Twigged
PrivacyCookiesTermsDPAComplaintsDisclosureData sources

Privacy Notice

Last updated: 24 August 2026

This notice explains how Twigged (“we”, “us”) handles personal data when you visit twigged.design or use the Twigged garden-design service (the “Service”). Twigged is operated from the United Kingdom. This notice is written for UK GDPR and the Data Protection Act 2018 and also explains the practices that apply when people in the United States and Canada use the Service. Additional local rights may apply depending on where you live.

1. Who is responsible for the data

Twigged is the controller for account administration, billing, security, service diagnostics, customer communications and the structured product-improvement processing described below. For privacy questions or rights requests, email privacy@twigged.design.

When a professional designer places a client’s personal data in Twigged so that we can provide the requested client-service functions, the designer is the controller and Twigged is its processor. Section 6 and our Data Processing Addendum explain that relationship.

2. Personal data we process

  • Account and profile data: email address, password hash, authentication identifiers, display name, company name, business country, interface locale, measurement preference, other account preferences and subscription tier. Before sign-in, an explicit country choice may be kept in a first-party cookie so pricing and sign-up remain consistent.
  • Waitlist and communication data: email, role, project type, optional notes, messages to support or privacy, and the information needed to handle a request or complaint.
  • Project and design data: project names, dimensions, drawings, bed geometry, plant selections, quantities, notes, comments, client details you enter, saved versions, exports and photographs uploaded to the Visualiser or Restyle tools.
  • Community gallery publication data: the submitted title and description, design snapshot, copied cover image, publication status and evidence of your publication request or withdrawal. A published listing is deliberately public.
  • Location data: a postcode, address or map point you choose to enter, coordinates returned from that request, aerial imagery and a traced garden boundary. Exact location can identify a property.
  • AI request and result data: briefs, prompts, conditions, reference images, generated plant palettes, garden layouts, visualisations, critiques, model and generation provenance, quality checks and approval evidence. Owner-private run records may preserve the requested input and output for project history, reliable retries and approval evidence.
  • Structured design activity: product events such as generating a palette, adding or moving a shape or plant, changing a quantity, swapping a species, accepting a plan, leaving a rating or recording a project outcome. Section 5 explains when these records are used to improve Twigged.
  • Billing and entitlement data: Stripe customer and transaction references, subscription state, invoices, credit purchases, credit usage and paid-operation ledgers. Twigged does not receive or store full payment-card details.
  • Reminder data: the email address and optional name supplied for plant-care reminders, confirmation state and the information needed to unsubscribe.
  • Technical and security data: request time, route, browser or device information, rate-limit counters and abuse signals. A raw IP address and user agent are necessarily processed by hosting, authentication and network-security providers and may appear in their time-limited operational logs. Twigged uses a secret-keyed pseudonym rather than the raw address for its own durable rate-limit key. Our host may also provide an IP-derived country so Twigged can suggest a regional version of the Service. That suggestion is not saved as your account country or used to decide billing currency; you must confirm the country yourself. Where Turnstile is enabled at sign-up, Cloudflare processes the address and browser challenge signals to detect automated abuse.
  • Error diagnostics: error messages, stack traces, route names and limited browser or server details. Request bodies, account details and sensitive URL values are removed or redacted before configured Sentry reports are sent. Twigged does not use Sentry Replay and does not intentionally send form text, project images or public bearer-link page content in diagnostics.
  • Retailer-link data:for a signed-in click, the retailer, canonical plant name, destination retailer origin and, while access is current, a project reference used for sourcing analysis. Anonymous click-outs are not written to Twigged’s product-analytics database, although the redirect request and its metadata can appear temporarily in necessary hosting and security logs.
  • Ask Twigged questions: the text you choose to send and the general section of Twigged you are viewing. To understand what people need help with, Twigged can keep the latest valid question after automatically redacting common contact details and bearer identifiers. The record can also include a coarse page family; whether text or one-off screen help was used; a local category; knowledge-match, direct-answer and reply-outcome labels; the served model identifier; review status; and timestamps. It does not have an account, project or user ID field, or a separate email, IP-address or user-agent field, and does not store the conversation history, AI answer, model prompt or screenshot. Free text can still contain personal data that automated redaction misses, so please do not include personal or private project details. Query strings and private share tokens are removed from the page context.
  • Optional one-off support screenshot: after you sign in and explicitly request screen help, your browser asks which surface to share. Twigged captures one compressed still, stops sharing immediately and processes it only to answer that request. The image is not saved to your account, project or support report.
  • Support reports: only after the chat has tried to help and you choose to send a report, Twigged stores the message you write, your account email, a general page name and limited browser details in the private admin inbox. The chat transcript and any screenshot are not attached automatically.

