1. Introduction
Welcome to Agrum AI ("we," "our," or "us"). We are committed to protecting your privacy and providing transparency about how we collect, use, and safeguard your personal information. This Privacy Policy applies to our mobile application ("App"), website, and related services (collectively, "Services").
By using Agrum AI, you agree to the collection and use of information in accordance with this policy.
About This Project: Agrum AI is created by an independent developer passionate about agriculture and technology. This app is provided free to farmers worldwide to support modern farm management. While we strive for quality and reliability, please use professional judgment when making farming decisions.
Contact Us:
Company: Agrum AI
Operator: Agrum AI Development Team
Email: support@agrum.ai
Website: https://agrum.ai
Location: Los Angeles, California, United States
2. Information We Collect
2.1 Information You Provide Directly
Account Information
- Email address (required for registration and login)
- Display name/username (optional)
- Farm name and location (city, state, country)
- Account credentials (password - securely hashed, never stored in plain text)
Farm Management Data
- Field Information: Field names, sizes (acres/hectares), boundaries, soil types
- Crop Information: Crop types, varieties, planting dates, growth stages, yield data
- Activity Records: Planting, fertilizing, irrigation, pest control, harvesting activities
- Financial Records: Income, expenses, transaction dates, categories, amounts
- Assets: Equipment, livestock, and other farm assets (names, types, acquisition dates)
- Notes and Observations: Text notes, observations, and custom data you enter
AI Chat Data
- Messages sent to our AI assistant
- Voice recordings (if using voice input - processed and deleted immediately after transcription)
- Chat history and conversation context
- Activity logging requests and extracted information
2.2 Information Collected Automatically
Location Data
- Farm Location: City, state, and coordinates for weather data (stored in your profile)
- Device Location: GPS coordinates when you permit location access (used only for weather, not stored permanently)
- Weather Data: Temperature, conditions, forecasts cached temporarily for your farm location
Usage Data
- App usage patterns and feature interactions
- Session duration and frequency
- Device information (type, OS version, app version)
- Crash reports and error logs (anonymous)
- Performance metrics and analytics
Technical Data
- IP address (temporary, for security)
- Device identifiers (for authentication)
- Browser type and version (web access)
- Time zone and language preferences
2.3 Information from Third Parties
Weather Data
We fetch weather information from OpenWeatherMap API using your farm location. Weather data includes: temperature, humidity, precipitation, wind, forecasts.
AI Processing
Your messages are processed by Google Gemini AI to extract farm activities and provide insights. Google processes data according to their privacy policy (we don't control their data practices).
2.4 Device Permissions
Our App requests the following device permissions to provide core functionality:
Camera Permission
- Purpose: Capture photos of crops for AI-powered disease detection and analysis, identify pests and plant health issues, document farm activities and crop growth
- Usage: Photos are processed through our AI models (Google Gemini Vision API) and stored securely with your farm data
- Control: Grant or revoke camera access anytime in device settings
- Optional: Camera is not required; you can use the app without this permission
Location Permission (GPS)
- Purpose: Automatically detect your farm location for accurate weather data and forecasts, enable location-based field mapping and farm boundaries, provide region-specific farming advice
- Usage: GPS coordinates are used only for weather services (shared with OpenWeatherMap API) and stored in your farm profile
- Control: Grant or revoke location access in device settings. You can manually enter location instead
- Not Used For: We do not track your movements, share location with advertisers, or use location for marketing purposes
Microphone Permission (Audio)
- Purpose: Enable voice input for AI assistant (speech-to-text), hands-free activity logging while working in fields
- Usage: Audio is transcribed locally or via speech recognition API, then immediately deleted. Only the text transcription is processed
- Control: Grant or revoke microphone access in device settings
- Optional: Voice input is not required; you can type messages instead
Storage Permission (Photos/Files)
- Purpose: Save crop photos and exported farm data to your device, access photos from your gallery to upload to farm records, create backups of your farm data
- Usage: Storage access is limited to user-selected files. We don't scan or access other files on your device
- Control: Grant or revoke storage access in device settings on Android 12 and below (Android 13+ uses scoped storage without explicit permission)
- Optional: You can use the app without granting storage access, but cannot save photos or export data locally
Internet/Network Access
- Purpose: Sync farm data to cloud servers, fetch weather forecasts, communicate with AI assistant, enable real-time updates across devices
- Usage: Always active for core app functionality
- Required: Internet access is required for most app features
Permission Summary Table:
| Permission |
Purpose |
Required |
Can Be Revoked |
| Camera |
Capture crop photos for AI analysis |
No |
Yes |
| Location |
Weather data and field mapping |
No |
Yes (manual entry alternative) |
