Plant Tender
How it works Pricing Sign in

← Plant Tender

Privacy

Last updated: September 2, 2026.

I'm Stephen. I built Plant Tender, I run it, and I'm the only person with access to the database. This page is my honest account of what data the app handles, where it goes, and what I do and don't do with it.

I rewrote this page from scratch on August 17, 2026, because the old version had drifted from what the code actually does. This one is written against the code as it stands today — and it also describes a few things that are built but not switched on yet, so that when I do switch them on, you were told first. Where something isn't live yet, I say so in that sentence.

If any of it isn't clear, email hello@plant-tender.com and I'll answer you personally.

The short version

  • Your plants, photos, and readings are yours. They're scoped to your Home, and only members of your Home can see them.
  • Photos and meter shots go to Anthropic (Claude) so the app can read them. They are not used to train anyone's model.
  • I run analytics — Google Analytics plus my own first-party event store — on the marketing pages and inside the app. That's how I learn which parts of the app work. Google is never sent the ID of a plant or a reading, even though those IDs appear in the address bar; the address is stripped before it goes.
  • I run ad pixels on the public pages my ads point at — the two ad landing pages and the free scanner at /scan — and my server reports signups, first-plant-added, and paid subscriptions to Meta and to Reddit so I can tell which ads actually work. Those reports carry your hashed email and click IDs. Never your plants, photos, or readings. One more report goes out about people who aren't signed up: if you take the free scan at /scan, the fact that a scan finished is reported the same way — with no email and no user ID attached, and never the plant it found.
  • I may publish aggregate, de-identified insights drawn from readings across all Homes — "monstera owners water at 28% moisture on average." Never your individual data, never anything that identifies you or your Home.
  • I don't sell your data, and I don't run a newsletter. The only marketing email I send is a short follow-up sequence you opt into by asking for the printable chart — one click gets you out of it, and it isn't switched on yet.

What I collect

Your account. When you sign up — with Google, with Facebook, or with an email and password — I keep your email, your name, and (if you used Google) your Google profile picture. If you set a password, I store a PBKDF2 hash of it, never the password itself.

Your Home and your plants. Everything in Plant Tender is grouped under a "Home." Inside your Home I store the plants you add (nickname, species, room, soil medium, pot depth, care thresholds), the photos you upload, the meter readings you log, and the watering and feeding entries you record. Every one of those rows is tagged with your Home's ID and is only ever readable by members of that Home.

Scans you run before you have an account. The public scan demo — not live yet, it's coming — lets you photograph a plant or a meter without signing up. That photo goes to Claude the same way an in-app scan does. I keep the photo and the result for up to 30 days so I can debug failures, then delete both. There's no account attached to it, only the anonymous visitor ID described below.

An email address, if you ask me for the printable chart. Not live yet — the form is built and switched off. There's a printable watering chart on the site behind a short form: you type in an email address, I send you the link. If you do that, I keep the address, which printable you asked for, the topic of the page you asked from, the ad parameters that brought you there if there were any, and the anonymous visitor ID below — so I can tell which pages actually earn a download. That form is the only place on the whole site that asks an email address of someone who doesn't have an account, and asking for the chart is the only way to end up on that list. Nobody can put you on it but you.

Product analytics. I run a first-party event store. It records things like: a page view, a click on a call-to-action, a scan attempted or failed, a signup started or completed, a plant added (including the species, and which number plant it is in your Home), a first verdict viewed, a paywall shown or dismissed, and a subscription started (including which plan and price you were shown). Each event carries the page path, the referring page, your browser's user-agent string, the anonymous visitor ID, the traffic source that first brought you here, and — once you're signed in — your email and Home ID.

This runs on the marketing pages and on the pages behind sign-in. An older version of this policy said the app carried no analytics. That was wrong when it was written and it would be wrong now, and rather than quietly pull the analytics out I'd rather tell you plainly that it's there. What it never records: the content of your photos, the values of your readings, your notes, or anything Claude says back to you.

How you got here. If you land on plant-tender.com from a link carrying utm_source, the site stores the source in a first-party cookie (pt_attrib, 30 days) so I know which channel introduced us. If you arrived by clicking a Facebook or Instagram ad, the link carries Meta's click ID (fbclid), and I store it in a first-party cookie (pt_fbc, 90 days). If you sign up during either window, I write those values onto your user record — along with Meta's own _fbp browser ID if its pixel set one — because the Purchase report described below fires weeks later from a billing webhook, where there's no browser left to read a cookie from.

Your session. After you sign in I set an HMAC-signed cookie (plant_tender_session, 30 days) carrying your email, name, role, Home ID, and admin flag. It's HttpOnly, Secure, SameSite=Lax, and sent only to plant-tender.com.

Your billing details, indirectly. If you subscribe to Pro I hand you to Stripe's Payment Element. Card numbers go straight to Stripe — I never see them and they never touch my servers. Stripe hands back a customer ID, a subscription status, a price ID, and a renewal date, and I store those on your Home.

Support conversations. Email to support@ or hello@, and messages in the in-app chat bubble, are stored along with my replies so I have a record to work from. If you tap "send feedback" in that chat, or the agent escalates something it can't handle, the thread — including your name and email — is filed as an issue in my private GitHub repository, because that's where my bug tracker lives.

Reviews you write. If you submit a review I store the rating, the text, and a snapshot of your display name and email. Approved reviews are published on the landing page with your display name attached. Nothing appears until I approve it, and if you want yours taken down, email me and it's down.

Technical telemetry on every AI scan. For each call to Claude I record which endpoint ran, the model, the latency, token counts, my cost, whether the response parsed, the model's confidence, and any failure reason — plus your email and Home ID so I can find your scan when you write in about it. This is how I know whether the scanner is actually working. The photo itself isn't stored in that record.

The pre-signup scan doesn't keep your photo at all. If you scan a plant before making an account, the photo goes to Claude, the answer comes back to you, and the image is dropped when the request ends — nothing is written to my storage. There's no account to attach it to, and I'd rather not hold a stranger's photo. If you then sign up and save the plant, the app uploads it again, and from that point it's covered by everything above.

Rate-limit counters. Scanning is unlimited on every plan, free included. To stop a runaway script from running up an Anthropic bill, I count scans per user, per Home, and globally in short time windows, and I check your IP address against a per-IP limit on the analytics and public endpoints. IP addresses are used for those checks in memory; they aren't written into the analytics rows.

The one exception, and I want to be exact about it: the free scan you can take before making an account is limited per IP address, and that limit has to survive a page reload, so it can't live only in memory. What gets stored is not your address — it's a keyed hash of it (HMAC, with a secret only my server holds), and for IPv6 only the network prefix, not the specific address. It sits in a counter row with no name, no email, and no Home attached, and those rows are deleted after 7 days. There is no way to turn one back into an address without the key, and I don't do that either. No device fingerprinting is used for this or anything else.

That's the full list. No device fingerprinting, no precise location, no contacts, no microphone, nothing bought from a data broker.

Cookies, specifically

Cookie Who sets it Lives What it's for
plant_tender_session me 30 days keeps you signed in
pt_vid me 1 year anonymous visitor ID that joins your visit to your signup
pt_attrib me 30 days which channel introduced us
pt_fbc me 90 days Meta click ID, for ad attribution
_ga, _ga_* Google Analytics up to 2 years analytics
_fbp, _fbc Meta pixel up to 90 days ad attribution
Reddit pixel cookies Reddit per Reddit's policy ad attribution
Cloudflare / Turnstile Cloudflare short-lived bot protection, see below

Block any of them in your browser and the app still works. Block the session cookie and you can't stay signed in.

Where your data goes

  • Anthropic (Claude). Plant ID photos, health-diagnosis photos, meter photos, and support messages go to Anthropic so Claude can read them and respond. Under Anthropic's commercial API terms, this data is not used to train their models.

  • Harper (HarperDB Fabric). The app, the database, and your photos run on Harper Fabric, in the United States. A disclosure worth making: I'm also the founder of Harper. It's the stack I know best. It isn't a data-sharing arrangement, and nobody at Harper gets access to your Home because of it.

