potted_plantAdopt a Plant
Browse
Sign in
Adopt a Plant
Share cuttings and plants, free of charge.
loginSign in
local_florist
Browse
add_circle
Share
forum
Chats
person
Me
settings
Settings
potted_plant
Species
info
About
lock
Privacy

login
Sign in
Share cuttings and plants, free of charge.

Privacy

What Adopt a Plant knows about you, where it is kept, and how to get it back or get it removed.

Last updated Aug 25, 2026

The short version

Adopt a Plant is run by one person, not by a company with a data department. There is no analytics, no advertising, no crash reporting and no tracking code of any kind in this app. Nothing about you is sold or handed to anyone for marketing, because there is nobody here to sell it to.

An email address so you can sign in is the only thing we ask you for. A display name so people know who they are talking to is written for you out of that address, and yours to change. A location, so plants can find someone nearby, is optional. Your exact location is never published. A postal address is seen only by the one person who is sending you a plant.

The rest of this page is the detail: what is stored, where it sits, who else ever touches it, and what you can ask us to do with it.

Who is responsible

Adopt a Plant is operated by dev24, Pepermuntstraat 12, Utrecht, the Netherlands. Under the GDPR that makes dev24 the controller of the personal data described here.

For anything on this page, write to hello@adoptaplant.eu. A real person reads it.

What we store about you

Your email address. It is how you sign in and how we tell you about requests, messages and shipments. We never store a password, because there is no password: you get a one-time sign-in link by email instead, and even that is kept only as a hash.

Your profile: a display name, and if you want them a short bio and an avatar photo. Other members see these. Nobody is asked to invent a name at sign-up, so the first one is made out of the part of your email address in front of the at sign, which means an address beginning "jane.doe" starts life as the name "jane doe". Change it in your settings whenever you like. Nothing else about your account is derived from your address.

Your location, twice over. The exact point you set is kept privately and is never shown to anyone else. From it we derive a second point, moved by up to a kilometre, and that moved point is the only one that reaches the map, the API or a search engine.

Your listings: title, description, species, quantity, form, handover options, shipping notes, what you would like in return, and the photos you upload. A listing also carries a view counter, which is a number and nothing more; it does not record who looked.

Chat messages between you and another member, including photos you attach to them.

Adoption records: who gave what to whom, when it was requested, accepted, sent, collected or completed, any tracking number entered, and the reviews and ratings the two of you leave afterwards.

A shipping address, but only for adoptions that go by post, only after the giver has accepted, and readable only by the two of you: name, street, postal code, city, region, country and an optional phone number. Pickup adoptions store no address at all, and no meeting place or time either. That part stays in your chat.

Favourites you save, and reports you send us about a listing or a member.

The technical residue of running a website: one record per signed-in session (a hash of the session token, the browser or app it was created from, and timestamps), the IP address attached to a request for a sign-in link, and ordinary web server access logs. If you use the iOS or Android app and allow notifications, a push token for that device as well.

What we do not do

No analytics, no advertising, no crash or performance reporting, no tracking pixels, no third-party cookies, no fingerprinting, no profiling, no automated decisions about you.

The website sets three cookies, and every one of them is doing a job you asked for. aap_session keeps you signed in, and can be read only by the server, never by scripts on the page. aap_locale remembers whether you read English or Dutch. aap_browse_country remembers which country you were browsing, so a visitor without an account does not have to pick one again on every visit. None of the three follows you anywhere else, which is why there is no cookie banner to click away. The mobile app keeps its session token in the app’s own storage on your device instead.

We hold no passwords, no payment details and no identity documents, because the app never asks you for any of them.

How your location is protected

When you set a location we store your exact point and immediately work out a blurred one. The offset is random within a circle of up to one kilometre, and it is derived from your account id, or from the listing id for a listing, so it comes out the same every time. That last part matters: a marker that jumped to a new spot on every page load could be averaged back down to your doorstep. Yours stays where it landed.

Search, distance sorting and everything drawn on the map use the blurred point. Your exact point stays on the server, where it is used to keep your own pin where you put it and to derive the blurred one.

Location is optional. You can leave it empty, set it by hand at the corner of your street rather than at your door, or clear it later in your settings.

There is also a "use my location" button, in the location picker and on the browse map, and it is the only thing in the app that reads the position sensor on your device. Your browser or phone asks your permission before it answers. Never press it and the app never asks your device where you are. Press it and the reading is used for three things: to look up the name of the place you are in, to centre the map, and to sort listings by how far away they are. That last one puts the coordinates in the address of the page, so they do reach our server and land in its access log. They are not written to your account: what gets saved as your location is the place you confirm afterwards, and it is blurred like any other.

Photos are resized and re-encoded on your own device before they are uploaded, which drops what the camera wrote into the file, including any GPS tag. The picture arrives here without it. On a phone, the app asks for the camera or your photo library only at the moment you add a photo, and it receives only the picture you picked.

Where your data lives

Everything that holds your data runs on a single small computer at the maintainer's home in the Netherlands: the database, the API, the website and every uploaded photo. In front of it sits a rented virtual machine in Amsterdam whose only job is to terminate the HTTPS connection from your browser and forward it, over an encrypted private link, to that computer. No content delivery network, no third-party proxy, and nobody outside the project decrypts your traffic on the way. The trade-off is worth stating plainly: your data is not spread across a cloud provider's datacentres, but it does sit on hardware in a home rather than in a facility with guards and generators.

That is a deliberate choice and it cost us the easy option. The first plan was to put Cloudflare in front of the site: free, and set up in an afternoon. It was dropped once the data flow was written down, because a tunnel or a CDN decrypts traffic on its way through, which would have given a company outside the EU the readable text of everyone’s chat messages, email addresses and postal addresses. Nobody in the middle can read your traffic here, because there is nobody in the middle.

A backup of the database is made every night onto the same machine, and copies older than fourteen days are deleted.

The few outside services

Email. Our transactional email provider, Brevo, based in France, delivers sign-in links and notification emails. It sees your email address and the contents of those emails, which can include a listing title, the other person’s display name, the message someone sent with a request, or a tracking number. Postal addresses are never put in an email.

Map tiles. The map is drawn with tiles from OpenFreeMap, built from OpenStreetMap data. Your browser or app fetches those tiles directly, so OpenFreeMap sees your IP address and roughly which area you are looking at. Never open the map and it is never contacted. Species reference photos come from Wikimedia Commons, but we serve our own copies, so Wikimedia sees nothing while you browse.

Place search. When you type a place name to set your location, those words go to Photon, an open geocoder run by Komoot in Germany, to be turned into coordinates. It runs the other way too: press "use my location" and it is the coordinates your device reported that go to Photon, to get a place name back. Either direction, our server asks on your behalf, so your IP address does not travel with the question, and the answer is cached for thirty days.

Parcel tracking. When a giver enters a tracking number, the app can ask a parcel tracking service, 17TRACK, for the status of that parcel. Only the tracking number and the carrier go out. Your name and address stay here.

Push notifications. If you use the mobile app and allow notifications, they travel to your device through Apple’s and Google’s push services, as notifications do for every app on your phone.

Oracle. Oracle rents us the small machine in Amsterdam that answers your browser and passes the request on. They run the hardware under it; the software and the TLS certificate are ours. Your data is not stored there, and nothing is handed to Oracle to process on our behalf.

That is the whole list. If it ever grows, this page changes first.

Why we are allowed to store it

Most of it because you asked us to run the service for you. An account, a listing, a chat, a request and an adoption cannot work without the data behind them, and under the GDPR that is a contract, article 6(1)(b).

Your location and your push notifications rest on consent, article 6(1)(a). Both are optional, and you can withdraw either whenever you like by clearing your location or turning notifications off.

Keeping abuse out rests on legitimate interest, article 6(1)(f): rate limits, the IP address stored alongside a sign-in request, and the reports and moderation records that let us act when someone behaves badly.

How long we keep it

Sign-in links expire after fifteen minutes, and a scheduled job deletes them a day after they expire or are used.

Sessions last thirty days, counted from the last time you used the app rather than from when you signed in, so something you keep opening does not log you out. Signing out deletes that session straight away.

Listings come off the market sixty days after they are published. The listing itself stays so you can put it back up, and nobody sees it in the meantime.

Cached place-name lookups are deleted after thirty days. Nightly database backups are kept for fourteen.

Chat messages, adoption records and reviews stay for as long as your account does. They are the record of something that happened between two people, so nothing removes them on a timer.

Your rights

You can ask for a copy of your data, have it corrected, have it deleted, have its use restricted, receive it in a portable file, or object to us processing it. Write to hello@adoptaplant.eu and we will answer within thirty days.

Some of it you can do yourself right now: change or clear your name, bio, avatar and location in your settings, delete a listing, sign out of a session.

There is no delete-my-account button in the app yet. Until there is, email us and we will do it by hand. We would rather write that down than pretend a button exists.

If you think we have handled your data badly, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority in the EU country where you live.

The awkward part: records that belong to two people

A completed adoption belongs to two people. So does the conversation around it, and so does a review. If you ask us to erase your account, we cannot erase the other person’s record of something that happened between you, any more than they could erase yours.

What we do instead: your profile, listings, photos, favourites and location go, and your name comes off the adoptions and reviews that remain, so what is left is the bare fact that an exchange took place and the other person’s own account of it. Messages you sent stay in their conversation, shown under a removed account rather than your name.

If that is not good enough for you, say so when you write. We will tell you exactly what would remain in your case before we touch anything.

Changes

If this policy changes in a way that matters, we will say so in the app before the change takes effect. The date at the top is the last time it changed.

descriptionTermsinfoAbout
SpeciesAboutPhoto creditsPrivacyTerms

Share cuttings and plants, free of charge.

local_florist
Browse
add_circle
Share
forum
Chats
account_circle
Me
chevron_leftchevron_right