Privacy Policy
Information about the protection of your personal data in accordance with GDPR
1. Overview
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy. The use of our website is generally possible without providing personal data. Where personal data is collected on our pages, this is always done on a voluntary basis.
2. Data Controller
Alexander Ohlei
Will be added shortly
Email: info@talkingplants.de
3. Data Collected
Account Data
- Username (freely chosen, no real name required)
- Password (stored encrypted as bcrypt hash)
- Display name (optional)
- Email address (optional, for account recovery)
- Language preference
- Theme preference (light/dark)
Telegram Data
- Telegram Chat ID (for delivering plant messages)
- Messages sent and received via Telegram
Sensor Data
- Plant sensor data: temperature, soil moisture, light intensity, conductivity (with timestamps)
- Sensor configuration: name, schedules, thresholds, assigned AI character
- Sensor hardware ID (for unique identification)
Chat Data
- All chat messages between you and your plant AIs
- AI-generated responses
- Custom-created characters and prompts
Usage Data
- Credit transactions (credits, consumption, voucher redemptions)
- Message log (timestamps of automated message deliveries)
- Session data (temporary, for authentication)
4. Purpose of Data Processing
- Providing and managing your user account
- Collecting and displaying your plant sensor data
- Generating personalized AI messages based on sensor data and chosen character
- Delivering messages via Telegram
- Managing the credit system for AI feature usage
- Ensuring technical operation and troubleshooting
5. Legal Basis
The processing of your data is based on the following legal grounds:
- Art. 6(1)(b) GDPR — Contract performance: Processing to provide the service (account, sensor data, AI chat)
- Art. 6(1)(a) GDPR — Consent: Voluntary information such as email, Telegram linking
- Art. 6(1)(f) GDPR — Legitimate interest: Technical operation and security of the platform
6. Cookies and Local Storage
Our website exclusively uses technically necessary cookies and local storage. No tracking or analytics cookies are used.
Necessary Cookies
| Name | Purpose | Duration |
|---|---|---|
PHPSESSID |
PHP session cookie for authentication | Session end (max. 24 hours) |
Local Storage (localStorage)
| Name | Purpose | Duration |
|---|---|---|
lang |
Stores your language preference | Persistent (until manually cleared) |
theme |
Stores your theme preference (light/dark) | Persistent (until manually cleared) |
cookie_consent |
Stores your cookie consent choice | Persistent (until manually cleared) |
We do not use tracking cookies, Google Analytics, social media plugins, or any other analytics tools. Your usage is not profiled.
7. Third-Party Services
Telegram (Telegram FZ-LLC)
We use the Telegram Bot API to send plant messages to your Telegram account. Your Telegram Chat ID is transmitted to Telegram. Telegram's privacy policy applies: https://telegram.org/privacy
OpenAI (OpenAI, L.L.C.)
For generating AI plant messages, we use the OpenAI API. Sensor data and chat context are transmitted to OpenAI. OpenAI processes this data according to their privacy policy: https://openai.com/privacy
Anthropic (Anthropic, PBC)
Alternatively, we use the Anthropic API (Claude) for AI generation. Sensor data and chat context are transmitted to Anthropic. Privacy policy: https://www.anthropic.com/privacy
Fonts (self-hosted)
This website uses the fonts Playfair Display and DM Sans. These are hosted locally on our server — no connection to Google servers is made.
8. Storage and Deletion
Your data is stored on a server in Europe. The storage duration depends on the type of data:
- Sensor data: Stored as long as your account exists. Older data may be aggregated.
- Chat history: Stored until you manually delete it or delete your account.
- Account data: Completely and irrevocably deleted upon account deletion.
9. Your Rights
Under the GDPR, you have the following rights regarding your personal data. To exercise your rights, please contact: info@talkingplants.de
- Right of access (Art. 15 GDPR) — You can request information about your stored data.
- Right to rectification (Art. 16 GDPR) — You can request the correction of inaccurate data.
- Right to erasure (Art. 17 GDPR) — You can request the deletion of your data.
- Right to restriction (Art. 18 GDPR) — You can request the restriction of processing.
- Right to data portability (Art. 20 GDPR) — You can receive your data in a machine-readable format.
- Right to object (Art. 21 GDPR) — You can object to the processing of your data.
You also have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data violates the GDPR.
10. Account Deletion
You have the right to delete your account at any time. Upon deletion, all personal data (profile data, sensor data, chat histories, credit transactions) will be irrevocably removed. The account deletion feature will be available in the user area shortly.
11. Changes to This Privacy Policy
We reserve the right to adapt this privacy policy to always comply with current legal requirements or to implement changes to our services. The new privacy policy will then apply to your subsequent visits.