๐ŸŒฟ
Privacy Policy
Microgreens Farm Hub โ€” Mobile App
Grow Fit · Eat Fit · Live Fit

Last updated: May 24, 2026  ยท  Effective: May 24, 2026  ยท  App version 1.6.5

Plain-English summary: Almost all your data stays on your device. We do not sell, share, or monetise your personal information. The only data that leaves your device is what you explicitly share (web orders, cloud backup).

Contents
  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Data Storage, Retention & Security
  5. Third-Party Services
  6. Device Permissions
  7. Children's Privacy
  8. Your Rights
  9. Changes to This Policy
  10. Contact Us

1 Who We Are

Microgreens Farm Hub is a mobile app designed for microgreens farmers to track their grow operations, manage orders, and run their small business. The app is currently available on the Apple App Store (iPhone & iPad); an Android version is in development.

References to "we", "us", or "our" in this policy refer to the developer of Microgreens Farm Hub.

2 Data We Collect

๐Ÿ“ฑ On-Device Data (never leaves your phone unless you choose)
  • Farm name, country, currency preference
  • Tray and crop data (variety, sow dates, stage, yield)
  • Sales, costs, and revenue records
  • Customer / buyer names and contact details
  • Orders and invoice data (including recurring/subscription order settings)
  • Photos you attach to tray stages
  • Payment QR code image and payment key identifier
  • Bank details you choose to enter (bank name, account number, IFSC/SWIFT/routing code, UPI ID) โ€” used only on your invoices and the optional Share Payment Details postcard you generate and send yourself

All of the above is stored in an on-device SQLite database. It never leaves your device unless you use the Cloud Backup feature or the Web Order Form. Bank details and payment QR images are never transmitted to our servers, to the AI assistant, or to the Community Leaderboard โ€” they only travel via the share sheet to whichever app you choose (WhatsApp, Instagram, email, etc.).

โ˜๏ธ Cloud Backup (optional, user-initiated)

If you enable Cloud Backup in Profile settings, an encrypted snapshot of your farm data is sent to our server and stored securely. This backup is keyed to your unique farm token (a random UUID generated locally on first launch). We cannot link it to your identity.

๐ŸŒ Web Order Form

When a customer submits an order via your web order form link โ€” including one-time and recurring/subscription orders โ€” we temporarily store that order on our server. The order (including the customer's name, phone number, delivery address, and chosen varieties) is transferred to your device the next time you open the app and is then deleted from the server. No customer data is retained beyond this transfer window.

๐Ÿค– AI Features (Gemini)

When you use AI-powered features (growing advice, packaging recommendations, social media caption suggestions for share story cards), the text of your question and basic farm context (farm name, variety name, harvest weight, monthly revenue, etc. โ€” only the fields visible on the card you are sharing) is sent to Google Gemini. Buyer names, addresses, payment details, bank credentials, and individual sale records are never transmitted to Gemini. See Google's Privacy Policy for how Gemini handles data.

When you use the Crop Health Scanner, a photo of your microgreens tray is captured and sent โ€” as a base64-encoded image โ€” to Google Gemini Vision along with the optional variety name and growth stage you have selected. The image contains only your crop; no people, location, or personally identifiable information is included in the photo. The image is transmitted to our server solely to relay it to Gemini and is never stored on our servers. Gemini returns a plain-text diagnosis (severity rating, issues list, and remediation steps) which is displayed in the app and not retained by us.

๐Ÿ† Community Leaderboard (optional, opt-in only)

If you choose to join the Community Leaderboard, the following aggregated statistics are sent to our server and displayed publicly to other farmers in the app: your farm name, country (two-letter code for flag display), monthly trays harvested, monthly revenue, monthly profit, and corresponding all-time totals. No customer names, addresses, personal contact details, or individual sale records are shared. You can leave the leaderboard at any time โ€” your data is removed immediately upon opt-out.

๐ŸŽฏ Grow Challenges (user-initiated score submission only)

The app runs monthly community challenges (e.g. highest average yield per tray, most varieties grown). When you tap Submit my score on a challenge card, the following data is sent to our server and displayed on the challenge leaderboard visible to other farmers: your farm name, country (two-letter code), the challenge metric (e.g. average grams per tray), the month, and your computed score. For revenue-based challenges the score is normalised to USD so farms across different currencies can be compared fairly โ€” your raw local-currency figure is not stored. No customer names, addresses, individual sale records, or payment details are shared. Score submissions require your Security PIN to prevent spoofing. You can view your personal challenge history in the app; your score is overwritten (not appended) each time you resubmit for the same month.

๐Ÿ’ณ Subscription & Purchases

In-app purchases and subscription management are handled by RevenueCat. RevenueCat may collect device identifiers and purchase history to manage your subscription. See RevenueCat's Privacy Policy.

๐Ÿ” Storefront Credentials You Choose to Save

If you publish a public storefront (Share Link), the following items are stored on our server, linked only to your anonymous farm token, so the storefront can accept and verify online payments on your behalf:

  • Your farm's display name, bio, phone, currency symbol, country, payment QR / UPI ID
  • The variety list, prices, and stock counts you choose to publish
  • Your Razorpay Key ID, Key Secret, and Webhook Secret (only if you have entered them) โ€” required to create payment orders and verify webhook signatures from your own Razorpay account. These are your Razorpay API keys, not your buyers' card details. Buyers' card / UPI / net-banking credentials are entered directly on Razorpay's hosted checkout and never reach our server.
  • A bcrypt hash of your 6-digit Security PIN (if you set one) โ€” the PIN itself is never stored or logged. The hash authorises storefront updates server-side so a stolen device or copied farm token alone cannot alter your published storefront.

You can clear all of the above at any time by tapping Profile โ†’ Storefront โ†’ Unpublish, which deletes your storefront row from our server.

โœˆ๏ธ Telegram Notifications (optional)

If you choose to enter a Telegram Bot Token and Chat ID in Profile, the app can send you self-routed alerts (e.g., new web orders, harvest reminders) by posting messages through your own Telegram bot. The bot token, chat ID, and message text pass through our server only as a relay to Telegram's API โ€” they are not stored, logged, or used for any other purpose. Telegram receives the message under your bot, not ours. See Telegram's Privacy Policy.

3 How We Use Your Data

We do not use your data for advertising, profiling, or any purpose beyond providing the app's features to you.

4 Data Storage, Retention & Security

Your primary data lives in an on-device SQLite database protected by your device's own security model (Face ID / passcode). The optional app lock adds an additional layer.

Cloud backups are stored on our server (hosted on Replit) and identified only by your anonymous farm token. Data is transmitted over HTTPS (TLS 1.2+). Cloud backup data is retained until you delete it via Profile โ†’ Help โ†’ Reset App Data or contact us for removal.

Web order payloads are stored temporarily on our server and are permanently deleted within 30 days โ€” or immediately when your app claims the order, whichever comes first. No customer order data is retained beyond this window.

Storefront credentials (Razorpay keys, webhook secret) and your bcrypt-hashed Security PIN are stored only while your storefront is published. They are deleted when you unpublish the storefront or reset your farm token. Razorpay key secrets are returned in API responses only as redacted tails (e.g. โ€ขโ€ขโ€ขโ€ขabcd); the full secret is never read back to the app once saved.

For accountability we keep a small Account Activity log (timestamp, action type such as pin_set / pin_changed / storefront_published, and a coarse IP-derived region) tied to your anonymous farm token. The log is visible to you under Profile โ†’ Security โ†’ Recent Account Activity and is retained for 90 days. It contains no buyer data and no message contents.

Crash reports sent to Sentry contain only anonymous device identifiers and stack traces. They contain no personally identifiable information and are automatically purged from Sentry's servers after 90 days.

5 Third-Party Services

The app integrates with the following third-party services:

6 Device Permissions

Microgreens Farm Hub requests the following device permissions. Each permission is optional โ€” you can decline it and the rest of the app continues to function.

  • Camera โ€” Used to scan payment QR codes, capture tray stage photos, and take photos for the AI Crop Health Scanner. Only accessed when you tap a camera action inside the app. When used with the Crop Health Scanner, the captured photo is sent to Google Gemini Vision for analysis (see AI Features section above).
  • Photo Library โ€” Used to save or load payment QR code images and tray photos. Only accessed when you choose to upload or save a photo.
  • Contacts โ€” Used to import buyer contact details into your customer list. Only accessed when you choose to import a contact.
  • Calendar โ€” Used to add harvest or sow reminders to your device calendar. Only accessed when you choose to create a reminder.
  • Notifications โ€” Used to send local reminders about upcoming harvest dates and sow schedules. No notifications are sent to any server; all alerts are generated on-device.

We do not access any permission silently or in the background. Permission requests always appear at the moment you use the relevant feature.

๐Ÿ“ฒ iOS Home Screen Widget, Live Activity, Dynamic Island & Time-Lapse Video

The app offers four optional iOS-only presentations of your tray data: (1) the home screen widget showing active trays and upcoming harvests, (2) per-tray Live Activities on the lock screen showing growing stage and harvest countdown (iOS 16.2+), (3) the same activities rendered in the Dynamic Island pill on supported iPhones, and (4) an optional ~3-second harvest time-lapse video stitched on-device from the stage photos you have already added to a tray. All four read from or generate from your on-device data only โ€” no data is sent anywhere to power them. The time-lapse video is created on your device using AVFoundation and only leaves your device if you explicitly tap the share sheet to send it.

7 Children's Privacy

Microgreens Farm Hub is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information through our app, please contact us at writetosureshraghuraman@gmail.com and we will delete it promptly.

8 Your Rights

You have the right to:

Residents of the EU (GDPR), California (CCPA), and other jurisdictions with data rights legislation may contact us at writetosureshraghuraman@gmail.com to exercise additional rights including access, rectification, and portability.

9 Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the app after changes constitutes acceptance of the updated policy. For material changes, we will notify you via an in-app notice.

10 Contact Us

Get in touch

For any questions about this Privacy Policy, data deletion requests, or to exercise your privacy rights, contact us directly:

Email: writetosureshraghuraman@gmail.com

App: Microgreens Farm Hub

We aim to respond to all privacy enquiries within 72 hours.