An email address and authentication data are required to create and secure an account; without them we cannot provide a signed-in account. Billing details are required only for a paid plan or credit purchase. Project, client, location, reminder and optional profile information is voluntary, but a feature that depends on information you choose not to provide may be unavailable or less accurate.

3. Where the data comes from

Most data comes directly from you when you create an account, enter a project, use an AI feature, change a design or contact us. Some is created automatically through normal use of the Service. We also receive authentication information from Google if you choose Google sign-in, payment and subscription status from Stripe, delivery status from Resend, and garden-location results from Mapbox or postcodes.io when you request those features.

4. Purposes and lawful bases

  • Contract: to create and secure your account, store projects, run requested AI and design tools, provide exports and shares, administer subscriptions and credits, and answer service requests (UK GDPR Article 6(1)(b)).
  • Legitimate interests: to protect the Service, prevent abuse and fraud, diagnose faults, understand feature use, improve product and AI design quality using the controlled records in section 5, review minimised Ask Twigged questions to find missing capabilities, broken workflows and help gaps, and understand signed- in retailer sourcing interest (Article 6(1)(f)). Our interests are a reliable, safe and genuinely useful professional design service. You can object at any time; see section 10.
  • Consent: for confirmed care reminders, requested launch communications, a design you explicitly submit for public display in the community gallery, and the separate sharing of a finally approved whole garden as a reusable design reference (Article 6(1)(a)). You can withdraw consent without affecting earlier lawful processing.
  • Legal obligation: for records or disclosures needed to comply with tax, accounting, regulatory or data-protection duties (Article 6(1)(c)).

Community gallery publication

The community gallery is different from private project storage and from the internal learning uses in section 5. Nothing is published there unless you make a separate submission and confirm that it can be public. The submitted title, description, design and copied cover image can then be viewed, copied or indexed by anyone, including search engines. Do not submit confidential material or personal data unless you have authority to publish it and have given any required notice.

You can withdraw a submission in any status from Settings → Data & privacy or by emailing privacy@twigged.design. We remove the Twigged listing and queue its copied cover for deletion. Copies already made by other people and search-engine caches can remain outside Twigged’s control.

5. Structured product and AI improvement

Twigged learns most from the chain between a design request, the result produced, the changes a designer makes and the eventual outcome. For a signed-in account, structured learning is on by default under our legitimate interests unless the account holder objects. We bring this use and the right to object to your attention when you first enter the account or use an AI design flow, and the control remains available in Settings → Data & privacy.

Eligible shared-learning records can include:

  • garden conditions and design attributes needed to understand the request, the generated plant list or layout, served model, validator scores and professional-quality checks;
  • structured editor actions such as locks, quantity changes, plant removals and swaps, bed or shape changes, regeneration, acceptance, export and undo events;
  • ratings, visualisation quality scores, and structured installation or garden-outcome information you choose to record; and
  • derived lessons about common failure modes, successful combinations, condition fit, spatial decisions and the corrections designers make.

Shared-learning records exclude free-text briefs, feedback, reviewer prose, client names and contact details, exact addresses and coordinates, private notes and recognisable people. Only closed horticultural categories, validated botanical names, measurements, booleans, scores and limited model provenance are admitted. Question text is not stored in editor telemetry; the event and a length indicator can be recorded instead. Operational, owner-private AI run records can still retain the source input and output to deliver the account functions described in section 2; they are not the shared- learning copy.

Recent eligible records can be reviewed by background critics to derive reusable design guidance for later generations. Twigged uses these records to improve its own prompts, validation, retrieval, product decisions and evaluation; we do not use them to train the foundation-model weights of OpenAI, Anthropic or Google.

Ask Twigged product insight

This is separate from the structured shared-learning records above. Twigged may keep the redacted, identity-free question record described in section 2 for up to 90 days so an authorised owner can find missing capabilities, broken workflows and gaps in our help. Categorisation is deterministic and does not make an extra AI request. The insight is not linked to an account or project, admitted to the reusable design- learning set or used to train a provider’s foundation-model weights. The full conversation, AI answer, model prompt and one-off screenshot are excluded.

Your objection control.Use “Opt out of ambient AI learning” in Settings → Data & privacy at any time. The design features continue to work, future activity is not admitted to the shared-learning set, and you can erase the account’s existing raw learning history. Owner-private operational checks required to verify an image against its plan can still run so professional safety features continue to work; their results are not admitted to shared learning. You can also object by emailing privacy@twigged.design.

