Privacy Policy for PlantQual

Last Updated: January 6, 2026

IMPORTANT PRIVACY INFORMATION

When you access our Website and use our mobile application PlantQual (the "App"), we automatically collect from your device language settings, IP address, time zone, type and model of a device, device settings, operating system, Internet service provider, mobile carrier, hardware ID, and other unique identifiers (such as IDFA and AAID). We need this data to provide our services, analyze how our customers use the App and Website, and to improve our services.

For improving the App and Website, we may share this data with third parties. Such parties include Google Cloud Platform, OpenAI, and Google Play Services. As a result of sharing this data with third parties we (1) analyze different interactions (what plants our users have identified); (2) improve our plant identification accuracy; (3) provide personalized plant care recommendations.

If you decide to make a purchase or subscribe to a premium plan in the App, we will process your payment information through Google Play Billing or Apple App Store. We will use this data to fulfill your subscription and to provide you with premium features.

Please read our Privacy Policy below to know more about what we do with data (Section 3), what data privacy rights are available to you (Section 6) and who will be the data controller (Section 1). If any questions will remain unanswered, please contact us at privacy@plantqual.com.


PRIVACY POLICY

This Privacy Policy explains what personal data is collected when you use the PlantQual mobile application (the "App"), the website located at: [www.plantqual.app] (the "Website"), the services and products provided through them (together with the App and Website, the "Service"), how such personal data will be used, and shared.

BY USING THE SERVICE, YOU PROMISE US THAT (I) YOU HAVE READ, UNDERSTAND AND AGREE TO THIS PRIVACY POLICY, AND (II) YOU ARE OVER 16 YEARS OF AGE (OR HAVE HAD YOUR PARENT OR GUARDIAN READ AND AGREE TO THIS PRIVACY POLICY FOR YOU). If you do not agree, or are unable to make this promise, you must not use the Service. In such case, you must (a) contact us at privacy@plantqual.com and request deletion of your data; and (b) delete the App and not access or use it.

"GDPR" means the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

"EEA" includes all current member states to the European Union and the European Economic Area.

"Process", in respect of personal data, includes to collect, store, and disclose to others.


TABLE OF CONTENTS

  1. PERSONAL DATA CONTROLLER
  2. CATEGORIES OF PERSONAL DATA WE COLLECT
  3. FOR WHAT PURPOSES WE PROCESS PERSONAL DATA
  4. UNDER WHAT LEGAL BASES WE PROCESS YOUR PERSONAL DATA
  5. WITH WHOM WE SHARE YOUR PERSONAL DATA
  6. HOW YOU CAN EXERCISE YOUR PRIVACY RIGHTS
  7. AGE LIMITATION
  8. INTERNATIONAL DATA TRANSFERS
  9. CHANGES TO THIS PRIVACY POLICY
  10. CALIFORNIA PRIVACY RIGHTS
  11. DATA RETENTION
  12. DATA SECURITY AND PROTECTION MEASURES
  13. HOW "DO NOT TRACK" REQUESTS ARE HANDLED
  14. CONTACT US

1. PERSONAL DATA CONTROLLER

Qualis IT Consulting sp. z o.o. is the data controller for your personal information. Qualis IT Consulting sp. z o.o. is a company registered in Poland.

For questions or concerns about data processing, please contact us at:

Email: privacy@plantqual.com
Or through the App: Settings → Contact Support

For EEA-based users: If you are located in the European Economic Area (EEA), Qualis IT Consulting sp. z o.o., a company registered in Poland, is the data controller responsible for your personal data. We do not currently have a designated Data Protection Officer (DPO) as we do not meet the criteria requiring a DPO under Article 37 of the GDPR. However, you can contact us directly at privacy@plantqual.com for any data protection inquiries.


2. CATEGORIES OF PERSONAL DATA WE COLLECT

We collect data you give us voluntarily (for example, plant notes, care schedules). We also collect data automatically (for example, your IP address, device information).

2.1. Data you give us

Plant Identification Data: - Photos of plants that you take or select for identification - Plant notes and observations you add to your collection - Plant care schedules and reminders you create - Health scores and timeline entries you record

Account and Subscription Data: - If you make a purchase or subscribe to a premium plan, we process your payment information through Google Play Billing or Apple App Store (we do not directly collect or store your payment card details) - Subscription tier and status (Free, Basic, Plus, or Pro) - Identification usage and limits

Communication Data: - If you contact our Support Team, we may collect your email address and other information you provide to fulfill your request

Device Permissions: - Camera Permission: We request access to your device's camera to allow you to take photos of plants directly within the App. Camera access is optional - you can also select photos from your gallery instead. - Storage/Media Permission: We request access to your device's photo gallery (READ_EXTERNAL_STORAGE on Android, Photo Library on iOS) to allow you to select existing photos of plants for identification. This permission is optional - you can use the camera feature instead. - Notification Permission: We request permission to send you notifications about plant care reminders and subscription updates. You can disable notifications at any time in your device settings.

