Privacy Policy
Last updated July 27, 2026
This Privacy Policy explains what personal data MyGrowLog ("we," "us," "our") collects, why we collect it, who we share it with, how long we keep it, and what rights you have.
MyGrowLog is a record-keeping tool for indoor cannabis cultivation. Records of cannabis cultivation can carry legal, employment, immigration, or personal consequences depending on where you live. We have designed the Service to keep your data private by default and to minimize what we collect, but you should read Section 5 (Sharing and public content) and Section 8 (Retention and deletion) carefully before you publish anything.
Contact for all privacy matters: legal@mygrowlog.com.
Where your data is held. Our servers are located in the European Union. If you are outside the EU, your data is transferred to and stored in the EU.
1. Summary
- The Service is currently free.
- Grow data is private by default. Nothing is public unless you choose to publish it.
- We never ask for your name, address, phone number, or date of birth.
- Photo location metadata (GPS/EXIF) is stripped and never stored.
- Your grow records and photographs are stored in the European Union.
2. What we collect
2.1 Information you give us
Account information
- Email address: Required for login, verification, password reset, and notifications.
- Password: We never store or see your password in plain text.
- Screen name: Your public identity on shared content. We retain a history of all previous screen names you have used, visible to administrators.
- Preferences: Settings such as timezone, temperature units, units of measure, default costs, notification settings.
Your timezone is a coarse indication of your general region. We use it to interpret timestamps correctly. We do not collect precise location data.
Grow content
- Grow cycle data such as plants, phase timelines, daily logs (water volume, EC, pH, PPFD, DLI, runoff), plant events, weekly journal entries, tags, tasks, and daily-entry templates.
- Notes & comments throughout the platform, these may contain anything you type.
- Inventory data such as nutrients, consumables, equipment, seed bank entries, electricity and cost records.
- Harvest data including weights and cost calculations.
Photographs
- Images you upload of your plants and grow.
- We read one piece of embedded metadata, the capture date/time. This is necessary to identify when your photo was taken so it can be better organized by date. We then strip all metadata from the stored image, including GPS coordinates, camera make and model, serial numbers, and every other EXIF field. That stripping overwrites the stored file, permanently destroying the metadata.
Imported sensor data
- Climate-controller CSV exports you upload: the raw file with all data you submit, its filename, and a checksum, plus the parsed temperature, humidity, and VPD readings.
Community content
- Comments you post, strain catalog submissions, abuse reports (including the free-text explanation and your identity as reporter), and feature requests.
2.2 Information generated automatically
- AI inspection results including data such as the summary, identified issues, and suggestions produced when you run an inspection, plus token counts and cost.
- Usage counters which may include your daily AI inspection count, for quota enforcement.
- Consent records that log which version of which policy you accepted and when.
- Audit logs which are records of changes to certain data, and a log of administrator actions affecting your account. See Section 8.3.
- Security data, see below.
2.3 What we do not collect
- No name, postal address, phone number, or date of birth.
- No payment or financial data of any kind.
- No precise or GPS location.
- No biometric data, and no data from social login providers (we do not offer social login).
- We do not sell your personal data, and we never have.
3. Why we use your data
For users in the EU, EEA, and UK, the GDPR requires us to identify a legal basis for each purpose.
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing your account and storing your grow records | Account info, all grow content, photos, imports | Contract (Art. 6(1)(b)) |
| Verifying your email and letting you reset your password | Email, tokens | Contract |
| Publishing content you choose to share | Screen name, the content you designate as shared | Contract, and your consent through the visibility setting you select |
| Running an AI inspection you request | Photo, grow context, notes (see Section 4.1) | Consent (Art. 6(1)(a)) - performed only on your explicit request |
| Sending comment notification emails | Email, notification preferences | Consent - opt-in, with one-click unsubscribe |
| Preventing abuse, brute-force attacks, and spam | IP address, email, rate-limit counters | Legitimate interests (Art. 6(1)(f)) - securing the Service |
| Moderating reported content and enforcing our Terms | Reports, the reported content, administrator logs | Legitimate interests - maintaining a lawful, safe service |
| Keeping audit and administrator-access logs | Change records, admin actions | Legitimate interests - accountability and security |
| Recording your acceptance of our policies | Consent log | Legal obligation (Art. 6(1)(c)) and legitimate interests |
| Diagnosing errors | Error reports | Legitimate interests - service reliability |
Where we rely on legitimate interests, we have considered your rights and interests and concluded they do not override ours for these narrow purposes. You may object at any time, see Section 9.
Special category data. We do not intentionally collect data revealing health, political opinions, religion, sexual orientation, or other special categories under GDPR Art. 9. However, free-text fields you control could contain such information if you choose to write it there, and in some contexts information about cannabis cultivation may itself be sensitive. Please consider what you record. Where you voluntarily enter such information, our basis is that you have manifestly made it public (Art. 9(2)(e)) for content you publish, or your explicit consent for content you keep private.
4. Who we share data with
We do not sell your data. We use the following processors:
4.1 Anthropic: AI Plant Inspector
Only when you explicitly request an inspection, we transmit to Anthropic (our AI provider):
- The plant photograph (downscaled).
- Cycle name, start date, and grow medium.
- Strain details, equipment list, plant status, phase timeline, and grow day.
- The last 14 days of your daily logs, including your free-text notes.
- Nutrient additives and quantities, consumables in use.
- The last 10 plant events, including your free-text notes.
- Summaries of your last 5 inspections.
This includes free-text notes that are never shown on public share pages. If you do not want this information transmitted to a third party, do not use the AI Plant Inspector. The feature is entirely optional and off unless you invoke it.
