Adopt a Plant1.14.0
Browse
Sign in
Adopt a Plant
Share cuttings and plants, free of charge.
loginSign in
local_florist
Browse
add_circle
Share
forum
Chats
person
Me
settings
Settings
potted_plant
Species
info
About
lock
Privacy
description
Terms

login
Sign in
Share cuttings and plants, free of charge.

Privacy

What Adopt a Plant knows about you, where it is kept, and how to get it back or get it removed.

Last updated Sep 21, 2026

The short version

Adopt a Plant is run by one person, not by a company with a data department. There is no analytics, no advertising, no crash reporting and no tracking code of any kind in this app. Nothing about you is sold or handed to anyone for marketing, because there is nobody here to sell it to.

An email address so you can sign in is the only thing we ask you for. A display name so people know who they are talking to is written for you out of that address, and yours to change. A location, so plants can find someone nearby, is optional. Your exact location is never published. A postal address is seen only by the one person who is sending you a plant.

The rest of this page is the detail: what is stored, where it sits, who else ever touches it, and what you can ask us to do with it.

Who is responsible

Adopt a Plant is operated by dev24, Pepermuntstraat 12, Utrecht, the Netherlands. Under the GDPR that makes dev24 the controller of the personal data described here.

For anything on this page, write to hello@adoptaplant.eu. A real person reads it.

What we store about you

Your email address. It is how you sign in and how we tell you about requests, messages and shipments. We never store a password, because there is no password: one email brings you a one-time sign-in link and a six-digit code, and both are kept only as a hash, next to a count of the wrong tries at the code. Beside the address as you typed it we keep an identity form of it, lower-cased and trimmed, and for a gmail address also stripped of dots and of anything after a plus sign, because those spellings all reach one mailbox and were quietly becoming separate accounts.

Your profile: a display name, and if you want them a short bio and an avatar photo. Other members see those, and with them the locality you set, the rating and the number of reviews other members left you, how many plants you have rehomed, counted one per adoption that the person who received the plant confirmed, the day you joined and when you were last seen. Nobody is asked to invent a name at sign-up, so the first one is made out of the part of your email address in front of the at sign, which means an address beginning "jane.doe" starts life as the name "jane doe". Change it in your settings whenever you like. The address itself is never shown to another member, only to an admin.

Your location, twice over, plus the name of the place. The exact point you set is kept privately and is never shown to anyone else. From it we derive a second point, moved by up to a kilometre, and that moved point is the only point that reaches the map, the API or a search engine. The locality that goes with it, your town or neighbourhood, is stored as plain text, and that text is shown on your profile and on your listings.

Your listings: title, description, species, quantity, form, handover options, shipping notes, what you would like in return, and the photos you upload.

A listing also carries a view counter. It counts page views of that listing and nothing more. It is not a measure of interest and not a number of people waiting for the plant: the same visitor who comes back tomorrow adds another one, and a view says nothing about whether anybody wanted what they looked at. Some visits are never counted at all. Your own visits to your own listing are not, as long as you are signed in; signed out, in a private window or on a device you never signed in on, there is nothing to recognise you by and the visit counts like any other. Neither are the ones we make ourselves: the admin account, the accounts that exist so that Apple can review the app, the crawlers and link previews that fetch a page for a search engine or a chat app, and the automatic check that opens a listing after every deploy.

What that counting costs you in privacy: nothing about a visit is written to the database, and the counter keeps no address. To tell one visitor from another for a single day, the running program holds a hash in its own memory, worked out from a random number that is thrown away and made again every midnight, together with your account id or, when you are not signed in, your network address. Neither of those can be recovered from the hash, none of it is written to disk, and a restart of the server loses that day’s hashes. So a visitor counts about once a day on a listing rather than exactly once. The ordinary web server logs further down this list are a separate thing, and are not where the counter looks.

Chat messages between you and another member, including photos you attach to them.

Adoption records: who gave what to whom, when it was requested, accepted, sent, collected or completed, any tracking number entered, and the reviews and ratings the two of you leave afterwards.

A shipping address, but only for adoptions that go by post, only after the giver has accepted, and readable only by the two of you: name, street, postal code, city, region, country and an optional phone number. Pickup adoptions store no address at all, and no meeting place or time either. That part stays in your chat.

Favourites you save, and reports you send us about a listing, a message or a member. A report records what you reported and why. When the report is about a message, an admin dealing with it sees the beginning of that message.

Moderation records. Every decision a moderator takes is written down as it happens: who took it, what it was, which account, listing or report it was about, when, and the reason the moderator typed. That reason is one person writing about another, so it can name you and describe what you did. It is never shown to another member.

What an admin sees. To keep the place safe, an admin can look through every account. For each one that shows the display name, the email address, the country, the day it joined, how many listings it has, how many reports about it are open or were acted on, and whether it is banned or deleted. It does not show your exact location, a shipping address or your conversations with other members. If an admin needs to reach you, they write to you in the app’s own chat, from an account marked Adopt a Plant team, and you can answer, report or block it there like any other conversation.