| Microphone |
Voice input for AI assistant |
No |
Yes |
| Storage |
Save photos and export data |
No |
Yes |
| Internet |
Sync data and access AI/weather |
Yes |
No |
Your Rights:
- You can deny permissions during installation
- Revoke any permission anytime in device settings (Settings → Apps → Agrum AI → Permissions)
- App will request permission only when the feature is first used
- Denying permissions limits related features but doesn't prevent basic app usage
- We never access device data beyond granted permissions
3. How We Use Your Information
3.1 Core App Functionality
- Account Management: Create and manage your account, authenticate logins, password resets
- Farm Data Management: Store, organize, and display your farm records
- AI Assistance: Process your messages to extract activities, provide recommendations, answer questions
- Weather Integration: Display current and forecast weather for your farm location
- Analytics: Calculate financial summaries, crop statistics, and farming insights
- Real-time Updates: Sync data across your devices in real-time
3.2 Service Improvements
- Analyze usage patterns to improve features and user experience
- Debug technical issues and monitor app performance
- Develop new features based on usage trends
- Train and improve AI models for better activity extraction
3.3 Communications
- Send transactional emails (password resets, account verification, OTP codes)
- Provide customer support and respond to inquiries
- Send important service updates and security alerts
- Notify you of significant app changes or new features (with your consent)
3.4 Legal and Security
- Comply with legal obligations and regulations
- Protect against fraud, abuse, and security threats
- Enforce our Terms of Service
- Respond to legal requests and prevent harm
4. How We Share Your Information
4.1 Service Providers
We share data with trusted third-party providers who help us operate our Services:
Authentication & Database
- Supabase (Database): Stores all your farm data, user account info (hosted in US/EU data centers)
- Supabase Auth: Manages secure authentication and password resets
AI Processing
⚠️ IMPORTANT DISCLOSURE: Your chat messages and farm data shared with the AI assistant are processed by Google Gemini AI. Google may use this data to improve their AI models and services, according to their own privacy practices. We send only necessary context (your message + relevant farm data).
See Google's Gemini API Terms of Service and Privacy Policy for details on how Google processes this data: https://ai.google.dev/terms
Weather Services
- OpenWeatherMap: Provides weather data based on your farm location coordinates (we share only latitude, longitude, and API key)
Email Services
- Resend.com: Sends transactional emails (OTP codes, password resets) - receives only your email address and verification code
Analytics & Monitoring
- Expo Application Services: App deployment, crash reporting, performance monitoring (collects anonymous usage data)
4.2 We Do NOT Sell Your Data
We never sell, rent, or trade your personal information or farm data to third parties for marketing purposes.
4.3 Legal Requirements
We may disclose your information if required to comply with legal obligations, protect our rights, investigate fraud, or prevent harm.
4.4 Business Transfers
If Agrum AI is involved in a merger, acquisition, or asset sale, your information may be transferred. We'll notify you before your data is transferred and becomes subject to a different privacy policy.
5. Data Security
5.1 Security Measures
We implement industry-standard security practices:
Encryption
- Data in Transit: All data transmitted between your device and our servers uses HTTPS/TLS encryption
- Data at Rest: Database encryption for stored farm data
- Password Security: Passwords are hashed using bcrypt (never stored in plain text)
Access Controls
- Role-based access control (RBAC) in database
- Row-level security (RLS) policies ensure users only access their own data
- Multi-factor authentication support (OTP-based)
- Secure API authentication with JWT tokens
Infrastructure Security
- Hosted on secure, SOC 2 compliant cloud infrastructure (Supabase/AWS)
- Regular security updates and patches
- Automated backup systems
- DDoS protection and rate limiting
5.2 Your Responsibility
- Use strong, unique passwords
- Don't share your account credentials
- Enable two-factor authentication when available
- Keep your device and app updated
- Report suspicious activity immediately to support@agrum.ai
5.3 Data Breach Notification
In the event of a data breach affecting your personal information, we will notify you promptly and without unreasonable delay, typically within 72 hours after confirming the breach and assessing its scope.
6. Your Privacy Rights
6.1 Access and Control
You have the right to:
Access Your Data
- View all personal information and farm data we hold about you
- Export your data in standard formats (CSV, JSON)
- Request: support@agrum.ai
Update Your Data
- Edit your profile, farm information, and settings anytime in the app
- Update or correct inaccurate data
Delete Your Data
- Delete individual records (activities, expenses, crops) from the app
- Request account deletion: support@agrum.ai (we will delete your account and all associated data within 30 days)
- Some data may be retained for legal/compliance purposes (anonymized)
Opt-Out of Communications
- Unsubscribe from promotional emails (doesn't affect transactional emails)
- Disable push notifications in device settings
6.2 Data Portability
Export your farm data anytime through the app and receive a copy in machine-readable format (JSON, CSV).
