Privacy Policy
1. Data Protection at a Glance
General Information
The following information provides a simple overview of what happens to your personal
data when you visit our website or use our app. Personal data is any data with which you can be
personally identified.
2. Responsible Party
Data processing on this website is carried out by the website operator. You can find their contact details in the imprint of this website.
3. Data Collection on our Website
Server Log Files
The provider of the pages automatically collects and stores information in so-called
server log files, which your browser automatically transmits to us. These are: browser type/browser
version, operating system used, referrer URL, hostname of the accessing computer,
time of server request, IP address.
This data is not merged with other data sources. The basis for
data processing is Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in the secure and
stable operation of the website).
SSL or TLS Encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of
confidential content, such as orders or inquiries that you send to us as the site operator. You can
recognize an encrypted connection by the browser's address line changing from “http://“
to “https://“ and by the padlock symbol in your browser line.
Optional Website Analytics with PostHog EU
PostHog is loaded on this website only after you expressly choose “Allow analytics” in
the consent dialog. We then process page views, time on page, referrer, browser and device
information, and a pseudonymous visitor identifier to understand website use and technical issues.
The legal basis is your consent under Art. 6(1)(a) GDPR. Your choice is stored locally in your
browser. If you choose “Necessary only”, PostHog is not loaded. You can reopen and
withdraw your choice at any time; locally stored PostHog identifiers are removed on withdrawal.
We do not use the Meta Pixel on this website.
Optional TikTok Account Connection and Content Posting
If you choose to connect TikTok through the LawnCoach sharing page, we process the opaque TikTok
account identifier, display name, authorized scopes, and OAuth access and refresh tokens provided
by TikTok. The tokens are encrypted server-side before they are stored in our Redis data store. A
browser-bound connection record is retained for no longer than 30 days, or less if TikTok's refresh
authorization expires or you disconnect sooner.
LawnCoach offers two user-initiated transfer modes. For Upload as a draft, your browser
sends the selected video directly to TikTok and you must review and finish it in TikTok. For
Direct Post, you preview the video, choose the caption, audience, interaction options,
commercial-content disclosures and AI-generated-content setting, and then give express final
authorization. To support TikTok's PULL_FROM_URL transfer, the browser may upload the selected
video to private Vercel Blob storage using a short-lived, file-specific upload address. TikTok then
retrieves that video from a signed, expiring lawncoach.net address without a redirect. The private
copy is deleted when TikTok reports completion or failure and, in any event, is scheduled for
deletion after no more than 24 hours. It is not made generally accessible or listed publicly.
We process the file name, file size, media type, video duration, selected posting settings,
disclosures, TikTok publish identifier, transfer source, and processing status needed to carry out
and track your request. We do not initiate a transfer or post without the final action on the
sharing page. TikTok may process, moderate, restrict, or reject the content under its own rules.
The legal basis is your consent (Art. 6(1)(a) GDPR) and, where applicable, performance of the
service you requested (Art. 6(1)(b) GDPR). Vercel acts as our hosting/storage processor and TikTok
receives the account authorization and video for posting; processing by these providers may occur
outside the EEA subject to the safeguards described in their privacy notices.
Disconnecting removes the local connection record and requests token revocation from TikTok.
TikTok-side revocation is best effort if TikTok is temporarily unavailable, while the local
connection is still removed. An already submitted draft or post remains subject to your TikTok
account controls and TikTok's retention rules.
4. App Usage & Permissions
Location Data (GPS)
To create tailor-made care plans for you, we use your location data (GPS). This data is processed
exclusively locally on your device or sent anonymously to our weather service provider
(Open-Meteo API) to retrieve local weather data. No permanent storage
of movement profiles takes place on our servers. The legal basis for this is your
consent (Art. 6 Abs. 1 a DSGVO), which we request before the first use.
Camera & Photos
The app requests access to the camera so that you can photograph your lawn and have it analyzed by AI
image analysis. Photos you submit for analysis are forwarded via our server (hosted at Vercel Inc.,
USA) to Google Gemini AI for image recognition. Our proxy does not persist the request content.
Google processes the photo, accompanying context, and response; under the current Gemini API
policy, inputs and outputs may be retained for up to 55 days solely to detect and prevent abuse.
Camera access is optional and is only activated upon your explicit request.
