Privacy Policy
Last updated: May 11, 2026
Effective date: December 29, 2020
Developer: Mehmet Canker (CoddyKit) ("we", "us", or "our")
This Privacy Policy applies to all mobile applications developed by Mehmet Canker, including but not limited to Coddy (coding education apps), Chibify (AI-powered image transformation app), and SafeChat AI (also published as KidsChat — a kid-safe AI chat app in Apple’s Kids Category and Google Play’s Designed for Families program). By using any of our applications, you agree to the collection and use of information as described below.
Different apps process different data. Section 12 of this policy lists the third-party services that apply to each individual app. Services that are listed in the general “Third-Party Services” section below (such as Firebase, AdMob, or Facebook SDK) are not used in our apps that target children — see Section 12.3 for SafeChat AI / KidsChat specifically.
1. Information We Collect
We may collect the following types of information when you use our applications:
- Account Information: Email address, name (when provided via third-party sign-in such as Google, Apple, or Facebook). SafeChat AI / KidsChat does not use third-party sign-in — see Section 12.3.
- Device Information: An anonymous device identifier (UUID) is generated locally on your device to manage your account, preferences, and subscription status. This identifier is not linked to your personal identity and is not shared with any third party for advertising purposes.
- Usage Data: In our non-kids apps we collect anonymized analytics about feature usage and crash reports. SafeChat AI / KidsChat does not collect any analytics or crash data — see Section 12.3.
- Photos and Images: In apps that offer image features (Chibify, and optionally in SafeChat AI for visual questions), you may submit photographs from your camera or photo library. These images are processed solely to generate the result you requested and are not retained on our servers after processing.
- Subscription Data: Payment and subscription information is collected through the Apple App Store and Google Play Store. We do not directly collect or store your payment card details.
- Chat Content (SafeChat AI / KidsChat only): The text messages and any optional photo your child sends through the chat are forwarded to our AI provider in order to generate a reply. See Section 2 for full details and Section 12.3 for what is specific to SafeChat AI.
2. AI-Powered Features and Third-Party AI Services
Some of our applications use artificial intelligence (AI) to provide core features. This section explains how your data is processed when you use these features.
2.1 What Data Is Sent to AI Services
When you use an AI-powered feature (e.g., image transformation, code generation, AI-assisted learning, kid-safe AI chat, or interview preparation), the following data may be sent to our AI service providers:
- Content you provide: The photo, text message, or code snippet you submit for processing.
- Style, mode, or age-group selection: The transformation style, processing mode, or (for SafeChat AI) the age group you have configured. SafeChat AI sends an age-band hint (e.g. “6-7”, “8-9”, “10-11”, “12-13”) so the model can return age-appropriate replies. We do not send the child’s exact birth date.
We do NOT send your name, email, account ID, contacts, location, advertising identifier, or device identifier to the AI service providers as part of any processing request.
2.2 Who Processes Your Data
We work with the following AI service providers to deliver AI-powered features. Each provider processes data in accordance with its own privacy policy:
- OpenRouter (used by SafeChat AI / KidsChat for text): An AI request-routing platform that forwards text requests to the underlying language model. Submitted message text is sent to OpenRouter’s API and is subject to the OpenRouter Privacy Policy (https://openrouter.ai/privacy).
- MiniMax — model M1 (used by SafeChat AI / KidsChat for text, via OpenRouter): The language model that generates text replies. Submitted text is processed by MiniMax under MiniMax’s Privacy Policy (https://www.minimax.io/privacy-policy).
- xAI (Grok) — used in Chibify: Used for image generation and transformation. Your submitted photos are sent to xAI API for processing and are subject to the xAI Privacy Policy (https://x.ai/legal/privacy).
- OpenAI — used in Coddy and other non-kids apps: Used for text generation, code assistance, and educational features. Submitted content is subject to the OpenAI Privacy Policy (https://openai.com/privacy).
