Legal

Privacy Policy

Last updated: 15 July 2026

Greenkeep cares about your privacy. This policy explains what personal data we process when you use the app and the website, why we do it, and the rights you have. It is written in line with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nFADP).

1. Data controller

The data controller is Federico Baldini, a natural person based in Switzerland. You can contact them at privacy@greenkeep.io; the full postal address is available on request.

2. Data we collect

We only collect the data needed to let you use Greenkeep:

  • Email — when you create an account (passwordless sign-in via an email link) or join the waitlist.
  • Plant photos — which you upload for species identification, health diagnosis, or the Gemma chat. They are stored privately and accessible only to you.
  • Care data — your plants, care events (watering, fertilizing…), care plans, diagnoses, health cases, and Gemma conversations.
  • Technical data — app version, platform, application logs, and the IP address of requests, used for security and diagnostics.
  • Subscription data — the status of your subscription and purchases, handled through the app stores and our payment provider; we do not process your card details.

We do not collect special categories of data and we do not sell your data.

3. How we use the data

We use your data to:

  • provide your account and the app’s features (plants, care, diagnosis, Gemma);
  • generate identifications, diagnoses, and care plans through the AI;
  • send care reminders and, with your consent, push notifications;
  • respond to your support requests;
  • ensure security, prevent abuse, and improve the service.

4. Plant photos and AI

To identify plants, diagnose health issues, generate care plans, and reply in the Gemma chat, your photos and the related data (species, environment, care history) are sent to our AI provider, Anthropic (Claude), which processes them on our behalf on servers in the United States.

Photos are not used to train third-party AI models. The AI key stays on our servers: the app never talks to the AI provider directly.

On the website we offer a free diagnosis with no sign-up: you upload a photo and we send it to Anthropic for the diagnosis but — unlike the app — we do not keep it on our servers. The photo stays only temporarily in your browser.

To prevent abuse and keep costs down, for each request we store only a salted (non-reversible) hash of your IP address and of an anonymous browser identifier — never the IP in clear text — and we use the Cloudflare Turnstile service to verify that you are a person. This anti-abuse data is deleted after 30 days.

The AI features give you guidance and suggestions: we take no automated decisions producing legal effects concerning you, or similarly significantly affecting you (Art. 22 GDPR). A diagnosis is support, not a decision — you always remain the one who chooses what to do with your plants.

5. Mode and place of processing

We process data using IT tools and apply appropriate technical and organizational security measures to protect it against unauthorized access, loss, disclosure, or alteration. Access is limited to the owner and to providers acting as data processors.

Data is processed at the operating premises of the owner and of the providers involved. Depending on your location, some transfers may involve sending data to a country other than yours, including the United States; in that case we apply appropriate safeguards (Standard Contractual Clauses).

6. Legal basis (GDPR/nFADP)

We process your data on the following legal bases:

  • Performance of a contract (Art. 6(1)(b) GDPR) — to provide your account and the app’s features.
  • Consent (Art. 6(1)(a)) — for the waitlist signup, push notifications, and analytics tools.
  • Legitimate interest (Art. 6(1)(f)) — for security, abuse prevention, and service improvement.

In Switzerland, the corresponding bases under the nFADP apply.

7. Data retention

We keep your data for as long as you keep your account, and then for as long as needed for the purposes it was collected for or as required by law. In particular:

  • Account and care data — while the account is active; on account closure the related data (plants, care, diagnoses, conversations, and photos) is deleted in cascade.
  • AI usage data — deleted automatically after 13 months.
  • Web-diagnosis anti-abuse data (IP and visitor hashes) — deleted after 30 days.
  • Web-form anti-abuse / rate-limit data (waitlist, contact, consent log; IP hash) — deleted after 7 days.
  • Web consent log (IP and visitor hashes) — kept for 24 months.
  • Waitlist signup — kept until the app launches, and in any case **at most 24 months** from signup: if the app isn’t out yet we ask you to re-confirm at 12 months, and without an answer within 30 days we delete the row. At launch, once the founder window closes (launch + 3 months), the waitlist is emptied.
  • Two separate actions on your signup: **Unsubscribe** stops the emails but **keeps** the row (you keep your founder place); **Delete my data** **removes** the row (you lose the founder place). Both links are in every email.
  • Never-confirmed waitlist signups — deleted after 14 days. If you don't click the confirmation link we send you, your address never joins the list and is removed.
  • Application logs — for as long as needed for security and diagnostics.

