Natives AI
GrowMe+ Privacy Policy
This policy explains how GrowMe+ handles information when you use its gardening, plant identification, Tohunga, community map, and account features.
1. Who is responsible
GrowMe+ is provided by Natives AI in Aotearoa New Zealand. For privacy questions or requests, email george@nativesonscreen.co.nz.
2. Information GrowMe+ handles
| Information | Examples and purpose |
|---|---|
| Account and profile | Google account email, display name, profile photo, Firebase user identifier, subscription access, mana, level, and achievements. Used to authenticate you, sync your account, and display the profile and leaderboard. |
| Purchases and subscriptions | Google Play product, purchase-token, subscription-status, renewal, cancellation, grace-period, expiry, and refund information. Used to verify purchases on the server, restore access, and apply subscription entitlements. |
| Garden and plant records | Plants, categories, notes, care and health logs, reminders, photos, Plant ID history, identification results, and confidence information. Used to provide My Garden, Plant ID, restoration, and offline-first synchronisation. |
| Tohunga interactions | Questions, recent conversation context, plant photos, and generated guidance. Used to answer gardening and plant-care questions and, when cloud history is enabled, restore chat history across devices. |
| Kai Map and community content | Spot title, description, produce status, precise map position, photos, privacy setting, ownership identifier, contributor display name, community-garden updates, reports, and blocked users. Used to operate the map, sharing, ownership controls, moderation, and community safety. |
| Location and weather requests | Foreground precise or approximate location when you request nearby spots, centring, local weather, a location label, or growing conditions. GrowMe+ does not request background location. |
| Security and usage | App integrity signals, authentication events, AI quota counts, timestamps, content moderation results, reports, and technical logs. Used to secure accounts, control costs, prevent abuse, diagnose failures, and enforce community rules. |
| On-device information | Local copies of garden records, photos, scan history, map cache, preferences, and scheduled reminder details. Used for offline-first operation and faster restoration. |
3. Device permissions
- Camera and photo picker: choose or capture plant, garden, profile, and Kai Map images.
- Location: show nearby places, centre the map, and request local weather and growing conditions while the app is in use.
- Notifications: deliver plant-care reminders you choose to schedule.
You can deny or revoke permissions in device settings. Some related features will then be unavailable. GrowMe+ does not request microphone, contacts, SMS, call log, or background-location access.
4. How information is used
- Provide, synchronise, restore, and improve GrowMe+ features.
- Authenticate accounts and apply subscription or complimentary access.
- Generate Plant ID and Tohunga responses and enforce daily quotas.
- Moderate photos, respond to reports, and protect community users.
- Award mana and achievements and operate the named leaderboard.
- Secure the service, prevent fraud and stale-account writes, and investigate technical problems.
5. When information is shared
Service providers
- Google Firebase and Google Cloud: authentication, database, file storage, server functions, app integrity, technical logging, Gemini/Vertex AI processing, and Cloud Vision photo moderation.
- OpenStreetMap: map tiles. Tile requests may expose network information such as IP address and the GrowMe+ app identifier to the tile service.
- Open-Meteo: weather and reverse-geocoding requests containing the latitude and longitude needed to return local results.
- Google Play and Apple platform services: app distribution, purchase and subscription handling, restore, cancellation, refund and entitlement status, and platform security services.
Other GrowMe+ users
A public Kai spot can expose its location, photo, produce details, and contributor display name to other users. Private spots and My Garden records are not publicly listed. The mana leaderboard displays a participant's chosen display name, mana, level, title, and profile image where available; accounts with zero mana are not shown.
GrowMe+ may disclose information when reasonably required to comply with law, protect users, investigate abuse, or defend legal rights. GrowMe+ does not sell personal information.
6. AI and photo moderation
Plant ID photos and Tohunga questions are sent through protected Firebase functions to Google Cloud AI services for processing. Plant ID input images are not saved by the diagnosis function itself. A one-way image hash and the generated identification result may be cached for up to 30 days to reduce repeated AI cost. Account-specific scan history and photos may be stored separately when you save or sync them.
Kai Map photos are checked with Google Cloud Vision for people, unsafe content, animals, and whether the image appears relevant to plants or kai. Rejected photos are removed from GrowMe+ storage. Automated results can be imperfect.
7. Retention and deletion
Account information and synced content are generally kept while your account is active or until you delete the relevant item. Daily account-linked AI quota records are configured to expire after about 35 days. Shared Plant ID cache results are configured to expire after 30 days. Provider security logs and backups may persist for limited operational periods under the provider's retention processes.
Deleting your GrowMe+ account removes the Firebase Authentication account and associated profile, mana, achievements, garden records, health logs, Plant ID history, Tohunga chat history, owned Kai spots, reports, attribution, and uploaded photos covered by GrowMe+'s deletion process. Local GrowMe+ account data is also cleared on the device that completes in-app deletion.
GrowMe+ retains a minimal security tombstone after deletion. It contains the former Firebase user identifier as the record key and the deletion start time, but no name, email, profile, photo, garden, chat, or map content. It is retained to reject stale authentication tokens and delayed writes that could otherwise recreate deleted data.
See Delete your GrowMe+ account for both in-app and web-request instructions.
8. Your choices
- Edit your display name and profile photo in GrowMe+.
- Edit, make private, or delete Kai spots you own.
- Edit or delete My Garden records and local history.
- Change device permissions and notification settings.
- Delete your account and associated data in Settings.
- Contact Natives AI to request access, correction, or deletion.
9. Children
GrowMe+ is a general-audience gardening app and is not designed or directed specifically to children. Do not submit another person's personal information or a photograph containing a person.
10. Security and international processing
GrowMe+ uses access controls, authenticated requests, App Check, encrypted network connections, scoped storage rules, and server-side ownership checks. No system can guarantee absolute security. Google and other providers may process information outside New Zealand where their infrastructure operates, subject to their contractual and security safeguards.
11. Changes to this policy
This policy will be updated when GrowMe+'s data practices materially change, including before new analytics or third-party SDKs are added. The effective date at the top identifies the current version.
12. Contact
Natives AI
Aotearoa New Zealand
george@nativesonscreen.co.nz