Privacy Policy
Loamhand is a garden planner. To plan a garden we need to know a little about you and a lot about your plants. This page says what we collect, which outside services receive any of it, how long we keep it, and what you can do about it. It is written from what the code actually does, service by service.
What we collect
Everything below is stored because a feature needs it.
- Email address — to sign you in, verify the account, reset your password, and deliver garden invites and membership changes.
- Password hash — a salted Argon2id hash of your password, never the password itself.
- Display name and region label, if you set them — shown to the people you share gardens with instead of your email address.
- Your gardens — names, plots (bed type, dimensions, soil type), plantings, care logs, harvests, measurements, soil tests, notes, reminders you write, and your own plants if you add any.
- A garden's location — the coordinates of the place you search for, pin, or share, and the place name you choose. Location is how weather, hardiness zones and frost dates work. It can be as precise as your garden or as rough as a town; you choose.
- Your device's location, only when you ask. During setup, "Use my location" asks your browser for your current position once. If you allow it, those coordinates become the garden's location. We do not track your location, and nothing asks for it again unless you press the button.
- Photos you upload, with their captions, size and the date you give — see "Photos" below.
- Membership records — which accounts belong to which gardens, with what role, who tends which bed, and the invites between them. An invite stores the address it was sent to.
- Your IP address — used for rate limiting on sign-in, sign-up and a few public forms, and written to server logs. It is not joined to your gardening data.
- Notification subscriptions, only if you turn notifications on — for each device, the push subscription its browser gives us (an address at the browser's push service and the keys that encrypt messages to it) and a label such as "Chrome on Android"; which alerts you want and your quiet hours, with the time zone they use; and a record of each notification we send, kept for 30 days.
- Acceptance of the Terms — the date you agreed to them and confirmed you are 13 or older.
We do not collect your contacts, device identifiers, or anything from other apps, and we use no advertising trackers or third-party cookies. A US ZIP code you type to look up a hardiness zone is used for that lookup and not stored.
Who else receives it
Some features need an outside service. Each receives only what that feature needs, and no account information goes with any request. Location lookups, forecasts and email are requested by our server, so those services see our server's address, not yours; the analytics script, if enabled, runs in your browser.
- OpenStreetMap Nominatim (nominatim.openstreetmap.org) receives the place text you type when you search for a location (for example "Somerville, MA"). It also receives a garden's coordinates when we look up the postcode for its hardiness zone. Results are © OpenStreetMap contributors.
- phzmapi.org receives a five-digit US ZIP code to look up the USDA hardiness zone for it.
- USGS Elevation Point Query Service (epqs.nationalmap.gov, a US government service) receives a garden's coordinates, when a US climate station is within reach, to find its elevation; that helps choose the station its frost dates come from.
- NOAA National Weather Service (api.weather.gov, a US government service) receives the coordinates of gardens inside its coverage area (the US, its territories and places close to them) to fetch a forecast.
- MET Norway (api.met.no, the Norwegian Meteorological Institute) receives the coordinates of gardens outside NOAA's coverage, rounded to four decimal places (about 11 metres), to fetch a forecast.
- Resend (api.resend.com) delivers our email: verification, password reset, garden invites and membership changes. It sees the recipient address and the message.
- Web push services, only if you turn notifications on. Notifications travel through the push service of the company that makes your browser: Google (fcm.googleapis.com) for Chrome and most other browsers built on it, Apple (web.push.apple.com) for Safari and for Loamhand on an iPhone or iPad, Mozilla (updates.push.services.mozilla.com) for Firefox, and Microsoft (notify.windows.com) for Edge on Windows. Each message is encrypted end to end, so the service cannot read it: it sees only that a message went to a device, when, and how large it was. Your device decrypts it, and what it shows — your garden's name, for example — can appear on the lock screen. We store each device's push subscription and a label, and keep delivery records for 30 days. A device's subscription is removed when you turn notifications off, sign out on that device, or delete your account.
- Fly.io will host the application in the US. We have not yet chosen the provider for the database; this page will name it before anybody's data is stored there.
- Cloudflare R2 will store the image files of photos you upload, in a private bucket. Nobody can reach a file directly: every photo is fetched through our server, which checks you are a member of its garden.
- Plausible Analytics (plausible.io), only if a deployment turns it on. It is cookieless and counts page views and a few product events such as "created a garden". It receives the address of the page you visited and your browser's normal request details, never your email, your garden's contents, or a cross-site identifier.