Data processed on the basis of consent is kept until you withdraw consent; we may keep it longer where a legal obligation requires it.

8. Sharing with third parties

We do not sell your data. We share it only with providers that process it on our behalf, as data processors:

  • Supabase — database, authentication, and photo storage (EU, Frankfurt).
  • Vercel — website hosting and delivery (edge); processes technical data such as your IP address to serve pages.
  • Anthropic (Claude) — AI processing of photos and text (USA).
  • Cloudflare Turnstile — anti-bot (captcha) verification for the web forms: free diagnosis, waitlist sign-up, and contact.
  • Apple App Store and RevenueCat — purchase and subscription management (USA).
  • Google Play — purchase and subscription management (for EU users via Google Ireland; Ireland/USA).
  • Resend — sending transactional emails (e.g. waitlist confirmation).
  • OpenWeatherMap — weather data for care recommendations.
  • Sentry — app error and crash reporting (USA).
  • PostHog — product usage analytics (EU).
  • Expo — push-notification delivery.

Transfers to the United States are carried out with appropriate safeguards (Standard Contractual Clauses).

9. Push notifications

With your consent we may send you push notifications (for example care reminders). You can turn them off at any time in your device settings. Disabling notifications may reduce the usefulness of some features.

10. Your rights

To the extent permitted by law, you have the following rights over your data:

  • Access — to know whether we process your data and obtain a copy of it.
  • Rectification — to correct inaccurate or incomplete data.
  • Erasure — to ask us to delete your data.
  • Restriction — to ask us to restrict processing.
  • Objection — to object to processing based on legitimate interest.
  • Portability — to receive your data in a structured format and, where technically feasible, have it transferred to another controller.
  • Withdraw consent — at any time, without affecting the lawfulness of prior processing.

To exercise these rights, write to privacy@greenkeep.io: we will respond free of charge and as soon as possible, usually within one month. You also have the right to lodge a complaint with the competent supervisory authority (in Switzerland the FDPIC; in the EU your country’s data protection authority).

11. Users in Switzerland (nFADP)

This section applies to users in Switzerland and, for such users, supersedes any divergent provisions in this policy. We process your data under the Swiss Federal Act on Data Protection (nFADP).

As a user in Switzerland you have, in particular, the right to access your data, to object to processing (including to request restriction or deletion), to data portability, and to rectification of inaccurate data. To exercise them, write to privacy@greenkeep.io; you may also contact the Federal Data Protection and Information Commissioner (FDPIC).

12. Users in the United States

This section applies to users resident in the United States. We do not sell or “share” (as defined by the CCPA and similar state laws) your personal data, and we do not use it for cross-context behavioral advertising.

To the extent permitted by applicable law, you can ask to know and access the data we process about you, to correct it, to delete it, and to receive a copy of it. To exercise these rights, write to privacy@greenkeep.io; we will not discriminate against you for doing so. We honor browser preference signals such as the Global Privacy Control (GPC).

14. Legal action and legal obligations

We may process your data for purposes connected with legal claims or defense, in case of misuse of the service, and we may be required to disclose it at the request of competent public authorities, within the limits of the law.

15. Changes to this policy

We may update this policy. For material changes we will give notice (for example on the website, in the app, or by email) and, where the changes concern processing based on consent, we will collect new consent where required. Please check this page from time to time, referring to the last-updated date.

16. Definitions

  • Personal data — any information that, directly or indirectly, allows a natural person to be identified.
  • Data controller — the party that determines the purposes and means of processing (here: Federico Baldini).
  • Data processor — the provider that processes data on the controller’s behalf.
  • Cookie / Tracker — small data or technologies (cookies, identifiers, scripts) that store or read information on your device.
  • Sale / Sharing (CCPA) — the transfer of personal data to third parties for valuable consideration or for cross-context behavioral advertising; an exchange with a provider bound by a contract is not a sale or sharing.

17. Children

Greenkeep is not intended for children under 16: you must be at least 16 to use the app and our services, as set out in the Terms and Conditions. We do not knowingly collect data from children under 16, and we offer no content designed for them.

If you become aware that a child under 16 has given us their data without the consent of the holder of parental responsibility, write to privacy@greenkeep.io: we will delete the data without undue delay.

18. Contact

For any question about this policy or your data, write to privacy@greenkeep.io. Data controller: Federico Baldini (Switzerland); the full postal address is available on request.