Your meadow lives on your phone, not on our servers. Here is exactly what we do and don’t collect, in plain English.
Effective September 4, 2026.
Meadow is made by Wildcard Wellness, LLC ("Wildcard Wellness", "we", "us", or "our"). This policy explains what happens to your information when you use the Meadow app for iPhone (the "App"), visit growyourmeadow.com (the "Site"), or write to us. It covers the App and the Site together, because the honest answer is the same for both: we collect very little, and we don't sell any of it.
We've written this to be read, not skimmed past. If anything is unclear, email us at support@growyourmeadow.com and a real person will reply. This policy is part of our Terms of Service; by using Meadow you agree to both.
Wildcard Wellness, LLC is a small company based in the United States. For the purposes of data protection law we are the "controller" (or "business") responsible for the limited personal data described here. Apple is a separate, independent controller for anything you do with the App Store or iCloud. You can reach us at support@growyourmeadow.com.
Meadow is built "local-first". When you open the App, your Meadow data is read from and written to storage on your iPhone. It is not sent to us. We don't run a backend that receives it, there is no login, and we don't ask for your name, email address, phone number, location, contacts, photos, or microphone.
Because your Meadow data never reaches us, we cannot read it, restore it, share it, or hand it over, including to law enforcement. That's by design. It also means it's protected by your device's own security: your passcode, Face ID or Touch ID, and the encryption iOS applies to app data at rest (Apple's Data Protection).
Some of what you write in Meadow may feel personal, such as how you're feeling today. We want to be clear that we never receive those words, so we never process, categorise, or make inferences from them. The gentle observations the App shows you about your own days (for example, that your mood tends to be brighter on days you move) are worked out on your device from your own Meadow data. Nothing about them is sent to us.
If you back up your iPhone to iCloud or to a computer, your Meadow data is included in that backup like any other app's data. Those backups are yours, handled by Apple or by your computer, and we have no access to them.
You can choose to keep your meadow in sync across your own Apple devices using iCloud. When iCloud sync is on, the App stores a copy of your Meadow data in the private area of your iCloud account using Apple's CloudKit service. That copy is held by Apple under Apple's iCloud terms and privacy policy, is tied to your Apple Account, and is encrypted in transit and at rest by Apple. We do not have access to your private iCloud database and cannot see, copy, or recover what's in it.
You control this. Turn iCloud sync off in the App's settings, or turn off iCloud for Meadow in your iPhone's Settings under your Apple Account. To remove the iCloud copy entirely, go to Settings, tap your name, then iCloud, then Manage Account Storage (or Manage Storage), choose Meadow, and delete the data. Apple explains this in its iCloud storage help.
Meadow is free for your first week and then continues as an auto-renewing subscription. All purchases are made through Apple's App Store using Apple's in-app purchase system. Apple is the merchant of record: Apple collects your payment, holds your billing details, issues refunds, and lets you manage or cancel the subscription in your App Store settings. We never see your card number, bank details, billing address, or Apple Account email.
To check whether your subscription is active, the App uses RevenueCat, a subscription management service. RevenueCat receives a randomly generated, anonymous app user ID created on your device, your App Store transaction and subscription status (which plan, when it started or renews, price and currency, whether it was refunded), and basic technical information such as iOS version, device model, App version, language, and the IP address of the request. RevenueCat uses this only to validate purchases, unlock the features you've paid for, and give us aggregate subscription reporting. This ID is not linked to your name or email, because we never collect them. If you restore purchases on a new iPhone, Apple confirms your existing subscription to the App; nothing new is collected.
The screens that offer you the subscription are delivered by Superwall, a paywall service. This lets us adjust the wording, design and plans on offer, and compare two versions of a screen, without shipping a new version of the App. When one of those screens is shown, Superwall receives the same kind of anonymous app user ID, which screen was shown and whether you tapped, dismissed or subscribed, the plan chosen, and basic technical information (iOS version, device model, App version, language and region, and the IP address of the request). Superwall exchanges subscription status with RevenueCat so a screen is not shown to someone who has already subscribed. Neither service receives your mood, movement, notes, wins or anything else from your meadow, and neither uses your information for its own purposes.
Apple also shares limited information with us through App Store Connect: aggregate sales and subscription figures, and, only if you've chosen to share analytics with app developers in your iPhone's Settings (Privacy & Security, then Analytics & Improvements), crash logs and anonymised app-usage statistics. We use these to fix bugs and understand how Meadow is doing overall. You can turn that sharing off at any time in the same place.
We use PostHog, a product analytics service, to understand how Meadow is used in general: which screens are opened, which features are used, where people get stuck, and whether the App crashes. This helps us make Meadow better and keep it working.
What analytics receives: a randomly generated anonymous identifier stored on your device, the names of screens and actions (for example, "check-in completed" or "seed packet opened"), the App version, iOS version, device model, language and region, and approximate country derived from the IP address of the request. What analytics never receives: your Meadow data, including how you said you feel, your energy, what movement you did, notes, wins, flower names, or anything else you type or choose. We deliberately keep event names generic so that no analytics event describes your mood, health, or body. Session recording and screen capture are not enabled.
We do not use this data to build a profile of you, and we don't combine it with data from other companies. If you'd rather not contribute usage data at all, turn analytics off in the App's settings; from then on nothing is sent. You can also email us to ask that we delete analytics records tied to the anonymous identifier shown in the App's settings.
If you allow notifications, Meadow schedules gentle reminders locally on your device. These are "local notifications": they are created and delivered by your iPhone, not by a server of ours, so no information leaves your device to send them. We don't use push notifications from a server, and we don't send marketing messages. You can change or turn off reminders in the App or in your iPhone's Settings at any time.
The current version of Meadow does not read or write Apple Health (HealthKit) data. If a future version lets you connect Apple Health so that walks and workouts grow your meadow automatically, it will only ever do so with your explicit permission through iOS's Health permission prompt, and you can withdraw that permission at any time in Settings under Health. Any Health data the App reads would be used only on your device to grow your meadow, would never be sent to us, to analytics, to advertisers, or to any other third party, would never be used for advertising or sold, and would not be stored in iCloud. We will update this policy before any such feature ships.
We do not use your Meadow data, your messages to us, or anything else about you to train artificial-intelligence or machine-learning models, ours or anyone else's, and we don't let our service providers do so either. Meadow doesn't send what you write to any AI service. If that ever changes for a feature, we'll ask you first, explain exactly what would be sent and to whom, and update this policy before it ships.
growyourmeadow.com is a simple, static website. It is hosted and delivered by Cloudflare, which processes visitors' IP addresses and request details for the short time needed to serve pages and defend against abuse, and may set a strictly necessary security cookie for that purpose.
We use Google Analytics 4 to see which pages are read and roughly where visitors come from.
Google Analytics sets first-party cookies (named _ga and _ga_…,
which last up to two years) and collects pseudonymous usage data such as device type,
browser, pages viewed, referring site, and approximate location. It doesn't receive your
name or email, and nothing on the Site asks you for either unless you fill in the contact
form. Google Signals, advertising features, and data sharing with Google's other products
are turned off. You can opt out with
Google's browser add-on,
by blocking cookies in your browser, or by using a content blocker. The Site works fully
without cookies. We don't use any other cookies, pixels, or tracking scripts.
Because the Site doesn't sell or share personal information, there's nothing to opt out of in that sense; we treat browser "Global Privacy Control" and "Do Not Track" signals as requests to opt out of sale and sharing, which we honour for everyone whether or not the signal is set.
If you email support@growyourmeadow.com, we receive your email address, whatever you choose to tell us, and anything you attach. If you use the contact form on the Site, it asks for a name (optional), an email address, and your message, and is delivered to the same inbox by Web3Forms, a form-relay service that also records the time of the submission and your IP address to prevent spam.
We use what you send only to reply and to fix whatever you wrote in about. We won't add you to a mailing list or send you marketing. Please don't send us your Meadow data or sensitive health details unless it's necessary to solve a problem; we're a small team, not a healthcare provider, and support email isn't covered by medical-privacy laws such as HIPAA. Support messages are held in our email and help-desk provider's systems and deleted once we're confident the matter is closed, typically within 24 months.
