This Privacy Policy explains how Sacha Benz ("we", "us", "our") collects, uses, and protects your personal data when you use the Parzelle37 mobile application ("App"). We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and applicable Swiss data protection law (nDSG).
The terms governing your use of the App, including subscriptions and AI allowances, are set out separately in our Terms of Service.
1. Data Controller
2. Data We Collect
When you register, or sign in with Google or Apple, we collect your name, email address and profile picture. As a profile picture you can either pick an avatar emoji or upload a photo of your own; an uploaded photo is stored in Firebase Storage (see section 10 on where that is). This data is stored in Firebase Authentication and Firebase Realtime Database.
When signing in with Apple you may hide your email address; Apple then passes us a relay address instead of your real one. We treat it like any other email address.
You can attach photos to entries in the app โ a picture of a task, for example. Those photos are kept in Firebase Storage; the database holds only a reference to them. Photos are visible to the members of your garden.
Stored in the United States. Unlike the rest of the app's data, which lives in the europe-west1 region, uploaded photos are currently stored in a United States region (us-east1). See section 10.
Access by link. For technical reasons every photo is reachable through a long, unguessable web address. Anyone holding that address can open the image, even without being signed in to the app. The address is only ever handed out to members of your garden through the app. Please do not upload photos showing confidential information.
A photo is deleted as soon as the entry it belongs to is deleted.
All data you enter in the App โ garden layouts, plant information, activity logs, todos, costs, meeting notes, and calendar entries โ is stored in Firebase Realtime Database, associated with your user account and garden.
You may optionally provide the geographic location of your garden (latitude and longitude). You either pick it on the map or have it read from the device once โ in the second case the operating system asks your permission first, and we determine the position only at that moment, not continuously. The location is used to provide localised weather forecasts and location-aware recommendations.
For that purpose the coordinates are passed to our weather providers (see section 5) and, as part of the garden context, to our AI provider, rounded there to two decimal places. Location data is stored in Firebase and is never shared for advertising purposes.
If you allow notifications, Firebase Cloud Messaging assigns your device an identifier (a token). We store that token under your account, because otherwise we would not know which device a reminder should go to โ it is therefore linked to your identity. It serves only to deliver the notifications you switched on; it is not an advertising identifier, and we do not use it to recognise you across apps or websites. You can turn notifications off at any time, in the app's settings or in your operating system.
If the app crashes, Firebase Crashlytics sends a technical report: the error and its call stack, device model, operating-system version and app version. This is used solely to find and fix faults. We pass Crashlytics no user identifier, so the reports are not linked to your account. Collection is switched off in development builds.
So that our servers only answer requests coming from the real app, we use Firebase App Check. On the web version App Check relies on Google reCAPTCHA, which evaluates technical signals from your browser. This serves to prevent abuse, not to analyse your behaviour.
When you use AI-powered features (Plant Autofill, Garden Coach, Weekly Tips), your garden context data โ including plant names, zone information, activity history, weather data, and your questions โ is sent to the Anthropic Claude API for processing. This data is transmitted via a Firebase Cloud Functions proxy hosted in Europe (europe-west1). We do not use this data to train AI models, and Anthropic does not use data submitted through its commercial API to train models in accordance with its current commercial terms. Please refer to Anthropic's Privacy Policy for details on how they handle API data.
We track usage counters for AI features (e.g. number of AI autofills used per month) to enforce free-tier limits. These counters are stored in Firebase Realtime Database under your user account.
We collect anonymous, aggregate statistics about how the App is used โ for example, which features and screens are opened, and whether you access the App via the web, Android or iOS version โ to help us improve Parzelle37. These statistics are simple counters that are not linked to your identity or account in any way, and are stored only in our own Firebase database. No third-party analytics or advertising services are used.
If you purchase a Premium subscription, your purchase is processed by the app store you obtained the App from โ Google Play on Android, the Apple App Store on iPhone and iPad. We use RevenueCat to manage subscription status. RevenueCat receives your Firebase User ID and purchase information to verify entitlements. No payment card details are processed by us directly. Please refer to RevenueCat's Privacy Policy, Google's Privacy Policy and Apple's Privacy Policy for details.
3. Legal Basis for Processing
- Contract performance (Art. 6(1)(b) GDPR): Processing necessary to provide the App's core functionality (account management, garden data storage, feature access). This includes the AI-powered features (Plant Autofill, Garden Coach, Weekly Tips): they are part of the service we undertake to provide, and transmitting the relevant garden context to our AI processor is necessary in order to deliver them. Where a shared garden is concerned, that context includes the names your fellow members chose to display within the garden.
- Legitimate interests (Art. 6(1)(f) GDPR): Anonymous usage statistics and the usage counters that enforce tier limits, in order to operate, secure, and improve the service.
- Consent (Art. 6(1)(a) GDPR): Optional location data for weather and AI recommendations โ you may decline or remove this at any time in App settings.
4. AI-Generated Content
AI features are powered by Anthropic Claude. Your garden context data is sent to Anthropic's API to generate responses. Anthropic processes data in accordance with their privacy policy. We use a Firebase Cloud Functions proxy in Europe to minimise data transfer outside the EU/EEA where possible.
