Privacy Policy

Effective Date: May 1, 2026
Last Updated: May 1, 2026
Legal Entity (Data Controller): KOLABS Kacper Orzechowski
Privacy Contact Email: contact@greenao.com

This Privacy Policy explains how Greenao ("we", "us", or "our") handles information when you use the Greenao app, website, and related services (the "Service").

1. Quick Summary

Greenao is designed to minimize server-side data storage. Most user content remains on your device.

2. Required Service Facts

  • Supabase is used for user authentication.
  • RevenueCat is the subscription handler.
  • Supabase also stores RevenueCat webhook events.
  • OpenAI is used to identify plants in AI scan feature.
  • Cloudflare R2 is used to temporarily upload scan photos and these photos are removed right after scan finishes.
  • No other user data is stored server-side; user content and plant data live on the user's device.

3. Information We Process

A) Account and Authentication Data

We process the minimum account and authentication data needed to sign you in and manage session access through Supabase Authentication.

B) Subscription and Purchase Status

  • Subscription transaction handling occurs through Apple App Store or Google Play.
  • RevenueCat is used to process subscription entitlement status.
  • RevenueCat webhook events are stored in Supabase for subscription state handling and service reliability.

C) AI Scan Data

  • When you use AI scan, scan photos are temporarily uploaded to Cloudflare R2 to process the scan.
  • OpenAI is used to identify plants in the AI scan feature.
  • Scan photos are removed right after scan finishes.

D) On-Device User Content

  • User content and plant data are stored on your device.
  • Greenao does not store this content server-side.

4. How We Use Information

We use information to:

  • Authenticate your account access.
  • Validate and maintain subscription access and entitlement status.
  • Perform AI plant identification.
  • Maintain operational reliability and basic service integrity.
  • Comply with legal obligations, if applicable.

We do not sell your personal information.

Depending on your jurisdiction, our legal bases may include:

  • Performance of a contract (providing the Service you request).
  • Legitimate interests (service security, fraud prevention, and reliability).
  • Compliance with legal obligations.
  • Consent where required by law.

6. Data Retention

  • Scan photos are temporarily stored in Cloudflare R2 and removed right after scan finishes.
  • Auth and account records are retained as needed to provide account access, unless and until deletion is requested or legally required otherwise.
  • RevenueCat webhook events stored in Supabase are retained as needed for subscription handling, reconciliation, support, and compliance obligations.
  • On-device user content and plant data are retained on your device under your control.

Retention periods may vary where law requires longer or shorter storage.

7. Sharing and Processors

We share limited information with processors strictly to operate the Service:

  • Supabase (authentication; storage of RevenueCat webhook events)
  • RevenueCat (subscription handling)
  • OpenAI (AI plant identification)
  • Cloudflare R2 (temporary scan photo upload during scan processing)
  • Apple and Google (in-app purchase and subscription billing ecosystem)

We may also disclose information if required by law, legal process, or to protect rights, safety, and security.

8. International Data Transfers

Service providers may process data in countries other than your own. Where required, we use appropriate safeguards for cross-border data transfers.

For users in the EEA and UK, we rely on appropriate safeguards for international transfers, including Standard Contractual Clauses (SCCs) and UK transfer mechanisms (including the UK International Data Transfer Addendum), where applicable.

9. Security

We use reasonable technical and organizational measures to protect data processed through the Service. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. Children's Privacy

The Service is not directed to children under 13 (or higher age where local law requires). We do not knowingly collect personal information from children in violation of applicable law. If you believe a child has provided personal information unlawfully, contact us so we can investigate and take appropriate action.

11. Your Privacy Rights

Depending on your location, you may have rights to:

  • Access personal data we process about you.
  • Request correction of inaccurate data.
  • Request deletion of your account-related data.
  • Request restriction or object to certain processing.
  • Request portability where applicable.
  • Withdraw consent where processing is based on consent.

To exercise rights, contact: contact@greenao.com. We may need to verify your identity before processing requests.

12. Account Deletion and Data Deletion Flow

You can request account deletion through: Send an account deletion request to contact@greenao.com.

When account deletion is completed:

  • Authentication and account records are deleted or anonymized unless retention is required by law.
  • Subscription handling records and webhook-related records may be retained where required for accounting, fraud prevention, legal defense, or compliance.
  • On-device user content and plant data remain under your local device control unless you remove them from your device.

13. App Store and Subscription Privacy Notes

Subscription purchases, renewals, and cancellations are managed by Apple or Google under their platform rules. RevenueCat processes subscription entitlement state to enable app features. For payment details and billing identifiers, refer to Apple and Google privacy terms.

14. Changes to This Policy

We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the app, website, or other appropriate means before the updated policy becomes effective.

15. Contact

  • Email: contact@greenao.com
  • Legal Entity: KOLABS Kacper Orzechowski

Greenao logoGreenao - AI-supported plant care for modern homes.