Last updated: August 25, 2026
Supplant is a game about the real plants around you: you photograph them, identify them, and collect them as cards whose role is relational to place. That means the app is built around two kinds of sensitive information — where you are and photos you take — so we've tried to be specific and honest about how each is handled. This policy explains what we collect, why, who we share it with, and the choices you have.
“Supplant,” “we,” and “us” refer to the team that operates the Supplant game and the supplant.app service.
You sign in with Google. Signing in shares only your basic profile — your name, email address, and profile photo — which we store to create your account, identify you across sessions, and show who you are in the game. That is the full extent of the access: we never receive your Google password, and the sign-in gives us no ability to read, post, or change anything in your Google account or any other Google service.
Because the game is available to a general audience that may include minors, we ask for your birth year once, on a neutral age screen. We use it only to determine whether age-based restrictions apply to your account (see Children's privacy below). We store the year you entered and the date you answered.
Supplant is a location-based game, so location is essential to how it works — a plant read as a native in one place is invasive in another, and that difference drives the mechanics. When you scan a plant, leave a plant at a spot, or pin your greenhouse, your device shares its precise GPS coordinates with us. From those coordinates we also derive coarse grid cells (roughly a 1.2 km area and a ~38 m square) used for gameplay such as daily catches and the greenhouse location lock.
Two things worth being clear about. When you catch a plant, the card briefly records the coarse ~1.2 km area it was caught in — never precise coordinates — because for the first hour the game uses it to tell a re-catch of the same plant from a genuinely new one. That area is then erased on the next nightly sweep, so it is held for about a day at most and never builds into a lasting record of where you have been. Nothing finer is ever stored on a card, a card never records when beyond the date, and a card's role is recalculated from your current location each time it's shown, so what matters is where a plant is now. A card you sell or buy on the market carries nothing at all about the player who caught it — no identifier, no area, no nickname. Your “Seen” life-list is handled the same way: each sighting is recorded with the coordinates of that scan, which we use for the life-list itself and to keep the game fair (for example, detecting physically impossible jumps between scans). We don't hold onto those coordinates — they are erased every night, so we never keep them beyond the current day. The life-list entry keeps only the species and the date. We delete the coordinates outright rather than blurring them to an approximate area.
To identify a plant, the photo you take is sent to a third-party plant-identification service (currently Pl@ntNet). Before any photo leaves our server we strip its metadata — including any embedded GPS/EXIF location — and if that cleanup can't be completed we reject the photo rather than forward it. We do not store your photos. What we do keep from a scan is a small mathematical “fingerprint” of the image (a perceptual hash) plus an advisory camera-authenticity score, used only to detect duplicate or replayed images and keep the game fair — neither is the image itself and neither can reconstruct it.
As you play, we store the data that makes up your game: your “Seen” life-list of identified plants, your kept collection and each card's stats and nicknames, coins, experience, battles, decks, inventory, and settings such as your display name and time zone.
We record a small set of product-analytics events (for example, “a scan happened”, “a battle was won”, or “the app hit an error”) to understand how the game is used in aggregate. These events are fully anonymous by design: they are not linked to your account or any per-person identifier, and they never include personal information or raw coordinates. Within this event stream we can see totals and trends, but not what any individual did.
Separately from those anonymous events, we look at the game data described above — which is tied to your account — to answer questions about the game as a whole, such as how many people who scan a plant come back the following day or week. This is ordinary aggregate analysis over data you can already see, export and delete; we are not building a profile of you, selling it, or sharing it with anyone. We describe it here because saying only that our analytics are anonymous would leave you with a more limited picture than the truth.
To keep you signed in we set one essential, secure session cookie. Our servers also keep standard operational logs (such as request and error logs) as part of running and securing the service.
We do not sell your personal information, and we don't share it for advertising. We share information only with the service providers that make the game work, and only as needed:
To describe a species we also look up openly available reference facts (for example native range and conservation status) from public botanical databases such as GBIF, POWO, and the IUCN. These lookups are keyed by a plant's scientific name only — no personal data about you is sent.
Trading a card with another player is the one place the game connects two accounts, and it is built to connect them for as little time as possible. While a trade is open we store which two accounts are in it, alongside the code and the card each of you has put down — that record lasts at most 24 hours and is deleted the moment the trade goes through. Afterwards all that remains is a count on each of your accounts, separately, rounded to the hour, so the game can apply your daily trading limit. Nothing links the two of you after that.
The other player is never shown your name, your email, or anything else about you— not while the trade is open and not afterwards. The code you send them is the only thing that identifies either of you to the other. A card you receive carries nothing about the person who caught it: no identifier, no nickname they gave it, and no record of where they found it.
We may also disclose information if required by law, to enforce our terms, or to protect the rights, safety, and security of our users and the service.
We use a single essential cookie to keep you signed in. It is HTTP-only and, in production, sent only over HTTPS. We do not use advertising cookies or third-party tracking cookies.
Supplant is not directed to children under 13 (or the equivalent minimum age in your country). The age screen determines whether an account is age-restricted; restricted accounts are blocked from features that collect personal information, such as scanning. We do not knowingly collect personal information from children under this threshold. If you believe a child under this age has provided us personal information, let us know and we will delete it.
We keep your account and gameplay data for as long as your account is active. Two things are minimized sooner: photos are not retained at all (see above), and the precise coordinates of a sighting are erased every night, so they are never kept beyond the current day — the life-list entry keeps only the species and date. A record of an open tradelasts at most 24 hours and is deleted when the trade completes; what survives is a per-account count, rounded to the hour, that the daily trading limit is measured against. If your account is deleted, we delete your personal information, except where we are required to keep it to comply with the law. Anonymous analytics events cannot be traced back to you and are retained in aggregate.
We protect your information with measures including encryption in transit (HTTPS) and secure, signed session cookies. No method of transmission or storage is perfectly secure, but we work to protect your information and limit access to it.
We operate the service from, and store data in, the United States. If you access Supplant from another country, you understand your information will be processed in the United States, which may have different data-protection laws than your own.
We may update this policy from time to time. When we do, we'll revise the “Last updated” date at the top. Significant changes will be communicated in the app where appropriate. Continuing to use Supplant after a change means you accept the updated policy.
You can download everything we store about your account at any time: open the menu, tap Settings, and choose Download my data. You'll get a JSON file containing your account record and every row tied to it — your plants and their equipment, your Seen life-list, your inventory, decks, battles, drops, and pending decisions.
You can permanently delete your account at any time from inside the app: open the menu, tap Settings, and choose Delete everything. If you no longer have the app installed, go to supplant.app/delete-account, which signs you in and takes you straight to that setting. This immediately and irreversibly erases your account and everything tied to it — your identified plants, your collection, your inventory, your decks and battle state, your coins, and your saved greenhouse and ATM locations. It cannot be undone. Signing in again afterwards with the same Google account creates a brand-new, empty account.
Two things are deliberately not linked to you and so are unaffected: cards you had already consigned to the market are anonymous once listed (they carry no reference back to you, they keep no nickname you gave them, and you were paid for them when you listed them), and our product analytics are fully anonymous with no account identifier. There is nothing in either that ties back to a deleted account.
For privacy questions, or to request account and data deletion by email instead of in the app, contact us at [email protected]. Significant changes to how we handle your data will also be surfaced in the app.