Media Library
The app can access your photo media library to save or share results (e.g., lawn status maps)
as an image on your device. This access only occurs upon your explicit request, and the images do
not leave your device unless you share them yourself.
Push Notifications
The app can send you push notifications to remind you of care tasks.
For this purpose, a device token is generated and transmitted to Apple's Push Notification Service
(APNs) or Google Firebase Cloud Messaging (FCM). Only the push token required for delivery is
transmitted to these services. For personalized irrigation reminders, our server (hosted by Vercel
Inc., USA) also processes the app installation ID, optional account ID, language, time zone,
location coordinate, lawn profile, weather data, and watering history logged through quick actions.
This data is used only to calculate and deliver lawn care and irrigation notifications, not for
tracking. You can deactivate push notifications at any time in the device settings; when you delete
your account in the app, the push registration for this app installation is disabled server-side.
AI-powered Lawn Coach (Google Gemini)
The app uses Google Gemini AI to provide you with personalized lawn care advice. When you use the
chat function, your messages, along with context data (weather, care plan, garden profile), are
forwarded via our server (hosted at Vercel Inc., USA) to Google for processing. Our proxy does not
persist the request content, and your chat history is stored only on your device. Google processes
your message, the stated context, and the response; under the current Gemini API policy, these
inputs and outputs may be retained for up to 55 days solely to detect and prevent abuse. Google's
privacy policy applies to this processing:
https://policies.google.com/privacy.
Analytics and Product Interaction
Only after you expressly consent in the app does LawnCoach send pseudonymous product interaction
events to PostHog EU and request Apple Ads attribution. These events can include app launches,
screen views, button taps, onboarding, photo-analysis, plan and progress events, purchase and
subscription-status events, the StoreKit product price and currency, session duration, technical
operation durations, normalized error categories and retryability, app version,
app build, platform, language, country or region, and pseudonymous Apple Ads organization,
campaign, ad-group, keyword and ad IDs, attribution and conversion type, country or region, and
ad placement. A persistent installation identifier and, after sign-in, a locally hashed account
analytics identifier connect events over time. Lawn photos, chat content, precise coordinates,
email addresses, and raw Apple or Google account or transaction identifiers are not sent to
PostHog. You can revoke usage analytics at any time in Settings; local queued events are then
deleted and future server-side subscription analytics are disabled. These analytics are used for
product analysis and app improvement, not third-party advertising or cross-provider tracking.
PostHog does not receive the IDFA. This consent is separate from the optional Meta advertising
measurement described below.
Optional Measurement of Meta App Advertising (prepared, not active)
We have prepared a direct server-side transfer of selected app events to Meta Platforms Ireland
Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, for the future measurement and optimization of our app ads
on Facebook and Instagram. This feature is currently disabled technically. While it remains
disabled, LawnCoach does not transmit any of these app events to Meta.
A transfer may begin only if you separately and voluntarily consent to advertising measurement in
the app and then choose “Allow Tracking” in Apple's system dialog (App
Tracking Transparency, ATT). ATT permission does not replace the in-app consent. Refusal does not
affect any app feature. Independently, Apple may provide aggregated, privacy-preserving attribution
information through its attribution technologies.
The prepared integration is limited to these categories: the IDFA advertising identifier, a random
event ID, the event time, and selected funnel or subscription steps such as first open or activation,
completed onboarding, an opened paywall, initiated purchase, started trial, started subscription,
completed purchase and — only after separately verified server-side confirmation — a
subscription renewal. A transfer also includes the bundle ID com.rasencoach.app, app
version, build number, and iOS version. Our server additionally processes a pseudonymous installation
ID to manage consent, withdrawal, the delivery queue, and deduplication; that installation ID is not
included in the prepared request to Meta.
Before you make a choice, the app may, if the integration is enabled in production, buffer up to 100
of these allowed events solely on your device for no longer than seven days. Such a local record
contains only the canonical event name, random event ID, and event time — no IDFA. Only if you
later consent in the app and Apple allows tracking may these buffered events be linked to the IDFA
then available and the app and system details listed above, and sent to Meta through our server. If
you refuse, the local records are deleted and not transmitted. We do not transmit
lawn photos, chat content, free text or other user content, location data (precise or approximate),
email addresses, raw Apple account, app-account or transaction identifiers, or the price, value, or
revenue of a purchase or subscription.
