BombayLabs

Lawnwell

Privacy policy

Last updated: September 14, 2026

1. About this policy

Lawnwell is operated by Bombay Labs LLC (“we”, “us”) and is part of the BombayLabs studio. This policy explains how we handle information in Lawnwell and when you contact Lawnwell support.

Lawnwell keeps your lawn record on your device. Some features communicate with service providers as described below. Local storage does not mean that no information leaves your phone.

2. Your lawn record

Depending on what you enter or use, Lawnwell stores these records on your device:

  • An optional first name or nickname, used for personal greetings. You can skip it, edit it or remove it in your lawn details.
  • Your lawn profile, address, precise coordinates, estimated lawn area and property boundaries.
  • Observations, notes, lawn photos and seed-tag photos.
  • Activity and treatment history, product details, soil-test results, watering measurements and seed projects.
  • Reminders, app preferences and a limited feature-use event history when you enable usage sharing.

We use these details to provide recommendations, organize your care history and support the features you choose. Lawnwell does not automatically upload your lawn record or photos. Your optional name is not sent to our analytics, purchase, weather, imagery, address-search or photo-identification services. If you export a text backup, it includes the name with your lawn profile. Photo identification, when available in your version, is a separate action that asks for your permission as described below. Cloud backup is not enabled in the current generally distributed build.

3. Location, weather and imagery

If you choose device location, Lawnwell requests permission to obtain coordinates. You can enter lawn information manually instead.

The National Weather Service receives latitude and longitude rounded to four decimal places when Lawnwell requests U.S. forecasts. Requests include Lawnwell’s public support contact, not a customer identifier. This integration does not supply measured soil temperature or historical rainfall. Esri’s ArcGIS Static Maps service receives your selected map center, zoom and image dimensions when property imagery is requested. Lawnwell also requests the imagery source credits. Your drawn lawn boundaries are stored locally, not sent with these imagery requests.

When you open address search and type at least four characters, Geoapify receives the search text to suggest U.S. addresses. This search does not request device-location permission or send your device coordinates. Lawnwell briefly caches searches in memory; the address and coordinates you select are saved in your local setup or lawn record. Unselected searches are not saved in that record or sent to our analytics.

Location requests reveal the area of your property to the receiving services. Internet connections also expose information such as your IP address. Geoapify says it retains API request details to operate its service and generally keeps successful-request data for no longer than 24 hours. Lawnwell does not send your photos, journal notes or complete lawn record with weather, imagery or address-search requests.

See the National Weather Service’s privacy information, Esri’s privacy information and Geoapify’s privacy policy.

4. Photos and reminders

Camera and photo-library access are used when you choose to capture or attach an image. Lawnwell saves a copy in its local app storage. Guided grass-problem checks use your answers rather than image analysis. Optional weed-photo identification is a separate, consented action described below; simply saving a photo does not send it for identification.

Reminders are scheduled through your device’s notification system when you allow notifications. You can change these permissions in your device settings. Enabling daily reminders during setup saves your preference; scheduling begins after an active trial or membership grants access. Reminders do not guarantee current weather conditions or permission to apply a treatment.

4a. Optional weed-photo identification

Photo identification may be unavailable in some versions. Where offered, taking, choosing or saving a photo does not send it for identification. You must agree to send the selected photo and tap “Identify this plant.” You can use the manual weed guide without sending a photo.

Your selected photo passes through Lawnwell’s service hosted on Railway to Pl@ntNet for possible plant matches. Lawnwell resizes and re-encodes the image, removes embedded image metadata and sends image bytes rather than a publicly accessible photo URL. We do not include your lawn address, coordinates, notes, email or complete lawn record. Details visible in the picture remain visible to the service, so keep people and private information out of the frame.

To protect this member feature without another sign-in, Lawnwell sends a signed Apple purchase record and its RevenueCat app-user identifier to our service. The service verifies the purchase with Apple’s verification tools and checks the matching RevenueCat membership. These purchase proofs and short-lived access credentials are not stored or written to our application logs. This check does not start another purchase or trial.

Lawnwell processes the identification photo in memory, without keeping it in a server photo library. Pl@ntNet states that submitted images are processed in memory rather than stored in its image database; it keeps request history such as the time and, when supplied, image URLs. Lawnwell does not supply image URLs. Pl@ntNet’s published terms do not specify a deletion deadline for that request history. Network and service metadata may also be processed by the hosting providers.

If you save a weed check, its photo and results remain in your local lawn record. Temporary previews use app cache. Stopping an upload does not retract an image a service has already received. Identification provides possible matches, not a confirmed diagnosis or permission to apply a pesticide.

See Pl@ntNet’s data-handling terms and Railway’s privacy policy.

5. Membership and purchases

Lawnwell uses RevenueCat to manage store purchases and membership access when its purchase service is enabled. RevenueCat receives an app-generated user identifier, purchase and entitlement information, and basic app/device information needed to operate that service.

Lawnwell does not send your lawn profile, address, coordinates, property boundaries, photos, treatment records or notes to RevenueCat. We do not receive or store your full payment-card details. The Apple App Store or Google Play processes payment.

See RevenueCat’s privacy policy, Apple’s privacy policy and Google’s privacy policy. Purchase restoration restores membership access; it does not restore your lawn records.

6. Optional usage sharing

Usage sharing is off by default. When you turn on “Share anonymous app usage,” Lawnwell records a limited set of feature-use events locally and sends permitted events to PostHog when analytics is configured. These can describe the screen or feature used, completion status and coarse categories. PostHog may associate events with a generated device/app identifier and receive basic app/device and network information.

Lawnwell filters its event properties to exclude addresses, coordinates, property geometry, photos, free-form notes, email addresses, product names and barcodes. Session replay, person profiles, automatic lifecycle capture, push-token capture and IP-based location enrichment are disabled.

Turn sharing off in My Lawn Font Awesome Free 7.3.1 by Fonticons, Inc. — https://fontawesome.com — CC BY 4.0 https://creativecommons.org/licenses/by/4.0/ — arrow-right, rotated for diagonal links. Settings Font Awesome Free 7.3.1 by Fonticons, Inc. — https://fontawesome.com — CC BY 4.0 https://creativecommons.org/licenses/by/4.0/ — arrow-right, rotated for diagonal links. Display & privacy. This stops new remote events and new entries in the local improvement-event log. It does not automatically erase events already sent. See PostHog’s privacy policy.

7. Sharing and contacting us

If you export a backup or share a care summary, the device share sheet sends the information to a destination you choose. A backup can include sensitive location and lawn information. Original photo files are not included in the text backup. Copies you share are controlled by you and the recipient.

Manufacturer and other external websites open when you follow their links and have their own privacy practices.

When you contact support, we receive your email address, message and any attachments you send. We use them to answer your request and troubleshoot the app. Zoho Mail processes communications sent to our bombaylabs.app addresses. Correspondence sent to our legacy trygambld.com address is processed by GoDaddy/Microsoft 365.

We do not sell your lawn record or use it for targeted advertising. We may disclose information we hold when required by law or when reasonably necessary to protect users, prevent fraud or defend legal rights.

8. Retention and deletion

Your local records remain in Lawnwell’s app storage until removed or replaced. To remove all app-local data, delete the app and its data using your device’s controls; offloading an app may preserve its data. Separately remove exported backups and any copies kept in your photo library or device/cloud backups if you no longer want them.

Local usage history is capped at 250 recent events. Subscription records are kept as needed to manage purchases and meet legal obligations. Support correspondence and optional analytics are retained only as needed for the purposes described here, subject to applicable legal requirements and provider backup cycles.

For photo-identification limits, Lawnwell keeps random request identifiers, timestamps and a pseudonymous membership identifier, not photos or plant results. These records normally expire from the active rate-limit database within 24–25 hours; a stopped service removes expired records when it resumes. We do not configure backups for that disposable database. Our application logs record request identifiers, status and timing, not photo payloads, purchase proofs or membership identifiers.

Railway separately processes connection metadata, which can include IP addresses and user-agent information. Its current hosting plan provides a seven-day log window, but this is not a guarantee that every infrastructure copy is deleted after seven days. Provider retention and legal obligations also apply.

For deletion of information held by us or our processors, contact us. We may need information sufficient to locate the relevant record and verify your request. We cannot remotely erase records that exist only on your device. Deleting data or uninstalling the app does not cancel a store subscription.

9. Your choices and rights

You can edit your lawn profile, export your record, turn optional analytics off and manage device permissions. Depending on the law that applies to you, you may also have rights to access, correct, delete or receive a copy of your personal information, object to or restrict processing, withdraw consent, and complain to your privacy regulator.

Contact us to exercise these rights. We may verify your identity and explain any legal limitation. Withdrawal of consent does not undo processing that took place beforehand. Service providers may process information in countries other than your own.

10. Security and children

We use reasonable safeguards appropriate to the information handled, but no storage or transmission method is completely secure. Protect access to your phone and be careful when sharing backups.

Lawnwell is designed for people managing lawn care and is not directed to children under 13. Contact us if you believe a child has provided personal information to us.

11. Updates and contact

We will update this policy when our practices change and show the revision date here. Material new data uses will be disclosed before they begin, with consent where required.

Questions or requests: privacy@bombaylabs.app. Please name Lawnwell in your message.