

When you log a care action (watering, fertilizing, repotting, pruning, misting), set a care reminder, or schedule a notice, this information is stored locally on your device and, if you are signed in, mirrored to your Firestore account (users/{your-uid}/streaks/... and on the related collection item). We use this data to power the care streak counter, achievement progress, and reminder notifications. It is not used for advertising or shared with third parties beyond Firebase.

Reference Plant Images (iNaturalist)

After a successful identification, the App may fetch a public reference photo for the identified species from the iNaturalist API so you can compare it to your scan. The only information sent to iNaturalist is the plant's common or scientific name. We do not send your photo, your account, your location, or any other personal data to iNaturalist. Please refer to iNaturalist's privacy policy for details on how they operate.

Plant Names, Occurrence Maps & Reference Images (GBIF)

The App uses the Global Biodiversity Information Facility (GBIF) API to resolve plant names to a canonical scientific name, to fetch a public reference photo when iNaturalist does not have one, and to show an occurrence map of where a species has been recorded. Name resolution and reference photo requests send only the plant's common or scientific name. Whenever the occurrence map is shown on a plant's page, the App requests map tiles from GBIF for the area centered on your device's location, so those tile requests reveal the map area you are viewing. Please refer to GBIF's privacy policy for details on how they operate.

Weather Data

The App uses the Open-Meteo API for weather-based gardening tips, pollen alerts, and weather-aware watering suggestions. Open-Meteo receives your coordinates at the precision you have chosen in Settings (if location access is granted), and returns weather, pollen, and forecast data in response. Open-Meteo does not require an API key and does not collect personally identifiable information. Weather, pollen, and forecast responses are cached locally on your device for between thirty minutes and three hours depending on the data, to reduce unnecessary requests. Please refer to Open-Meteo's privacy documentation for more details.

Advertising Infrastructure (Not Currently Active)

The App does not currently show advertisements. The Android AD_ID permission is explicitly blocked in the app manifest, so the App cannot read your advertising identifier. If we ever enable advertising in the future, this Privacy Policy will be updated in advance.

Note on Third-Party Services:

We use third-party services that have their own privacy policies governing how they collect and use your data. We encourage you to review them:

2. Use of your information

Having accurate information permits us to provide you with a smooth, efficient, and customized experience. Specifically, we may use information collected about you via the Application to:

  • Create and manage your account (guest or named).
  • Provide, operate, and maintain the App, including plant identification, diagnosis, companion planting suggestions, and care information.
  • Sync your saved plants and preferences across devices when you are signed in.
  • Enforce daily usage limits.
  • Send plant care reminders via push notifications (only if you have granted notification permission).
  • Derive your USDA hardiness zone for region-aware care advice on Premium.
  • Improve, personalize, and expand the App.
  • Understand and analyze how you use the App through usage data we aggregate for reporting. If you are signed in, this data is linked to your account identifier rather than anonymous.
  • Diagnose and fix technical issues through crash and error reports.
  • Comply with legal obligations.

3. Disclosure of your information

We may share information we have collected about you in certain situations. Your information may be disclosed as follows:

  • By Law or to Protect Rights: If we believe the release of information about you is necessary to respond to legal process, to investigate or remedy potential violations of our policies, or to protect the rights, property, and safety of others, we may share your information as permitted or required by any applicable law, rule, or regulation.
  • Third-Party Service Providers: We share your information with third parties that perform services for us or on our behalf, including Firebase (authentication, cloud database and storage, cloud functions, app integrity, analytics, crash reporting, performance monitoring, and remote configuration), Google Sign-In and Sign in with Apple (authentication), RevenueCat (subscription and purchase management), Open-Meteo (weather data), iNaturalist (public plant reference photos), and GBIF (plant name resolution, occurrence maps, and reference photos). These providers process your data only as necessary to provide their services.
  • AI Processing (Gemini API): Photos and chat messages you submit for plant identification, diagnosis, text search, or in-app chat are sent to Google's Gemini AI API for processing. For the Premium regional advice feature, your USDA hardiness zone (not your coordinates or a place name) is also sent. This is necessary to provide the core functionality of the App.
  • Business Transfers: We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
  • Aggregated or Anonymized Data: We may share aggregated or anonymized information, which does not directly identify you, with third parties for various purposes, including research or improving our services.