To protect against forged, manipulated, or replayed measurement requests, our server additionally
processes a pseudonymous installation identifier, Apple App Attest technical evidence including a
public key and attestation receipt, a usage counter, app distribution status, build number, and
timestamps. A random 32-byte recovery token remains in the iOS Keychain; our server stores only its
non-reversible SHA-256 hash. It is used solely to bind the same pseudonymous installation safely to
a newly attested Apple key if the prior App Attest key is lost. A separate device-only Keychain
record retains the last completed change of the pseudonymous installation identifier, so a backup
restored on a second device receives a new identifier before measurement or purchase. This record
remains local and is sent neither to our server nor to Meta. Vercel technically processes the IP
address at the server edge; our application code
stores it only as a non-reversible keyed hash for abuse prevention and rate limiting. App Attest
credentials and the pseudonymous installation linkage, including the recovery-token hash, are
retained on a rolling basis for no longer than 400 days, challenges for no longer than five minutes,
and rate-limit values for no longer than
24 hours. A contracted Redis service may process these technical security, consent, and queue data.
The App Attest receipt, public key, IP hash, and installation identifier are not sent to Meta. They
are used solely for system security, fraud/abuse prevention, consent management, and replay
protection. The classification and legal basis of this security processing will receive final legal
review before activation.
The legal basis for the transfer initiated by us is your consent under Art. 6(1)(a) GDPR. Under its
own responsibility, Meta may use the events for attribution, advertising measurement and optimization
and may match them with information from Meta services. Processing may involve Meta Platforms, Inc.
and other Meta companies outside the EEA. Meta describes, among other safeguards, the EU-US Data
Privacy Framework and Standard Contractual Clauses. For more information, see the
Meta Privacy Policy and
Meta's Conversions API information.
On our server, the consent or withdrawal status and pseudonymous installation ID are kept for no
longer than 400 days. After consent, server-side unsent events containing an IDFA are kept for no
longer than seven days, and a technical deduplication marker without an IDFA for no longer than 31
days. Withdrawing consent removes local buffered records as well as server-side queued events and
their IDFA data, and stops future transfers. Data already sent to Meta is then
subject to Meta's retention and deletion rules. You can withdraw consent at any time in the app
settings.
Activation remains blocked until this information is published in production, the privacy details
in App Store Connect are updated, and the consent and ATT flow has been verified in the production
app version.
App Store Purchases, Subscriptions & Pro Access
Purchases and subscriptions are processed by the Apple App Store. We do not receive payment
details such as credit card numbers or bank details. To unlock and restore LawnCoach Pro, the app
processes StoreKit information such as product identifier, subscription status, expiration or
renewal date, transaction status, and Apple-signed transaction data. This information is used to
unlock Pro features, restore purchases, prevent misuse, and synchronize the current subscription
status. Apple may send signed App Store Server Notifications V2 to our entitlement server for trial
conversion, renewal, cancellation, billing retry, grace period, expiration, refund, or revocation.
Pseudonymous lifecycle events are sent to PostHog only when analytics consent has been granted.
Optional Account and Entitlement Sync
If you sign in with Apple or Google, LawnCoach may store a pseudonymous account mapping so your
Pro status can be recognized across devices and platforms. For this purpose, provider, provider
user ID, app account token, subscription or entitlement status, product tier, expiration date, and
where applicable Apple-signed transaction evidence may be sent to and stored by our entitlement
server. This processing is used to perform the subscription contract and provide Pro features.
After successful account deletion, deletion of the associated pseudonymous PostHog person, events,
and recordings is also queued.
Local Storage
Your care history and settings are stored locally on your device. An account is not required to use
the basic app features. For Pro features, purchase restoration, and cross-device access, the
subscription and entitlement data described above may be processed.
5. Your Rights as a Data Subject
You generally have the rights to information, rectification, erasure, restriction of processing, data portability, revocation, and objection. If you believe that the processing of your data violates data protection law or that your data protection rights have otherwise been violated, you can complain to the supervisory authority. In Austria, this is the Data Protection Authority (Barichgasse 40-42, 1030 Wien, dsb.gv.at).
6. Contact
For questions regarding data protection, please contact:
support@lawncoach.net
Last updated: 27 July 2026