Privacy Policy
Last updated: July 16, 2026
Welcome to Keen Labs LLC ("Keen Labs," "we," "us," or "our"). This document contains both our Master Privacy Policy (which governs how we collect, use, and protect your information across our products, websites, and services) and our App-Specific Privacy Addenda (which cover additional data processing unique to specific apps, such as our gardening app, Arbor).
We may update this Privacy Policy from time to time. When we make material changes, we will update the date at the top of this page and, where appropriate, provide additional notice (for example, in-app or by email). Your continued use of the Services after an update means you have been informed of the revised Policy; it does not replace consents we must obtain where the law requires them.
Part A: Keen Labs LLC Master Privacy Policy
1. Introduction & Our "Hub-and-Spoke" Privacy Model
Keen Labs builds software products that help people get useful work done. We try not to collect more personal information than we need to operate and improve those products. Arbor and our other apps are cloud-hosted services: account and garden data are stored on our servers and with the subprocessors listed below, not only on your device.
Because we operate (or may operate) multiple applications under the Keen Labs umbrella, we use a Hub-and-Spoke model for privacy disclosures:
- The Hub (This Master Policy): Core partners and practices that commonly apply across Keen Labs applications — authentication, hosting, databases, analytics, and error reporting.
- The Spoke (App-Specific Addenda): Additional collection and subprocessors that are unique to a single app (for example, weather APIs, AI features, or payment processors in Arbor).
Geographic scope: Our Services are offered to users located in the United States. They are not directed to residents of the European Economic Area, United Kingdom, Switzerland, or other non-U.S. jurisdictions. If you access the Services from outside the United States, you do so at your own initiative; we may decline, suspend, or delete accounts that appear to be outside our supported region.
This Privacy Policy describes our privacy practices. It is a notice, not a separate contract. Use of the Services is governed by our Terms of Service. If you do not want us to process your information as described here, do not use the Services.
2. Information We Collect (Across All Apps)
When you interact with a Keen Labs application, we may collect the following types of information:
- Account & Authentication Data: To create an account and keep you signed in, our identity partner Clerk processes credentials and profile fields such as email address, authentication secrets (for example, a password you set with Clerk — we do not store your raw password on Keen Labs systems), name (if provided), profile image (if provided by you or an identity provider), and Clerk's unique user identifier. We store the Clerk user id and related account fields needed to operate the app.
- Third-Party Authentication (Google & Apple): If you register or log in with Google or Apple through Clerk, we receive profile information from that provider as configured in Clerk — typically name, email address, profile picture, and a provider-specific user identifier.
- Google API User Data: If you use Google authentication, our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
- Application Data: Profile data, settings, preferences, and content you create in an app (for Arbor, see Part B) are stored in our databases. We use Supabase as the hosted PostgreSQL provider (and, where applicable, object storage). Our application servers run on Railway. Web frontends are typically hosted on Vercel. Marketing and content sites may be hosted on Cloudflare.
- Technical, Device & Telemetry Data: When you use a browser or mobile app, we and our service providers may automatically collect technical data such as IP address, device type/model, operating system and version, browser type, app version, approximate network information, crash diagnostics, and similar telemetry. This may come from our apps, hosting providers, and SDKs listed in this Policy — not solely from Expo or Vercel.
- Push Notifications: On mobile, with your permission, we may collect a push notification token and related settings (for example, a reminder timezone) so we can send account or product reminders via Expo's push infrastructure. You can disable notifications in your device settings and, where offered, in the app.
- Performance & Crash Reports: We use Sentry for error tracking, performance diagnostics, and (where you opt in) session replay. Crash and error events can include device/app metadata and operational identifiers (such as a Clerk user id). They are not "anonymous" in all cases. See session replay below.
- Product Analytics: On web, we use PostHog to understand product usage (for example, screen views and feature events). When you are signed in we may associate events with your Clerk user id via PostHog's identify features. We configure PostHog with autocapture off and do not use PostHog for session replay. Mobile analytics may be limited or stubbed until a mobile analytics SDK is enabled; this Policy will be updated if that changes.