We do not sell your personal information.

4. Cookies and analytics

This website does not set advertising cookies, and it does not use cookies or other technologies that identify you or follow you across other websites. We do not run Google Analytics or any third-party advertising or analytics tags here, so there is no cookie banner to accept. The Pocket Botanist mobile app does not use cookies either.

Our mobile application stores data locally on your device using AsyncStorage (a standard React Native key-value store). This includes your identification history, settings preferences, daily usage counts, and temporary data such as a pending sign-in email address. This data remains on your device and is not shared with third parties, except where it is synced to Firebase Firestore for signed-in users as described in this policy.

If you are in the UK or the European Economic Area (EEA), or if the App cannot determine your region, the App asks whether to turn Firebase Analytics on the first time you use it, and Analytics stays off until you answer. In other regions, Analytics is switched on for you once you finish onboarding. Either way, you can turn Analytics off at any time from the App's Settings. When enabled, Firebase Analytics collects information about how you use the App (such as which features are used and session information), which we aggregate for reporting to understand usage patterns and improve the App. If you are signed in, these analytics events are linked to your account identifier rather than anonymous. Firebase Performance Monitoring does not have its own Settings toggle; see the Performance Monitoring section above for what it collects.

Where we ask you and you say yes, your consent is the lawful basis we rely on for Firebase Analytics, and you can withdraw it at any time in Settings. In regions where Analytics is switched on for you after onboarding, we rely on our legitimate interests instead, and you can still switch it off. Section 9 sets out our lawful bases in full.

We use Firebase App Check (using Play Integrity on Android, and App Attest on iOS with Apple's DeviceCheck service as a fallback) to verify that requests to our backend come from genuine instances of the App. This is a security measure and does not involve collecting personal information beyond device attestation tokens.

RevenueCat may use a pseudonymous device-level identifier (your Firebase UID) to associate subscription status with your account. See the Subscription & Purchase Data section above for details.

The Android AD_ID permission is explicitly blocked in the App's manifest, which means the App cannot read your advertising identifier and does not use one for any purpose.

5. Push notifications

With your permission, the App can send you local push notifications to remind you to care for your plants (e.g., watering, fertilizing, repotting). These reminders are scheduled locally on your device and are not sent via a remote push notification server. You can configure quiet hours and disable reminders in the App's Settings, or revoke notification permission through your device settings at any time.

6. Data security

We use administrative, technical, and physical security measures to help protect your information, including Firebase App Check to verify the integrity of requests to our backend services, and automatic scrubbing of error messages in crash reports. Before an error message is sent, we remove things like email addresses, tokens, file paths, and query strings. The accompanying stack trace is sent as-is, so it may still contain code paths. While we have taken reasonable steps to secure the information you provide to us, please be aware that despite our efforts, no security measures are perfect or impenetrable, and no method of data transmission can be guaranteed against any interception or other type of misuse. Therefore, we cannot guarantee complete security if you provide personal information.

7. Data retention

We will retain your information only for as long as is necessary for the purposes set out in this privacy policy:

  • Guest usage counters: Usage counters tracked against a guest credential or Firebase Installation ID are retained for 8 days.
  • Signed-in usage counters: Usage counters tracked against your Firebase account are retained for 30 days.
  • Chat data: Plant-chat and diagnosis-chat sessions are retained for about 30 days, after which a periodic cleanup job removes them.
  • Analytics data: Firebase Analytics event data is retained for 14 months.
  • Account data: Your email address, sign-in identifiers and account record are kept for as long as your account stays open, because we need them to sign you in and to sync your collection. They are deleted when you delete your account, apart from the abuse-prevention record described below. We do not currently delete accounts for inactivity. If we introduce a policy that deletes dormant accounts in the future, we will give you notice before the policy takes effect and before any account is deleted under it.
  • Collection (cloud): If you are signed in, your saved plants are stored in Firebase Firestore until you delete individual items or request account deletion.
  • Local data: Data stored in AsyncStorage on your device (including identification history, settings, and usage counts) persists until you uninstall the App or clear the App's data through your device settings.
  • Crash reports: Crash report data retained by Crashlytics is subject to Crashlytics's own data retention policies.

