Pet Safety: Plant Checker (the "App") is developed and operated by an independent developer based in Amsterdam, Netherlands.
Contact: basarapps@gmail.com
2. What data we collect
There are no accounts. The App has no login, no sign-up, and no email or social sign-in. Your identity is an anonymous random identifier generated on your device at first launch (a "device ID"). We never collect your name, email address, or any social-login profile.
Device identifier: a random per-install device ID, generated on first launch. It is the only thing that links your device to our server โ used to track your credit balance and subscription and to prevent starter-credit abuse. It is not tied to your name, email, or any account.
Pet profiles: the pet name, type, breed, emoji, and optional photo you create are stored only on your device. They are never uploaded to our servers.
Saved plants (My Plants library): the plants you save are stored only on your device, not on our servers.
Plant scan history: your readable scan history (plant names, verdicts, photos, timestamps) is stored only on your device. On our servers we keep only an anonymous scan-event log for each scan โ the resolved plant name, the safety verdict, and an IP-derived country code. We do not store the location (coordinates) of your scans on our servers. This log is tied to your anonymous device ID, not to any personal identity, and does not contain your pet's name or the full result text. The one exception: if you report an incorrect result using the in-app flag feature, the result details (and the photo, if you attach one) are uploaded and stored for our review.
Plant photos: the photo you scan is sent to our AI provider for analysis and is not stored by us โ except a photo you choose to attach to an incorrect-result report (see above).
Scan location: if you grant location permission, the scans on your private Map tab (fog-of-war reveal, home-zone progress, your personal pins) are kept only on your device. The exact coordinates of your scans are never sent to or stored on our servers. The single exception you control: if you pin your home location on the Map, that one coordinate is stored once in a separate home-pin record, and you can remove it at any time. We also store an IP-derived ISO country code (country-level only, not a precise location) on each scan and each toxicity-quiz score so we can show regional plant-prevalence stats and country-scoped leaderboards. See the community density map note below for the only location-derived data that is shared โ and even then it is anonymized and aggregated, never your exact location.
Usage data: credit balance, subscription plan, and language preference.
Push notification token: a Firebase Cloud Messaging (FCM) token, collected if you grant notification permission, used only to send you app notifications.
Operational data: per-analysis diagnostic data linked to your anonymous device ID โ including the raw plant-identification output from the AI, the canonical plant name resolved against the GBIF taxonomy database, whether the safety verdict was served from our cache, the language code used for the response, request latency, and an idempotency key to handle client retries safely. Used for service monitoring, quality investigation, and debugging.
Community density map (anonymized & aggregated): the Map shows a coarse "density" heatmap of where plants โ especially toxic ones โ are being found by users in your area. If you have enabled location for the Map, each of your located scans contributes one anonymous tick to this heatmap. Before anything leaves your device, the location is snapped to a coarse grid (roughly one kilometre), and we store only a per-cell count together with the most-common verdict and plant for that cell. We never store your exact coordinates, we never attach your device ID or identity to it, and it cannot be linked back to you or to any individual scan. Grid cells with too few scans are hidden entirely, so a single person's activity can never be singled out. This is the only scan-location-derived data that is ever shared with other users, and there is no precise location, no publishing step, and no individual pin involved. To stop contributing, turn off location for the Map.
Nearby vets: when you tap to find nearby vet clinics, your coordinates are sent through our backend to the Google Places API at request time only. We do not write those coordinates to our database โ they are used for that single lookup and discarded.
This app contains no advertising and integrates no advertising or analytics SDKs beyond the operational services listed in section 4. We do not track you across other apps or websites.
3. How we use your data
To identify plants and generate safety assessments via AI.
To track your subscription and credit balance against your anonymous device ID.
To power the Map, its anonymized community density layer, regional stats, and quiz leaderboards.
To send push notifications you have opted into.
To prevent abuse of the free starter credits.
We do not sell your data to third parties.
We do not use your data for advertising.
4. Third-party services
Anthropic Claude API โ processes plant photos for identification and generates safety assessments. Per Anthropic's data usage policy, content submitted via the API is not used to train their models and is retained only for a limited period for operational and abuse-monitoring purposes.
RevenueCat โ manages subscriptions and in-app purchases. We receive only your subscription status and transaction IDs, not payment details. Purchases are tied to your store account (Apple ID / Google account) and your anonymous device ID โ not to any account with us.
Firebase Cloud Messaging (Google) โ delivers push notifications to your device. Your FCM token is stored on our server and shared with Firebase solely to send notifications.
Google Places API โ used server-side to find nearby open veterinary clinics based on your device's location. Your coordinates are sent to Google and are subject to Google's Privacy Policy.
GBIF / Wikipedia / Wikidata / iNaturalist / POWO (Kew Royal Botanic Gardens) โ used to look up plant names, multilingual translations, and reference photos. Only plant names and language codes are shared with these services; no personal data is involved.
CARTO (CartoDB) โ serves the base map tiles you see on the Map tab (basemaps.cartocdn.com). Your device requests tiles directly from CARTO when you pan or zoom the map, so CARTO sees your IP address and the tile coordinates you are viewing. Subject to CARTO's privacy policy.
Cloudflare โ sits in front of our backend API for DDoS protection and TLS termination. Cloudflare logs the IP address and request URL for every API call and provides us with a pre-computed ISO country code derived from your IP, which we use for the country-level stats described in section 2.
ip-api.com โ fallback IP-to-country resolver used only when the Cloudflare country header is missing. We send only the request IP; no API key, no account, no other data is shared.
Sentry โ used for crash and error monitoring. Unhandled errors may include technical context such as plant names or pet types. Personal identifiers are not sent to Sentry.
Railway โ hosts our backend server and PostgreSQL database.
5. Data retention
Your pet profiles, saved plants, and readable scan history live on your device and are removed when you delete the app or use "Delete my data" in Settings. On our servers we keep your anonymous device record (subscription, credits, language) and the anonymous scan-event log described in section 2. We retain up to 10,000 scan-event rows per device; once that ceiling is reached, the oldest is auto-trimmed when a new scan is made. When you use "Delete my data," your device record and all of its scan-events, home pin, quiz scores, and any reports you filed are permanently erased from our servers. The anonymized community-density counts are aggregate and contain no device ID or coordinates, so they cannot be linked to you and are not part of (or affected by) a deletion request.
6. Your rights (GDPR)
Because we hold no name or email, we cannot identify you from our records alone โ your data is keyed only to an anonymous device ID. As a resident of the EU/EEA you have the right to:
Delete your data โ use the "Delete my data" option in the app's Settings screen. No email or account is required. This permanently erases, from your device and our servers, your on-device data plus the server-side device record: scan-events, home pin, quiz scores, any notes, and any reports you filed.
Access & portability โ your readable history already lives on your device, in your control. For a copy of the anonymous server-side data tied to your device, contact us at the email below with your in-app device ID (shown in Settings).
Object / restrict processing โ contact us at the email below.
You may also lodge a complaint with the data protection authority in your country of residence.
7. Security
All data is transmitted over TLS. There are no accounts and no passwords โ identity is an anonymous on-device identifier, so there are no login credentials to steal. API keys are stored as environment variables, not in source code.
8. Changes
We may update this policy. Material changes will be communicated via an in-app notice.