Who We Are

Plant Rescue is operated by Kandusol Ltd, trading as Kandu Solutions. Kandusol Ltd is registered in England and Wales under company number 17242843. Its registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

References to Plant Rescue, we, us, and our mean Kandusol Ltd when operating the Plant Rescue app. For the purposes of UK data protection law, Kandusol Ltd is the controller of the personal data described in this policy.

What Plant Rescue Does

Plant Rescue helps users assess plant health from photos, receive plant rescue guidance, save rescue cases, and track progress over time.

Plant Rescue is not a medical, veterinary, agricultural, pesticide, or professional horticultural advisory service. The app provides general plant-care guidance and uses third-party plant identification and plant health assessment services where needed to provide diagnosis results.

Personal Data We May Collect

The personal data we collect depends on how you use the app and which features you choose.

  • Account data such as email address, authentication provider, Supabase user ID, account timestamps, and sign-in records.
  • Plant rescue data such as uploaded plant photos, diagnosis attempts, plant identification results, health assessment results, follow-up answers, rescue history, saved cases, and progress updates.
  • Location context such as device location, manually selected location, latitude and longitude used for diagnosis context, and human-readable location labels.
  • Subscription data such as RevenueCat customer identifiers, Google Play purchase or subscription information, entitlement status, subscription product, store, environment, renewal and expiry dates, and purchase event metadata.
  • Analytics consent data such as whether you accepted or rejected optional analytics and the local setting used to remember that choice.
  • Optional analytics event metadata such as app opens, onboarding progress, photo source choice, scan start and completion metadata, safe scan failure categories, plant saved events, saved case opens, paywall views, subscription events, and parsed install referrer UTM values where available.
  • Crash and diagnostics data such as device and platform information, app version, operating system version, crash stack traces, error information, session information, and diagnostic logs.
  • Support data such as messages, verification information, and correspondence you send when contacting support or requesting account deletion.

Photos And Diagnosis Data

When you upload or capture plant photos, we use them to create a rescue case, request plant identification and plant health assessment, generate diagnosis and rescue guidance, save your rescue history if you are signed in, and support progress updates for the same rescue case.

We do not use plant photos to identify people. However, plant photos may accidentally include personal data, for example if a person, address, room, or location-identifying detail appears in the image. Please do not upload photos that include people, children, addresses, documents, screens, or other private information.

We do not send plant photos, image URLs, user-entered notes, raw provider responses, or diagnosis text to Firebase Analytics. Analytics events are limited to metadata-style events and safe categories.

Analytics Consent

On first launch, Plant Rescue asks whether you accept optional analytics. You can accept or reject non-essential analytics, and you can change your choice later in the app settings.

If you reject optional analytics, Firebase Analytics collection is disabled and Plant Rescue does not log optional product analytics events through the app analytics service. Core app features remain available.

If you accept optional analytics, we may use Firebase Analytics and our own app analytics records to understand aggregate app usage, onboarding, scan flow reliability, saved case usage, paywall views, subscription success, and install attribution. Where available, Firebase Analytics user ID may be set to the same internal Supabase user ID so we can understand app behaviour without using email addresses in analytics events.

Crash Reporting And Essential Diagnostics

Plant Rescue uses Firebase Crashlytics for essential diagnostics, crash reporting, and app stability monitoring. Crashlytics helps us understand crashes and serious errors so we can fix reliability problems.

Crash reports may include technical information such as app version, device model, operating system version, timestamps, stack traces, crash state, and a user identifier after sign-in. Crash reports are not used for advertising and are separate from optional product analytics consent.

Install Attribution And Advertising

After optional analytics consent is accepted, Plant Rescue may read the Google Play Install Referrer once to understand how the app was installed. We may log parsed UTM values such as source, medium, and campaign where they are available.

We store only a local processed flag for install referrer capture. We do not store the raw referrer string.

Plant Rescue may be promoted through external advertising, including Google or Meta/Facebook advertising campaigns. Running external ads for the app does not mean the app contains ads. Plant Rescue does not currently show in-app ads, does not use AdMob, and does not include the Meta/Facebook SDK.

Why We Use Personal Data

We only process personal data where we have a lawful basis under UK data protection law. Depending on the context, we may rely on performance of a contract, consent, legitimate interests, or legal obligation.

We use personal data to create and manage accounts, provide plant identification and health assessment, save and revisit rescue cases, improve diagnosis context with location where enabled, manage subscriptions and Pro access, maintain security, prevent abuse, enforce usage limits, understand app performance, debug crashes, respond to support requests, handle deletion requests, and comply with legal, tax, accounting, and regulatory requirements.

Where we rely on consent, such as optional analytics consent or device-level location permission, you can withdraw that consent through app settings or device settings as applicable. Some app features may work less accurately if location access is disabled.

Third Parties And Processors

We use third-party providers to operate Plant Rescue. These include Supabase for authentication, database, storage, and app backend services; Kindwise Plant API, iNaturalist and Open Plantbook for plant identification, plant health assessment and Plant care and scientific information; RevenueCat for subscription entitlement management; Firebase Analytics for optional analytics; Firebase Crashlytics for crash reporting and essential diagnostics; Google Play for Android app distribution, billing, subscriptions, Install Referrer, and Play Console reporting; Google OAuth if you choose Google sign-in; and device, platform, or geocoding services for location search and reverse geocoding.

These providers process personal data only as needed for the relevant service. Their own privacy notices may also apply, especially where you interact with Google Play, Google sign-in, or subscription management directly.

International Transfers

Some service providers may process personal data outside the United Kingdom. Where personal data is transferred internationally, we rely on appropriate safeguards such as adequacy regulations, standard contractual clauses, international data transfer agreements, UK addenda, or equivalent mechanisms required by applicable data protection law.

Retention And Deletion

We keep personal data only for as long as needed for the purposes described in this policy. Account data, rescue cases, plant photos, diagnosis history, and progress updates are generally kept while your account remains active, unless you delete the data or request deletion.

Subscription entitlement records may be kept for as long as needed to provide Pro access and maintain purchase history, plus any period required for legal, accounting, tax, fraud-prevention, or dispute-resolution purposes. Optional analytics, install attribution, and technical logs are usually kept in identifiable form only for as long as needed to operate, debug, secure, and improve the service.

Crash reports and diagnostic records are kept for the period needed to identify, investigate, and fix stability issues, subject to the retention settings and limits of the relevant service provider.

When we no longer need identifiable data, we delete it or anonymise it.

Account Deletion

You can request deletion of your Plant Rescue account and associated app data using the account deletion page. When your request is verified, we will delete or anonymise account data, saved rescue cases, uploaded plant photos, diagnosis history, progress updates, and related app data, unless we need to retain limited information for legal, accounting, fraud-prevention, dispute-resolution, or regulatory reasons.

Deleting your Plant Rescue account does not automatically cancel an active Google Play subscription. You must manage or cancel subscriptions through Google Play.

Your Rights

Subject to applicable law, you may have rights to be informed about how we use your personal data, access a copy of your personal data, correct inaccurate personal data, request deletion, restrict processing, object to certain uses, receive certain data in a portable format, withdraw consent where processing is based on consent, and complain to the Information Commissioner's Office or another applicable data protection authority.

We may need to verify your identity before responding to a rights request.

Children And Teenagers

Plant Rescue is intended for adults. It is not directed to children, and we do not knowingly collect personal data from children under 13.

If you are under 18, do not create an account, upload photos, buy a subscription, or submit personal data through Plant Rescue unless your parent or guardian has agreed and supervises your use of the app.

Parents or guardians who believe a child has provided personal data through Plant Rescue can contact us at appsupport@kandusolutions.co. If we learn that we have collected personal data from a child under 13 without the required parental consent, we will delete the data or disable the account where required.

If Plant Rescue is later designed for, marketed to, or likely to be used by children or families, we will review the app design, Google Play target-audience settings, age-appropriate notices, analytics and advertising SDKs, consent flows, and child privacy requirements before release.

Security

We use technical and organisational measures designed to protect personal data, including access controls, encrypted transport, and service-provider security features. No app or internet service can guarantee absolute security.

Changes And Governing Law

We may update this policy from time to time. If we make material changes, we will update the last updated date and, where appropriate, provide additional notice in the app or through the app store listing.

This policy and any non-contractual obligations arising from it are governed by the laws of England and Wales, except where applicable data protection law gives you rights that cannot be limited by this section.