Sprout Privacy Policy
This Privacy Policy explains how Sprout handles personal information when you use the Sprout iOS application, its cloud services, plant-care tools, reminders, weather experience, plant scanning, AI features, and related services (collectively, the “Services”).
Effective and last updated 8 September 2026
Summary
- Sprout uses Sign in with Apple to create a private cloud account and synchronize your garden across signed-in devices.
- Your plant records, preferences, check-ins, and private growth photos are stored through Supabase. Deleting the app does not delete those cloud records.
- Location, notifications, camera, photo-library, microphone, speech-recognition, and cloud-AI features are optional and controlled separately.
- Sprout asks for low-accuracy location and rounds coordinates before storing or using them for weather.
- Compatible Apple Intelligence features run on the device. If you separately consent, Sprout may send a plant photo or limited plant-care context to Google Gemini through a Supabase Edge Function.
- OneSignal processes notification and limited garden-status information only after you enable care reminders. Sprout disables OneSignal location sharing.
- Sprout does not sell personal information, show third-party behavioural advertising, or share personal information for cross-context behavioural advertising.
- You can export your Sprout data, delete a plant, reset your garden, or delete your account and associated cloud data from within the app.
1. Scope and controller
This Policy applies to the Services that link to it. It does not govern a third-party service, website, or app that you choose to open from Sprout.
The controller responsible for your personal information is Sprout (“Sprout,” “we,” “us,” or “our”). Questions and privacy requests may be sent to es404020@gmail.com.
By using the Services, you acknowledge the practices described in this Policy. Where applicable law requires consent, we will ask for it before carrying out the relevant processing.
2. Information we collect
The information we process depends on the features you use and the permissions you grant.
Account and profile information
When you choose Sign in with Apple, we receive an Apple account identifier and, if Apple makes them available, your name and email address or private relay email address. We assign a Sprout account identifier and maintain authentication and session information needed to keep you signed in and synchronize your garden.
Garden and preference information
We process information you provide or create in Sprout, including:
- plant species, plant pet names, whether a plant is new or existing, planting source, current growth stage, planting date, lifecycle status, and health state;
- completed and missed care tasks, daily check-ins, care history, growth milestones, and mature-shelf records;
- onboarding answers, experience level, care pace, reminder time, time zone, language, accessibility preferences, and privacy choices;
- journal entries, notes, generated care summaries, and other information you enter; and
- app configuration and synchronization metadata, such as when a record was created or last changed.
Sprout uses these records to calculate care tasks and render the plant’s simulated DNA growth. The care schedule is determined by Sprout’s species profiles and deterministic care engine, not by an AI model.
Photos and visual information
If you choose to scan a plant or add a growth photo, Sprout processes the photograph and related information such as the plant, lifecycle day, stage, capture time, file type, and storage path.
Plant-scan photos are used for the requested match and are not automatically added to your garden or growth journey. Growth-journey photos are uploaded to a private Supabase Storage bucket and linked to your account. They are not public.
Do not include faces, people, private documents, addresses, or other unrelated personal information in plant photos.
Voice and speech information
On compatible devices, the optional “talk to your plant” feature uses the microphone while you are actively speaking. Sprout requires on-device speech recognition, temporarily converts your speech to text, and uses Apple Intelligence on the device to create a playful reply. Sprout does not save the raw audio recording or send it to Sprout’s cloud, Gemini, or OneSignal. The temporary transcript is cleared after the interaction.
Location and weather information
If you enable local weather and grant iOS location permission, Sprout requests low-accuracy location. The app rounds latitude and longitude before sending a weather request or storing coordinates in your private account. Sprout also processes the resulting weather condition, temperature, wind, precipitation, day/night state, and update time.
The weather provider and network infrastructure may receive your IP address as part of an ordinary internet request. Sprout does not send weather coordinates to OneSignal.
You may decline location permission or turn weather off. Sprout will then use cached conditions or a non-location fallback scene.
Notifications and device information
If you enable care reminders, Sprout and OneSignal may process:
- your Sprout account identifier, device push token, app and device identifiers used for notification delivery;
- device type, operating-system version, app version, language, time zone, network information, IP address, and notification status;
- limited tags such as language, number of active plants, current plant stage, broad care state, last check-in time, next growth-photo time, and whether a photo is due; and
- notification delivery, interaction, and open information.
OneSignal does not receive plant photos, journal entries, pet names, or weather coordinates from Sprout. Sprout only creates or updates a OneSignal messaging profile after you enable care reminders.
Technical, security, and support information
Our cloud providers may automatically process request metadata such as IP address, device or browser characteristics, timestamps, response status, diagnostic logs, and security events. We use this information to operate, secure, troubleshoot, and prevent abuse of the Services.
