Privacy Policy — Plantarium: Plant ID & Care

Last updated: August 10, 2026

We are glad that you are interested in Plantarium: Plant ID & Care ("Plantarium"). In order to provide you with our service, we need certain information about you (including personally identifiable information — information that identifies you personally). This Privacy Policy explains what information we collect about you, for what purpose, and what we use it for. It also explains what rights you have with regard to the data processing operations affecting you.

The "Responsible body" (data controller) is the natural or legal person who, alone or together with others, decides on the purposes and means of processing personal data (e.g. names, email addresses, photographs, device identifiers, etc.). For Plantarium, the data controller is Alvin AI Studio LLC, 447 Broadway, 2nd Floor Suite 3007, New York, NY 10013, USA. Our technical provider, Otto Apps Yazılım Uygulama Bilgi Teknolojileri Reklamcılık Danışmanlık Sanayi ve Ticaret A.Ş. ("Otto Apps"), acts as a data processor on our behalf in its capacity as the developer and operator of the app's technical infrastructure. With respect to purchases made through the Apple App Store and Google Play Store, Apple and Google act as independent data controllers for payment and billing data under their own privacy policies.

1. Data We Collect About You

On the one hand, your data is captured because you communicate it to us — for example, an email address you enter to restore access on a new device, or a photograph you submit for identification. Other data is collected automatically when using our app or visiting our website through our IT systems. These are above all technical data (e.g. device model, operating system, or time of a request). The collection of this data is automatic as soon as you use our platform.

Photographs Submitted for Identification

When you use the plant, mushroom, or pest identification features, the photograph you capture or upload is sent to our identification-technology provider (see Section 9, "Kindwise") for processing, and the resulting identification is returned to you through the Service. We do not require you to identify yourself in order to use this feature.

Device Identifier

Instead of a traditional account, Plantarium identifies your installation using an anonymous device identifier (generated by our subscription-management provider, RevenueCat, or — if that is unavailable — a random identifier generated on your device and stored only in the app's local storage). This identifier — not your name or email — is what links your subscription status and usage to your device. If you purchase through our website, we additionally link the email address you provide at checkout to that identifier, solely so that you can restore access if you reinstall the app or switch devices.

iNaturalist

The "Discover" (what grows near you) and "Field Guide" features, and searching the plant library, send your search text or an approximate location (rounded to roughly 1km resolution before it ever leaves your device) directly from the app to iNaturalist.org, operated by iNaturalist, an independent nonprofit organization, to retrieve species information and community-contributed photographs. This is a direct connection from your device to iNaturalist's public API — we do not proxy or store this data ourselves.

Mobile Advertising ID

If not disabled by the user, we collect the mobile advertising identifier provided by your device — the Google Advertising ID (GAID) on Android, or the IDFA on iOS where App Tracking Transparency permission has been granted — for advertising-attribution purposes. You can reset or delete this identifier at any time: on Android under Settings → Privacy → Ads, and on iOS by declining the App Tracking Transparency prompt or turning off Allow Apps to Request to Track.

Cookies and Cookie Policy

For the provision of the Plantarium website and marketing pages, and to make our offer more user-friendly, effective, and secure, we may use so-called cookies for data collection and storage. Cookies are small data packets that are stored on your device and do no harm. Our mobile application itself does not use browser cookies; the categories below apply to our website(s). We collect Cookies in the following categories:

- Necessary technical or functional cookies: They help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
- Preference cookies: They enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
- Statistical cookies: They help website owners understand how visitors interact with websites by collecting and reporting information anonymously.
- Marketing cookies: They are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user.

Payment Information

If you purchase a subscription through our website, credit card information and other financial information we need to process the payment are collected and stored by our payment service provider, Stripe (see Section 9). We ourselves receive very limited information from Stripe about you (such as your email address and transaction status) — we do not receive or store your full card number.

Personal Data of Children

We are not aware of collecting personal data from children under 16 years of age; if you are under 16 years of age, please do not use Plantarium or send us any personal data without the involvement of a parent or guardian. If we learn we have collected personal data from a child under 16 years of age without appropriate consent, we will delete that information as quickly as possible. If you believe that a child under 16 may have provided us personal data, please contact us at support@plantarium.io.

2. How We Collect Your Data

We collect your data in three different ways:

- Automated, when you use our app or visit our website
- Through cookies (website only)
- Through your voluntary input (e.g. a restore-access email address, a photograph you submit, or a message you send to our in-app assistant)

Install referrer (Android)

When you install the Android app from Google Play, Play provides the app with the referrer information associated with your install. We use it for two purposes: to attribute the install to the campaign or link it came from, and — where you followed a subscription link we emailed you — to carry a one-time access code through the install so your subscription is active on first launch. It is read once, on first launch, and is not retained afterwards.

3. How We Work With Partners

In some cases, your data is also processed with the help of third-party providers of various online services. However, this is exclusively regulated by data processing agreements, and the processing is instruction-bound, so that we always keep the responsibility for the processing.

Processors from a third country outside the European Economic Area only receive access to personal data if these third countries offer an appropriate level of data protection in connection with an adequacy decision by the EU Commission, or if we have suitable guarantees with these service providers (so-called Standard Contractual Clauses in accordance with Art. 46 GDPR) or recognized Binding Corporate Rules in accordance with Art. 47 GDPR.

4. Your Rights

Revocation of Consent

Many data processing operations are only possible with your express consent (for example, advertising identifiers, or the App Tracking Transparency permission). You can revoke an existing consent at any time — through your device settings, or with an informal message by email to support@plantarium.io. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Right to Complain

In the event of data protection violations, you, the person concerned, have the right of appeal to the competent supervisory authority for data protection issues in the country in which our company is based, or in which you have your residence.

Information, Correction, Deletion, Blocking, Data Transferability

You have the right at any time to request information about your personal data processed by us, free of charge. In particular, you may request that we provide information about the processing purposes, the category of personal data, the categories of recipients to whom your data has been disclosed, the planned retention period, the right of rectification, deletion, limitation of processing or opposition, the right to lodge a complaint, the origin of your data if not collected by us, and the existence of automated decision-making including profiling.

You have the right to request the immediate correction of incorrect or incomplete personal data of you stored by us.

You have the right to request the deletion of your personal data stored by us, except in cases where the processing of the data is required for the exercise of the right to freedom of expression and information, for the fulfillment of a legal obligation, for reasons of public interest, or for the assertion, exercise, or defense of legal claims. Deleting the app from your device does not, by itself, delete your data from our servers — please contact us to request deletion.

You have the right to demand the restriction of the processing of your personal data, as far as the accuracy of the data is disputed by you, the processing is unlawful but you reject its deletion and we no longer need the data, or if you have objected to the processing in accordance with Art. 21 GDPR.

You have the right to receive your personal information that you have provided to us in a structured, common, and machine-readable format, or to request that it be sent to another person in charge.

Right to Object

If your personal data is processed based on legitimate interests in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR, you have the right to file an objection against the processing of your personal data in accordance with Art. 21 GDPR, provided that there are reasons for this arising from your particular situation, or the objection is directed against direct marketing. In the latter case, you have a general right to object, which is implemented by us without your needing to specify any particular situation.

Data Retention

- Account record and email address — kept while your subscription is active, and deleted immediately when you delete your account.
- Subscription records — kept for the life of the subscription and deleted with the account.
- Photographs submitted for identification — not stored. They are passed to the identification provider to produce a result and are not written to our servers.
- Assistant conversations — not stored on our servers.
- Payment and invoice records — held by our payment processors (Apple, Google, Stripe) for the period tax and accounting law requires, and deleted once that period ends. We cannot delete these on request.
- Aggregated, anonymised usage statistics — contain no personal data and cannot be traced back to an individual, so they are retained indefinitely.
- Crash and diagnostic reports — retained by Firebase Crashlytics for up to 90 days.

