Legal

Privacy Policy

Last updated: 26 August 2026

Greenkeep cares about your privacy. This policy explains what personal data we process when you use the app and the website, why we do it, and the rights you have. It is written in line with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nFADP). The app is not on the stores yet: for now we only process the data this website collects, namely your waitlist signup, the messages you send us, the photo you submit for a free diagnosis, and technical data. The parts about the app describe what will happen once you start using it.

1. Data controller

The data controller is Federico Baldini, a natural person based in Switzerland. You can contact them at privacy@greenkeep.io; the full postal address is available on request.

2. Data we collect

We only collect the data needed to let you use Greenkeep:

  • Email — when you create an account (passwordless sign-in via an email link) or join the waitlist.
  • Invite code — if you join the waitlist through another subscriber's personal link, we record their code alongside your signup, for the sole purpose of understanding how the list grows (word of mouth). It follows the same retention as the signup.
  • Plant photos — which you upload for species identification, health diagnosis, or the Gemma chat. They are stored privately and accessible only to you.
  • Care data — your plants, care events (watering, fertilizing…), care plans, diagnoses, health cases, and Gemma conversations. If you complete the plant suggestions questionnaire, we also save the winter climate band you declare on your profile, so your care plan can follow the seasons where you live: it is your own answer, not something inferred from your location.
  • Sharing invite email — if you share a plant with someone who is not registered yet, we store the email address you enter for the sole purpose of delivering the invitation and activating the share when they sign up.
  • Approximate location — only if you grant location access, we use your device’s city-level (~1 km) position to show you the local weather and related tips. We send it to the weather provider (OpenWeatherMap) to fetch the forecast and do not store it on our servers. If you turned weather alerts on, the position already stored is also used to **let the care plan follow the seasons**: the app works out on your phone how many hours of daylight there are where you live and stretches or shortens the intervals accordingly, without sending your position to anyone for this purpose.
  • Technical data — app version, platform, application logs, and the IP address of requests, used for security and diagnostics.
  • Site statistics (cookieless) — how many visits a page gets, the country, the device type, and the site you came from. These are overall figures: they do not identify you, nothing stays on your device, and no consent is required. Details in §13.
  • In-app usage events (analytics) — only with your consent, we collect a few essential usage events (like “plant added” or “diagnosis completed”) to understand which features truly help: never photos, notes or your plants’ content. Analytics stays off until you turn it on, and you can change your mind anytime from your profile (“Privacy & usage data”): turning it off stops sending at once and resets the analytics identifier.
  • Subscription data — the status of your subscription and purchases, handled through the app stores and our payment provider; we do not process your card details.

We do not collect special categories of data and we do not sell your data.

3. How we use the data

We use your data to:

  • provide your account and the app’s features (plants, care, diagnosis, Gemma);
  • generate identifications, diagnoses, and care plans through the AI;
  • send care reminders and, with your consent, push notifications;
  • show you the local weather, related tips, species suited to your climate and a care plan that follows the seasons, if you share your location;
  • respond to your support requests;
  • understand which features truly help, through a few essential usage events and only if you consent;
  • ensure security, prevent abuse, and improve the service.

4. Plant photos and AI

To identify plants, diagnose health issues, generate care plans, and reply in the Gemma chat, your photos and the related data (species, environment, care history) are sent to our AI provider, Anthropic (Claude), which processes them on our behalf on servers in the United States. You normally photograph the plant, but the light check asks you to photograph the spot where you keep it (a corner, a windowsill, a balcony): that image shows part of your home and follows the same path as the other photos. Frame only what is needed to judge the light.

Photos are not used to train third-party AI models. The AI key stays on our servers: the app never talks to the AI provider directly.

On the website we offer a free diagnosis with no sign-up: you upload a photo and we send it to Anthropic for the diagnosis but — unlike the app — we do not keep it on our servers. The photo stays only temporarily in your browser.

To prevent abuse and keep costs down, for each request we store only a salted (non-reversible) hash of your IP address and of an anonymous browser identifier — never the IP in clear text — and we use the Cloudflare Turnstile service to verify that you are a person. This anti-abuse data is deleted after 30 days.

The AI features give you guidance and suggestions: we take no automated decisions producing legal effects concerning you, or similarly significantly affecting you (Art. 22 GDPR). A diagnosis is support, not a decision — you always remain the one who chooses what to do with your plants.

