eQuill Labs · the small print

Privacy Policy

Your garden is your business. This page sets out, in full, what we hold about you, why we hold it, who else ever sees it, and how to take it back.

Last updated July 22, 2026

Jump to a section
  1. 1Who we are
  2. 2What we collect
  3. 3Why we use it
  4. 4Cookies and local storage
  5. 5Who else sees it
  6. 6Sharing you choose
  7. 7Where it lives
  8. 8How long we keep it
  9. 9Your rights
  10. 10How we look after it
  11. 11Children's privacy
  12. 12Changes to this policy
  13. 13How to reach us

In short

  • We run no analytics, no advertising and no tracking of any kind — on any page.
  • We never sell, rent or trade your data, and we never train AI models on your gardens.
  • We never see your card number. Stripe handles payment end to end.
  • Your plans, journal and account are yours: export the lot at any time, and delete the lot at any time.
  • The whole third-party list is four companies, named below, and nobody else.

1. Who we are

The Cottage Garden Companion is a garden planning service operated by eQuill Labs ("we", "us"). This policy covers cottagegardencompanion.com and everything you do while signed in to it. It is written to be read, not to be survived — if a sentence here is unclear, ask us and we will fix the sentence.

For the purposes of the UK and EU General Data Protection Regulation, eQuill Labs is the data controller for the information described below. Under California law we are a "business", not a data broker.

2. What we collect

What you give us

  • Your account. The name you sign up with, your email address, and your password. Passwords are stored only as a salted one-way hash — we cannot read yours, and neither can anyone who takes a copy of the database.
  • Your gardens. The garden's name, the place label and approximate latitude and longitude of the weather station you pick, the country, hardiness zone, frost dates, and your unit preferences. The coordinates are the station's, not a live location from your device — we never ask your browser for your location.
  • Your plans. Every bed, path, structure, plant and label you draw, and the revision history of that drawing.
  • Your journal and tasks. Whatever you write in an entry — free text, dates, tags and due dates.
  • Your varieties. The cultivars you add and any notes you attach to them.
  • Your preferences. Which notifications you have switched on and how far ahead they look.

What the service records as it runs

  • Sessions. When you sign in we store a session record containing the IP address and browser user-agent string it was created from, so that you can be shown where your account is signed in and so we can end a session that should not exist.
  • Server logs. The web server records requests — timestamp, path, status code, IP address — as every web server does. These are used for debugging and abuse prevention and are not joined to your account.
  • An email ledger. A row per notification email actually sent to you (which kind, which month or task), so a retried job cannot email you twice. It holds no message content.
  • Billing status. Whether your subscription is trialling, active or lapsed, when the current period ends, and the identifiers Stripe uses for you. Not your card.

What we deliberately do not collect

  • No analytics, product telemetry, session recording or heatmaps.
  • No advertising pixels, conversion tags or third-party marketing scripts.
  • No device fingerprinting, and no cross-site tracking.
  • No card numbers, expiry dates or security codes — those go straight to Stripe.
  • No contact list, calendar, photo library or precise device location.

3. Why we use it

WhatWhat it is forLawful basis (UK/EU GDPR)
Account and passwordLetting you in, and keeping everyone else outPerformance of our contract with you
Gardens, plans, journal, varietiesBeing the service — storing, drawing and calculating what you asked forPerformance of our contract with you
Email addressVerification, password resets, and account notices we must sendPerformance of our contract; legal obligation
Digests, reminders and product newsOnly the channels you switched on, all off by defaultYour consent, withdrawable at any time
Sessions and server logsSecurity, abuse prevention and debuggingOur legitimate interest in a service that stays up and stays yours
Billing statusKnowing whether an account may edit, and keeping tax recordsPerformance of our contract; legal obligation

We do not use your data for automated decision-making that produces legal effects, and we do not profile you. We do not use anything you write or draw to train machine-learning models, ours or anyone else's. If that ever changes it will be an opt-in you are asked for, not a line quietly added to this page.

4. Cookies and local storage

The app sets no advertising or analytics cookies, which is why you have never seen a consent banner here. What it does set:

  • A session cookie, written when you sign in and cleared when you sign out. It is signed, so it cannot be forged, and it is what keeps you signed in between pages. Strictly necessary — block it and you cannot sign in.
  • Short-lived security cookies used by the sign-in flow to tie a request back to the browser that started it.
  • An administrator session cookie, set only for us, only on the staff console.

Your light or dark theme choice is kept in your browser's local storage under gp-theme. That is not a cookie and is never sent to our server; clearing your browser data forgets it.

5. Who else sees it

We do not sell, rent, trade or share your personal information for money or for anyone's advertising — not in the ordinary sense, and not in the broader statutory senses California's CPRA gives to "sell" and "share". We have never done so and have no plans to.

