Privacy Policy

Last updated: 25 September 2026

1. What data do we collect?

We collect the following personal data when you use GardenWorld: name, email address, photos of your garden, garden preferences and payment information. Photos are used exclusively for generating garden designs. What the app collects when you use it without an account is described in section 10.

2. How do we use your data?

Your data is used to generate personalised garden designs, manage your account, process payments and improve our services. We do not share your data with third parties for marketing purposes.

3. Processing of designs

Garden photos and preferences go through OpenRouter to the image model and the analysis model of the provider listed in section 4. These create the design and analyse the photo. This data is not used for training models. Generated designs are stored in your account, or in the app under the device ID (section 10).

4. Who processes your data?

We only share your data with the processors below. Each of them processes it only for the purpose stated and must protect it at least as well as this policy does. Before the first photo leaves your phone, the app names the processors from this list that apply to the app.

OpenRouter
Passes your photo and your answers on to the image model and the analysis model, and the result back.
United States
Google
Provides the image model that creates the design and the model that analyses the photo, through OpenRouter.
United States
Cloudflare R2
Stores your photos and the generated images.
United States
Microsoft Azure
Runs our server and our database.
Ireland (EU)
SMTP2GO
Sends our emails, such as the link to your design when you ask for it.
New Zealand
RevenueCat
Verifies purchases in the app with Apple and Google and keeps track of what you have unlocked.
United States
PostHog
Measures how the website and the app are used, without the content of your photos or designs.
United States (company); the measurements are stored in the PostHog EU cloud
Clerk
Manages accounts on the website: signing in, name and email address.
United States
Stripe
Processes payments on the website.
Ireland (EU) and United States
Expo
Delivers push notifications to the app, only if you allow notifications. Reminders you schedule yourself in the app stay on your phone.
United States

5. Payment processing

Payments on the website are securely processed via Stripe. We do not store credit card details on our servers. Stripe processes your payment information in accordance with the PCI DSS standard. In the app you pay through Apple (App Store) or Google (Google Play), under their own terms and privacy policies; we do not receive any card details. RevenueCat confirms the purchase to us.

6. Retention periods

We do not retain your personal data longer than necessary for the purposes for which it was collected. Account data is retained as long as your account is active. After deletion of your account, your data is permanently erased within 30 days. Payment data is retained for 7 years in accordance with legal requirements. If you make a design on the website without an account and do not buy it, we delete it after 72 hours, together with the photo and the generated images; a link you have emailed to yourself to continue works for the same time and is deleted afterwards. Of a deleted design we only keep a count without content (the day, the language, the variant and whether it succeeded), without photo, answers, name or IP hash, so that we can see how many designs are made. For the app without an account, the periods in section 10 apply.

7. International data transfers

Some of our processors are established in the United States or in New Zealand (section 4). Transfers to the United States take place on the basis of Standard Contractual Clauses (SCC) and the EU-US Data Privacy Framework. For New Zealand, an adequacy decision of the European Commission applies. Payments are processed by Stripe, which complies with PCI DSS and stores data within the EU where possible.

8. Legal basis for processing

We process your data on the basis of: (a) performance of the contract (account management, design generation), (b) your consent (analytical cookies, and in the app sending your photo), and (c) legitimate interest (security, fraud prevention, service improvement). You can withdraw your consent at any time via the cookie settings, or in the app as described in section 10. The app asks for your consent before the first photo leaves your phone, naming the processors; if that list changes, the app asks again.

9. Your rights

Under the GDPR, you have the right to access, rectify, delete and port your personal data. You can delete your account and all associated data via your account settings or by contacting us. If you use the app without an account, you erase everything with “Erase my data” (section 10). See also our cookie policy for information about cookies.

10. The app

The GardenWorld app for iOS and Android works without an account. On first launch the app creates a random device ID. It is not an account and carries no name or email address. Linked to that ID, we hold: the garden photo you choose (the app removes the location data from the photo on your phone already), your answers to the questions and the resulting design. If you scan a garden or have a plant recognised, that photo and the result are linked to the ID as well. To limit abuse, we also store a hash of your IP address with each design, scan and recognition, not the address itself; it disappears together with that design, scan or recognition.

A preview you do not buy is deleted after 72 hours, together with the photo and the generated images. A design you buy is kept, so you can keep opening it. Scans and recognitions are kept until you delete them.

Under More you will find “Erase my data”. It erases everything of this device on our side: designs, photos, images, scans and recognitions, including the files in our storage. Only the purchase records remain, without the photo, because bookkeeping requires them. On your phone the app erases the same data.

The app measures usage with a fixed list of events, without content: no photo, no text you type, no name or email address. These measurements are linked to the device ID and go through our server to PostHog.

To withdraw your consent: stop sending photos and use “Erase my data”; what we held is then gone. Access to the camera, photos and notifications is withdrawn in your phone’s settings. You can also email [email protected].

Accounts in the app will come in a later version. You will then also be able to delete your account in the app itself, with all data linked to it, within the periods in section 6.

11. Contact

For questions about this privacy policy, you can contact us by email: [email protected]