Legal

Privacy Policy

Last updated: August 9, 2026

Overview

Cambium is a plant-identification and care application provided by MaskedSyntax. It does not require or offer an account. Your Garden is stored locally on your iPhone. Plant photos are sent for analysis only when you choose to identify a plant or check its visible health. This policy describes what Cambium does today.

Information we process

  • Plant photos and scan results: every photo submitted for identification or diagnosis is sent from the app to CambiumRelay (our server), which forwards it to OpenAI's API to produce a result. This happens for every scan — Cambium does not identify plants on your device. CambiumRelay does not intentionally retain the submitted image after completing the request. OpenAI's handling of the image while processing it is governed by OpenAI's own API data usage policies, which are separate from this policy; under OpenAI's standard API terms, data sent through their API is not used to train their models.
  • Garden data: plant names, care information, photos, diagnoses, notes, treatment progress, and scan history are stored on your iPhone using Apple’s local data storage. Cambium does not upload this Garden to a cloud database. An export leaves the app only when you explicitly share the generated file.
  • Usage information: a randomly generated installation identifier and monthly scan and diagnosis counts are sent to CambiumRelay to enforce free-plan limits and prevent abuse. If you have an active purchase, the App Store receipt for that purchase, signed by Apple, is sent so the relay can confirm it and bypass those limits. It identifies which Cambium product you bought and when it expires. It never includes card or bank details, and the relay verifies it and discards it rather than storing it. Cambium can also send optional, aggregate product events such as onboarding completion, scan success, or a broad error category. These events do not include photos, plant names, results, diagnoses, notes, account identifiers, advertising identifiers, or the installation identifier, and can be disabled in Settings.
  • Purchase information: Apple processes payment details directly and is the only payment processor. Cambium receives only what unlocking paid features requires — the product and its expiry — and never your card or bank details.
  • Support messages: if you contact support, we receive the information you choose to include, along with basic app version and platform diagnostics attached automatically by the in-app support form.

What Cambium does not do

Cambium does not sell personal information. Cambium does not include advertising SDKs, third-party analytics SDKs, or crash-reporting SDKs of any kind. Optional first-party aggregate product metrics do not create a behavioral profile and are retained for no more than 30 days. We do not use your photos to train a Cambium model. Watering and care reminders are scheduled entirely on your device; no notification content or push token is sent to a server.

How information is used

We use this information to identify plants, provide visible-health and care guidance, operate purchases, enforce usage limits, respond to support requests, and protect the service.

Service providers

Cambium relies on Cloudflare for CambiumRelay and anonymous usage counters; OpenAI for image-based plant analysis; and Apple for local app storage, distribution, and payment processing. Cambium sends OpenAI a hashed safety identifier rather than its installation UUID and requests that API responses are not stored. These providers process information only as needed to provide their services and under their own applicable terms and privacy policies.

Retention and deletion

Local Garden data remains on your device until you delete a plant, choose Delete all local data in Settings, or uninstall the app. CambiumRelay keeps monthly counters associated with a random installation identifier only as long as needed to enforce the free tier.

There is no Cambium account or cloud Garden to request that we delete. See our data deletion instructions for local deletion and monthly-usage identity reset. Support messages remain in our support mailbox as needed to respond and maintain ordinary business records.

Your choices

  • Use scanning and local Garden storage without an account.
  • Export your local data as JSON from Settings → Export my data.
  • Delete all Garden data and optionally reset the usage identity from Settings.
  • Disable notification permission in your device settings.
  • Manage or cancel a subscription through Settings → Manage subscription, or directly in your App Store account.

Children

Cambium is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Changes and contact

We may update this policy when the product or legal requirements change. The updated date will be shown above. Questions or privacy requests can be sent to [email protected], or see our Support page.

← Back to Cambium