People you block. Blocking stores who blocked whom and when, so the two of you stop seeing each other and can no longer write to each other. Your own list is in your settings, and you can undo an entry there.

The notifications the app shows you: what happened, which member it came from, and for a new message a short preview of it. They are stored so the list is still there when you come back.

The technical residue of running a website: one record per signed-in session (a hash of the session token, the browser or app it was created from, and timestamps), the IP address attached to a request for a sign-in link, and ordinary web server access logs. If you use the iOS app and allow notifications, a push token for that device as well.

What we do not do

No analytics, no advertising, no crash or performance reporting, no tracking pixels, no third-party cookies, no fingerprinting, no profiling, no automated decisions about you.

The website sets four cookies, and every one of them is doing a job you asked for. aap_session keeps you signed in, and can be read only by the server, never by scripts on the page. aap_locale remembers which language you read the site in. aap_browse_country remembers which country you were browsing, so a visitor without an account does not have to pick one again on every visit. aap_scheme remembers whether this device came out light or dark, so the first page the server draws is not the wrong one. None of the four follows you anywhere else, which is why there is no cookie banner to click away. Your browser also keeps your language, your light-or-dark preference and which cards you have closed on the browse page, such as a card from the team, in its own storage on your device, and the mobile app keeps its session token in the app’s own storage there.

We hold no passwords, no payment details and no identity documents, because the app never asks you for any of them.

How your location is protected

When you set a location we store your exact point and immediately work out a blurred one. The offset is random within a circle of up to one kilometre, and it is derived from your account id, or from the listing id for a listing, so it comes out the same every time. That last part matters: a marker that jumped to a new spot on every page load could be averaged back down to your doorstep. Yours stays where it landed.

Search, distance sorting and everything drawn on the map use the blurred point. Your exact point stays on the server, where it is used to keep your own pin where you put it and to derive the blurred one.

Location is optional. You can leave it empty, set it by hand at the corner of your street rather than at your door, or clear it later in your settings.

There is also a "use my location" button, in the location picker and on the browse map, and it is the only thing in the app that reads the position sensor on your device. Your browser or phone asks your permission before it answers. Never press it and the app never asks your device where you are. Press it and the reading is used for three things: to look up the name of the place you are in, to centre the map, and to sort listings by how far away they are. That last one puts the coordinates in the address of the page, so they do reach our server and land in its access log. They are not written to your account: what gets saved as your location is the place you confirm afterwards, and it is blurred like any other.

Photos are resized and re-encoded on your own device before they are uploaded, which drops what the camera wrote into the file, including any GPS tag. The picture arrives here without it. On a phone, the app asks for the camera or your photo library only at the moment you add a photo, and it receives only the picture you picked.

Where your data lives

Everything behind the site runs on a single small computer at the maintainer's home in the Netherlands: the database, the API, the website and every uploaded photo. In front of it sits a rented virtual machine in Amsterdam whose only job is to terminate the HTTPS connection from your browser and forward it, over an encrypted private link, to that computer. No content delivery network, no third-party proxy, and nobody outside the project decrypts your traffic on the way. The trade-off is worth stating plainly: your data is not spread across a cloud provider's datacentres, but it does sit on hardware in a home rather than in a facility with guards and generators.

That is a deliberate choice and it cost us the easy option. The first plan was to put Cloudflare in front of the site: free, and set up in an afternoon. It was dropped once the data flow was written down, because a tunnel or a CDN decrypts traffic on its way through, which would have given a company outside the EU the readable text of everyone’s chat messages, email addresses and postal addresses. Nobody in the middle can read your traffic here, because there is nobody in the middle.

A backup of the database is made every night onto the same machine, and copies older than fourteen days are deleted. Once a day those backups and the uploaded photos are also copied onto a separate encrypted disk, attached to another computer in the same home. That disk keeps database backups for ninety days, and its copy of the photos follows the site: a photo removed here is set aside there for thirty days and then deleted. No copy is kept anywhere outside that home.

The few outside services

Email. Our transactional email provider, Brevo, based in France, delivers sign-in links and notification emails. It sees your email address and the contents of those emails, which can include a listing title, the other person’s display name, the message someone sent with a request, or a tracking number. If we suspend your account, the notice telling you why goes the same way, with the moderator’s reason in it. Postal addresses are never put in an email.

Map tiles. The map is drawn with tiles from OpenFreeMap, built from OpenStreetMap data. Your browser or app fetches those tiles directly, so OpenFreeMap sees your IP address and roughly which area you are looking at. Never open the map and it is never contacted. Species reference photos come from Wikimedia Commons, but we serve our own copies, so Wikimedia sees nothing while you browse.

Place search. When you type a place name to set your location, those words go to Photon, an open geocoder run by Komoot in Germany, to be turned into coordinates. It runs the other way too: press "use my location" and it is the coordinates your device reported that go to Photon, to get a place name back. Either direction, our server asks on your behalf, so your IP address does not travel with the question, and the answer is cached for thirty days.

