Privacy Policy
Last updated: September 24, 2026
Overview
GrowVPD Pro ("the app") is an indoor-growing climate and grow-diary app published by VPD Labs LLC (Wyoming, USA), which is the data controller for the purposes of this policy.
GrowVPD Pro is built offline-first: the core app — the VPD calculator, grow diary, calculators, and guides — works fully offline, and the data you create is stored on your device. Several features that connect to the internet are optional and off by default. When you turn them on, limited data is transmitted as described below. This policy explains what is collected, why, and your choices.
Data stored on your device
By default, the data you enter is stored only on your device and is not uploaded:
- Grow diary entries, photos, and notes
- Sensor history, VPD calculations, and settings
- Equipment profiles and templates
- App preferences (language, theme, units)
When you uninstall the app, this local data is permanently removed from your device.
Crash reporting and diagnostics
The app uses Firebase Crashlytics (a Google service) to report crashes so we can fix them. When the app crashes, it sends a crash report containing the error, your device model, operating-system version, app version, an app-installation identifier, and a small set of non-identifying app-state values (such as your selected language and theme, and the number of grows or tents you have). This does not include your name, diary content, photos, or sensor readings.
You can turn crash reporting off at any time in the app's Settings.
Push notifications
To deliver notifications (for example, sensor or watering alerts), the app registers a push token and a Firebase installation identifier with Firebase Cloud Messaging (a Google service). If you enable cloud monitoring or multi-device sync (below), this token is also shared with our services so they can wake the app or send you alerts. The token identifies your app installation, not you.
Crash reporting is currently used on Android only; the iOS app uses Cloud Messaging but does not include a crash-reporting SDK.
Cloud monitoring (optional)
If you enable cloud monitoring, the app periodically sends a status update to our monitoring service (operated by VPD Labs LLC at witness.growvpd.pro) so it can alert you when something needs attention. This update includes a random installation identifier and device model, your push token, current environmental readings (temperature, humidity, VPD, PPFD, soil values, water level) and target ranges, the names of your rooms, tents, grows, and devices, automation and watering status, and basic diagnostics (such as battery level and network type). These status records are kept for 7 days and then expire automatically. Cloud monitoring is off unless you turn it on, and disabling it stops these updates.
Smart-device connections (optional)
If you connect smart devices, the app communicates with the relevant manufacturer's cloud service or with the device directly on your local network. For Mars Hydro, Spider Farmer, Bluelab (Edenic), Ecowitt, UbiBot, Govee, SwitchBot, SensorPush and Pulse, the credentials or API keys you enter are sent by the app straight to that manufacturer's service; we never receive them. Bluetooth sensors are read directly by your phone.
For Smart Life / Tuya, AC Infinity and VIVOSUN, connecting the account goes through our own connection service (witness.growvpd.pro, operated by VPD Labs LLC on Cloudflare), because these platforms require server-side steps to obtain the keys that let the app control your devices locally. In that case the app sends the sign-in details you enter (Smart Life e-mail and password, or your own Tuya IoT project client ID and secret, or AC Infinity / VIVOSUN e-mail and password) to our service over an encrypted connection. Our service uses them to sign in to the manufacturer's platform on your behalf, retrieve your device list and device keys, and return them to the app. The credentials are stored on our service encrypted with a server-side key, together with your random installation identifier and the list of devices, for as long as the platform stays connected, so that cloud monitoring and key refresh can keep working while the app is closed. They are deleted when you disconnect the platform in the app (Settings) or when you request deletion (see Data Deletion). Device status and sensor readings exchanged through this service are kept for up to 7 days.
Multi-device sync (optional)
If you pair your phones or the GrowVPD Hub desktop app, your grow data (diary, devices, rules, and photos) is exchanged between your own devices, either directly over your local network or through a relay service operated by VPD Labs LLC (sync.growvpd.pro, hosted on Cloudflare). Everything that passes through the relay is end-to-end encrypted on your devices with keys that only your paired devices hold — the relay stores only encrypted packets, hashed device identifiers, timestamps and, where you allow notifications, a push token used to wake the receiving device. It cannot read your data. Encrypted packets are held until the paired device fetches them and expire automatically after at most 7 days.
