Flit🌿

Privacy Policy

Last updated 1 October 2026

Flit uses your account, garden content, and location to provide a personalised gardening service. We do not sell your data, show advertising, or track you across other companies' apps or websites.

Plant identification photos are shared with Pl@ntNet. A photo you submit to identify a plant is uploaded to Pl@ntNet, which says it processes the image temporarily and does not store it. If the service fails, we try Amazon Bedrock instead. You can also add plants by name without sending an identification photo. More about identification and your photos.

Need help or want to exercise a privacy right? Email hello@flitgarden.com.

Who is responsible for your data

Flit is built and operated in the United Kingdom by Jordan Beagle, an individual rather than a registered company. Jordan Beagle is the data controller for information Flit collects. Contact hello@flitgarden.com with any privacy or support question.

What we collect and how

  • Account information for new accounts: your email address, chosen username, and an internal account identifier. Flit does not ask new users for a first name or gardening reason.
  • Optional marketing emails: we store your latest choice, the version of the consent wording, where you made the choice, and the time recorded by your device with your account. The signup checkbox is optional and starts unchecked.
  • Older account information: accounts created before 2 September 2026 may still retain the first name and gardening reason collected by the previous signup form. Flit no longer collects either detail.
  • Username availability: while registration is awaiting confirmation, Flit keeps the username and a one-way hash of the email address for up to 24 hours. After confirmation, the reservation is linked to the internal account identifier instead so usernames remain unique.
  • Exact garden location: the address text you enter, the full address you select, latitude and longitude, and the garden outline you draw or Flit creates for a balcony. Flit also records property type, approximate area, and facing direction. Flit does not request your phone's GPS location.
  • Coarsened location: an outward postcode such as YO10 and a rounded area cell approximately one kilometre across, derived from the exact garden location.
  • Garden content: the plants, wildlife sightings, bird boxes, bird feeders, ponds, lawns and meadows you record, including names, dates, photos, notes, posts, tags, and mapped garden details. We also store an optional profile photo. For plant-event photos, we may read and retain the capture date from the original photo before resizing it for upload.
  • Questions and AI content: questions you ask, chat history, the garden or plant context used to answer, AI prompts, and generated answers, identifications, descriptions, suggestions, and insights. This includes the text of plant and wildlife searches, which we also use to see what people look for and improve Flit and its catalogue.
  • Use and service information: counts and dates for AI-assisted requests and feature use, whether an operation succeeded, and information needed to enforce fair-use limits, secure the service, diagnose faults, and provide support. We also record account-linked events such as opening the app, starting or leaving garden setup, viewing cards and stories, and adding plants, sightings, features or posts, to understand which features people use and improve Flit. Internet services may also receive standard connection data such as IP address, browser or device type, and request time.
  • Optional iPhone notifications: if you enable daily card notifications, we link your device’s push token to your account and garden. AWS and Apple deliver the notification. We record the day of sending to prevent repeat alerts. You can turn notifications off from your profile menu. Account deletion removes the link. Signing out attempts to remove it; if the network request fails, Flit keeps a local retry record. Inactive registrations expire after 90 days without opening Flit.
  • Support correspondence: anything you include when you contact us for help or exercise a privacy right.

How we use your data

  • To create and secure your account and send sign-in codes.
  • If you opt in, to email you Flit news, gardening tips and offers. You can change your choice anytime in the account menu under Marketing emails, or contact hello@flitgarden.com. Choosing not to receive marketing does not affect your access to Flit or essential account emails. Your saved preference is deleted when you delete your account.
  • To save and display your garden record, photos, posts, notes, and wildlife observations.
  • To locate and map the garden and calculate its size and direction.
  • To provide local weather, rainfall, habitat, species, and wildlife information.
  • To generate personalised descriptions, identifications, answers, suggestions, and insights using AI.
  • To operate, secure, troubleshoot, and support Flit, enforce usage limits, and understand the cost and reliability of individual service operations, and improve onboarding and features using the account-linked usage events described above.
  • To comply with legal obligations and protect legal rights.

