Privacy Policy
Last updated: September 2026
1. Data Controller
The controller responsible for processing your personal data under the GDPR is:
Daniel JurgesHeckscherstrasse 6
20253 Hamburg
hej@theflora.app
2. Information We Collect
We collect information you provide directly: your name and email from Google or Apple Sign-In, plant photos you upload, care logs you record, and optional location data for climate-aware tips. We also collect limited technical data automatically, such as your device type, app version and crash diagnostics.
3. How We Use Your Information
We use your information to identify your plants, assess their health, build personalised care schedules and answer your questions; to send the care reminders you switch on; to run your household and any invites you send; to manage your subscription; and to fix crashes and improve the app.
4. Legal Basis for Processing
We rely on the following legal bases under Article 6(1) GDPR. Performance of our contract with you (Art. 6(1)(b)) covers account management, plant identification, care schedules and subscriptions. Your consent (Art. 6(1)(a)) covers push notifications, precise location and optional analytics, and you can withdraw it at any time in Settings. Our legitimate interests (Art. 6(1)(f)) cover keeping the service secure, preventing abuse, and understanding aggregate usage so we can improve Flora. Legal obligations (Art. 6(1)(c)) cover records we are required to keep, such as billing records.
5. AI Processing
Plant identifications, health assessments, care advice and chat replies are generated by Google Gemini, operated by Google as our processor. Photos and messages you submit are sent to that service for analysis; they are not used to train the provider's models and are not retained by the provider beyond processing your request. AI output is generated automatically and can be wrong. It is informational only and has no legal or similarly significant effect on you, so it is not automated decision-making within the meaning of Article 22 GDPR.
6. Data Storage and Security
Account data is held in a managed PostgreSQL database and photos in encrypted S3-compatible object storage. Data is encrypted in transit (TLS) and at rest, access is limited to what is needed to run the service, and we apply industry-standard security practices.
7. International Data Transfers
Some of our processors are based outside the EU/EEA, including in the United States. Where that is the case, transfers are covered either by a European Commission adequacy decision — such as the EU–US Data Privacy Framework, where the recipient is certified under it — or by the European Commission's Standard Contractual Clauses, together with supplementary measures where these are required. You can request a copy of the relevant safeguards using the contact details below.
8. Data Sharing
We do not sell your personal data. We share data only with service providers necessary to operate the app (cloud hosting, AI processing, push notifications, product analytics, and crash reporting). These providers act as processors and are bound by data processing agreements. We also measure whether our transactional emails are delivered, opened, and clicked, so we can improve them.
9. Push Notifications
If you enable push notifications, your device token is stored to send care reminders. You can disable notifications at any time in Settings.
10. Data Retention
We keep your account data for as long as your account exists. If you delete your account, your personal data (such as your name, email, and login credentials) is anonymised immediately. Content you contributed to a shared household — plants, photos, and care history — is not deleted along with your account; it remains part of the household for its other members, unless you are the household's only member, in which case it and its photos are deleted from storage along with your account. Server and error logs are kept for up to 90 days. Billing records are kept for as long as tax and commercial law requires, which in Germany is up to ten years. Anonymised data that can no longer be linked to you may be retained indefinitely for analytics.
11. Your Rights
If you are in the EU/EEA or the UK, you have the right to access your data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable, machine-readable format. You can export your data or delete your account at any time from Settings → Danger Zone. Where processing is based on consent, you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal. You also have the right to lodge a complaint with a data protection supervisory authority — either in the EU/EEA country where you live or work, or with the authority competent for us, the Hamburg Commissioner for Data Protection and Freedom of Information.
12. Children's Privacy
Flora is not directed at children. We do not knowingly collect personal information from anyone under 13. If you are in the EEA and below the age of digital consent in your country — which ranges from 13 to 16 depending on the country — any processing we base on consent requires the consent of a holder of parental responsibility. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Changes to This Policy
We may update this policy. We will notify you of significant changes via the app. Continued use constitutes acceptance.
14. Contact
For privacy questions, data requests, or to exercise any of the rights above, contact us at hej@theflora.app. We respond within one month, as required by Article 12(3) GDPR.