Privacy Policy

Last updated: 24 August 2026

This Privacy Policy explains how Zohho Ltd (“we”, “us”, “our”) collects, uses, and protects your personal data when you use the Folly mobile app (“Folly” or the “App”). Zohho Ltd is a company registered in the United Kingdom and is the data controller for the purposes of UK data protection law (UK GDPR and the Data Protection Act 2018).

If you have any questions, contact us at [email protected].

1. Information we collect

We collect the following categories of data, depending on how you use Folly:

  • Account information: You can use Folly without creating an account. In that case we create a guest profile for you, identified only by a random identifier, with no email address or name attached. If you later create an account, or sign in with email, Google, or Apple, we collect your email address, display name, and a provider identifier, and these are linked to the same profile so your content is kept. Authentication is handled by Supabase.
  • Content you provide: Plant photos you capture or upload, plus the plants, sites, notes, and care details you add. Photos are processed to identify plants and diagnose issues (see Section 3).
  • Location data: If you grant permission, your approximate or precise location is used to provide local weather, climate, and site-specific care features. You can decline or revoke this at any time in your device settings.
  • Device and notification data: A push notification token (via Expo) so we can send care reminders and weather alerts you have enabled, and basic device information.
  • Purchase and subscription data: Your subscription status, entitlements, and transaction identifiers, processed through RevenueCat and the Google Play or Apple App Store. We never receive or store your full payment card details; those are handled by the app store.
  • Usage and diagnostics: App analytics events (via PostHog) and crash and error reports (via Sentry) to keep Folly stable and improve it. Analytics events record in-app actions such as screens viewed, scans performed, plants added, and care tasks completed, together with your account identifier, app version, and basic device information. Crash reports also carry your account identifier, so that we can tell whether an error affected one person or many. They never carry your email address or your name.
  • Session recordings: PostHog can record a sample of app sessions as a sequence of screenshots, so we can see where people get stuck. Recording is limited to a small proportion of users at any time. Images and text you type are masked on your device before anything is uploaded, so your plant photographs and anything you enter, including your email address, are not readable in a recording.
  • Ad measurement data: Whether this applies to you depends on where you are. In the UK and the European Economic Area we ask first and it is off unless you say yes. In the United States it is on by default and there is a switch to turn it off. See Section 5, which explains which applies to you, exactly what is shared, who with, and how to turn it off.
  • How you found us, on Android: When you install Folly from Google Play, Play passes the App a note of which advert or link you arrived from. We read it once, keep only the campaign name it resolves to, and store that against your profile. It holds no advertising identifier, we never keep the raw note, and it is never shared with anyone. See Section 5.

2. How we use your data

  • Provide and operate Folly, including plant identification, diagnosis, and care plans.
  • Send the care reminders and weather alerts you choose to enable.
  • Process and manage subscriptions, trials, and scan credits.
  • Provide customer support and respond to your requests.
  • Maintain security, prevent abuse, and comply with our legal obligations.
  • Understand usage and improve features and reliability.
  • Measure which adverts bring people to Folly, so that we spend less on advertising and more on the App. Whether we ask you first depends on where you are, and you can turn it off wherever you are (Section 5).

3. Photos and AI processing

When you scan or upload a plant photo, the image and limited related data are sent to our processing providers, including a specialist plant identification service for identification and health assessment, and OpenAI for diagnosis and care guidance. These providers process the image to return results to you and act under our instructions as processors. AI-generated results are for general informational purposes only and may be inaccurate (see our Terms of Service).

4. Service providers and sharing

We do not sell your personal data. We share data only with providers that help us run Folly, under appropriate data protection terms:

  • Supabase: authentication, database, and storage (backend).
  • A specialist plant identification service and OpenAI: plant identification and diagnosis.
  • RevenueCat, Google Play, and Apple: subscription processing.
  • PostHog: product analytics and session recordings, hosted in the European Union (Frankfurt). Sentry: crash and error reporting.
  • Expo: push notification delivery, which reaches your device through Google Firebase Cloud Messaging on Android and the Apple Push Notification service on iOS.
  • Open-Meteo, OpenWeatherMap, and OpenStreetMap (Nominatim): weather, climate, and geocoding from location data.
  • AppsFlyer, and the advertising networks named in Section 5: ad measurement. Only while ad measurement is on for you, which depends on your region and on your own choice (Section 5).

We may also disclose data where required by law or to protect our rights, users, or the public.

5. Ad measurement and your choice

If we pay to advertise Folly, we want to know which adverts actually bring people to the App, so that we can stop paying for the ones that do not. Doing that means sharing a small amount of data with a measurement provider, AppsFlyer Ltd, and with the advertising network the advert ran on. Because this is advertising rather than something Folly needs to work, we ask first.

In the UK and the European Economic Area, it is off unless you say yes. We ask once during onboarding. Until you turn it on, the AppsFlyer software does not run and nothing described in this section leaves your device. Declining changes nothing about how Folly works.

In the United States, it is on and you can turn it off. US state privacy laws work the other way round from UK and EU law: measurement of this kind may run by default so long as you are told and given a clear way to stop it. So we do not interrupt onboarding with a question there. This policy is the notice, and the switch described below is the way to stop it.

The switch is the same one either way. It is in the App under Settings, then Privacy and data, then Ad measurement, it shows you what is actually happening, and it is yours to change at any time. Turning it off stops the AppsFlyer software and removes your advertising identifiers from our records. Your own choice always wins over the regional default, in both directions, and it survives signing out and signing back in.

We work out which of the two applies from two things your device already tells us: its region setting and its time zone. We only treat you as being in the United States when both agree. Anything else, including any disagreement between them, is treated as the UK and EEA, so the worst that happens is that we ask someone we did not have to.

On iOS, Apple also asks for its own permission before an app may use the advertising identifier. That prompt appears after ours, and you can decline either one.

What is shared when it is on:

  • Your device advertising identifier, which is the Google Advertising ID on Android or the Advertising Identifier (IDFA) on iOS, along with an install identifier that AppsFlyer assigns to the App on your device.
  • Which advert or campaign you arrived from, and basic technical information such as device type, operating system version, and approximate location derived from your IP address.
  • Your account identifier, so that activity on the same account can be recognised across your devices.
  • A short, fixed list of in-app milestones: finishing onboarding, creating an account, adding a plant, completing a scan, setting up Smart Care, allowing notifications, viewing the paid plan, and reaching a second plant in your garden.
  • Subscription and one-off purchases, including the amount and currency, sent from RevenueCat rather than from the App.

What is never shared: your plant photographs, your plants, sites or notes, your email address, and your name. Session recordings are never shared with AppsFlyer or with any advertising network.

Who receives it:AppsFlyer acts as our processor and returns measurement results to the advertising network a campaign ran on. The networks we advertise with are Apple Search Ads, Meta, Google Ads, and TikTok. Those networks act as independent controllers of the data they receive and use it to report and improve campaign performance. On iOS, Apple’s own SKAdNetwork and AdAttribution Kit may also return aggregated, non-identifying measurement to us.

How long it is kept:AppsFlyer’s published policy is that it does not retain end user data for more than 24 months, unless the customer directs otherwise or the law requires it. We do not direct otherwise. See the AppsFlyer Services Privacy Policy. When you delete your Folly account we ask AppsFlyer to erase the data held against your device as part of the same request (Section 10).

Android installs, counted by us rather than by anyone else. Separately from everything above, when you install Folly from Google Play, Play passes the App a short note saying which advert or link brought you. We read it once, work out which campaign it means, and keep only that. It carries no advertising identifier. We never store the note itself, and where an advertising network encrypts part of it we do not attempt to read that part.

This is how we tell whether our advertising is working for people who have turned ad measurement off, and it is first-party in the strict sense: the result stays in our own database, it is never sent to AppsFlyer or to any advertising network, and nobody outside Folly sees it. It records how you arrived, not anything you do afterwards. We rely on our legitimate interest in knowing which of our own adverts are worth paying for. If you would rather we did not keep it, email us and we will remove it from your profile. There is no equivalent on iOS.

6. Legal bases for processing

Under UK GDPR we rely on: performance of our contract with you (to provide the App and your subscription); our legitimate interests (to secure, maintain, and improve the App); your consent (for location access, push notifications, photo processing, and ad measurement, which you can withdraw at any time); and compliance with legal obligations.

Ad measurement additionally relies on your consent under the Privacy and Electronic Communications Regulations, because it involves reading an identifier stored on your device. That is why, in the UK and the EEA, it is off until you choose otherwise, and why withdrawing it takes effect straight away. Those Regulations do not apply outside the UK and the EEA. In the United States we rely instead on the opt-out model those state laws provide for, which is why the switch exists everywhere even where we do not ask (Sections 5 and 9).

Reading the Google Play install referrer described in Section 5 relies on our legitimate interest in measuring our own advertising. We have limited it to what that purpose needs: one read, the campaign name only, no advertising identifier, no onward sharing, and no record of what you do afterwards. You can object at any time by emailing us.

7. International transfers

Some of our providers process data outside the United Kingdom. Where data is transferred internationally, we rely on appropriate safeguards such as UK adequacy regulations or standard contractual clauses (the UK International Data Transfer Agreement or Addendum).

8. Data retention

We keep your personal data for as long as your account is active and as needed to provide the App. If you delete your account, we delete or anonymise your personal data within a reasonable period, except where we must retain certain records to meet legal, accounting, or security obligations.

Guest profiles work the same way, with one difference: a guest profile has no sign-in credentials, so it can only be accessed from the device that created it. If you uninstall the App or lose the device without creating an account, the guest profile becomes inaccessible to you, and we may delete inactive guest profiles and their data after a period of inactivity.

9. Your rights

Subject to UK GDPR, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and the right to data portability. Where we rely on consent, you may withdraw it at any time. Ad measurement can be withdrawn in the App under Settings, then Privacy and data. To exercise any other right, contact [email protected]. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.

If you are in the United States, ad measurement is on by default and the Ad measurement control is how you opt out of it, including any sharing of your data that state law treats as a sale or as sharing for targeted advertising. It is the same switch, in the same place, and we honour it the same way. We do not need you to create an account or verify anything to act on it, and it takes effect immediately.

10. Deleting your account and data

You can request deletion of your account and associated personal data at any time from within the App, or by emailing [email protected]. We will process your request in line with applicable law. This applies to guest profiles too. Deleting a guest profile is permanent, because there are no sign-in credentials to recover it with. If ad measurement was on, the same request asks AppsFlyer to erase the attribution data held against your device. The Android install campaign described in Section 5 sits on your profile, so it goes with the profile.

11. Children

Folly is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has provided us with personal data, please contact us so we can remove it.

12. Security

We use technical and organisational measures to protect your data, including encryption in transit and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, where appropriate, notify you in the App.

14. Contact us

Zohho Ltd (Company No. 12739680), 20-22 Wenlock Road, London, England, N1 7GU. Email: [email protected]