Controller
GospodApp is operated by Futuristic SRL, CUI 49637694, J08/607/2024, Str. Lebedei 27, Bl. B56, Et. 5, Ap. 27, Brasov, Romania.
This policy explains what GospodApp processes, why we process it, how long we keep it, and the choices available to you.
Effective date: August 24, 2026
GospodApp is operated by Futuristic SRL, CUI 49637694, J08/607/2024, Str. Lebedei 27, Bl. B56, Et. 5, Ap. 27, Brasov, Romania.
We may process account identifiers, sign-in details, billing entitlement status, plant photos, messages, diagnoses, saved Plant Plans, notes, reminders, support requests, app language, and the technical information needed to deliver these features.
When you ask for a plant check or follow-up, the photo, message, and relevant Plant Plan context may be sent to our AI and hosting providers to produce the requested answer. We do not use your plant content for advertising.
To enforce usage limits and prevent repeated account creation from resetting free allowances, we briefly process the app installation identifier and network address in memory. We use a keyed cryptographic method to create pseudonymous values. We also process whether a successful request used image analysis or text, when it happened, and app-integrity results such as a broad recent-device-activity category.
Pseudonymous does not mean anonymous, but it reduces the data exposed in our anti-abuse records. The 31-day anti-abuse ledger does not contain the raw installation identifier, raw network address, photos, messages, prompts, diagnoses, or other plant content.
Operational and security logs may contain a raw IP address, request time, route, response status, and technical error details. New API access and error logs rotate after approximately seven days. Older shared server logs created before August 24, 2026, may take up to 14 days to expire during this transition. We do not intentionally place plant photos, messages, access tokens, integrity tokens, or full anti-abuse pseudonyms in these logs.
We use data to provide plant checks, keep saved plans available, restore Premium access, answer support requests, maintain reliability, enforce plan limits, investigate abuse, and control fraud-related operating costs.
We process data when it is needed to provide the service or perform our agreement with you. For service security, quota enforcement, and fraud prevention, we rely on our legitimate interests, balanced against your rights and expectations. We process billing or accounting records when required by law.
Account content is kept while needed to provide your account and saved features, then deleted under our account-deletion process unless a legal duty requires a specific record. Pseudonymous quota and anti-abuse events are kept for 31 days from the event and then deleted automatically. Deleting an account does not reset that short anti-abuse period, but the retained record cannot be used to recover deleted photos, messages, diagnoses, or Plant Plans.
We use providers for hosting, databases, AI-assisted guidance, App Store and Google Play billing, diagnostics, and support. They process data only as needed to provide those services under their contracts and applicable safeguards. Some providers may process data outside Romania or the European Economic Area using available legal transfer safeguards.
The Free plan does not currently contain third-party advertising, and the current app does not include a third-party advertising SDK. Premium is ad-free while a paid entitlement is active.
We may introduce advertising or optional rewarded-ad offers for Free users in the future. Before advertising data is collected or shared, we will update this Privacy Policy, our store disclosures, and consent controls as required by applicable law and platform rules.
Personal data and anti-abuse data are not sold and are not used for advertising. We do not build advertising profiles from your plant photos, messages, installation pseudonym, network pseudonym, or app-integrity result.
Depending on applicable law, you may ask for access, correction, deletion, restriction, portability, or objection. You may object to processing based on legitimate interests; we will stop unless we have compelling security or legal grounds to continue. You may also complain to the Romanian data-protection authority or another competent supervisory authority.
For a privacy request or a question about these safeguards, write to privacy@gospodapp.com. We may need to verify your identity before acting on an account-specific request.