Sill/Patch Terms ›

Privacy

Last updated 6 September 2026 · Sill/Patch is in beta

This says what we hold, why, where it goes and how to get it back. It is written to be read rather than to be survived. If something here is unclear, ask — the answer is probably shorter than the paragraph.

The three things people are most surprised by, said first:

Who we are

Sill/Patch is run by The Mana Drop group. For anything about your data, write to support@sillpatch.com and a person will answer.

What we hold, and why

WhatWhy we have it
Your email address and passwordTo let you sign in. The password is stored only as a bcrypt hash — we cannot read it, and neither can anyone who takes a copy of the database.
Your display name, picture and the line you write about yourselfSo the people you share with know who you are. Only friends you have accepted can see them.
Your plants, their names, notes and care historyThis is the app. It is why you are here.
Photographs, voice notes and written notesThe growth diary, and the record of what went wrong with a plant and what fixed it.
The address you give a space, and the coordinates and climate zone we work out from itTo follow the weather and the seasons where the plant actually is, rather than guessing.
Care profiles — a name and a colourSo a household can record who watered what. These are typed in by you; they are not accounts and they cannot sign in.
Friendships, what you have shared, notes between friends, blocks and reportsThe sharing features, and the means to stop them.
When you last signed in and last used the appTo tell an account that is being used from one that has been abandoned.
How many AI calls and reference look-ups you have made this monthTo keep you inside your plan's allowance. It is a count, not a copy of what you asked.

What we do not do

Cookies

One, and it is the one that keeps you signed in. It lasts thirty days, it holds a session identifier and nothing else, and the app does not work without it. There are no advertising or analytics cookies, which is why you have not been asked to dismiss a banner.

Who else sees it

We use a small number of services to run the app. Each gets only what it needs to do its job.

ServiceWhat it receives
Hostinger — hosting and databaseEverything, because it is where the app runs and where the database and photographs live.
OpenRouter, and through it the AI model in use — identifying, diagnosing and Sage's answersThe photograph or question you send, and the plant details needed to answer it. Not your email, your name or your address.
Open-Meteo — weather, geocoding and climate historyThe place you typed, or its coordinates. Nothing about you.
Brevo — emailYour email address and the message being sent: a password reset, an invitation, a trial notice, your monthly report if you ask for one.

Some of these process data outside the UK and the EEA. Where they do, they do so under the standard contractual protections their own terms set out.

Photographs, specifically

Photographs are the most personal thing most people put in this app, so it is worth being exact.

What we can see

Two things are worth being exact about, because "we take your privacy seriously" is what a policy says instead of this.

What an administrator cannot do: read your notes to a friend beyond a reported one and its immediate neighbours, read your conversations with Sage, or sign in as you.

Notes between friends

Notes are between the two of you. Nobody else can read them — not your other friends, not people who share a space with you.

The exception is a note that somebody reports. We can then read that note and up to three either side of it, so it can be judged fairly and in context. Not the rest of your conversation, and not your other conversations. That limit is built into the software and not merely promised here.

How long we keep it

Your plants, photographs and history stay for as long as your account does — the whole point is a record that goes back years. Two things are deliberately not kept for ever:

Getting your data, and getting rid of it

A copy

Settings has an Export that gives you everything as a single file you can keep anywhere. It still works if your account has gone read-only.

Deletion

There is no delete-my-account button yet, and there should be. Until there is, write to support@sillpatch.com from the address you signed up with and we will delete the account, its plants, its photographs and its files. We will confirm when it is done.

Saying so plainly seemed better than implying a button exists.

Your other rights

If you are in the UK or the EEA you can ask us to correct what we hold, to give you a copy, to delete it, or to stop using it in a particular way. Ask at support@sillpatch.com. If you are not satisfied with how we answer, you can complain to your data protection regulator — in the UK that is the Information Commissioner's Office.

Children

Sill/Patch is for people aged 16 and over. We do not knowingly hold data about anybody younger. If you believe a child has an account, tell us and we will remove it.

A care profile you create for a child — a name and a colour, so their watering is recorded — is not an account. It holds nothing about them beyond what you typed.

Security, honestly

Passwords are hashed with bcrypt. The site is served over HTTPS. Photographs are served only to people entitled to see them, checked on every request rather than trusted from the address. Access to your rows is decided by which household or friendship you belong to, enforced in the database queries themselves.

What we will not claim: that a beta run by a small team is impregnable. If something goes wrong that affects you, we will tell you what happened and what we are doing, and we will do it quickly rather than tidily.

Changes

If we change something that matters, we will say so in the app rather than quietly editing this page and changing the date at the top.