These are the companies that help us run Meadow. Each one receives only what it needs to do its job, is bound by its own privacy policy and a written agreement with us that limits what it may do with the data, and may not use the data for its own purposes.
We don't use advertising networks, social-media SDKs, attribution or "install tracking" SDKs, or data brokers, and no third party receives your Meadow data. If we add or change a provider, we'll update this list.
Apple asks every developer to summarise their data practices in the "App Privacy" section of the App Store listing. Ours says, in Apple's categories, that Meadow collects Purchases (purchase history, via Apple, RevenueCat and Superwall), Identifiers (the anonymous app user ID described above), Usage Data (product interaction, meaning which screens and features are used), and Diagnostics (crash and performance data). None of it is linked to your identity, none of it is used to track you across other companies' apps or websites, and all of it is used only for app functionality and analytics. Your Meadow data, including anything Apple would classify as Health & Fitness or Sensitive Info, is not collected by us at all. If you ever spot a difference between that label and this policy, tell us and we'll fix whichever one is wrong.
We use the limited information described above to:
We don't use your information for advertising, we don't build profiles of you, and we don't make automated decisions about you that have legal or similarly significant effects. We won't use your information for a materially different purpose without telling you first, and asking where the law requires it.
We don't sell personal information, and we don't "share" it for cross-context behavioural advertising, and we haven't in the past 12 months. We disclose information only:
Meadow does not track you across other companies' apps or websites, and it doesn't use the advertising identifier (IDFA) or any fingerprinting technique. Because we don't track, the App doesn't need to show Apple's App Tracking Transparency prompt. There are no ads in Meadow and there never will be ones built on your data.
When a retention period ends, we delete the information or anonymise it so it can no longer be linked to you.
You don't need to ask us to delete your meadow, because we don't have it. To delete it yourself:
The best protection in Meadow is structural: your meadow never leaves your device unless you choose iCloud, and even then it goes to your own account, not ours. For the small amount of data that does reach us or our service providers, we use encrypted connections (TLS), access limited to the people who need it, two-factor authentication on the accounts we use to run Meadow, and reputable providers that maintain their own security programmes and certifications. No method of storage or transmission is perfectly secure, so we can't promise absolute security, but we've tried to make the amount of data at risk as close to zero as we can.
If we ever learn of a security breach involving personal information we hold, we'll investigate, notify affected people and regulators where the law requires it, and post a notice here or in the App if that's the most practical way to reach you.
We're based in the United States, and our service providers process data there and in other countries. If you're in the European Economic Area, the United Kingdom, or Switzerland, that means the limited data described here may be transferred outside your region. Where that happens we rely on safeguards recognised under applicable law, such as the European Commission's Standard Contractual Clauses (and the UK Addendum), or a provider's certification under the EU–US Data Privacy Framework. Data you keep in iCloud is handled by Apple under Apple's own transfer safeguards.
Wherever you live, you can email us to ask what information we hold that relates to you, to have it corrected or deleted, to receive a copy of it, or to object to how we use it. You can also withdraw any consent you've given, without affecting what was done before. We won't treat you differently for exercising your rights.
How we handle requests. Because we don't collect identifying details, we may ask you for the anonymous identifier from the App's settings, or to write from the email address you used before, so we can find anything at all. That's the only verification we can do, and we'll never ask for more than we need. If we can't link any data to you (which is likely, given how Meadow works), we'll tell you so. We aim to answer within 30 days and will always answer within 45, and we'll tell you if we need longer. You may use an authorised agent to make a request on your behalf; we may ask for proof that you've authorised them. If we decline a request, we'll explain why, and you can appeal by replying to us; if you're still not satisfied, you can contact your state attorney general or data protection authority.
Our legal bases under the GDPR and UK GDPR are: performance of a contract (providing the App you've chosen to use and managing your subscription); our legitimate interests in understanding and improving Meadow, keeping it secure, preventing fraud, and answering your messages, balanced against your rights; your consent, where we ask for it (for example analytics, notifications, website cookies, or any future Apple Health connection), which you can withdraw at any time; and legal obligations, such as tax rules on subscriptions.