- Sentry (error reports), only if a deployment turns it on. When the server fails unexpectedly, or the app crashes in your browser, a report goes to Sentry with the error message and stack trace, the kind of page or request it happened on (a route such as "invites/[token]", never the address with its codes), the status, and, from the browser, your browser's user agent. Reports never include request bodies, cookies, your email, your photos or your garden's contents.
No one else. There are no data brokers, no ad networks, and no "partners".
Photos
Before a photo leaves your device, the app shrinks it and saves it again as a new image. That strips its EXIF data, including any GPS position your camera recorded. The files are stored privately and shown only to members of the garden they belong to. When you delete a photo, or a garden is retired, the files stay in storage for 30 days in case it was a mistake; after that they are deleted. A short record that the photo existed — its date, size and caption — stays with the garden's history.
The waitlist
If you join the waitlist on the home page we store your email address, where you signed up (the home page) and when. We use it only to tell you when estimated zones and local guidance reach where you garden, and we have not sent any waitlist email yet. To be removed, email support@loamhand.com and we will delete it.
We never sell your data
This is one of the product's founding rules, not a marketing line. We will not sell, rent, or trade your personal information or your garden records to anyone, ever. If the company is ever acquired, this policy travels with your data and you will be told before anything changes.
How we use it
- To run the product: schedules, weather, reminders, shared gardens.
- To keep it working and secure: logs, rate limiting, abuse prevention.
- To email you about your account or gardens. We do not send marketing email without asking first.
- In aggregate, to understand which features get used. Aggregate means counts, never individuals.
How long we keep it
Your garden data is kept for as long as your account exists, because history across seasons is the point of the product. Loamhand records changes as an append-only history, so a correction adds a new entry rather than erasing the old one; that history is yours and is included in your export. New history entries record that a garden's location was set, not its coordinates, and an invite entry does not record the address it was sent to.
Account deletion. When you delete your account we immediately sign you out and stop all email. You leave every garden: the beds you tended and any helper access you had are released. Gardens where you were the only member are retired, not removed: they stop generating tasks and weather requests, and their records are kept. Your account stays recoverable for 30 days in case you change your mind or the request was not you: sign in again and you can restore it, with the gardens it retired and your places in other gardens. Beds you tended in shared gardens and helper access are not given back, and invites you had sent stay cancelled. We email you when an account is restored.
After 30 days the account is anonymised:
- your email address and password hash are replaced, and your display name and region label are deleted;
- your email address is removed from the history wherever it appears, and from invites you accepted;
- the coordinates and place name of any garden only you ever belonged to are removed, from the garden and its history;
- photo files in your retired gardens are deleted from storage (see "Photos").
What stays is the history itself: what was planted, cared for and harvested, notes and photo captions, and when. In gardens you shared, your entries stay with the garden so the other members' history is not destroyed by your departure, and they are shown as "Deleted account". Each entry still points at your old account's identifier, which no longer leads to anything about you.
Server logs, including IP addresses, are kept for no more than 30 days.
Your rights
- Export — download everything tied to your account as a JSON file from Settings, at any time, on any tier. It contains your account details; each garden you belong to with its plots, soil tests, plantings, care logs, harvests, measurements, photo details (not the image files themselves), tasks and history; every change you made; invites you sent; your membership history; your own plants; the reminders and repeat sowings you set up; the beds you tend and helper access you hold; and the weather alerts you acknowledged. Other members appear by display name and role only, never by email address.
- Delete — delete your account from Settings. No emails to support, no retention offers.
- Correct — change your data in the app. Because history is append-only you will see both the old and the new value; that is by design.
- Ask — email support@loamhand.com with any question about your data. A person will answer.
Children
Loamhand is for people aged 13 and over. We do not knowingly collect information from anyone younger. If you believe a child under 13 has an account, email us and we will remove it.
Where this applies
Loamhand can be used from anywhere. The application is hosted in the US. This draft was written for US law and has not yet been reviewed for the protections of other regions (such as the GDPR in Europe or the Privacy Act in New Zealand); until it has, what it says above is what we do, and we will spell out regional rights here before we say we meet them.
Security
Passwords are hashed with Argon2id. Traffic is encrypted with TLS. Session tokens can be revoked everywhere at once from Settings. If we discover a breach affecting your data we will tell you promptly and plainly.
Changes to this policy
When this policy changes in a way that matters, we will email account holders and show the date at the top of this page. Continuing to use Loamhand after the change means you accept the updated policy; if you do not, you can export and delete your account.
Earlier versions of this policy are kept, each with the date it took effect. Ask and we will send you the one that applied to you.
Questions: support@loamhand.com. See also the Terms of Service.