Use this as a practical draft for the public Privacy Policy URL required by App Store Connect. This is implementation-support drafting, not legal advice. Final legal review is required before public launch.
YardGuardian Privacy Policy
Effective date: [TODO: final effective date]
Operator: [TODO: final legal company/operator name]
Contact: support@yardguardianai.com
YardGuardian helps homeowners create AI landscape and garden design ideas from yard photos, project instructions, ZIP-code climate context, plant preferences, and design goals. This policy explains what information YardGuardian may collect, how it is collected, how it is used, when service providers process it, how long it may be kept, and how users can clear local Profile data or make privacy requests.
Information YardGuardian May Collect
YardGuardian may collect or process information users choose to provide, including:
Yard photos selected from the photo library through Apple's photo picker
Photos added as reference images or custom project assets
Mask/mark-up information showing areas to keep, change, or remove
Project names, yard type, design style, goals, constraints, requested features, and revision instructions
Free-form project notes or prompts
ZIP code or manually entered climate/location context used to estimate plant hardiness guidance
Sun, slope, moisture, drainage, family, pet, HOA, and watering preferences selected in the app
Generated design summaries, plant notes, warnings, before/after previews, exported plans, and related project content
Optional local Profile details such as first name, last name, email address, city, and state when users choose to enter them
Purchase, subscription, product, entitlement, restore, and available-design status
A RevenueCat app user ID generated by the app and stored in the device Keychain
Basic app state stored on the device, such as saved projects, draft projects, plant favorites, hidden plant-risk preferences, review-prompt state, default ZIP code, and design-credit history
Support emails and any information users choose to include when contacting support
Backend request and diagnostic metadata, such as request status, content length, whether a photo or mask was attached, generation mode, usage counts returned by AI providers, rate-limit/quota status, app version if supplied, and error state
YardGuardian does not require users to create an account for the current app flow.
How Information Is Collected
YardGuardian collects information in these ways:
Directly from users when they choose photos, enter ZIP codes, write instructions, choose goals, mark areas in a photo, save projects, revise designs, export plans, or contact support
Automatically from app operation when YardGuardian saves local projects, draft projects, design-credit state, review-prompt state, plant preferences, and selected app settings on the user's device
Through Apple's in-app purchase system and RevenueCat when users view plans, buy subscriptions or design bundles, restore purchases, or when the app verifies entitlement status
Through backend requests when the app sends generation inputs to YardGuardian's backend to create AI design outputs
Through server logs and diagnostics needed to secure, debug, rate limit, validate entitlements, and operate the service
Photos And Photo Picker Access
YardGuardian uses Apple's photo picker where available so users can choose specific photos instead of granting access to the full photo library.
The code reviewed for this draft uses selected photos and does not currently include a separate in-app camera capture flow. If camera capture is added later, YardGuardian should update the app permission prompt and this policy before release.
Selected photos may be resized, compressed, saved locally in the user's project, sent to YardGuardian's backend, and sent to AI service providers as needed to generate design previews, revisions, plant and planning guidance, saved projects, exports, and support troubleshooting requested by the user.
Users should not upload photos that contain sensitive personal information they do not want processed for landscape design.
ZIP Code And Climate Guidance
YardGuardian uses manually entered ZIP code or similar climate context to estimate plant hardiness guidance and improve design recommendations.
YardGuardian does not currently need precise GPS location for the core design flow based on the code reviewed for this draft. If precise location services are added later, this policy and the app's permission prompts should be updated before release.
ZIP-code climate guidance is approximate. Users should confirm local plant suitability, microclimate, availability, and installation details before spending money or starting work.
How YardGuardian Uses Information
YardGuardian may use collected information to:
Generate AI landscape and garden design previews
Create revisions from user instructions
Create plant, hardscape, climate, safety, watering, and planning notes
Save and display projects, drafts, reference photos, generated images, and plan details in the app
Create shareable exports or contractor planning documents
Estimate plant fit from ZIP-code and project context
Process purchases, subscriptions, design bundles, entitlements, restores, free previews, and available-design limits
Prevent abuse, duplicate charges, quota mistakes, reinstall-based preview abuse, and unauthorized backend use
Troubleshoot generation, image, purchase, restore, quota, support, and app issues
Maintain service security, reliability, debugging, and rate limits
Respond to support requests and privacy/support-record deletion requests
AI Processing
YardGuardian uses AI services to create design plans, generated images, plant notes, and planning guidance. Photos, masks, ZIP-code context, project instructions, selected goals, plant candidates, reference images, and revision instructions may be sent to YardGuardian's backend and AI providers as needed to generate results.
AI outputs may be inaccurate, incomplete, unrealistic, outdated, or unsuitable for a specific property. Users should verify measurements, property lines, grading, drainage, utilities, easements, HOA rules, permits, local codes, plant safety, plant availability, and installation details before spending money or starting work.
TODO: Brian should confirm AI provider data retention settings, whether provider opt-out or zero-retention settings are configured, and whether generated images are stored server-side.
Purchases And RevenueCat
YardGuardian uses Apple's in-app purchase system and RevenueCat to display plans, process purchases, restore purchases, check entitlements, manage available designs, and reduce purchase or quota errors.
The app generates a RevenueCat app user ID before configuring RevenueCat. The current implementation stores this identifier as a non-synchronizing Keychain item so it can remain stable on the same device across app deletion and reinstall. This identifier is intended for purchase entitlement and preview-abuse resistance. It is not a user account and does not provide cross-device identity by itself.
The app may send the RevenueCat app user ID to YardGuardian's backend so the backend can verify entitlements with RevenueCat before generating paid designs.
App Store purchases, subscriptions, renewals, cancellations, and refunds are handled through Apple. Some purchase and receipt records may remain with Apple or RevenueCat as needed for billing, receipts, fraud prevention, tax, accounting, legal compliance, and purchase restoration.
TODO: Brian should confirm whether RevenueCat customer IDs are anonymous only or linked to any email/account in production, and how this should be represented in App Store privacy labels.
Local Device Storage
YardGuardian stores some information locally on the user's device using app storage, UserDefaults, and Keychain. This may include:
Saved projects and draft projects
Selected/compressed yard photos and generated images saved as part of projects
Project names, ZIP codes, instructions, constraints, requested features, site conditions, mask strokes, custom reference assets, and generated design content
Optional local Profile details, default ZIP code, plant favorites, hidden plant-risk tags, local notification preference, local onboarding/session state, review-prompt state, design-credit state, and local entitlement state
The non-synchronizing Keychain RevenueCat app user ID
Internal tester access state if configured for private testing
Users can remove saved projects inside the app where deletion controls are available. Users can also clear local Profile details, the local notification preference, and local Profile/session state from the Profile screen. Deleting the app may remove app-storage data, but Keychain items can persist across reinstall on the same device.
Backend Logs, Rate Limits, And Diagnostics
YardGuardian's backend may process request metadata needed to operate the service, including request timing, request size, route, generation mode, whether a photo/mask was attached, plant-candidate count, product/entitlement status, rate-limit and quota counters, idempotency request IDs, AI usage counts, and safe error details.
The code reviewed for this draft is designed to avoid logging full prompts, uploaded photos, base64 image data, API keys, Redis tokens, RevenueCat secrets, or tester bypass token values in diagnostics. Users should still avoid sending unnecessary sensitive information in prompts, support emails, or photos.
The backend may use IP address or forwarded IP address to apply short-term rate limits before reading generation requests.
TODO: Brian should confirm final hosting/server log retention, whether logs are exported to any observability provider, whether generated images are stored outside the immediate response flow, and the retention duration for backend idempotency, quota, rate-limit, and diagnostic records.
Third-Party Service Providers
YardGuardian may share limited information with service providers needed to operate the app, including:
Apple App Store and StoreKit for in-app purchases, subscriptions, restores, refunds, and app distribution
RevenueCat for purchase products, customer IDs, subscription status, entitlements, restores, and purchase support
AI providers, including OpenAI, for design plans, generated images, and AI landscape guidance
Backend hosting providers, including Vercel or other configured hosting, for public pages and backend generation requests
Usage or storage providers, such as Redis-compatible usage storage if configured, for quotas, rate limits, and idempotency records
Email providers used by the user's email app or YardGuardian support inbox when a user contacts support
Apple review prompt and system services when the app requests an App Store review
TODO: Brian should confirm the final production hosting, logging, support email, Redis/usage-storage, analytics, crash-reporting, and AI-provider configuration before publication.
Analytics, Crash Reporting, Tracking, And Advertising
The current code review did not find Firebase, Sentry, Mixpanel, Amplitude, or another separate third-party analytics or crash-reporting SDK in the iOS app.
YardGuardian does not sell user-uploaded yard photos.
YardGuardian does not use uploaded yard photos for third-party advertising.
TODO: Do not claim "no tracking" or "Data Not Collected" in App Store Connect until Brian confirms the final production analytics, crash-reporting, hosting logs, support tooling, and provider settings.
If advertising, tracking, analytics, crash reporting, or logging practices change, this policy and App Store privacy details should be updated before release.
Data Retention
YardGuardian keeps information only as long as needed to provide the app, maintain saved projects, process purchases, enforce quotas and rate limits, troubleshoot issues, respond to support, comply with legal obligations, and improve service reliability.
Local projects and drafts may remain on the user's device until the user deletes them, clears app data, or deletes the app. Some Keychain data may persist across reinstall on the same device.