  • Cloudflare. Sits in front of plant-tender.com, so it terminates TLS and sees the IP address and request metadata of everyone who visits. Cloudflare Turnstile protects the public pre-signup scan endpoint, running in invisible mode — there's no puzzle to solve and normally nothing to see; Cloudflare's handling of that data is covered by the Turnstile Privacy Addendum, which I'm required to link here and am glad to.

  • Stripe. Card processing and subscription management. I never hold card data.

  • Resend. All outbound email — setup, password resets, receipts, support replies, the short onboarding sequence. Inbound mail to my support addresses comes back to me through a Resend webhook.

  • Google (sign-in). If you sign in with Google, Google verifies you and returns an identity token with your email, name, and picture.

  • Google Analytics (property G-5T4LMZFD87). Runs on the public pages — the landing page, the blog, the pricing page, the guide pages, the legal pages, the ad landing pages, and the free scanner at /scan — and on every screen of the app, including sign-in and sign-up. Google sets its own cookies and sees your IP address and which pages you viewed.

    Two things I want to be exact about, because app addresses are not like marketing-page addresses. The address is stripped before Google sees it. Screens like the plant profile and the weekly check carry a record ID in the address bar (?id=…), and that ID is a durable identifier for one of your records even though it isn't your name — so the address I report is rebuilt from scratch: the page, with the query rebuilt from a five-item list of ad-campaign tags (utm_source and its four siblings) and nothing else. Record IDs, referral codes, and ad click IDs are dropped, and the same stripping is applied to the previous page's address, which is the other place it would otherwise leak. And two places it deliberately never runs: my own admin screens, so that my own use doesn't distort the numbers, and a plant-sitter link (/sit/…), whose address is the pass — that one is never reported to anybody.

  • Google Search Console. Shows me which search queries surface Plant Tender. Aggregate only — Google never tells me who searched.

  • Meta. Four separate things, and I want to be precise about each. (1) Facebook sign-in returns your name and email, same as Google. (2) Meta's pixel loads on exactly three pages and nowhere else: my Facebook/Instagram ad landing page, the free pre-signup scanner at /scan (the page those ads now point at), and — the only one inside the signed-in app — the add-a-plant screen, where it fires a single FirstPlantAdded event the first time a Home adds a plant. On /scan it records the page view and sets the cookies in the table above; it is not told what you photographed or what the scan returned. It does not load on any other screen of the app. (3) My server reports four conversions to Meta's Conversions API — SignUp, FirstPlantAdded, Purchase (the last with the amount you paid), and ScanCompleted. The first three carry your email hashed with SHA-256, a hashed internal user ID, your IP address, your user-agent string, and the click IDs above. Meta compares the hash against its own records; your address never goes over in the clear.

    ScanCompleted is the odd one out and I want to be exact about it. It fires when the free pre-signup scan at /scan finishes successfully, which is before there is any account, so there is no email and no user ID to send and none is sent. What goes over is your IP address, your user-agent string, and — only if you arrived from a Meta ad and its click ID is in your browser already — that click ID. Not the photo, not the plant it identified, not a first-party ID of mine. It exists because I need some signal an ad platform can optimise toward that happens more than four times, and a finished scan is the one honest candidate. There is a switch on my side and this stays off until I turn it on. (4) I use Meta's APIs to publish Plant Tender's own posts to my Facebook Page, Instagram, and Threads — outbound only, none of your data involved.

  • Reddit. Two things. (1) Reddit's pixel runs on my Reddit ad landing page and reports the visit and the signup. (2) My server reports the same four conversions to Reddit's Conversions API that it reports to Meta — SignUp, FirstPlantAdded, Purchase (the last with the amount you paid), and ScanCompleted, with the same carve-out described above: a scan report carries no email and no user ID, because there is no account behind it. The other three carry your email hashed with SHA-256, a hashed internal user ID, and your user-agent string — plus, once I capture it on the ad landing page, the Reddit click ID from the ad you arrived on. Your IP address goes to Reddit hashed, not in the clear the way it goes to Meta: Reddit's API asks for the hash, and I'd rather send the hash. Reddit compares the hashes against its own records. This half is switched on by a credential I hold in Reddit's Events Manager; while that credential is absent the reports simply don't go out, and I'm telling you about it here first either way. Meta and Reddit are the only two places data about you goes to an ad platform from my servers.

