Our transparency promise Effective: [DATE] Transparency is massively important to us. We built Ezina to help others, help nature, and bring us all a bit closer together. This page is a breakdown of all our commitments to transparency and how they apply to you. What we share with outside services We share data with outside services only when it's necessary to deliver the product to you. The recipients are: - Plant.id receives photos you submit for identification and health assessment. It returns species matches, similar reference images, and disease findings. - PlantNet receives photos you submit for identification. It returns species matches drawn from citizen-science contributions. - Sightengine (operated by Kozelo SAS, a French company) receives photos you post to the community, through a short-lived private link, so it can check them for unsafe content before they become visible. It returns category scores describing what an image may contain. It does not receive your name or email address, it does not use your photos to train its models, and it is bound by a data processing agreement under EU law. - Supabase hosts our database, authentication, and storage. It holds your account, plant records, social posts, and uploaded photos. Supabase serves this data back to you when you ask and does not use it for any other purpose. Supabase is bound by a data processing agreement and operates only on our instructions. - Open-Meteo receives an approximate location when we build your watering forecast. We round the coordinates to a coarse grid first, so it gets a weather cell rather than an address, and no account identifier. - PostHog receives product analytics: which screens you open, which features you use, and your Ezina account ID. We use it to tell whether a feature works before building more of it. - Sentry receives crash reports and error diagnostics, including device model, operating system, app version, and your Ezina account ID, so a bug can be traced to the person it happened to. - RevenueCat manages subscriptions. It receives your Ezina account ID and subscription state so entitlements follow you across devices. It does not receive your payment method. - Google Firebase Cloud Messaging receives a device push token so care reminders reach your phone. Notification content passes through it on the way to you. - Cloudflare serves our website and sits in front of our API. It processes request metadata, including IP address, to deliver pages and block abuse. - Apple and Google receive subscription transaction information through their respective in-app purchase systems. We do not see your payment method or billing address through this channel. For plant identification specifically: we do not attach your name, email, account ID, or any other identifying field. Plant.id and PlantNet receive image bytes and an optional location hint (see below). Nothing else. Wikimedia Commons is not a recipient of your data. We pull canonical species photos from Wikimedia on our side and include them alongside identification results. The flow is one-way: we read from Wikimedia, we send nothing to it. We do not share data with advertisers, data brokers, analytics resellers, or any company whose business is targeting users. Location data, and how to share less Identification gets more accurate when the service knows roughly where the plant is, because regional ranges narrow the candidate list. You decide how precise that hint is. Exact coordinates from your device give the strongest identification accuracy. This is the default if you grant location permission. City-level information is the alternative. Identification still works. The candidate list is broader and confidence scores are lower for species with overlapping ranges. The difference is meaningful for hard-to-distinguish species and negligible for unmistakable ones. You can change this setting at any time in Settings → Privacy → Location precision. The change applies to future identification requests, not to ones already submitted. Social posts and moderation Photos you post to the community are checked before they publish. When you post one, it stays private while an automated moderation service reviews it, and it becomes visible only if it passes. Content the check scores as clearly unsafe is withheld and never published. Borderline images are published and sent to a human review queue. This applies to community photos only, not to your identification or health-check photos, which stay private to you. The automated check is one layer. Reporting and blocking are the others. Anyone can report a post, comment, or profile, and reports route to a human review queue we aim to clear within 48 hours. You can block another user at any time, which removes their content from your view and stops them interacting with you. Blocking is immediate and does not wait on us. The automated check is a probability score, not a certainty, so a person makes the final call on anything serious. If the check reads an image as possible child-safety content, we withhold it and a person reviews it before any further action. When we become aware of apparent child sexual abuse material, US law requires us to report it, along with related account information, to the National Center for Missing & Exploited Children (NCMEC). We do this. If you delete a social post, it disappears from your visible profile and the public feed within seconds. Underlying record removal follows the same 30-day primary, 90-day backup schedule as your other data. Social posts are deleted entirely on account deletion. Unlike identification photos, they are not retained in any anonymized form. Product analytics We use PostHog to see how Ezina gets used. The point is to know which screens people reach, which they don't, and where the app gets in the way. That