Camera, photos, Bluetooth and location
Camera and photo access is used for your grow diary and, if you enable it, for the tent camera of the phone-as-hub feature; photos and clips are stored on your device and are not uploaded to us (they are shared only with your own paired devices through end-to-end encrypted sync). The microphone is used only for optional video clips and the optional fan-noise monitor, and nothing recorded leaves your device. Bluetooth is used to connect to nearby sensors and devices. On older Android versions the app requests location permission solely because Android required it for Bluetooth scanning — the app does not collect, track, or transmit your location. The light sensor is used by the PPFD meter. The app does not use an advertising identifier.
Advertising and analytics
GrowVPD Pro contains no advertising and no advertising or general-analytics SDKs (no Google AdMob, no Firebase Analytics). It does not build advertising profiles and does not track you across other apps or websites. The only Google services used are Crashlytics and Cloud Messaging, described above.
Our website
The website growvpd.pro uses no cookies, no analytics and no advertising trackers. It remembers the language you pick in your browser's local storage, which stays on your device. The site, including its fonts, is served by our hosting provider, Cloudflare.
If you enter your e-mail address in one of the website's sign-up forms to hear when the app launches, our server (operated by VPD Labs LLC) stores the address together with the language of the page, which form you used, your IP address and the time of sign-up, and we receive a private notification of the sign-up with the same details through Discord. We use the address only to send you the launch e-mail; we do not sell it or use it for advertising. To have it deleted, write to privacy@growvpd.pro.
Third-party services
Depending on the features you use, data may be processed by:
- Google / Firebase — Crashlytics (crash reports) and Cloud Messaging (push notifications)
- VPD Labs LLC services (hosted on Cloudflare) — the connection service for Smart Life / Tuya, AC Infinity and VIVOSUN, cloud monitoring, and the multi-device sync relay
- Smart-device manufacturers — Tuya / Smart Life, AC Infinity, Mars Hydro, Spider Farmer, VIVOSUN, Bluelab, Ecowitt, UbiBot, Govee, SwitchBot, SensorPush, Pulse — only when you connect their devices
- Google Play Billing / Apple App Store — for Pro purchases; we never receive your payment details
- Cloudflare — hosts this website
- Discord — delivers our private notification of website e-mail sign-ups
All network communication uses encrypted (HTTPS/TLS) connections.
Data retention
- On-device data — kept until you delete it or uninstall the app.
- Crash reports — retained by Firebase Crashlytics for up to 90 days.
- Platform credentials held by our connection service — kept, encrypted, while the platform is connected; deleted when you disconnect it in the app or request deletion.
- Cloud-monitoring status and sensor records — expire automatically after 7 days; deleted earlier on request.
- Multi-device sync packets — stored only in encrypted form, until fetched by your paired device and at most 7 days.
- Push tokens — kept with the records above and replaced whenever the app registers a new token.
- Website e-mail sign-ups — kept until you ask us to delete them.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict its processing, and to withdraw consent for optional features at any time. Users in the European Economic Area and the United Kingdom have these rights under the GDPR; California residents have comparable rights under the CCPA, including the right not to be discriminated against for exercising them. We do not sell personal data.
To exercise any of these rights, contact us at privacy@growvpd.pro.
Data deletion
The app has no user accounts, so there is nothing to close. You can delete on-device data at any time in the app (Settings » Data » Delete all data), by clearing the app's data in your device settings, or by uninstalling the app. Disconnecting a platform in Settings removes the credentials our connection service holds for it; unpairing a device stops sync. To request deletion of anything else held by our services, see our Data Deletion page or email privacy@growvpd.pro or support@growvpd.pro. We answer within 30 days.
International data transfers
VPD Labs LLC is based in the United States, and the optional cloud services described above are operated from the United States. If you use these features from outside the US, your data is transferred to and processed in the US.
Children's privacy
GrowVPD Pro is intended for adults (18+) and is not directed to children under 13. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.
Changes to This Policy
We may update this privacy policy from time to time. Material changes will be posted on this page with a revised "last updated" date.
Contact
VPD Labs LLC
30 N Gould St, Sheridan, WY 82801, USA
privacy@growvpd.pro