You can delete your account at any time from the App's Settings. If you cannot access the App, you can instead request deletion by contacting us using the details in Section 11. When your account is deleted, we permanently delete your Firestore data under users/{your-uid} (your collection, chat sessions, streaks, and care logs), your chat usage records, your reauthentication records, your Storage files, and your Firebase Auth account. For abuse-prevention purposes, we keep a separate record with no expiry: your subscription entitlement status and a link between your account and your device's Firebase Installation ID. We also keep a copy of your daily usage counts under a device-keyed record. Because this data stays linked to your device's Firebase Installation ID, it is pseudonymous, not anonymous.

8. Children's privacy

Our App is not intended for use by children under the age of 13 (or a higher age threshold if required by applicable law, e.g., 16 in some EU countries under GDPR). We do not knowingly collect personally identifiable information from children under these ages. If we become aware that we have collected personal information from a child under the relevant age without verification of parental consent, we will take steps to remove that information from our servers. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us.

9. Your data protection rights (e.g., GDPR/CCPA)

Depending on your location and applicable laws, you may have certain rights regarding your personal information. These may include the right to:

  • Access the personal information we hold about you.
  • Request that we correct any inaccurate personal information.
  • Request that we delete your personal information.
  • Object to or restrict our processing of your personal information.
  • Request the transfer of your personal information to another party (data portability).
  • Withdraw consent at any time (if processing is based on consent).

If you wish to exercise any of these rights, please contact us at the email address provided below. We will respond to your request within the timeframes required by applicable law.

Complaining to a regulator. If you are unhappy with how we have handled your personal data, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint, by post at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, or by phone on 0303 123 1113. If you are in the EEA, you can complain to your national data protection authority. We would rather hear from you first at support@pocketbotanist.app.

For European Union (EU) and United Kingdom (UK) Residents (GDPR):

If you are a resident of the European Economic Area (EEA) or the UK, you have certain data protection rights. We aim to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.

Legal Basis for Processing Personal Data under GDPR:

  • Performance of our contract with you (Article 6(1)(b)): running the App, identifying and diagnosing your plants, sending your plant images to the Gemini API, syncing your collection, enforcing usage limits and tiers, and managing your subscription.
  • Consent (Article 6(1)(a)): Firebase Analytics where we ask you and you say yes, which is what happens in the UK and the EEA and wherever the App cannot work out your region. You can withdraw that consent at any time in the App's Settings, and withdrawing it does not affect anything we did before you withdrew it.
  • Our legitimate interests (Article 6(1)(f)): keeping the App secure and preventing abuse (App Check, usage counters, rate limiting), diagnosing crashes and errors so we can fix faults, and, in regions where Analytics is switched on after onboarding rather than asked for, understanding how the App is used so we can improve it. We have balanced these interests against your rights and freedoms, and you can object at any time using the contact details in Section 11. If you are signed in, usage analytics and crash reports are linked to your account identifier rather than anonymous.
  • Legal obligation (Article 6(1)(c)): processing necessary for compliance with a legal obligation to which we are subject.

Camera, location and notification permissions are granted through your device's operating system. They control what the App is allowed to access. They are not, by themselves, your consent under data protection law, and the lawful basis for what we then do with that data is the one set out above.

Do you have to give us this data? You do not have to give us any personal data to use the App as a guest. Creating an account requires an email address, or a sign-in identifier from Apple or Google, because that is how we recognize you and sync your collection. That is a contractual requirement: without it we cannot give you an account, cloud sync, or chat. Camera, location and notification permissions are optional. If you decline them, the features that depend on them will not work, but the rest of the App will.

Automated decisions. We do not make decisions about you that produce a legal effect, or a similarly significant effect, using automated processing alone, and we do not profile you. The App's identification, diagnosis and care suggestions are generated by AI, but they are information for you to act on, not decisions we make about you.

