Skip to content
Legal

Privacy Policy

Last updated: July 26, 2026Version 1.0
On this page
  1. 1. Controller
  2. 2. General principles
  3. 3. What data we process
  4. 4. Cookies
  5. 5. Audience measurement
  6. 6. Processors and external services
  7. 7. Retention
  8. 8. No automated decision-making
  9. 9. Your rights (GDPR Art. 15 to 22)
  10. 10. Backups and deletion periods
  11. 11. Minimum age
  12. 12. Security (GDPR Art. 32)
  13. 13. Data breach notification

1. Controller

The controller for data processing within the meaning of the GDPR is:

Robert Gürgens
Software- und IT-Dienstleistungen
Suhler Straße 17
12629 Berlin
Germany

Email: dpo@gartenkern.de

We are not legally required to appoint a data protection officer. The address above reaches the controller directly.

2. General principles

We process personal data of our users only to the extent necessary to provide a functional platform and to fulfil our contractual and legal obligations (data minimisation, Art. 5 GDPR).

  • Art. 6 (1)(a) GDPR: consent, where you grant it separately for individual features
  • Art. 6 (1)(b) GDPR: performance of a contract (account, platform use)
  • Art. 6 (1)(c) GDPR: legal obligation (accounting, taxes)
  • Art. 6 (1)(f) GDPR: legitimate interests (security, abuse detection)

You may withdraw consent at any time with effect for the future (Art. 7 (3) GDPR). The lawfulness of processing carried out before withdrawal remains unaffected.

3. What data we process

DataPurposeLegal basis
Email, display nameAccount creation, loginArt. 6 (1)(b)
Workspace and garden content (plantings, journal, tasks, images)Platform useArt. 6 (1)(b)
Garden location polygonMap and weather featuresArt. 6 (1)(b)
EXIF data in uploaded imagesStripped before storage (data minimisation)not applicable
Technical checksum of uploaded imagesMatched against content we previously removed, prevents re-upload. The image itself is not stored for this.Art. 6 (1)(f)
Content you set to "Community" or "Public"Display to signed-in users or to any visitor. Voluntary, revocable at any time; shown without your name.Art. 6 (1)(a)
Reports submitted via the "Report content" button (statement, optional contact details, IP)Handling under DSA Art. 16, record of handling, abuse protection via rate limitArt. 6 (1)(c), Art. 6 (1)(f)
IP address on login and uploadSecurity, abuse detectionArt. 6 (1)(f)
Server log files (IP, timestamp, requested resource, status code)Operation, debugging, attack defenceArt. 6 (1)(f)
Payment references and subscription statusContract performance, accountingArt. 6 (1)(b), Art. 6 (1)(c)
Cancellation declaration submitted through the cancellation button (contract number, email, name, reason)Evidence under § 312k (3) and (4) of the German Civil CodeArt. 6 (1)(c)
Cookies (session, locale, theme)Platform function (strictly necessary)Art. 6 (1)(b) + § 25 (2) TDDDG

4. Cookies

We use strictly necessary cookies only:

  • ory_kratos_session: login session (essential, session cookie)
  • csrf_token_…: cross-site request forgery protection (essential)
  • NEXT_LOCALE: selected language (essential)
  • theme: light or dark preference (essential)
  • gartenkern_invite_token: validation of your invite code during the closed beta (essential, HttpOnly, expires after 2 hours)

There is no tracking, no profiling, and no third-party advertising. A cookie consent banner is therefore not required under § 25 (2) TDDDG.

5. Audience measurement

We want to know which pages are read and whether what we offer lands. For that we use no Google Analytics and no other outside service, but our own measurement on our server in Nuremberg. It sets no cookie and stores or reads nothing on your device.

For a page view we store:

  • the page you opened, in coarsened form. /gardens/8f2c… becomes /gardens/{id}; the identifier itself is discarded.
  • the language of the page (de or en)
  • the referring site, but only its address without additions: google.com/search?q=… becomes google.com. A search term never reaches us.
  • browser family (e.g. "Chrome"), operating-system family (e.g. "Android") and device class (phone, tablet, desktop)
  • the country, where the local GeoLite2 database provides it. Deliberately only the country, no city, no region.
  • a pseudonym valid for one day (see below)

We do not store your IP address. It goes into the calculation of the pseudonym and is discarded afterwards.

How the pseudonym works. From your IP address, your browser identifier and a secret random value that changes every day we compute a checksum. It lets us tell that two views on the same day likely came from the same person. Once that day's random value is deleted (after two days at the latest), the checksum cannot be traced back to a person, and the next day the same person yields a different one. Recognising and following someone across days is therefore technically impossible.

We also count certain events without a personal reference, such as "a garden was created for the first time" or "a subscription was taken out". The contents of your garden, your journal entries or your photos are not transmitted.

Search terms without results. When you submit a search on our search page and it returns nothing at all, we keep the search term. It tells us which magazine article or which plant in the encyclopedia is missing. We store only the term itself in lower case, together with a counter and the time of the last search. No IP address, no pseudonym value, no link to your account. Two searches therefore cannot be recognised as belonging together. Input that looks like personal data (email addresses, phone numbers, long digit sequences, whole sentences) is not stored at all. Neither are searches that did return results, nor the suggestions shown while you type. After 90 days without another search we delete the term.

Legal basis is our legitimate interest in data-minimising audience measurement (Art. 6 (1)(f) GDPR). Since we neither store nor read anything on your device, § 25 (1) TDDDG does not apply and no consent is required.

Retention: individual measurements are deleted after 90 days. What remains are aggregate numbers (e.g. "1,200 views of the pricing page in May") that no longer relate to a person.

Country lookup uses the GeoLite2 database by MaxMind (CC BY-SA 4.0). It sits locally on our server; no query is sent to MaxMind.

6. Processors and external services

ProviderPurposeLocationLegal basis
netcup GmbHHostingDE NurembergDPA under Art. 28 GDPR
Hetzner Online GmbHBackup storage (encrypted)DEDPA under Art. 28 GDPR
Proton AGEmail receipt and deliveryCH (adequacy decision)DPA
Stripe Payments Europe, Ltd.Payment processing (subscriptions, invoices)IE (EU)DPA under Art. 28 GDPR
PayPal (Europe) S.à r.l. et Cie, S.C.A.Payment processing, if you choose PayPalLU (EU)Art. 6 (1)(b)
Mistral AI SASPlant recognition, AI chat, season summaries, receipt and meter OCR, disease diagnosisFR (EU)DPA under Art. 28 GDPR
OpenRouter, Inc.Public plant knowledge enrichment and DE/EN translationsUS (SCCs)Art. 28 + Art. 46 GDPR

Mistral La Plateforme (servers in the EU, France) processes on our behalf:

  • Plant photos for recognition (plant identify) and disease diagnosis
  • AI chat requests with journal context, only if you use the AI chat
  • Season summaries about your garden, only if you generate them
  • Receipts you upload to the expense book
  • Meter reading photos you upload to meter tracking

Mistral processes this content solely for inference and deletes it from audit logs within 30 days, as contractually assured. No training use takes place. We store neither the original image nor raw Mistral responses long term; only the structured result (recognised plant, extracted receipt item, answer text) enters your garden.

For public data without personal reference (general plant knowledge enrichment in our plant knowledge base, DE/EN translations of plant content and blog articles) we additionally use OpenRouter, Inc. (USA, under EU standard contractual clauses per Art. 46 GDPR). Your journal entries, AI chat requests, and photos are never processed there; the router refuses those routes technically.

A detailed sub-processor list with models and architecture guarantees is available on request at dpo@gartenkern.de.

When you take out a paid subscription, the payment provider you choose (Stripe Payments Europe, Ltd., Ireland, or PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg) processes your payment data, for example payment method and billing address. PayPal acts as an independent controller in this respect. We ourselves store no complete payment data, only the provider's reference IDs and the subscription status.

