Privacy notice
Last updated: 27 September 2026
1. Controller
Jakob Maximilian PelzOlenhoffweg 1a
21614 Buxtehude
Deutschland
Email: info@terrana.garden
No data protection officer has been appointed; the conditions of § 38 BDSG are not met.
2. What Terrana does not do
This site sets no analytics or advertising cookies, stores nothing in your browser’s local storage, and embeds no scripts, fonts or videos from anyone else’s servers. There is no analytics tool: no behavioural trackers, no advertising cookies, no session recording. A cookie banner is therefore not needed: § 25 TDDDG presupposes access to information on your device, and there is none here.
The exceptions are technically necessary cookies (§ 25(2) no. 2 TDDDG): the sign-in cookie, which holds your session; two short-lived cookies of the sign-in process itself, which fend off a forged sign-in request and remember which page to return to afterwards; and a cookie holding the language you chose, when you switch it — it lasts a year and holds nothing but “de” or “en”.
3. The processing, one by one
3.1 Visiting the website
When you visit, your browser sends technical data to our host: IP address, time, the address requested, user agent. It lands in the server log and serves the operation of the service and the prevention of abuse. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is a service that works and can be defended.
We also count for ourselves how often the public pages are opened. What is stored is only: the full hour of the request, the page requested, the campaign parameters from the address bar, and the host name of the referring site — not its address. Nothing that identifies you is stored: no IP address, no hash of one, no cookie, no identifier, and not your user agent either. The user agent is read only to filter out search engines, and then discarded. So these rows cannot be attributed to a person — not even by us — and storing the hour rather than the second is exactly why. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is knowing whether our pages are found at all.
3.2 Waiting list
If we cannot yet compute your address, you can ask to be told when we can. We then store your email address and the time. You first get an email with a confirmation link; the entry counts only once you click it (double opt-in). The legal basis is your consent under Art. 6(1)(a) GDPR. You can withdraw it at any time, an informal email to info@terrana.garden is enough, and we delete the entry. Every email we send about the waiting list tells you how to come off it.
Without confirmation the link expires after seven days. It stops working then, and the entry is deleted, not to the minute, but at the next write to the list. An unconfirmed entry is not a consent: we send you nothing on it, and if you want it removed immediately, an email is enough.
3.3 Contact form
If you write to us through the contact form, we process your email address, your message and, if you give it, your name, in order to reply. The legal basis is Art. 6(1)(b) GDPR where it concerns a contract or the steps leading to one, otherwise our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR), and § 5 DDG, which obliges us to offer such a channel.
The message is not stored here. It is forwarded as an email to our inbox and sits there afterwards, like any other email to us. There is no database of messages from the form, and therefore no separate deletion period for it. What applies is what is said below under “email correspondence”.
We do not ask you for a telephone number, and we do not give one out. The way back is the email address you give us.
3.4 Account
For an account we process your email address and a password hash; a plain-text password is stored nowhere. The legal basis is Art. 6(1)(b) GDPR, without this data there is no account. To confirm the address and to reset the password we send emails with a time-limited link; of those links, too, we store only a hash.
We also keep a few milestones against your account: when you first saw a finished garden, when you first recorded a plant, how far you got while tracing, and when you first met a limit of the free scope. Of each of those only the first time is stored, with its timestamp — no history, no counting, no further content. We read them to see where setting up gets stuck. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is a product that can be set up without help. These milestones are deleted with your account.
If you signed up with a code — from a flyer or a noticeboard — we record which code it was and the date the trial it started runs until. The code itself belongs to nobody: it is handed to a group and tells us only where we put the flyers. The legal basis is Art. 6(1)(b) GDPR, since without this entry we cannot grant the trial. It too is deleted with your account.
3.5 Your garden
If you record a garden, we process the address, the coordinates determined from it, the plot boundary and the zones and plants you draw, along with photographs you upload. The legal basis is Art. 6(1)(b) GDPR.
The address is stored and not discarded after the computation: it is what tells your gardens apart, and the computation is repeated from it when better geodata becomes available. A garden would be personal data even without the address, a plot boundary can readily be matched back to one. That is why deletion, rather than the omission of individual fields, is what we commit to (section 6).
Do not upload photographs in which other people can be recognised. If it happens anyway: tell us, and we delete the photograph.
A photograph leaves our systems only when you press “Identify the species” on a plant's page. That one photograph then goes to OpenAI (section 4.1) so a model can suggest what the species might be — without the location and camera data a phone writes into a photograph: we remove it from the copy the model receives. In your garden the photograph stays as you uploaded it, because we read the location in it to place the plant. Without that press it does not happen, and the suggestion becomes a name only when you accept it.
3.6 Share links
You can create a link for a garden that lets anyone who knows the link view it, with no account and no sign-in. That is a disclosure to third parties that you trigger yourself, and it covers the outline and the location of your plot. The link can be withdrawn at any time; that takes effect immediately.
