Privacy
Green Claws is made by Zander Martineau. This page says what the app stores, what it sends to other companies and why, in plain terms rather than in the language of a template.
Last updated 23 August 2026.
The short version
Your garden is private unless you choose to share it, and there are exactly two ways to do that: publishing it as a web page, or handing support a temporary link. Both are off unless you turn them on, and both can be turned off again. There is no advertising, no tracking, no per-person analytics, and nothing about you is sold or shared for marketing. Your location is deliberately stored too coarsely to identify your address.
Who you are
Signing in uses Sign in with Apple, and it is the only way in. Apple gives the app an identifier for you, your email address, and your name if you choose to share it. All three are stored. If you use Apple’s Hide My Email, the address stored is Apple’s relay address rather than your real one, and that works fine.
Nothing else about who you are is collected. There is no password, no profile, and no third-party sign-in.
Your photographs
Photographs you take are stored in Cloudflare R2. Deleting a photo or a plant in the app deletes the underlying file.
To identify a plant, the photograph is sent to OpenAI. When the model is not confident enough, it is also sent to PlantNet for a second opinion. Both are used for identification only. Photographs are not used to advertise to you.
Where your garden is
Location is optional, and declining it only turns off the watering feed. Nothing else stops working.
If you allow it, the app asks iOS for a deliberately reduced-accuracy fix, and the server then rounds that to roughly a 10km grid before storing it. Your precise position is never stored. The rounded point is sent to Open-Meteo to look up rainfall where you garden, which is what makes the watering advice follow real weather instead of a fixed schedule.
Notifications
Turning notifications on stores a device token from Apple, so the weekly digest and dry-spell messages can reach your phone. Turning them off in iOS Settings stops them.
Crash and failure reports
When the app cannot reach the server at all, there is no record of the failure on the server side, so the app writes one to your device and sends it the next time it gets through. The same happens after a crash.
These reports contain the app version, your iOS version, your device model (for
example iPhone16,2) and what failed. They do not contain your photographs,
your plants or your location.
Payments
Subscriptions and the lifetime purchase are handled entirely by Apple. Card details never reach the app or the server. Apple tells the server only whether your subscription is active.
Publishing your garden
Publishing is off by default. If you turn it on, the page you choose the address for becomes readable by anyone with the link, including search engines. It shows your photographs, your plants and what is in flower. Turning it off takes the page down.
Showing support your garden
Some problems cannot be diagnosed from a crash report, because the thing that is wrong is in your own garden. Settings → Help → Share with support creates a link that lets us look at it, and it exists only if you make one.
What that link shows: your plants and their photographs, your notes, nicknames and where things grow, whether your subscription is active, and whether you have shared a location — never where that location is. It does not show your name or your email address. The page is read-only, so nothing looked at through it can be changed.
The link expires after a week on its own, and Stop sharing ends it immediately. The same screen shows how many times it has been opened and when it was last opened, so you can see what came of it rather than having to take our word for it. We store a fingerprint of the link rather than the link, which is why it is shown to you once and cannot be retrieved afterwards.
Knowing how the app is used
We look at counts, never at people. How many plants a typical garden holds, what proportion of identifications get confirmed, which species are most commonly grown, how many gardens are published. Every one of those is a total or an average across everybody, and no report of this kind names an account, opens a garden or shows a photograph. There is no analytics service involved, and nothing is sent anywhere to produce them.
Who else sees anything
- Apple. Sign-in, notification delivery, and confirming your subscription.
- OpenAI. Receives photographs you take, to identify them.
- PlantNet. Receives a photograph when the first identification was not confident.
- Open-Meteo. Receives the rounded location to return rainfall.
- Cloudflare. Hosts the service and stores the photographs.
- Wikipedia. The app fetches reference photographs by species name. It is never sent anything about you.
- The RHS. The server reads public plant pages to build the care records. No information about you is involved.
Plant records are shared across everyone who grows the same species, and contain nothing about the person who first photographed it.
Data is held in a PostgreSQL database in the AWS Europe West location and in Cloudflare R2.
Deleting things
Individual photographs and plants can be deleted in the app at any time, and deleting a plant deletes its photographs from our system. Settings also has Remove all plants, which empties the garden of every plant, every photograph and anything still waiting to be identified, while keeping the account and the garden’s web address.
Delete account is in the same place, and it removes everything: your plants, your photographs, your published page, any support link you had shared, your name, your email and your location. It takes effect immediately. You are signed out, and a published garden stops being reachable the moment you ask. The records themselves are kept for 30 days so that an accidental deletion can be undone by simply signing in again; after that they are deleted for good and cannot be recovered. Deleting your account also tells Apple to revoke Sign in with Apple for this app, so Green Claws disappears from the list in your Apple ID settings.
A subscription is held by Apple rather than by us, so deleting your account does not cancel one. Use Manage subscription in Settings before you go.
Your rights
Under UK data protection law you can ask for a copy of what is held about you, ask for it to be corrected, or ask for it to be deleted. Write to privacy@greenclaws.app. If you are unhappy with the response, you can complain to the Information Commissioner’s Office at ico.org.uk.
Children
Green Claws is not aimed at children and is not designed to collect anything about them.
Changes
If this policy changes in a way that affects what is collected, the date at the top changes and the app will say so rather than changing quietly.