Effective 12 June 2026

Privacy Policy

Learn how HaljasVaade handles accounts, uploaded garden photos, AI prompts, generated ideas, purchases, analytics consent, waitlist data, retention, and deletion.

Operator

HaljasVaade is operated by J&L Serverid OÜ, registry code 11478495, VAT number EE101657514, Tartu, Estonia. Contact: info@haljasvaade.ee.

Data we collect

We collect account details such as name, email address, password credentials or Apple/Google sign-in identifiers, language preference, notification preferences, push notification device tokens, terms acceptance, and email verification status.

When you create a garden idea, we process uploaded outdoor-space photos, project details, prompts, generated images, saved ideas, folders, and refinement notes.

If you buy a prepaid design pack, Apple, Google, and RevenueCat process the payment. We receive purchase identifiers, entitlement status, product identifiers, and transaction summaries needed to unlock paid features.

We store technical data needed to run the service, including authentication tokens, API request records, generation job status, push delivery records, media URLs, error logs, and security or abuse-prevention signals.

On the public website, we use optional Google Analytics 4 and PostHog only after you accept analytics. These tools may process page URL, referrer, approximate location, device and browser details, product interaction events, and analytics identifiers stored in cookies or local storage. We also store your analytics choice in this browser's local storage.

If you join the waitlist, we collect your email address, language, source page, selected interest, contact-consent choice, and technical anti-spam fields so we can send launch or product updates you requested and measure which public pages create interest.

How we use data

We use data to provide accounts, uploads, AI-assisted garden visualizations, job-ready push notifications when enabled, saved projects, billing entitlements, customer support, security, rate limits, exports, account deletion, and waitlist/product-update messages when you consent.

Our legal bases are contract performance for accounts, uploads, generated ideas, saved projects, billing entitlements, support, exports, and deletion; consent for optional push notifications and optional website analytics; legal obligation for required tax, accounting, and consumer records; and legitimate interest for security, abuse prevention, diagnostics, rate limits, and service reliability.

Uploaded photos and prompts are sent to our backend and may be sent to AI model providers to generate and refine garden concepts. AI outputs are for inspiration and planning support, not professional advice.

We do not sell personal data and we do not use third-party advertising tracking.

Website analytics and cookies

The website does not load Google Analytics or send PostHog analytics before you accept analytics. If you accept, we load GA4 from googletagmanager.com and send page-view events to measurement ID G-C5LL32FPZ5. We also send page views and explicit product events such as store-download clicks and waitlist submissions to PostHog EU project 142971.

GA4 and PostHog use analytics identifiers such as _ga and ph_ cookies or local storage to distinguish visits and prepare product reports. We use these reports to understand which public pages are useful, whether campaigns work, where the website needs improvement, and where product funnels lose users.

Your choice is stored locally under haljasvaade.analyticsConsent.v1. You can decline analytics in the consent banner or change your choice on this privacy page. If you decline after previously accepting, we stop sending analytics events and ask the browser to remove GA and PostHog analytics cookies for this site.

Service providers

We use infrastructure, email, payment, billing, and AI generation providers to operate the service. These providers process data only as needed for their service role.

Current provider categories include hosting and storage, email delivery, Apple and Google identity providers when you use social sign-in, Firebase Cloud Messaging, Apple App Store, Google Play, RevenueCat, Google Analytics and PostHog for optional website analytics, waitlist/message delivery tooling, and AI model APIs such as OpenRouter and the model providers routed through it.

Retention and deletion

We keep account, project, media, billing, and operational records while your account is active or while needed for legal, tax, security, and service reliability reasons.

Deleted accounts are removed from the active service within 30 days unless a longer period is required for legal, payment, fraud-prevention, or security reasons. Billing and accounting records may be retained for up to 7 years where required by Estonian accounting law. Security, abuse, and operational logs are normally kept for up to 12 months unless needed to investigate an issue. Waitlist records are kept until you withdraw consent, unsubscribe, or we no longer need them for the launch/update purpose.

You can request account export or deletion in the app settings. The export is a ZIP archive that includes your account data, uploaded photos, and generated images. Deletion removes or disables account access and removes personal project data unless retention is required by law, fraud prevention, payment records, or legitimate security needs.

Your rights

Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing of personal data.

To exercise privacy rights, withdraw waitlist consent, or unsubscribe from product-update messages, contact info@haljasvaade.ee from the email address connected to your account or waitlist signup.

If you are in the EU or EEA, you may also complain to a supervisory authority. In Estonia, the supervisory authority is Andmekaitse Inspektsioon at https://www.aki.ee/en.

Security and international processing

We use technical and organizational safeguards appropriate for a small online service, including authenticated API access and restricted operational access.

Providers may process data in countries outside your own. For transfers outside the EU/EEA, we rely on the European Commission adequacy decisions, including the EU-US Data Privacy Framework where the recipient is certified, and Standard Contractual Clauses or equivalent safeguards where needed.

We are not required to appoint a Data Protection Officer under GDPR Article 37. For privacy questions, contact info@haljasvaade.ee.

Changes

We may update this policy as the service changes. Material updates will be reflected on this page, and we may notify users in the app when appropriate.