You have the right to access, rectify, erase, and receive a portable copy of your personal data, to restrict or object to processing, and to withdraw consent. You also have the right to lodge a complaint with your data protection authority, such as the UK Information Commissioner's Office, the Swiss Federal Data Protection and Information Commissioner, or the supervisory authority in your EU member state. We'd appreciate the chance to help first.
Under the California Consumer Privacy Act (as amended by the CPRA), this section is our notice at collection. In the last 12 months we have collected these categories of personal information: identifiers (an anonymous app user ID, an anonymous analytics ID, an IP address, and your name and email address if you write to us); commercial information (subscription status and transaction history, via Apple, RevenueCat and Superwall); and internet or network activity (app screens used, website pages viewed, device and browser details). We collect this directly from your device, from Apple, or from you, for the purposes described in How we use information, and keep it for the periods in How long we keep information. We disclose it only to the service providers listed above. We do not collect sensitive personal information as defined by the CCPA, we do not sell personal information, we do not share it for cross-context behavioural advertising, and we have no actual knowledge of selling or sharing the personal information of anyone under 16.
You have the right to know what personal information we collect and how we use and disclose it, to delete it, to correct it, to opt out of sale or sharing (which we don't do), to limit the use of sensitive personal information (which we don't collect), and not to be discriminated against for exercising these rights. To make a request, email support@growyourmeadow.com; we'll confirm receipt within 10 days and respond within 45. California's "Shine the Light" law also lets you ask whether we've disclosed personal information to third parties for their direct marketing; we haven't.
Residents of states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, New Jersey, Delaware, Iowa, Nebraska, New Hampshire, Kentucky, Maryland, Minnesota, Rhode Island, Tennessee, Indiana, and others) have similar rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising, sales, and profiling. We don't do any of the latter three. Email us to exercise a right or to appeal a decision we've made about a request; if the appeal is denied, you can contact your state attorney general.
Some states, including Washington under its My Health My Data Act, Nevada, and Connecticut, give extra protection to "consumer health data": information that could reveal your physical or mental health, including mood and exercise. Meadow is exactly the kind of app those laws are written for, so we want to be direct. Your check-ins, your energy, the movement you log, and everything else in your meadow stay on your device (and in your own iCloud, if you choose). We do not collect, process, share, or sell consumer health data, and we don't use geofencing. The anonymous analytics described above are limited to generic screen and action names and are not linked to you or to what you recorded. If you believe we hold consumer health data about you anyway, you have the right to confirm whether we do, to access it, to withdraw consent, and to have it deleted, and to appeal our response; email us and we'll act on it.
Meadow is made for adults, and our Terms of Service require you to be at least 18 to use it. It isn't directed at children, and we don't knowingly collect personal information from anyone under 18, and in particular from anyone under 13, or under 16 where local law sets a higher age of digital consent (including the EEA and UK). If you believe a child has used Meadow and that we've somehow received their personal information, email us and we'll delete it.
Meadow is a gentle habit companion, not a medical device or a healthcare service, and nothing in it is medical advice. Your Meadow data is not a medical record and isn't governed by health-records laws such as HIPAA. If you're struggling, please reach out to a healthcare professional or a local support line.
The Site and the App may link to places we don't run, such as the App Store, Apple's help pages, or our social profiles on Instagram, Facebook, and TikTok. Their privacy policies, not this one, apply once you're there, including to anything you post or message us on those platforms. We have no control over, and take no responsibility for, their content or practices.
We'll update this policy when Meadow changes in a way that affects your data, for example if we add an Apple Health connection, change a service provider, or begin collecting something new. When we do, we'll post the new version here and update the date at the top. For significant changes we'll also let you know in the App before they take effect, and we'll ask for your consent where the law requires it. Continuing to use Meadow after a change means you accept the updated policy. Earlier versions are available on request.
Questions, requests, or worries about any of this? We'd love to hear from you. Email is the only way to reach us; we don't publish a postal address.