Flit Plus subscriptions and Apple

Apple processes Flit Plus payments through your Apple Account. Flit does not receive your card or bank details. When you subscribe, Flit sends Apple your internal Flit account identifier to link the purchase to your Flit account.

Flit receives signed purchase information and subscription updates from Apple. We store the original transaction identifier, product, subscription status, access expiry, renewal setting, purchase environment, and verification timestamps linked to your Flit account. We use these records to provide paid access, restore purchases, process renewals and refunds, and resolve support issues. Apple keeps its own payment and purchase records under its privacy policy.

Deleting your Flit account does not cancel your Apple subscription. Apple billing continues until you cancel through Apple subscription settings. Flit Plus uses Apple’s standard Terms of Use.

AI processing

Flit uses Amazon Bedrock, an Amazon Web Services (AWS) service, to run Anthropic Claude models. Plant photo identification also uses Pl@ntNet, with Claude Sonnet on Bedrock as the fallback if that service fails. Flit can also run it on Bedrock alone. Some AI work starts after a garden is created or on a schedule; other work starts when you ask a question, request a suggestion, or submit a photo for identification.

Flit asks for your permission before it sends anything to the AI service, and none of the processing below happens without it. You can turn it off, or back on, at any time under AI processing in the app's account menu. Turning it off stops new AI processing straight away; features that do not use AI keep working.

  • Plant photo identification uploads the photo to Pl@ntNet, without garden location or account details. If the Pl@ntNet API fails (including a timeout or service limit), Flit tries Amazon Bedrock instead. A successful response with no plant or low confidence does not trigger this fallback. Bedrock receives the photo, outward postcode, and current month. Wildlife photo identification uses Amazon Bedrock only, with the same information.
  • Attaching a photo to a garden plant event automatically starts an AI plant-condition assessment. It sends the photo, plant name, whether the plant is in a pot, outward postcode, and the month of the photo or upload.
  • Plant description search can start automatically after you pause typing a description that has no name match. It sends your search text and shared plant and wildlife catalogue information to the AI service.
  • Ask Flit sends your question, earlier messages in that chat, relevant plant or garden content, and location text derived from your selected address. Flit reduces address detail where it recognises the format, but street-level text may remain for some addresses.
  • Garden descriptions send the outward postcode, garden size, facing direction, and broad rural or urban context. Insights and recommendations can use reduced address text, garden details, plants, weather, and local ecology context. Bird-box suggestions can send the full address and bird-box and garden details.

AWS states that standard Bedrock inputs and outputs are not used to train the underlying models and are not shared with model providers. Read the AWS Bedrock security and privacy information. Flit separately stores copies of AI prompts and responses for the retention period described below. AI output can be wrong and should not be treated as professional or safety-critical advice.

Pl@ntNet and your plant photos. Pl@ntNet says uploaded images are kept only in server memory during identification, and are not stored in its database. It keeps query history for usage monitoring. Flit uploads image files directly rather than sharing links to your stored photos. See the Pl@ntNet API terms. Plant identification through this service is based on the regularly updated Pl@ntNet recognition API.

Data stored on your device

Flit uses browser or app storage to keep you signed in, cache reference catalogue information, remember dismissed messages, and manage notification preferences and pending notification changes. Some records last for the current session; others remain until replaced, cleared by Flit, or removed using your browser or device settings. Clearing this storage may sign you out or reset preferences. Downloaded images may also remain in your browser or device cache.

Maps and address searches connect directly to Mapbox, which may use device storage and collect technical usage information as described in its privacy information below. Flit does not use advertising cookies or a third-party advertising analytics SDK.

The iPhone app uses PostHog for product usage analytics. It stores a random installation identifier locally so we can understand repeat use on that installation. Signing out resets it. We do not link this identifier to your Flit account or use it for advertising.

