Legal

Hydrofy Privacy Policy

How Hydrofy handles information across the app, website, and related services.

Effective Date: July 22, 2026

This Policy explains what Hydrofy handles, why it is handled, the providers involved, and the choices available to you.

If you have questions about this Privacy Policy, contact us at support@hydrofygarden.com.

1. Scope and Overview

Hydrofy is operated by Merek Barrett in Ontario, Canada. This Privacy Policy applies to the Hydrofy iOS app, the Hydrofy website, and related support and backend services (collectively, “Hydrofy”).

Hydrofy helps users manage hydroponic systems, plants, measurements, reminders, routines, integrations, and optional AI-powered features. The app is designed to keep much of your garden information on your device and, when enabled by your Apple settings, in Apple iCloud or CloudKit. Other information is transmitted off-device to operate subscriptions, analytics, attribution, weather, AI, support, and connected-service features.

2. Information We Handle

Garden information stored on your device or through Apple services

Depending on the features you use, Hydrofy may store or sync the following information using the app’s local database, app files, Apple backups, and Apple CloudKit or iCloud services:

  • hydroponic systems, plants, varieties, growth stages, layouts, and location labels
  • measurements, logs, notes, schedules, reminders, tasks, harvest information, and maintenance history
  • photos stored as app files, plus photo identifiers and metadata that may sync through Core Data and CloudKit
  • preferences, units, onboarding selections, and feature settings
  • IoT configurations and mappings for services you choose to connect
  • up to a limited number of locally saved AI conversations; images are not intentionally retained in saved chat history

Apple controls its own iCloud, CloudKit, backup, App Store, and device services. Removing the app from one device may not remove information already stored in iCloud, a device backup, or another synced device.

App identity and account information

Hydrofy may automatically create a pseudonymous or anonymous Firebase identity so that app services can operate without requiring you to enter an email address or password. Related records may include:

  • a Firebase user identifier and randomly generated username
  • an app installation identifier, session identifiers, and a RevenueCat customer identifier
  • account creation and recent-activity dates
  • preferences, subscription status, and coarse counts such as the number of systems or plants

Onboarding and personalization information

Hydrofy may process your experience level, crops, growing method, setup style, approximate plant-count range, goals, reminder preferences, acquisition source, grower profile, and experiment assignment. We use these selections to personalize the app and evaluate onboarding, messaging, and product performance.

Product analytics and diagnostics

Hydrofy and its analytics providers may receive app opens, sessions, screen views, taps, feature use, garden setup milestones, logs and reminder actions, onboarding events, A/B-test assignments, paywall and checkout events, timestamps, app version, build number, operating system, device model, language, country or region, performance information, and error information.

First-party analytics events may include a persistent installation identifier and, when available, Firebase and RevenueCat identifiers. Ordinary product analytics are designed not to contain raw garden notes, AI prompt text, AI response text, or photo files.

Subscription and purchase information

Apple and RevenueCat may provide Hydrofy with subscription and entitlement information such as the product and plan, trial or introductory-offer status, purchase date, renewal status, cancellation date, expiration date, refund or revocation status, and a pseudonymous customer identifier. Apple processes payment credentials; Hydrofy does not receive your complete payment-card details.

Attribution and advertising measurement

When enabled for your app version, Hydrofy may receive or share installation and campaign information through Apple attribution services, AppsFlyer, and Meta. This can include media source, campaign, ad set, ad or creative, placement, keyword, publisher platform, deep-link information, click or install timestamps, and conversion events. Attribution and app-event reporting that does not use Apple’s advertising identifier may occur without App Tracking Transparency authorization.

Access to Apple’s advertising identifier and cross-company tracking are subject to Apple’s App Tracking Transparency controls. Hydrofy does not intentionally access the Apple advertising identifier unless Apple reports that the required authorization is available. Privacy-preserving, aggregated, or non-IDFA attribution may still occur without that authorization.

AI requests and operational metadata

If you choose AI Chat, plant scan, or another AI feature, Hydrofy may transmit the content needed to answer your request. Depending on what you submit and the feature you use, this can include conversation text, plant photos, system information, plant details, recent logs and notes, reminders, and tasks.

Hydrofy may also process AI operational metadata such as the selected feature, model, token counts, request characteristics, and success or error state. This operational metadata is used to operate, secure, and troubleshoot the feature.