External services your browser contacts directly

For some features, your browser contacts external services directly; for technical reasons your IP address is transmitted. These services are not processors but independent recipients. The legal basis is our legitimate interest in providing the respective feature (Art. 6 (1)(f) GDPR):

ServicePurposeLocation
OpenFreeMapMap tiles (standard map view)EU (public instance)
MapTiler AGMap tiles (satellite and hybrid)CH (adequacy decision)
Open-MeteoWeather data for your garden (no API key, no tracking)DE/EU

Push notifications: If you enable browser notifications, they are delivered via your browser's push service, for example Mozilla, Google, or Apple depending on the browser. We store only a technical push subscription, which you can revoke at any time in your settings.

Error telemetry: We record technical errors through a self-hosted GlitchTip on our server in Germany. No data is passed to third parties. IP addresses are not stored by default.

7. Retention

The access log files of our web servers, which contain your IP address, are rotated daily. We keep 14 generations and delete older ones automatically. Your IP address is therefore stored for no longer than 15 days after the request, and is irreversibly deleted afterwards. These log files are never combined with your account.

Cancellation declarations submitted through the cancellation page are retained as evidence, even when they cannot be matched to a contract. § 312k (3) and (4) of the German Civil Code require us to document and confirm the receipt of a cancellation. Without that record, neither you nor we could show, in a dispute, when a cancellation was received.

We store account and garden data for as long as your account exists. After a deletion request, the period in Section 10 applies. Invoices and accounting records are retained for ten years under § 147 AO and § 257 HGB; they are blocked from further use.

Individual audience-measurement records (Section 5) are deleted after 90 days, the daily random value after two days. Aggregate numbers without a personal reference are kept.

8. No automated decision-making

There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR. The platform's AI features (plant recognition, chat, summaries) produce suggestions, not legally binding decisions about you.

9. Your rights (GDPR Art. 15 to 22)

You have the right at any time to:

  • Access (Art. 15) what we store about you, on request at dpo@gartenkern.de
  • Rectification (Art. 16), directly in your account profile
  • Erasure (Art. 17, "right to be forgotten"), on request at dpo@gartenkern.de
  • Restriction of processing (Art. 18), on request by email
  • Data portability (Art. 20), on request in a structured, commonly used format
  • Object (Art. 21) to processing based on Art. 6 (1)(f) GDPR
  • Lodge a complaint with a supervisory authority (Art. 77)

Send these requests and any other data protection questions to dpo@gartenkern.de. We respond without undue delay and at the latest within one month. Where a request is particularly complex, that period may be extended by up to two further months; we will tell you within the first month if that happens (GDPR Art. 12 (3)).

The supervisory authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59 to 61, 10555 Berlin, Germany
https://www.datenschutz-berlin.de/

You may also contact the supervisory authority of your habitual residence.

10. Backups and deletion periods

Backups are stored encrypted for 30 days. A deletion request takes immediate effect in the live database; deletion is finalised in backups through rollover within 30 days. Backups are used solely for disaster recovery.

11. Minimum age

The platform is open to persons aged 16 and over (Art. 8 GDPR). Anyone younger may use the service only with the consent of a legal guardian.

12. Security (GDPR Art. 32)

We take technical and organisational measures that reflect the state of the art: encrypted transport for all connections, passwords stored only as a secure hash and never in plain text, EXIF stripping on image uploads, strict separation between the data of different garden accounts, and a permission check on every access.

We do not list the individual mechanisms here. They evolve with the state of the art, and publishing them would make an attacker's work easier. We provide information on reasoned request.

13. Data breach notification

In the event of a personal data breach we notify the competent supervisory authority within 72 hours of becoming aware of it (GDPR Art. 33). Where the breach is likely to result in a high risk to your rights and freedoms, we also notify you without undue delay (GDPR Art. 34).