Bird sound identification. Where the iPhone app offers “Who’s singing?”, it listens and suggests birds entirely on your phone: nothing it hears is saved or leaves the device. It uses the Perch 2.0 bird sound model by Google, licensed under the Apache License 2.0 and modified by Flit (classifier restricted to British species, unused outputs removed), run by ONNX Runtime by Microsoft, licensed under the MIT License.

Location and service providers

Different features send different information to providers. Public ecology services receive no Flit account identifier, email address, or full street address. Requests to those services are made by Flit's AWS servers unless stated otherwise.

  • PostHog: receives selected iPhone app usage events, such as opening the app or adding a plant, with random installation and session identifiers, basic device information, and app build information. Requests go directly to PostHog's EU service. We do not send your account identifier, name, email, garden identifiers, location, photos, written content or page addresses. Session recording and automatic interaction capture are disabled. IP-based geolocation is disabled, although the service receives standard network connection information. See PostHog's privacy information.
  • Amazon Web Services: hosts Flit's account, database, photo storage, email, server functions, operational records, and AI processing. AWS therefore processes the Flit data needed for each of those services. See the AWS privacy notice.
  • Pl@ntNet: receives plant identification photos for identification. See Pl@ntNet and your plant photos.
  • Mapbox: receives address text as you type and the location or map area needed to return search results and display map tiles. These requests go directly from your device, so Mapbox also receives standard connection information. Flit stores the full address and coordinates you choose. See the Mapbox privacy information.
  • WeatherAPI.com: receives your garden's latitude and longitude, once a night from Flit's AWS servers, to return the previous day's rainfall and temperature and a seven-day forecast. Requests never come from your device. Flit stores the weather values it uses. See the WeatherAPI.com privacy policy.
  • postcodes.io: receives exact coordinates once during initial garden description work and a rounded area centre for later ecology refreshes. Flit uses the response to understand broad rural/urban context and retains only the result needed by the feature. See the postcodes.io service.
  • OpenStreetMap contributors through public Overpass services: receive a rounded area centre and search radius to return nearby habitat, green-space, water, road, and railway map features. See the OpenStreetMap Foundation privacy policy. Public Overpass mirrors may keep their own technical logs.
  • Natural England through ArcGIS: receives a rounded area centre and search radius to return nearby habitat and designated-site data in England. See Natural England's privacy notices.
  • NatureScot through ArcGIS: receives a rounded area centre and search radius to return nearby designated-site data in Scotland. See NatureScot's privacy notice.
  • GBIF: receives a rounded area and search radius to return recent, public species-occurrence evidence, plus species names for catalogue lookups. See the GBIF privacy policy.
  • iNaturalist: receives plant or species names to retrieve public taxonomy records and openly licensed photos and recordings. It does not receive your garden location or Flit account details in these requests. See the iNaturalist privacy policy.

Providers may retain technical request records under their own published policies. Where a provider processes personal data on Flit's behalf, we require it to protect that data consistently with this policy and applicable law. We do not share data for third-party advertising or cross-app tracking.

Who else can access your data

Flit does not offer photo contributions to the shared catalogue. Photos submitted for identification are not published as catalogue pictures. If you chose to contribute a photo in an earlier version, its separate catalogue copy may remain visible to other gardeners and accessible through a public web address without your name. To request removal of an earlier contribution, contact hello@flitgarden.com.

The Flit operator may access account data when necessary to answer a support request, investigate a fault or security issue, maintain the service, or comply with law. Access through Flit's support/admin tool is limited to an authorised account and recorded in an audit log. We may disclose information when legally required, or when necessary to protect users, Flit, or others from harm.