- Google — Gemini Flash (used by SafeChat AI / KidsChat for image analysis, and by Coddy and other non-kids apps for content generation): When a child attaches a photo to ask a visual question in SafeChat AI, the image is sent directly to Google’s Gemini Flash API for analysis. Submitted content is subject to the Google Privacy Policy (https://policies.google.com/privacy) and Google’s generative AI terms.
- OpenAI — GPT-4o-mini (used by Sobriety Tracker & Sober Days, via OpenRouter, for the optional AI craving coach chat): When you choose to use the in-app AI craving coach, the message you type is routed through OpenRouter (https://openrouter.ai/privacy) to OpenAI’s GPT-4o-mini model to generate a supportive reply. Submitted content is subject to the OpenAI Privacy Policy (https://openai.com/privacy). See Section 12.5 for full details.
We may update the list of AI service providers from time to time. Any changes will be reflected in this Privacy Policy and, for SafeChat AI / KidsChat, will require a renewed in-app parental consent before any data is sent to the new provider.
2.3 How AI Processing Works
- Your submitted content (photo, text, or code) is sent securely over HTTPS/TLS to the selected AI provider’s API.
- The AI provider processes your content and returns the generated result.
- No biometric data extraction, facial recognition, or facial identification is performed. No facial geometry, faceprint, or biometric template is created or stored by us or our AI providers.
- The AI providers may temporarily retain the request for service-provision and abuse-prevention purposes in accordance with their respective retention policies. We do not retain the raw request body on our servers after the response is returned.
2.4 Your Consent
Before any data is sent to a third-party AI service for the first time, our application will:
- Clearly inform you what data will be sent;
- Identify the AI service provider(s) involved;
- Ask for your explicit consent before proceeding.
For SafeChat AI / KidsChat, this consent is collected on a dedicated full-screen disclosure presented before any chat is possible, and is gated behind a parental verification step (a simple math/logic question that a young child cannot reliably answer alone). The consent decision is stored locally on the device. You may revoke consent at any time by deleting the app or by tapping “Reset consent” in Parental Controls; revoking consent disables all AI features.
3. Third-Party Services
Our applications use the following third-party services. Not every service is used in every app. See Section 12 for a per-app breakdown:
- Firebase Analytics and Crashlytics (https://firebase.google.com/policies/analytics) — Anonymized usage analytics and crash reporting. Not used in SafeChat AI / KidsChat.
- RevenueCat (https://www.revenuecat.com/privacy) — Subscription and in-app purchase management. RevenueCat receives an anonymous device-generated identifier and the App Store/Play Store transaction; it does not receive your name, email, or chat content.
- AWS S3 / CloudFront (https://aws.amazon.com/privacy/) — Cloud storage for app bundle delivery (over-the-air updates) and, in apps that produce them, user-generated images.
- Supabase (https://supabase.com/privacy) — Database and authentication services for user accounts, app data, and serverless API functions. For SafeChat AI / KidsChat, the only personally identifying data Supabase stores is the anonymous device UUID and an optional parent email if the parent enables daily reports.
- Google AdMob (https://support.google.com/admob/answer/6128543) — Advertising. Not used in SafeChat AI / KidsChat or in any other app we publish in a kids/family category.
- Google Play Services (https://www.google.com/policies/privacy/) — Core Android services.
- Facebook SDK (https://www.facebook.com/about/privacy/update/printable) — Authentication and social features. Not used in SafeChat AI / KidsChat.
4. Data Retention
- Original photos submitted for AI processing are temporarily held in server memory during the generation process and are not permanently stored on our servers after the result is generated.
- Generated content (in apps that produce shareable output, e.g. transformed images) is stored in cloud storage and is accessible to you. You may request deletion at any time.
- Chat messages (SafeChat AI / KidsChat): The most recent chat history is stored in our database for up to 30 days so the child can return to a recent conversation, after which it is automatically deleted. Parents can clear the history at any time from Parental Controls. The raw request body sent to the AI provider is not retained on our servers after the response is returned.
- Account data is retained for as long as your account is active. Upon account deletion, your personal data is removed within 30 days.
