Privacy
Plain English. We collect what we need to run the service, nothing more, and we never sell it.
What we collect
If you sign up for an account: your email address, the password you choose (stored hashed, not in plain text), your postcode (used to determine your climate zone), the crops you add to your garden journal, and the photos you upload for pest identification.
If you pay us: Stripe handles the payment data and we never see your card number. We see the transaction status (paid/failed/refunded) and the amount.
If you visit any page: standard server logs (IP address, browser, page requested, timestamp). We use Koko Analytics, which is privacy-friendly and does not set tracking cookies.
What we do with it
We use your zone and active crops to personalise advice. We use your email to send the digests and alerts you signed up for, and to recover your account if you forget your password. We use server logs to fix bugs and detect abuse.
That is it. We never sell your data. We never share it with third-party advertisers. Logged-in members never see ads. We do not have a marketing relationship with any plant nursery, seed supplier, or garden product brand — though we may add affiliate links in the future, in which case we will tell you clearly which links are affiliates.
How long we keep it
While your account is active, we keep your garden journal, photos, and history. If you delete your account, we delete all your personal data within 30 days. Server logs are kept for 90 days then automatically rotated out.
Where it lives
Our database is hosted in Australia. The site runs on Australian infrastructure. The AI processing happens on hardware we own, located in Australia — your photos do not get sent to OpenAI, Google, or any other third-party AI vendor.
Stripe (which handles payments) is a US company and complies with Australian Privacy Principles. Their privacy policy is at stripe.com/au/privacy.
Your rights
Under the Australian Privacy Act, you can:
- Ask us what data we hold about you (we will export it as JSON within 30 days)
- Ask us to correct anything that is wrong
- Ask us to delete everything (full account deletion, 30-day SLA)
- Complain to the Office of the Australian Information Commissioner if you think we have done the wrong thing
For any of the above, email support@gardenbuddy.au.
Cookies
We use the minimum number of cookies needed to make the site work. PHPSESSID and a logged-in cookie are required. We do not use Google Analytics, Facebook Pixel, or any third-party tracking.
Last updated: 12 April 2026.