6.3 Location Rights
Grant or revoke location permissions in device settings. Use manual location entry instead of GPS. Location is only used for weather - not tracking or advertising.
6.4 Rights Under Privacy Laws
For California Residents (CCPA/CPRA)
- Right to know what personal information we collect
- Right to delete personal information
- Right to opt-out of sale (we don't sell data)
- Right to non-discrimination for exercising rights
- Submit requests: support@agrum.ai
For EU/UK Residents (GDPR)
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
- Right to lodge a complaint with supervisory authority
- Submit requests: support@agrum.ai
For Other Jurisdictions
We respect privacy rights under applicable local laws. Contact support@agrum.ai for assistance.
7. Data Retention
7.1 Active Accounts
We retain your data as long as your account is active to provide Services:
- Account information: Retained while account is active
- Farm data: Retained indefinitely (you control deletions)
- Chat history: Retained for AI context and improvements
- Activity logs: Retained for 2 years (aggregated data may be kept longer)
7.2 Inactive Accounts
If your account is inactive for:
- 12 months: We may send a reminder email
- 24 months: We may deactivate your account (data preserved)
- 36 months: We may delete inactive account data (after email notice)
7.3 Deleted Accounts
When you delete your account:
- Personal data deleted within 30 days
- Farm data permanently deleted (backups deleted after 90 days)
- Some data retained for legal compliance (anonymized): Transaction records (7 years), Security logs (1 year), Aggregated analytics (indefinitely, anonymous)
7.4 Legal Hold
Data may be retained longer if required for legal proceedings or regulatory compliance.
8. Age Restrictions
Agrum AI is intended for users 18 years of age or older.
- We do not permit users under 18 to create accounts or use the Service
- This restriction is required by our AI service provider (Google Gemini API)
- If we discover an account belongs to someone under 18, we will immediately delete it
- Parents/Guardians: If your minor child created an account, contact support@agrum.ai immediately
By using the Service, you confirm you are at least 18 years old.
9. International Data Transfers
9.1 Data Storage Locations
Your data may be stored and processed in:
- United States (Primary: Supabase/AWS US regions)
- European Union (Optional: Supabase EU regions)
9.2 Cross-Border Transfers
If you're outside the US, your data may be transferred to and processed in the US. We rely on Standard Contractual Clauses (SCCs) approved by the EU Commission. Adequate safeguards are in place per GDPR requirements.
9.3 EU-US Data Privacy Framework
We comply with applicable data transfer mechanisms including the EU-US Data Privacy Framework principles.
10. Third-Party Links and Services
10.1 External Links
Our App may contain links to third-party websites or services (e.g., weather websites, agricultural resources). We are not responsible for privacy practices of external sites, content accuracy or security, or data collection by third parties.
10.2 Third-Party Terms
When using integrated services (Google AI, weather APIs), you're also subject to their terms:
- Google Gemini AI Terms of Service
- OpenWeatherMap Terms & Conditions
- Supabase Terms of Service
10.3 Social Media
If we add social login (Google, Apple Sign-In), we'll collect only basic profile info (name, email). You control permissions in your social media account settings. We don't post on your behalf without permission.
11. Cookies and Tracking
11.1 Mobile App
Our mobile app does NOT use traditional cookies. However, we use:
- Local Storage: Store session tokens, user preferences, cache data on your device
- Authentication Tokens: Securely store login credentials (JWT)
- Analytics SDKs: Expo Analytics for crash reporting and usage stats (opt-out available)
11.2 Website
If you visit our website (https://agrum.ai):
- Essential Cookies: Required for login, security, basic functionality
- Analytics Cookies: Google Analytics (optional, with consent banner)
- No Advertising Cookies: We don't use tracking for ads
11.3 Do Not Track
Our mobile app doesn't respond to browser "Do Not Track" signals (not applicable to mobile apps). You can control tracking through device privacy settings (iOS: Tracking, Android: Ad Settings) or app permissions.
12. California Privacy Rights (CCPA/CPRA)
12.1 California Consumer Rights
If you're a California resident, you have additional rights:
Right to Know
Request disclosure of categories of personal information collected, sources, purposes, third parties we share with, and specific pieces of data.
Right to Delete
Request deletion of your personal information (with exceptions for legal compliance).
Right to Opt-Out
We don't sell personal information (no opt-out needed).
Right to Non-Discrimination
We won't discriminate against you for exercising your privacy rights.
12.2 Submitting CCPA Requests
Email: support@agrum.ai
Subject: "California Privacy Rights Request"
Include: Your name, email, and specific request
Response Time: Within 45 days (may extend 45 more days with notice)
Verification: We'll verify your identity before processing requests
12.3 California "Shine the Light" Law
You may request information about data shared with third parties for marketing (we don't share data for marketing purposes).
13. Changes to This Privacy Policy
13.1 Updates
We may update this Privacy Policy to reflect changes in our practices, legal or regulatory requirements, or new features or services.
13.2 Notification
When we make material changes, we will update the "Last Updated" date at the top, notify you via email (if you have an account), display a prominent notice in the app, and require acknowledgment for significant changes.
13.3 Your Continued Use
Continued use of Services after changes constitutes acceptance of the updated Privacy Policy. If you disagree, stop using the Services and delete your account.
13.4 Policy History
Previous versions available upon request: support@agrum.ai
14. Contact Us
14.1 Privacy Questions
For questions, concerns, or requests about this Privacy Policy or your data:
Email: support@agrum.ai
Subject Line: "Privacy Inquiry"
Response Time: Within 2-5 business days (we're a small team!)
14.2 Data Protection Officer
For EU/GDPR-related inquiries:
Email: support@agrum.ai
Subject: "GDPR / Data Protection Inquiry"
14.3 Supervisory Authority (EU)
EU residents have the right to lodge a complaint with their local data protection authority if unsatisfied with our response.
15. Legal Basis for Processing (GDPR)
15.1 Why We Process Your Data
Under GDPR, we process your personal data based on:
Contractual Necessity
Creating and managing your account, providing farm management services, processing activities and financial records, delivering weather and AI insights.
Legitimate Interests
Improving our Services and user experience, security and fraud prevention, analytics and service optimization, customer support.
Consent
Marketing communications (opt-in), non-essential analytics, location access for device GPS.
Legal Obligations
Complying with tax and financial regulations, responding to legal requests, protecting rights and safety.
15.2 Withdrawing Consent
You may withdraw consent anytime (won't affect lawfulness of previous processing) via email to support@agrum.ai or in-app settings (for specific permissions).
16. Automated Decision-Making and Profiling
16.1 AI-Powered Features
Our AI assistant uses automated processing to extract farming activities from chat messages, generate daily farming advice, provide crop and weather recommendations, and analyze patterns in your farm data.
16.2 No Significant Automated Decisions
We do NOT use automated decision-making that has legal or similarly significant effects on you. All AI features are advisory only (you make final decisions), transparent in operation, and reviewable and correctable by you.
16.3 Your Rights
You have the right to receive an explanation of AI-generated recommendations, challenge or correct AI interpretations, request human review of AI decisions, and opt-out of AI features (will limit functionality).
17. Data Accuracy and Quality
17.1 Your Responsibility
Please ensure your data is accurate and up-to-date, complete for intended purposes, and relevant to your farming operations.
17.2 Our Commitment
We will provide tools to easily update your information, correct errors upon notification, validate data inputs where possible, and not use inaccurate data for decision-making.
18. Special Categories of Data
18.1 No Sensitive Data Required
We do NOT require you to provide racial or ethnic origin, political opinions, religious beliefs, health information, sexual orientation, or biometric data (beyond device auth).
18.2 Voluntary Disclosure
If you voluntarily include sensitive information in notes or chat, it will be processed with your consent, you can delete it anytime, it's subject to the same security measures, and we recommend not sharing unnecessary sensitive data.
19. Your Consent
By using Agrum AI, you consent to collection and use of your information as described, processing by third-party service providers, transfer of data to the United States, and use of AI to process your farm activities.
You may withdraw consent anytime by: Deleting your account, emailing support@agrum.ai, or revoking specific permissions in app settings.
20. Additional State Privacy Rights
20.1 Virginia (VCDPA)
Virginia residents have rights to confirm whether we process your personal data, access your personal data, correct inaccuracies, delete your personal data, obtain a copy of your data, and opt-out of profiling (we don't conduct profiling).
20.2 Colorado (CPA)
Similar rights as Virginia, plus right to opt-out of targeted advertising (we don't use targeted ads).
20.3 Connecticut, Utah, and Other States
We extend similar rights to residents of all U.S. states. Contact support@agrum.ai to exercise your rights.
21. Summary of Key Points
What data do we collect?
Email, farm data (crops, activities, finances), location (for weather), chat messages, usage analytics.
How do we use your data?
Provide farm management services, AI assistance, weather forecasts, analytics, and customer support.
Do we share your data?
Only with essential service providers (Supabase, Google AI, weather API, email service). We never sell data.
How do we protect your data?
Encryption, secure authentication, access controls, regular backups, SOC 2 compliant hosting.
What are your rights?
Access, correct, delete, export your data. Opt-out of communications. Request account deletion.
How to contact us?
Email: support@agrum.ai for all privacy inquiries.
This Privacy Policy is effective as of January 1, 2026.
By using Agrum AI, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.