Privacy Policy
1. Who is responsible
The Herbarium is operated by a sole trader based in Malta, who is the data controller for the processing described here. Contact: theherbarium.beta@gmail.com.
2. Data that stays on your device
- Everything, if you don't sign in. Signed out, your journal, vault, stash, preferences, photos, and settings live only in your device's browser storage. Nothing is transmitted to us.
- Photos, signed out, are stored in your device's local database (IndexedDB) and are not uploaded. If you sign in, they sync under your account — see section 3.
- Your app PIN (if you set one) is stored only on your device as a hash and never leaves it.
- Age and terms confirmation dates are recorded on your device and are not uploaded.
- Usage counts. The app tallies which features you use and how often, on the device. Once a day it reports the day's tallies to our own server (see section 5): event names and counts, the app version, and nothing else — no account or device identifier, no names of strains, no journal content, whether or not you are signed in. The report cannot be linked to you or across days. You can turn the reporting off in Profile > Privacy; the tallies then stay on the device only.
- Backups you export, plain or encrypted, are files saved to your device. The encrypted backup is locked with a passphrase you choose; we never see the passphrase and cannot recover it or open the file. If the passphrase is lost, the backup is unreadable by design.
3. Data we store if you create an account
Accounts are optional. If you create one, we store:
- Your email address, used to send sign-in links (there are no passwords) and for account and service messages such as replies to your support requests. Not for marketing.
- A copy of your collection, only after you switch on backup & sync and give explicit consent in the app (the consent screen lists exactly what travels; its text is versioned, and your agreement is recorded with its date and version). It syncs across your devices: journal entries (including any text you write in them), your collected strains and the dates you collected them, stash jars, leaf marks, badges, completed sets, milestones, small display preferences, and the date of your last backup export.
- Your specimen photos, only if you additionally opt in to photo backup — a separate choice, off until you make it. They are stored in a private bucket under your account, fenced to you by row-level security, only ever fetched through the signed-in app, and never given a public or shareable link. Deleting a photo in the app deletes the server copy; deleting your account deletes them all.
- Not synced, ever: your PIN, your invite code, and your age and terms confirmation dates. Your plan (free or Premium) is recorded on the server from billing events, never sent up from the app.
A sign-in token is kept in your browser's local storage so you stay signed in on that device. Sign-in links are single-use and the app removes the token from the address bar as soon as it arrives, so it is not left in your browsing history.
An account without backup & sync is fine: you can keep using the app locally, signed in or out, and nothing you record leaves the device.
3a. Consent, and changing your mind
Backup & sync runs on your explicit consent (GDPR art. 6(1)(a) and art. 9(2)(a)), asked for in the app at the moment you switch it on — not buried in sign-up. Photos have their own separate opt-in. We record which version of the consent text you agreed to and when, in an append-only record we cannot edit; if the text ever changes materially, we ask again.
Withdrawing is as easy as agreeing: turn backup off in Profile. Uploading stops immediately, and the live server copy of your journal and photos is removed without undue delay; if you are offline at that moment, removal completes on your next connection. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. It never touches the data on your devices, and declining or withdrawing never limits the app on your device.
4. Payments
- Subscriptions are processed by Stripe through Stripe Checkout and the Stripe billing portal. Your card number and payment credentials go directly to Stripe; they never pass through the app or our database, and we cannot see them.
- What we store about billing: your Stripe customer reference, subscription reference, subscription status, plan, and the date your current billing period ends. This is what lets the app know your subscription is active.
- Stripe acts as its own controller for payment processing, including VAT calculation and fraud prevention, under the Stripe privacy policy.
5. Where data lives, and who processes it
- Supabase hosts account data (email, synced collection, billing status) on servers in the EU (region eu-west-1). Supabase is our processor for hosting and authentication.
- Resend delivers the sign-in emails (there are no passwords, so a sign-in link is the whole login). Resend processes your email address for that delivery and related operational records only.
- Stripe processes payments as described in section 4.
- Hosting logs. The servers that deliver the app (Cloudflare) process standard technical request data (such as IP address and browser type) in short-lived logs to serve the site and protect it from abuse. We do not use this data to identify you.
- Usage counts are received by our own endpoint on Cloudflare (theherbarium.eu) and stored as anonymous daily totals with no identifier and no IP address attached, self-purging after 100 days. They are aggregate numbers about the app, not records about you: they are never sold, never shared, and cannot be traced back to a person or device.
- The app loads no third-party fonts, scripts, ad networks, or tracking pixels. All assets are served with the app itself.
6. Legal bases
- Consent (GDPR art. 6(1)(a)), and explicit consent for special-category data (art. 9(2)(a)): syncing your journal and collection, and storing your specimen photos. This applies to server-side storage of journal content and photos.
- Contract (art. 6(1)(b)): creating and running your account itself, and managing your subscription.
- Legal obligation (art. 6(1)(c)): keeping billing records where tax and accounting law requires it.
- Legitimate interest (art. 6(1)(f)): short-lived technical logs needed to keep the service secure and working.
7. Retention and deletion
- Synced data is kept while your account exists and your consent stands.
- Withdrawing consent (Profile → turn off backup & sync) stops further uploading immediately and removes the live server copy without undue delay; if you are offline at that moment, removal completes on your next connection.
- If Premium ends while backup is on, the server copy is kept for 90 days so a returning subscriber can pick up where they left off, then removed automatically.
- Deleting your account is done in the app: Profile → Delete account. It removes your photos, your synced journal, your consent records and the account itself, in that order, without undue delay. If a paid subscription is live, cancel it first (Manage subscription) — deletion tells you if so. Billing records that tax law requires us to keep are retained for the legally required period only.
- Our database provider currently keeps no server backups for this project (verified 29 July 2026: point-in-time recovery disabled, no stored backups), so removal from live systems is final. Durability comes from your own devices and exports, not server copies. If provider backups are ever enabled, this policy will first be updated with the backup window, and the rule will be: deleted data may persist in backups until the provider's normal cycle expires, is never restored except in a disaster-recovery event, and deletions are re-applied after any restore.
- Deleting the account removes the server copy, not the copy on your devices; you remove that on the device itself (or keep it and continue signed out). Likewise, clearing a device does not delete the server copy.
- Data you have emailed us (support, feedback) is deleted on request.
8. Your rights (GDPR)
You have the rights of access, rectification, erasure, restriction, portability, and objection. Much of this you can do directly in the app: export your data any time from Profile (this covers portability), correct it by editing, and erase local data by deleting entries or clearing the app's storage. For server-side data, you can withdraw consent or delete your account in the app under Profile. For any other rights — access, rectification, restriction, objection — email us and we will act on it. You also have the right to lodge a complaint with a supervisory authority, either the Information and Data Protection Commissioner in Malta or the data protection authority where you live.
9. What we don't do
- No third-party analytics or tracking scripts, no tracking cookies, no fingerprinting, no third-party fonts. The only usage measurement is the anonymous, identity-free counting described in sections 2 and 5 — switchable off in the app.
- No advertising networks.
- No selling, renting, or sharing of personal data with third parties beyond the processors named above.
- No automated decision-making or profiling with legal effect.
10. Children
The Herbarium is strictly for adults 18 and over. The app requires age confirmation before entry, and we do not knowingly allow use by minors. If you believe a minor has created an account, contact us and we will delete it.
11. Changes
If what we process or why changes, this policy will be updated first and the change flagged in the app before it takes effect.
12. Contact
Data controller and contact for all privacy matters: theherbarium.beta@gmail.com.