Last updated 13 September 2026
Plants in Pocket is made by Fintlock. This policy explains what the app sends, what it stores, and what you control.
| Data | Purpose |
|---|---|
| Prepared photos, re-encoded without EXIF or GPS | Cloudflare forwards them to OpenAI for identification and visible-health/care guidance |
| A random installation ID | Allowance enforcement and subscription binding on Cloudflare |
| Apple-signed purchase confirmation, product, transaction, environment and expiry details | Verify Premium and associate its allowance with installations |
| Plant names, follow-up questions, recent conversation and scan context | Generate reference information and answer your plant-care questions |
| Request identifiers and fingerprints | Recognize retries and recover the same scan |
| IP address at Cloudflare's edge; technical app-version, timing and outcome metadata | Deliver requests, prevent abuse and diagnose failures |
Our application does not retain raw IP addresses. Abuse counters use salted hashes. We do not receive card numbers, payment details, or Apple Account credentials. Purchase confirmation is still purchase-related data even though it does not create an app account.
Unsaved photo bytes stay in memory. Explicitly saved plants and check-ins keep local reduced-size photos. Care schedules, journal notes, recovery plans, saved conversations, discovery entries, cached profiles and progress remain local unless you choose to share them. We do not provide account-based cloud sync; your system device backup may include local app data.
Deleting a plant removes its own record and journal photos and cancels its reminders. Separately kept discovery entries are managed in the field guide. Erase on the About screen removes local plants, photos, profiles, discovery records and progress. A recipient keeps control of a copy you chose to share. The Keychain installation ID may survive reinstall; Premium access tokens are stored in the Keychain.
We do not persist upload photos, request prompts, submitted questions or conversation history. A completed scan's generated text result is available for recovery for ten minutes. Operation metadata without that content remains for up to 24 hours to prevent duplicate work. Follow-up answers are not stored for recovery. Profiles are cached as reference text for up to 90 days.
Coordinated allowance counters expire two days after their period ends; IP and global counters expire one day after their period ends. Older counters can remain up to 62 days. Subscription-to-installation bindings expire after 90 days. SQLite database backups can restore contents, including deleted records, from the preceding 30 days. The ten-minute recovery window is not an absolute backup-deletion deadline. See Cloudflare's storage documentation.
Application logs contain technical outcomes, timing, sanitized app version, Apple transaction environment and aggregate token usage, without image bytes, questions, answers, device/request identifiers, credentials or signed purchase records. Cloudflare Workers Logs retention is plan-dependent, currently three days on Free or seven days on Paid.
We request store:false, which disables ordinary saved-response storage. Separate default abuse-monitoring logs can contain prompts and responses for up to 30 days, or longer for legal or safety reasons, and may undergo human review. Flagged image inputs can be retained for manual review. Supported prompt caching can retain encrypted cache state up to 24 hours. OpenAI does not use API content for model training unless the customer opts in. See OpenAI's data controls.
Apple handles the monthly subscription and shows the local price before purchase. Manage or cancel it in your Apple Account subscription settings. No subscription is required to delete local data. Reminders are optional and camera/photo permissions can be changed in iOS Settings.
We do not sell information or share it for advertising. Data linked to an installation or subscription is used to provide the app, verify purchases, manage allowances and recover scans. Local owner notes and shared cards are not automatically sent for AI analysis.
The app is not directed to children under 13. It has no account, social messaging or advertising. We do not knowingly collect children's personal information.
Requests use HTTPS and ephemeral network sessions without cookies or a disk cache. Released apps contain no AI provider key. For a privacy question or request, contact us below. No-login use does not mean that we hold no records: installation and subscription records may be relevant to a request.
We update this policy when data handling changes. Meaningful changes are also described in release notes. Contact contact@fintlock.com.