Legal

Privacy Policy

Last updated 11 September 2026

ChloroFile is a grow journal for iPhone and Android. This policy explains exactly what it collects, what it does not, and what control you have. It is written to describe how the app actually behaves rather than to reserve rights we do not use.

The short version. The app works fully without an account, and your grow records stay on your device until you choose to sign in. Your photos never leave your device at all. There is no advertising in the app and nothing follows you across other apps or websites. This website is a separate matter and some of its pages do carry an affiliate banner, described below.

Signing in is optional on both iPhone and Android, and adds a backup and sync across your own devices. On iPhone, and only on iPhone, the app reports a short list of measurement events so we can tell which adverts led to an install. It is named in full below, it carries none of what you write in the app, and it is the one thing on this page that changed on 6 September 2026. It used to say there was no analytics of any kind, and until that date there was none.

Who we are

ChloroFile is an app for iPhone and Android, made and operated by its independent developer, based in Minnesota, United States, and contactable at support@chlorofile.app. Where UK or EU data protection law applies, we are the data controller for the information described below.

What differs between iPhone and Android

Almost nothing. Both apps work fully without an account, both can sign in for backup and sync, both store the same records and no more, and both let you delete the account from inside the app. What you sign in with differs, because the platforms do: iPhone offers Sign in with Apple, Android offers Sign in with Google, and both offer an email address and a password for anyone who would rather use neither.

The one real difference is measurement. The Android app contains no measurement software of any kind and reports nothing: the install numbers for Android come from Google Play itself, which needs nothing inside the app. The measurement section below therefore describes the iPhone app only. Everything else on this page applies to both.

Everything under What we never collect is true of both.

Using ChloroFile without an account

You can install and use every feature of ChloroFile without creating an account, signing in, or connecting to the internet. Used this way, your grow records exist only on your device: no plant, log entry, reading, note or photo is sent anywhere, and nothing you write in the app reaches us.

On iPhone the app does report the measurement events described in the next section, whether or not you sign in. Those are counts of actions, not the content of them, and they are the only thing the app sends without an account.

What we collect if you sign in

Signing in is entirely optional, and exists so your records can be backed up and kept in step across your own devices. If you do sign in, the following is stored on our hosting provider's servers:

DataWhy
Your email address To identify your account and let you sign back in. On iPhone, if you use Sign in with Apple and choose Hide My Email, we only ever receive Apple's private relay address, never your real one. Sign in with Google passes us the address on that Google account, and nothing else from it: no contacts, no profile, no access to anything in your Google account.
Your grow records: plants, varieties, stages and dates, log entries (temperature, humidity, pH, EC, water, height, notes), environments, equipment, and harvest weights This is the content you create in the app. It is stored so it can be restored and synced.
Account timestamps When your account was created and when records were last changed, used to resolve which version of a record is newest.

Measurement on iPhone

We advertise the app, and adverts cost money. Apple gives an advertiser no way to know whether an advert led to an install unless measurement software is inside the app itself. So on iPhone, ChloroFile includes Google Analytics for Firebase, limited as far as it can be while still answering that one question. On Android the same question is answered by Google Play, so the Android app carries nothing.

Every event the app sends, in full:

EventWhat it carries
First openNothing beyond the fact of a first launch.
A plant was addedWhether a variety was chosen from the catalogue. Not which one, and not the plant's name.
A log entry was writtenHow many plants it was saved against. None of the readings, and none of the notes.
A subscription was boughtWhich plan, and whether it was a trial.

Firebase also records, on its own, that a session started and roughly how long the app was open, along with your device model, operating system version, app version, language, and an approximate region worked out from your IP address. It creates a random identifier for your installation of the app, which is reset if you delete and reinstall.

What it deliberately does not do. It does not use your device's advertising identifier, and the library that would read one is not built into the app, so no tracking permission prompt is shown and nothing here can follow you into another app or website. Screen tracking is switched off, so we cannot see which screens you open. It carries no plant names, varieties, readings, notes, photos, harvest weights, email address or account identity. Google acts as our processor for these events and does not receive your grow records.

