1. Introduction
Built by Foundry, Inc., formerly known as Playpen Games, Inc. ("Foundry," "we," "us," or "our"), operates the Vine Guard mobile application ("App") for UCLA Wines. This Privacy Policy explains how we collect, use, share, and protect information when you use the App or contact us about it.Contact: For privacy requests, email privacy@builtbyfoundry.io. For general questions: hello@builtbyfoundry.io2. Information We Collect
2.1 Information You Provide
• Vineyard photos you capture or select from your photo library for diagnosis or varietal identification
• Vineyard names you choose to tag scans with (stored locally on your device unless you create an account)
• Private notes you add to scans (stored locally on your device unless you create an account)
• Account details if you choose to sign in: email, display name, and sign-in identifiers from Apple
• Support requests and feedback you send us, including any information you include in the message2.2 Automatically Collected Information
• Device and app information: device type, operating system, app version, language settings
• Usage and analytics: screens viewed, features used, scan counts, session events
• Crash and error diagnostics used to fix bugs
• Approximate location inferred from IP address
• Subscription state returned by our billing providers (active, trial, expired) to unlock Pro features
• Apple App Tracking Transparency status if the App ever requests it2.3 Location (When Attached to a Scan)
If you allow location access, the App may attach approximate or precise coordinates to a scan you capture so you can recall where a vine was photographed. Location is attached to the scan record only; the App does not track your location in the background. You can turn location access off at any time in your device settings.2.4 Permissions
Camera access lets you photograph vines inside the App. Photo library access lets you select existing photos. Local and push notifications are optional and used only to remind you to check back on a vine you flagged. You can revoke any permission at any time in your device settings.2.5 AI-Assisted Diagnosis and Care Plans
When you submit a photo for diagnosis, the App uploads the photo to our backend so a large language model can analyze it and return a likely issue, tissue, confidence score, and care plan. For diagnosis we use OpenAI (GPT-5-mini class models) for accuracy, and Google Gemini (Gemini 3 Flash class models) to generate the care plan for speed.
Per-vendor training disclosure: under our API agreements with OpenAI and Google, prompts and images submitted through the API are not used to train their foundation models. Your photos are used to generate your diagnosis and care plan only.
Please avoid submitting photos that contain unnecessary sensitive personal information.3. How We Use Your Information
• Run AI-assisted vine diagnosis and generate care plans
• Identify likely varietals from leaf photos
• Save and organize scans by vineyard in your Pro library
• Send optional reminders to check back on a flagged vine
• Authenticate your account and restore your data when you sign back in
• Process subscriptions, free trials, renewals, restores, and customer support requests
• Monitor product performance, debug issues, and improve the App
• Detect abuse, enforce our terms, and comply with legal obligations4. Third-Party Service Providers
We share limited data with service providers to operate the App. All are contractually required to protect your data and use it only as we instruct.Infrastructure and Authentication: Supabase (database, storage, auth, edge functions). Data processed in the United States.AI Inference: OpenAI for diagnosis (GPT-5-mini class). Google Gemini for care plan generation (Gemini 3 Flash class). Under our API agreements, prompts and images are not used to train their foundation models. Data processed in the United States.Subscriptions and Payments: RevenueCat for subscription management. Apple App Store for payment processing. Apple handles refunds.Analytics: PostHog for product analytics (screens viewed, features used, scan counts).Crash Reporting: Sentry for crash and error diagnostics, where integrated. Text inputs are not captured.Distribution: Apple App Store for distribution, in-app purchases, and TestFlight beta testing.We Never Sell Your Data. Full service provider details and privacy policies available upon request.5. International Data Transfers
The App is hosted in the United States. If you access from other regions, your data is transferred to and processed in the US.EU/UK Users: We use Standard Contractual Clauses (SCCs) approved by the European Commission and Data Processing Agreements (DPAs) with all processors. All transfers are encrypted. You can request copies of our SCCs by contacting privacy@builtbyfoundry.io.6. Data Retention and Deletion
We retain data only as long as necessary or required by law.While your account is active: account info, subscription state, and scans you save to your Pro library are retained as long as you use the App.Local-only data: vineyard names and private notes are stored on your device using MMKV. If you delete the App, this data is removed with it unless we have introduced a sync feature you explicitly opted in to at the time.After account deletion: We remove or de-identify active account data (including saved scans and uploaded photos) within 30 days. Backup copies are purged within 90 days.Other retention periods: analytics events (up to 26 months), crash reports (up to 90 days), support tickets (up to 3 years), subscription and tax records (up to 7 years as required by law).7. Your Privacy Rights
All Users can request access, correction, or deletion of personal data.EU/UK Users (GDPR)
Additional rights: Data portability, restrict processing, object to processing, withdraw consent, file complaints with your Data Protection Authority.File a complaint: UK (ICO: ico.org.uk), Ireland (dataprotection.ie), or your local EU authority.Legal basis: Contract performance, legitimate interests (analytics, security), consent (session replay), legal obligations.California Users (CCPA/CPRA)
Additional rights: Know what data we collect and who we share with, delete data, correct inaccuracies, opt-out of data sales (we don't sell data), limit use of sensitive information.You can designate an authorized agent to make requests. We verify identity before fulfilling requests. No discrimination for exercising rights.How to Exercise Rights
Email privacy@builtbyfoundry.io with your name, email, user ID (Settings → Profile), and specific request.In-app deletion: Settings → Account → Delete AccountResponse time: GDPR: 30 days, CCPA: 45 days. Requests are free.8. Children's Privacy
Vine Guard is not directed to children under 13. We do not knowingly collect data from children under 13.Parents: If your child under 13 has provided information, contact privacy@builtbyfoundry.io. We'll delete it within 30 days.Teens (13-17): Review this policy with a parent or guardian.9. Data Breach Notification
If a breach compromises your data, we will notify you and relevant authorities within 72 hours, describing what happened, what data was affected, what we're doing, and what you should do.Report security concerns: privacy@builtbyfoundry.io10. Security
We use encryption in transit (TLS 1.3+), encryption at rest (AES-256), secure authentication (OAuth 2.0), access controls, and regular security audits. While no system is 100% secure, we work to protect your data.You should: Protect your device passcode and biometric authentication, use strong Apple/Google account passwords, enable two-factor authentication.11. Vine Guard Is a Diagnostic Aid, Not Professional Advice
Vine Guard is an AI-assisted diagnostic aid. It is not a substitute for a licensed Pest Control Adviser (PCA), farm adviser, extension service, certified agronomist, or laboratory testing. Before applying any treatment, confirm the diagnosis and the care plan with a qualified professional. Check PHI (preharvest interval) and REI (restricted-entry interval) labels before re-entry or harvest. Varietal ID is assistive only; for certification-grade identification, confirm with a DNA test through a qualified lab.12. Updates to This Policy
We may update this policy to reflect new features or legal requirements. Material changes will be communicated via email or in-app notification 30 days before taking effect. Continued use after changes means you accept the updated policy.