If you contact us, we process the message, your contact details, and any attachments or information you choose to provide so we can respond.
Information we do not intentionally request
Sprout does not intentionally request payment-card numbers, government identifiers, contacts, HealthKit data, biometric templates, precise stored location history, or information about race, religion, politics, sexual orientation, or medical conditions. Please do not place sensitive or unrelated personal information in plant names, notes, photos, or support messages.
Sprout does not currently offer third-party advertising, an advertising offer wall, or paid virtual currency. If paid features are introduced, Apple will process App Store payments; Sprout will not receive your complete card number or security code.
3. How we use information
We use personal information to:
- create, authenticate, and maintain your Sprout account;
- save and synchronize your private garden across your signed-in devices;
- calculate lifecycle days, care tasks, check-ins, health, growth stages, and milestones;
- display your garden, weather-responsive environment, widget, growth journey, and mature shelf;
- identify a supported species or estimate a current growth stage when you request a scan;
- generate optional personalized wording and playful on-device plant conversations;
- schedule and deliver reminders and route you to the relevant part of the app;
- create a growth video on your device when you ask for one;
- honour consent choices and provide export, deletion, and account controls;
- operate, secure, debug, maintain, and improve the Services;
- detect misuse, fraud, or security incidents; and
- comply with law, enforce our terms, and establish, exercise, or defend legal claims.
We do not use plant photos or garden records for third-party advertising.
4. Apple Intelligence and Google Gemini
Apple Intelligence
Where a compatible iPhone, iOS version, language, and Apple Intelligence configuration are available, Sprout may use Apple’s on-device frameworks for plant matching, short care wording, and the optional plant-conversation feature. Sprout does not transmit the content of these on-device requests to its own cloud merely because the feature runs.
Optional Gemini fallback
If Apple’s on-device feature is unavailable or uncertain, Sprout may offer Google Gemini as a cloud fallback. Gemini is used only after the relevant separate choice is allowed:
- Plant photo analysis: the selected photo, supported-species catalog, and request metadata are sent through an authenticated Supabase Edge Function to Gemini. The photo is not added to your growth journey unless you separately choose to add it.
- Daily-care wording: limited plant context, such as species, growth stage, health, and already-determined care tasks, may be sent through a Supabase Edge Function to Gemini to rewrite the message. Gemini does not decide whether watering or another task is due.
If Gemini is unavailable, denied, or fails, Sprout uses the supported-species catalog and deterministic wording. Core care tracking remains available.
AI results may be inaccurate. They are not professional plant identification, horticultural, medical, veterinary, or safety advice. Sprout does not use AI output to make a decision that produces legal or similarly significant effects about you.
Google processes submitted content and request metadata under its applicable Gemini API terms and privacy practices. Provider retention and model-improvement treatment can depend on the service tier and configuration.
5. Legal bases for processing
If the laws of the European Economic Area, United Kingdom, Switzerland, or another jurisdiction require us to identify a legal basis, we rely on:
- Contract: to create your account, synchronize your garden, provide requested care features, and perform our Terms of Use.
- Consent: for optional location, notifications, camera, photo-library, microphone, speech-recognition, Gemini photo analysis, Gemini care wording, and any processing that applicable law requires you to authorize. You may withdraw consent at any time, without affecting processing that was lawful before withdrawal.
- Legitimate interests: to secure, maintain, troubleshoot, and improve the Services; prevent abuse; understand reliability; and respond to support requests, where those interests are not overridden by your rights.
- Legal obligations: to comply with applicable law, lawful requests, and regulatory duties.
- Legal claims and vital interests: where necessary to establish, exercise, or defend legal claims or protect someone’s vital interests.
Where information is required to provide an account or requested feature, declining it may prevent that feature from working. Optional permissions are not required for core manual plant tracking.
6. When and with whom we disclose information
We disclose only the information reasonably necessary for the purpose described.
| Recipient | Purpose and information involved |
|---|---|
| Apple | Sign in with Apple; iOS permissions; local notifications; on-device intelligence, vision, speech recognition, speech synthesis, sharing, and App Store services. Apple may provide us with your account identifier, name, and email or relay email. |
| Supabase | Authentication, database synchronization, private growth-photo storage, signed photo access, and server-side Edge Functions. This may include account identifiers, garden content, photos you save, preferences, consent records, rounded weather coordinates, and request/security logs. |
| Google Gemini | Optional cloud plant-photo analysis and optional care-message wording, only after the relevant consent. Gemini may receive the selected photo or limited plant context plus technical request information. |
| OneSignal | Optional push-notification delivery, localization, routing, broad garden-status tags, delivery analytics, and deletion of the messaging profile when the Sprout account is deleted. |
| Open-Meteo | Optional current-weather retrieval using rounded coordinates and ordinary network request information. Open-Meteo does not receive your Sprout account record from Sprout. |
| Professional advisers and authorities | Lawyers, auditors, insurers, courts, regulators, law enforcement, or other parties where reasonably necessary to comply with law or protect rights, safety, and security. |
| Business transaction parties | A buyer, investor, successor, or adviser in a merger, financing, reorganization, sale, or transfer, subject to appropriate confidentiality and applicable law. |
Relevant provider notices include the Apple Privacy Policy, Supabase Privacy Policy, Google Privacy Policy, Gemini API Additional Terms, OneSignal Privacy Policy, and Open-Meteo Terms and Privacy.
Service providers acting for us are expected to protect personal information, use it for the contracted purpose, and comply with applicable law. Some providers also act independently for parts of their services, in which case their own privacy notices apply.
7. Sale, advertising, attribution, and tracking
Sprout does not sell personal information. Sprout does not share personal information for cross-context behavioural advertising and does not display third-party behavioural ads.
The iOS app currently presents Apple’s App Tracking Transparency permission before any future cross-company attribution or tracking. The current Sprout code does not use the authorization to access the advertising identifier, run an advertising SDK, or track activity across other companies’ apps and websites. Declining the permission does not reduce Sprout functionality.
If Sprout later adds attribution, advertising, or tracking, we will update this Policy and the App Store privacy disclosures before enabling it and will honour the ATT status and other legally required opt-outs.
Because Sprout does not currently sell or share personal information for cross-context behavioural advertising, browser Do Not Track and Global Privacy Control signals do not change its current app practices. If this changes, we will describe the applicable signal support here.
8. On-device storage, cloud storage, widgets, and exports
Core account data and private growth photos are stored in the signed-in Sprout cloud account through Supabase. The app also uses local storage, Capacitor Preferences, the iOS Keychain or equivalent protected session storage, temporary files, and caches to keep you signed in, support offline or pending changes, and render the app.
The Sprout widget receives a limited snapshot through the app’s private iOS App Group, such as the selected plant’s species, name, stage, health, growth, timer, and current weather scene. This widget exchange remains on the device and does not independently send information to a third party.
When you create a growth video, Sprout temporarily retrieves the selected private growth photos and encodes an MP4 on the iPhone. The file leaves Sprout only if you choose a destination in the iOS share sheet. The temporary export is removed after sharing finishes, but a destination you choose will apply its own terms and privacy practices.
When you export your Sprout data, the app creates a JSON file and opens the iOS share sheet. You control where the exported copy is saved or sent. Protect exported files because they may contain personal garden information.
9. Retention and deletion
We retain personal information only for as long as reasonably necessary to provide the Services, fulfil the purposes in this Policy, comply with law, resolve disputes, enforce agreements, and protect security.
In general:
- account and garden records remain while your account is active;
- a private growth photo remains until you replace or delete it, delete its plant, reset the relevant garden data, or delete the account;
- a scan photo is processed for the requested scan and is not added to your Sprout garden record unless you separately save it as a growth photo;
- raw microphone audio and the temporary plant-conversation transcript are not retained by Sprout after the interaction;
- temporary export and video files are removed by the app after the related sharing flow, subject to copies you choose to save elsewhere;
- local caches and pending state remain only as needed for operation and synchronization; and
- security logs and backups may remain for a limited additional period where deletion is not immediately practical or where law requires retention. Such data will be isolated from ordinary use until deleted or overwritten.
Deleting the iOS app does not delete your Sprout account or cloud records. Use Settings → Data & Privacy → Delete account and data to request deletion. Account deletion removes the authentication account, associated Sprout database records, private growth photos, and linked OneSignal profile, subject to limited legally required records and backup cycles.
10. Your choices and controls
Sprout provides the following controls:
- Account data: export your data, delete an individual plant, reset your garden, or delete your account and cloud data from Data & Privacy.
- Weather: enable or disable weather in Sprout and manage location permission in iOS Settings.
- Plant photo analysis: allow or deny Gemini analysis separately from weather and other AI features.
- Care wording: allow or deny Gemini care wording separately. The deterministic care engine continues to work if denied.
- Notifications: enable or disable care reminders in Sprout and manage notification permission in iOS Settings.
- Camera and photos: grant, limit, or revoke access in iOS Settings. Sprout uses the iOS picker where available so you can select only the photo you intend to share.
- Microphone and speech recognition: grant or revoke access in iOS Settings. Without them, the optional voice conversation is unavailable.
- Tracking: select “Ask App Not to Track” in the ATT prompt or manage the setting in iOS privacy controls. Core features remain available.
- Language and time zone: Sprout follows supported app-language and device-time-zone settings for localized experiences and reminders.
Allowing one optional purpose does not authorize another. For example, enabling weather does not authorize Gemini photo analysis or Gemini care wording.
11. Security
We use technical and organizational measures designed to protect personal information. These include encrypted network connections, authenticated access, private storage, database row-level security, short-lived signed photo URLs, and separation of server-side provider keys from the iOS application.
No storage or transmission system can be guaranteed to be completely secure. You are responsible for maintaining control of your Apple account, device passcode, and exported files. Contact us promptly if you believe your Sprout account or information has been compromised.
12. International data transfers
Sprout and its providers may process information in countries other than the one where you live. Those countries may have different privacy laws. Where required, we use recognized transfer mechanisms and safeguards, such as adequacy decisions, standard contractual clauses, contractual protections, or another lawful transfer basis.
13. Children
Sprout is intended for adults and is not directed to children under 18. We do not knowingly collect personal information from a child under 18. If you believe a child has provided personal information, contact us at es404020@gmail.com so we can investigate and delete it where required.
14. Privacy rights
Depending on where you live, you may have the right to:
- know whether we process your personal information and request access to it;
- receive a copy of certain information in a portable format;
- correct inaccurate or incomplete information;
- request deletion of personal information;
- restrict or object to certain processing;
- withdraw consent at any time;
- opt out of a sale, targeted advertising, profiling, or sharing where applicable;
- appeal a refusal of a privacy request where applicable;
- use an authorized agent where permitted; and
- complain to your local privacy or data-protection authority.
You may exercise in-app controls or contact es404020@gmail.com. We may need to verify your identity and authority before fulfilling a request. We will use verification information only for that purpose. We will respond within the period required by applicable law and will not discriminate against you for exercising a privacy right.
If you are in the EEA, you may complain to your local supervisory authority. If you are in the United Kingdom, you may complain to the Information Commissioner’s Office. If you are in Switzerland, you may contact the Federal Data Protection and Information Commissioner. Residents of Canada, Australia, New Zealand, and other regions may contact their applicable privacy regulator.
15. United States privacy disclosures
Depending on the law that applies and the features you use, Sprout may have processed the following categories of personal information during the preceding 12 months:
| Category | Examples relevant to Sprout | Processed |
|---|---|---|
| Identifiers | Apple and Sprout account identifiers, name, email or relay email, IP address, push token | Yes |
| California customer-record information | Name and email address | Yes |
| Protected classifications | Race, religion, sex, disability, and similar classifications | No, not intentionally requested |
| Commercial information | Purchase or subscription history | No in the current version |
| Biometric information | Face geometry, fingerprints, or voiceprints used to identify a person | No |
| Internet or electronic-network activity | App interactions, request timestamps, notification delivery/open information, diagnostics | Yes |
| Geolocation data | Low-accuracy location rounded for optional weather | Yes, if enabled |
| Audio, electronic, or visual information | Plant photos; transient microphone audio and transcript during an optional on-device conversation | Yes, if used |
| Professional or employment information | Job or employment history | No |
| Education information | Student records | No |
| Inferences | Plant-care preferences, broad care state, and estimated plant stage | Yes |
| Sensitive personal information | Precise geolocation, government IDs, account credentials, health data, and other legally designated sensitive data | Sprout does not intentionally retain precise location or request the other listed sensitive categories; device location is accessed only with permission and is rounded for weather |
We use and disclose these categories for the business purposes explained in Sections 3 and 6. We do not sell them or share them for cross-context behavioural advertising. We have not knowingly sold or shared personal information of consumers under 16.
Applicable state law may let you request access, correction, deletion, portability, or information about collection and disclosure, and may allow an authorized agent to act for you. Because Sprout does not currently sell personal information or use it for targeted advertising, there is no sale or targeted-advertising opt-out to apply. You may still contact us with a request.
California residents may also request information under California’s “Shine the Light” law about personal information disclosed to third parties for their own direct-marketing purposes. Sprout does not make such disclosures in the current version.
16. Changes to this Policy
We may update this Policy to reflect changes in the Services, providers, law, or security practices. We will update the date at the top. If a change is material, we will provide additional notice where required, such as an in-app notice or another appropriate communication. Changes apply prospectively from their effective date.
17. Contact us
Questions, complaints, and privacy requests may be sent to:
Sprout es404020@gmail.com