What we never collect

How your data is used

Your data is used for exactly one purpose: operating the app for you. Specifically, to authenticate you, to store your records, and to sync them to your other devices. We do not use it to build profiles, we do not analyse it in aggregate, and we do not use it to train anything.

We do not sell your data, and we do not share it with advertisers or data brokers. There is no such arrangement, and no third party receives your grow records.

Where your data is stored

If you sign in, your data is stored using Supabase, which provides our database and authentication and acts as our data processor. Data travels over encrypted connections (HTTPS/TLS) and is encrypted at rest.

Access is restricted at the database level: every record is tied to your account, and the security rules on our database make it impossible for one account to read another's records, including via the app's public key.

Apple is involved on iPhone if you choose Sign in with Apple, which verifies your identity and returns either your email address or a private relay address. Apple's handling of that is covered by Apple's own privacy policy.

Google receives the measurement events listed under Measurement on iPhone, and nothing else. It does not receive your grow records, your photos or your email address. Google's handling of that data is covered by Firebase's privacy documentation.

How long we keep it

Your records are kept for as long as your account exists. When you delete your account, they are deleted immediately as described below. If you never sign in, there are no grow records for us to keep. The iPhone measurement events described above are held by Google under its own retention policy and are not tied to an account, so there is nothing there to delete on request either; deleting and reinstalling the app resets the random installation identifier they are grouped by.

Deleting your account and data

You can delete your account from inside the app at any time:

This permanently deletes your account and every record synced to it: plants, logs, environments, equipment, and harvests. The copies held on that device are removed at the same time. The deletion is immediate and cannot be undone, and we do not retain a backup copy of deleted accounts.

If you cannot access the app, email support@chlorofile.app from the address on the account and we will delete it for you.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, to object to or restrict its processing, and to complain to a data protection authority. The app already gives you direct access to all of your data and the ability to delete it. For anything else, write to support@chlorofile.app and we will respond within 30 days.

US residents: we do not sell or share personal information, and have not done so in the preceding 12 months. Depending on your state, you may have rights to know what we hold, to have it corrected or deleted, and not to be discriminated against for exercising them. Deleting your account from Settings exercises the deletion right directly; for anything else, write to us.

Children

ChloroFile is intended for adults. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us and we will remove it.

Variety reference data

The variety catalog bundled with the app is compiled reference data drawn from breeder catalogs and openly licensed datasets. It describes varieties in general and is not a measurement of, or a claim about, the plant in front of you. Nothing in the app is advice of any kind.

This website

Everything above describes the app. The website is a separate thing: it has no account, no sign-in, and none of your grow records exist here at all, so there is nothing of yours here to collect.

Analytics. Pages on chlorofile.app load Google Analytics, which records the page you looked at, roughly where in the world you are, and what kind of device you used. We read it to see which reference pages people actually reach. It is not joined to anything in the app, and it cannot be, because this site has no idea who you are.

Affiliate banners. Some pages carry an advertisement for a company whose products growers buy. If you click one and go on to buy something, we are paid a commission, at no extra cost to you. That is the whole arrangement. Nobody pays for a favourable mention, the catalog is not ordered, filtered, or written around who advertises, and no advertiser has any say in what the reference data says about anything.

These banners come from advertising networks, which means they are somebody else's code. Each one is loaded inside a sandboxed frame: it draws itself and counts its own view, but it cannot read the page around it, cannot see anything else you have looked at on this site, and cannot store anything under chlorofile.app. If a network ever has to run outside that sandbox to work at all, this paragraph will say so before it does.

Clicking a banner takes you to the advertiser's own site, where their privacy policy applies and this one does not. They will normally record the click so the sale can be credited, which is how the commission is worked out.

Which banners are running is held in the same Supabase project the app uses, and your browser asks it for that list once per visit. Supabase sees the request and your IP address in the course of answering it, as any host would. No grow records are involved, because a browser on this site has none: the site cannot read what is in the app.

The home page, the privacy policy, the terms, and the support page never carry advertising.

Changes to this policy

If this policy changes, the date at the top will be updated, and material changes will be noted in the app's release notes. We will not retroactively reduce your privacy protections for data already collected without telling you.

Contact

Questions about this policy or your data: support@chlorofile.app