BotanAI Get the app
Privacy

Privacy policy

BotanAI is local-first. There are no accounts and no sign-in, and there is no BotanAI server. Your data lives on your device.

Last updated 2026-07-18 Accounts None Server None

BotanAI does not have accounts, and it does not have a server to store your data on. Everything you create in the app lives on your phone: your garden, your plants, your photos, your growth timeline, your care logs, your AI Plant Doctor history, your wishlist and your settings. Nothing syncs to us, because there is nowhere to sync it to.

This policy explains the one thing that is not local: to identify a plant, check its health, answer a Plant Doctor question or fetch weather, the app sometimes sends a specific piece of data to a third-party service that does that job. Those services are listed in full below, along with exactly what each one receives and when. We are not one of them: BotanAI runs no servers of its own, sells nothing, and builds no advertising profile.

never sent anywhere

What stays on your device

The following is stored only on your device, in a local database, local settings and local image files. It is never transmitted to BotanAI, and it is never shared with other users.

  • Your garden and the plants in it, including photos.
  • Your growth timeline and care logs.
  • Your AI Plant Doctor chat history.
  • Your wishlist and your settings.
  • All community content. Community features are single-device and local-only. Nothing you post is transmitted to BotanAI or to anyone else.

Firebase Firestore, Firebase Auth, Firebase Storage and Cloud Messaging are absent from the build. There is no cloud copy of your garden.

7 services

Third-party processors

Data leaves your device only as transient, per-feature calls to the processors below. Each does one job and receives only what that job needs. Each keeps your data under its own privacy policy, linked in the last column.

Processor What it receives When Policy
Pl@ntNet my-api.plantnet.org The plant photo or photos, plus an API key. During identification, only when the on-device model is not confident. Read
Plant.id plant.id The plant photo (base64), an API key, and your approximate latitude and longitude when available. For identification and health checks when the free paths are not confident, and to analyse a photo you attach in the AI Plant Doctor. Read
Groq api.groq.com AI Plant Doctor chat text only: your typed message, a short text summary of the identification, and the selected plant name. No photo, no location, no identifier. When you use the AI Plant Doctor chat (model openai/gpt-oss-120b). Read
Google, Gemini via Firebase AI Logic googleapis.com Downscaled photos and text prompts for PlantProof photo verification, or text only for the optional plant-voice feature. Firebase App Check (Play Integrity) attests these calls. When you use PlantProof, or the plant-voice feature, which is off by default. Read
Open-Meteo api.open-meteo.com Your approximate latitude and longitude. To power weather-smart care reminders. Read
Firebase Analytics and Crashlytics (Google) firebase.google.com Anonymous, non-identifying usage events and crash reports. No user id, no user properties, no advertising id. Usage events in all builds; crash reporting in release builds only. Read
Google Play Billing play.google.com Your subscription and purchase state. When you buy or restore BotanAI Pro. Read

Identification is a privacy-first cascade, not a simultaneous cross-check. The app tries three engines in order and escalates only when your phone is not sure: first the on-device TFLite model (Google AIY Plants V1, 2,102 classes, fully offline, nothing leaves the device); then Pl@ntNet; then Plant.id. Subscriptions are handled by Google Play Billing.

six events, no id

Analytics

Firebase Analytics and Crashlytics record anonymous, non-identifying usage and crash data. There is no user id, there are no user properties, and there is no advertising id: ad-id collection is disabled and the advertising-id permissions are removed from the build. The complete list of analytics events is these six, and nothing else.

EventMeaning
plant_identified A plant was identified.
plant_added_to_garden A plant was added to the garden.
plant_shared A plant was shared.
pro_screen_viewed The Pro screen was opened.
pro_purchase A Pro purchase completed.
ai_content_reported AI content was reported.
and why

Permissions

PermissionWhy it is needed
Camera To take the photos you identify and add to your garden.
Notifications To show your care and watering reminders.
Internet To reach the identification, weather and AI services when needed.
Coarse location Weather-smart care and regional identification accuracy. Approximate only. No fine location and no background location.
Receive boot completed To reschedule your reminders after the phone restarts.
Vibrate For reminder alerts.

There are no ads and no advertising id.

you hold it

Data retention

Your data lives on your device and you control it. To delete it, uninstall the app or clear its storage in Android settings. There is no server-side copy to request, because there is no server.

The processors listed above retain only what their own policies state, for the calls they handle. The analytics and crash data are anonymous, so there is no profile tied to you to retain or delete.

general audience

Children

BotanAI is a general-audience app and is not directed at children. Because there are no accounts, the app does not knowingly collect personal information from anyone, including children. If you believe a child has entered personal information into the app, clearing the app storage removes it from the device.

reach us

Contact

If you have a question about this policy or how your data is handled, write to support@botanai.app. If something here is wrong or unclear, tell us and we will fix it.