3.7 Reports from inside the app
While you are signed in, every page carries a “Feedback” button. If you send us something through it, we process your message, your email address and your user identifier so that we can work on the problem and answer you. The legal basis is Art. 6(1)(b) GDPR, because it concerns the contract for using the product, and alongside it our legitimate interest in a product that works (Art. 6(1)(f) GDPR).
Context goes with the message. That is the page you were on, the size of your browser window, your time zone, your language setting and your browser identification – and, if you had just been writing to the plan or about a plant, the last three turns of that conversation. The dialog shows you every one of those lines verbatim before you send. Sending it, or not sending it, is how you decide.
The report is not stored here. It is forwarded as an email to our inbox and sits there afterwards, like any other email to us. There is no database of reports and therefore no separate deletion period for it; what applies is what is said below under “email correspondence”.
3.8 Access by us
For the vegetation review — which crown is a tree and which is not — a person here occasionally opens your garden. It is the only place in the product where somebody who does not belong to your account opens it.
Every one of those accesses is recorded: who here it was, which garden, what was done — opened, the aerial photograph fetched, or a verdict written — and when. The content of your garden is not in those lines; they say only that somebody was there. The legal basis is Art. 6(1)(f) GDPR, and the legitimate interest is being able to answer you this question.
Ask us about it. If you want to know who here looked into your garden and when, write to us — we look it up and tell you. These lines are deleted together with the garden they are about: delete it, and the list of accesses to it is gone too.
3.9 Product news by email
At our payment provider’s checkout you can tick a box allowing us to email you product news. If you tick it, we store that you agreed, when, and which purchase it came in on. Nothing else — no order contents, no payment details. The legal basis is your consent under Art. 6(1)(a) GDPR, and the purchase itself is the evidence that the consent is yours.
We only write when there is something to say. There is no fixed rhythm and no issue that has to appear: an email when we have built something that affects your garden. And we write only to people who agreed — having bought something does not put you on this list.
You can withdraw at any time, in one click and with no reason given — exactly as easy as the tick at the checkout was (Art. 7(3) GDPR). There are two routes and neither needs a sign-in: the unsubscribe link at the foot of every one of those emails, which is also what your mail program’s own unsubscribe button uses, and your account. An informal email to info@terrana.garden works too. Your emails about an order, your account and your garden are unaffected: those belong to the contract and do not hang on this consent.
We keep a note of what we sent you — which mailing and when, nothing more. Without it we could send you the same email twice, and we could not show what we actually sent on the basis of your consent. If you delete your account, that goes too. The emails themselves carry no tracking pixel: we do not know whether you opened them.
The consent is yours, not the account’s. Where two people share an account — a household, say — each answers for themselves. If one ticks the box, only that person gets product news; the other does not until they agree themselves. And if one withdraws, it changes nothing about the other’s consent.
A withdrawal stands. If you buy something later, the box at our payment provider’s checkout may be pre-filled again — we cannot untick it there. We do not read that as fresh consent: withdrawn with us means withdrawn.
3.10 The weekly overview
Once a week we send you an email about your own garden: what has happened there and what stands out — an empty bed, two plants standing too close together, a pruning window opening. It goes to the person who owns the account, in the language your account is set to, and it contains nothing we are trying to sell you.
This is not advertising, it is the product. The legal basis is Art. 6(1)(b) GDPR: the overview is the part of the service that arrives rather than being fetched. We ask for no consent for it, and the consent in 3.9 has nothing to do with it — they are two separate lists. Someone who never ticked a box still gets the overview about their garden, and so does someone who unsubscribed from product news.
You can switch it off, in one click in your account, and every one of those emails tells you where the switch is. We then store when you switched it off, and nothing else. Your emails about an order, your account and your garden are unaffected.
We keep a note of which week we sent you and what was in it — the points observed, not the text. Without it you would get the same week twice, and the same empty bed every Monday. Those notes belong to the garden and are deleted with it. The emails carry no tracking pixel: we do not know whether you opened them.
3.11 Invitations and shared accounts
You can invite somebody else to help look after your gardens. For that you give us their e-mail address, and we send them exactly one e-mail with a link: no reminder, no further message, and the address goes on no list. That is data about somebody who is not yet a customer. The legal basis is the legitimate interest in working on a garden together with somebody (Art. 6(1)(f) GDPR). If they do not accept, we delete the invitation and the address after 14 days; if you withdraw it before then, at once. Only invite people who expect it.
If they accept, they see the same gardens as you, and you see what they add there. Every member of an account sees its gardens with everything in them — plants, photographs, observations, tasks and conversations — including what another member added. While an invitation is open, the members who may invite can see whom it went to. None of this is visible through a share link (3.6).