Note: All permissions are optional and can be revoked at any time through your device settings. Revoking permissions may limit certain features of the App.

2.2. Data provided to us by third parties

Payment Processors: - When you make a purchase through Google Play or Apple App Store, we receive transaction information (subscription status, purchase date, product ID) - We do not receive or store your payment card details - these are handled entirely by Google Play or Apple App Store

2.3. Data we collect automatically

2.3.1. Device and Location data

We collect data from your device. Examples of such data include: - Language settings - IP address - Time zone - Type and model of a device - Device settings - Operating system - Internet service provider - Mobile carrier - Hardware ID - Advertising identifiers (IDFA on iOS, AAID on Android)

Note: We do not collect precise geolocation data. We may use your time zone and general location (country/region) to provide better plant care recommendations based on climate and daylight hours.

2.3.2. Usage data

We record how you interact with our Service. For example, we log: - What screens you have viewed - How often you access the App - How long you use the App - Which features you use most frequently - Plant identification requests and results - Error reports and crash logs

2.3.3. Advertising IDs

We collect your Apple Identifier for Advertising ("IDFA") or Google Advertising ID ("AAID") (depending on the operating system of your device) when you access our App. You can typically reset these numbers through the settings of your device's operating system (but we do not control this).

Note: We do not use advertising IDs for personalized advertising. We use them only for analytics and service improvement purposes.

2.3.4. Image Processing Data

When you submit a plant photo for identification: - The image is temporarily processed by our secure API service - Images are sent to OpenAI API for plant identification - Images are not stored permanently on our servers after processing - Only identification results (plant name, confidence score, care recommendations) are stored locally on your device


3. FOR WHAT PURPOSES WE PROCESS YOUR PERSONAL DATA

Legal basis for processing: For EEA-based users, we process your personal data based on the legal bases set out in Section 4 below. For non-EEA users, we process your data in accordance with applicable local laws and this Privacy Policy.

We process your personal data:

3.1. To provide our Service

This includes: - Enabling you to use the Service in a seamless manner - Providing plant identification services using AI technology - Delivering plant care recommendations and schedules - Sending care reminders and notifications - Preventing or addressing Service errors or technical issues

Service Providers: - Google Cloud Platform: We use Google Cloud Platform for hosting our backend services and API endpoints - OpenAI API: We use OpenAI's API to provide AI-powered plant identification services. Images are sent to OpenAI for processing but are not stored by OpenAI after processing

3.2. To customize your experience

We process your personal data to: - Adjust the content of the Service and make offers tailored to your personal preferences - Create personalized plant care schedules for you - Provide recommendations based on your plant collection and care history - Remember your preferences and settings

3.3. To provide you with customer support

We process your personal data to: - Respond to your requests for technical support - Provide Service information - Address any other communication you initiate - Send you emails about, for example, the performance of our Service, payment transactions, notices regarding our Terms and Conditions of Use or this Privacy Policy

3.4. To communicate with you regarding your use of our Service

We communicate with you, for example, by: - Push notifications (plant care reminders, subscription updates) - In-app notifications - Email (if you provide your email address)

These may include: - Information about the Service - Care reminders for your plants - Subscription status updates - Special offers (you can opt out)

To opt out of receiving notifications: - iOS: Settings → Notifications → PlantQual - Android: Settings → Apps → PlantQual → Notifications

3.5. To research and analyze your use of the Service

This helps us to: - Better understand our business - Analyze our operations - Maintain, improve, innovate, plan, design, and develop the App and our new products - Use such data for statistical analysis purposes - Test and improve our offers - Better understand what categories of users use our App - Improve plant identification accuracy

Service Providers: - Google Play Services: We may use Google Play Services for analytics and crash reporting (if applicable) - Google Cloud Platform: We use Google Cloud Platform for logging and analytics

3.6. To send you marketing communications

We process your personal data for our marketing campaigns. As a result, you may receive information about our products, such as: - Special offers - New features available in the App - Subscription promotions

To opt out of receiving marketing communications: - Unsubscribe following instructions in the footer of marketing emails - Contact us at privacy@plantqual.com - Adjust your notification settings in the App

3.7. To process your payments

We provide paid products and/or services within the Service. For this purpose, we use third-party services for payment processing:

Important: We will not store or collect your payment card details ourselves. This information is provided directly to Google Play or Apple App Store, and we only receive confirmation of successful transactions.

