Sprout House

Privacy Policy

Last updated: 15 August 2026. This policy takes effect when it is published at this address.

Local-first by default. Your plant collection and most app information stay on your device. Information leaves your device only when you choose a remote Sprig or reporting feature described below.

Information you create in Sprout House

You may create plant records, nicknames, species and care information, rooms and placement details, Plant Passport information (including acquisition, cost, substrate, propagation, repotting, treatment, and collection information), care and watering history, tasks, diary entries, light readings, and preferences. These are stored locally on your device in the current app.

Photos, camera, and light features

Growth and other app-owned plant photos, and optional room/light-map photos, are stored locally. Sprout House requests camera or photo-library access only when you choose a photo-related action. Removing an app-owned photo or resetting app data removes the app's stored copy; it does not remove an original from your device photo library.

If you explicitly start plant photo analysis or light-map analysis and confirm the relevant disclosure, Sprout House sends the selected image and limited related context to its backend for that requested analysis. Sprout House does not automatically send all of your photos, and ordinary Sprig chat does not send photo bytes.

Sprig and AI-powered features

Remote Sprig is optional. When you choose it, Sprout House sends your question, a limited conversation history, and limited selected-plant context to the Sprout House backend, which uses OpenAI to provide the requested response. Photo and light-image analysis are separate, user-triggered flows. The app stores Sprig conversations locally; the ordinary chat backend does not keep a conversation database.

Responses API requests are configured with store: false. This setting concerns Responses API application-state storage; it is not a promise of zero provider retention, immediate deletion, or a statement about all provider practices. We do not make a broader claim about AI training without supporting evidence.

If you report a Sprig response, the report contains the reported response, the preceding user message, your selected reason, any optional comment, and limited technical metadata. Reports do not include full conversation history, plant context, or images, and are not sent to OpenAI. Report storage is intended for safety and moderation review; a production retention period has not yet been approved.

Accounts, cloud services, subscriptions, and purchases

Sprout House does not currently provide production user accounts or cloud sync. It does not currently process subscriptions or purchases. The app has entitlement-domain foundations only; that does not mean billing is active. If account, cloud, or purchase features are introduced, we will update this policy before or when they become available.

Technical and security information

Services that receive remote requests may process technical information needed to operate and protect them, such as connection information, IP-derived rate-limiting state, request identifiers or hashes used for temporary deduplication, and privacy-aware operational logs. Sprout House does not currently use an analytics or crash-reporting SDK. Firebase App Check is planned as an integrity control but is not active in the current Flutter client.

How we use information and service providers

We use information to provide local plant-care features, fulfill optional remote Sprig and image-analysis requests, review user-submitted AI reports, and protect and improve service reliability. Current repository evidence identifies OpenAI for requested AI processing. The Sprout House backend and its future production host may process remote requests and reports. Firebase is configuration-ready for future App Check, not active today. We do not list advertising, analytics, payment, or cloud-sync providers because the current implementation does not use them.

Retention, security, and international processing

Local information remains on your device until you delete it or reset app data. Remote operational information and reports may be retained only as needed for their stated purpose and applicable security or legal requirements; no fixed production retention period has been approved. We use reasonable safeguards appropriate to the service, but no system can guarantee absolute security. Service providers may process information outside your country, subject to applicable protections.

Your choices and deletion rights

You can remove individual app-owned data in the relevant app areas and use the app's reset option to clear local personal app state, Sprig history, and Sprout House-owned media. Reset retains appearance, notification, onboarding, and saved remote-Sprig-consent preferences. Depending on applicable law, you may have rights to request access, correction, or deletion of remotely processed information. See Delete your Sprout House account and data for the current request route.

Children's privacy

Sprout House is not designed for children. We do not knowingly create accounts for children because the current app does not offer accounts.

Changes and contact

We may update this policy as Sprout House changes. We will post the updated version here. For privacy or data requests, email hello@sprouthouse.app. Please do not send passwords, payment-card details, or other unnecessary sensitive information.