Privacy

Privacy policy

Clover helps you identify houseplants, diagnose plant problems from a photo, and look up care guides. This policy explains what data the app handles, why, and what your rights are.

Last updated: September 4, 2026

Who is responsible for your data

Clover is provided by Braider AB, Turevägen 78, 191 47 Sollentuna, Sweden (company registration number 559196-0157). We are the data controller for the personal data described here.

Questions, or to exercise any of your rights: hello@cloverhouseplants.com

The short version

What we handle, and why

Photos of plants

When you ask Clover to identify a plant or diagnose a problem, the app resizes the photo on your device and sends it to our server (the Clover API), which forwards it to third-party AI providers to be analyzed. The result is sent back to your device.

A photo can contain more than a plant — background, interior, people. Please avoid including anything you would not want processed.

Text you type

Descriptions of what is wrong with a plant, and plant names you search for, are sent to our server and the AI providers together with the request, for the same purpose, on the same legal basis, and with the same retention as photos.

Please don't include personal details about yourself or anyone else in these descriptions — they are not needed to diagnose a plant.

A random device identifier

On first launch the app generates a random identifier (a UUID) and stores it on your device. It is sent with every request to our server.

Our server also processes your IP address as an unavoidable part of serving a request, and uses it for short-term burst rate limiting.

Subscriptions and purchases

Clover offers an optional paid subscription (Clover Pro). We never see your payment details. The purchase itself is handled entirely by Apple or Google, who take the payment and tell us only whether a subscription exists.

To know whether your device is subscribed, we use RevenueCat, a subscription service. It receives your random device identifier, the store receipt for the purchase, and the resulting purchase history (which product, when it started, when it renews or expires, and whether it is a sandbox or test purchase). Our server asks RevenueCat about your identifier when it needs to check whether the paid allowance applies.

App integrity checks

Clover uses Firebase App Check (Google) to verify that requests come from a genuine, unmodified copy of the app. On iOS this uses Apple's App Attest, on Android Google Play Integrity. These produce a device attestation token.

Crash reports and diagnostics

Release versions of the app send crash and error reports to Sentry (EU-hosted). A report can include the error and its stack trace, the app version, device model, OS version, and a short trail of preceding in-app events.

Clover is configured not to attach IP addresses or user identifiers to these reports.

For sessions where an error occurs, Sentry also records a session replay — a reconstruction of which screens you moved through and where you tapped. All text and all images are masked out before the replay leaves your device, so the replay shows the shape of the screen, not your plant photos or anything you typed. Sessions without an error are never recorded.

Data stored only on your device

Your plants, their names and photos, saved diagnoses and care guides, your recent searches, your usage counter, and onboarding state are stored locally on your device. We cannot see them. Deleting the app deletes them, and they are not backed up to us. Depending on your own iCloud or Android backup settings, your device's operating system may include them in your personal device backup.

What we never collect

Who else sees your data

Clover cross-checks several AI models, so a single request may go to more than one of these providers.

Recipient What they receive How long they keep it
Google (Gemini API, paid tier) Photos and text you submit A limited period, for abuse and safety monitoring only
OpenAI Photos and text you submit Up to 30 days for abuse monitoring, then deleted
Anthropic Photos and text you submit Deleted within 30 days
Google (Firebase App Check) Device attestation tokens Per Firebase's retention
RevenueCat Device identifier, store receipts, purchase history While the subscription is active, then a limited period
Sentry Crash reports, masked session replays Up to 90 days
Vercel Requests to the Clover API, incl. your IP address Short-term operational logs

None of these providers use your photos or text to train their models on our plan tier: OpenAI and Anthropic exclude API data from training by default, and we use Google's paid tier, which also excludes it. Where a provider retains data briefly, it is for detecting abuse of the service, and it may be reviewed by that provider's staff for that purpose.

These providers act as our processors, or as independent controllers where their own terms say so, in each case under a data processing agreement. We do not sell personal data and we do not share it for advertising.

Several of these providers are based in, or process data in, the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.

Children

Clover is not directed at children and we do not knowingly collect data from children under 13 (or the higher age of digital consent in your country). If you believe a child has submitted personal data, contact us and we will delete it.

Your rights

Under the GDPR you have the right to access, correct, delete, restrict, and object to our processing of your personal data, to data portability, and to lodge a complaint with a supervisory authority — in Sweden, Integritetsskyddsmyndigheten (IMY, imy.se).

Because Clover has no accounts, we usually cannot connect any data to you as a person, which limits what we can look up on request. In practice:

Security

Data in transit is encrypted with HTTPS/TLS. Requests are authenticated with Firebase App Check. We keep no copies of your photos on our servers. No system is perfectly secure, but we take reasonable technical and organizational measures to protect what we do process.

Changes to this policy

If we change how Clover handles data, we will update this page and the "last updated" date above, and — for material changes — surface a notice in the app.

Contact

Braider AB
Turevägen 78, 191 47 Sollentuna, Sweden
hello@cloverhouseplants.com