Last updated 31 August 2026
Tomatograph helps households plan and track what they grow. This policy explains exactly what we collect, why we collect it, who else sees it, and how to get rid of it. It covers both the Tomatograph website and the Tomatograph iOS app.
We don't sell your data, we don't share it with advertisers, and we don't use third-party advertising or analytics trackers.
Tomatograph is operated by Mantas Ratomskis. For any privacy question, or to request access to or deletion of your data, email grow@tomatograph.com.
You sign in with Apple or Google — we never see or store a password. From that sign-in we receive and store a provider account identifier, your email address, and your display name if the provider supplies one. If you use Sign in with Apple's “Hide My Email”, we only ever see the relayed address. We also store your time zone, hemisphere, and notification preferences.
This is the substance of the product: your gardens, the structures in them (beds, greenhouses, lawn areas), what you're growing, growth stages, the care tasks we generate, and which ones you complete.
Location. A garden is tied to a location — either one you search for by name, or your device's location if you tap “use my location” and grant permission. We store the coordinates plus the resolved city, region, country, and postal code. We need this because the entire product is driven by local weather, frost dates, and hardiness zone; a garden without a location can't generate meaningful advice. On iOS, location permission is requested only at the moment you tap that button, and you can decline and type a location instead.
If you add a photo of a plant, we store it and — only when you explicitly tap “identify plant” or “check health” — send it to the third-party services listed below for analysis. We don't scan your photo library; the app only receives the specific images you pick or capture.
If you enable push notifications we store a device push token. We log plant-library search terms against your account, which we use to decide what to add to the plant database. Our servers keep standard request logs.
For users in the EEA and UK: we process account and garden data because it's necessary to perform our contract with you — without it the service cannot function. Push notifications and marketing email are processed on the basis of your consent, which you can withdraw at any time in Settings. Keeping the service secure and working rests on our legitimate interests.
We use the following processors. Each receives only what that specific feature needs, and none of them are permitted to use your data for their own purposes.
| Service | What it receives | Why |
|---|---|---|
| Apple, Google | Sign-in exchange | Authentication |
| Anthropic (Claude) | Garden details and, on request, plant photos | AI garden review and plant health checks |
| Pl@ntNet | Plant photos you submit for identification | Species identification |
| Open-Meteo | Garden coordinates | Weather forecast |
| OpenStreetMap (Nominatim) | Coordinates or a place-name search term | Finding and naming your garden's location |
| phzmapi.org | Postal code | Hardiness zone lookup |
| Cloudflare (R2) | Your uploaded photos | Photo storage |
| Resend | Recipient email address | Household invitation emails |
| Apple (APNs) | Device token and notification text | Push notifications |
| Hostinger | Hosts our servers and database | Infrastructure |
We may also disclose data if legally required to, or to protect our rights or someone's safety.
Tomatograph is built for shared gardens. Anyone you invite into your household can see that household's gardens, plants, photos, and task history, and can see which member completed which task. Only invite people you're comfortable sharing that with.
Our servers are in the EU. Some processors above are based in the United States, so your data may be transferred there under appropriate safeguards such as Standard Contractual Clauses.
We keep your data for as long as your account exists. If you delete your account, we delete your personal data, gardens, and photos within 30 days, except where we're legally required to retain something (for example, payment records). Backups are purged on a rolling basis within 90 days.
You can request access to, correction of, export of, or deletion of your data, and you can object to or restrict certain processing. Email grow@tomatograph.com and we'll respond within 30 days. If you're in the EEA or UK you also have the right to complain to your local data protection authority.
Email grow@tomatograph.com from your account's address and we will delete your account and associated data within 30 days.
Tomatograph isn't directed at children under 13 (or under 16 in the EEA), and we don't knowingly collect their data. If you believe a child has given us data, contact us and we'll delete it.
Traffic is encrypted in transit with TLS. Access to production systems is restricted. No system is perfectly secure, but if we ever discover a breach affecting your personal data we'll notify you and the relevant regulator as required by law.
If we make a material change we'll update the date at the top of this page and, where the change is significant, notify you in the app or by email.