5. SSL/TLS Encryption

We use SSL or TLS encryption for security reasons and to protect the transmission of sensitive content, such as photographs, purchases, or requests you send to us. An encrypted connection is indicated by the browser's address bar switching from "http://" to "https://" and the lock icon in your browser bar, and is used throughout the app's own communication with our servers. If SSL or TLS encryption is enabled, the data you submit to us cannot be read by third parties in transit.

6. Data Collection and Use

Server Log Files

Our hosting provider automatically collects and stores information in so-called server log files, which your app or browser automatically transmits to us. These are app/browser version, operating system used, time of the server request, and the IP address. The data is used for data security and error analysis only. A merge of this data with other data sources will not be done. The basis for data processing is Art. 6 (1) lit. b GDPR.

Cookies

We use so-called cookies on our website. Cookies do not harm your access device and do not contain viruses. Cookies serve to make our offer more user-friendly, effective, and secure. Most of the cookies we use are so-called "session cookies." They will be deleted automatically at the end of your visit. Other cookies remain stored on your device until you delete them.

You can set your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general, and enable the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of our website.

Restore-Access Emails

If you request a restore-access link (for example, after reinstalling the app or switching devices), we send that link to the email address you provide via our transactional email provider, Resend (see Section 9). We only use this email address to send you the requested link and, if you purchased through the web, to link your purchase to your device.

7. In-App AI Assistant ("Ari")

If you use the in-app conversational assistant, your messages (and any photograph you attach) are sent to Google's Gemini API for processing in order to generate a response. Please do not share sensitive personal information you would not want processed by this third party in your messages to the assistant.

8. Analysis Tools and Advertising

Firebase (Google)

We use Firebase Analytics and Firebase Crashlytics, services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"), to understand app usage (screens viewed, sessions, features used) and to diagnose crashes. We have entered into a Data Processing Agreement with Google in compliance with Art. 46 GDPR.

AppsFlyer

We use AppsFlyer (AppsFlyer Ltd.) as our mobile measurement partner, to attribute app installs and in-app events to the marketing channel that led to them (e.g. a specific ad). AppsFlyer receives device identifiers and event data on our behalf, under a data processing agreement.

Google Ads, including On-Device Conversion Measurement

For marketing optimization purposes, if not disabled by the user in the system settings of their device, we send the Mobile Advertising ID and app-event data to Google Ireland Limited ("Google") in connection with Google Ads. On devices in the European Economic Area, the United Kingdom, and Switzerland, we additionally use Google's on-device conversion measurement technology, which generates a privacy-preserving, aggregated conversion signal on your device without relying on cross-app identifiers, and shares that signal with Google via our attribution partner. We have entered into a Data Processing Agreement with Google in compliance with Art. 46 GDPR.

Meta (Facebook)

For marketing optimization purposes, we send app-event data (including purchase events, and, where you have granted App Tracking Transparency permission, your advertising identifier) to Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland ("Meta"), so that Meta can measure and optimize the performance of our advertising campaigns. Meta also receives standard SKAdNetwork attribution postbacks from Apple for users who do not grant tracking permission. We have entered into a Data Processing Agreement with Meta in compliance with Art. 46 GDPR.

9. Service Providers and Infrastructure

RevenueCat

We use RevenueCat, Inc. to manage App Store and Play Store subscriptions and to generate the anonymous device identifier described in Section 1. RevenueCat receives your purchase and entitlement data from Apple/Google on our behalf.

Supabase

Our backend database, which stores your subscription status, device links, and usage counters, is hosted on Supabase. Supabase stores this operational data on our behalf under a data processing arrangement.

Google Cloud Platform / Cloud Run

Our backend service is hosted on Google Cloud Platform. Google Cloud Platform receives the same operational data described above as our infrastructure provider, under a Data Processing Agreement in compliance with Art. 46 GDPR.

