Ezina · A Field Manual for Plant Care · United States Vol. I · Ed. 2027 · Proof copy

Privacy Policy

What we collect, who it goes to and why, how long we keep it, and how to get it deleted.

This policy describes how Ezina LLC, doing business as Ezina ("Ezina," "we," or "us"), collects, uses, and shares information when you use the Ezina app and related services.

What we collect

When you use Ezina, we collect:

  • Account information. Your email address, used to sign in and to contact you about the service. Magic-link sign-in means we don't require a password. We don't ask for your name, phone number, or social-account credentials.
  • Plant information. The plants, seeds, and observations you add to your garden, with any notes, nicknames, or photos you attach.
  • Photos you submit. Photos you take or upload for plant identification, disease checks, or social posts. To identify a plant or check its health, we send the photo to our identification providers, and we may keep a de-identified copy to help improve identification quality unless you opt out (see "How we use what we collect" below).
  • Location. If you grant location access, we use it to build weather-adjusted watering schedules. You can decline it and enter a hardiness zone or ZIP code by hand instead. We do not track your real-time location.
  • Device information. Standard technical data (device type, operating system, app version, language preference) needed to run the service and diagnose problems.
  • Subscription status. Whether you have an active subscription, your trial dates, and your credit balance.

We do not collect contacts, calendar data, microphone access, or web browsing history.

How we use what we collect

  • To run the service: identify plants, build watering schedules, send reminders, and keep your garden in sync across devices.
  • To reach you about your account or important changes to the service.
  • To improve the product. We record which screens you open and which features you use, tied to your account ID, so we can tell whether something works before we build more of it. The same account ID rides along with crash reports so we can fix the bug for the person it happened to. We do not sell this, and it stays with the service providers listed below.
  • To keep the community safe. Photos posted to the community are checked by an automated moderation service before they publish, and unsafe content is withheld. When you report a post, comment, or profile, we review the reported content and the account that posted it.
  • To improve plant identification. To identify a plant or check its health, we send your photo to our identification providers (Plant.id and PlantNet), who may use photos submitted to them to improve their own services, under their own policies. We may also keep your photo, plus any correction you give us when we get an identification wrong, to review and improve identification quality. Photos we keep this way are de-identified: account ID, email, and precise location are stripped. We do not sell them, and we do not publish them anywhere unless you separately opt in to let us use your photos for marketing or research (described under Data retention below). You can opt out at any time in Settings → Privacy. If you opt out, we stop keeping your future identification photos and remove any we have already kept within 30 days. To identify a plant, its photo still has to go to a provider, whichever way this is set. For users in the EU and UK, we ask for explicit consent before we keep identification photos this way, and declining does not affect your ability to use the app.
  • To meet legal obligations and respond to lawful requests.

We do not use your information for advertising, retargeting, or behavioral profiling. We run the product analytics described above, and none of it is shared with advertising networks or used to track you across other apps and websites.

Who we share information with

We share information only with services that help us run Ezina, and only what they need to do their job.

  • Plant.id receives photos you submit for plant identification and health assessment. It returns species matches, similar reference images, and disease findings. It gets image bytes and an optional location hint, and no name, email, account ID, or other identifying field.
  • PlantNet receives photos you submit for identification. It returns species matches drawn from citizen-science contributions. It gets the same scope as Plant.id: image bytes and an optional location hint.
  • Sightengine (operated by Kozelo SAS, a French company) receives photos you post to the community, through a short-lived private link, so it can check them for unsafe content before they become visible. It returns category scores describing what an image may contain. It does not receive your name or email address, and it does not use your photos to train its models. Sightengine is bound by a data processing agreement under EU law and acts only on our instructions.
  • Supabase hosts our database, authentication, and storage on our behalf. It holds your account, plant records, social posts, and uploaded photos. Supabase is bound by a data processing agreement and acts only on our instructions.
  • Open-Meteo receives an approximate location when we build your watering forecast. We round the coordinates to a coarse grid first, so what it gets is a weather cell, not your address, and no account identifier.
  • PostHog receives product analytics: which screens you open, which features you use, and your Ezina account ID, so we can tell whether a feature works before we build more of it. We report no advertising identifiers to it, and it connects to no ad network.
  • Sentry receives crash reports and error diagnostics, including device model, operating system, app version, and your Ezina account ID, so we can find the person a bug happened to and fix it.
  • RevenueCat manages subscriptions on our behalf. It receives your Ezina account ID and subscription state so entitlements follow you across devices. It does not receive your payment method.
  • Apple and Google receive subscription transaction information through their in-app purchase systems. We do not see your payment method or billing address through this channel.
  • Google Firebase Cloud Messaging receives a device push token so care reminders reach your phone. Notification content passes through it on the way to you.
  • Cloudflare serves our website and sits in front of our API. It processes request metadata, including IP address, to deliver pages and block abuse.
  • Wikimedia Commons is not a recipient of your data. We read plant reference photos from Wikimedia on our side and show them alongside identification results. The flow runs one way: we read from Wikimedia and send it nothing.

