Privacy Policy
Draft — not yet reviewed by legal counsel. This English text is published so that users outside Japan can read it, and it is expected to change once legal review is complete. The Japanese versions at /legal/privacy and /legal/terms carry the same status.
Gadenin ("we", "the service") is a home gardening journal operated from Japan. This policy explains what we hold about you, why we hold it, who else sees it, what your device keeps, and how you exercise your rights over it.
1. What we store on our servers
Account. An internal user identifier, the subject identifier issued by Google or Apple when you sign in, your display name, handle, profile name, avatar image, a short bio, an optional grower role and the year you started growing, and whether your profile is public. We do not store your email address on your account record. The email column was removed from the account table. The sign-in provider does return an email address to the app as part of an ordinary sign-in response, and we discard it instead of writing it to our database. The only email address we store is the reply address you type into the support form yourself.
Growing area. A country and an administrative region (for Japan, a prefecture) that you choose yourself. This is a coarse, self-declared area, not a device location.
Content. Plants, growth records, work logs, categories, notes, posts, comments, likes, follows and favourites, and the photos and videos you attach to them.
Support. If you write to us through the support form we keep the category, the reply address you type, your message, a truncated user-agent string, a one-way hash of your IP address used only to stop repeated submissions, and the language and country of the request so that we can reply in the right language. We do not store the raw IP address. We delete an enquiry 180 days after we receive it (section 10).
Operational data. Error reports and usage events recorded against your internal user identifier, plus moderation and abuse-report records.
2. Location data
We do not store your device's precise location. Weather is looked up from the representative coordinates of the region you selected, and that request is made by our server, so your device coordinates are never sent to the weather provider.
If you grant the device location permission, your coordinates are used to work out which country and region you are in, so that the region in your settings matches where you are. Turning coordinates into a place name uses the geocoding service built into your operating system, so those coordinates are sent to Apple or Google at that moment. We do not keep them afterwards. You can withdraw the permission at any time in your operating system settings.
Photos taken on a phone often carry the capture location in their Exif metadata. The app re-encodes a photo before upload, which removes the Exif metadata, and our server rejects images it detects as still carrying it. Video files are re-encoded by the picker when you choose them, but our server does not run the same check on video, so we do not make the same promise for videos as for photos.
3. What is stored on your device (we use no cookies in the app)
The Gadenin app is not a web page and sets no cookies. It does keep the following on your device:
- Authentication tokens — an access token and a refresh token held in the operating system's secure storage (iOS Keychain / Android Keystore). They identify your session to our API and are cleared when you sign out.
- Cached profile and subscription status — your own profile fields and your current entitlement, so the app can render before the network answers.
- Display preferences — the small settings the app needs to open the way you left it, such as your chosen language, theme, region, notification and sync toggles, list and view modes, and the record tags you used most recently.
- An image cache — copies of photos already shown to you, kept on disk so the app does not refetch them. It contains no additional information about you.
Signing out, and deleting your account, clears the authentication tokens, the cached profile, the cached subscription status and your location mode. The rest — your language and display preferences, the region and taxonomy caches, your list view mode and your recently used record tags — stays on the device until you clear the app storage or delete the app.
Our public website pages are served through Cloudflare, which may set strictly necessary cookies for security and traffic management.
Advertising cookies on the website (gadenin.com)
Some pages of our website — the plant guides, the pest and disease dictionary, the growing calendar, the glossary, the video rankings and the blog — show ads served by Google (Google AdSense). The home page, the app pages, the legal pages, the contact page, the operator page and the signed-in web app carry no ads. The app itself carries no ads.
Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this and other websites. Google's use of advertising cookies enables it and its partners to serve ads based on your visits to this site and other sites on the Internet. You may opt out of personalised advertising in Google's Ads Settings, and opt out of some third-party vendors' cookies at www.aboutads.info. How Google uses information from sites that use its services is described in Google's policies. If you visit from the European Economic Area or the United Kingdom you will be asked for consent before any advertising cookie is set, and without consent only non-personalised ads are shown.
4. Who else processes your data
We share only what each recipient needs, and only with the recipients listed here. We do not use data brokers.
Cloudflare
Hosting, database (D1), object storage (R2) and content delivery for everything above. Cloudflare processes account records, growing records, posts, comments and media on our behalf.
Google Sign-In and Sign in with Apple
Identity verification only. They receive the authentication request; we receive a subject identifier and the result. Your Google or Apple password never reaches us. Your growing records, photos and notes are never sent to them.
RevenueCat
Subscription state. It receives the internal user identifier, the product identifier, purchase, renewal, cancellation and expiry events, and whether the transaction was production or sandbox. It receives no growing records, photos, notes, plant names, precise location or access tokens.
Sentry
Crash and error diagnostics. It receives the app release and build, the exception type and a stack trace that does not directly identify you. We do not send it the internal user identifier, authentication headers or tokens, URL query strings, request bodies, free-text you typed, local variables, photos, notes, plant names or precise location.
PostHog
Product analytics. It receives an analytics identifier or the internal user identifier and a fixed set of named usage and subscription events with allow-listed enumerated values, booleans and counts. Session replay, screen recording and autocapture are off. It receives no photos, notes, plant names, precise location, access tokens or free text.