Kindwise

Photographs you submit for plant, mushroom, or pest identification are sent to Kindwise s.r.o. (the operator of plant.id, mushroom.kindwise.com, and insect.kindwise.com), our third-party identification-technology provider, solely for the purpose of generating an identification result. Kindwise processes these photographs on our behalf.

Resend

Transactional emails — specifically, restore-access links — are sent via Resend, our email delivery provider. Resend processes the recipient email address and message content solely to deliver that email.

OpenRouter

The in-app assistant ("Ask Ari") sends the question you type, and the plant context relevant to it, to OpenRouter Inc., which routes the request to a third-party language-model provider in order to generate an answer. We do not send your email address, device identifier or location with these requests, and we do not store the conversation on our servers — the text is used to produce the reply and is not retained by us. Providers reached through OpenRouter may retain request data under their own terms.

Stripe

When you make payments for our services through the web channel, no credit or debit card information is stored on our own servers. This information is stored by our PCI-compliant payment processor, Stripe, Inc., 185 Berry Street, Suite 550, San Francisco, CA 94107 (USA). All credit and debit card transactions occur between the computer or device from which the transaction originates and Stripe. We also receive certain limited information from Stripe, such as your email address and transaction history. We have entered into a Data Processing Agreement with Stripe in compliance with Art. 46 GDPR.

Apple App Store / Google Play Store

If you subscribe through the App Store or Play Store, your payment information is processed entirely by Apple or Google, respectively, under their own privacy policies. We receive only your purchase and entitlement status (via RevenueCat) — never your payment details.

10. Payment Information — Refund Requests

If you purchased a subscription via the App Store or Play Store and consider that a payment has been wrongly debited, you may request a refund directly through your Apple ID or Google Play account, which will then be processed directly by Apple or Google. In order to enable Apple or Google to make a decision about the legitimacy of your refund request, we may transfer data about your usage history to them. You agree to this data transfer by requesting a refund. The legal basis is your consent (Art. 6 para. 1 p. 1 lit. a GDPR) as well as our legitimate interest (Art. 6 para. 1 p. 1 lit. f GDPR).

11. California Privacy Rights

We take the data protection regulations of the California Consumer Privacy Act ("CCPA") and the California Civil Code seriously and respect the resulting rights for California residents. We will not discriminate against you for exercising your rights under the CCPA.

Shine the Light / Opt-Out

California residents have the right to request information about their personal data that we have shared with third parties once a calendar year, and to have this data deleted by us. In addition, California residents have the right to opt out of the disclosure of their personal data to third parties. To exercise these rights, an informal email to support@plantarium.io is sufficient, along with proof of identity and place of residence. We will respond to verified requests within 30 days. We do not sell personal data.

Purposes of Data Processing

We collect and process personal data of California residents only for the purposes stated in this Privacy Policy, in particular to provide our Service, analyze app usage, and optimize our marketing. We do not sell personal data of California residents.

Categories of Personal Data

We collect and process personal data from California residents from the following categories: (i) identifiers (e.g. email address, device identifier); (ii) photographs you submit for identification; (iii) information about activity within the app. The categories of third parties with whom we may share this information are: (i) marketing/attribution networks, (ii) analytics, hosting, and identification-technology providers, and (iii) payment service providers. We have no knowledge of disclosing personal data of minors under 16 years of age to third parties.

Contact

Alvin AI Studio LLC

447 Broadway, 2nd Floor Suite 3007, New York, NY 10013, USA

Developer / Technical Provider

Otto Apps Yazılım Uygulama Bilgi Teknolojileri Reklamcılık Danışmanlık Sanayi ve Ticaret A.Ş. İçerenköy Mah. Topçu İbrahim Sk. Quick Tower No:8-10D Ataşehir / İstanbul

support@plantarium.io