AI model training. We use Google's Gemini API, both directly from the App through Firebase AI Logic and from our server through Google's Genkit framework, to process the photos, text queries, and chat messages you send. Every Google Cloud project we use for this processing has an active Cloud Billing account, because that is required to run our server-side Cloud Functions, so our use of the Gemini API sits in Google's paid tier under its Gemini API Additional Terms. Under those terms, on the paid tier Google does not use your prompts or its responses to train or improve its general models, and keeps only limited, short-lived logs to detect abuse. Firebase AI Logic's own data-governance documentation defers to those same terms.

Sending data outside the UK. Some of our providers, including Google, process personal data outside the UK and the EEA (for example on Google's servers for Firebase and Gemini API processing). Where that happens, the transfer is covered either by an adequacy decision, called adequacy regulations in the UK, or by contractual safeguards. For transfers out of the UK those safeguards are the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. For transfers out of the EEA they are the EU Standard Contractual Clauses. You can ask us for a copy of the safeguards that apply to you by writing to support@pocketbotanist.app.

For United States residents:

This section supplements the information contained in our Privacy Policy. It applies to residents of California under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CPRA). Residents of other states with their own privacy statutes, including Virginia, Colorado, Connecticut, Utah and Texas, have broadly similar rights, and we handle their requests the same way.

Categories of personal information collected: In the preceding twelve (12) months, we have collected the following categories of personal information:

  • Identifiers (e.g., Firebase user ID, email address if you sign in, and your device's Firebase Installation ID).
  • Internet or other similar network activity (e.g., usage data, feature access, error logs).
  • Geolocation data (if you grant location permission: city and country level, or GPS coordinates stored with collection items).
  • Visual information (e.g., images you submit for plant identification or diagnosis, processed locally and sent to the Gemini API).
  • Commercial information (your subscription and purchase status).
  • Sensitive personal information: precise geolocation, where you have left the "Location saved with plants" setting on Precise. We use it only to tag your plants and to provide weather, pollen and hardiness-zone features. We do not use it to infer characteristics about you.

Categories of sources: we collect this information directly from you and from your device. We also receive account identifiers from Apple and Google when you sign in with them, and purchase and entitlement information from the App Store, Google Play and RevenueCat.

Categories of third parties we disclose to: the service providers listed in Section 3 (Disclosure of your information), including Google for Firebase and Gemini API services and Crashlytics for crash reporting. We disclose personal information to them for business purposes only.

Business or commercial purposes: we collect personal information for the business purposes described in Section 2 (Use of your information).

Retention: we keep each category for the periods, and on the criteria, set out in Section 7 (Data retention). Where a category is not listed there, we keep it only for as long as we need it for the purpose we collected it for.

We do not sell or share your personal information. We do not sell personal information, and we do not share it for cross-context behavioral advertising. Advertisements are not currently served in the App. If that ever changes, this policy will be updated and opt-out mechanisms will be provided before any sale or sharing begins.

Your rights: California residents have the right to:

  • Know and access what personal information we collect, use, disclose and keep about you, and receive a copy of it (the right to know).
  • Have inaccurate personal information about you corrected (the right to correct).
  • Request that we delete personal information we collected from you, subject to certain exceptions (the right to delete).
  • Opt out of the sale or sharing of personal information. We do not sell or share personal information, so there is nothing to opt out of today.
  • Limit our use and disclosure of sensitive personal information. We use precise geolocation only to provide the features you asked for, which is a permitted use, and you can switch that setting to Approximate or Off at any time in the App's Settings.
  • Not be discriminated or retaliated against for exercising any of these rights.

Global Privacy Control. This website sets no advertising cookies and we do not sell or share personal information, so there is nothing for an opt-out signal to stop today. We treat a Global Privacy Control signal sent by your browser as a valid opt-out request, and if we ever introduce selling or sharing we will honor it automatically.

How to make a request. Contact us using the details in Section 11. You can use an authorized agent, who must give us written permission signed by you. Before we act on a request we will verify who you are, normally by asking you to make the request from the email address on your account, or by asking you to sign in. We will respond within the time the law allows.

10. Changes to this privacy policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page. Significant changes may also be communicated through the App or via email if we have your contact information.

11. Contact us

If you have any questions or suggestions about our Privacy Policy, or to exercise your data rights, do not hesitate to contact us.

General questions: hello@pocketbotanist.app

Data requests or account help: support@pocketbotanist.app