Privacy
Privacy policy
Clover helps you identify houseplants, diagnose plant problems from a photo, and look up care guides. This policy explains what data the app handles, why, and what your rights are.
Last updated: September 4, 2026
Who is responsible for your data
Clover is provided by Braider AB, Turevägen 78, 191 47 Sollentuna, Sweden (company registration number 559196-0157). We are the data controller for the personal data described here.
Questions, or to exercise any of your rights: hello@cloverhouseplants.com
The short version
- No account. There is no sign-up, no email, no name, no password.
- We do not sell your data, and there is no advertising or cross-app tracking in Clover.
- Photos you submit are sent to our server and to AI providers for analysis. They are not kept on our server afterwards.
- Your plants, their photos, and your saved results live on your device, not on our servers.
- If you subscribe, we never see your payment details — Apple or Google handle the payment and only tell us that a subscription exists.
What we handle, and why
Photos of plants
When you ask Clover to identify a plant or diagnose a problem, the app resizes the photo on your device and sends it to our server (the Clover API), which forwards it to third-party AI providers to be analyzed. The result is sent back to your device.
- Purpose: producing the identification, diagnosis, or care advice you asked for.
- Legal basis (GDPR): performance of a contract — providing the service you requested (Art. 6(1)(b)).
- Retention: the photo is processed and is not stored on our server afterwards, and request contents are not written to our server logs. The AI providers keep it briefly for their own abuse monitoring — see "Who else sees your data" below.
- Photos you choose to save to a plant are stored only on your device and are never uploaded for that purpose.
A photo can contain more than a plant — background, interior, people. Please avoid including anything you would not want processed.
Text you type
Descriptions of what is wrong with a plant, and plant names you search for, are sent to our server and the AI providers together with the request, for the same purpose, on the same legal basis, and with the same retention as photos.
Please don't include personal details about yourself or anyone else in these descriptions — they are not needed to diagnose a plant.
A random device identifier
On first launch the app generates a random identifier (a UUID) and stores it on your device. It is sent with every request to our server.
- Purpose: enforcing the free monthly usage allowance and short-term abuse rate limits, and — if you subscribe — identifying which device the subscription belongs to. There is no account, so this identifier is what your subscription is attached to.
- Legal basis: legitimate interest in preventing abuse and in offering a free tier without accounts (Art. 6(1)(f)); for the subscription part, performance of our contract with you (Art. 6(1)(b)).
- Retention: the usage counter is kept per identifier per calendar month, and only the current and the previous month are held — anything older is deleted. If you subscribe, the identifier is also kept alongside your subscription record for as long as that subscription is active, and for a limited period afterwards so a lapsed subscription can be restored.
- It is not derived from any hardware identifier, is not linked to your identity, and is not used to track you across apps or websites. Deleting the app deletes the identifier; reinstalling produces a new one — which is why a subscription has to be restored after a reinstall, using the Restore purchases button.
Our server also processes your IP address as an unavoidable part of serving a request, and uses it for short-term burst rate limiting.
Subscriptions and purchases
Clover offers an optional paid subscription (Clover Pro). We never see your payment details. The purchase itself is handled entirely by Apple or Google, who take the payment and tell us only whether a subscription exists.
To know whether your device is subscribed, we use RevenueCat, a subscription service. It receives your random device identifier, the store receipt for the purchase, and the resulting purchase history (which product, when it started, when it renews or expires, and whether it is a sandbox or test purchase). Our server asks RevenueCat about your identifier when it needs to check whether the paid allowance applies.
- Purpose: giving you what you paid for, restoring a subscription after a reinstall or on a new device, and preventing abuse of the paid tier.
- Legal basis: performance of our contract with you (Art. 6(1)(b)).
- Retention: for as long as the subscription is active, and for a limited period afterwards so a lapsed subscription can still be restored.
- No name, email or card number reaches us or RevenueCat from the app. If you want a receipt or a refund, that is between you and Apple or Google.
App integrity checks
Clover uses Firebase App Check (Google) to verify that requests come from a genuine, unmodified copy of the app. On iOS this uses Apple's App Attest, on Android Google Play Integrity. These produce a device attestation token.
- Purpose: blocking automated abuse of our API.
- Legal basis: legitimate interest in securing the service (Art. 6(1)(f)).
- The token says something about the device and app, not about you.
Crash reports and diagnostics
Release versions of the app send crash and error reports to Sentry (EU-hosted). A report can include the error and its stack trace, the app version, device model, OS version, and a short trail of preceding in-app events.
Clover is configured not to attach IP addresses or user identifiers to these reports.
For sessions where an error occurs, Sentry also records a session replay — a reconstruction of which screens you moved through and where you tapped. All text and all images are masked out before the replay leaves your device, so the replay shows the shape of the screen, not your plant photos or anything you typed. Sessions without an error are never recorded.
- Purpose: finding and fixing crashes and bugs.
- Legal basis: legitimate interest in a working, secure app (Art. 6(1)(f)).
- Retention: up to 90 days, after which Sentry deletes the report. This is fixed by Sentry and cannot be extended.
Data stored only on your device
Your plants, their names and photos, saved diagnoses and care guides, your recent searches, your usage counter, and onboarding state are stored locally on your device. We cannot see them. Deleting the app deletes them, and they are not backed up to us. Depending on your own iCloud or Android backup settings, your device's operating system may include them in your personal device backup.
What we never collect
- Your name, email address, phone number, or postal address
- Any account credentials
- Payment details — card numbers, billing address, or anything else you give Apple or Google to pay with. We never receive them
- Precise or coarse location
- Your contacts, calendar, health data, or files beyond the photos you pick
- Advertising identifiers — Clover contains no ads and no advertising SDKs
Who else sees your data
Clover cross-checks several AI models, so a single request may go to more than one of these providers.
| Recipient | What they receive | How long they keep it |
|---|---|---|
| Google (Gemini API, paid tier) | Photos and text you submit | A limited period, for abuse and safety monitoring only |
| OpenAI | Photos and text you submit | Up to 30 days for abuse monitoring, then deleted |
| Anthropic | Photos and text you submit | Deleted within 30 days |
| Google (Firebase App Check) | Device attestation tokens | Per Firebase's retention |
| RevenueCat | Device identifier, store receipts, purchase history | While the subscription is active, then a limited period |
| Sentry | Crash reports, masked session replays | Up to 90 days |
| Vercel | Requests to the Clover API, incl. your IP address | Short-term operational logs |
None of these providers use your photos or text to train their models on our plan tier: OpenAI and Anthropic exclude API data from training by default, and we use Google's paid tier, which also excludes it. Where a provider retains data briefly, it is for detecting abuse of the service, and it may be reviewed by that provider's staff for that purpose.
These providers act as our processors, or as independent controllers where their own terms say so, in each case under a data processing agreement. We do not sell personal data and we do not share it for advertising.
Several of these providers are based in, or process data in, the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.
Children
Clover is not directed at children and we do not knowingly collect data from children under 13 (or the higher age of digital consent in your country). If you believe a child has submitted personal data, contact us and we will delete it.
Your rights
Under the GDPR you have the right to access, correct, delete, restrict, and object to our processing of your personal data, to data portability, and to lodge a complaint with a supervisory authority — in Sweden, Integritetsskyddsmyndigheten (IMY, imy.se).
Because Clover has no accounts, we usually cannot connect any data to you as a person, which limits what we can look up on request. In practice:
- Data on your device: delete a plant or photo in the app, or uninstall the app, and it is gone.
- The device identifier and usage counters: uninstalling the app deletes the identifier, after which the counter expires on its own. You can also email us to have it deleted immediately.
- Crash reports: email us and we will delete any report we can locate from the details you provide.
Security
Data in transit is encrypted with HTTPS/TLS. Requests are authenticated with Firebase App Check. We keep no copies of your photos on our servers. No system is perfectly secure, but we take reasonable technical and organizational measures to protect what we do process.
Changes to this policy
If we change how Clover handles data, we will update this page and the "last updated" date above, and — for material changes — surface a notice in the app.
Contact
Braider AB
Turevägen 78, 191 47 Sollentuna, Sweden
hello@cloverhouseplants.com