- Session Replay (opt-in): Session replay is provided by Sentry, not PostHog. Recording runs only after you opt in (and only subject to our operator sampling caps). If you opt in, replay may capture on-screen content in the app — including garden-related text visible in the UI — as well as navigation and interaction context. We pause replay on certain sensitive surfaces (for example, authentication and payment overlays) where implemented. You can change your preference in the app's settings/profile. Opting out stops new recording under our controls; it does not erase replays already stored by Sentry under its retention settings.
-
Cookies & Similar Technologies: On the web, we and our providers use cookies,
local/session storage, and similar technologies. Today that includes, at minimum:
- Essential / authentication: Clerk uses cookies (and related browser storage) to maintain your signed-in session and secure authentication flows.
- Preferences: We may set first-party cookies or local storage for UI state (for example, sidebar open/closed) and similar non-tracking preferences.
- Analytics & diagnostics: PostHog and Sentry may use cookies or browser storage to operate analytics, error reporting, and (if opted in) session replay.
- Communications & Feedback: If you email us or use an in-app feedback feature, we collect the content of your message and related metadata needed to respond or improve the product (see app-specific addenda for any automated triage).
3. How We Use Your Information
We process personal information for the following business purposes:
- Service Provision: To provide, operate, maintain, and secure our applications.
- Identity Management: To authenticate you and keep your account working.
- User Support & Communication: To respond to inquiries, fix bugs, and provide support.
- Product Improvement: To analyze usage, evaluate performance, and improve experiences.
- Feedback Requests: To contact you occasionally about your experience.
- Security & Fraud Prevention: To protect the Services, monitor abuse, and enforce our Terms.
- Legal Compliance: To comply with law and respond to valid legal requests.
Because we offer the Services to U.S. users, we generally rely on U.S. privacy frameworks (including applicable state laws) rather than GDPR "lawful bases." Where a specific feature requires consent under U.S. law or platform rules (for example, optional session replay, or certain device permissions), we will ask for that consent in the product.
4. When & With Whom We Share Your Data
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only in the limited situations below.
- Core Service Providers (Subprocessors): We share data with infrastructure and tooling partners needed to run the Services:
| Service Provider | Purpose | Privacy Policy Link |
|---|---|---|
| Clerk | User authentication & identity (including Google/Apple Sign-In where enabled) | Clerk Privacy |
| Supabase | Hosted PostgreSQL database and (where used) object storage — not Supabase Auth | Supabase Privacy |
| Railway | Application / API server hosting | Railway Privacy |
| Vercel | Web application hosting & deployment | Vercel Privacy |
| Cloudflare | Marketing / content site hosting, CDN, and edge security (where used) | Cloudflare Privacy |
| Expo | Mobile app framework, over-the-air updates, and push notification delivery | Expo Privacy |
| Sentry | Error tracking, diagnostics, and opt-in session replay | Sentry Privacy |
| PostHog | Web product analytics (not session replay) | PostHog Privacy |
- App-Specific Providers: Individual apps may use additional processors (payments, AI, weather, etc.). Those are listed in the relevant App-Specific Addendum.
- Business Transfers: If Keen Labs LLC is involved in a merger, acquisition, asset sale, financing, or bankruptcy, personal data may be transferred to a successor or affiliate as part of that transaction, subject to this Policy or a successor policy with comparable protections.
- Legal Protections: We may disclose information if required by law, or if we believe in good faith that disclosure is necessary to protect users, the public, or our rights, property, or safety, or to detect/prevent fraud or security issues.
5. Data Security & Retention
- Security Measures: We use industry-standard encryption (TLS) for data in transit and rely on our hosting and database providers' protections for data at rest, plus access controls on our systems. No method of transmission or storage is 100% secure.
- Retention: We retain personal data for as long as your account is active and as needed to provide the Services, comply with law, resolve disputes, and enforce agreements. Operational logs, backups, analytics, and error/replay data may persist for longer according to our (and our vendors') retention schedules.
- Account deletion: Where an app offers in-app account deletion, you may delete your account from that app's profile/settings. For Arbor, see Part B. After a successful deletion request, we erase personal data from our active application databases and request deletion of your Clerk authentication record, subject to the limitations below. Residual copies may remain in encrypted backups for a limited period until those backups rotate.
- What deletion does not guarantee: Unless a specific law requires us to do more, we do not promise to locate and erase every copy of your information from all analytics, error-monitoring, session-replay, AI-provider, CDN, or email systems on a fixed timeline. Those vendors retain data under their own policies. Where a privacy law requires us to direct a service provider to delete personal information, we will do so as required. Payment processors and app stores may retain transaction records independently of Keen Labs.
6. Children's Privacy
Our Services are intended for users aged 13 and older located in the United States. We do not knowingly collect personal information from children under 13. We do not provide a COPPA parental-consent flow. If you believe we have collected data from a child under 13, contact privacy@keenlabsapps.com and we will delete the associated account data from our active systems.
Age eligibility is enforced primarily through our Terms (your representation that you meet the age requirement) and, where enabled, Clerk's requirement that you accept our legal terms at sign-up. Clerk does not independently verify that a user is 13 or older.
7. Your Rights & Regional Disclosures
A. United States State Privacy Rights
Depending on your state of residence (for example, California, Virginia, Colorado, Connecticut, Utah, or Texas), you may have rights to:
- Know / Access: Request the categories and specific pieces of personal information we have collected about you, and information about how we use and disclose it.
- Delete: Request deletion of personal information, subject to legal exceptions.
- Correct: Request correction of inaccurate personal information.
- Opt out of sale / sharing: Keen Labs does not sell personal information or share it for cross-context behavioral advertising. If that ever changes, we will update this Policy and provide required opt-out mechanisms.
- Non-discrimination: We will not discriminate against you for exercising privacy rights.
How to exercise rights: Email privacy@keenlabsapps.com (or use in-app account deletion for erasure of your Arbor account). We may need to verify your identity (for example, by confirming control of your account email) before fulfilling a request. We will respond within the time required by applicable law (generally up to 45 days under California law, with a possible extension where permitted). If your state provides an appeal process and we deny a request, our response will explain how to appeal.
Authorized agents: Where your state allows it, you may designate an authorized agent to submit a request on your behalf. We may require proof of authorization and still verify your identity directly.
California "Shine the Light": We do not disclose personal information to third parties for their own direct marketing purposes.
B. Non-U.S. Users
The Services are not directed to the EEA, UK, or Switzerland. We do not maintain a GDPR representative or Data Protection Officer for those regions. If you are outside the United States and believe we hold your personal information, contact privacy@keenlabsapps.com. We may delete the account and decline further service rather than support a non-U.S. product offering.
C. Do-Not-Track & Global Privacy Control
Some browsers offer Do-Not-Track ("DNT") signals. There is no consistent industry standard for DNT, and we do not respond to DNT signals at this time.
Some browsers and extensions offer Global Privacy Control ("GPC") signals related to the "sale" or "sharing" of personal information. Because we do not sell personal information or share it for cross-context behavioral advertising, we treat GPC as consistent with our current practices. If our practices change, we will update this Policy and our technical response to GPC as required.
8. Contact
Privacy questions and rights requests: privacy@keenlabsapps.com
Product support (Arbor): support@arborgarden.app
Keen Labs LLC
United States
Part B: Arbor App-Specific Privacy Addendum
This Arbor App-Specific Privacy Addendum supplements the Keen Labs Master Privacy Policy. It applies to personal information we process when you use the Arbor mobile and web applications and related services at arborgarden.app (and associated app hosts).
1. Additional Information Collected by Arbor
In addition to the Master Policy categories, Arbor processes:
- Location derived from ZIP code (not GPS): You enter a U.S. ZIP code during onboarding/planning. We store that ZIP (and derived fields such as city/region labels, USDA hardiness zone, and frost/season windows) to personalize care plans and weather. Arbor does not request access to your device's GPS or real-time precise geolocation APIs.
- Garden profile & inventory: Beds, plants, varieties, quantities, watering and fertilizing preferences, and related structured garden data you confirm in the app.
- Tasks, notes, harvest logs & history: Care tasks, completions, snoozes, dismissals, free-text garden notes, harvest entries, and related history generated as you use Arbor.
- Conversations with Arbor's AI features: Messages you send in onboarding, planning, garden-update chat, and similar flows, plus model outputs we persist to operate those features.
- Garden sketch images: Optional AI-generated illustration of your garden layout, stored so you can view it in the app.
- Subscription & entitlement data: Whether you are on Free, Trial, or Pro; processor customer/app-user identifiers; renewal/expiration metadata needed to unlock features. We do not store full payment card numbers on Keen Labs servers.
- Push reminder data (mobile): Expo push token, reminder timezone, and related delivery metadata when you enable reminders.
- Session replay preference: Your opt-in/opt-out choice for Sentry session replay.
- Product feedback: Messages you submit via Send feedback, plus technical context needed to triage them (see below).
Arbor does not currently offer a user-facing plant photo upload or photo-based disease diagnosis feature. If that changes, we will update this Addendum before enabling it.
2. Arbor-Specific Subprocessors & Service Integrations
A. Artificial Intelligence
-
Anthropic (Claude): We use Anthropic's API (called only from our servers) to
power conversational garden setup, planning, garden updates, note triage, briefings, feedback
classification, and related care features.
- What we share: User-authored content and garden context needed for the feature — for example, chat messages, garden inventory/profile details, notes, and your ZIP code (used for seasonal/calendar context). We do not intentionally send your email address or name to Anthropic as part of those prompts.
- Important: Under privacy laws, ZIP code and garden details can still be personal information. Do not assume AI prompts are free of personal data.
-
OpenAI: We use OpenAI's image API (server-side only) to generate stylized
garden sketch images from prompts our servers build from your garden inventory
(not from arbitrary user-uploaded photos).
- What we share: Anonymized or inventory-derived text prompts describing beds/plants for illustration. We do not intentionally include your email or name in those prompts.
B. Environmental & Zone Data APIs
- OpenStreetMap Nominatim: Our servers send your ZIP code to geocode it to approximate coordinates (no GPS from your device).
- Open-Meteo: Our servers request weather forecasts for those coordinates to power weather context and weather-informed task adjustments.
- PHZM API (phzmapi.org): Our servers look up USDA hardiness zone information from your ZIP code.
We do not send your username, email, or Clerk user id to Nominatim, Open-Meteo, or PHZM. Your ZIP code is location data and is transmitted to those services as described above.
C. Payment & Subscription Processing
- Stripe (Web): Web subscriptions are processed by Stripe. Stripe collects and processes payment method, billing, and transaction details as an independent PCI-compliant processor. Keen Labs receives subscription status and customer identifiers needed for entitlements, not your full card number. Stripe Privacy Policy.
- RevenueCat (Mobile) + Apple / Google: Mobile subscriptions use RevenueCat with Apple App Store and/or Google Play Billing. Apple or Google processes the payment. RevenueCat helps us verify entitlements; we typically link RevenueCat's app user id to your Clerk user id. Keen Labs does not receive your full card number from these flows. RevenueCat Privacy.
D. Feedback Triage
- Feedback you submit may be stored in our database, classified with assistance from Anthropic, and — when we file product issues — summarized or filed into our engineering tracker on GitHub. Avoid including passwords, precise personal addresses, or other sensitive data in feedback text. We try not to publish email addresses in public issues, but feedback content may become visible to people with access to our tracker.
E. Affiliate Links
- Some product recommendations in Arbor link to third-party retailers through affiliate networks. These links include an anonymous click identifier so the retailer can credit Arbor for a referral; it contains no account information and is not linked to your identity by the retailer. Once you leave Arbor, the retailer's own privacy policy and cookies apply.
- We receive aggregate conversion reports from these networks — order totals and commissions — and we store only the fields needed to reconcile a referral. We do not store the customer details a network may include in those reports.
- How we choose what to recommend is explained on our affiliate disclosure page.
3. Arbor Account Deletion
You can delete your Arbor account in-app via Profile → Delete account (web and mobile). That request:
- Cancels active Stripe subscriptions we can cancel server-side (web billing), when applicable;
- Erases your Arbor data from our active application database (garden profile, tasks, notes, conversations, feedback rows, entitlement rows, and related records);
- Deletes associated garden sketch storage objects where applicable; and
- Requests deletion of your Clerk user record.
App Store / Play subscriptions: Deleting your Arbor account does not by itself cancel an Apple or Google subscription. You must manage or cancel those in your Apple ID or Google Play subscription settings (the app warns you about this when relevant).
As described in Part A, deletion from our active systems does not guarantee erasure from every analytics, crash, replay, AI, or backup system on a fixed schedule, except where law requires us to direct a service provider to delete.
4. Contact
Privacy:
privacy@keenlabsapps.com
Arbor support:
support@arborgarden.app
Keen Labs LLC — United States