5. Third-Party Services
Firebase (Google LLC)
We use Firebase Authentication, Firebase Realtime Database, Firebase Cloud Functions, Firebase Storage, Firebase Cloud Messaging (notifications), Firebase Crashlytics (crash reports) and Firebase App Check (abuse protection) to store and process your data. Firebase is operated by Google LLC and data may be stored in Google's data centres. Our project's database and cloud functions run in the europe-west1 region (Belgium). Firebase Storage is the exception โ the photos you upload are held in the us-east1 region in the United States. See Firebase Privacy.
Anthropic (Claude API)
AI features are powered by Anthropic's Claude API. Garden context data is sent to Anthropic for processing when you use AI features. See Anthropic Privacy Policy.
Yr.no (MET Norway)
Weather forecasts are sourced from the Norwegian Meteorological Institute (MET Norway) via the Yr.no API. Your garden's geographic coordinates are sent to this API. No personal identifiers are transmitted. Weather data ยฉ MET Norway.
Visual Crossing
For historical weather records โ the basis of the watering plan and the ripeness forecast โ we use Visual Crossing Corporation. The request is made server-side only, from our Cloud Functions; all that is sent is the garden's coordinates, no personal identifier and nothing about your device. See Visual Crossing's privacy policy.
MeteoSwiss (Federal Office of Meteorology and Climatology)
For gardens in Switzerland we supplement this with measurements from the MeteoSwiss open data service. This request is also made server-side; no personal data is transmitted.
Deutscher Wetterdienst (via Bright Sky)
For gardens in Germany we supplement this with measured rainfall from the open data of the German national weather service (Deutscher Wetterdienst). The request is made through the open service Bright Sky and server-side only, from our Cloud Functions; it transmits the garden's coordinates alone โ no personal identifier and no information about your device. Weather data: Deutscher Wetterdienst, licensed under CC BY 4.0.
GeoSphere Austria
For gardens in Austria we supplement this with measured rainfall from the open data of GeoSphere Austria. This request is likewise made server-side only and transmits the garden's coordinates alone. Datenquelle: GeoSphere Austria - https://data.hub.geosphere.at
Apple (Sign in with Apple)
If you sign in with Apple, Apple verifies your identity and passes us an identifier and โ depending on your choice โ your email address or an anonymised relay address. See Apple's privacy policy.
RevenueCat
Subscription management is handled by RevenueCat, Inc. Your Firebase User ID and purchase receipts are shared with RevenueCat to verify Premium entitlements. See RevenueCat Privacy Policy.
Google Maps
The App may use Google Maps to display garden location. See Google Privacy Policy.
6. Data Retention
We retain your data for as long as your account is active. You may delete your account at any time via Settings โ Danger zone โ Delete account in the app, or request deletion through our account deletion page.
Deleted immediately: your sign-in account, your profile (name, profile picture, language, notification settings and the device tokens used for notifications), and your membership in all gardens. Any garden where you are the only member is deleted in full โ including its beds, plants, activity log, to-dos, costs, meetings, uploaded photos and open invitations.
Not removed automatically: content you contributed to a shared garden โ activity log entries, to-dos, cost items and uploaded photos. That content belongs to the garden as a shared record, and the remaining members keep working with it. For the same reason a garden stays in place when other members are in it.
You can still request the removal of that remaining content โ write to us at info [at] parzelle37.app or use the account deletion page. We complete this within 30 days. Where an entry is genuinely needed by the remaining members (a cost item that has already been settled, for instance), we remove the link to you instead.
AI usage counters are retained for billing and abuse-prevention purposes for up to 12 months after account deletion. Crash reports are retained according to Firebase Crashlytics' own periods; they are not linked to your account and cannot be attributed to a person.
7. Your Rights
Under the GDPR and Swiss nDSG, you have the following rights:
- Right of access โ request a copy of your personal data
- Right to rectification โ correct inaccurate data
- Right to erasure โ request deletion of your data ("right to be forgotten")
- Right to restriction โ request restricted processing of your data
- Right to data portability โ receive your data in a structured, machine-readable format
- Right to object โ object to processing based on legitimate interests
- Right to withdraw consent โ withdraw consent at any time without affecting prior processing
To exercise any of these rights, please contact us at info [at] parzelle37.app. We will respond within 30 days.
You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch, or with your local EU supervisory authority.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- All data in transit is encrypted using TLS/HTTPS
- Firebase Authentication provides secure, token-based access control
- API keys and secrets are stored server-side in Firebase Cloud Functions and never exposed in the App
- Firebase Realtime Database security rules restrict access to authorised users only
9. Children's Privacy
Parzelle37 is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. International Data Transfers
Your data may be processed outside Switzerland and the EU/EEA by our third-party service providers (Google/Firebase, Anthropic, RevenueCat). Where required, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or adequacy decisions. Firebase data is processed under Google's Data Processing Terms which include SCCs.
We keep data in Europe wherever we can: the database and cloud functions run in europe-west1, and AI requests go through a proxy hosted in Europe. Photos you upload are a deliberate exception โ they are stored in the United States (us-east1), because Firebase Storage offers no equivalent no-cost option in Europe. That transfer also relies on the Standard Contractual Clauses in Google's Data Processing Terms. If you would rather not have this, simply do not upload photos โ every other part of the app works exactly the same.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the "Last updated" date at the top of this page. Continued use of the App after changes constitutes acceptance of the updated policy.
12. Contact
For any questions, requests, or complaints regarding this Privacy Policy or our data practices, please contact: