Effective Date: December 2025
My Cozy Plant ("we", "us", or "our") operates the My Cozy Plant mobile application. This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data. For the purposes of the UK General Data Protection Regulation (UK GDPR), we are the Data Controller.
1. Information We Collect & Why (Legal Basis)
We process your personal data under the following legal bases:
- Contractual Necessity: Data required to make the app work for you.
- Legitimate Interest: Data used to improve our app and fix bugs.
A. Personal Data
We collect the following to provide our Service:
- Account Data (Email): Used to create your account, secure your data, and allow password recovery. (Basis: Contractual Necessity)
- Location Data (Postcode/Coordinates): We collect your approximate location/postcode to fetch accurate weather and frost risk data for your specific garden. This is stored in our secure database. (Basis: Contractual Necessity)
- User Content (Plant Data): The plants you add and their settings are stored to sync across your devices. (Basis: Contractual Necessity)
- Device Tokens: We store your device's push notification token (FCM Token) to send you frost alerts. (Basis: Consent/Contractual Necessity)
B. Usage & Log Data
When the app encounters an error, we collect data and information (through Google Firebase Crashlytics) on your phone called Log Data. This may include your device Internet Protocol ("IP") address, device name, operating system version, and the time/date of the error. We use this to fix bugs. (Basis: Legitimate Interest)
2. Third-Party Service Providers (Data Processors)
We share data with specific third-party providers to facilitate our Service. These parties have access to your Personal Data only to perform specific tasks on our behalf and are obligated not to disclose or use it for any other purpose:
- Supabase: For secure database hosting and user authentication.
- Google Firebase: For analytics, crash reporting, and sending push notifications.
- RevenueCat: For processing subscription status and payments (we do not process or store your credit card details; Apple/Google handles financial transactions).
- Postcodes.io & Open-Meteo: We send anonymous coordinate data to these services to retrieve location and weather information.
3. Data Retention
We retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies. If you delete your account, your data is removed immediately.
4. Your Data Protection Rights
Under the UK GDPR, you have the following rights:
- The right to access: You can request copies of your personal data.
- The right to rectification: You can request that we correct any information you believe is inaccurate (e.g., updating your postcode in Settings).
- The right to erasure: You can request that we erase your personal data. You can do this directly in the app via Settings > Delete Account.
- The right to restrict processing: You have the right to request that we restrict the processing of your personal data.
5. International Transfer of Data
Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction. We ensure appropriate safeguards are in place (such as Standard Contractual Clauses) with our providers (Supabase/Google) to protect your data.
6. Children's Privacy
Our Service does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from children under 13.
7. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us:
- By email: hello@mycozyplant.com