Privacy policy · effective 21 August 2026
Your yard is yours.
Waystation is a native-plant gardening app for iPhone. It keeps a map of the plants in your yard, scores what they do for wildlife, and tells you what to plant next. This page describes exactly what the app does with the information it touches. It is written to be read, not to cover anybody.
The short version. Your plants, your photos, and your yard's location live on your phone and in your own iCloud. There is no Waystation account, no Waystation server holding your yard, no analytics, and no ads. The one piece of your content that leaves your device is a photo you choose to send for plant identification.
What stays on your device
Everything that makes up your yard is stored locally on your iPhone:
- Your plants: species, names, notes, dates, health, and every score derived from them.
- Photos you take or import for each plant.
- Your yard's location and the map positions of individual plants.
- Your settings.
None of this is sent to a server run by us, because there is no server run by us. There is no place for us to look at your yard even if we wanted to.
Your iCloud
So that your yard survives a lost phone and follows you to a new one, Waystation is built to sync through your own iCloud account, into the private database of your Apple ID. That is the same mechanism Apple's own apps use. We do not have credentials for it and cannot read it. Apple's handling of iCloud data is covered by Apple's privacy policy, not this one. If iCloud sync is turned off or unavailable on your device, Waystation simply keeps everything locally instead.
What leaves your device, and why
Plant photos, when you ask for an identification
When you point the camera at a plant and ask Waystation what it is, the photo is sent to Pl@ntNet, a botanical identification service run by a French research consortium. This is the one place your own content leaves your phone. Specifically:
- Up to five images of that one plant, resized to at most 1600 pixels on the long edge and re-encoded, which drops the original file's EXIF metadata, including any GPS coordinates the camera recorded.
- A tag for each image saying which part of the plant it shows: leaf, flower, fruit, bark, or "let the model decide".
- An API key that is the same for every copy of Waystation, so it identifies the app, not you.
No location, no name, no device identifier, and no account is attached to that request. Waystation does not send your photos anywhere else, and it does not send photos in the background. Nothing is uploaded unless you tap to identify. Pl@ntNet's own terms describe what they do with submitted images.
Your yard's approximate location, for the native-range question
Whether a plant is native where you live is a question that only has an answer once you have a place. To answer it, Waystation asks iNaturalist's public API which state, county, or country contains your yard, then asks whether that species is native or introduced there. That lookup does not send your yard's coordinates. It sends a bounding box roughly 2.5 miles across that contains your yard but is not centered on it, which is all the region question needs. This is a plain, unauthenticated public API request: no account, no key, no identifier for you or your device beyond the standard metadata any web request carries, such as your IP address.
If you have not given Waystation a location, the app skips the place lookup and falls back to a broader answer.
A rough starting point for the map
When you first set up your yard's area and have not granted location access, Waystation asks ipwho.is for the approximate location of your internet connection, so the map opens somewhere near you instead of in the middle of the ocean. That service sees your IP address, which is how it answers the question. It receives nothing else about you, and the result is only used to point the map.
Reference data about plants, not about you
To fill in species facts, photos, and where to buy a plant, Waystation reads from public sources: iNaturalist for taxonomy and species photos, the USDA PLANTS Database for plant type and growth data, and the product pages of Direct Native Plants to check whether a species is in stock. The app also links out to BONAP range maps and to iNaturalist species pages, which open in your browser.
These requests carry a species name and nothing about you. No account, no key, no user or device identifier is attached. Like any request to any website, they carry standard network metadata such as your IP address, and each of those organizations handles that under its own policy. Following a link out of the app puts you on someone else's site under someone else's terms.
What Waystation does not do
- No accounts. You never make one. There is nothing to sign in to.
- No analytics or tracking SDKs. The app contains no third-party analytics, attribution, crash-reporting, or advertising libraries. It has no third-party dependencies at all.
- No ads, and nothing sold or shared. Your data is not sold, rented, brokered, or shared for advertising, because it is not collected in the first place.
- No background uploads. The app talks to the network when you ask it a question, and not otherwise.
- No weather lookups. A rain-aware watering feature was built and then shelved before release. Its code is disabled and makes no requests. If it ever ships, this page will say so first.
Permissions the app asks for
- Camera, to photograph a plant you want identified or recorded.
- Photo library, when you import an existing photo. Waystation reads the capture date and any GPS coordinates stored in that photo's metadata so it can place the plant on your map for you. That reading happens on your device.
- Location, while using the app, to drop plants on the map where you are standing and to answer the native-range question above. Waystation does not ask for background location and does not track where you go.
Each one is optional. Declining any of them leaves the rest of the app working.
Deleting your data
Delete a plant in the app and it is gone, along with its photos and map position. Delete the app from your iPhone and the local copy goes with it. If your yard has been syncing to iCloud, remove it there through Settings on your device, under your Apple ID, in iCloud storage. We cannot delete your data for you, because we never have it. There is nothing to request from us and no retention period to describe.
This website
Separately from the app, waystation.garden runs a beta waitlist. If you fill in that form, the first name, email address, and phone platform you type are stored in a database used for one purpose: emailing you when the beta opens. It is not sold, shared, or fed to an ad network. Ask at the address below and it will be deleted. The site is hosted on Vercel and loads fonts from Google Fonts, both of which see standard request metadata such as your IP address. The site sets no advertising or tracking cookies.
Children
Waystation is not aimed at children under 13 and collects no personal information from anyone, children included.
Changes
If the app starts doing something new with data, this page changes before that version ships, and the effective date at the top changes with it.
Contact
Waystation is made by one person. Questions, corrections, and "wait, why does it do that" all go to the same place: dennis.s.lysenko@gmail.com.