- Analytics data (in non-kids apps only) is anonymized and retained for up to 14 months for service-improvement purposes.
5. Data Sharing
We do not sell your personal data. We share data only with:
- AI service providers, as described in Section 2, with your explicit consent;
- Third-party services listed in Section 3, solely to provide the app functionality and limited to what is described in Section 12 for the specific app you are using;
- Law enforcement, if required by applicable law.
6. Data Security
We use industry-standard security measures to protect your data, including encrypted data transmission (HTTPS/TLS), secure cloud infrastructure, and access controls. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
7. Children’s Privacy
Most of our apps (Coddy, Chibify, etc.) are not directed to children under the age of 13 and we do not knowingly collect personal information from children under 13 in those apps.
SafeChat AI (also published as KidsChat) is the exception: it is specifically designed for children aged 6–13 and is published in Apple’s Kids Category. For SafeChat AI we have engineered the app to be compliant with the U.S. Children’s Online Privacy Protection Act (COPPA), the U.K. Age-Appropriate Design Code, and Apple’s Kids Category requirements. The full data practices for SafeChat AI are described in Section 12.3 below; the highlights are:
- No third-party advertising (no AdMob, no ad networks).
- No third-party analytics (no Firebase Analytics, no Crashlytics, no Facebook SDK).
- No social-login or third-party sign-in flows.
- No tracking across other apps and websites; the app does not request the iOS App Tracking Transparency permission.
- An anonymous device-generated UUID is the only persistent identifier; no name, email, phone number, or precise location is required to use the app.
- An optional parent email may be entered by a parent (after passing a parental gate) to receive daily activity reports. This email is used solely for that purpose and is never shared with advertisers or AI providers.
- All AI features require explicit, parent-gated consent before any data leaves the device.
Parents who believe their child has provided us with personal information they did not authorize may contact us at the email address in Section 11 and we will delete it promptly.
8. Your Rights
You have the right to:
- Access the personal data we hold about you;
- Request correction or deletion of your personal data;
- Withdraw consent for data processing at any time;
- Request an export of your data.
To exercise any of these rights, use the Delete My Account feature within the app or contact us at the email address below.
9. App Tracking Transparency (iOS)
On iOS devices, our non-kids apps may request permission to track your activity across apps and websites owned by other companies. This permission is optional. SafeChat AI / KidsChat does not request and does not use the App Tracking Transparency permission and does not track users across other apps or websites.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last updated” date. Material changes that affect SafeChat AI / KidsChat (for example, adding a new AI provider) will require a renewed in-app parental consent before they take effect for that app.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
- Email: coddy@coddykit.com
- Developer: Mehmet Canker (CoddyKit)
12. Per-App Data Practices
This section lists, on a per-app basis, exactly which third-party services receive data and what data they receive. If a service is not listed for a given app, that service is not used in that app.
12.1 Coddy (coding-education apps)
- Firebase Analytics & Crashlytics — anonymized event & crash data.
- RevenueCat — subscription state, anonymous device identifier.
- Supabase — account data, lesson progress.
- OpenAI / Google Gemini — AI-assisted learning content (with consent).
- Google AdMob, Facebook SDK — in some Coddy variants only; never in any kids/family-category build.
12.2 Chibify (AI image transformation)
- Firebase Analytics & Crashlytics — anonymized event & crash data.
- RevenueCat — subscription state, anonymous device identifier.
- AWS S3 / CloudFront — storage of generated images.
- Supabase — account data, generation history.
- xAI (Grok) — image-generation requests (with consent).
12.3 SafeChat AI / KidsChat (Apple Kids Category, ages 6–13)
Identifiers and account data we store:
- An anonymous device-generated UUID (created locally on the device).
- The age-band selected by the parent during onboarding (one of: 6-7, 8-9, 10-11, 12-13).
- An optional parent email, only if the parent voluntarily enters one in Parental Controls to receive daily activity reports.
- An optional 4-digit parental PIN (stored hashed, used only to gate Parental Controls inside the app).
- Recent chat history (up to 30 days; parent-clearable from Parental Controls).
Data sent to third parties:
- OpenRouter (AI router, text only) — receives: the chat message text and the age-band hint. Receives nothing else. Used only to forward the text request to MiniMax. No photos are sent to OpenRouter.
- MiniMax model M1 (text AI model, via OpenRouter) — receives the same text payload as OpenRouter; generates the text reply. Used only to generate text replies.
- Google — Gemini Flash (image AI model, direct) — when (and only when) the child attaches a photo for a visual question, the photo and the chat message text are sent directly to Google’s Gemini Flash API, together with the age-band hint. Used only to generate the reply for that photo. No photo is ever stored by us after the reply is returned.
- RevenueCat — receives: the anonymous device-generated UUID and the App Store / Play Store subscription transaction. Used only to determine whether the device has an active Pro subscription.
- Supabase — receives: anonymous device UUID, age-band, optional parent email (if entered), recent chat history. Used only to operate the app’s backend (login, daily-message-quota counter, daily-report email).
- AWS S3 / CloudFront — serves the over-the-air JavaScript bundle to the app. Receives no user data.
Data NOT collected and NOT sent in SafeChat AI / KidsChat:
- No name, real birth date, phone number, address, or precise location.
- No advertising identifier (IDFA / GAID); the app does not request App Tracking Transparency.
- No third-party analytics (no Firebase Analytics, no Crashlytics, no Facebook SDK, no Mixpanel, no Amplitude, etc.).
- No third-party advertising (no AdMob, no ad networks of any kind).
- No social login (no Google Sign-In, no Apple Sign-In with name, no Facebook Login).
- No push-tracking SDKs.
Daily message limit: Free users are limited to 10 AI messages per day; the count is stored on our server keyed only to the anonymous device UUID. Pro users have unlimited messages. The limit is reset daily and no message content is shared with advertisers or used for behavioural profiling.
12.4 InterviewAce AI (interview preparation)
- Firebase Analytics & Crashlytics — anonymized event & crash data.
- RevenueCat — subscription state, anonymous device identifier.
- Supabase — guest account data, saved resumes, job targets and interview session history.
- OpenRouter — routes AI requests to underlying model providers (primarily Google Gemini, with OpenAI as a fallback). The following content is sent to generate your analysis, scores, questions and feedback: your resume text, job descriptions, your interview answers (including voice‑to‑text transcripts) and the company names you research. This content is sent only after you grant in-app consent, is used solely to produce your results, is not used to train third-party models, and is never sold or shared with advertisers or data brokers.
- Google AdMob — advertising to users who are not subscribed to Pro, including opt-in rewarded ads. Detailed below.
Advertising. This app shows ads to users who are not subscribed to Pro.
- Google AdMob. Banner ads appear on the Progress tab, the Company Research tab, the Job list, the Resume list and the Story Bank. A full-screen ad may appear at two moments — when you leave an interview feedback report, and after your third company research of the day — never more than one every few minutes; one of our own cross-promotion ads is shown first, and a Google ad only once ours have been used. Google receives the data described in its own advertising policies, which can include a device advertising identifier, your IP address, and coarse information about the ad request. We never send Google your resume, your interview answers, or anything else you have written in the app.
- Rewarded ads, only if you choose to watch one. When you have used up your free mock interviews for the day, the Practice tab offers you the option to watch a video ad in exchange for one extra interview that day. Nothing is shown unless you tap it. Google confirms to our server that the ad was watched; your account identifier is passed to Google for that confirmation and for nothing else.
- Our own cross-promotion ads. Some ads are for other CoddyApps apps rather than a third party; the banner on the Home tab is one of these. These are served by us. To count them and to avoid showing you the same one repeatedly, we store a random identifier generated on this device the first time the app runs — it is not your advertising identifier and it is not your account — together with which app was promoted, the ad format, and, if you tap one, your platform and device model. This never includes anything you have entered in the app.
- Pro removes the Google AdMob banners and the full-screen ads, and the rewarded ad is never offered to a Pro subscriber. Pro subscribers may still see the cross-promotion banner for our own other apps on the Home tab.
App Tracking Transparency (iOS). Because this app shows ads, on iOS it asks your permission to use a tracking identifier before the ad SDK starts. If you allow it, your device advertising identifier (IDFA) may be used to personalize the ads you see; if you decline, you still see ads, but non-personalized ones. You can change this at any time in the iOS Settings app.
We do not use a Facebook or Meta advertising SDK in this app, and we send no data to Meta.
12.5 Sobriety Tracker & Sober Days (sobriety tracking with optional AI craving coach)
- Firebase Analytics & Crashlytics — anonymized event & crash data.
- RevenueCat — subscription state, anonymous device identifier.
- Supabase — account data only: your display name, your email address, and whether your subscription is active. Your sober-day counters, your reasons list, your journal entries, your urge log and your relapse log are stored only in this app on your phone; they are never uploaded to our servers.
- Google AdMob — advertising to users who are not subscribed to Pro: banner ads, and one full-screen ad after you save a journal entry. Detailed below.
Advertising. This app shows ads to users who are not subscribed to Pro.
- Google AdMob. Banner ads appear on the Progress tab, the Settings tab, and the Reasons list. A single full-screen ad may also appear after you save a journal entry; that one is one of our own cross-promotion ads first, and a Google ad once our own have been shown. Google receives the data described in its own advertising policies, which can include a device advertising identifier, your IP address, and coarse information about the ad request. On iOS the app asks for your permission before any tracking identifier is used; if you decline, you still see ads, but non-personalized ones. We never send Google anything you have written in the app.
- Our own cross-promotion ads. Some ads are for other CoddyApps apps rather than a third party. These are served by us. To count them and to avoid showing you the same one repeatedly, we store a random identifier generated on this device the first time the app runs — it is not your advertising identifier and it is not your account — together with which app was promoted, the ad format, and, if you tap one, your platform and device model. This never includes anything you have entered in the app.
- Pro removes all Google AdMob advertising. Pro subscribers may still see one small cross-promotion banner for our own other apps.
We do not use a Facebook or Meta advertising SDK in this app, and we send no data to Meta.
AI craving coach (optional feature): The app includes an optional “AI craving coach” chat. Before this feature can be used, and before any data leaves the device, the app shows an explicit in-app consent screen. If you tap “I agree — send my messages,” the following happens:
- What is sent: only the message you type into that chat, plus the app’s display language.
- What is never sent: your name, email, sober-day streak, journal entries, reasons, relapse log, or any other data stored in the app.
- Who receives it: OpenRouter (https://openrouter.ai/privacy), which routes the message to OpenAI’s GPT-4o-mini model (https://openai.com/privacy) to generate the reply.
- Retention: the conversation is not stored on our servers after the reply is shown and is never used to train AI models.
You can decline (“Not now”) and keep using every other feature of the app. Consent can be withdrawn at any time in Settings → AI craving coach; no further messages are sent once it is withdrawn.
The craving coach uses more than one model. OpenRouter normally routes your message to OpenAI’s GPT-4o-mini; a backup model is used if that one is briefly unavailable, and an Anthropic Claude model is used when your message needs a safety-focused reply.
A second, separate AI feature: the Weekly Recovery Brief. The paragraphs above describe the craving coach only. The app also offers an optional Weekly Recovery Brief, and it is asked for separately — agreeing to the craving coach does not turn it on, and either one can be withdrawn on its own in Settings. For the brief we transmit only five numbers covering the past seven days — how long your current streak is, how many days you were active, how many urges you logged, how many of those you resisted, and how many journal entries you wrote — plus your app language. Your journal text, your reasons and your coach conversation are never included. The numbers go to OpenRouter in the same way, which routes them to Google Gemini Flash Lite, or to OpenAI’s GPT-4o-mini if that model is unavailable. We do not keep the numbers or the brief on our servers once it has been shown to you.
