Our privacy promise
We do not sell your personal information. We do not “share” it for cross-context behavioral advertising. Cottage has no ads, third-party ad trackers, or marketing profiles.
We also will not use confusing buttons, preselected consent, guilt, artificial urgency, or other dark patterns to push you into giving up privacy. Optional features should feel optional.
What stays on your device
Your seed library—including packet photos, extracted or manually entered seed details, planting history and plans, garden name, hardiness zone, and frost dates—is stored in Cottage’s local database on your device. You can use a local garden anonymously, without creating an account. Cottage does not upload a local garden to cloud storage unless you deliberately turn on sharing for that garden.
Your phone’s operating system or a backup service you enable may back up app data under its own settings and privacy policy.
When data leaves your device
Only the online feature you choose sends the data it needs:
- Packet reading. When you finish a scan, the cropped front and back images go to Cottage’s server and then to OpenAI to read the packet. The extracted result returns to your device. Cottage does not put the images or result in its cloud database or application logs.
- Garden location lookups. Only when you tap the location button, your approximate coordinates go to Cottage’s server. A zone lookup uses Esri’s ArcGIS geocoder to identify a ZIP code, then queries the official 2023 USDA Plant Hardiness Zone Map table. A frost-date lookup sends the selected year and queries NOAA climate data. Cottage saves the resulting zone or dates only after you save your garden settings; it does not save the coordinates or ZIP code. A rounded location used for frost dates may remain in a temporary in-memory cache until that server instance restarts.
- Service protection. Online features use the anonymous Firebase identifier and device/app-attestation signals. Cottage also receives normal network information, including an IP address, to authenticate requests, prevent abuse, and enforce fair daily limits.
- Shared gardens. Only after you create or join one, Cottage sends that garden’s records, membership changes, and compressed photos to Firebase so authorized members can synchronize them. Invitation links and codes are sent to Cottage’s server to preview and accept an invitation.
What we keep, and for how long
- Quota records contain the Firebase identifier or a one-way, secret-keyed version of the IP address, counts, and timestamps. They are scheduled to expire after 48 hours.
- Service logs contain the event, status, duration, Firebase identifier, and app identifier—not photos, coordinates, request bodies, raw IP addresses, or security tokens. Production logs are scheduled for deletion after 30 days.
- The anonymous Firebase account exists to secure online features. It is not connected to a name or email unless you link a sign-in provider.
- Shared-garden records and photos remain while the garden is shared. Deletion markers may be retained while needed to prevent an offline device from restoring deleted content.
- Removing a member revokes that person’s cloud access immediately. Cottage clears that garden’s local cache on the removed device the next time it connects. Stopping sharing removes member access and marks the shared cloud records inactive, while each person’s other local gardens remain untouched.
- Cottage asks OpenAI not to store a response record. OpenAI does not use API content to train its models unless the API customer opts in, which Cottage does not. OpenAI may still retain content in abuse-monitoring logs for up to 30 days, or longer when legally required.
Deleting your Cottage cloud account
You can initiate deletion inside Cottage from Settings → Cottage account → Delete Cottage account. If you used Sign in with Apple, Cottage may ask you to authorize again so it can revoke the Apple sign-in token before deleting the account.
Once deletion is confirmed and completes, Cottage immediately deletes the active Firebase authentication account and its associated active cloud data. If you own a shared garden, its cloud copy is deleted and its members lose access. If you joined a shared garden, your membership is removed and Cottage clears that joined garden’s local cache. Local gardens—and local copies of gardens you owned—remain only on your device unless you delete them or remove the app and its data. Records you contributed to a shared garden owned by someone else may remain as part of that garden, but Cottage redacts your account identifier from those retained records.
Limited security logs, operational records, and backups may remain until their stated schedules or a service provider’s retention period ends. Deleting your Cottage account does not control device backups that you enabled or records your sign-in provider must keep under its own policy. If in-app deletion does not complete, contact hello@getcottage.app.
Why we use this data
We use data only to:
- provide the feature you requested;
- secure the service and apply usage limits;
- diagnose failures and keep Cottage reliable; and
- comply with law or protect people when genuinely necessary.
We do not use packet contents, location, or activity to target ads or build a profile of your interests.
The companies that help
Cottage uses Google Firebase and Google Cloud for anonymous authentication, optional account linking, shared-garden synchronization and photo storage, app verification, hosting, quotas, and service logs; OpenAI for optional packet reading; Esri ArcGIS for optional location-to-ZIP lookup; the USDA Plant Hardiness Zone Map for optional U.S. zone lookup; and NOAA for optional U.S. frost-date normals. Sign in with Apple is provided by Apple. These companies process limited data for us or answer the request we send them, under their own legal and security obligations. We do not let them use your information for Cottage advertising.
Your choices and rights
- Skip packet reading and enter seed details manually.
- Deny location access and enter your hardiness zone and frost dates manually. Cottage requests foreground location only after you tap a lookup button; it does not track background location.
- Edit or delete any seed and its planting details in the app. Removing the app ordinarily removes its local copy, subject to device backups you control.
- Do not enable sharing, or leave a shared garden you joined. An owner can remove editors or stop sharing the garden. Offline copies may not disappear until a device reconnects and receives the change.
- Use in-app deletion or ask to access or delete cloud-side information associated with your app session or durable account. You may also exercise privacy rights that apply where you live. We will not discriminate against you for asking.
Children
Cottage is a general gardening app and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If you believe a child sent us personal information, please contact us so we can delete it.
Questions or requests
Cottage is provided by the developer identified on its App Store listing. Email hello@getcottage.app for privacy questions, access or deletion requests, or help using an in-app privacy control. We may need limited information to verify a request, but we will not ask for more than reasonably necessary.
If this policy changes
We will update the effective date and explain material changes in the app or its store listing before they take effect when practical. We will not quietly turn a local-first promise into permission to sell your data. If a new feature needs new data, we will explain it at the point of choice.