  • GitHub. Support escalations and in-app feedback are filed as issues in my private repository, including the message text, your name, and your email.

  • Google Gemini. Generates illustrations for blog and social posts. No user data is ever sent to it — only my own prompts.

  • Amazon. The soil-meter links on this site are Amazon affiliate links. Click one and Amazon knows you arrived from me and sets its own cookies; if you buy, I earn a small commission (about 3%). Amazon never tells me who you are, and the price is the same either way.

If you interact with Plant Tender's own posts on Facebook, Instagram, or Threads, I store the public comment, your handle, and your display name so the app can reply. That's information you already made public on those platforms.

That's every third-party integration there is. Nothing else.

What I do with it

Run the app. Identify your plants, read your meter, produce your verdicts, keep your history, bill you if you're on Pro, answer your email.

Figure out what's working. Which pages get read, which ads bring real users, where people get stuck, which scans fail. That's what the analytics and the conversion reports above are for.

Publish aggregate insights. This is new, and I want to be explicit about it. I intend to publish things like "across Plant Tender Homes, fiddle-leaf figs get watered when moisture drops below 30%," or "monsteras in low light are the most-diagnosed plant in winter" — statistics computed across many Homes, on the blog and on the species pages. The rules I hold myself to: it's always aggregated across many Homes, never a single one; it's stripped of names, emails, Home IDs, locations, and nicknames; your photos are never part of it; and if a cut of the data is thin enough that it could point at one person, I don't publish that cut. If you'd rather your readings weren't in the aggregate at all, email me and I'll exclude your Home.

Improve the care thresholds. Those same aggregate readings help me correct the per-species numbers the app compares your plants against.

Send you email. Account setup, password resets, billing receipts, and replies to threads you started — all transactional. Plus one short onboarding sequence: at most three emails over your first week, sent only if you signed up and haven't added a plant yet, each with a one-click unsubscribe link, and adding a plant ends it on its own.

If you asked for the printable chart, that's a second and completely separate sequence: the chart itself, then at most three follow-ups over the next eight days. It's the only thing that address is ever used for. Every message carries one-click unsubscribe both in the header your mail app reads and as a link in the footer, signing up for an account ends the sequence, and it never restarts on its own — nothing in it loops back around to try you again. It isn't switched on yet.

Referrals. When the referral program ships it will be one-sided and uncapped: you share a link, and you get credit when someone signs up through it. I'll record that their signup came from your link. You'll see how many people signed up — you won't see who they are, and they won't be told who referred them.

What I don't do

  • I don't sell your data. Not to brokers, not to anyone.
  • I don't send your plant data to ad platforms. What the ad platforms get is: a hashed email, a hashed user ID, an IP address, a user-agent string, click IDs, the fact that a signup, a first plant, a purchase, or a free scan happened, and the purchase amount. They never get your photos, your readings, your notes, your plants' names, or anything Claude told you — including the plant a free scan just identified.
  • I don't use your photos or readings to train any model — mine, Anthropic's, or anyone else's. The aggregate statistics described above are computed with ordinary database queries, not model training, and never include images.
  • I don't run a newsletter. There's no broadcast list and I have never emailed everybody at once about anything. Two sequences exist and they're both described above: three onboarding emails if you sign up, and — only if you asked for the printable chart — the chart plus three follow-ups over eight days. Both are bounded, both end on one click, and both end on their own. After that, nothing unless you write to me.
  • I don't build or buy cross-site profiles. The pixels count conversions from ads I paid for. There's no fingerprinting anywhere, and I've never bought a third-party audience list.
  • I don't read your Home for fun. I can technically see any row in the database — I'm the admin. I look when you ask me to debug something, when a support thread needs it, or when something is broken. Not otherwise.