How long we keep data

  • Photos sent to a previous plant identification provider may remain with that provider under the terms that applied when they were sent. Switching providers or deleting your Flit account does not withdraw those earlier licences. Contact hello@flitgarden.com if you need help with a previously shared photo.
  • Your account, garden records, chat history, and photos are kept while your account exists. Removing a plant or garden feature from view can preserve its history, but not its photos.
  • A photo you remove or replace, or that goes with something you remove or with your account, disappears from Flit straight away. A copy stays recoverable in our storage for 30 days, so a mistake or a fault can be put right, and is then permanently erased.
  • An unconfirmed username reservation expires after 24 hours. A confirmed reservation is kept while the account exists and is released when the account is deleted.
  • Flit's separate copies of AI prompts, responses, and related account-linked usage and operational events are scheduled for deletion after 365 days, or included in account deletion earlier. Automatic database expiry is asynchronous, so physical deletion can take additional time after the expiry date.
  • A record used to resume an interrupted account deletion, containing your internal account identifier, garden identifiers and signup date, is scheduled to expire after 30 days. Daily signup totals and deletion statistics are retained without a fixed expiry. Deletion statistics omit your account identifier and email but include signup and deletion times, garden counts, and which feature milestones you reached.
  • Reduced ecology evidence is cached against a rounded area for reuse periods of roughly three or six months depending on the source. These periods determine when information needs refreshing; they do not guarantee deletion of the cache. It has no account identifier or street address, can serve several nearby gardens, and may remain after one account is deleted.
  • Support correspondence and security records are kept only as long as reasonably needed for support, fraud prevention, security, legal, or accounting obligations.
  • PostHog installation usage events are separate from Flit's account-linked records. Because we do not send an account identifier to PostHog, deleting an account does not automatically locate or remove those events. Contact hello@flitgarden.com for help with analytics data or privacy choices.

Deletion and your choices

You can permanently delete your account from the profile menu in the app. This removes the login, owner-linked garden records, photos still referenced by those records, posts, notes, chat history, AI prompt records, subscription access records, and account-linked usage records, and releases the username reservation. Deleted photos stay recoverable in our storage for 30 days and are then permanently erased (see How long we keep data). The deletion recovery record and statistics described above are retained separately. Shared plant and wildlife catalogue material, and the rounded ecology cache described above, can remain because those records are not linked to your account. If you contributed a plant to the shared catalogue, it can remain for other gardeners without a link back to you, and so can a catalogue picture you chose to contribute in an earlier version (it is a separate copy, not your garden photo). To have such a picture removed, contact hello@flitgarden.com.

Deletion from the live service does not immediately erase copies in backups, device caches, or providers' technical and security logs, or withdraw licences already granted to a previous plant identification provider. If you need help with a particular photo or other retained information, contact hello@flitgarden.com.

You can choose not to add optional photos, posts, or notes, and not to start on-demand AI actions. Once you allow AI processing, some descriptions and insights run automatically for a saved garden, and adding plant photos or typing a plant description can start AI work as described above. You can withdraw your AI processing consent at any time under AI processing in the app's account menu, which stops new AI processing immediately, or by contacting hello@flitgarden.com. To object to processing, restrict future AI processing, correct account information, or request a copy of your data, contact hello@flitgarden.com. Removing location prevents mapping, weather, local ecology, and location-personalised advice from working. Stopping AI processing prevents identification, Ask Flit, AI-generated descriptions, suggestions, and insights from working and may require the garden or account to be removed.

Your UK data protection rights

Depending on the circumstances, you may have rights to access, correct, erase, restrict, or receive a copy of your personal data, and to object to processing or withdraw consent. Contact hello@flitgarden.com to make a request. You can also complain to the UK Information Commissioner's Office.

Security and international processing

Flit uses access controls and encryption in transit and at rest. Core AWS services run in European AWS regions, while some providers process data in other countries, including the United States. Those providers describe their transfer safeguards in the policies linked above. No internet service can guarantee absolute security.

Children

Flit is not intended for children and does not knowingly collect personal data from anyone under 16. Contact hello@flitgarden.com if you believe a child has provided data to Flit.

Changes to this policy

We may update this policy as Flit changes. We will update the date at the top and provide additional notice when a change materially affects how personal data is used.

Ready to return?

Open Flit