Privacy policy
Last updated: 28 August 2026
1. Who we are
Plant Planner ("we", "us", "our") operates the website plantplanner.com.au and the Plant Planner app for iPhone. We are an Australian-based service that helps home gardeners plan and manage their vegetable garden beds.
2. Information we collect
We collect the following personal information:
- Account information: Name, email address (for authentication via magic link or Google sign-in)
- Garden data: Postcode, family size, garden bed dimensions, crop assignments, planting schedules
- Photos: Bed, crop, and plant-diagnosis photos you optionally upload
- Preferences: Dietary preferences, crop preferences (favourites/blacklist), notification settings
- Feedback: Survey answers, ratings, recommendation choice, and any later permission you give us to publish an exact excerpt
- Payment information: Processed securely by Stripe. We do not store your card details.
- Usage data: PostHog records page views and basic interaction data for visitors using a pseudonymous browser identifier. After sign-in, analytics and error reports are tied to your account; a sample of signed-in sessions may also be replayed, with all form inputs masked and never captured. We use this to diagnose bugs and improve the planner. This collection is disclosed here as part of how the service operates; we do not treat continued use or silence as a separate consent choice.
3. How we use your information
- To provide personalised crop recommendations based on your postcode and climate zone
- To calculate family consumption needs based on household size
- To generate planting schedules and send email reminders
- To process subscription payments via Stripe
- To improve our recommendation engine and user experience
- To keep a private visual timeline of your garden photos
- To display a particular photo in the community gallery only after you submit that photo for review
- To publish an exact feedback excerpt only when you separately approve the quote, attribution and channels
4. Private photos and the community gallery
Saving a photo to a bed does not publish it. It stays in the private growth journal for that garden and is visible to you and people you have given access to the garden.
You may separately submit an individual photo to the public community gallery. Before submission, we show what will be published and ask you to actively confirm that you took the photo or have permission to share it. The sharing confirmation is not pre-selected.
- Shown if approved: The selected photo, caption, crop or growth stage, month, and the display name and broad region you choose
- Not shown: Email address, account name, exact postcode or address, payment details, private bed name, or private journal history
- Review: A submitted photo remains private until we approve it against our community standards
You can withdraw a shared photo at any time. We stop listing it and queue deletion of the public copy; your private journal copy remains unless you delete it too. A withdrawn image may remain briefly in third-party delivery caches, and copies already saved or screenshotted by another person are outside our control.
Community-gallery permission does not let us use a photo in advertising, email campaigns, paid promotion, or social media. We ask for separate, optional permission before any marketing use.
5. Data storage & security
- Data is stored on Neon (PostgreSQL) servers
- Photos are stored on Vercel Blob. Private growth-journal files and approved public gallery copies use separate access paths
- All connections use TLS/SSL encryption
- Authentication is handled via NextAuth.js with secure session tokens
- We do not sell your personal data to third parties
6. Third-party services
We use the following third-party services:
- Vercel: Hosting and infrastructure
- Neon: Database
- Stripe: Payment processing
- Resend: Transactional email
- Google: Authentication (optional)
- Apple: Authentication (optional), plus in-app purchases and push notification delivery for the iPhone app
- Anthropic: Powers the planner's crop suggestions, Plant Doctor and garden coach
- PostHog: Product analytics, sampled session replay (form inputs fully masked), and error tracking
7. The Plant Planner iPhone app
The Plant Planner app for iPhone is a native wrapper around the same Plant Planner service. It signs you in to the same account and reads and writes the same data as the website, so everything else in this policy applies to the app as well. These parts are specific to the app:
- Camera & photo library: With your permission, the app uses your camera or photo library so you can add garden photos or send a photo of an ailing plant to Plant Doctor. Growth-journal images are re-encoded to remove embedded metadata, including location data, before a gallery copy can be published. You should still keep people, house numbers and other identifying details out of frame. Plant Doctor photos are sent to Anthropic to analyse the image and return the diagnosis. iOS asks for camera and photo access the first time you use it, and you can change or withdraw that permission at any time in iOS Settings.
- Push notifications: Optional and off until you accept the iOS prompt. If you accept, we store a device token against your account so we can send planting and watering reminders to that iPhone. The token identifies the device, not you personally, and we use it for nothing else. You can turn notifications off at any time in iOS Settings, and the token is deleted when your account is deleted.
- Face ID / Touch ID app lock: Optional, and off unless you turn it on. The check is performed by iOS on the device itself. No biometric data is ever sent to us, stored by us, or available to us, we only learn whether the device unlocked.
- In-app purchases: Subscriptions bought inside the app are processed by Apple. Apple sends us a signed transaction record containing a transaction identifier and the product purchased, which we store to activate your plan. We never see your card details or your Apple ID. Subscriptions started on the website are still handled by Stripe.
- Analytics: The app loads the same web experience, so the same PostHog product analytics, sampled session replay, and error reporting described in section 9 apply, with form inputs masked in exactly the same way. The app contains no additional advertising, attribution, or tracking software, we do not use Apple’s advertising identifier, and we do not track you across other apps or websites.
- Account deletion: You can delete your account from inside the app under Settings → Privacy & data, and download a copy of your data from the same place first. Deletion signs you out immediately and, after a 48-hour safety window, removes your account and garden data from our live systems, including beds, crops, schedules, harvest records, photos, and registered device tokens, and cancels any Stripe subscription. Access-controlled disaster-recovery backups are isolated from normal use and expire on a rolling schedule within 12 weeks; they are used only to restore the service after a serious incident, not to recover an individual account. We retain de-identified deletion timing and plan statistics; the raw email and optional deletion reason are removed at purge. A subscription bought through Apple must also be cancelled in your iPhone’s subscription settings, only Apple can stop that billing.
8. Your rights
You can use the access and correction rights provided by the Australian Privacy Principles (APPs), and the additional account controls Plant Planner provides:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated personal data, subject to limited legal, security, and de-identified records described above
- Opt out of marketing communications
- Withdraw an individual community-gallery photo at any time
To exercise these rights, contact us at support@plantplanner.com.au.
9. Cookies & analytics
Essential cookies keep you signed in and remember your preferences. These always run, they’re required for the app to work.
Product analytics (via PostHog) record page views for visitors using a pseudonymous browser identifier. When you sign in, we associate product events and error reports with your account. A sample of signed-in sessions may also be replayed so we can diagnose difficult interface problems. We disclose this collection in this policy; because there is no per-session choice, we do not describe continued use as consent.
What we record: page views, clicks, scroll depth, and, for sampled signed-in sessions, a replay of navigation. Form inputs (postcode, names, addresses, messages, card numbers) are fully masked and never captured in the replay stream.
We do not use third-party advertising cookies, and we never sell or share analytics data with advertisers. If you want your data removed you can delete your account in Settings → Privacy & data, or contact support@plantplanner.com.au.
10. Children
Plant Planner is not directed at children under 16. We do not knowingly collect personal information from children.
11. Changes to this policy
We may update this privacy policy from time to time. We will notify registered users of significant changes via email. The "last updated" date at the top reflects the most recent revision.
12. Contact
If you have questions about this privacy policy, contact us at: