Privacy Policy
“Limellia is the interface between a plant and its human. It doesn't need to know who you are to help you care for them.”
The essentials, in four points:
- Your photos stay on your phone. They are never stored on our servers; they only pass through, for the duration of the analysis, to the artificial-intelligence service — stripped of all their metadata (GPS location, device model, date).
- Your location is optional, one-off, and deliberately imprecise. It is only used for local weather, is never tracked continuously, never stored, and it is rounded to about 1 km before anything is sent.
- You are not required to create an account with your identity. The app works with a pseudonymous technical identifier. Linking an Apple or Google account is optional (it only serves to recover your garden if you change phones).
- You can erase everything, from within the app, in a single action.
1. Who is responsible for your data?
The Limellia app is published by Tatsiana Zubro, sole trader (French “entrepreneuse individuelle”, EI) — 206 rue Conte Devolx, 13300 Salon-de-Provence, France — SIREN 106 153 810, data controller within the meaning of the General Data Protection Regulation (GDPR).
For any question about your data: privacy@limellia.com.
2. What data is processed, and why?
| Data | Purpose | Where it lives | Legal basis |
|---|---|---|---|
| Pseudonymous technical identifier (anonymous Firebase account) | Operating your personal space without asking for your identity | Cloud (Google Firebase, see §8) | Performance of the contract |
| Your garden: plants, care tasks, progression (points, “Sap”) | The core of the service | On your phone (encrypted local database); only progression and premium status are synced to the cloud | Performance of the contract |
| Plant photos | AI identification and diagnosis | On your phone only; ephemeral transit to the AI (see §3 and §4) | Performance of the contract |
| First name (if you provide it), care context, diagnosis history | Personalising the AI's advice | On your phone; sent to the AI at the time of an analysis | Performance of the contract |
| One-off, rounded geographic location (~1 km) | Local weather and light advice | Never stored; sent to the weather service at the time of the request | Consent (system permission, refusable at any time) |
| Email address and name (only if you link an Apple or Google account) | Recovering your garden on a new device | Cloud (Google Firebase) | Performance of the contract (optional feature) |
| Advertising identifiers (IDFA on iOS if you accept, Android advertising ID) | Displaying ads (free version) | Processed by Google AdMob | Consent (consent banner + iOS tracking permission) |
| Usage events (e.g. “a scan was performed”, “the premium screen was viewed”) | Understanding usage and improving the app | Google Analytics for Firebase | Consent (disabled if you decline the consent banner) |
| Subscription status and purchase receipts | Managing your premium subscription | RevenueCat + Apple App Store / Google Play | Performance of the contract |
| Technical crash reports (error, device model, app version — no screenshots) | Fixing bugs | Sentry (hosted in the European Union) | Legitimate interest (service reliability) |
| Device attestation tokens | Protecting the service against fraud and abuse | Firebase App Check | Legitimate interest (security) |
3. Your photos: what really happens
- Storage: local only. Your plant photos are saved on your phone. We keep no album of your photos on our servers.
- Metadata: stripped at the root. Before any analysis, each image is decoded then fully re-encoded: EXIF metadata (GPS coordinates of the shot, device model, date) is not copied over. This stripping applies both to the image sent to the AI and to the copy kept on your phone.
- Transit: ephemeral. The normalised image is sent to the AI service for the duration of the diagnosis, then is not retained by the app server-side.
- Deletion: deleting a plant or uninstalling the app deletes the associated photos from your device.
4. Artificial intelligence: transparency
Plant diagnoses are generated by an artificial intelligence (Google's Gemini models, via the Firebase AI Logic service). Like any AI, it can be wrong: recommendations are plant-care advice, not certainties.
What is sent to the AI at the time of an analysis: the normalised photo (without metadata), your answers to the context questions (pot size, watering, light exposure…), your gardener profile, your first name if you provided it, the language and the season. In accordance with the paid terms of the service we use as of the date of this version, this content is not used by Google to train its models. Should those terms change, this page will be updated before the change takes effect.
5. Geolocation: optional, one-off, deliberately degraded
- Optional: the app works entirely without it. If you decline the permission, the weather is simply hidden.
- One-off: your position is read only at the moment the weather is fetched. No continuous tracking, no background tracking.
- Deliberately degraded: coordinates are rounded to two decimal places (about 1 km) before being sent to the weather service Open-Meteo (hosted in the European Union, no account and no identifier). Your exact position never leaves your device.
- Never stored: neither on the phone nor in the cloud. Your city name, shown on screen, is obtained through your system's geocoding service (Apple on iPhone, Google on Android).
6. Advertising and consent (free version)
The free version offers opt-in video ads via Google AdMob, which grant additional analyses.
- On first launch in the European Economic Area, a consent banner (Google UMP) asks for your choice. You can decline: you will then see non-personalised (or contextual) ads, with no profiling.
- On iOS, the tracking permission (App Tracking Transparency) is requested separately. If you decline, the IDFA advertising identifier is not accessible.
- You can change your choices at any time in the app's or your device's settings.
- Google's advertising SDK also collects technical data — performance (app launch time, energy use), crash logs, and IP address, from which an approximate location can be inferred — used for ad serving, measurement and fraud protection.
- Premium subscribers see no ads at all.
7. Analytics
We use Google Analytics for Firebase to understand how the app is used (e.g. number of scans, screens viewed, first-launch steps). These events are tied to the pseudonymous identifier, never to your identity. Collection is disabled if you decline the consent banner.
8. Recipients and processors
| Provider | Role | Location |
|---|---|---|
| Google Ireland / Google LLC (Firebase: authentication, database, Gemini AI, Analytics, App Check, AdMob) | Infrastructure, AI, advertising, analytics | EU / United States* |
| RevenueCat, Inc. | Subscription management | United States* |
| Apple (App Store, iOS geocoding) / Google Play | Distribution, payment, geocoding | EU / United States* |
| Open-Meteo | Weather data (rounded coordinates, no identifier) | European Union |
| Functional Software, Inc. (Sentry) | Crash reports | Hosted in the European Union |
9. Retention periods
- Garden, photos, history: on your device, until you delete them or uninstall.
- Cloud data (progression, premium status, account): lifetime of the account; deleted when the account is deleted.
- Analytics data: standard retention period of Google Analytics for Firebase (maximum 14 months for data associated with the identifier).
- Crash reports: 90 days.
- Photos sent to the AI: ephemeral transit, not retained by the app.
10. Your rights, and how to exercise them in two taps
You have the rights of access, rectification, erasure, restriction, objection and portability over your data.
- Immediate erasure, without writing to us: Profile → Account → Delete my account. This action deletes your cloud data (account and progression) and resets local data. Uninstalling removes everything left on the device.
- For everything else: write to us at privacy@limellia.com — we reply within one month at most.
- You may also lodge a complaint with the French supervisory authority, the CNIL (cnil.fr), if you believe your rights are not being respected.
11. Minors
Limellia is a general-audience plant-care app, with no sensitive content. It is not specifically aimed at children and does not seek to collect data about minors under 15. If you are a parent and believe a minor has provided data without approval, contact us.
12. Security
- Local data is stored in an encrypted database on your device, with keys protected by the system keychain.
- All network communications are encrypted (HTTPS/TLS).
- A device-attestation mechanism (App Check) protects our services against fraudulent access.
- No banking data passes through us: payments are handled by Apple and Google.
13. Changes to this policy
This policy evolves with the app. Any substantial change (new data collected, new provider) will be announced in the app before it takes effect, and the version history remains available on this page.
14. Contact
Tatsiana Zubro (EI) · 206 rue Conte Devolx, 13300 Salon-de-Provence, France · SIREN 106 153 810
Email: privacy@limellia.com