Privacy Policy

Last updated: May 2026

1. What we collect

When you create an account we collect your name and email address. When you use the app we store the plant photos you upload, the garden and zone structure you define, AI-generated health scores, care notes, and action logs. We log the timestamp of your last login.

If you sign in with Google, we receive your name and email from Google. We do not receive or store your Google password.

2. How we use your data

  • To run AI analysis on your plant photos and return health scores.
  • To store and display your garden data across sessions and devices.
  • To send transactional emails (account creation confirmation, occasional product tips). You can opt out by replying to any email.
  • To operate, debug, and improve the service. We may review aggregate, anonymised usage patterns — never individual photo content — to improve AI prompts.

3. Plant photos and AI processing

Photos you upload are sent to Anthropic's Claude API for vision analysis. Anthropic processes these images to return a health assessment; they do not train models on your images under their standard API terms. See Anthropic's Privacy Policy for details.

Photos are stored on Google Cloud Storage in a private bucket. They are not publicly accessible and are not shared with third parties beyond the AI processing described above.

4. Data sharing

We do not sell your data. We share data only with:

  • Anthropic — for AI vision analysis of uploaded photos.
  • Google Cloud — for hosting, database, and file storage.
  • Google (OAuth) — if you choose to sign in with Google.

We may disclose data if required by law or to protect the rights and safety of our users.

5. Data retention

Your data is retained for as long as your account is active. If you request account deletion, we will delete your personal data and garden content within 30 days, except where retention is required by law.

6. Security

Passwords are hashed with bcrypt and never stored in plain text. All data in transit is encrypted via TLS. We use Google Cloud's managed security controls for at-rest encryption. We do not store payment card details — payments (if applicable) are handled by Stripe.

7. Cookies and sessions

We use a single session cookie to keep you signed in. We do not use advertising cookies or third-party tracking pixels.

8. Your rights

You can request a copy of your data or ask us to delete your account at any time by emailing privacy@trellisiq.online. We will respond within 30 days.

9. Changes to this policy

We may update this policy as the service evolves. We will notify registered users by email of material changes. Continued use of TrellisIQ after a change constitutes acceptance of the updated policy.

10. Contact

Questions about this policy? Email privacy@trellisiq.online.