Privacy policy
Last updated
Your saved plants, photos and notes stay on your phone. If you choose an AI feature, the specific photo and plant details needed for that request are sent for processing, as described below. There's no app account, advertising or analytics SDK. This policy also covers visits to this website and messages you send for support.
Who I am
My Wife's Plants is written and published by Jacob North, based in the State of Georgia, United States. I'm the data controller for the small amount of processing described here. The app is operated from the United States, and service providers may process data in other countries as described below. Reach me at support@mywifesplants.app.
What stays on your phone
Plant names, nicknames, locations, photos, care details, notes, watering history, fertilizing state, per-plant conversations, reminder settings and identification metadata all live in the app's private storage on your device. None of it is synced to an account or stored in any database of mine. The limited data used for an AI request is transmitted only when you choose that feature, as described next.
The app schedules local notifications. Depending on your phone's settings, a plant's nickname, species, location and reminder may show on the lock screen.
Camera and photo access is used when you choose to add or change a plant photo, identify a plant, check a sunlight spot or check whether a plant looks sick; notification permission only to deliver your own reminders. Refuse any of them and the rest of the app carries on working.
What leaves it, and when
The AI features are optional. Your plants, reminders, watering and feeding schedules, the built-in care guides for 252 houseplants and backups all work with no connection and no subscription.
AI content is sent when you use an AI feature. Separately, the App Store build connects to RevenueCat and the care proxy at startup to check subscriptions and allowances, even if you haven't subscribed or sent an AI request.
Anthropic Claude — the AI itself
- Identify from a photo: Claude receives a metadata-stripped copy of that photo, and the pot size if you've chosen one. If you add the optional leaf close-up or leaf-underside photo, Claude also receives a metadata-stripped copy of each. It returns the scientific name, common name and care details, plus a pot-size guess and notes on photo quality and how healthy the plant looks. The extra leaf photos are used only for that identification: the app doesn't save them with the plant, and deletes them when you finish or leave adding the plant.
- AI care and feeding lookups: Claude receives the species name, and the pot size if you've chosen one, to generate care details or a feeding plan. A feeding lookup also includes the plant's light level and current feeding interval, where recorded. Searching the built-in guides works offline.
- Ask about one of your plants: Claude receives that plant's nickname, species, room or spot, watering and feeding schedule, last-watered and next-due dates, pot size, light needs, safety information, acquisition date, care guide and your notes, where recorded. It also receives your question and up to 20 prior messages from that plant's conversation. The app lets you view the plant context sent with the question.
- Sunlight spot check: Claude receives a metadata-stripped photo of the place, the plant's nickname and species, light and placement guidance, and any spot description you enter. The app does not add that photo to your saved plant record.
- “Is it sick?” health check: Claude receives a metadata-stripped photo of the plant, and that plant's nickname, species and watering interval, plus its light level, water amount, pot size, last-watered date and care notes, where recorded. Your personal notes are not sent. It returns a verdict on how the plant looks, a short summary and a few things to try. The app doesn't keep the photo; the result is added to the plant's notes only if you choose to save it.
- “Meet your collection” reading: Claude receives a summary of your active plants that the app works out on your phone: how many plants, species and rooms you have, six scores describing the collection, and for each plant its nickname, species, type, room, watering interval, light level, pot size, safety information, how long you have had it and its recorded condition. No photos and none of your notes are sent. It returns a name and short description for the collection, a line about each score, and one plant you might add. The chart and the statistics on that screen are calculated on your phone and are not sent anywhere.
Every AI call also carries the app's fixed care instructions, and an identification also carries a fixed plant-identification guide — the same text on every request, cached on Anthropic's side so it doesn't have to be reprocessed. The app does not send your other plants or the full watering-event log. Information you include in a photo, note or message can still be part of the request, so avoid including private information about yourself or other people. Anthropic processes content under its privacy policy and API retention terms; provider retention can vary by model, service settings and legal or safety requirements.
The care proxy — a small server I run
In the public build, AI requests go through a relay of mine rather than straight to Anthropic, so that the Anthropic credential is never inside the app on your phone. It:
- forwards the request and returns the answer;
- does not save AI request content — the proxy code does not store photos, prompts, plant data or responses;
- keeps monthly and lifetime free-use counts against a pseudonymous subscriber identifier, plus request identifiers and timestamps to avoid counting retries twice;
- temporarily caches subscription status and expiry information to verify access;
- writes operational events such as the feature, model, result status and subscription-check outcome. These application logs omit photos, prompts, plant data and subscriber identifiers.
The proxy runs on Cloudflare. It uses your IP address and subscriber identifier in temporary rate-limit records to prevent abuse. Cloudflare also processes technical request information to deliver and protect the service. See Cloudflare's privacy policy and the retention details below.
iNaturalist — reference photos
When the AI suggests possible matches, the app may send only a suggested common or scientific plant name to iNaturalist's public API to find a reference thumbnail. It does not send your uploaded photo, plant collection, care history or profile. iNaturalist and the service hosting each reference image also receive your IP address and standard network request information when the app loads them. See iNaturalist's privacy policy.
RevenueCat — subscriptions
- Generates a pseudonymous app user identifier for your installation. It processes purchase receipts, subscription status and technical information such as app and OS version, device information, IP address and store country, as described in RevenueCat's privacy policy.
- No email, no name, no account. There is nothing to sign into.
- That identifier is what the proxy checks for an active subscription and remaining allowance.
- The purchase itself is Apple's. Apple holds your payment details; the app never sees them. See Apple's privacy policy.
The identifier is not a name or email address, but it can link requests and purchase activity, so it should not be treated as fully anonymous. Restoring purchases may associate identifiers through the store and RevenueCat.
If you don't subscribe
If a request fails, if you have no subscription, or if the build has no AI at all, the app falls back to its built-in guides for 252 houseplants. Add plants by name and it works entirely offline.
Website visits and support email
Cloudflare hosts this website and processes IP addresses and standard request information to serve pages and protect the site. The site source contains no advertising, analytics scripts or tracking cookies. Hosting and security records are separate from the app's plant collection.
If you email support, I and the email providers handling delivery receive your email address, message and any attachments you choose to send. I use these to answer questions, investigate problems and handle privacy requests. Please don't send passwords, payment details or a full plant backup unless we have discussed why it is needed. A support attachment is retained in email; it is not covered by the proxy's rule against storing AI content.
What I don't collect
No advertising, no analytics SDK, no cross-app tracking, no accounts. I don't sell or share personal information for targeted advertising. Data is shared with the service providers described above to operate the app and website. The app doesn't request your contacts, GPS location or your advertising identifier, and it never asks for App Tracking Transparency permission, because it doesn't track you.
Server-side records are limited to the operational, subscription, usage and support information described here. Your plant collection is not synced to a developer account.
Legal bases
Where UK or EU data protection law applies, the purposes and legal bases for processing are:
| What | Basis |
|---|---|
| Sending a photo or plant details to the AI when you use an AI feature | Contract — it's the feature you asked for (Art. 6(1)(b)) |
| Counting requests against a subscription allowance | Contract (Art. 6(1)(b)) |
| Rate limiting and operational logs | Legitimate interests — keeping it up and preventing abuse (Art. 6(1)(f)) |
| Subscription state at RevenueCat and Apple | Contract (Art. 6(1)(b)) |
| Serving and protecting this website; answering support messages | Legitimate interests — providing information, help and a reliable service (Art. 6(1)(f)) |
| Responding to legally required privacy requests | Legal obligation (Art. 6(1)(c)) |
Local plant storage and reminders do not require sending your collection to me.
Where processing happens
I'm in the United States, so that's where anything reaching me is handled. The proxy runs on Cloudflare's global network and is served from whichever edge location is nearest you; Anthropic and RevenueCat operate internationally.
If you're in the UK or EEA, that means the limited data described above is transferred outside it. Applicable safeguards are described in each provider's privacy policy and data-processing terms. Contact me for information about the safeguards that apply to your data. The proxy forwards AI content without saving it; providers' own retention rules and attachments you send to support are separate.
Backups
Export backup writes a JSON file holding your plant records, care history, conversations, preferences and encoded photos. You choose where it goes. Anyone who can open that file can read all of it, so keep it somewhere you'd keep a photo album.
Exported backups are not encrypted by the app. Copies you save to Files, iCloud Drive or another service remain there until you delete them. iOS device backups may also include app data, depending on your settings; manage those copies through Apple or the backup provider. Deleting the app does not delete existing backups.
Subscription state is deliberately not in a backup, and can't be granted by editing one.
How long things are kept
- On-device plant data stays until you delete it, replace it with a backup or delete the app. Offloading an iOS app keeps its documents and data. Exported and device backups must be managed separately.
- Monthly usage resets when the proxy next handles a request in a new calendar month. Stored counter records do not automatically expire; lifetime free-use counts persist until deleted. Retry identifiers are used for a ten-minute deduplication window and pruned on a subsequent successful request; inactive records can remain stored.
- Per-minute rate-limit records, keyed by subscriber identifier or IP address, expire 120 seconds after their last update. Daily free-use IP records expire 48 hours after their last update.
- Cached subscription status expires 24 hours after its last successful refresh.
- Application logs and hosting/security records follow the configured Cloudflare retention settings. Contact me for details about a particular record.
- Support correspondence is kept as needed to resolve the request and handle follow-up, disputes or legal obligations. You can request deletion.
- AI content at Anthropic follows the API retention terms linked above. The app's local deletion does not itself delete a provider's records.
- Subscription records at RevenueCat and Apple follow their own terms. Cancelling is done in your Apple ID settings.
Your rights
Depending on where you live you may have rights to access, correct, delete, restrict or object to processing, and to portability. Here's what that means in practice:
- Data on your phone
- Edit or delete any plant, export a portable copy with Export backup, or delete the app to remove its local plant data. Manage exported and device backups separately. I don't hold your collection unless you choose to send it to support.
- Your app user identifier and usage records
- These records aren't indexed by your email address. Deleting the app does not erase server-side records. Contact me and I'll help identify the relevant records and handle an access or deletion request, subject to applicable retention obligations.
- Subscription records
- Contact me about data processed for the app through RevenueCat or other providers. Apple also handles store records under its own policy. Cancelling a subscription and deleting personal data are separate actions; cancellations and refunds go through Apple.
- Support correspondence
- Contact me from the address you used for support to request access, correction or deletion of that correspondence.
Email support@mywifesplants.app and I'll respond without undue delay and within one calendar month, or sooner if the law requires. If a lawful extension or identity check is needed, I'll explain why. I won't charge you for asking, and I won't treat you any differently for having asked.
If you're unhappy with the answer: in the United States you can complain to your state Attorney General — for Georgia, the Georgia Department of Law's Consumer Protection Division. In the UK or EEA you can complain to your supervisory authority — in the UK, the Information Commissioner's Office at ico.org.uk.
US state privacy rights
Depending on your state and whether its privacy law applies to this service, you may have rights to access, correct or delete personal information, obtain a copy, appeal a denied request, or opt out of sale or targeted advertising.
- I don't sell personal information, and don't share it for cross-context behavioural advertising. I haven't in the past twelve months and have no plans to.
- There are no advertising identifiers, no analytics and no tracking in the app, so there is no targeted advertising to opt out of.
- The app does not request sensitive personal information. Avoid including it in photos, notes, AI messages or support emails.
- Nothing here is used for profiling or any automated decision with a legal or similarly significant effect.
What's left is access, correction and deletion — and the Your rights section above is how you exercise them, wherever you live. Because there's no account, I can't identify you from an email address; that section explains what I can and can't reach, and what you already hold on your own phone.
Children
The app isn't directed at children under 13 and doesn't knowingly collect personal information from them. Photos, AI messages and support emails can contain personal information even without an account. If you believe a child under 13 has provided personal information, contact me so I can investigate and arrange appropriate deletion.
Changes and contact
If this policy changes materially I'll update this page and its date, and note it in the app's release notes.
Questions: support@mywifesplants.app.