Anthropic processes this data to generate the response and, under its commercial terms, does not use API inputs or outputs to train its models. Anthropic retains API data for a limited period for abuse monitoring. Anthropic's privacy practices are described at anthropic.com/privacy.
We store only the structured result and the cost/token count. We do not use your content to train any model, and we have no plans to.
4.2 Other disclosures
We may disclose data if we believe in good faith it is necessary to: comply with a legal obligation or valid legal process; enforce our Terms; investigate suspected fraud, abuse, or security incidents; or protect the rights, property, or safety of any person.
Given the subject matter of this Service, we want to be direct with you: we are subject to legal process in the jurisdictions where we and our providers operate. We cannot promise that we will never be compelled to disclose data. The most reliable protection is not to record information you would not want disclosed. We will resist overbroad requests where we reasonably can, and where we are legally permitted to notify you of a request affecting your account, we will try to do so.
If the Service is transferred to a business entity, sold, or merged, your data may transfer as part of that transaction. We will publish notice before that happens.
4.3 Administrators
The Service administrator accounts can view your photographs and your shared content**, and can open a read-only session as your account for support and moderation purposes. Read-only sessions require a stated reason, and cannot make changes. Every administrator access to your data is recorded for internal auditing.
5. Sharing and public content
Your grow cycles are private by default. You choose the visibility of each cycle:
- Private: only you can see it.
- Unlisted: anyone with the share link can view it. We ask search engines not to index these pages, but a share link is not a password: anyone you send it to can forward it, and we cannot guarantee every crawler or archiving service honors our request.
- Listed: publicly visible and indexable by search engines. Listed cycles appear in our public discovery pages and sitemap, and social-media preview images are generated for them.
What appears on a public page: your screen name (or "anonymous"), grow data, photographs, climate charts, journal entries, equipment and consumables, and — only if you opt in — your cost breakdown.
What never appears on a public page: your email address, and the free-text notes on your daily logs and plant events.
Comments on shared cycles display the commenter's screen name.
Public content cannot be fully retracted. Once a page has been public, it may have been copied, archived, cached, or screenshotted by others. Making it private again removes it from our Service but does not recall copies elsewhere.
6. Security
- Passwords hashed and never stored in plaintext.
- Sessions in an encrypted cookie; all sessions can be revoked, and changing your password revokes every other session.
- TLS encryption in transit, with HSTS, Content Security Policy, and other hardening headers.
No system is perfectly secure. We cannot guarantee absolute security, and you should keep your own copies of records that matter to you.
7. International transfers
Our servers and our photo storage are both in the European Union. If you are in the EU/EEA/UK, your grow records and photographs stay in the EU.
Two processors are outside the EU, and receive only the limited data described in Section 4:
- Anthropic (United States): receives inspection data only when you request an inspection.
- Resend (United States): receives your email address and the contents of messages we send you.
- Sentry (United States): error data.
Transfers to these providers rely on Standard Contractual Clauses approved by the European Commission, or another valid transfer mechanism, together with the safeguards described in this Policy.
8. How long we keep data, and what happens when you delete
8.1 Automatic deletion
| Data | Deleted after |
|---|---|
| Uploaded raw CSV files | 180 days (parsed readings are kept with your cycle) |
| Rate-limit records containing IP addresses | ~24 hours |
| Used or expired password reset / verification tokens | 7 days |
| In-app notifications | Oldest deleted beyond 200 per user |
| Background job records | Days |
Everything else is kept as long as your account exists.
8.2 When you delete your account
Account deletion is scheduled and can be cancelled during a grace period shown in the app. When it executes, we permanently delete: your account record, email address, password hash, screen name history, preferences, all grow cycles and everything within them, all photographs (including the underlying image files), sensor imports, inventories, tags, tasks, AI inspection results, notifications, consent records, and authentication tokens.
You can also reset your account, this deletes all grow content immediately but keeps your login, or wipe all photographs without deleting anything else.
8.3 What survives account deletion
We want to be explicit about this rather than bury it:
- Comments you posted on other people's grows. The text of your comments is blanked and your authorship is anonymized, but the reply structure remains so surrounding conversations stay readable.
- Strain catalog entries you submitted and we approved. These are shared community reference data and are retained permanently, with your authorship reference removed.
- Audit logs and administrator-access logs. References to you are removed, but these records persist for security and accountability. Note: audit entries record the old and new values of changed fields, and administrator log entries include a free-text reason and technical metadata. These fields are not scrubbed, so fragments of content may remain in them.
- Backups. Data may persist in routine backups until those expire.
9. Additional Information
For anything the app does not cover, email legal@mygrowlog.com. We will respond within 30 days. We may need to verify that you control the account before acting.
On data export specifically: the app currently offers export of individual grow cycles as CSV files (this does not include image files).
We will not charge you, refuse service, or treat you differently for exercising any of your rights.
10. Children
The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal data from children. We do not currently verify age; our Terms of Service require you to confirm you are at least 18 and of legal age in your jurisdiction.
If you believe a person under 18 has created an account, contact legal@mygrowlog.com and we will investigate and delete the account and its data.
11. Changes to this Policy
We may update this Policy. When we do, we will change the "Last updated" date and publish the new version. For material changes, we will notify you and may require you to review and accept the updated Policy before continuing to use the Service. Previous versions are retained and your acceptance of each is logged.
12. Contact and complaints
Privacy questions, requests, and rights: legal@mygrowlog.com Abuse reports and content complaints: abuse@mygrowlog.com
If you are in the EU, EEA, or UK and believe we have not handled your data lawfully, we would like the chance to fix it first — but you have the right to complain directly to your national data protection authority. In the UK, that is the Information Commissioner's Office (ico.org.uk). In the EU, a list of authorities is published at edpb.europa.eu.