What stays on your device
Your beds, plants, projects, notes and photos are saved in your browser's local storage on the device you use. Clearing that storage, or the browser, removes them. GardenLab cannot see this data and cannot recover it for you unless you have chosen to keep your garden online (below).
What leaves your device, and to whom
Each row is triggered by an action you take. None happens on its own.
| When you | What is sent | To whom |
|---|---|---|
| Identify a plant from a photo | That photo only. GardenLab's own server forwards it and does not keep a copy. | Pl@ntNet (a plant-identification service run by a French research consortium). Their handling of the image is governed by their terms. |
| Ask a question in the app | Your question and a text summary of your garden (bed names, plant names, conditions) so the answer is about your garden. No photos. | An AI provider (currently Anthropic) via GardenLab's server, which does not store the exchange. |
| Keep your garden online | Your email address, and the garden data you built: beds, plants, projects, notes, and the garden's location as recorded (see the Location row), which syncs with the record. Photos are not sent; they stay on your device and travel only in your own backup file. | Supabase, the database and sign-in provider GardenLab runs on. Your email is used to send you a sign-in code, delivered by Resend, an email service, and for nothing else. If you choose "Continue with Google" instead, Google handles that sign-in under its own terms and GardenLab receives your email address only. |
| Publish your garden page, or share your garden by link | What the page shows: the beds, plants, notes and photos it draws on. A shared link carries beds and plants only. Both are choices you make in Settings, and both can be taken down there. | Supabase storage. Anyone who has the address can open it; it is not listed or indexed. A garden appears on this site's Gardens page only when its gardener asks for that, and it comes off the same way. |
| Location (opt-in) | Only if you choose it: your device's GPS fix (the browser asks first) or the town or ZIP you type. What is kept, on your device and with your record when you keep it online, is the town-level point, the ZIP area, not the fix itself. It is never sold, and anything ever shared or aggregated is at ZIP level, never finer. | The lookups in the next two rows, and nowhere else. |
| Set up your garden's climate | Where the garden is: the town or ZIP you type, or, if you tap "Use my location", your device's position, once. GardenLab's server turns it into a town-level point and keeps nothing; your device stores the town, never the position. | GardenLab's server, which forwards it to public geocoding and climate services: OpenStreetMap Nominatim, the US Census geocoder, phzmapi.org for the USDA hardiness zone, and Open-Meteo for frost history. |
| Estimate a bed's soil from the USDA survey | Your device's position, once, so the survey can be read for your area. It is not stored. | GardenLab's server, which forwards it to the USDA Soil Data Access service. |
| Load any page | Standard web-server access logs (IP address, browser type, time). | Netlify, the hosting provider. GardenLab does not run analytics or tracking scripts. |
What is never collected
- Your exact location. GardenLab asks for your position only when you choose "Use my location" to set up the garden's climate or a bed's soil, and then it keeps the town, not the position: no street-level coordinates are stored, for you or your garden. Photos you attach are re-encoded in the browser, which removes embedded location data before they are stored.
- Your name, address, or contacts.
- Anything for advertising or profiling.
The demo garden
When you first open the app you see a real garden in Irvington, New York, loaded as an example. It is the owner's, shared deliberately. Anything you do to it stays in your browser until you start your own garden, which replaces it.
Deleting your data
- On your device: clear the site's data in your browser, or start a new garden in the app.
- Online: in the app, open Settings and choose "Delete my garden". It removes the online copy from your account together with the copy on the device, and no copy is kept. If you can no longer get into the app, write to hernan@pisano.pro from the address you signed in with and the online copy is deleted, usually within a week.
You can also ask, at the same address, for a copy of everything held online about you. The app's own backup export gives you the same thing at any time without asking.
Age
GardenLab is for adults. It is not directed at children under 18 and does not knowingly hold data about them.
Changes
If this policy changes, the date at the top changes and the previous version stays available on request. Any change that sends new data to a new recipient will be announced in the app before it takes effect.
Contact
Hernan Pisano, Irvington, New York. hernan@pisano.pro