Backend idempotency results are currently designed to expire after about 24 hours in code. Other backend usage, quota, support, server log, uploaded photo, generated image, and diagnostic retention periods require final confirmation.
TODO: Brian should confirm:
Backend retention duration for uploaded photos
Backend retention duration for generated images
Whether generated images are stored server-side after being returned to the app
Retention duration for server logs and diagnostics
Retention duration for Redis or other usage/quota records
Support email retention duration
Whether AI provider retention settings are configured
User Choices And Privacy Requests
Users can choose whether to upload photos, enter ZIP codes, add instructions, save projects, create exports, buy plans, restore purchases, or contact support.
Users can stop using photos, remove saved projects in the app where available, clear local Profile details and local Profile/session state from the Profile screen, and manage any future camera or photo permissions through iOS Settings if those permission-based features are added.
Users can manage or cancel subscriptions through their Apple account settings.
Clearing local Profile data in the app does not cancel Apple subscription billing, delete Apple purchase history, delete RevenueCat purchase records, clear the RevenueCat Keychain app user ID, delete saved projects, or delete backend/server/provider records that may be retained for service, security, legal, accounting, troubleshooting, or purchase-restoration reasons.
Users can request deletion of support records or other personal information associated with support conversations by contacting:
support@yardguardianai.com
Privacy requests should include enough information for YardGuardian to identify the relevant support conversation or records. Users should not include passwords, full payment card numbers, API keys, or sensitive/private photos unless support specifically asks for them through a secure process.
Some records may remain with Apple, RevenueCat, hosting providers, or other service providers as needed for receipts, fraud prevention, security, tax, accounting, legal compliance, dispute handling, and purchase restoration.
Children
YardGuardian is not intended for children under 13. YardGuardian is not currently planned as a Kids Category app unless Brian later decides otherwise and updates the product, privacy practices, and App Store settings accordingly.
Security
YardGuardian uses reasonable technical and operational measures intended to protect information processed by the app and backend. No method of transmission or storage is completely secure.
Users should avoid uploading unnecessary sensitive information in photos or instructions, and should not send passwords, full payment card numbers, API keys, or sensitive/private photos through support unless specifically requested through a secure process.
Availability
TODO: Brian should confirm whether YardGuardian will be available only in the United States at launch. If launch is U.S.-only, add a clear U.S.-only availability note here and in App Store submission materials.
Changes To This Policy
YardGuardian may update this Privacy Policy as the app, backend, providers, or legal requirements change. The updated policy should include a new effective date. Material privacy changes should be reflected in the app, public website, and App Store Connect metadata as appropriate.
Contact
Support email: support@yardguardianai.com
Support URL: https://yardguardianai.com/support
Privacy Policy URL: https://yardguardianai.com/privacy
Operator/company: [TODO: final legal company/operator name]
Business address: [TODO: final business address, if needed]
App Store Privacy Label Planning
This planning section is for Brian's App Store Connect review and final legal/privacy review. It should not be published as user-facing policy text unless intentionally included.
Likely data categories to review:
User Content: Photos or Videos, because selected yard photos, custom reference photos, masks, and generated images may be saved locally and transmitted for AI processing
User Content: Other User Content, because project names, instructions, goals, constraints, custom asset notes, revision prompts, generated summaries, plant notes, and exports may be processed
Location: Coarse Location, only if ZIP code or ZIP-derived climate/zone guidance is treated as coarse location in App Store Connect
Purchases, because subscriptions, design bundles, entitlement status, restores, and product IDs are processed through Apple and RevenueCat
Identifiers, because a RevenueCat app user ID is generated and used for purchase entitlement checks, quota enforcement, and backend verification
Diagnostics, if server logs, support diagnostics, request status, error state, app version, device details, or generation diagnostics are collected or retained
Usage Data, only if analytics, event logging, rate limits, quota counters, or feature-usage records are treated as usage data under App Store Connect definitions
Do not claim "Data Not Collected" if photos, prompts, ZIP code, purchase status, identifiers, diagnostics, or support emails are transmitted off-device or retained.
Do not claim data is "not linked to user" unless Brian confirms the final technical implementation, provider settings, and App Store Connect definitions support that answer.
TODOs for Brian before App Store submission:
Confirm backend retention duration for uploaded photos
Confirm whether generated images are stored server-side
Confirm AI provider data retention settings
Confirm whether RevenueCat customer IDs are anonymous or linked to user email/account
Confirm whether any analytics SDKs, crash SDKs, log drains, or support tooling are used in production
Confirm whether App Store privacy labels should list data as linked to the user
Confirm final privacy/legal language for local Profile clearing, backend/provider retention, and Apple subscription billing being handled separately
Confirm final legal company/operator name
Confirm final business address, if needed
Confirm whether the app is U.S.-only at launch
Confirm final support email and support workflow