Privacy Policy

Last updated: April 2, 2026

TL;DR — Your data is yours. We don't want it, we don't sell it, and we definitely don't build creepy profiles about you. We store the bare minimum to help you plan your garden — your email, where your garden is, and what you plant in it. That's it. No trackers, no analytics, no "partners" getting a peek. You can download everything we have on you anytime, and if you ever want to leave, just say the word and we'll toss all your data in the compost bin. 🪱

For the legally-binding version that would make a lawyer proud, keep reading below.

Willow ("we", "us", "our") is a garden planning application. This policy explains what personal data we collect, why we collect it, and what rights you have over it.

What data we collect

  • Account information — your name, email address, and hashed password.
  • Garden location — latitude and longitude coordinates you provide for your garden. This does not have to be your home address.
  • Garden data — beds, plantings, ground covers, decorations, journal entries, harvest records, and to-do items you create.
  • Chat messages — conversations with the Willow AI assistant.
  • Preferences — display settings such as unit system, time format, and lighting preferences.
  • Feedback — any feedback you voluntarily submit through the app.

Why we collect it

  • To provide the service — your email is needed for account access and notifications. Garden coordinates are used to determine your hardiness zone, frost dates, and local weather.
  • To improve the service — aggregated, non-identifying usage patterns help us improve features.

Legal basis

We process your data under contractual necessity (Article 6(1)(b) GDPR) — the data is required to deliver the service you signed up for. For service improvement, we rely on legitimate interest (Article 6(1)(f) GDPR).

How long we keep your data

Your data is retained for as long as your account is active. When you delete your account, all personal data is permanently removed from our systems immediately. Database backups that may contain your data are rotated and fully purged within 30 days of account deletion.

Your rights

Under the GDPR, you have the right to:

  • Access — download a copy of all your data via the "Download My Data" button in Settings.
  • Erasure — permanently delete your account and all data via the "Delete Account" button in Settings.
  • Portability — export your data in a machine-readable JSON format.
  • Rectification — update your profile information through the app.
  • Restriction & Objection — contact us to restrict or object to processing.

Cookies

We use only strictly necessary cookies to maintain your login session. We do not use analytics cookies, advertising cookies, or any third-party tracking. No consent is required for strictly necessary cookies under the ePrivacy Directive.

Third-party services

  • Open-Meteo — we send your garden coordinates to retrieve weather forecasts. No other personal data is shared.
  • AI assistant provider — chat messages are processed by a third-party AI model to generate responses. Messages are not used for model training.

Data security

All data is transmitted over HTTPS. Passwords are hashed using bcrypt and are never stored in plain text. Two-factor authentication is available for additional account security.

Contact

For any privacy-related questions or to exercise your rights, email us at privacy@meetwillow.app.

Changes to this policy

We will notify you of material changes to this policy via email. Continued use of the service after notification constitutes acceptance of the updated policy.