12.6 AnatoMe (3D anatomy learning)
- Firebase Analytics & Crashlytics — anonymized event & crash data.
- RevenueCat — subscription state, anonymous device identifier.
- Supabase — account data, learning progress, exam answers and lab-run records, AI usage counters.
- Google AdMob — advertising to free users, including rewarded ads that unlock extra AI explanations.
- OpenRouter — AI tutor requests (with consent). Detailed below.
AI tutor (optional feature). AnatoMe has three AI features: Explain, the Quick check follow-up question, and AI practice questions (Pro). Before any of them can run, and before anything leaves the device, the app shows an explicit in-app disclosure screen. Nothing is sent unless you accept it. If you decline, every other part of the app — the 3D body, the lessons, the pathway puzzles and the bundled exam sets — keeps working exactly as before.
What is sent, feature by feature:
- Explain — a plain-language description of the build currently on your workbench, assembled by the app from a fixed list of structure, slot and system names: which structure you have placed in which slot, which are still unplaced, which are not in their usual position, and the target system. Plus the title of the lesson you are in (or “Lab” when you use the Playground). This description is generated by the app — there is no free-text box on this screen, so nothing you type is included.
- Quick check (the one follow-up question, only if you tap it) — everything Explain sends, plus two things: how many times you have run this exact build, and the tutor’s own previous explanation of it.
- AI practice questions (Pro) — the title of the exam set you opened, and the wording of up to 8 of that set’s own questions. These questions are content we ship inside the app; nothing you wrote is included.
What is never sent: your name, e-mail address, password, account identifier or subscription details; your exam scores or answer history; your lesson progress. The requests contain no photos, no microphone recording, no contacts and no location. There is no free-text field anywhere in the AI tutor, so no text you type ever leaves the app.
Who receives it: OpenRouter (https://openrouter.ai/privacy), an AI request router, which passes the text to the model that writes the answer — OpenAI’s GPT-4o-mini, or DeepSeek Chat if the first model is unavailable. Requests reach OpenRouter from our own server, not from your device, and they carry no identifier of you: your account identifier is used on our server to check your quota and never leaves it.
Retention: we do not store what is sent or what the model writes back. The explanation is shown to you and kept only in the app on your device. On our servers we keep a count of how many free explanations your account has used (a number, no content). We do not use anything sent to the AI tutor to train AI models.
The answers are educational only. They describe how healthy body systems are organised and how they function. They are never a diagnosis, a medical opinion, or advice about your own health.
You can review this disclosure again at any time from the AI tutor screen.
12.7 Tarot Journal (tarot readings with an optional AI interpreter)
- Firebase Analytics, Crashlytics & Cloud Messaging — anonymized event & crash data, push notifications.
- RevenueCat — subscription state, anonymous device identifier.
- Supabase — account data, AI usage counters, generated AI text (see Retention), and — only if you turn on journal backup — a copy of your journal.
- Google AdMob — advertising to free users.
- OpenRouter — AI interpretation requests (with consent). Detailed below.
Your journal lives on your phone. Readings, reflections and the notes you write are stored in the app on your device. They are not uploaded anywhere unless you do one of two things: turn on journal backup, or use one of the AI features described below. Both are off until you switch them on, and both can be switched off again.
AI interpretations (optional feature). Tarot interpretations are written by a third-party AI service. Before any AI feature can run, and before anything leaves the device, the app shows an explicit in-app disclosure screen. Nothing is sent unless you agree. If you decline, drawing cards, the card meanings bundled with the app, and your whole journal keep working exactly as before.
What is sent, feature by feature:
- Card of the day — the card’s name, whether it is reversed, the traditional meaning bundled with the app, and your app language. Nothing you wrote.
- Reading interpretation — the spread’s name, the cards you drew with their bundled keywords, meanings and position names, your app language, and: the question you typed before drawing, word for word, if you typed one, and your own saved “my meaning” note for a card, word for word, if you saved one.
- Journaling prompts (Pro) — the AI’s own earlier interpretation of that reading and the card names. Not the reflection you wrote.
- Weekly pattern (Pro) — how many readings you logged in the last seven days, which cards and suits came up, and up to 10 verbatim excerpts of the reflections you wrote, 160 characters each.
- Card history summary (Pro) — up to 8 verbatim excerpts, 160 characters each, of what you have written about that one card in the past, each labelled upright or reversed.
- Monthly arc (Pro, and only if journal backup is on) — once a month, overnight and with no phone connected, our server reads your backed-up journal and sends that month’s card totals plus up to 20 verbatim excerpts, 160 characters each, of your reflections and position answers from that month. This runs only if journal backup is on and you have agreed to AI interpretations; turning either one off stops it.
Your typed question, your “my meaning” notes and your journal excerpts are your own free writing, and free writing can hold personal things — relationships, health, money. Read yours once before you agree.
What is never sent to the AI service: your name, e-mail address, password or subscription details; your reminder settings or theme; and no reading from outside the period the feature is about — with the single exception of the monthly arc, which by design looks across a whole month. No entry is ever sent whole; only the excerpts named above. The requests contain no photos, no microphone recording, no contacts and no location. Card of the day and journaling prompts send none of your own writing at all.
Who receives it: OpenRouter (https://openrouter.ai/privacy), an AI request router, which passes the text to the model that writes the answer: Google Gemini Flash Lite (card of the day, journaling prompts, card history summary), DeepSeek Chat (reading interpretation), OpenAI GPT-4o-mini (weekly pattern), or Anthropic Claude (deep spreads and the monthly arc) — with a second model as a fallback if the first is unavailable. Requests reach OpenRouter from our own server, not from your device, and carry no identifier of you: your account identifier is used on our server to check your quota and your subscription, and never leaves it.
Retention: the answer is saved into the reading in the app on your device. On our servers we keep only generated text, never your input: the card-of-the-day message (cached by card and language, not by person — it is the same text for everyone who draws that card), your weekly reflection (kept for that week so it need not be generated again), and your monthly arc (kept for that month). Your typed question, your “my meaning” notes and your journal excerpts are not stored once the answer is written. The card history summary is not stored at all — only a usage count. We do not use anything sent to the AI service to train AI models.
You can withdraw this permission at any time in Settings → AI interpretations. Nothing further is sent once it is withdrawn, and the monthly arc stops being generated.
Journal backup (optional, separate from AI). Journal backup is off by default and needs a real account rather than a guest one. When you turn it on, a copy of your journal — your readings and the reflections and answers you wrote in them, in full — is stored on our Supabase servers under your account so you can restore it on a new device. This is the one case in which whole entries leave your phone. It is not sent to any AI service by the act of backing up; the monthly arc above is the only feature that reads from it, and only under the two conditions named there. You can delete the backup at any time from Settings → Backup, and deleting your account deletes it too.
Not a prediction. Interpretations are reflective writing, not fortune-telling, and never advice about your health, your money or your relationships.
12.8 Garden Planner (vegetable-garden planning with optional AI and optional backup)
- Firebase Analytics & Crashlytics — anonymized event & crash data.
- RevenueCat — subscription state, anonymous device identifier.
- Supabase — account data, AI usage counters, and — only if you turn on garden backup — a copy of your garden.
- Google AdMob — advertising to free users, including a rewarded ad that unlocks an extra AI bed plan.
- OpenRouter — AI requests (with consent). Detailed below.
Your garden lives on your phone. Your beds, your plantings, your harvest log, your succession series, your crop-rotation history and your garden profile (your growing zone and any frost dates you set by hand) are stored in the app on your device. They are not uploaded anywhere unless you do one of two things: turn on garden backup, or use one of the AI features described below. Both are off until you switch them on, and both can be switched off again. Sow, harvest and frost reminders are scheduled by your phone itself — there is no push server behind this app, and it never asks for a push notification token.
