Sign in

Privacy Policy

Last updated July 27, 2026

This Privacy Policy explains what personal data MyGrowLog ("we," "us," "our") collects, why we collect it, who we share it with, how long we keep it, and what rights you have.

MyGrowLog is a record-keeping tool for indoor cannabis cultivation. Records of cannabis cultivation can carry legal, employment, immigration, or personal consequences depending on where you live. We have designed the Service to keep your data private by default and to minimize what we collect, but you should read Section 5 (Sharing and public content) and Section 8 (Retention and deletion) carefully before you publish anything.

Contact for all privacy matters: legal@mygrowlog.com.

Where your data is held. Our servers are located in the European Union. If you are outside the EU, your data is transferred to and stored in the EU.


1. Summary


2. What we collect

2.1 Information you give us

Account information

Your timezone is a coarse indication of your general region. We use it to interpret timestamps correctly. We do not collect precise location data.

Grow content

Photographs

Imported sensor data

Community content

2.2 Information generated automatically

2.3 What we do not collect

3. Why we use your data

For users in the EU, EEA, and UK, the GDPR requires us to identify a legal basis for each purpose.

PurposeData usedLegal basis
Providing your account and storing your grow recordsAccount info, all grow content, photos, importsContract (Art. 6(1)(b))
Verifying your email and letting you reset your passwordEmail, tokensContract
Publishing content you choose to shareScreen name, the content you designate as sharedContract, and your consent through the visibility setting you select
Running an AI inspection you requestPhoto, grow context, notes (see Section 4.1)Consent (Art. 6(1)(a)) - performed only on your explicit request
Sending comment notification emailsEmail, notification preferencesConsent - opt-in, with one-click unsubscribe
Preventing abuse, brute-force attacks, and spamIP address, email, rate-limit countersLegitimate interests (Art. 6(1)(f)) - securing the Service
Moderating reported content and enforcing our TermsReports, the reported content, administrator logsLegitimate interests - maintaining a lawful, safe service
Keeping audit and administrator-access logsChange records, admin actionsLegitimate interests - accountability and security
Recording your acceptance of our policiesConsent logLegal obligation (Art. 6(1)(c)) and legitimate interests
Diagnosing errorsError reportsLegitimate interests - service reliability

Where we rely on legitimate interests, we have considered your rights and interests and concluded they do not override ours for these narrow purposes. You may object at any time, see Section 9.

Special category data. We do not intentionally collect data revealing health, political opinions, religion, sexual orientation, or other special categories under GDPR Art. 9. However, free-text fields you control could contain such information if you choose to write it there, and in some contexts information about cannabis cultivation may itself be sensitive. Please consider what you record. Where you voluntarily enter such information, our basis is that you have manifestly made it public (Art. 9(2)(e)) for content you publish, or your explicit consent for content you keep private.

4. Who we share data with

We do not sell your data. We use the following processors:

4.1 Anthropic: AI Plant Inspector

Only when you explicitly request an inspection, we transmit to Anthropic (our AI provider):

This includes free-text notes that are never shown on public share pages. If you do not want this information transmitted to a third party, do not use the AI Plant Inspector. The feature is entirely optional and off unless you invoke it.

Anthropic processes this data to generate the response and, under its commercial terms, does not use API inputs or outputs to train its models. Anthropic retains API data for a limited period for abuse monitoring. Anthropic's privacy practices are described at anthropic.com/privacy.

We store only the structured result and the cost/token count. We do not use your content to train any model, and we have no plans to.

4.2 Other disclosures

We may disclose data if we believe in good faith it is necessary to: comply with a legal obligation or valid legal process; enforce our Terms; investigate suspected fraud, abuse, or security incidents; or protect the rights, property, or safety of any person.

Given the subject matter of this Service, we want to be direct with you: we are subject to legal process in the jurisdictions where we and our providers operate. We cannot promise that we will never be compelled to disclose data. The most reliable protection is not to record information you would not want disclosed. We will resist overbroad requests where we reasonably can, and where we are legally permitted to notify you of a request affecting your account, we will try to do so.

If the Service is transferred to a business entity, sold, or merged, your data may transfer as part of that transaction. We will publish notice before that happens.

4.3 Administrators

The Service administrator accounts can view your photographs and your shared content**, and can open a read-only session as your account for support and moderation purposes. Read-only sessions require a stated reason, and cannot make changes. Every administrator access to your data is recorded for internal auditing.

5. Sharing and public content

Your grow cycles are private by default. You choose the visibility of each cycle:

What appears on a public page: your screen name (or "anonymous"), grow data, photographs, climate charts, journal entries, equipment and consumables, and — only if you opt in — your cost breakdown.

What never appears on a public page: your email address, and the free-text notes on your daily logs and plant events.

Comments on shared cycles display the commenter's screen name.

Public content cannot be fully retracted. Once a page has been public, it may have been copied, archived, cached, or screenshotted by others. Making it private again removes it from our Service but does not recall copies elsewhere.

6. Security

No system is perfectly secure. We cannot guarantee absolute security, and you should keep your own copies of records that matter to you.

7. International transfers

Our servers and our photo storage are both in the European Union. If you are in the EU/EEA/UK, your grow records and photographs stay in the EU.

Two processors are outside the EU, and receive only the limited data described in Section 4:

Transfers to these providers rely on Standard Contractual Clauses approved by the European Commission, or another valid transfer mechanism, together with the safeguards described in this Policy.

8. How long we keep data, and what happens when you delete

8.1 Automatic deletion

DataDeleted after
Uploaded raw CSV files180 days (parsed readings are kept with your cycle)
Rate-limit records containing IP addresses~24 hours
Used or expired password reset / verification tokens7 days
In-app notificationsOldest deleted beyond 200 per user
Background job recordsDays

Everything else is kept as long as your account exists.

8.2 When you delete your account

Account deletion is scheduled and can be cancelled during a grace period shown in the app. When it executes, we permanently delete: your account record, email address, password hash, screen name history, preferences, all grow cycles and everything within them, all photographs (including the underlying image files), sensor imports, inventories, tags, tasks, AI inspection results, notifications, consent records, and authentication tokens.

You can also reset your account, this deletes all grow content immediately but keeps your login, or wipe all photographs without deleting anything else.

8.3 What survives account deletion

We want to be explicit about this rather than bury it:

9. Additional Information

For anything the app does not cover, email legal@mygrowlog.com. We will respond within 30 days. We may need to verify that you control the account before acting.

On data export specifically: the app currently offers export of individual grow cycles as CSV files (this does not include image files).

We will not charge you, refuse service, or treat you differently for exercising any of your rights.

10. Children

The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal data from children. We do not currently verify age; our Terms of Service require you to confirm you are at least 18 and of legal age in your jurisdiction.

If you believe a person under 18 has created an account, contact legal@mygrowlog.com and we will investigate and delete the account and its data.

11. Changes to this Policy

We may update this Policy. When we do, we will change the "Last updated" date and publish the new version. For material changes, we will notify you and may require you to review and accept the updated Policy before continuing to use the Service. Previous versions are retained and your acceptance of each is logged.

12. Contact and complaints

Privacy questions, requests, and rights: legal@mygrowlog.com Abuse reports and content complaints: abuse@mygrowlog.com

If you are in the EU, EEA, or UK and believe we have not handled your data lawfully, we would like the chance to fix it first — but you have the right to complain directly to your national data protection authority. In the UK, that is the Information Commissioner's Office (ico.org.uk). In the EU, a list of authorities is published at edpb.europa.eu.