Legal

Privacy Policy

Last updated: 27 July 2026

This privacy policy explains how the Diora mobile application ("Diora", "we", "us", or "our") collects, uses, and protects information about you when you use the app. Diora is a plant collection tracker for iOS and Android, built for rare plant collectors. It includes optional social features: a public profile, following other collectors, sharing individual plants and breeding programs at a visibility level you choose, offering pollen, and direct messaging, described in section 9. By creating an account and using the app, you agree to the practices described below.

1. Who runs Diora

Diora is built and operated by Beebles, an Australian company. You can reach us at support@joindiora.com for any privacy question, request, or concern.

2. What we collect

We collect only what is necessary to make the app work, keep your data secure, and diagnose problems.

We do not collect: your device's location (Diora never asks for GPS permission, and we strip GPS coordinates out of every photo before storing it), your contacts, your full camera roll (we ask for permission only when you tap "add a photo" and only the photos you select are uploaded), your advertising ID, or anything used for ad targeting. A delivery address you type in when buying a plant is a different thing, and it is covered above. Diora does not show ads, and we have no plans to ever introduce them.

3. Why we collect it

By creating an account you agree to this Privacy Policy. You can withdraw consent at any time by deleting your account.

4. How we store and secure it

No system is perfectly secure. If we become aware of a breach affecting your data, we will let you know without undue delay and explain what happened and what we are doing about it.

5. Who we share it with

Diora uses a small number of third-party processors. We chose each one for security, clear privacy posture, and the ability to delete data on request.

We do not currently use a third-party crash-reporting processor (such as Sentry). Diora sends push notifications for activity you opt into (such as new followers, replies, and messages) using the Expo Push Service, which delivers them via Apple Push Notification service (APNs) on iOS and Firebase Cloud Messaging (FCM) on Android. These messages carry only the notification text and routing information, never the content of your records, and you can turn each type off in the app's notification settings.

We do not sell your data. We do not share it with advertisers. We do not use your plant data, notes, photos, messages, or any other content you create to train any machine learning model.

6. Your rights

You can:

If you live in the EU or UK, you have additional rights under GDPR: to restrict processing, to object, and to lodge a complaint with your local data protection authority. If you live in California, you have rights under the CCPA, including the right to know and the right to delete. We respond to verifiable requests within 30 days.

7. Children's data

Diora is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child has used the app, please email us and we will delete the account.

8. International data

Diora is operated from Australia. The processors listed in section 5 may store and process your data in regions including Australia, the European Union, and the United States, depending on the service and the region selected at provisioning time. Our analytics processor, PostHog, is hosted in the European Union. Supabase stores your account and content in the region selected when the backend was provisioned. By using Diora you consent to your data being transferred to and processed in these regions. We take reasonable steps to ensure that any international transfer is protected by appropriate safeguards, including the standard contractual clauses where applicable.

9. Social features and how sharing works

Diora has a social layer ("Grapevine"), and every plant and breeding program carries its own visibility setting that you control. New accounts start public. When you set up your account, we ask you to choose, on a screen you cannot skip past, whether your collection starts public or private. Public is what the account is already set to, and choosing private changes it. Whichever you pick, you can change any single plant at any time, change the default later in Settings, and apply a level across your whole collection at once. Here is exactly how it works.

Your profile is visible to others. Once you have an account you have a public profile: your display name, your username (@handle), your bio if you write one, and your avatar if you set one. Other collectors can find your profile (for example by searching your username) and see these fields. Your profile does not expose your email address or any plant you have not chosen to share.

Every plant and breeding program has a visibility setting that you control. Each item can be set to one of three levels:

You set this per item, and you can change it at any time. You can also set a default visibility for new items and bulk-apply a visibility level across your collection. Raising an item to "followers" or "public" is what makes its details and photos (including provenance/source text) readable by that audience. Lowering it back to "private" hides it again.

Following. You can follow other collectors and they can follow you. Following is one-way: following someone does not require their approval and does not make them follow you back. Who you follow and who follows you is used to decide whose content appears in your feed and to activate the "followers" visibility level described above.

Feed. The feed shows activity from accounts you follow and public activity, for example a new plant added, a propagation, or a new breeding program, but only for items whose visibility allows you to see them. Items you have kept private never appear in anyone else's feed.

Pollen offers. You can post a pollen offer to make your pollen available to the community. An offer you post is visible to others and can carry a photo. People can reply to your offer; those replies are attached to that specific offer.

Direct messaging. Diora includes private one-to-one messaging. You can message another collector (for example, to follow up on a pollen offer), and the messages you send and receive are stored so the conversation persists. Messages are delivered to the other participant in the conversation and are not part of your public profile or feed. Blocking prevents messaging between the two accounts.

Blocking. You can block another account. Blocking is symmetric in effect: a blocked account cannot see your followers-only or public content, cannot follow you, and cannot message you, and you stop seeing theirs. By design, blocking is silent: the blocked person is not told they have been blocked.

Provenance / source text. Diora lets you record where each plant came from as free-text source data, which may include another collector's @handle. When you share that plant (followers or public), this text is visible to the audience you shared with, and a mentioned handle can be surfaced as a discovery suggestion. You enter this text yourself and Diora has no way to verify it; we do not vouch for the accuracy of provenance claims. If you believe source text in another user's shared collection misrepresents you, email us.

In short: profiles are public, every plant and photo carries a visibility setting you control, and you can raise or lower it at any time. We will update this policy before adding a materially new way to share your data.

10. Deleting your social content

When you delete your account (section 6), your profile, follows, visibility settings, pollen offers, and the records of your messages are removed along with the rest of your data. Note that messages you sent to another person, and replies you posted on someone else's pollen offer, may have been seen by their recipient before deletion; deletion removes them from our systems but cannot un-send what another person has already read. If you want a specific piece of shared content taken down sooner, you can lower its visibility to private in the app, or email us.

11. We are not a plant care advice service

Diora records what you tell it about your plants. We do not provide care guides, watering schedules, diagnoses, or species identification. Nothing in the app should be treated as professional horticultural advice. This is a deliberate product choice, not a limitation we plan to fix.

12. Changes to this policy

We may update this policy as the app evolves. The "Last updated" date at the top reflects the most recent change. For material changes (anything that adds a new category of data collection, a new third-party processor, or a new sharing capability), we will surface a notice in the app the next time you open it.

13. How to contact us

For any privacy question, data export request, deletion request, or concern, email support@joindiora.com. Diora is a small project and replies are best effort, but we will get back to you as soon as we reasonably can.


This policy is written in plain English by intent. If anything in it is unclear, please email us. We will fix the wording.