Privacy

    Privacy Policy

    This privacy policy explains how personal data is processed when you use the GrowHelper website and web application.

    Last updated: 20 July 2026

    1. Controller

    The controller under the General Data Protection Regulation (GDPR) is:

    Marvin Trilk
    Sole proprietor, trading as GrowHelper
    Eresburgstr. 46b
    12103 Berlin, Germany
    info@grow-helper.com

    2. General principles

    We process personal data only where necessary to operate the website, provide the app, perform a contract, communicate with you, process payments or protect the service. The main legal bases are Article 6(1)(b) GDPR for pre-contractual measures and contract performance, Article 6(1)(c) GDPR for legal obligations and Article 6(1)(f) GDPR for legitimate interests in secure, stable and economical operation.

    3. Firebase Hosting, server logs and domain management

    The public GrowHelper website and the web application at app.grow-helper.com are provided through separate Firebase Hosting sites. Firebase Hosting is a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and, depending on the processing activity, Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Static content is delivered over an encrypted connection and a global content delivery network (CDN).

    When the website or web application is accessed, technically necessary connection and web request data is processed. This may include the IP address, date and time, requested URL or file, referrer URL, browser and device information, data volume, HTTP status code, response times and security information. The processing is used to deliver content, maintain stable and secure operation, diagnose errors and protect against misuse and attacks. The legal basis is Article 6(1)(f) GDPR. Google generally processes customer data as a processor under the applicable data processing terms. Log data is retained only for as long as necessary for these purposes, the configured logging settings or legal obligations.

    Further information about Firebase Hosting: Firebase Privacy and Security

    The grow-helper.com domain and its DNS configuration are managed through IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. IONOS does not deliver the GrowHelper website. In connection with domain and DNS management, IONOS processes the contractual, administrative and technical data required for those services. The legal basis is Article 6(1)(b) GDPR where the processing is necessary to provide the domain and otherwise Article 6(1)(f) GDPR based on our legitimate interest in reliable domain and DNS management.

    Further information about privacy at IONOS: https://www.ionos.de/terms-gtc/datenschutzerklaerung/

    4. Additional Firebase and Google Cloud services

    In addition to Firebase Hosting, GrowHelper uses further services provided by Google Ireland Limited and, depending on the processing activity, Google LLC. These include Firebase Authentication, Cloud Firestore, Cloud Storage for Firebase and Google Cloud Run for server-side API processing. These services are used to manage user accounts, secure sign-in sessions, store and provide grow data, equipment, strains, chats, images and related files, and securely execute server-side requests. API calls may additionally involve technically necessary log data such as the IP address, time, requested endpoint, status code and security information. Google generally processes customer data for these services as a processor under the applicable data processing terms. Our legal basis is Article 6(1)(b) GDPR; additional security, stability and abuse-prevention measures are based on Article 6(1)(f) GDPR.

    Further information: Firebase Privacy and Security

    5. Account and Google Sign-In

    The app currently requires sign-in with a Google account. During sign-in, we receive, depending on the account data released by Google, your name, email address, optional profile image and a unique Google or Firebase user ID. We use this data to create your account, authenticate you and associate stored content with your account. The legal basis is Article 6(1)(b) GDPR. During the Google sign-in process, Google also processes data under its own responsibility in accordance with Google's privacy policy.

    Google Privacy Policy: https://policies.google.com/privacy

    6. Grow data, equipment, strains, chats and images

    When you use GrowHelper, we process content that you enter or upload. This may include equipment profiles, grow and strain data, germination and status data, medium, pot and water information, water reports, feeding schedules, current measurements, light information, chat messages, AI responses, images and documents. The data is associated with your account and processed to provide, synchronise and personalise the app. The legal basis is Article 6(1)(b) GDPR. We do not sell this data. It is disclosed only to service providers where necessary for storage, authentication, AI processing, payment processing, communication or security, or where required by law.

    7. AI processing with the Google Gemini API

    For AI chat, image analysis and OCR, GrowHelper transmits the content required for the specific request to the paid Google Gemini API. Depending on your use, this may include your message, selected grow and equipment data, current measurement and light values, the chat history included within the applicable context limit and newly uploaded images or documents. The data is transmitted so that Google can generate the requested AI output. The legal basis is Article 6(1)(b) GDPR.

    Under the terms for paid Gemini API services, Google does not use prompts, associated files or responses to improve its products. Google may, however, log prompts and responses for a limited period for safety, abuse detection and legal compliance. Data may be processed or cached temporarily in countries where Google or its subprocessors maintain facilities. The applicable Google data processing terms govern processing on our behalf.

    Gemini API terms: https://ai.google.dev/gemini-api/terms

    Please do not upload identity documents, health records, medical diagnoses or other highly sensitive personal data. Only upload personal data relating to third parties where you are legally authorised to do so.

    8. OCR processing

    When using OCR, water reports, feeding schedules, tables or similar documents supplied by you are transmitted to the Gemini API so that relevant values can be recognised and transferred into your grow profile. Before uploading, please check the document and remove names, customer numbers, addresses or other personal details that are not required for the analysis. The legal basis is Article 6(1)(b) GDPR.

    9. Usage and quota data

    To manage plan limits, token budgets, active chats, top-up balances and abuse prevention, we process usage data such as plan status, consumed or estimated tokens, the number of chat, vision and OCR operations, timestamps and technical status information. The legal basis is Article 6(1)(b) GDPR and Article 6(1)(f) GDPR based on our legitimate interest in correct billing, capacity management and protection against misuse.

    10. Stripe: subscriptions, payments and token top-ups

    We use Stripe for paid subscriptions and token top-ups. Depending on the processing activity, Stripe Payments Europe, Limited, and other Stripe entities identified in Stripe's privacy information may be involved. When a purchase is initiated, you are redirected to Stripe Checkout. To manage an active subscription, update payment information, view payment history or cancel through the app, you are redirected to the Stripe Customer Portal.

    Stripe processes in particular the name, email address, billing and payment information, selected payment method, amount, currency, plan or top-up, payment and subscription status, transaction, customer and subscription identifiers, and technical data such as IP address, device and browser information. Stripe may also use data for payment processing, authentication, fraud prevention, risk assessment, compliance with financial and regulatory obligations, and the handling of refunds and chargebacks. Full card or bank details are generally collected directly by Stripe and are not transmitted to GrowHelper. We receive the status and transaction information required for contract administration, activation, accounting and customer support.

    Our legal basis for payment- and contract-related processing is Article 6(1)(b) GDPR. Billing and accounting data required by law is processed under Article 6(1)(c) GDPR. Fraud and abuse prevention measures may be based on Article 6(1)(f) GDPR. Depending on the activity, Stripe processes certain data as an independent controller and other data as a processor or service provider. Stripe's privacy policy and terms additionally apply.

    Stripe privacy information: https://stripe.com/de/privacy

    11. Contacting us

    If you contact us by email, we process your contact details and the content of your message in order to handle your request. The legal basis is Article 6(1)(b) GDPR where the request relates to a contract or pre-contractual measures, otherwise Article 6(1)(f) GDPR based on our legitimate interest in handling support, feedback, partnership and press inquiries. Messages are deleted once the request is complete and there are no statutory retention requirements or legitimate reasons for further storage.

    12. Cookies and local storage

    GrowHelper currently uses only strictly necessary cookies and browser storage. This includes language and display preferences, Firebase authentication data and local AI chat settings. We currently do not use analytics, marketing or advertising cookies. Further details are available in the Cookie and Storage Policy.

    13. Recipients and processors

    The principal recipients and service providers currently include IONOS for domain and DNS management, Google or Firebase for hosting, authentication, database, file storage, server-side API processing and app infrastructure, Google Gemini for AI chat, image analysis and OCR, and Stripe for checkout, payments, subscriptions, top-ups and the customer portal. Data may also be disclosed where necessary to providers of email communications and IT security, and to legal or tax advisers. Where required by law, we enter into processor agreements under Article 28 GDPR. We do not disclose personal data for advertising purposes or sell it.

    14. International data transfers

    IONOS is established in Germany. When Google, Firebase, Google Cloud, Gemini, Stripe and their affiliates or subprocessors are used, processing outside the European Economic Area may take place. Firebase states that Firebase Authentication is operated exclusively from data centres in the United States. Globally provided Firebase services such as Firebase Hosting, Cloud Firestore and Cloud Storage for Firebase may, depending on the service configuration and any selected data location, be processed on global Google infrastructure. Where no European Commission adequacy decision applies, transfers are based in particular on European Commission-approved Standard Contractual Clauses and supplementary safeguards. Google and certain Stripe entities may additionally be certified under the EU-US Data Privacy Framework for particular transfers. Despite these safeguards, third countries may provide different forms of government access.

    15. Retention and deletion

    Account data and content stored in GrowHelper are generally processed for as long as your account exists or the data is required for the relevant function. You can delete individual chats, images and grow data through the available features. Following account deletion or a valid erasure request, we remove or anonymise personal data from active systems without undue delay unless statutory retention obligations, outstanding claims, security requirements or mandatory technical periods apply. Billing and business records may be retained for several years where required by law. Backup copies are overwritten within regular backup cycles. The applicable Google or Firebase retention rules and the periods configured by us apply to technical hosting and API logs and to security logs maintained by Google in connection with the Gemini API.

    16. Your data protection rights

    Subject to the statutory requirements, you have in particular the right of access under Article 15 GDPR, rectification under Article 16 GDPR, erasure under Article 17 GDPR, restriction of processing under Article 18 GDPR, data portability under Article 20 GDPR and objection under Article 21 GDPR to processing based on Article 6(1)(e) or (f) GDPR. Where processing is based on consent, you may withdraw that consent at any time with future effect. To exercise your rights, email info@grow-helper.com.

    17. Right to lodge a complaint

    You have the right to lodge a complaint with a data protection supervisory authority. The Berlin Commissioner for Data Protection and Freedom of Information is generally the authority responsible for GrowHelper. You may also contact the authority at your habitual residence or place of work.

    https://www.datenschutz-berlin.de/

    18. Automated decision-making

    GrowHelper does not make decisions based solely on automated processing that produce legal or similarly significant effects within the meaning of Article 22 GDPR. AI outputs are supporting information. You remain responsible for decisions concerning cultivation and the implementation of recommendations.

    19. Minors

    GrowHelper is intended solely for adults. We do not intend to offer accounts to anyone under the age of 18. If we become aware that an account is being used by a minor contrary to this requirement, we may suspend the account and delete the associated data in accordance with applicable law.

    20. Data security

    We implement appropriate technical and organisational measures to protect personal data against loss, unauthorised access, alteration and disclosure. These measures include encrypted transmission, account-based access controls and limiting data disclosures to necessary service providers. Absolute protection during transmission or storage cannot be guaranteed.

    21. Changes to this privacy policy

    We update this privacy policy when features, data flows, service providers or legal requirements change. We will provide appropriate notice of material changes. The current version is always available at this URL.