We keep track of who added what. For every observation and care entry we store who made it, and for every task whom it is for and who finished it — as a reference to that person's account, never as a copy of their name. It is shown only while more than one person is on the account, and then as their e-mail address. Somebody who leaves an account is no longer named there. If you delete your account, your entries in shared gardens stay, but without any reference to you. None of it goes to the language model (4.1).
3.12 Buying, cancelling and withdrawing
When you buy a year for a garden, we store about that contract: which garden, which tier and which price, what Paddle charged (amount and currency), the state of the contract (running, payment outstanding, cancelled, withdrawn) with the start and end of the paid term, the ids of the purchase, the subscription and your customer account at Paddle, and who ordered. The legal basis is the contract (Art. 6(1)(b) GDPR): what your garden may do depends on it, and it is how we confirm the order, a cancellation and a withdrawal, remind you 30 days before a renewal, and tell you when a payment did not go through. We never see card details or the billing address; you give those to Paddle alone (4.1).
When you cancel through “Cancel contracts here”, we process what you enter there: email address, name, the type and timing of the cancellation and, if you give them, a date, a reason and how you name the contract. We send the confirmation, with its content, date and time, to the address given, because § 312k BGB requires it (Art. 6(1)(c) GDPR). On the contract we store only that it was cancelled, and when. If a person has to check something — a date of your own, an extraordinary cancellation, or no matching contract — the notice also goes by email to our inbox; what is said below under “email correspondence” applies.
When you withdraw through “Withdraw from contract”, we process the contract, your name and the address for the receipt that § 356a BGB requires (Art. 6(1)(c) GDPR). On the contract we store when you withdrew; an email to our inbox tells us which payment to refund through Paddle.
4. Recipients
4.1 Processors
These service providers process data on our behalf, under a contract pursuant to Art. 28 GDPR:
| Service | What for | Seat |
|---|---|---|
| Railway | running the website, the database and the file storage | United States |
| Paddle | the sale, the payment and the invoice: your email address and the ids of your account and garden — and, if you tick the box at the checkout, your consent to product news by email | United Kingdom |
| Resend | sending our email | United States |
| OpenAI | wording the care recommendations, and naming the species in a photograph when you ask for it | United States |
Neither your address nor a coordinate goes to OpenAI. For the care plan the model gets the area, the federal state, the zones with their names, the computed sun hours, the plants and your instructions about the plan. When you hold a conversation about the plan or about a plant, what you write there is added, and for a plant its entry: species, place in the bed, observations and care entries with your notes, open tasks and your instructions about it. “Identify the species” sends the one photograph, without location and camera data (3.5). That is not a promise but a property of the code: an automatic check fails as soon as a coordinate finds its way into the request for the plan, and a photograph’s metadata is removed before it is sent.
Paddle is more than a processor. Paddle sells you the year in its own name (merchant of record) and is itself the controller for the sale, the payment, the invoice and the tax. What Paddle keeps for that and for how long is governed by Paddle’s own privacy policy; a deletion with us does not reach it.
4.2 Services we query
These parties store nothing for us, we query them. What is transmitted differs, and the difference is the point:
| Service | What is transmitted | Seat |
|---|---|---|
| OpenStreetMap / Nominatim | the full postal address, verbatim | Germany |
| Meteostat | a public weather station's identifier and a year — nothing about the address | Germany |
| LGLN Niedersachsen | the name of a one-square-kilometre tile, nobody can be identified from that | Germany |
| OpenStreetMap / Overpass | a map window of a few hundred metres around the garden, to find buildings and trees — outside Lower Saxony only | Germany |
| Vermessungsverwaltungen | a map window of a few hundred metres around the garden, for the aerial photograph you trace on — sent to the official mapping agency of the country the garden is in | The garden's country |
| Amazon Web Services | the name of a tile of open terrain and canopy-height data several kilometres across, nobody can be identified from that | United States |
4.3 Transfer to the United States
The US services named in 4.1 process data outside the EU. Of the services in 4.2, Amazon Web Services receives only the name of a tile of open data, from which nobody can be identified. If your garden lies outside the EU, the map window for the aerial photograph goes to the official agency of the country it lies in — in the United States, for instance, the U.S. Geological Survey. The transfer relies on the European Commission’s standard contractual clauses under Art. 46(2)(c) GDPR or, where the provider in question is certified, on the adequacy decision for the EU-US Data Privacy Framework under Art. 45 GDPR. An equivalent level of protection cannot be guaranteed in every case; we point this out expressly.
5. Retention
- Waiting list: until you withdraw or we have invited you. Unconfirmed entries: the link is valid for seven days, and the entry is deleted afterwards at the next write to the list, and immediately on request.
