Legal

Privacy Policy

Last updated: May 11, 2026

The short version: Petla stores the account, profile, plant, journal, community, subscription, and notification data needed to run the app. We do not sell personal data.

Who we are

Petla is operated by Kameleonic Design, based in England, UK. When this policy refers to "Petla", "we", "us", or "our", it means Kameleonic Design trading as Petla.

Correspondence address: Unit 167204, PO Box 7169, Poole, BH15 9EL.

You can contact us at hello@petla.uk.

What this policy covers

This policy covers the Petla mobile app, the Petla website at petla.uk, and the related support, legal, referral, and account pages we operate.

Data we collect

Depending on how you use Petla, we may collect and store:

How we use your data

We use your data to provide and operate Petla, including account creation, sign-in, profile display, plant care features, journals, community features, swaps, weather-aware reminders, plant identification, subscriptions, push notifications, support, safety, troubleshooting, and fraud or abuse prevention.

Core service providers and processors

Petla uses the following service providers to operate the app:

International data transfers

Some of Petla's service providers are based outside the UK. Where personal data is transferred internationally, Petla relies on the following mechanisms:

For provider Data Processing Agreements or privacy addenda, links are available on request at hello@petla.uk.

Photos and plant identification

Photos you upload to Petla are used for the feature you chose, such as avatars, journals, community posts, swap listings, or garden images.

If you use plant identification, the image you submit is sent for processing through Petla's backend to Plant.id. Petla stores the identification result and image hash needed for the feature. The app does not keep the original identification photo as part of the long-term identification cache.

If you upload a community post image, Petla may also send that image through backend moderation checks using Google Vision SafeSearch so we can operate community safety controls.

Social sign-in

If you choose Google sign-in, Petla uses Google through Supabase Auth to complete authentication and create or access your Petla account.

Community and user-generated content

Profile details, community posts, comments, shared garden details, and swap listings may be visible to other users where the relevant feature is designed to be social or public within the app.

Location data

Petla uses approximate location information that you enter, such as a postcode or location text, to support weather-aware reminders, frost alerts, and location display features. For postcode-based weather features, Petla's backend currently uses postcodes.io and Met Office Weather DataHub. We do not state that the app collects precise GPS location in this policy.

Subscriptions

If you subscribe, RevenueCat and the relevant app store billing provider process purchase and entitlement data so Petla can unlock paid features. Petla account deletion does not itself cancel an app store subscription. You must manage or cancel recurring billing in Google Play or the App Store.

Push notifications

If you enable notifications, Petla uses OneSignal to route pushes to your device and associate notification delivery with your Petla account. This may involve app or service identifiers used for push delivery.

Analytics and service operations

Petla does not use a third-party mobile analytics SDK in the audited app build. Petla does log first-party operational events to Supabase, including events such as journal activity metadata and notification-open events.

Ask Petla

If you use Ask Petla, the prompts or messages you submit are sent to Petla's backend to generate a response. Those prompts, related plant context, and response records may be processed or stored through service providers including OpenAI (US) or Hugging Face (US), depending on system configuration at the time of your request. Do not submit sensitive personal data that is not necessary for your request.

Legal bases

Under UK GDPR Article 13(1)(c), we are required to state the specific legal basis for each processing activity:

How long we keep data

We retain data for the periods set out below, or longer where required by law or for the defence of legal claims:

Deletion and export

You can request deletion of your Petla account and Petla-stored data in the app, or through our account deletion page at petla.uk/account/delete. You can also export a JSON copy of your account data from the Settings screen before deleting your account.

Some provider-managed records, such as app store billing history, provider-side service identifiers, or third-party processor records retained under their own policies, may be retained separately under those providers' policies.

Security

Petla is intended to use encrypted HTTPS connections for production traffic. We also rely on our infrastructure providers' security controls for storage and service delivery.

Your rights

Subject to applicable law, you may have rights to access, correct, delete, restrict, object to, or export personal data we hold about you, and to lodge a complaint with the Information Commissioner's Office.

Where we process your data on the basis of consent — for example, push notifications or optional profile details — you have the right to withdraw that consent at any time. You can do this by disabling notifications in your device settings or removing optional profile information in the app. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

To exercise your rights or ask a privacy question, email hello@petla.uk.

Changes to this policy

If we make material changes, we will update the date at the top of this page and publish the revised version here.

Contact

Questions about this policy or how Petla handles data: hello@petla.uk