Location and weather

If you grant location access and request weather-based features, Hydrofy may send reduced-accuracy location coordinates to WeatherAPI.com to obtain local weather information. You can withdraw location permission in iOS Settings.

Connected services

If you connect ThingSpeak, Home Assistant, MQTT, or a custom API, Hydrofy processes the connection details, credentials, mappings, and sensor readings you provide to communicate with that service. These services are optional and are governed by their own terms and privacy practices. Some connection details may be stored with app data and may sync through Apple CloudKit when syncing is enabled.

Website, support, and technical information

If you contact Hydrofy or submit the website contact form, we receive the name, email address, message, and other information you choose to provide. The website may use Google Analytics and receive browser and device information, pages viewed, referral information, approximate location derived from an IP address, cookies or similar identifiers, and diagnostic information.

Hydrofy and its infrastructure providers may automatically process IP addresses, request timestamps, headers, and server logs to deliver and secure the app and website, prevent abuse, and diagnose failures.

3. How We Use Information

We use information for the following purposes:

  • provide, sync, personalize, and secure Hydrofy features
  • manage purchases, trials, entitlements, renewals, cancellations, and restores, and process refund or revocation status received from Apple or RevenueCat
  • generate AI responses when you choose an AI feature
  • provide weather and user-selected connected-service functionality
  • measure onboarding, paywalls, subscriptions, retention, feature use, reliability, and product performance
  • run and evaluate A/B tests and improve product design, flows, messaging, and recommendations
  • attribute installs and conversions to campaigns and measure advertising effectiveness, subject to applicable consent and platform controls
  • answer support requests, maintain business records, investigate misuse, and comply with legal obligations

4. Subscription and Cancellation Analytics

To understand whether Hydrofy delivers value before and after a subscription is cancelled, Hydrofy may join a pseudonymous installation identifier with a RevenueCat customer identifier and subscription-lifecycle events. We may analyze activity relative to trial start, cancellation, reactivation, refund, and expiration dates.

This analysis may include whether the app was opened and whether broad feature categories such as systems, plants, logs, or reminders were used. We use this information for cohort-level product and retention analysis. We do not need raw plant names, garden notes, AI prompts, AI responses, or photos for this analysis and do not intentionally include them in these event payloads.

5. AI Processing

AI features are optional. When you choose to submit an AI request, its text, images, and relevant garden context are sent through Hydrofy’s Vercel-hosted backend to OpenAI to generate a response. Hydrofy does not use AI request content for advertising.

Hydrofy’s backend does not intentionally create a permanent archive of raw AI prompts or images. Limited device, server, security, and error logs may temporarily contain request metadata or request and response previews to operate, troubleshoot, and protect the service. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer opts in, and that API content may be retained in abuse-monitoring logs for up to 30 days unless different retention controls or legal requirements apply.

AI outputs are automated and may be inaccurate, incomplete, delayed, or unsuitable for a particular plant, crop, system, environment, treatment, or food-safety decision.

6. Advertising Attribution and Tracking

Hydrofy does not sell personal information for money. Hydrofy may disclose limited identifiers, campaign information, and conversion events to Apple, AppsFlyer, or Meta for attribution and advertising measurement as permitted by applicable law and platform rules.

The current app can perform attribution and app-event reporting without using Apple’s advertising identifier. If Hydrofy enables IDFA-based tracking in an app version, Hydrofy will use Apple’s required App Tracking Transparency permission flow before accessing the identifier. A tracking choice does not prevent essential subscription processing, fraud prevention, app functionality, or analytics that do not meet Apple’s definition of tracking.

7. Service Providers and Other Recipients

Hydrofy uses service providers only for the purposes described in this Policy. Depending on the features and app version you use, recipients may include:

  • Apple — App Store purchases, StoreKit, iCloud or CloudKit, device services, and privacy-preserving attribution
  • Google Firebase and Google Analytics — anonymous identity, app analytics, diagnostics, and related infrastructure
  • RevenueCat — purchase validation, subscription status, entitlements, and subscription lifecycle events
  • AppsFlyer — installation, deep-link, campaign attribution, and conversion measurement
  • Meta or Facebook — app-event and advertising measurement where enabled and permitted
  • OpenAI — processing optional AI requests
  • Vercel — website, API, and backend hosting
  • Neon or PostgreSQL infrastructure — first-party analytics and identity-link records
  • MongoDB-compatible infrastructure — website content and contact submissions
  • WeatherAPI.com — optional local-weather requests
  • ThingSpeak, Home Assistant, MQTT brokers, and custom API providers — only when you choose to connect them

Hydrofy selects providers that are expected to protect information appropriately for their role and requires them, through applicable agreements and law, to process information consistently with the services they provide. Providers also publish their own terms and privacy practices, and no provider can guarantee absolute security.

8. Legal Disclosures and Business Changes

We may disclose information when reasonably necessary to comply with law, legal process, or enforceable government requests; protect the rights, safety, and security of users, Hydrofy, or others; investigate fraud or abuse; or establish, exercise, or defend legal claims.

If Hydrofy is involved in a financing, reorganization, merger, acquisition, or sale of assets, relevant information may be transferred as part of that transaction, subject to applicable law and appropriate safeguards.

9. Data Retention and Deletion

Garden data stored on your device is retained until you remove it through available app or device controls or remove the app’s local storage, subject to orphaned files and Apple iCloud, CloudKit, synced-device, and backup behavior. Hydrofy does not guarantee that uninstalling the app removes copies held by Apple or copies in device backups.

Subscription and entitlement records are retained for as long as reasonably necessary to provide access, restore purchases, handle disputes and fraud, maintain financial records, and satisfy legal obligations.

Hydrofy currently does not apply one fixed automatic deletion interval to every event-level analytics, attribution, pseudonymous identity-link, diagnostic, and backend record. Retention is based on whether a record remains necessary to attribute a subscription period, compare product cohorts, investigate delivery or security issues, resolve disputes, or comply with law. Hydrofy may delete, aggregate, or de-identify records when they are no longer needed for those purposes. Aggregated information that no longer identifies a person or device may be kept longer.

Support messages and website contact submissions are retained as needed to answer the request, maintain reasonable business records, protect the service, and comply with law. AI-provider retention is described in Section 5.

To request access, correction, or deletion of backend information that Hydrofy can reasonably identify, email support@hydrofygarden.com. Because Hydrofy often uses anonymous or pseudonymous identifiers, we may need an identifier or technical information from your installation and may not be able to link an email address to every anonymous record. We may retain limited information where required by law or necessary to prevent fraud, resolve disputes, or enforce agreements.

10. Your Choices and Privacy Rights

Depending on your location, you may have rights to access, correct, delete, or obtain a copy of personal information; withdraw consent; object to or restrict certain processing; or complain to a privacy regulator. These rights may be subject to legal exceptions.

  • Use iOS Settings to manage camera, photo, location, and notification permissions and, if Hydrofy requests it in a future app version, Apple tracking permission.
  • Do not submit an AI request if you do not want its content sent to Hydrofy’s backend and OpenAI.
  • Disconnect optional weather or IoT services to stop new requests to those providers.
  • Contact Hydrofy to object to or ask about limiting future non-essential analytics associated with an identifier Hydrofy can locate. Hydrofy will assess the request under applicable law and technical limitations; a request may not affect essential subscription records, previously aggregated information, or records controlled independently by a provider.
  • Email support@hydrofygarden.com to make a privacy request or withdraw consent where applicable.

Deleting Hydrofy or requesting deletion of Hydrofy records does not cancel an Apple subscription. Apple subscriptions must be managed separately through your Apple account.

11. Security

Hydrofy uses technical and organizational measures intended to protect information. No electronic transmission, device, cloud service, or storage system is completely secure, and we cannot guarantee absolute security. Protect your device and use care when entering credentials for third-party IoT or custom API services.

12. Children’s Privacy

Hydrofy is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so that we can review and, where appropriate, delete it.

13. International Processing

Hydrofy and its providers may process information in Canada, the United States, and other jurisdictions where they operate. Privacy laws in those jurisdictions may differ from those where you live. We use contractual, technical, and organizational safeguards where required by applicable law.

14. Changes to This Privacy Policy

We may update this Policy as Hydrofy changes. We will update the effective date and provide additional notice or request fresh consent when required for a material new purpose or recipient.

15. Contact

For privacy questions, requests, or complaints, contact:

Hydrofy

Merek Barrett

Ontario, Canada

support@hydrofygarden.com