Plant Tender
How it works Pricing Sign in

← Plant Tender

Privacy

Last updated: August 15, 2026.

I'm Stephen — Plant Tender is a small SaaS I built and run. This page is my honest account of what data the app handles, where it goes, and what I do and don't do with it. If any of it isn't clear, email [email protected] and I'll answer you personally.

What I collect

Your account. When you sign up — with Google, with Facebook, or with an email and password — I keep your email, your name, and (if you used Google) your Google profile picture. That's the whole account record.

Your Home and plants. Plant Tender groups everything under a "Home." Inside your Home I store the plants you add (nickname, species, room, care thresholds), the photos you upload of them, the meter readings you log, and the watering and feeding entries you record. Every one of those rows is tagged with your Home's ID and is only ever readable by members of that Home.

How you got here. If you land on plant-tender.com from a link with utm_source on it (say, a Facebook ad or a blog post), the site drops a small first-party cookie called pt_attrib so I know which channel introduced us. It lives for 30 days, it doesn't leave this site, and it isn't tied to a real person until you sign up. If you sign up during that window I write the source onto your user record so I can tell what's actually bringing people in.

If you arrived by clicking a Facebook or Instagram ad, the link also carries Meta's click ID (fbclid), and the site stores it in a second first-party cookie called pt_fbc for 90 days. If you sign up during that window I save that click ID on your user record — and, if Meta's pixel set its own _fbp cookie on the ads page, that value too. Those exist for one purpose: telling Meta "this ad led to a signup," which is spelled out under Facebook (Meta) below.

Your session. After you sign in I set an HMAC-signed session cookie called plant_tender_session for 30 days. It carries your email, your Home ID, and your role. It's HttpOnly and Secure and only sent to plant-tender.com.

Your billing details, indirectly. If you subscribe to Pro I hand you off to Stripe's Payment Element. Card numbers go straight to Stripe — I don't see them, and they never touch my servers. Stripe sends me back a customer ID, a subscription status, and a renewal date, and I store those on your Home.

Support conversations. If you email support@ or hello@, the message and my replies are stored so I have a record to work from. See "How long I keep things" below.

That's the full list. I don't collect device fingerprints, precise location, contacts, or anything else that isn't in the sections above.

Where your data goes

Plant Tender relies on a few services to work. Here's exactly what leaves my servers and why:

  • Anthropic (Claude). When you take a photo to identify a plant, run the health diagnosis, or ask a support question, the image and the text go to Anthropic so Claude can read it and respond. Same for the meter OCR — the photo of your soil probe is sent to Claude to pull the numbers off the display. Per Anthropic's API terms, this data isn't used to train their models.
  • Resend. All outbound email (welcome messages, password resets, billing receipts, support replies) goes through Resend. Inbound email to my support addresses comes back to me through a Resend webhook and lands in the support agent.
  • Stripe. Card processing and subscription management. See above — I don't hold card data.
  • Google. When you sign in with Google, Google verifies who you are and hands me back an identity token containing your email, name, and profile picture. That's the only conversation Plant Tender has with Google.
  • Facebook (Meta). Three separate things, and I want to be precise: (1) if you sign in with Facebook, Meta hands me back your name and email, same as Google. (2) I use Meta's APIs to publish posts to Plant Tender's own Facebook Page, Instagram account, and Threads — outbound publishing on my behalf, none of your data involved. (3) When conversion reporting is switched on, my server reports each new signup to Meta so the ads that produce real users get credited. That report contains your email address hashed with SHA-256 (Meta compares the hash against its own records — the address itself never goes over in the clear), your IP address, your browser's user-agent string, and — if you came from a Meta ad — the click IDs from the pt_fbc and _fbp cookies described above. It's sent once, at signup, for every new signup regardless of how you found us, and it says nothing about your plants or anything you do inside the app. This is the one place data about you goes to an ad platform from my servers — the pixels below run in your own browser, on the public ad pages only. If it isn't live yet when you read this, it will only be turned on after this page already describes it — that's the order of operations I hold myself to.
  • Google Analytics. The public pages — the landing page, the blog, this page, the terms page, and the two ad landing pages — load Google's gtag.js so I can see which pages get read and which channels bring people in. Google sets its own cookies for that and sees your IP address and the pages you visited. The app itself — everything behind sign-in, where your plants live — carries no analytics script at all.
  • Meta Pixel. The page my Facebook and Instagram ads land on loads Meta's pixel so Meta can match ad clicks to signups. Meta sets its cookies and learns you visited that page (and, if you sign up there, that you signed up). It runs on that one ads landing page only — never inside the app.
  • Reddit Pixel. Same arrangement on the page my Reddit ads land on: Reddit's pixel reports the visit and the signup so Reddit optimizes my ads toward people who actually sign up rather than people who click. That one page only.

That's every third-party integration there is. The analytics tag and the ad pixels live only on the public marketing pages named above — inspect the network tab inside the app after you sign in and you'll see my servers and the services listed here, no pixels, no trackers, nothing else.

What I don't do

  • I don't sell your data. There is nobody I could sell it to that I'd want to.
  • I don't share your data with data brokers, and the only thing an advertiser ever gets from me is the signup report described under Facebook (Meta) above — a hashed email and click metadata that says "this ad produced a signup." Nothing about your plants, your photos, your readings, or anything you do inside the app goes to any ad platform, ever.
  • I don't send marketing blasts. Nearly all email from me is transactional — account setup, password resets, billing receipts, support replies to threads you started. The one exception is a short onboarding sequence: at most three emails, sent only if you signed up and haven't added a plant yet, each with a one-click unsubscribe link, and adding a plant ends it on its own. No newsletter, no re-engagement campaigns.
  • I don't follow you around the web. The ad pixels above run on their own landing pages so the ad platforms can count signups from ads they showed you; there is no pixel, tag, or fingerprinting anywhere inside the app, and I don't buy, build, or contribute to cross-site profiles.
  • I don't use your plant photos or readings to train any model, mine or anyone else's.

How long I keep things

The default is: your data stays as long as your account exists, and it's deleted when you delete your account.

If you (or, for members, your Home's owner) delete your account from the Home settings page, that removes every row tied to your Home ID — plants, readings, photos, uploads, users. It's a real delete, not an "archive" or a "soft delete with a hidden flag." Once it's gone I can't recover it, so make sure that's what you want.

Two things live a little differently:

  • Support conversations. I keep the transcript for up to two years so I can look up context if you come back with a follow-up, or in the rare case of a billing dispute. After that they get purged.
  • Billing records. Stripe keeps invoices and payment records on their side according to their own retention rules — I don't control that. On my side I keep enough to reconcile your subscription state.

What you can ask me to do

Email [email protected] and I'll:

  • Send you a copy of everything I have on your Home.
  • Fix anything that's wrong.
  • Delete your account (you can also do this yourself from the Home settings page in the app).
  • Answer any question about this page you'd like a human answer to.

I'm the person who reads that inbox. Usually within a day.

Kids

Plant Tender isn't for kids under 13. I don't knowingly collect data about children. If you're a parent and you think your child signed up, email me and I'll delete the account.

When this page changes

If I change something material — a new third-party service, a new category of data, a change to retention — I'll email active account owners before it takes effect and update the "last updated" line at the top.

If a change is cosmetic (fixing a typo, rewriting a sentence for clarity), I'll just do it.

Contact

[email protected] — for anything on this page, or about your data, or if you just want to tell me something's confusing. It's me on the other end.

← Home Terms →
Plant Tender — built because my ficus deserved better. Pricing · Blog · Privacy · Terms · Sign in