BotanAI does not have accounts, and it does not have a server to store your data on. Everything you create in the app lives on your phone: your garden, your plants, your photos, your growth timeline, your care logs, your AI Plant Doctor history, your wishlist and your settings. Nothing syncs to us, because there is nowhere to sync it to.
This policy explains the one thing that is not local: to identify a plant, check its health, answer a Plant Doctor question or fetch weather, the app sometimes sends a specific piece of data to a third-party service that does that job. Those services are listed in full below, along with exactly what each one receives and when. We are not one of them: BotanAI runs no servers of its own, sells nothing, and builds no advertising profile.
What stays on your device
The following is stored only on your device, in a local database, local settings and local image files. It is never transmitted to BotanAI, and it is never shared with other users.
- Your garden and the plants in it, including photos.
- Your growth timeline and care logs.
- Your AI Plant Doctor chat history.
- Your wishlist and your settings.
- All community content. Community features are single-device and local-only. Nothing you post is transmitted to BotanAI or to anyone else.
Firebase Firestore, Firebase Auth, Firebase Storage and Cloud Messaging are absent from the build. There is no cloud copy of your garden.
Third-party processors
Data leaves your device only as transient, per-feature calls to the processors below. Each does one job and receives only what that job needs. Each keeps your data under its own privacy policy, linked in the last column.
| Processor | What it receives | When | Policy |
|---|---|---|---|
| Pl@ntNet my-api.plantnet.org | The plant photo or photos, plus an API key. | During identification, only when the on-device model is not confident. | Read |
| Plant.id plant.id | The plant photo (base64), an API key, and your approximate latitude and longitude when available. | For identification and health checks when the free paths are not confident, and to analyse a photo you attach in the AI Plant Doctor. | Read |
| Groq api.groq.com | AI Plant Doctor chat text only: your typed message, a short text summary of the identification, and the selected plant name. No photo, no location, no identifier. | When you use the AI Plant Doctor chat (model openai/gpt-oss-120b). | Read |
| Google, Gemini via Firebase AI Logic googleapis.com | Downscaled photos and text prompts for PlantProof photo verification, or text only for the optional plant-voice feature. Firebase App Check (Play Integrity) attests these calls. | When you use PlantProof, or the plant-voice feature, which is off by default. | Read |
| Open-Meteo api.open-meteo.com | Your approximate latitude and longitude. | To power weather-smart care reminders. | Read |
| Firebase Analytics and Crashlytics (Google) firebase.google.com | Anonymous, non-identifying usage events and crash reports. No user id, no user properties, no advertising id. | Usage events in all builds; crash reporting in release builds only. | Read |
| Google Play Billing play.google.com | Your subscription and purchase state. | When you buy or restore BotanAI Pro. | Read |
Identification is a privacy-first cascade, not a simultaneous cross-check. The app tries three engines in order and escalates only when your phone is not sure: first the on-device TFLite model (Google AIY Plants V1, 2,102 classes, fully offline, nothing leaves the device); then Pl@ntNet; then Plant.id. Subscriptions are handled by Google Play Billing.
Analytics
Firebase Analytics and Crashlytics record anonymous, non-identifying usage and crash data. There is no user id, there are no user properties, and there is no advertising id: ad-id collection is disabled and the advertising-id permissions are removed from the build. The complete list of analytics events is these six, and nothing else.
| Event | Meaning |
|---|---|
| plant_identified | A plant was identified. |
| plant_added_to_garden | A plant was added to the garden. |
| plant_shared | A plant was shared. |
| pro_screen_viewed | The Pro screen was opened. |
| pro_purchase | A Pro purchase completed. |
| ai_content_reported | AI content was reported. |
Permissions
| Permission | Why it is needed |
|---|---|
| Camera | To take the photos you identify and add to your garden. |
| Notifications | To show your care and watering reminders. |
| Internet | To reach the identification, weather and AI services when needed. |
| Coarse location | Weather-smart care and regional identification accuracy. Approximate only. No fine location and no background location. |
| Receive boot completed | To reschedule your reminders after the phone restarts. |
| Vibrate | For reminder alerts. |
There are no ads and no advertising id.
Data retention
Your data lives on your device and you control it. To delete it, uninstall the app or clear its storage in Android settings. There is no server-side copy to request, because there is no server.
The processors listed above retain only what their own policies state, for the calls they handle. The analytics and crash data are anonymous, so there is no profile tied to you to retain or delete.
Children
BotanAI is a general-audience app and is not directed at children. Because there are no accounts, the app does not knowingly collect personal information from anyone, including children. If you believe a child has entered personal information into the app, clearing the app storage removes it from the device.
Contact
If you have a question about this policy or how your data is handled, write to support@botanai.app. If something here is wrong or unclear, tell us and we will fix it.