5. Mode and place of processing

We process data using IT tools and apply appropriate technical and organizational security measures to protect it against unauthorized access, loss, disclosure, or alteration. Access is limited to the owner and to providers acting as data processors.

Data is processed at the operating premises of the owner and of the providers involved. Depending on your location, some transfers may involve sending data to a country other than yours, including the United States; in that case we apply appropriate safeguards (Standard Contractual Clauses).

6. Legal basis (GDPR/nFADP)

We process your data on the following legal bases:

  • Performance of a contract (Art. 6(1)(b) GDPR) — to provide your account and the app’s features.
  • Consent (Art. 6(1)(a)) — for the waitlist signup, push notifications, location access for the weather, and analytics tools: analytics cookies on the site and in-app usage events, which stay off until you turn them on.
  • Legitimate interest (Art. 6(1)(f)) — for security, abuse prevention, service improvement, error and crash reporting (Sentry), and the cookieless aggregate measurement of site traffic (§13). All of this stays on regardless of analytics consent and serves no advertising purpose; you can object at any time by writing to privacy@greenkeep.io.

In Switzerland, the corresponding bases under the nFADP apply.

7. Data retention

We keep your data for as long as you keep your account, and then for as long as needed for the purposes it was collected for or as required by law. In particular:

  • Account and care data — while the account is active. When you request deletion the account is **frozen immediately** and can no longer be used; **after 14 days** we permanently delete all related data (plants, photos, care events, plans, diagnoses, health cases, conversations with Gemma, notification tokens and avatar). During those 14 days you can still cancel the request and get the account back intact.
  • While the account is frozen we send you neither care reminders nor promotional messages: only the emails of this process (freeze, reminder two days before the deadline, confirmation once the deletion has happened).
  • Plants you share with someone in the **Editor** role pass to them, photos included, instead of being deleted: they are data that person is using. Plants shared only with a **Viewer**, or not shared at all, are deleted with the account. In the app you can choose to delete everything anyway.
  • Only what we are legally required to keep remains, for example the tax records of purchases (which live with the stores), technical logs for as long as security and diagnostics require, and already-anonymous anti-abuse hashes, which expire on their own within 7-30 days.
  • Web deletion requests that were never confirmed — kept for at most 24 hours, then deleted. The confirmation code the app asks for is stored only as a hash, lasts 10 minutes and can be used once.
  • AI usage data — deleted automatically after 13 months.
  • Pending sharing invites — the invitee’s email is kept for at most 30 days: if they do not sign up within that time the invitation expires and is deleted; if they sign up earlier, the invitation becomes a share and the row is removed.
  • Web-diagnosis anti-abuse data (IP and visitor hashes) — deleted after 30 days.
  • Anti-abuse / rate-limit data for the web forms and app endpoints (waitlist, contact, consent log, weather, AI requests, login link; salted hashes of the IP and, for the login link only, of the email: never the clear-text values) — deleted after 7 days.
  • Never-activated accounts (a sign-in request whose link was never clicked: no session, no data) — deleted after 7 days.
  • Web consent log (IP and visitor hashes) — kept for 24 months.
  • Waitlist signup — kept until the app launches, and in any case **at most 24 months** from signup: if the app isn’t out yet we ask you to re-confirm at 12 months, and without an answer within 30 days we delete the row. At launch, once the founder window closes (launch + 3 months), the waitlist is emptied.
  • Two separate actions on your signup: **Unsubscribe** stops the emails but **keeps** the row (you keep your founder place); **Delete my data** **removes** the row (you lose the founder place). Both links are in every email.
  • Never-confirmed waitlist signups — deleted after 14 days. If you don't click the confirmation link we send you, your address never joins the list and is removed.
  • Application logs — for as long as needed for security and diagnostics.

Data processed on the basis of consent is kept until you withdraw consent; we may keep it longer where a legal obligation requires it.

8. Sharing with third parties

We do not sell your data. We share it only with providers that process it on our behalf, as data processors:

  • Supabase — database, authentication, and photo storage (EU, Frankfurt).
  • Vercel — website hosting and delivery (edge); processes technical data such as your IP address to serve pages, and produces the aggregate traffic measurement described in §13, with no cookies and without storing your IP address.
  • Anthropic (Claude) — AI processing of photos and text (USA).
  • Cloudflare Turnstile — anti-bot (captcha) verification for the web forms: free diagnosis, waitlist sign-up, and contact.
  • Apple App Store and RevenueCat — purchase and subscription management (USA).
  • Google Play — purchase and subscription management (for EU users via Google Ireland; Ireland/USA).
  • Resend — sending transactional emails (e.g. waitlist confirmation).
  • OpenWeatherMap — weather data for care recommendations.
  • Sentry — app and site error and crash reporting (USA), on legitimate interest.
  • PostHog — product usage analytics (EU); in the app only with your consent.
  • Expo — push-notification delivery.

