Privacy Policy

Datenschutzerklärung

GrassBuddy by Tanpau

Last updated: June 2025

1. Overview

GrassBuddy is built on a privacy-first principle: your data is stored locally on your device by default and never leaves it unless you explicitly choose to enable cloud sync. No account is required to use the core features of the app.

This policy explains what data GrassBuddy collects, how it is used, and what rights you have over it.

2. Data We Collect

2.1 Data stored locally on your device (default)

All of the following is stored exclusively on your device in an SQLite database and never transmitted anywhere unless you opt in to cloud sync:

  • Plant profiles (name, strain, start date, soil type, location, grow environment)
  • Growth stage history and transitions
  • Diary entries (observations, notes, timestamps)
  • Photos (stored in your device's local file system)
  • Nutrient and fertilizer logs (product, amount, date, pH, EC/PPM values)
  • Watering logs
  • Environment logs (temperature, humidity)
  • Pest and disease treatment records
  • Completed grow archives
  • App preferences and notification settings

2.2 Data synced to the cloud (opt-in only)

If you choose to enable cloud sync, the following data is encrypted and stored on Supabase infrastructure:

  • All locally stored plant and diary data listed above
  • Photo files (backed up to Supabase Storage)

Cloud sync requires your explicit consent. You will be shown a clear summary of what will be synced and where it is stored before you can enable it. You can disable cloud sync and delete all cloud data at any time from within the app.

2.3 Data sent to AI services

When you use AI-powered features (AI Chat, Photo Diagnosis, or AI Nutrient Plan), relevant portions of your grow data are sent to the Claude API by Anthropic. This is always clearly indicated in the app interface with a "Claude AI" badge. These features require an internet connection.

The Claude API key is never stored on your device. All cloud AI requests are proxied through Supabase Edge Functions. Please review Anthropic's Privacy Policy for details on how they handle data sent to their API.

You can use GrassBuddy without ever triggering cloud AI. The on-device coaching engine (coaching tips, value validation, VPD calculator, reminders) works entirely offline and does not send any data externally.

3. How We Use Your Data

  • Local data — used exclusively to power app features on your device. Never sold, never shared.
  • Cloud sync data — used solely for backup and cross-device access as described at consent time.
  • AI feature data — sent to the Claude API to generate a response to your request, then discarded. Not used to train models.

We do not use any analytics SDKs, advertising networks, or third-party tracking in GrassBuddy.

4. Cloud Sync Consent

Before cloud sync is activated, you will see an explicit consent screen that explains:

  • What data will be synced
  • Where it is stored (Supabase infrastructure)
  • That the Claude API is used for certain AI features when online
  • How to delete your data

You must actively check a checkbox and confirm before sync is enabled. Consent is timestamped and stored locally. You can withdraw consent at any time by disabling cloud sync in the Privacy Dashboard.

Note: Disabling cloud sync stops future uploads but does not automatically delete data already stored in the cloud. Use "Delete Cloud Data" in the Privacy Dashboard to request erasure of all previously synced data.

5. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:

👁

Right of Access

View all data stored in the cloud via the Privacy Dashboard in the app.

🗑

Right to Erasure

Delete all cloud data at any time using "Delete Cloud Data" or "Delete My Account" in the Privacy Dashboard.

📦

Right to Portability

Export a complete archive of all your data (including photos and diary entries) as a ZIP file at any time.

🚫

Right to Withdraw Consent

Disable cloud sync at any time. This stops future uploads immediately without affecting local data.

To exercise any of these rights, use the Privacy Dashboard inside the app (Settings → Privacy & Data). For account deletion or other requests that cannot be fulfilled in-app, contact us at privacy@tanpau.com.

6. Data Retention

  • Local data — retained on your device until you delete the app or delete individual records within the app.
  • Cloud data — retained until you request deletion via the Privacy Dashboard or by contacting us. When you delete your account, all cloud data is permanently and irreversibly erased.
  • AI request data — not retained by us. See Anthropic's data retention policy for Claude API usage.

7. Data Security

Local data is stored in a sandboxed SQLite database accessible only to GrassBuddy on your device. Cloud data is transmitted over HTTPS and stored on Supabase, which provides encryption at rest and in transit. The Claude API key is server-side only and never exposed to the client.

Photos stored locally are kept in the app's protected file system directory. Photos synced to the cloud are stored in Supabase Storage with access restricted to your account.

8. Third-Party Services

ServicePurposeActivated
Supabase Cloud data storage & sync, push notifications, AI proxy Only if cloud sync is enabled
Anthropic Claude API AI Chat, Photo Diagnosis, Nutrient Plan Only when using AI features online

GrassBuddy does not integrate any advertising networks, analytics platforms, or social media SDKs.

9. Children's Privacy

GrassBuddy is not intended for use by individuals under the age of 18. We do not knowingly collect data from minors. If you believe a minor has used the app and provided data, please contact us at privacy@tanpau.com.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If changes are material, we will notify you in the app before the changes take effect. The date at the top of this page reflects when the policy was last updated. Continued use of the app after a policy update constitutes acceptance of the revised policy.

11. Contact

For any privacy-related questions, requests, or concerns:

Tanpau · Bucher IT Solutions
Email: privacy@tanpau.com
Based in Heidelberg, Germany