No camera, no photo library, no location. Garden Planner asks for none of those permissions and contains no code that uses them. It suggests a starting growing zone from your device’s region setting — a country-level code, never GPS — and you can always correct it by hand. Nothing in this app involves a photo, so no photo is ever sent anywhere or stored.
AI features (optional). Garden Planner has three: the AI Bed Planner, the Succession Coach (Pro) and the AI Advisor (Pro). Before any of them can run, and before anything leaves the device, the app shows an explicit in-app disclosure screen. Nothing is sent unless you accept it. If you decline, everything else — the planting calendar, the bundled plant library, your beds and your reminders — keeps working exactly as before.
What is sent, feature by feature:
- AI Bed Planner — the width and length of the one bed you are planning, in centimetres; the identifiers of the plants you picked from the library bundled with the app; your growing zone code; and your app language. Not the name you gave the bed, and not your other beds.
- Succession Coach (Pro) — the identifier of the crop you just harvested, your growing zone code, and your app language.
- AI Advisor (Pro) — the symptom you tapped from a fixed list of eight (yellowing leaves, wilting, holes in leaves, stunted growth, no flowers, blossom-end rot, moldy patches, curling leaves), the plant it is on if you named one, and your app language. There is no free-text box on that screen and the feature never accepts a photo, so nothing you write and no image is ever part of the request.
What is never sent to the AI service: your name, e-mail address, password, account identifier or subscription details; the names you gave your beds and any notes on your plantings; your harvest log, your succession series, your rotation history and your reminder settings; and any bed or planting other than the one the feature is about. The requests contain no photos, no microphone recording, no contacts and no location.
Who receives it: OpenRouter (https://openrouter.ai/privacy), an AI request router, which passes the text to the model that writes the answer — currently DeepSeek Chat or OpenAI’s GPT-4o-mini, depending on the feature, with the other one as a fallback if the first is unavailable. Requests reach OpenRouter from our own server, not from your device, and they carry no identifier of you: your account identifier is used on our server to check your quota and your subscription, and never leaves it.
Retention: we do not store what is sent or what the model writes back. The answer is shown to you, and where the app saves it, it is saved on your device. On our servers we keep only a count of the AI requests your account has made — which of the three features it was, how many plants were involved, and whether it succeeded. Numbers, no content. We do not use anything sent to the AI features to train AI models.
You can withdraw this permission at any time in Settings → AI features. Nothing further is sent once it is withdrawn.
Garden backup is being introduced with an app update, and this paragraph describes it in advance. Until that update reaches your device and the option appears in your Settings, there is nothing to switch on and no part of your garden leaves your phone at all.
Garden backup (optional, separate from AI). Garden backup is off by default. Nothing about your garden reaches our servers until you turn it on in Settings → Back up your garden and tap Back up now. When you do, a copy of your garden is stored on our Supabase servers under your identity so that you can restore it on a new device: your beds — including the names you typed for them — your plantings, including any note attached to one, your harvest log, your succession series, your crop-rotation history, and your garden profile with your growing zone and any frost dates you overrode. Bed names and planting notes are your own free writing, so read yours once before you switch backup on. Restoring is free for everybody — your own garden is never held back from you. What a subscription changes is how often a new copy may be written: on the free plan, once every 24 hours, enforced by our server. You can switch backup off again at any time, and deleting your account deletes the stored copy with it.
The device identifier stored with a backup. A backup also carries a short random identifier that the app generates for itself the first time you back up and keeps in its own storage on your phone. We store it beside the archive so that a restore can tell you which device last wrote it. It is not the advertising identifier (IDFA or Android Advertising ID), it is not read from your phone’s operating system, it is not shared with anyone, and it is never generated at all if you leave backup off.
If you never turn backup on, the only things our servers hold for you are your account record, the usage counters described under Retention above, and the content of an AI request you chose to make. Your beds and plantings stay on your phone, exactly as they do today.
General gardening information only. What the AI features write is general horticultural guidance. It is never a diagnosis, and never a substitute for your local agricultural extension office or a professional horticulturist.