MyGardenGet the app

Privacy Policy

Last updated 30 July 2026

This policy explains what MyGarden does with your data. It covers the MyGarden mobile app and the mygrdn.app website. The controller is Nikola Dadić, Zagreb, Croatia, reachable at hello@mygrdn.app.

The short version

  • Your garden lives on your device. Plants, photos, care history, diary entries and schedules are stored locally on your phone, not on our servers.
  • What leaves your device does so to answer a question you asked — a photo you send for identification or diagnosis, the context needed for a chat reply, or the coordinates of a garden location so we can fetch its weather.
  • We do not sell your data and we do not use your photos or notes to train AI models.
  • Analytics are anonymous by default and hosted in the EU.

1. What we collect, and why

Account data

When you create an account we store your email address, an encrypted password credential, and the date you signed up. If you sign in with Apple we store the identifier Apple gives us and, where you choose to hide it, the relay email address. Purpose: to give you an account and to link a subscription to it. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

Your plants, photos and notes

Stored on your device. We do not hold a copy on our servers. Photos are transmitted to a processing provider only at the moment you ask for an identification, a health diagnosis or an answer about a photo — see section 3. Legal basis: performance of a contract.

Location of your garden spots

If you give a location approximate coordinates, we use them to fetch a local weather forecast and daylight data so watering and frost warnings are accurate for that spot. Coordinates are stored on your device and sent to our weather provider with each forecast request. We do not track your movements and the app does not collect background location. Legal basis: performance of a contract.

Usage limits

To keep AI features affordable we count requests per user per day (account identifier, date, which feature, a counter). No request content is stored. Legal basis: legitimate interest (Art. 6(1)(f)) in preventing abuse and controlling cost.

Purchases

If you subscribe in the app, Apple or Google process the payment and tell us only that an entitlement is active — we never see your card. If you subscribe on mygrdn.app, Stripe processes the payment as an independent controller for payment and fraud purposes, and we receive your subscription status, plan and billing country. Legal basis: performance of a contract and legal obligation (tax records).

Website analytics

We use PostHog (EU-hosted) to understand which pages people find useful. By default this is cookieless and anonymous — no cookie is set and no cross-site profile is built. If you sign in, events are linked to your account so we can support you and measure our own funnel. Legal basis: legitimate interest in operating and improving the site; you can opt out with your browser’s Global Privacy Control or Do Not Track signal, which we honour.

Support

If you email us, we keep the correspondence so we can help you and follow up. Legal basis: legitimate interest.

2. What we do not do

  • We do not sell or rent personal data.
  • We do not use your photos, plant notes or chat messages to train our own or third parties’ AI models.
  • We do not run advertising or share data with ad networks.
  • We do not collect background or continuous location.

3. Who processes data for us

These providers act on our instructions under data-processing agreements, except where noted as independent controllers.

  • Supabase (EU region) — authentication, database and the server functions that hold our API keys.
  • Google (Gemini API) — generates chat answers, care plans and photo analysis. Requests are sent through our own server so our keys stay off your device. Google states that data submitted through the paid Gemini API is not used to train its models.
  • Kindwise (EU) — plant and insect identification from a photo.
  • Open-Meteo (EU) — weather and forecast data, queried by coordinates.
  • PostHog (EU cloud) — website product analytics.
  • Stripe and RevenueCat — payments and subscription state for purchases made on the website. Stripe is an independent controller for payment processing.
  • Vercel — hosting for mygrdn.app.
  • Resend — transactional email (confirmation codes, password resets).

Some of these providers are based in the United States. Where data is transferred outside the EEA, transfers rely on the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

4. How long we keep things

  • Account data: until you delete your account, then removed promptly (backups roll off within 30 days).
  • On-device data: until you delete it or remove the app. Deleting the app deletes it.
  • Photos sent for analysis: not retained by us; our providers hold them only transiently for abuse-monitoring under their own policies.
  • Usage counters: rolling, kept no longer than 90 days.
  • Invoices and tax records: as required by law (typically 10 years in Croatia).
  • Support email: up to 24 months.

5. Your rights

Under the GDPR you can request access to your data, correction, deletion, restriction of processing, portability, and you can object to processing based on legitimate interest. You can withdraw consent where processing relies on it, without affecting prior processing.

The fastest route to deletion is in the app: Settings → Account → Delete account, which erases your account and associated server-side data and revokes any Sign in with Apple grant. For anything else, email hello@mygrdn.app; we answer within 30 days. You also have the right to complain to your supervisory authority — in Croatia, AZOP (azop.hr).

6. Children

The Service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.

7. Security

Data in transit is encrypted with TLS. Provider API keys are held as server-side secrets and never ship inside the app. Server endpoints require an authenticated session and enforce per-user rate limits. Access to production systems is limited to the operator of the Service. No system is perfectly secure; if a breach affects you, we will notify you and the supervisory authority as the law requires.

8. Cookies

The website sets no advertising or tracking cookies. Analytics run in cookieless mode. If you sign in, a strictly necessary cookie keeps you signed in; payment pages may set cookies required by Stripe for fraud prevention.

9. Changes

If we change this policy materially we will tell you in the app or by email before the change takes effect, and update the date at the top of this page.

10. Contact

Nikola Dadić, Zagreb, Croatia hello@mygrdn.app