Approved whole gardens are separate. A complete garden is admitted to the reusable garden-reference corpus only when you turn on the separate sharing control and explicitly approve a final review. That consent is off by default. The shared copy discards the project name, raw brief, notes, postcode and coordinates and keeps catalogue plant names, bed roles and coarse horticultural conditions. A restricted internal account and project link remains solely so we can honour withdrawal, enforce expiry and audit the consent. Withdrawing the separate consent removes references previously shared from that account.

6. Client data and our processor role

A professional designer may enter a client’s name, address, property image, comments or other personal data. For the storage, display, requested AI processing, collaboration and export of that Client Personal Data, the designer is the controller and Twigged acts on the designer’s documented instructions as processor. The designer is responsible for a lawful basis, appropriate client notice and permission to upload or share the material. A designer who chooses community-gallery publication must also have authority to make every submitted element public.

Client Personal Data is not eligible for Twigged’s own shared- learning purpose. The safeguards in section 5 are designed to keep client identifiers out of that copy. The Data Processing Addendum contains the full processor terms, including security, sub-processors, assistance, deletion and audit provisions.

7. Service providers and other recipients

We disclose only the data needed for the relevant function. We do not sell personal data or share it for cross-context behavioural advertising. Depending on what you use and which services are configured, recipients include:

  • Supabase for database hosting, authentication and private files, minimised Ask Twigged question insights, plus files you explicitly publish to the community gallery;
  • Vercel for application hosting and AI Gateway, including routing some requested AI generations and optional Ask Twigged questions or one-off support screenshots;
  • OpenAI, Anthropic and Googlefor requested text, design, validation or image generation; Google also processes sign- in data if you select Google sign-in. Twigged does not use shared- learning records to train these providers’ foundation-model weights, and configured Gateway requests disallow prompt training;
  • fal.ai where the optional depth-conditioned structure stage of a requested garden visualisation is switched on; it receives the generated garden description, the geometry and colour guide images drawn from your plan, and returns the structure image. It is not routed through the Vercel AI Gateway, so any no-training or retention commitment comes from its own terms;
  • Stripe for checkout, subscriptions, invoices, payment processing and the billing portal;
  • Resend for requested transactional emails and care reminders;
  • Proton Mail for monitored privacy, support and business correspondence;
  • Sentry for minimised error diagnostics only; no session replay is used;
  • Mapbox and postcodes.io for location, postcode, mapping and aerial-imagery functions you request;
  • Cloudflare Turnstile for automated-abuse checks on sign-up when enabled; and
  • Upstash for short-lived pseudonymous rate-limit counters when distributed rate limiting is enabled.

Plant and price providers receive botanical search terms needed for a lookup, not a Twigged account identifier. Where a plant photograph is delivered directly by a plant-data provider, Wikimedia, iNaturalist or its image-delivery network, that provider also receives normal browser request metadata such as IP address, browser information and referring origin. When you follow a retailer link, the destination retailer receives the normal request information sent by your browser and handles it under its own privacy notice. Our Retailer Links & Affiliate Disclosure explains the redirect and Twigged’s click record.

A community-gallery submission is disclosed to the public and can be indexed by search engines. The listing does not need to identify the account holder, but personal information included in its title, description, design or image becomes public with the submission.

We may also disclose data where the law requires it, to establish or defend legal claims, to protect people or the Service, or as part of a business transfer subject to appropriate confidentiality and notice.

8. International transfers

Some providers may process personal data outside the UK. The countries involved and the legal mechanism depend on the provider, service and account configuration. Where UK data-protection law treats an active transfer as restricted, an applicable UK adequacy regulation or appropriate safeguard—such as the UK International Data Transfer Agreement or UK Addendum—is required before that transfer begins. Email privacy@twigged.design for the countries and mechanism applicable to a service you use, subject to necessary commercial and security redactions.

9. Retention

Our standard retention schedule is:

