Last updated 6 September 2026 · Sill/Patch is in beta
This says what we hold, why, where it goes and how to get it back. It is written to be read rather than to be survived. If something here is unclear, ask — the answer is probably shorter than the paragraph.
The three things people are most surprised by, said first:
Sill/Patch is run by The Mana Drop group. For anything about your data, write to support@sillpatch.com and a person will answer.
| What | Why we have it |
|---|---|
| Your email address and password | To let you sign in. The password is stored only as a bcrypt hash — we cannot read it, and neither can anyone who takes a copy of the database. |
| Your display name, picture and the line you write about yourself | So the people you share with know who you are. Only friends you have accepted can see them. |
| Your plants, their names, notes and care history | This is the app. It is why you are here. |
| Photographs, voice notes and written notes | The growth diary, and the record of what went wrong with a plant and what fixed it. |
| The address you give a space, and the coordinates and climate zone we work out from it | To follow the weather and the seasons where the plant actually is, rather than guessing. |
| Care profiles — a name and a colour | So a household can record who watered what. These are typed in by you; they are not accounts and they cannot sign in. |
| Friendships, what you have shared, notes between friends, blocks and reports | The sharing features, and the means to stop them. |
| When you last signed in and last used the app | To tell an account that is being used from one that has been abandoned. |
| How many AI calls and reference look-ups you have made this month | To keep you inside your plan's allowance. It is a count, not a copy of what you asked. |
One, and it is the one that keeps you signed in. It lasts thirty days, it holds a session identifier and nothing else, and the app does not work without it. There are no advertising or analytics cookies, which is why you have not been asked to dismiss a banner.
We use a small number of services to run the app. Each gets only what it needs to do its job.
| Service | What it receives |
|---|---|
| Hostinger — hosting and database | Everything, because it is where the app runs and where the database and photographs live. |
| OpenRouter, and through it the AI model in use — identifying, diagnosing and Sage's answers | The photograph or question you send, and the plant details needed to answer it. Not your email, your name or your address. |
| Open-Meteo — weather, geocoding and climate history | The place you typed, or its coordinates. Nothing about you. |
| Brevo — email | Your email address and the message being sent: a password reset, an invitation, a trial notice, your monthly report if you ask for one. |
Some of these process data outside the UK and the EEA. Where they do, they do so under the standard contractual protections their own terms set out.
Photographs are the most personal thing most people put in this app, so it is worth being exact.
Two things are worth being exact about, because "we take your privacy seriously" is what a policy says instead of this.
What an administrator cannot do: read your notes to a friend beyond a reported one and its immediate neighbours, read your conversations with Sage, or sign in as you.
Notes are between the two of you. Nobody else can read them — not your other friends, not people who share a space with you.
The exception is a note that somebody reports. We can then read that note and up to three either side of it, so it can be judged fairly and in context. Not the rest of your conversation, and not your other conversations. That limit is built into the software and not merely promised here.
Your plants, photographs and history stay for as long as your account does — the whole point is a record that goes back years. Two things are deliberately not kept for ever:
Settings has an Export that gives you everything as a single file you can keep anywhere. It still works if your account has gone read-only.
There is no delete-my-account button yet, and there should be. Until there is, write to support@sillpatch.com from the address you signed up with and we will delete the account, its plants, its photographs and its files. We will confirm when it is done.
Saying so plainly seemed better than implying a button exists.
If you are in the UK or the EEA you can ask us to correct what we hold, to give you a copy, to delete it, or to stop using it in a particular way. Ask at support@sillpatch.com. If you are not satisfied with how we answer, you can complain to your data protection regulator — in the UK that is the Information Commissioner's Office.
Sill/Patch is for people aged 16 and over. We do not knowingly hold data about anybody younger. If you believe a child has an account, tell us and we will remove it.
A care profile you create for a child — a name and a colour, so their watering is recorded — is not an account. It holds nothing about them beyond what you typed.
Passwords are hashed with bcrypt. The site is served over HTTPS. Photographs are served only to people entitled to see them, checked on every request rather than trusted from the address. Access to your rows is decided by which household or friendship you belong to, enforced in the database queries themselves.
What we will not claim: that a beta run by a small team is impregnable. If something goes wrong that affects you, we will tell you what happened and what we are doing, and we will do it quickly rather than tidily.
If we change something that matters, we will say so in the app rather than quietly editing this page and changing the date at the top.