3.8. To enforce our Terms and Conditions of Use and to prevent and combat fraud

We use personal data to: - Enforce our agreements and contractual commitments - Detect, prevent, and combat fraud - Prevent unauthorized use of the Service - Ensure compliance with subscription limits

As a result of such processing, we may share your information with others, including law enforcement agencies (in particular, if a dispute arises in connection with our Terms and Conditions of Use).

We may process, use, or share your data when the law requires it, in particular, if a law enforcement agency requests your data by available legal means.


(Applies only to EEA-based users)

In this section, we are letting you know what legal basis we use for each particular purpose of processing. For more information on a particular purpose, please refer to Section 3.

We process your personal data under the following legal bases:

We process your personal data based on your consent when you: - Provide us with optional information (such as plant notes) - Subscribe to marketing communications - Allow us to send push notifications

You can withdraw your consent at any time by contacting us at privacy@plantqual.com or adjusting your App settings.

4.2. To perform our contract with you

Under this legal basis we: - Provide our Service (in accordance with our Terms and Conditions of Use) - Customize your experience - Provide you with customer support - Communicate with you regarding your use of our Service - Process your payments - Fulfill your subscription and provide premium features

4.3. For our (or others') legitimate interests

We rely on legitimate interests:

To communicate with you regarding your use of our Service: - The legitimate interest we rely on for this purpose is our interest to encourage you to use our Service more often and provide you with relevant information about your plants

To research and analyze your use of the Service: - Our legitimate interest for this purpose is our interest in improving our Service so that we understand users' preferences and are able to provide you with a better experience

To send you marketing communications: - The legitimate interest we rely on for this processing is our interest to promote our Service, including new products and special offers, in a measured and appropriate way

To process your payments: - The legitimate interest we rely on for this processing is our interest to make the Service available for you through easy and effective payment process

To enforce our Terms and Conditions of Use and to prevent and combat fraud: - Our legitimate interests for this purpose are enforcing our legal rights, preventing and addressing fraud and unauthorized use of the Service, non-compliance with our Terms and Conditions of Use

We process your personal data to comply with legal obligations, such as: - Responding to lawful requests from law enforcement agencies - Complying with tax and accounting requirements - Maintaining records as required by law


5. WITH WHOM WE SHARE YOUR PERSONAL DATA

We share information with third parties that help us operate, provide, improve, integrate, customize, support, and market our Service. We may share some sets of personal data, in particular, for purposes and with parties indicated in Section 3 of this Privacy Policy.

The types of third parties we share information with include, in particular:

5.1. Service providers

We share personal data with third parties that we hire to provide services or perform business functions on our behalf, based on our instructions. We may share your personal information with the following types of service providers:

Cloud storage and hosting providers: - Google Cloud Platform: We use Google Cloud Platform for hosting our backend services, API endpoints, and data storage

AI and machine learning providers: - OpenAI: We use OpenAI's API to provide plant identification services. When you submit a plant photo, it is sent to OpenAI for processing. OpenAI does not store your images after processing

Payment service providers: - Google Play Billing: For processing payments on Android devices - Apple App Store: For processing payments on iOS devices

Analytics providers: - Google Play Services: For app analytics and crash reporting (if applicable) - Google Cloud Platform: For logging and service analytics

5.2. Law enforcement agencies and other public authorities

We may use and disclose personal data to enforce our Terms and Conditions of Use, to protect our rights, privacy, safety, or property, and/or that of our affiliates, you or others, and to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, or in other cases provided for by law.

5.3. Third parties as part of a merger or acquisition

As we develop our business, we may buy or sell assets or business offerings. Customers' information is generally one of the transferred business assets in these types of transactions. We may also share such information with any affiliated entity (e.g. parent company or subsidiary) and may transfer such information in the course of a corporate transaction, such as the sale of our business, a divestiture, merger, consolidation, or asset sale, or in the unlikely event of bankruptcy.


6. HOW YOU CAN EXERCISE YOUR PRIVACY RIGHTS

To be in control of your personal data, you have the following rights:

6.1. Accessing / reviewing / updating / correcting your personal data

You may: - Review, edit, or change the personal data that you had previously provided in the App through your account settings - Request a copy of your personal data collected during your use of the App by contacting us at privacy@plantqual.com

6.2. Deleting your personal data

You can request erasure of your personal data by: - Using the "Clear All Data" feature in the App (Settings → Data → Clear All Data) - Contacting us at privacy@plantqual.com

When you request deletion of your personal data, we will use reasonable efforts to honor your request. In some cases, we may be legally required to keep some of the data for a certain time; in such event, we will fulfill your request after we have complied with our obligations.

Note: Clearing all data in the App will delete: - All plant identifications - All plant notes - All collections - All care tasks - All timeline entries - All wishlist entries

This action cannot be undone.

6.3. Objecting to or restricting the use of your personal data

You can ask us to stop using all or some of your personal data or limit our use thereof by: - Contacting us at privacy@plantqual.com - Adjusting your App settings (notifications, analytics)

6.4. Data portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format. You can export your data using the "Export Data" feature in the App (Settings → Data → Export Data).

6.5. Additional information for EEA-based users

If you are based in the EEA, you have the following additional rights under the GDPR:

Right to Access (Article 15 GDPR): - You have the right to obtain confirmation as to whether or not personal data concerning you is being processed - You have the right to access your personal data and receive a copy of the data we hold about you - You can request this by contacting us at privacy@plantqual.com

Right to Rectification (Article 16 GDPR): - You have the right to have inaccurate personal data corrected - You can update your data directly in the App settings or contact us at privacy@plantqual.com

Right to Erasure / "Right to be Forgotten" (Article 17 GDPR): - You have the right to request deletion of your personal data - We will comply with your request unless we have a legal obligation to retain the data - You can request deletion using the "Clear All Data" feature in the App or by contacting us

Right to Restrict Processing (Article 18 GDPR): - You have the right to request restriction of processing of your personal data - This means we will limit how we use your data while your request is being considered - Contact us at privacy@plantqual.com to exercise this right

Right to Data Portability (Article 20 GDPR): - You have the right to receive your personal data in a structured, commonly used, and machine-readable format - You can export your data using the "Export Data" feature in the App (Settings → Data → Export Data) - You have the right to transmit this data to another service provider

Right to Object (Article 21 GDPR): - You have the right to object to processing of your personal data based on legitimate interests - You can object to direct marketing at any time - Contact us at privacy@plantqual.com to exercise this right

Right to Withdraw Consent (Article 7 GDPR): - Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time - Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal - You can withdraw consent by adjusting your App settings or contacting us

Right to Lodge a Complaint (Article 77 GDPR): - You have the right to lodge a complaint with a supervisory authority in your country of residence, place of work, or place of the alleged infringement - Since our company is registered in Poland, the supervisory authority for our data processing activities is: Urząd Ochrony Danych Osobowych (UODO) - Address: ul. Stawki 2, 00-193 Warszawa, Poland - Website: https://uodo.gov.pl - Email: kancelaria@uodo.gov.pl - Phone: +48 22 531 03 00 - However, if you are located in another EEA country, you may also lodge a complaint with your local supervisory authority. You can find your local supervisory authority here: https://edpb.europa.eu/about-edpb/board/members_en

Automated Decision-Making and Profiling: - We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you - Our plant identification service uses AI, but the results are recommendations only and do not constitute automated decision-making under GDPR Article 22

Response Time: - We will respond to your GDPR requests within one month of receipt (as required by GDPR Article 12(3)) - If your request is complex, we may extend this period by a further two months, and we will inform you of this extension within one month of receipt of your request, explaining why the extension is necessary (as required by GDPR Article 12(3)) - We will provide information free of charge, except where requests are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request (as permitted by GDPR Article 12(5))


7. AGE LIMITATION

We do not knowingly process personal data from persons under 16 years of age. If you learn that anyone younger than 16 has provided us with personal data, please contact us at privacy@plantqual.com.

If you are under 16, you must have your parent or guardian read and agree to this Privacy Policy for you before using the Service.


8. INTERNATIONAL DATA TRANSFERS

We may transfer personal data to countries other than the country in which the data was originally collected in order to provide the Service set forth in the Terms and Conditions of Use and for purposes indicated in this Privacy Policy.

Our Service Providers: - Google Cloud Platform: Data may be stored and processed in various Google Cloud regions - OpenAI: Plant images are sent to OpenAI's servers (which may be located outside your country) for processing, but are not stored by OpenAI after processing

If these countries do not have the same data protection laws as the country in which you initially provided the information, we deploy special safeguards.

For EEA-based users: If we transfer personal data originating from the EEA to countries with not adequate level of data protection, we use one of the following legal bases:

Current Data Transfers: - Google Cloud Platform: Data may be stored in Google Cloud regions, which may include regions outside the EEA. Google Cloud Platform is certified under various data protection frameworks and uses Standard Contractual Clauses where applicable.

