Legal
Privacy Policy
Gardi ("we", "us") respects your privacy and processes personal data only to the extent necessary for providing the app and associated services. This policy explains what data we collect, why, how long we retain it, and what rights you have under the General Data Protection Regulation (GDPR).
1. Who we are
Gardi is a garden app that lets you map your garden digitally, identify plants via AI, and keep track of a maintenance programme. The app is available for iOS (via the App Store), Android (via Google Play), and as a web app at app.gardi.nl.
2. Data we process
2.1 Account data
When you create an account via Google or email, we store:
- Email address
- Display name
- Firebase user ID (uid)
- Subscription status (free or premium)
You can also use the app anonymously. In that case, no email address or name is processed. Anonymous sessions are automatically deleted after 90 days of inactivity.
2.2 Garden data
- Garden name and dimensions
- Address and geographic coordinates (latitude/longitude) — only if you enter these for map detection
- Plant species, positions on the garden map, and care data
- Journal notes that you enter manually
- Calendar items and maintenance tasks
2.3 Photos
When you identify a plant via AI, you send a photo to our server. The photo is used exclusively for AI analysis and is not retained on our servers afterwards. Uploaded photos that you save within the app are stored in Firebase Storage for as long as your account exists.
2.4 Technical data
- Firebase Analytics: anonymous usage statistics (screen visits, features used). No advertising IDs.
- Last activity date: for each account we only store the date you last used the app (no times or history). We use this solely to count the number of active users (legitimate interest). The date is deleted together with your account.
- Firebase Crashlytics: crash reports with device and OS version.
- Server logs: IP addresses and request metadata, retained for a maximum of 30 days by Google Cloud Run.
2.5 Website visits (gardi.nl)
On our landing page we use Plausible Analytics, a privacy-friendly analytics service without cookies and without personal data. No tracking cookies are set; Plausible is fully GDPR-compliant.
2.6 Feedback and messages
When you send feedback through the app or exchange messages with the Gardi team, we store the content of the conversation (text and any screenshots), your user ID and technical context (app version, platform, language, the screen you were on, your number of plants and your subscription type). We use this solely to reply to you and to improve the app. Your email address is not stored with the conversation.
3. Purposes and legal bases
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Providing the app service (gardens, plants, maintenance) | Performance of a contract (6.1.b) |
| Plant identification via AI | Performance of a contract (6.1.b) |
| Sending maintenance notifications (push) | Consent (6.1.a) — withdrawable via device settings |
| Subscription management and billing | Performance of a contract (6.1.b) / Legal obligation (6.1.c) |
| App improvement (crash logs, usage statistics) | Legitimate interest (6.1.f) |
| Replying to feedback and messages | Legitimate interest (6.1.f) |
| Security and abuse prevention | Legitimate interest (6.1.f) |
4. Third parties and sub-processors
We use the following sub-processors. All processing takes place within the European Economic Area (EEA) or on the basis of adequacy decisions / Standard Contractual Clauses (SCCs).
| Service | Data processed | Location |
|---|---|---|
| Google Firebase (Auth, Firestore, Storage, Analytics, Crashlytics) | Account data, garden data, photos, crashes | EU (europe-west1) |
| Google Cloud Run | API requests, server logs | EU (europe-west1) |
| Google Gemini AI | Plant photos (for analysis only, not retained) | EU / US (SCC) |
| RevenueCat | Subscription status, transaction IDs (no full payment details) | US (SCC) |
| Plausible Analytics | Anonymised website statistics | EU |
| Google Play / Apple App Store | Payment and app distribution (outside our responsibility) | Their own policy applies |
We never sell your data to third parties and do not use it for advertising purposes.
5. Retention periods
- Account data and garden data: retained for as long as your account is active. After account deletion, all data is permanently erased within 30 days.
- Anonymous sessions: automatically deleted after 90 days of inactivity.
- Photos (stored in app): retained until you delete them or your account is deleted.
- Feedback and messages: closed conversations are automatically deleted 24 months after the last message. Open conversations are kept until they are closed or you delete your account; this also applies to conversations started from an anonymous session. When you delete your account, all your conversations are deleted as well.
- Server logs: maximum 30 days.
- Crash logs: maximum 90 days.
- Subscription history: 7 years (statutory retention obligation for financial records).
6. Your rights
Under the GDPR you have the following rights:
- Right of access: you can request what data we process about you.
- Right to rectification: you can have inaccurate data corrected. Name and email can be updated yourself via the app settings.
- Right to erasure: you can have your account and all associated data deleted via Settings → Account → Delete account in the app.
- Right to data portability: you can request an export of your garden data via Settings → Account → Export data.
- Right to restriction: you can request that processing be temporarily restricted while an objection is assessed.
- Right to object: you can object to processing based on legitimate interest.
- Withdraw consent: push notifications can be disabled via your phone's device settings.
Send your request to privacy@gardi.nl. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority (in the Netherlands: the Autoriteit Persoonsgegevens).
7. App permissions
| Permission | Purpose | Optional? |
|---|---|---|
| Camera | Taking photos for plant identification | Yes — you can also upload an existing photo |
| Photo library | Uploading existing photos for plant identification | Yes |
| Location (one-time) | Geocoding address when creating a garden (PDOK/BAG) | Yes — on request only, not continuous |
| Push notifications | Maintenance reminders (pruning, fertilising) | Yes — withdrawable via device settings |
8. Security
We implement appropriate technical and organisational measures to protect your data:
- All data transfer takes place via HTTPS/TLS 1.3.
- Data in Firestore is secured with Firebase Security Rules that restrict access to the garden owner.
- Firebase Storage files are not publicly accessible.
- Backend APIs require a valid Firebase ID token with every request.
- Sensitive fields (subscription status, counters) are only writable via the Admin SDK on our servers.
9. Children
Gardi is not directed at children under 16 years of age. We do not knowingly collect data from minors. If you suspect that a child has created an account, please contact us at privacy@gardi.nl.
10. Changes to this policy
We may update this privacy policy from time to time. For material changes we will notify you via the app or by email. The date at the top of this page indicates the most recent version. Continued use after an update constitutes acceptance of the revised policy.
11. Contact
For questions or requests regarding your privacy: