Naar hoofdinhoud springen
Back to homepage

Privacy Policy for the Android App "Naturkompass"

Version: June 2026. English fallback for all non-German locale routes.

This privacy policy explains which personal data may be processed when you use the Android app “Naturkompass”. The app is technically based on the Naturkompass web platform and provides the platform’s content, user features, and tools inside an Android app.

1. Controller

The controller responsible for data processing is:

Alexander Göcke

Gartenexpedition sole proprietorship

Fellackerstr. 4a

47495 Rheinberg

Germany

Email: support@gartenexpedition.de

Website: gartenexpedition.de

Naturkompass: naturkompass.gartenexpedition.de

2. Nature of the app

The Android app “Naturkompass” is technically implemented as a web app / Trusted Web Activity. The app loads content from the Naturkompass platform at https://naturkompass.gartenexpedition.de.

The app itself does not operate any separate advertising, tracking, or analytics SDK infrastructure beyond the services named in this privacy policy. Data processing largely corresponds to the use of the Naturkompass web platform, supplemented by technical processes required for delivery through Google Play and Android.

3. What data we process

a) Technical access data

When the app or the web content loaded within it is accessed, technically necessary data may be processed, in particular IP address, time of access, pages or functions called up, device and browser information, language settings, and technical error and security events.

Legal basis: Art. 6(1)(f) GDPR.

b) User account and profile data

If you create or use a user account, we process data such as your email address, username, country, postal code region using only the first two digits, garden size, garden type, and further voluntary profile information.

The full postal code is not stored. The postal region is used for regional recommendations and coarse regional evaluation.

Legal basis: Art. 6(1)(b) GDPR.

c) Garden inventory, watchlists, and personalised recommendations

If you add plants, animals, modules, or other entries to your garden, we process these data to provide Naturkompass features. This includes added plants and animals, garden modules, measures, watchlists, garden inventory, and the resulting recommendations and biodiversity or ecology scores where available.

Legal basis: Art. 6(1)(b) GDPR.

d) Course progress and quiz results

If you use academy, learning, or course areas, completed lessons, course progress, quiz results, and earned badges or similar progress indicators may be stored.

Legal basis: Art. 6(1)(b) GDPR.

e) Internal privacy-conscious usage statistics

Naturkompass processes internal usage statistics to improve stability, content, and navigation. This may include page views, dwell time, exit events, referrer information, device type, screen size, app or browser language, and technical baseline usage data.

A daily rotating SHA-256 visitor hash may be used to recognise repeat visits within the same day. There is no cross-day tracking and no personal advertising profile is created.

Legal basis: Art. 6(1)(f) GDPR.

f) AI garden assistant and chat features

If you use the AI garden assistant or similar chat features, your submitted messages are processed in real time in order to generate a response. Naturkompass does not permanently store chat messages unless an explicit storage feature is provided and actively used by you.

Depending on the feature, messages may be transmitted to an AI service provider for processing.

Legal basis: Art. 6(1)(b) GDPR.

g) Photo and upload features

If the app provides photo, observation, or upload features, processing only takes place when you actively use those features. Uploaded images are not secretly or automatically analysed beyond the relevant feature.

  • EXIF metadata, including GPS coordinates, are removed server-side where technically implemented.
  • Photos are processed only for the feature you intentionally use.
  • Photos are not displayed publicly unless the relevant feature is explicitly marked as public.
  • If an associated entry is deleted, stored image data are deleted as well unless statutory retention duties apply.

Legal basis depending on the feature: Art. 6(1)(b) GDPR or Art. 6(1)(a) GDPR.

h) Contact, feedback, and support requests

If you contact us through a contact form, a feedback feature, or by email, we process your message, your email address, and where relevant your name, username, and technical context information required to handle your request.

Legal basis: Art. 6(1)(f) GDPR.

i) Newsletter

If you sign up for a newsletter, we process your email address, the time of subscription, consent status, and where applicable proof of double opt-in. You can unsubscribe at any time.

Legal basis: Art. 6(1)(a) GDPR.

j) Shop and payment features

If you use products or paid features through Naturkompass or linked shop areas, order, contact, and payment data may be processed depending on the feature. Payment data are usually processed directly by the relevant payment provider. Naturkompass does not store full credit card data.

Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR.

4. No automatic processing of certain sensitive device data

At present, the app does not automatically process the following categories of data:

  • no background GPS location data
  • no contacts
  • no calendar data
  • no phone or SMS contents
  • no microphone recordings
  • no health data
  • no advertising ID for personalised advertising
  • no transfers to data brokers
  • no third-party advertising networks

If future Android permissions become necessary for new features, they will only be used after active user approval and this privacy policy will be updated accordingly.