- Account and gardens: for as long as the account exists, and at most 24 months after you last used it. For that we keep the day you were last signed in to Terrana. An account nobody has used for 24 months is deleted with every garden, photograph and aerial image — but never without warning: we write to you at the earliest 30 days and again at the earliest seven days before, and nothing is deleted until both messages have been sent. Signing in once is enough, and the period starts again. While a paid year is running for a garden in your account, a cancelled one included until its end, nothing is deleted for inactivity.
- Unconfirmed accounts: seven days. If you do not confirm your email address within seven days of signing up, we delete the account with everything attached to it.
- Error messages from the computation: if computing a garden fails, we record why — which can include the address. We delete that message 90 days after the failure; the fact that there was one stays with the garden.
- Invitations (3.11): until accepted or withdrawn, and at most 14 days. After that we delete them with the invited address.
- Deleted gardens: 30 days. When you delete a garden it disappears from your list straight away, and any shared link to it stops working straight away. The data is kept for 30 days so that you can bring the garden back. After that it is deleted for good, with every photograph and aerial image. If you would rather not wait, send us an email and we delete it immediately.
- Email correspondence, including from the contact form and from reports: for as long as it takes to answer your enquiry, and afterwards for as long as we need to be able to account for it. Neither form creates anything itself, they forward.
- Consent to product news (3.9): for as long as the account exists. We keep it as a history: the consent stays stored after you have withdrawn it, because otherwise we could not show on what basis we would have been allowed to write to you until then. The same goes for the note of which mailing went to you and when. Delete your account and both go with it.
- The weekly overview (3.10): for as long as the garden it is about exists. The note of which week went to you, and with which points in it, is deleted along with it. When you switched the overview off belongs to your account instead, and goes with that.
- Server logs: for the period our host provides for.
- The page-view count (3.1): indefinitely. Those rows hold nothing that identifies you — they cannot be attributed to anyone, not even by us, so there is nothing there to delete. They are only ever read as a total.
- Your account’s milestones and a redeemed code (3.4): as long as your account exists. They are deleted with it.
- Accesses by us (3.8): as long as the garden they are about exists. They are deleted with it — including when that leaves us unable to look up who opened a garden that has since been deleted.
- Invoices and accounting records: Paddle issues the invoices as the seller and keeps them under the obligations that apply to Paddle (4.1). With us, the record of a purchased year (3.12) is deleted with the garden: with the account, or 30 days after the garden is deleted. Where a garden passes to somebody else with a shared account, the record stays with that account, without saying who ordered. For our own accounts we keep Paddle’s settlements to us (§ 147 AO, § 257 HGB), with what they say about a purchase.
Deleted data may persist for a limited time in backups until those are overwritten on schedule. Concretely: the database is backed up daily, and each backup is kept for six days. So at most six days after a deletion, the last backup that still held the record has been overwritten too. From live operation the data is gone immediately. Backups exist solely for recovery after an outage and are read for no other purpose.
6. Deleting
You can delete each garden individually, or the whole account with every garden in it. That is not a request we process but a button in your account, and it covers the database rows as well as the photographs and images in file storage. Deleting the whole account takes two steps: you ask for it under “Account”, and we send a link to your address that is valid for one hour and deletes only on the page behind it — so that a click you did not make cannot remove anything.
The two buttons take effect at different speeds, and that is deliberate. A deleted garden can be brought back for 30 days: it is gone immediately, but not yet deleted. A deleted account is gone immediately, with every garden in it — including any still sitting in those 30 days. Somebody who is done with us should not have to wait a month.
Gardens that others help look after (3.11) are not deleted with your account. They stay with the shared account, which passes to whichever of your equals on it has been on it longest, or else to whoever has been gardening on it longest. What is deleted is your access, your address and everything that is yours alone. Somebody who leaves an account, or is taken off one, loses only the access: the gardens in it and what was added to them stay with that account, and their own accounts and gardens are untouched.
Deleting ends a paid year. If a paid year is running for a garden, it no longer renews from the moment you delete it; when the garden is deleted for good, with the account or after the 30 days, the year ends with it, with no refund for the rest of the term. If you paid for a shared account that passes to somebody else, or you leave it, it no longer renews at your cost. What Paddle must keep as the seller is not reached by a deletion here (4.1).
7. Your rights
You have the right to
- access to the data stored about you (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability, that is a machine-readable copy (Art. 20 GDPR),
- objection to processing based on legitimate interests (Art. 21 GDPR),
- withdrawal of a consent given, with effect for the future (Art. 7(3) GDPR).
An email to info@terrana.garden is enough. A request for access or for a copy gets you everything we hold about you and the gardens of your accounts as one machine-readable file (JSON), with your photographs and aerial images.
You can also complain to a supervisory authority (Art. 77 GDPR), in particular to the authority where you habitually reside or to the state authority responsible for us.
8. Changes
If what is processed changes, or who gets to see it, this page changes with it. The date at the top says when that last happened.