These are the only companies that process any of it on our behalf:

WhoWhat they doWhat reaches themWhere
Stripe, Inc.Payments and subscription billingYour name, email address, billing address and card details — collected by Stripe directly, never through our servers. We store only the customer and subscription identifiers Stripe gives back, plus whether the subscription is active.United States
Amazon Web Services, Inc. (Amazon SES)Delivery of transactional and notification emailYour email address and name, and the contents of the messages we send you — sign-in verification, password resets, and any digests or reminders you have switched on.United States
DigitalOcean, LLCServer and database hostingEverything you store in the app, because the application and its database run on a server we rent from them. DigitalOcean does not access it in the ordinary course.United States
Google LLC (Google Fonts)Serving the two typefaces the pages are set inYour browser fetches the fonts from Google directly, which discloses your IP address, user agent and the page you are on to Google. No account data passes through this request.United States

Beyond that list, we will disclose personal information only where:

  • The law compels us. A valid subpoena, warrant or court order. We will tell you it happened unless we are legally forbidden from doing so.
  • Safety requires it — to investigate fraud or a threat to someone's physical safety.
  • The service changes hands. If eQuill Labs is ever sold or merged, your data may transfer with it. You will be told before that happens, and this policy binds whoever takes over until they publish their own and give you a chance to leave.

Within eQuill Labs, access is limited to the people who run the service, through a staff console that requires its own separate credentials and writes an audit record of every administrative action taken.

6. Sharing you choose

  • Share links. Publishing a plan mints an unlisted link. Anyone holding that link can view that one plan read-only without signing in, and search engines may index it if you post it publicly. It shows the plan, the garden's name and its frost dates — never your email, your journal or your other gardens. Revoking the link kills it immediately.
  • Exports and printing. A backup file or a printed sheet leaves our hands entirely. What happens to it afterwards is up to you.

7. Where it lives

The application and its database run on a single rented server in the United States, as do all four companies listed above. If you are in the United Kingdom, the European Economic Area or Switzerland, using the service means your information is transferred to and stored in the US, which your regulator does not treat as offering equivalent protection by default. That transfer is necessary to perform the contract you asked us to perform; where a transfer is instead made on our behalf by a processor, that processor's own Standard Contractual Clauses apply. You are entitled to ask us for details, and entitled to decide the trade is not worth it and close your account.

8. How long we keep it

  • While your account is open, we keep what you put in it. A lapsed subscription changes nothing: your gardens stay readable, printable and exportable, and we do not delete them to pressure you into paying.
  • When you close your account — from the account page, confirmed by a link emailed to you — your user record and everything hanging off it is deleted immediately: gardens, plans, journal entries, varieties, preferences, notifications, sessions and the email ledger. This is a real deletion, not a flag.
  • Backups. Nightly database archives are kept for 14 days and then destroyed, so a copy of deleted data can survive in a backup for up to 14 days. We do not restore a backup to resurrect a closed account.
  • Payment records. Stripe keeps its own record of transactions for as long as tax and anti-fraud law requires it to, independently of us. Closing your account here does not erase Stripe's books, and cannot.
  • Server logs roll over on a short cycle and are not archived.

9. Your rights

Wherever you live, you can:

  • Get a copy. Account → Your data exports every garden, plan, journal entry and variety as one JSON file, at any time, with no request to us at all.
  • Correct it. Your name, email and password change from Account.
  • Delete it. Account → close your account, as described above.
  • Take it elsewhere. That export is machine-readable and yours to import anywhere.
  • Withdraw consent for any optional email from Account → Notifications, without affecting anything else.

If the UK or EU GDPR applies to you, you additionally have the rights to restrict or object to processing, to have inaccurate data rectified, and to lodge a complaint with your supervisory authority (in the UK, the Information Commissioner's Office). We would much rather you gave us a chance to put it right first.

If you are a California resident, you have the rights to know what we collect and why, to obtain a copy, to correct it, to delete it, to opt out of sale or sharing (there is nothing to opt out of — we do neither), and to limit the use of sensitive personal information (we collect none). We will never discriminate against you for exercising any of them.

To exercise anything the app cannot do for you, write to equilllabs+cottage-garden-companion@gmail.com. We answer within 30 days, and will ask you to write from the address on the account so that we are not handing your garden to a stranger. An authorised agent may act for you with written proof.

10. How we look after it

  • Everything travels over HTTPS; the site refuses plain HTTP.
  • Passwords are salted and hashed with a deliberately slow algorithm — never stored readable.
  • Session cookies are signed with a secret held only on the server.
  • The database is not exposed to the internet: it is reachable only by the application process on the same machine.
  • The staff console sits behind separate credentials from any user account and records an audit trail of what was done and by whom.
  • Backups are taken nightly and pruned on the schedule described above.

No service can promise perfect security, and we will not pretend otherwise. If we ever discover a breach affecting your personal data, we will tell affected gardeners by email — and any regulator we must notify — without undue delay, along with what we know and what we are doing about it. If you think you have found a vulnerability, please write to equilllabs+cottage-garden-companion@gmail.com before disclosing it publicly; we will not pursue anyone who reports a genuine problem in good faith.

11. Children's privacy

The service is not directed at children under 13, and we do not knowingly collect personal information from them. In the EEA and the UK, where the digital age of consent is 16 (or lower where a member state has set it so), anyone below it needs a parent or guardian to hold the account. If you believe a child has signed up, write to us and we will delete the account.

12. Changes to this policy

We will update this page when the service changes — a new sub-processor, a new kind of data, a new feature that shares something. The "last updated" date at the top always reflects the last real change. If a change materially reduces your privacy, we will tell you by email or an in-app notice before it takes effect, so that you can export and leave if you disagree.

13. How to reach us

eQuill Labs, operator of The Cottage Garden Companion — equilllabs+cottage-garden-companion@gmail.com. A person reads it, and a postal address for formal notices is available on request.

See also the Terms of Service, which govern your account itself.