Legal

Privacy Policy

Last updated: July 20, 2026

Overview

Cambium is a plant-identification and care application provided by MaskedSyntax. You can scan plants and keep a local Garden without creating an account. Signing in is optional and enables private cross-device synchronization. This policy describes what Cambium actually does with your information today, not what we plan to build.

Information we process

  • Plant photos and scan results: every photo submitted for identification or diagnosis is sent from the app to CambiumRelay (our server), which forwards it to OpenAI's API to produce a result. This happens for every scan — Cambium does not identify plants on your device. CambiumRelay does not intentionally retain the submitted image after completing the request. OpenAI's handling of the image while processing it is governed by OpenAI's own API data usage policies, which are separate from this policy; under OpenAI's standard API terms, data sent through their API is not used to train their models.
  • Garden data: plant names, care information, photos, diagnoses, and saved scan history are stored on your device. If you sign in, this information is also stored in Cambium's private Supabase database and Storage bucket so it can sync across devices. Cloud rows and photos are restricted to your account by database access rules.
  • Account information: when you use Apple or Google sign-in, we receive an account identifier and available profile information, such as your name and email address. Supabase Auth manages the account session; Cambium does not receive or store your Apple or Google password.
  • Usage information: a randomly generated installation identifier and monthly scan and diagnosis counts are sent to CambiumRelay to enforce free-plan limits and prevent abuse. If you have an active subscription, your RevenueCat app user ID is sent so the relay can verify entitlement and bypass those limits.
  • Purchase information: Apple or Google processes payment details directly. Cambium uses RevenueCat to receive product and entitlement information needed to unlock paid features; neither Cambium nor RevenueCat receives your full card or bank details.
  • Support messages: if you contact support, we receive the information you choose to include, along with basic app version and platform diagnostics attached automatically by the in-app support form.

What Cambium does not do

Cambium does not sell personal information. Cambium does not include advertising SDKs, third-party analytics SDKs, or crash-reporting SDKs of any kind — we don't know how many sessions you have, what you tap, or how long you use the app, because we don't instrument for it. We do not use your photos to train a Cambium model. Watering and care reminders are scheduled entirely on your device; no notification content or push token is sent to a server.

How information is used

We use this information to identify plants, provide diagnoses and care guidance, save and sync your Garden, operate purchases, enforce usage limits, respond to support requests, and protect the service.

Service providers

Cambium relies on Supabase for authentication, database, and private photo storage; Cloudflare for CambiumRelay and usage counters; OpenAI for image-based plant analysis; RevenueCat for purchase entitlement management; and Apple or Google for sign-in, distribution, and payment processing. These providers process information only as needed to provide their services and under their own applicable terms and privacy policies.

Retention and deletion

Local Garden data remains on your device until you delete the relevant plant data, clear the app's storage, or uninstall the app. Synced Garden data — including plants, care profiles, scans, diagnoses, treatment steps, recovery episodes, and stored scan photos — remains in Supabase while your account is active.

Account deletion is currently a manual, request-based process: email us or use our account deletion page. When we complete a deletion request, we delete your account and its associated database records and stored photos. We aim to complete verified requests within 30 days. Deleting your account does not remove data that only exists locally on a device — remove that by deleting the relevant plants in the app or uninstalling it.

Your choices

  • Use scanning and local Garden storage without signing in.
  • Export your local data as JSON from Profile → Export my data.
  • Disable notification permission in your device settings.
  • Sign out from Profile at any time.
  • Request deletion of your account and cloud-synced data at any time (see above).
  • Manage or cancel a subscription through Profile → Manage store subscription, or directly in your App Store or Google Play account.

Children

Cambium is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Changes and contact

We may update this policy when the product or legal requirements change. The updated date will be shown above. Questions or privacy requests can be sent to [email protected], or see our Support page.

← Back to Cambium