  • Account and project content: while the account is active. After deletion is requested, active data is removed or put into the deletion queue within 30 days; protected backups age out within 90 days and are not restored as an active account.
  • Community gallery submissions: until you withdraw the submission or delete the account. Withdrawal removes the Twigged listing and queues its copied cover for deletion. Copies made by others and search-engine caches can persist outside our control.
  • Raw structured learning and event records: up to 36 months from collection, unless you erase learning history or object earlier.
  • AI batch bookkeeping: abandoned provider-batch references are removed after seven days and reconciled references after 30 days; deleting a linked critique removes its row reference sooner. A provider may retain an already submitted in-flight request for the shorter period required by its security and service terms.
  • Privacy choices and notice evidence: while the account remains active, then removed with account erasure.
  • Regional preference: an explicit pre-sign-in country cookie lasts up to one year unless you replace it or clear browser cookies. A saved account country lasts while the account is active or until you change it.
  • Ask Twigged and screen help: ordinary chat stays in the current browser session. The redacted, identity-free copy of the latest valid question and its service-quality labels are kept for no more than 90 days and removed by scheduled cleanup. Marking an item as planned, reviewed or resolved does not extend that deadline. The AI answer, model prompt and conversation are not stored in that insight. A one-off screenshot is held in browser memory only for the request, transiently processed and removed from chat state after the reply; it is not stored in the insight. Support reports you explicitly send are separate and retained in the private feedback inbox only as long as reasonably needed to investigate and improve the Service.
  • Error diagnostics:up to 90 days where retention is under Twigged’s control, unless a shorter period is configured or a specific security investigation reasonably requires longer.
  • Support and privacy complaints: six years after the matter is closed.
  • De-identified aggregate statistics and derived design lessons: may be retained indefinitely where they can no longer reasonably be linked to an account or person.
  • Rate limits and deletion security: pseudonymous counters expire within one hour. Production can use a distributed fixed-window store; a short-lived in-process counter remains as the outage and local-development fallback. A one-way deletion marker can remain while a durable deletion job is pending so an old access token cannot recreate files.
  • Waitlist and reminder data:waitlist contact is enabled only after the email owner confirms the seven-day link. Unconfirmed details and tokens are removed by scheduled cleanup. Confirmed waitlist data remains until the launch programme closes or you unsubscribe. A minimal suppression record may then be retained so Twigged does not contact that address again. Unconfirmed care reminder links also expire after seven days and are removed shortly afterwards. Confirmed reminders remain until unsubscribed or otherwise removed; delivery and suppression records can follow the email provider’s security and abuse-prevention period.
  • Billing and legal records:while needed to provide paid features and for the applicable tax, accounting, fraud, chargeback or legal-claims period. This exception covers records Twigged itself must retain; it does not turn a professional customer’s client-project documents into Twigged records. Those project documents are removed with the project or account, so the professional customer should export anything its practice must keep before deletion.

10. Your rights, including the right to object

Depending on the circumstances, UK data-protection law gives you the right to access personal data, correct it, erase it, restrict its use, receive portable data, withdraw consent and object to processing based on legitimate interests. Depending on your US state or Canadian province, similar or additional rights may apply. Rights can have legal exceptions, which we will explain if they apply.

Right to object:you may object at any time to structured product and AI improvement, Ask Twigged product insight, service analytics, or another use based on legitimate interests. The permanent learning control in Settings → Data & privacy also stops new first-party retailer-interest records, or you can email privacy@twigged.design. We will stop the objected-to processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. Direct marketing, if introduced, would stop on objection without that balancing test.

Ask Twigged insights are deliberately not linked to an account, so account export or deletion cannot reliably select them. If you think a retained question contains your personal data, email the approximate date, time, page and enough wording to locate it. We will use only proportionate detail to check for and delete a reliable match; if no match can be found, the insight expires automatically within 90 days. You can contact us before using Ask Twigged if you prefer another support route.

You can download a structured JSON export of account, project and linked records in Settings. It includes storage references where they are recorded, but not the private uploaded image or file binaries themselves. Email privacy@twigged.design to request copies of those files, another accessible format, a broader copy of your personal data or, where technically feasible, direct transfer of portable data to another controller. The self-service archive does not limit your statutory rights. You can also start account deletion in Settings. We may ask for proportionate identity evidence. You can use our privacy complaints procedureor complain to the UK Information Commissioner’s Office at ico.org.uk.

11. Cookies and browser storage

Twigged currently uses authentication cookies and functional local or session storage, including the explicit pre-sign-in country choice, not advertising cookies, optional analytics cookies or replay storage. The names, purposes, controls and durations are in our Cookies and browser storage notice.

12. Automated suggestions

AI features make design suggestions, but they do not make decisions about you that produce legal or similarly significant effects. A designer remains responsible for reviewing horticultural, safety and client decisions before relying on an output.

13. Security

Measures used by Twigged include encrypted transport, managed encryption at rest, password hashing, authenticated access, row-level database rules, private storage for non-public files, rate limiting, minimised diagnostics and dependency maintenance. No online service is perfectly secure. If a personal-data breach occurs, we will assess it and notify affected controllers, people and the ICO where the law requires.

14. Children

Twigged is intended for professional use and is not directed to children under 16. Please do not create an account if you are under 16.

15. Changes and contact

We may update this notice as Twigged changes. We will update the date above and give account holders suitable advance notice of a material change. Questions, rights requests and objections can be sent to privacy@twigged.design. Complaints are handled under our privacy complaints procedure.