Transfers to the United States are carried out with appropriate safeguards (Standard Contractual Clauses).

9. Push notifications

With your consent we may send you push notifications: care reminders and alerts about shared-plant events (for example when someone shares a plant with you or changes your role). Together with the notification token we store your device's language, so notifications arrive in your language. From the profile's Notifications screen you can choose which categories to receive; we store these preferences on your account. For care reminders we store your device's time zone and how far ahead the app managed to schedule them, so we can send you the digest even when the phone cannot. If you enable **weather alerts**, we also store your approximate location (city level, ~1 km), so we can check tomorrow's conditions in the evening and warn you only about frost, extreme heat or heavy rain: turning the switch off deletes this data immediately. You can also turn them off in your device settings; disabling them may reduce the usefulness of some features.

10. Your rights

To the extent permitted by law, you have the following rights over your data:

  • Access — to know whether we process your data and obtain a copy of it.
  • Rectification — to correct inaccurate or incomplete data.
  • Erasure — to ask us to delete your data.
  • Restriction — to ask us to restrict processing.
  • Objection — to object to processing based on legitimate interest.
  • Portability — to receive your data in a structured format and, where technically feasible, have it transferred to another controller.
  • Withdraw consent — at any time, without affecting the lawfulness of prior processing.

You do not need to go through us to delete your account: you can do it yourself in the app, under Profile → Delete account, or from the website on the «Delete your data» page, even if you no longer have the app installed. Either way the process is the one described in section 7: an immediate freeze, and permanent deletion after 14 days.

To exercise these rights, write to privacy@greenkeep.io: we will respond free of charge and as soon as possible, usually within one month. You also have the right to lodge a complaint with the competent supervisory authority (in Switzerland the FDPIC; in the EU your country’s data protection authority).

11. Users in Switzerland (nFADP)

This section applies to users in Switzerland and, for such users, supersedes any divergent provisions in this policy. We process your data under the Swiss Federal Act on Data Protection (nFADP).

As a user in Switzerland you have, in particular, the right to access your data, to object to processing (including to request restriction or deletion), to data portability, and to rectification of inaccurate data. To exercise them, write to privacy@greenkeep.io; you may also contact the Federal Data Protection and Information Commissioner (FDPIC).

12. Users in the United States

This section applies to users resident in the United States. We do not sell or “share” (as defined by the CCPA and similar state laws) your personal data, and we do not use it for cross-context behavioral advertising.

To the extent permitted by applicable law, you can ask to know and access the data we process about you, to correct it, to delete it, and to receive a copy of it. To exercise these rights, write to privacy@greenkeep.io; we will not discriminate against you for doing so. We honor browser preference signals such as the Global Privacy Control (GPC).

14. Legal action and legal obligations

We may process your data for purposes connected with legal claims or defense, in case of misuse of the service, and we may be required to disclose it at the request of competent public authorities, within the limits of the law.

15. Changes to this policy

We may update this policy. For material changes we will give notice (for example on the website, in the app, or by email) and, where the changes concern processing based on consent, we will collect new consent where required. Please check this page from time to time, referring to the last-updated date.

16. Definitions

  • Personal data — any information that, directly or indirectly, allows a natural person to be identified.
  • Data controller — the party that determines the purposes and means of processing (here: Federico Baldini).
  • Data processor — the provider that processes data on the controller’s behalf.
  • Cookie / Tracker — small data or technologies (cookies, identifiers, scripts) that store or read information on your device.
  • Sale / Sharing (CCPA) — the transfer of personal data to third parties for valuable consideration or for cross-context behavioral advertising; an exchange with a provider bound by a contract is not a sale or sharing.

17. Children

Greenkeep is not intended for children under 16: you must be at least 16 to use the app and our services, as set out in the Terms and Conditions. We do not knowingly collect data from children under 16, and we offer no content designed for them.

If you become aware that a child under 16 has given us their data without the consent of the holder of parental responsibility, write to privacy@greenkeep.io: we will delete the data without undue delay.

18. Contact

For any question about this policy or your data, write to privacy@greenkeep.io. Data controller: Federico Baldini (Switzerland); the full postal address is available on request.