Effective date: 2026-05-21 Last updated: 2026-09-03
Sementeira ("the App", "we", "us") is a privacy-first gardening companion published by Kebrabsoluta Unipessoal Lda ("Sementeira", a Portuguese sole-shareholder limited company / Sociedade Unipessoal por Quotas). Contact: geral@kebrabsoluta.pt.
This policy explains exactly what data the App handles, where it goes, and how long it stays. It is written to comply with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and the Portuguese Lei n.º 58/2019.
Legal basis: not applicable — this data is not under our control. It leaves your device only if you move it: by exporting a backup file (§4) or by running an Android phone-to-phone transfer (§2.3). In neither case does it reach us or any server of ours.
| Trigger | Sent | Recipient | Retention |
|---|---|---|---|
| Opening the Dashboard | Approximate latitude/longitude + timezone | Open-Meteo (api.open-meteo.com) — free public weather API |
None disclosed; no account; no API key. See open-meteo.com/en/terms. |
| Tapping "Diagnose" with a photo and a network connection | Base64-encoded plant photo + optional symptom list | Sementeira backend (api.sementeira.app), which forwards the photo in a single request to Anthropic (api.anthropic.com) for AI analysis via Claude Haiku vision |
Sementeira backend: not stored. Anthropic API: zero retention under the API's default policy. See anthropic.com/legal/privacy. |
| Taking a garden-walk check-in photo with a network connection | Base64-encoded plant photo | Same path as above — Sementeira backend → Anthropic, which returns one coarse word (healthy, droopy, possibleIssue). The advice you then see is computed on your device. |
Same as above: not stored by us, zero retention at Anthropic. |
| The first time you use either photo feature | No data about you or your garden. The backend generates a random token for this installation and records it together with the IP address the request arrived from | Sementeira backend | Kept while the token exists — see §2.5. |
If you have no network, or the API is unreachable, the App falls back to an on-device TFLite model for diagnosis, and a garden-walk check-in simply records what you saw without the vision step. In those cases the photo never leaves your device. Check-in photos are always kept on the device as well — what is sent is a copy, and only at the moment you take it.
These are the only endpoints the App calls on our backend, and there are no others: /api/install/register (§2.5), /api/diagnose and /api/observe. The list is enforced by a test in the source repository, so a new call cannot ship without appearing here.
Legal basis (GDPR Art. 6(1)(b)): processing necessary to perform the service you requested (a weather forecast, a disease diagnosis, a check-in reading).
| Channel | Status | What it means |
|---|---|---|
| Google Drive cloud backup | Blocked by the App | Android's automatic backup would copy app data to Google's servers. Sementeira forbids it for every file, on every Android version. Your garden is never uploaded to Google. |
| Phone-to-phone transfer (Smart Switch, "Copy apps & data") | Allowed | During new-phone setup, Android copies your Sementeira data straight from the old device to the new one. No server is involved, and we never see it. |
| Android → iPhone transfer | Blocked by the App | Not yet verified as a safe restore, so we refuse it rather than restore your garden half-complete. |
| Manual export (Settings → Back up my garden) | You control it | Produces a single JSON file you choose where to send. Whatever you do with that file is outside our control — treat it as you would any document containing your own data. |
We enable phone-to-phone transfer deliberately. Blocking it does not protect you from anyone: the data travels from your old phone to your new phone, both yours. Blocking it only means losing your garden when you upgrade.
Legal basis: not applicable — no processing by us occurs in any of these channels.
We do not collect or process: name, email address, account credentials, payment information, contacts, calendar, hardware or advertising identifiers (advertising ID, IMEI, MAC address, Android ID), app activity logs, web browsing, audio, or files outside the photos you explicitly take inside the App.
The one identifier that does exist is the random install token in §2.5. We generate it ourselves, it identifies an installation rather than you or your device, and it does nothing except rate-limit the photo endpoint.
The photo features cost us money on every request, so that endpoint cannot be left open to the whole internet. The first time you use one, the App asks our backend for a random install token and stores it on your device; every later photo request carries it.
Legal basis (GDPR Art. 6(1)(f)): our legitimate interest in preventing abuse of a paid API. We balanced this against a design with no identifier at all, which would leave the endpoint open to anyone.
| Permission | Why we need it | When we ask |
|---|---|---|
| Camera | Taking photos of plants for disease diagnosis and garden-walk check-ins | First time you open the Diagnosis or Garden-walk screen |
| Location (approximate) | Weather forecast, microclimate zoning map, AR sun-position calculation | First time you open the Dashboard or Zoning screen |
| Bluetooth scan / connect | Pairing with supported soil sensors | First time you open Bluetooth settings |
We never request background location and we never request access to your gallery, contacts, calendar, microphone, or files outside the App's sandbox.
You have the right to:
To exercise any of these rights write to geral@kebrabsoluta.pt. We respond within 30 days.
The App is suitable for users aged 16 and over. We do not knowingly collect data from children under 16. The minimum digital-consent age under the Portuguese GDPR transposition (Lei n.º 58/2019) is 13, but the App's marketplace feature is age-gated to 16+.
In transit: all network calls use TLS 1.2+. At rest: data on your device is protected by the OS's storage encryption (Android default since API 23). We have no access to your device, your AsyncStorage, or your photos.
The Sementeira backend is hosted in France (Scaleway, Paris region) under the EEA. Anthropic's API may process requests in the United States, which is covered by the EU–US Data Privacy Framework (Anthropic is a participant). Open-Meteo operates servers in Germany (EEA).
We may update this policy when features change. The "Last updated" date at the top reflects the current version. Material changes will be announced inside the App on next launch.
Kebrabsoluta Unipessoal Lda
Rua Ramiro de Oliveira Lt 21 3 Dto, 3150-195 Condeixa-a-Nova, Coimbra, PT
NIPC: 519191218
Email: geral@kebrabsoluta.pt
This policy is published at https://kebrabsoluta.pt/docs/sementeira/privacy.html and bundled with each release.