is the whole reason it's there. What PostHog receives: - An anonymous identifier tied to your account so we can tell two sessions are the same person without knowing who you are. - The names of screens you open and product events like adding a plant, starting an identification, opening a group, or snoozing a reminder. - Device type, operating system version, and app version. What PostHog does not receive: - Your name, email, password, or any other contact information. - Your photos or anything they contain. - Plant nicknames, group names, or notes you've written. - Location coordinates or city, in any precision. - Subscription receipts or payment details. We strip these fields before any event leaves the device. The list is enforced in code, not by policy alone. You can turn analytics off in Settings → Privacy → Anonymous analytics. The toggle takes effect immediately and persists across app restarts. Turning it off does not change anything else about how the app works. We do not sell event data, share it with advertisers, or pass it to any third party other than PostHog itself. PostHog is bound by a data processing agreement and operates only on our instructions. No ads We do not run ads in the app. We will not run ads in any future version. We will not insert sponsored placements, affiliate links, or paid species into identification results, care reminders, or any other surface. This is permanent. Pricing changes: notice and opt-in If we ever change subscription prices or credit pack prices, three things are guaranteed: 1. You will be notified at least 30 calendar days before the new price takes effect. 2. The notice is sent by email and shown inside the app. 3. Renewing at the new price requires your explicit opt-in. We do not auto-renew you onto a new rate. If you do nothing during the notice window, your subscription ends at the close of the current billing period. Credit packs you have already purchased continue to work normally regardless of pricing changes. Their value does not expire. This applies to subscriptions and credit packs equally. How we fund Ezina Ezina is funded by the people who use it. Subscription revenue and credit pack purchases pay for the identification API costs, hosting, infrastructure, and the team's time. We do not take venture capital, equity investment, accelerator funding, or any other outside money that comes with strategic input. No outside party has a seat at the table for product decisions or long-term plans. Growth is slower than a VC-backed competitor's. Decisions stay with the team and with the people using the product. If this changes, it changes in only one direction: more user revenue, never outside capital. Who we partner with We partner with companies and individuals whose work aligns with our values. The values are: - Transparency in how we price, what we collect, and what we share. - Compassion when users are confused, frustrated, or need help. - Education as the goal, with success measured by what users learn about their plants. - Support that is responsive and direct. When we add or change a partner, the partner appears on this page and the change is dated. How long we keep your data When you delete your account, your personal information is removed from primary storage within 30 days and from backups within 90 days. This covers your account profile, contact details, notification logs, and bug reports. Plant care data is kept after your account is deleted, in an anonymized form with the link to you permanently severed. This includes watering events and timings, fertilization records, disease and pest identification timings, plant placement and environmental context, and other general care signals. We keep this data because it makes the guidance we provide better for everyone. The dataset becomes more accurate as more plants of more species, in more conditions, generate more outcomes. None of it is tied back to you after deletion. Identification and health-check photos are handled on the same principle. With your permission at deletion time, anonymized copies stay in the species reference dataset to improve identification accuracy for everyone. The opt-out is a single tap on the account deletion screen, not a hidden setting. If you opt out, those photos are deleted on the same 30-day primary, 90-day backup schedule as your personal information. How you access your data You can download everything we have about you from Settings → Export my data. The export is a single archive containing: - JSON files for your account, plants, observations, watering history, fertilization records, identification history, notification history, and bug reports - Your original photos at their stored resolution - A README explaining what each file contains Export requests are limited to one per account per week. Generating an export costs us real compute and bandwidth, and a weekly cadence keeps that cost manageable while giving you a meaningful recurring window to pull a fresh copy whenever you want one. When you submit a request, the in-app screen shows the date you'll next be eligible. You can delete your account from the same Settings area without contacting us. Confirmation locks your account immediately and starts the deletion timeline above. If you need a partial export, a specific date range, or a partial deletion that the in-app flow does not cover, email support and we will handle it within 30 calendar days. When this page changes When we update this page, the change is dated at the top and described in the in-app changelog. Material changes are notified by email at least 30 calendar days before they take effect, on the same schedule as pricing changes. If you have questions about anything on this page, or want clarification on a specific commitment, email [SUPPORT_EMAIL]. We answer directly.