How long I keep things

What How long
Account, plants, readings, photos until you delete your account
Support email and chat threads 2 years, then purged automatically
Product analytics events up to 24 months
An email address given for the printable chart, and the record of which follow-ups went to it 24 months from the day you gave it
AI scan telemetry (tokens, cost, confidence) 90 days
Rate-limit counters 7 days
Anonymous pre-signup scan photos 30 days
Billing records Stripe's own retention rules apply on their side; I keep enough to reconcile your subscription

Deleting your account removes every row tied to your Home ID — plants, readings, photos, uploads, members, support and chat threads, reviews, scan telemetry, and the record of which emails you were sent. It's a real delete, not an archive with a hidden flag, and I can't recover it afterward. One deliberate exception: the product-analytics events described above aren't deleted, because most of the funnel they belong to is anonymous traffic that was never yours to begin with. Instead your email address and Home ID are stripped off those rows at deletion time, which leaves an anonymous page view that no longer points at anybody.

There's a second exception, and it runs the other way round. If you ever gave me an email address for the printable chart, that row isn't tied to your Home ID — you didn't have one when it was created — so deleting your account doesn't sweep it up. What deletion does instead is mark that row do-not-mail and cut its link to your anonymous browsing trail. I keep the address itself, and I want to be straight about why: the address is the only thing that lets anything recognise you and refuse to send, so throwing it away would mean that the next time anyone typed it into that form, nothing in the system would know you'd already left. It gets purged on the 24-month clock in the table above like any other lead, and in the meantime it is on a do-not-mail list and nothing else.

What you can ask me to do

Email hello@plant-tender.com and I'll:

  • Send you a copy of everything I hold about you and your Home.
  • Correct anything that's wrong.
  • Delete your account and your Home. You don't have to ask me for this one — it's in the app, under Home settings → Danger zone, and it runs the moment you confirm it. If you're a member rather than the owner, the same place removes just you and leaves the household's plants alone. The one case that still comes to me by email: deleting while a Pro subscription is still running. Cancel the subscription first (Home settings → Billing), or email me and I'll do both at once — I won't quietly delete an account out from under live billing.
  • Take your Home's readings out of the published aggregates.
  • Unsubscribe you from the onboarding emails or the printable-chart follow-ups (or use the link in any of them).
  • Answer any question about this page you'd like a human answer to.

Depending on where you live you may have rights under the GDPR, the UK GDPR, or the CCPA — access, correction, deletion, portability, and objection to certain processing. I honor all of those for everyone regardless of where they live, because maintaining two tiers of respect would be worse than just doing the right thing once. I don't sell or "share" personal information in the CCPA's sense, so there's no opt-out to offer there. Where the GDPR asks for a legal basis: running the app and billing you is contract; analytics, conversion reporting, and abuse prevention are legitimate interests; the onboarding emails are legitimate interests with a one-click opt-out on every one; and the printable-chart follow-ups are consent, because the only way onto that list is asking for the chart.

I'm the person who reads that inbox. Usually within a day.

Security, and where your data lives

Everything runs in the United States. Sessions are signed and HttpOnly, passwords are PBKDF2-hashed, every scoped query is filtered by your Home ID so one Home can never read another's rows, and admin endpoints re-check the admin flag against the database on every request rather than trusting the cookie.

I'm one person, not a security department. If something ever leaked, I'd email everyone affected within 72 hours of finding out, tell you what happened and what I got wrong, and fix it in public. If you find a hole, email me — I'd much rather hear it from you than from someone else.

Kids

Plant Tender isn't for children under 13, and I don't knowingly collect data about them. If you're a parent and you think your child signed up, email me and I'll delete the account.

When this page changes

If I change something material — a new third-party service, a new category of data, a change in retention — I'll update the date at the top and email account owners. Cosmetic edits (typos, clearer wording) I'll just make.

This page lives in the same git repository as the app, so its history is the real changelog.

Contact

hello@plant-tender.com — for anything on this page, about your data, or if a sentence here reads like it's trying to sneak something past you. It's me on the other end.

← Home Terms →
Plant Tender — built because my ficus deserved better. Pricing · Meter chart · Meter readings · Which meter? · Blog · Privacy · Terms · Sign in