GardenKeen
GardenKeen privacy

Privacy Policy

Last updated July 25, 2026

GardenKeen uses the photo and growing location you choose to identify a plant and build a care plan. Email sync is optional, purchases stay with Apple, and the app includes local and synced deletion controls.

Information you provide

GardenKeen uses plant photos you take or select, the care language you choose, and a growing location you enter. The location may include city, region, country, latitude, and longitude. Optional sync uses an email address and one-time verification code.

Plant analysis and AI providers

When you scan a plant, the selected photo and requested health setting are sent through Tepesoft's encrypted backend to Plant.id for specialist plant identification and diagnosis. The photo, candidate identification, chosen language, and growing-location context may be sent to Google's Gemini service to create the care guide. These providers process data under their own service terms and privacy policies.

Location

GardenKeen uses the location you select to personalize planting months, weather-sensitive care, light, watering, and timing guidance. The app does not require continuous or background location. Location is not included on generated social share images.

History and My Garden

Photos, reports, plant notes, chat history, watering events, and reminders are stored locally on your iPhone. If you optionally verify an email in Settings, encrypted background sync stores this data with your GardenKeen account so it can be restored after reinstalling or on another device.

Purchases

Subscriptions are processed by Apple. GardenKeen checks cryptographically signed App Store transaction information on device and may send the signed transaction to Tepesoft for entitlement verification. Tepesoft does not receive your full payment card details.

App product analytics

After the matching App Store privacy disclosure is live, GardenKeen may use first-party product-interaction events to measure whether scans lead to saved plants and completed care reminders. Events use a random app-scoped identifier that Tepesoft hashes before storage. They may include app version, entitlement state, capture source, broad confidence and duration ranges, permission outcome, and coarse failure reason. They never include plant photos, EXIF, coordinates, place names, filenames, plant or diagnosis text, notes, notification text, email, advertising identifiers, or model prompts and responses. This collection is disabled until the compatible app update and disclosure are available.

Caching and reliability

Tepesoft may retain a SHA-256 image hash and successful Plant.id response in a protected cache for up to 90 days. The cache does not retain the original photo bytes. It prevents the same unchanged photo from consuming another Plant.id credit and improves speed. For compatible app versions, a retry result may be retained for up to 24 hours and successful scan-allowance records for up to 35 days. The app keeps undelivered product-event retry data on the iPhone for no longer than 7 days. App-scoped and account identifiers in allowance records are stored as one-way hashes. These records are used for reliability and cost control, not advertising.

Sharing and sales

We do not sell GardenKeen personal information. Data is shared only with service providers needed for hosting, identification, AI care guidance, email verification, purchase verification, security, and support, or when legally required.

Website analytics

If you select Allow analytics, the GardenKeen website loads Tepesoft's self-hosted Umami analytics and Microsoft Clarity with strict text masking. They measure public-page visits, referral and campaign tags, device and browser details, approximate network location, clicks, and scrolling. They do not receive plant photos, diagnoses, garden records, notes, email, or anything from the iPhone app. Select Analytics choices at any time to allow or withdraw access.

Retention and deletion

Local photos, reports, and garden records remain on your iPhone until you delete them in the app or remove the app. Optional synced data remains while your GardenKeen account is active. Deleting an item or account removes its live server copy promptly; encrypted operational backups may retain deleted records for up to 30 days before automatic rotation. The local event retry queue expires after 7 days, retry result bodies after 24 hours, scan-allowance records after 35 days, the Plant.id response cache after 90 days, and first-party product events after 400 days. Account deletion does not cancel an Apple subscription, which must be managed through your Apple Account.

Safety and children

Plant identification and care guidance can be wrong. Use qualified expert confirmation before eating, touching, treating, selling, or making medical, toxic, allergy, or pet-safety decisions about a plant. GardenKeen is not directed to children under 13.

Contact and changes

Questions can be sent to info@tepesoft.com. We may update this policy when providers or app features change. Material updates will be reflected here with a new date.