5. Third-party providers and processors

We use service providers for the operation, security, and delivery of Naturkompass. These may include in particular:

  • Supabase for database, authentication, and user features.
  • Vercel for hosting, delivery, and technical operation of the web platform.
  • Cloudflare R2 for storage and delivery of media and image files where relevant.
  • Brevo for newsletters and notifications from contact forms.
  • Stripe for paid features and payments.
  • YouTube / Google only when you actively start videos or consent to their embedding.
  • AI service providers such as Anthropic or Google for AI-powered features where technically necessary.

Where providers outside the EU are used, this is done on the basis of appropriate legal safeguards, in particular the EU-U.S. Data Privacy Framework, standard contractual clauses, or other lawful safeguards under the GDPR.

6. Cookies, local storage, and similar technologies

Because the app loads web content, technically necessary cookies or local storage mechanisms may be used. This includes session cookies for login, security and authentication data, language settings, consent or preference storage, and shopping-cart or shop session data where shop features are used.

Naturkompass does not use third-party advertising cookies and does not use retargeting through external advertising partners.

Technically necessary cookies and storage mechanisms are used on the basis of section 25(2) TDDDG. Optional cookies or personalisation features are only used after consent where required.

7. Children and families

Naturkompass is generally aimed at a broad audience as a biodiversity and nature education platform. Some educational content may be suitable for children or may be used jointly by children and parents, teachers, or educational professionals.

  • Children do not receive standalone user accounts.
  • Use takes place through a parent or adult account.
  • No full names, dates of birth, or addresses of children are required.
  • No child profiles are created for advertising purposes.
  • Child-related features may only be used under the supervision of a parent or another responsible adult.

8. Citizen science and voluntary garden observations

Naturkompass may offer optional citizen-science or garden-observation features. Participation is voluntary.

Where anonymous or aggregated evaluation takes place, the following principles apply:

  • no publication of individual gardens
  • no publication of exact addresses
  • no publication of exact GPS coordinates
  • no public display of individual user profiles
  • aggregation only above defined minimum thresholds
  • k-anonymity where evaluations become publicly visible
  • withdrawal from participation for future processing remains possible

The goal is to make ecological patterns visible without making private gardens or individuals identifiable.

9. Storage periods and deletion

Personal data are stored only as long as necessary for the relevant purpose.

  • user account, profile, garden inventory, watchlists, and course progress: until account deletion
  • contact requests: until final handling plus customary documentation periods
  • newsletter data: until consent is withdrawn
  • internal analytics data: up to 365 days unless a shorter technical period applies
  • chat messages: generally no permanent storage by Naturkompass
  • uploaded media: until the associated entry or account is deleted unless retention duties apply
  • payment and invoice data: according to statutory retention periods

Registered users may delete their account or request deletion. Deletion requests can be sent to support@gartenexpedition.de.

10. Data security

We implement technical and organisational measures to protect your data. These include HTTPS/TLS encryption, secure authentication, role-based access restrictions, row-level security for user-related data, technical security headers, and deletion and access concepts.

Despite all security measures, no internet-based application can guarantee absolute security.

11. Your rights

Under the GDPR, you have in particular the following rights:

  • right of access, Art. 15 GDPR
  • right to rectification, Art. 16 GDPR
  • right to erasure, Art. 17 GDPR
  • right to restriction of processing, Art. 18 GDPR
  • right to data portability, Art. 20 GDPR
  • right to object, Art. 21 GDPR
  • right to withdraw consent, Art. 7(3) GDPR
  • right to lodge a complaint with a supervisory authority, Art. 77 GDPR

To exercise your rights, please contact us at support@gartenexpedition.de.

The competent supervisory authority is in particular the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestrasse 2–4, 40213 Düsseldorf, Germany.

12. Relationship with Google Play

When you download, install, update, or use the app through Google Play, Google processes certain data under its own responsibility. This includes, in particular, Google account, device, payment, security, and usage data within Google Play services.

Google’s own privacy policies apply to that processing. This privacy policy concerns the data processing carried out by Naturkompass / Gartenexpedition within the app and the loaded Naturkompass services.

13. Changes to this privacy policy

We reserve the right to adapt this privacy policy if app features, technical service providers, or legal requirements change. The current version will be made available in the app and online.

In the event of material changes, we will inform registered users in an appropriate manner.