Parcel tracking. When a giver enters a tracking number, the app can ask a parcel tracking service, 17TRACK, for the status of that parcel. Only the tracking number and the carrier go out. Your name and address stay here.

Push notifications. If you use the iOS app and allow notifications, they travel to your device through Apple’s push service, as notifications do for every app on your phone.

Oracle. Oracle rents us the small machine in Amsterdam that answers your browser and passes the request on. They run the hardware under it; the software and the TLS certificate are ours. Your data is not stored there, and nothing is handed to Oracle to process on our behalf.

That is the whole list. If it ever grows, this page changes first.

Why we are allowed to store it

Most of it because you asked us to run the service for you. An account, a listing, a chat, a request and an adoption cannot work without the data behind them, and under the GDPR that is a contract, article 6(1)(b).

Your location and your push notifications rest on consent, article 6(1)(a). Both are optional, and you can withdraw either whenever you like by clearing your location or turning notifications off.

Keeping abuse out rests on legitimate interest, article 6(1)(f): rate limits, the IP address stored alongside a sign-in request, the record of who blocked whom, and the reports and moderation records that let us act when someone behaves badly.

The moderation records rest on that same ground. A place people share has to be safe, and a decision we took about someone has to be one we can still account for afterwards. That limits what erasure can do here: deleting your account does not delete the record of a decision made about you.

How long we keep it

Sign-in links expire after fifteen minutes and the six-digit code in the same email after ten. Five wrong tries at the code kill it and the link with it. A scheduled job deletes the record a day after it expires or is used.

Sessions last thirty days, counted from the last time you used the app rather than from when you signed in, so something you keep opening does not log you out. Signing out deletes that session straight away.

Listings come off the market sixty days after they are published. The listing itself stays so you can put it back up, and nobody sees it in the meantime.

Cached place-name lookups are deleted after thirty days. Nightly database backups are kept for fourteen days on the machine that runs the site and for about ninety on the separate disk, which also keeps a removed photo for about thirty. What you delete, your account included, can survive in those copies for that long.

Chat messages, adoption records and reviews have no clock on them at all. They are the record of something that happened between two people, so they outlive the account that leaves: deleting yours takes your name off them, and what you wrote stays where the other person can still read it.

A shipping address stays on its adoption for as long as that adoption exists, which is indefinitely. Deleting your account erases the ones you shared yourself; an address someone else shared with you is theirs, and stays until they delete theirs.

Reports are kept after they have been dealt with, including reports about you. A moderation record that disappears is no record at all.

Moderation records are kept indefinitely, and deleting your account does not take them away. If the moderator who wrote one later deletes their own account, the row still points at that account but there is no name or address left on it. The decision, its date and the reason written at the time stay.

Your rights

You can ask for a copy of your data, have it corrected, have it deleted, have its use restricted, receive it in a portable file, or object to us processing it. Write to hello@adoptaplant.eu and we will answer within thirty days.

Some of it you can do yourself right now: change or clear your name, bio, avatar and location in your settings, delete a listing, sign out of a session.

Deleting the account is something you do yourself: Settings, then Delete account, then type the word it asks for. It happens immediately and cannot be undone. The one thing that stops it is an adoption still in progress, because someone on the other side is waiting on a plant or owes one; finish or cancel that first and come back. The screen lists what goes and what stays before you confirm, and the section below is the long version of that list.

If you think we have handled your data badly, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority in the EU country where you live.

The awkward part: records that belong to two people

A completed adoption belongs to two people. So does the conversation around it, and so does a review. If you ask us to erase your account, we cannot erase the other person’s record of something that happened between you, any more than they could erase yours.

What we do instead: your email address, name, bio, country and location are wiped from the account and your avatar file is deleted from the server. Your favourites, the notifications in your list, your blocked list, every session and push token and any sign-in link still outstanding are deleted outright. Any shipping address you shared as an adopter is erased. Your listings come off the site, the people queued on them are told the plant is gone, and your own open requests are withdrawn.

Your name then comes off the adoptions and reviews that remain, so what is left is the bare fact that an exchange took place and the other person’s own account of it. Messages you sent stay in their conversation, shown under a removed name rather than yours, and the photos already attached to them stay with the conversation. A listing of yours that someone adopted keeps its photo in their record of that adoption, for the same reason the conversation does, and that holds even if the adoption was later cancelled, because the record of it stays with them. Every other listing photo is deleted from the server outright: the original file and every size we rendered from it, including the photos on listings you had already deleted yourself.

If that is not good enough for you, say so when you write. We will tell you exactly what would remain in your case before we touch anything.

Changes

If this policy changes in a way that matters, we will say so in the app before the change takes effect. The date at the top is the last time it changed.

descriptionTermsinfoAbout
SpeciesAboutPhoto creditsPrivacyTerms

Share cuttings and plants, free of charge.

Created by Dev24

local_florist
Browse
add_circle
Share
forum
Chats
account_circle
Me
chevron_leftchevron_right