Privacy Policy

Effective July 31, 2026

The short version

Green Mind: Zone 9 is operated by ConcordiaPax LLC. This policy explains what we collect, why we collect it, who it reaches, and what you can require us to do about it. It is written to be read, not to be survived.
The short version: we collect what the app needs to plan your garden and reach you about it. We do not sell your personal data, and we do not share it for advertising.

What we collect

Information you give us:
Name and email address — to create your account and send you what you ask for.
Phone number — only if you enter one when requesting a service.
ZIP code — your planting calendar, frost dates, and weather alerts are location-specific, and a Zone 9 plan for the wrong location is worse than no plan. ZIP is all we ask for. We do not collect your street address.
Garden details — bed names and types, sun exposure, your garden goal, plants you track, journal entries, and notes.
Photos you upload — pictures of plants and garden areas you submit for diagnosis. See “Photos and AI” below.
Information collected automatically:
IP address — logged by our hosting and database providers for security, abuse prevention, and reliability.
Approximate coordinates for your ZIP code — we look your ZIP up in a bundled table and store that ZIP’s center point so we can pull the right weather forecast. Everyone in a ZIP code gets the same point. We do not collect your device’s location, and we do not track where you go.
Usage activity — which tasks you complete, scans you run, and links you follow inside the app, so the app can track your progress. We review this internally to see which guidance is working. It is not sold, not shared with advertisers, and not used to build a profile of you.
Sign-in and device data — session tokens stored on your device to keep you logged in.

What we do with it

Build and update your planting calendar, tasks, and weather guidance.
Diagnose plant problems from photos you submit.
Send account, task, and weather emails you have asked for.
Connect you with a local service provider — only when you submit a service request.
Keep the service secure, working, and free of abuse.
We do not use your personal data to build advertising profiles, and we do not run third-party ad or analytics trackers on this site.

We do not sell or share your data

We do not sell your personal data. We do not share it for cross-context behavioral advertising. We do not trade, rent, or license it to data brokers.
We do use a small number of vendors to run the service, and your data passes through them because it has to. They process data under their applicable terms to provide and secure the assigned service. Counsel and operator verification of those terms remains a launch gate:
Supabase — database, authentication, and photo storage.
Cloudflare — website hosting and network security.
Stripe — Checkout, subscription billing, and the Customer Portal. Stripe receives your billing contact and payment details. We do not store your full card number or card security code.
Our configured AI provider — analyzes the scan photo, or a short-lived link to it, only to return the diagnosis you requested.
Sentry — receives scrubbed technical error reports when monitoring is configured; replay, request bodies, credentials, contact fields, and customer content are excluded.
Our email provider — delivers the messages you have asked for.
Open-Meteo — receives configured regional grid coordinates to return forecasts. Those approximate coordinates come from your ZIP code, not your name, email, street address, or device location.
If you submit a service request and we bring in an outside provider to do the work, the contact details and request summary you entered go to that provider so they can reach you. We will tell you that at the point you submit the request, before you send it — you will not find out afterward. These are independent local service providers, not ConcordiaPax employees, agents, or partners.
We may also disclose information if the law requires it, or to protect someone’s safety or our legal rights.

Photos and AI

When you submit a photo for diagnosis, it is stored in our private Supabase storage bucket, attached to your account. Our configured AI provider receives the photo, or a short-lived link to it, for GreenMind’s purpose of producing the diagnosis you requested. The provider’s own privacy terms also apply to its processing.
Photos can carry more than the plant. If your camera records location in image metadata, that metadata travels with the file. If you would rather not include it, turn off location tagging in your camera app before photographing.

Training our gardening AI

Launch training uses only reviewed, repository-authored knowledge. Private journals, scan photos and diagnoses, service requests and contact data, and engagement events are excluded and never used for model training.
Historical consent flags do not grant permission to publish or train. The launch scan flow does not ask for community-sharing consent, and scan photos remain private account data. A future photo-publication or customer-content training program would require a separate approved workflow and new permission.
Operational usage activity remains in the service database for product operation; it is not copied into a training or evaluation dataset. Repository-authored training records keep their source and review metadata.

Subscriptions and billing

GreenMind offers an auto-renewing web subscription for $5.99 monthly or $55 annually. The selected price and billing period are shown before purchase. Stripe processes Checkout, recurring billing, and billing-account management; GreenMind stores a limited subscription-status record so the app can grant access after Stripe’s signed update is reconciled.
You can cancel from Settings through the Stripe Customer Portal. Unless a different outcome is required or a refund is issued, cancellation stops the next renewal and subscriber access continues through the reconciled end of the paid period. Contact our support destination for GreenMind account or access problems; Stripe processes payment details and Portal actions as our billing service provider.

Your rights

If you are a Texas resident, the Texas Data Privacy and Security Act gives you the right to:
confirm whether we process your personal data, and get a copy of it;
correct inaccuracies in it;
delete it;
obtain it in a portable, machine-readable format;
opt out of targeted advertising, sale of personal data, or profiling with legal effects — none of which we do.
Residents of other states with comprehensive privacy laws, including California, have comparable rights, and we honor the same requests regardless of where you live.
To make a request, email privacy@concordiapax.net. We will respond within 45 days, and may extend once by another 45 days if the request is complex — we will tell you if that happens. We will not charge you or degrade your service for exercising a right.
If we deny your request, you may appeal by replying to our decision. We will respond to an appeal within 60 days, and if we deny the appeal we will give you a way to file a complaint with the Texas Attorney General.

If there is a data breach

If we discover a breach of security that exposes your sensitive personal information, we are legally required to notify you, and we will. Texas law requires that notice without unreasonable delay and, absent a law-enforcement hold, no later than 60 days after we determine the breach occurred.
If a breach affects at least 250 Texas residents, we are also required to notify the Texas Attorney General. Where other states’ laws apply to affected residents, we will follow those as well.
Our notice will tell you what happened, what categories of information were involved, and what you can do about it.

Keeping and deleting your data

You can export a portable copy of your account data and delete your account from Settings. Deletion first cancels current Stripe subscriptions and removes private scan photos and account-owned garden data. Limited service-lead and email-delivery records may remain only after contact fields and customer-authored content are scrubbed. The deletion receipt retains only controlled, non-personal status data.
Exact backup-retention and deletion timing remain operator and counsel gates before billing activation; the in-app workflow does not set them. Email privacy@concordiapax.net for correction or individual-record requests that the current interface does not provide.

Children

Green Mind is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us information, email privacy@concordiapax.net and we will delete it.

Security

Your data is isolated to your account at the database level, transmitted over encrypted connections, and encrypted at rest by our providers. No system is perfectly secure, and we will not claim otherwise — which is why the breach-notification commitment above matters.

Changes to this policy

If we change this policy in a way that materially affects how we handle your personal data, we will update the effective date above and notify account holders by email before the change takes effect.

Contact

Questions, requests, or complaints: privacy@concordiapax.net
ConcordiaPax LLC, 190 South Gulf Freeway, Ste B2 #214, League City, TX 77573
Green Mind: Zone 9
A practical garden plan for the Gulf Coast, built by ConcordiaPax LLC.
Planting windows, weather guardrails, and local services are tuned for humid coastal USDA Zone 9 and currently serve Galveston County, Texas first. Guidance is organic and environmentally responsible by policy — Green Mind never recommends restricted-use products or anything requiring an applicator’s license.