Privacy policy
Effective 30 July 2026
Your plants, photos and notes stay on your phone. There's no account, no advertising and no analytics. The only thing I ever hold is a count of AI requests, and only if you use the AI features. The rest of this page is the detail behind those sentences.
Who I am
My Wife's Plants is written and published by Jacob North, who is the data controller for the small amount of processing described here. Reach me at support@mywifesplants.app.
What stays on your phone
Plant names, nicknames, locations, photos, care details, notes, watering history, fertilizing state, per-plant conversations, reminder settings and identification metadata all live in the app's private storage on your device. None of it is synced to an account or to any database of mine.
The app schedules local notifications. Depending on your phone's settings, a plant's nickname, species, location and reminder may show on the lock screen.
Camera and photo access is requested only when you choose to add or identify a plant; notification permission only to deliver your own reminders. Refuse any of them and the rest of the app carries on working.
What leaves it, and when
The AI features are optional. Your plants, reminders, watering and feeding schedules, the built-in care guides for 120 houseplants and backups all work with no connection and no subscription.
Use the AI, and up to three services are involved.
Google Gemini — the AI itself
- Identify from a photo: Gemini receives that photo, and returns the species and its care details.
- Pick a species by name: Gemini receives the name only. No photo.
- Ask about one of your plants: Gemini receives that plant's saved profile — schedule, spot, pot size, care notes and your own notes on it — plus the conversation so far, so the answer is about your plant rather than the species in general. The app shows you exactly what it was told.
- Sunlight spot check: Gemini receives the photo of the place and the plant's light needs. That photo is never saved.
Nothing else goes: not your other plants, not your watering history, not your reminder settings. Google processes what it receives under its own policy and retention terms.
The care proxy — a small server I run
In the public build, AI requests go through a relay of mine rather than straight to Google, so that the Gemini credential is never inside the app on your phone. It:
- forwards the request and returns the answer;
- stores and logs nothing — no photos, no prompts, no plant data, no responses;
- keeps a count of requests per anonymous subscriber, per month, so a subscription's allowance can be enforced. A number, not a copy of anything you sent. Monthly counts reset; the count of free identifications persists, so the free allowance can't be reused;
- writes a short operational log — which feature, which model, what status — to spot outages. No photos, no prompts, no plant data, nothing identifying you.
It also applies a short-lived rate limit based on the network address a request arrives from, to stop the free allowance being farmed. Used for that check, not kept as a record of you.
RevenueCat — subscriptions
- Holds an anonymous identifier it generates for your installation, the receipt Apple issued, and the store metadata on it: platform, country, whether the subscription is active.
- No email, no name, no account. There is nothing to sign into.
- That identifier is what the proxy checks for an active subscription and remaining allowance.
- The purchase itself is Apple's. Apple holds your payment details; the app never sees them.
If you don't subscribe
If a request fails, if you have no subscription, or if the build has no AI at all, the app falls back to its built-in guides for 120 houseplants. Add plants by name and it works entirely offline.
What I don't collect
No advertising, no analytics SDK, no cross-app tracking, no accounts. I don't sell or share personal information. The app doesn't touch your contacts, your location or your advertising identifier, and it never asks for App Tracking Transparency permission, because it doesn't track you.
The one thing kept on a server of mine is the per-subscriber request count above, which exists only to enforce an allowance.
Legal bases
Where UK or EU data protection law applies:
| What | Basis |
|---|---|
| Sending a photo or plant details to the AI when you use an AI feature | Contract — it's the feature you asked for (Art. 6(1)(b)) |
| Counting requests against a subscription allowance | Contract (Art. 6(1)(b)) |
| Rate limiting and operational logs | Legitimate interests — keeping it up and preventing abuse (Art. 6(1)(f)) |
| Subscription state at RevenueCat and Apple | Contract (Art. 6(1)(b)) |
Everything on your device is processed on your device and never sent to me.
International transfers
The proxy runs on Cloudflare's global network, and Google and RevenueCat operate internationally, so the limited data above may be processed outside the UK and EEA, including in the United States. Those providers rely on Standard Contractual Clauses or an equivalent mechanism. No plant data, photos or prompts are stored by me anywhere.
Backups
Export backup writes a JSON file holding your plant records, care history, conversations, preferences and encoded photos. You choose where it goes. Anyone who can open that file can read all of it, so keep it somewhere you'd keep a photo album.
Subscription state is deliberately not in a backup, and can't be granted by editing one.
How long things are kept
- On-device data stays until you delete a plant, restore a different backup, clear the app's data or uninstall it. Deleting a plant takes its photo, history and conversation with it. Uninstalling removes all of it.
- Request counts on the proxy cover the current and previous calendar month, then expire on their own.
- Operational logs are kept briefly for diagnosis and contain nothing identifying you.
- Subscription records at RevenueCat and Apple follow their own terms. Cancelling is done in your Apple ID settings.
Your rights
Depending on where you live you may have rights to access, correct, delete, restrict or object to processing, and to portability. Here's what that means in practice:
- Data on your phone
- You already hold it. Edit or delete any plant, export a portable copy with Export backup, or uninstall to erase the lot. I have no copy to send you and none to delete.
- Your anonymous identifier and its request count
- Generated by the store SDK, not by me, and not linked to your name, email or Apple ID — which also means I can't look it up from an email address. Uninstalling discards your copy, and monthly counts expire by themselves. If you want the counters against a particular identifier erased, get in touch and I'll help work out which record it is.
- Subscription records
- Held by Apple and RevenueCat under their own policies. Cancellations and refunds go through your Apple ID.
I'll answer within a month. If you're in the UK or EEA and unhappy with the answer, you can complain to your supervisory authority — in the UK, the Information Commissioner's Office at ico.org.uk.
California
I don't sell personal information and don't share it for cross-context behavioural advertising, and haven't in the past twelve months. There are no advertising identifiers and no tracking in the app, so there's nothing to opt out of. California residents can still use the access and deletion routes above.
Children
The app isn't directed at children under 13 and doesn't knowingly collect account or contact details from them. If you think a child has sent me something, tell me and I'll delete it.
Changes and contact
If this policy changes materially I'll update this page and its date, and note it in the app's release notes.
Questions: support@mywifesplants.app.