If you have questions about our international data transfers, please contact us at privacy@plantqual.com.


9. CHANGES TO THIS PRIVACY POLICY

We may modify this Privacy Policy from time to time. If we decide to make material changes to this Privacy Policy, you will be notified by available means such as: - Email (if you have provided your email address) - In-app notification - Update to the "Last Updated" date at the top of this Privacy Policy

By continuing to access or use the Service after those changes become effective, you agree to be bound by the revised Privacy Policy.


10. CALIFORNIA PRIVACY RIGHTS

California's Shine the Light law gives California residents the right to ask companies once a year what personal information they share with third parties for those third parties' direct marketing purposes.

To obtain this information from us, please send an email message to privacy@plantqual.com which includes "Request for California Privacy Information" on the subject line and your state of residence and email address in the body of your message. If you are a California resident, we will provide the requested information to you at your email address in response.

California Consumer Privacy Act (CCPA) Rights:

If you are a California resident, you have the following rights: - Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell - Right to Delete: You have the right to request that we delete your personal information - Right to Opt-Out: You have the right to opt-out of the sale of your personal information (we do not sell your personal information) - Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

To exercise these rights, please contact us at privacy@plantqual.com.


11. DATA RETENTION

We will store your personal data for as long as it is reasonably necessary for achieving the purposes set forth in this Privacy Policy (including providing the Service to you). We will also retain and use your personal data as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

Specific retention periods: - Plant identification images: Not stored permanently - images are deleted immediately after processing (typically within seconds or minutes) - Plant collection data: Stored locally on your device until you delete it or clear all data. We do not store this data on our servers unless you explicitly enable cloud sync (if available in future versions) - Subscription data: Retained for the duration of your subscription and for up to 7 years after termination as required by law for accounting and tax purposes - Analytics data: Aggregated and anonymized data may be retained indefinitely for service improvement. Personal identifiers are removed from analytics data - Support communications: Retained for as long as necessary to resolve your inquiry and for up to 3 years after resolution for quality assurance purposes - IP addresses and device identifiers: Retained for up to 12 months for security and fraud prevention purposes - Error logs and crash reports: Retained for up to 90 days for debugging and service improvement

For EEA-based users: In accordance with GDPR Article 5(1)(e) (storage limitation principle), we will: - Not keep personal data in a form which permits identification of data subjects for longer than is necessary - Delete or anonymize personal data once the retention period expires - Inform you of the retention period or criteria used to determine it (as set out above)

Deletion upon request: You can request deletion of your personal data at any time by: - Using the "Clear All Data" feature in the App - Contacting us at privacy@plantqual.com

We will delete your data within 30 days of your request, unless we have a legal obligation to retain it.


12. DATA SECURITY AND PROTECTION MEASURES

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, in accordance with GDPR Article 32.

Technical Measures: - Encryption: All data transmitted between the App and our servers is encrypted using HTTPS/TLS - API Security: All API requests require authentication using secure API keys - Secure Storage: Data stored on our servers is protected by Google Cloud Platform's security measures - Image Processing: Plant images are processed securely and deleted immediately after processing - Access Controls: Access to personal data is restricted to authorized personnel only - Regular Security Updates: We keep our systems and dependencies up to date with security patches

Organizational Measures: - Staff Training: Our personnel are trained on data protection and privacy requirements - Data Minimization: We only collect and process data that is necessary for the purposes stated in this Privacy Policy - Incident Response: We have procedures in place to detect, report, and investigate data breaches - Regular Audits: We conduct regular reviews of our data processing activities

For EEA-based users: In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, in accordance with GDPR Articles 33 and 34.

Your Role in Data Security: - Keep your device and App updated - Use strong passwords or biometric authentication on your device - Do not share your device with unauthorized persons - Report any security concerns to us at privacy@plantqual.com


13. HOW "DO NOT TRACK" REQUESTS ARE HANDLED

Except as otherwise stipulated in this Privacy Policy, this App and Website do not support "Do Not Track" requests. To determine whether any of the third-party services it uses honor the "Do Not Track" requests, please read their privacy policies: - Google Privacy Policy - OpenAI Privacy Policy


14. CONTACT US

You may contact us at any time for details regarding this Privacy Policy and its previous versions. For any questions concerning your account or your personal data, please contact us at:

Email: privacy@plantqual.com

Or through the App: Settings → Contact Support

Data Controller: Qualis IT Consulting sp. z o.o.
Registered in: Poland


Effective as of: January 1, 2026

Last Updated: January 6, 2026

Last Updated: Last Updated: