plantyful
DEEN
Back to home

Privacy

Privacy Policy

Last updated: August 22, 2026

1. Controller

Julian Zefferer
Müllerstraße 29
13353 Berlin, Germany
Email: hello@julianzett.com

2. Scope

This policy explains how Plantyful processes personal data in the iOS app, including service providers that process data on our behalf. Plantyful does not sell personal data or use it for personalized advertising or cross-app tracking.

3. Data we process

Account and sign-in

  • Email address, sign-in provider, and a random account ID.
  • Authentication and session data needed for sign-in, account security, and synchronization.

Plant, room, and user content

  • Plant species and names, care schedules and logs, light, substrate, pot, and location details.
  • Rooms, furnishings, progress, XP, Amber, streaks, milestones, and settings.
  • Plant photos you select or capture and associated journal notes. Photo files remain on your device; associated journal metadata may be synchronized with your garden data.
  • Memberships, roles, and invitations for privately shared gardens.

Purchases

  • Purchased product, transaction and purchase history, and the Plantyful account ID.
  • No card or bank details; Apple processes payment information.

Diagnostics and performance

  • Crashes, handled errors, app/build version, device type, operating system, and technical event context.
  • Sampled performance traces for approximately 10% of operations.
  • The account ID may be attached to Sentry to diagnose account-specific failures; Plantyful does not intentionally send an email address or name to Sentry.

Optional product analytics

PostHog product analytics is off by default. Only after your affirmative consent may Plantyful collect app launches, sanitized screen names, onboarding steps, care, shop, notification, and sharing events, plus technical properties such as app version, platform, and language. PostHog uses a random installation identifier. Plantyful does not send your email, account ID, plant names, photos, notes, push tokens, purchase prices, or revenue to PostHog and does not join the installation identifier to Supabase or RevenueCat. Session Replay and GeoIP are disabled.

4. Purposes and legal bases

  • Contract performance (GDPR Art. 6(1)(b)): account, sign-in, local operation, cloud synchronization, shared gardens, care features, and purchase fulfillment.
  • Consent (GDPR Art. 6(1)(a)): optional product analytics. You may withdraw consent at any time in Profile.
  • Legitimate interests (GDPR Art. 6(1)(f)): stability, diagnostics, abuse and fraud prevention, and secure delivery.
  • Legal obligations (GDPR Art. 6(1)(c)): mandatory retention and handling of purchase or authority-related records.

5. Service providers and recipients

  • Supabase: authentication and Postgres database for synchronized account and garden data; production region eu-central-1 (Frankfurt).
  • Sentry: crash, error, and performance diagnostics.
  • RevenueCat: validation, attribution, and fulfillment of in-app purchases.
  • Apple: Sign in with Apple, app distribution, and payment processing.
  • PostHog Cloud EU: optional consent-based product analytics hosted in Frankfurt.

Where a provider processes data outside the EEA, we rely on available appropriate safeguards such as adequacy decisions, the EU-U.S. Data Privacy Framework, or EU Standard Contractual Clauses. Details are provided in the relevant provider agreements and privacy notices.

6. Local storage, notifications, and permissions

  • Plantyful stores a SQLCipher-encrypted SQLite database on your device.
  • Care reminders are currently scheduled locally. Plantyful does not upload an Expo push token for this feature.
  • Camera and photo-library access are requested only when you choose to add a plant or journal photo.
  • You can disable notifications and individual categories in Plantyful or system settings.

7. Retention

  • Account and garden data are generally kept until account deletion or until no longer needed for the stated purpose.
  • Raw PostHog events are currently retained for no more than 12 months.
  • Sentry events are retained for 30 days.
  • Purchase records may be retained longer for fulfillment, fraud prevention, or legal obligations.
  • Technical backups may contain data for a limited additional period and are overwritten according to the relevant backup cycle.

8. Account deletion and analytics withdrawal

Delete your account in Profile → Account → Delete account. This removes your account and synchronized user data from active systems. If you manage a shared garden, management is transferred to the longest-standing remaining member first. Legally required purchase records are not affected.

You can disable product analytics in Profile at any time, which stops future collection. To request deletion of previously collected anonymous analytics data, contact us at the email address above.

9. Your rights

Subject to applicable law, you may have rights of access, correction, deletion, restriction, portability, and objection. You may withdraw consent at any time for future processing and lodge a complaint with a data protection authority. Email hello@julianzett.com to exercise your rights.

10. Children

Plantyful is not directed specifically at children under 13. If we learn that a child’s data was processed without required permission, we will delete it as required by law.

11. Changes

We update this policy when features, service providers, or legal requirements change. The date above indicates the current version.

Privacy Policy – Plantyful