Every company on this list is a service provider acting on our instructions under a data processing agreement, not an independent user of your data.

We do not share data with advertisers, data brokers, analytics resellers, or any company whose business is targeting users.

We may disclose information when the law requires it (subpoena, court order, regulatory request) or to protect rights, safety, or property. When it's practical and lawful, we will tell you before we do.

Data retention

  • Account data stays while your account is active and for 30 days after deletion, so you can recover from an accidental deletion. This covers your profile, posts, comments, and garden plans.
  • Plant care data (your plant records, care history, and observations) stays while your account is active and for 30 days after deletion, then it's deleted. When you delete your account you can choose to leave this data behind in de-identified form, to improve care guidance for other growers. That choice is off unless you turn it on. De-identified records are stripped of anything that connects them to you, including your account, email, device, photos, and precise location, which is replaced with a general region. We do not try to re-identify them.
  • Photos stay while you keep them in your garden. Deleted photos leave our active systems within 30 days and our backups within 90. Photos we keep to improve identification quality follow the opt-out described below.
  • Photos you allow us to publish (marketing or research) are separate from the identification setting above. You can opt in to let us use photos you've uploaded in our own marketing and communications, or include them in research we publish. This is off unless you turn it on, and nothing is published without it. We do not sell your photos, license them to third parties, or use them to identify you, and we attach no name, handle, or email. You can withdraw at any time by emailing [email protected]; we stop using the photos going forward and remove them from materials we control, though research we have already published may not be fully retractable. If you grant this at account deletion, we keep the covered photos for up to 3 years, then remove them.
  • Subscription records stay for 4 years after account deletion, as tax and accounting rules require.
  • Aggregated, non-identifying analytics stay indefinitely.

Your rights

You can:

  • Access your data through the app (your garden, observations, settings).
  • Export your data in a machine-readable format from Settings.
  • Delete your account at any time. Your profile, posts, comments, garden plans, photos, and plant care data are removed, and deletion is permanent after a 30-day recovery window. Subscription and payment records stay for 4 years, as tax and accounting rules require. During deletion you can choose to leave your plant care data behind in de-identified form; if you don't turn that on, it's deleted with everything else. Deleting your account also gives up any early-access pricing attached to it.
  • Correct anything inaccurate through Settings or by emailing [email protected].
  • Opt out of having your identification photos kept to improve identification quality, in Settings → Privacy. The opt-out takes effect immediately for future submissions, and photos we have kept are removed within 30 days.
  • Withdraw your permission for us to publish your photos in marketing or research by emailing [email protected]. We stop using the photos going forward and remove them from materials we control. Research already published may not be fully retractable.

If you're in the EU, UK, or California, you have additional rights under GDPR, UK GDPR, and CCPA, including the right to object to processing and to lodge a complaint with your local data protection authority.

To exercise any right, email [email protected]. We respond within 30 days.

Children's privacy

Ezina is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has given us information, contact [email protected] and we will remove it.

For users aged 13 to 17, we recommend parental consent.

International users

Ezina is operated from the United States. If you use it from outside the US, your information is transferred to and processed in the US, and by using Ezina you consent to that transfer.

For EU users, we rely on Standard Contractual Clauses or equivalent safeguards for cross-border transfers where they're required.

Security

We protect your information with industry-standard measures, including encrypted connections (TLS), encrypted storage, and access controls. No system is perfectly secure, but we take responsibility for protecting what you trust us with.

If we ever have a data breach that affects your information, we will notify you as the law requires and within a reasonable time of finding it.

Changes to this policy

We may update this policy as Ezina changes. When we do, we'll update the effective date at the top, and for material changes we'll tell you through the app or by email before the change takes effect.

Contact

For privacy questions or to exercise any right above:

Ezina
13 Flag Road
Little Rock, AR 72205-5051
[email protected]