OpenWeatherMap
Weather lookup. Our server sends only the latitude and longitude of the representative point of a region. It receives no user identifier, display name, growing record, photo or note, and never your device coordinates.
Your operating system geocoding service (Apple, Google)
Turning coordinates into a region name. It receives the coordinates read when you ask the app to fill in your region from your current location, and nothing else from Gadenin.
Gadenin's operator
Gadenin is run by a single operator. To answer support requests, moderate the community and diagnose failures, the operator can open account records and content through an internal administration tool, including content you have not made public.
5. International transfers
Gadenin is operated from Japan, and our operational, support and moderation processes run there. Our data is held and served on Cloudflare's platform, and Cloudflare's edge network delivers it from the data centre nearest the person requesting it, so it is not confined to one country. PostHog is configured to its European Union host and Sentry to its European (Germany) region. The other processors named above operate internationally.
This means your information may be processed in a country other than the one you live in, including Japan, whose data protection regime may differ from your own. If you want to know what applies to a particular transfer, ask us and we will tell you what we know.
6. Your rights over your data
Depending on where you live, you may ask us to do the following. Where the law gives you these rights — in the European Economic Area, the United Kingdom, California and anywhere else whose law requires it — we honour them. If you write from somewhere the law does not require it, we will still take your request and do what we reasonably can.
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct anything inaccurate. Most profile and record fields can also be edited directly in the app.
- Erasure — have your account and its data deleted (see section 7).
- Portability — receive your growing records, work logs and the photos you uploaded. There is no self-service export in the app, so we put the file together by hand and send it in a commonly used format; that takes longer than a download would.
- Restriction and objection — ask us to stop a particular use, including analytics measurement through Sentry and PostHog. There is no analytics switch in the app today, so we will review the request and tell you what we can and cannot stop.
- Withdraw consent — where processing rests on consent, such as the device location permission, withdraw it without affecting what was lawful beforehand.
- Complain — lodge a complaint with your local supervisory authority.
We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not profile you for advertising.
To exercise any of these, use the support form and choose the privacy category, or email support@gadenin.com. We respond within one month; where a request is complex we will tell you and may take up to two further months. We do not charge for this and we do not treat you differently for asking.
7. Deleting your account and your data
You can delete your account yourself from the app's settings screen; the app asks for a two-step confirmation. You can also request deletion by writing to support@gadenin.com or through the support form, choosing the account category.
Deletion removes your photos and videos, including generated video thumbnails, and your avatar from object storage, and then removes your account record together with your plants, plant groups, growth records, work logs, categories, photo records, subscription state, follows, favourites, likes and comments. Your session tokens are invalidated at the same time.
Support enquiries you sent while signed in, including the reply address and the message, are deleted with your account. An enquiry sent without signing in, or sent before September 2026, is not tied to an account and cannot be found this way; those are deleted 180 days after we receive them (section 10). Write to us if you want yours removed sooner.
Some records are not removed by account deletion and are kept separately: your comments and reactions on the Gadenin blog; the subscription notifications we receive from the app store billing provider; moderation and abuse-report records; and administrative change logs. Write to us if you want your blog comments removed as well.
We also retain what the law or fraud prevention requires us to retain, and we keep abuse-report and moderation records for as long as safe community operation and the appeals process need them.
Our database keeps a point-in-time restore window of up to 30 days, so a copy of a deleted row can exist inside that window. Photos and videos live in object storage, which holds no backup copies, so deletion there is immediate.
8. Notice for California residents
We do not sell your personal information. We do not share the information tied to your account (profile, growing records, photos) for cross-context behavioural advertising, and we have not done so in the preceding twelve months, including for anyone we know to be under sixteen. Ads shown by Google on some pages of our public website (section 3) rely on Google's cookies and may be treated as "sharing" under California law; we ask Google to apply restricted data processing for California visitors, and you can opt out of personalised advertising in Google's Ads Settings.
The categories we collect are described in section 1; the business purposes are service operation, security, subscription management, support and quality improvement; the categories of recipient are described in section 4. You may exercise the rights to know, to delete, to correct, and to opt out of sale or sharing (see the previous paragraph for the website's advertising cookies), and you will not receive different pricing or a degraded service for exercising them. Send requests to support@gadenin.com or through the support form; we will ask you for enough detail to satisfy ourselves that the request comes from you. An authorised agent may act for you with written permission.
9. Children
Gadenin is not directed at children under 13 (or the higher age of digital consent that applies where you live), and we do not knowingly collect their personal information. If you believe a child has given us data, write to us and we will delete it.
10. Security
Traffic is encrypted in transit and access to production data is restricted. A scheduled job runs daily and deletes every support enquiry more than 180 days old, and you can ask us to remove yours sooner. Crash and usage records are held by Sentry and PostHog under the retention settings of those services. No system is perfectly secure, and we will notify you and the relevant authority where the law requires it.
11. Changes
We announce material changes in the app or by another reasonable means before they take effect, and the document version and effective date at the foot of this page always identify the text you are reading.
12. Contact
Support form: https://gadenin.com/support
Email: support@gadenin.com