Legal
Privacy policy
Linny is built so that most of what you do never leaves your phone, and the parts that do are reduced before they go. This policy explains exactly what happens to your data, the legal basis for each use, and how to exercise your rights under the General Data Protection Regulation (GDPR).
In effect 24 July 2026
1. Who we are
Linny is operated by Touch Grass AB, reg. no. 559484-7435 (Sweden). For the purposes of the GDPR, Touch Grass AB is the data controller for the personal data described in this policy. You can reach us about anything on this page at privacy@touchgrass.consulting.
2. The short version
Three things govern everything below, and the rest of this document is detail underneath them:
- On-device by default. Your spots, your finds, your photographs and your multi-year journal are stored on your phone. They are not uploaded to run the forecast — the forecast runs against public environmental data, not against your records.
- Private is structural. A spot you keep private cannot reach any public surface, because the code that produces anything public has no field that can carry an exact coordinate. It is not a setting you have to trust yourself to have set.
- We never sell your data, and we do not use it for advertising or share it with advertisers or data brokers.
3. What we process
We handle the following categories of data.
Account data. If you create an account, we hold an anonymous account identifier and, if you choose to sign in with Apple, the identifier Apple returns to us. If you claim a username for public sharing, we hold that username. We do not require your real name.
Location. With your permission, the app reads your device location to centre the map, to record a spot where you are standing, and to time-and-place-stamp a find. Location is processed on the device. A precise coordinate leaves the device only when you deliberately share a find, and then only in the coarsened form described in section 6 — never as an exact private coordinate.
Your collection. Spots, finds, no-find visits, notes, photographs and the weather-and-terrain snapshot recorded at the moment you log — stored on the device. You can export a copy at any time (see section 11); it is not uploaded to us.
Entitlement data. Whether you hold a membership, handled through Apple’s App Store and our subscription provider. We receive the fact of a valid entitlement and its renewal state. We do not receive your card number.
Diagnostics. If you opt in, crash reports and basic technical diagnostics, which do not include your spots or their coordinates.
Waitlist. If you ask to be told when the app is available, we hold the email address and the province you gave, for that single purpose.
4. Legal bases
Under Article 6 of the GDPR we rely on the following bases:
- Contract (Art. 6(1)(b)) — to provide the app and your membership: your account, your collection, and your entitlement.
- Consent (Art. 6(1)(a)) — for device location, for opting in to diagnostics, for making a spot or a find public, and for joining the waitlist. You can withdraw any of these at any time, and withdrawing is as easy as giving it.
- Legitimate interests (Art. 6(1)(f)) — to keep the service secure and to prevent fraudulent or abusive use. Where we rely on this basis we have weighed it against your interests, and you may object (section 12).
Photographs you choose to attach to a find may show people or reveal precise places. Handling them is covered by the consent you give when you enable photo logging; you control which finds carry a photograph and whether any find is ever shared.
5. On your device
The forecast is computed from public environmental data — terrain derived from the national laser scan, and live weather from national services. Producing a read for a place does not require uploading your spots, and it does not. Your collection stays on the device, and the engine that scores the ground runs on the device.
This is why the app can tell you, honestly, that most of what you record never leaves your phone. It is an architectural fact, not a promise about our conduct.
6. Spots and the firewall
Every spot has a visibility that is fixed at the moment you write it. A private spot is private for good: nothing in the app moves data from private to public on its own — no update republishes you, and a lapsed membership never exposes a private spot.
When you deliberately share a find, what leaves the device is a card carrying a species, a season and a province — nothing more. The card is constructed without any field that can hold a coordinate, so an exact location cannot travel with it even in principle. This is the firewall referred to throughout Linny, and it is enforced in the structure of the code rather than by a rule we ask ourselves to follow.
If you claim a username and publish a find, that find is associated with your username at the coarse precision described above. You can stop publishing at any time; already-published coarse cards are covered by your erasure rights in section 12.
7. Forecast improvement
The forecast is computed from public environmental data, not from your collection (section 5). We do not currently pool your records to train anything.
If in future we want to use find and no-find records to improve forecast quality, we will do so only after de-identifying them — stripping your identity and coarsening any location below the resolution at which a spot could be reconstructed — and we will update this policy and tell you before that starts, so you can object first. We will not turn your private records into a public map.
8. External data we read
The forecast reads from public data published by national bodies. Fetching a forecast for a location involves sending that location to the relevant service so it can return the weather for it. These services are independent controllers for any data they log about such requests, under their own terms:
- Lantmäteriet — national elevation model (terrain), processed by us in advance.
- SMHI — weather observations and lightning data.
- MET Norway — ten-day forecast data.
- Naturvårdsverket — national land cover, processed by us in advance.
Terrain is prepared ahead of time and served as small map tiles, so reading the ground for a place does not tell us which place you looked at beyond ordinary tile requests.
9. Processors we use
We use a small number of service providers who process data on our behalf, under written agreements that bind them to act only on our instructions and to protect the data to GDPR standard:
- Apple — App Store distribution, Sign in with Apple, and subscription billing. Apple processes your payment; we never receive card details.
- Our subscription-management and infrastructure providers — to confirm entitlements and serve map tiles. These providers store data within the EU/EEA where feasible.
A current list of processors is available on request from privacy@touchgrass.consulting.
10. International transfers
We aim to keep personal data within the EU/EEA. Where a processor necessarily handles data outside the EEA — for example a global platform provider — that transfer is covered by an adequacy decision or by the European Commission’s Standard Contractual Clauses together with supplementary safeguards. You can ask us which mechanism applies to a given transfer.
11. How long we keep things
Your collection stays on your device for as long as you keep the app installed. It is yours; we do not delete it, move it, or alter it. A lapsed membership revokes access to paid features — it never destroys what you recorded (see the immutability principle below).
Account and entitlement data are kept while your account exists and for a short period afterwards as required to meet tax and accounting obligations.
Waitlist data is deleted once the app is generally available in your region or on request, whichever comes first.
Immutability. A log’s visibility is stamped when it is written and is never changed retroactively, and nothing you have recorded is silently altered or removed. Genuine deletion is always available to you as a deliberate act — see the next section.
12. Your rights
The GDPR gives you the following rights, and the app is built to honour them:
- Access — a copy of the personal data we hold about you.
- Portability — your collection exported in a portable, machine-readable format.
- Rectification — correction of anything inaccurate.
- Erasure — deletion of your data. The app provides a direct “delete everything” action that removes your collection and account; this is a separate, deliberate flow, precisely so that it never happens by accident and never happens merely because a membership lapsed.
- Restriction and objection — including objecting to any future forecast-improvement use described in section 7.
- Withdraw consent — at any time, for location, diagnostics, public sharing or the waitlist, without affecting the lawfulness of processing before you withdrew.
To exercise any right, write to privacy@touchgrass.consulting. We respond within one month. Much of this — export, and full deletion — you can also do yourself from within the app without contacting us.
If you believe we have handled your data wrongly you have the right to complain to your supervisory authority. In Sweden this is Integritetsskyddsmyndigheten (IMY), imy.se. We would ask you to raise it with us first so we can put it right.
13. Children
Linny is not directed at children and is intended for adults who forage. We do not knowingly collect data from children under the age of digital consent in their country (13 in Sweden). If you believe a child has provided us data, contact us and we will delete it.
14. Security
Keeping your collection on the device is itself the strongest privacy measure available: data that is not transmitted cannot be intercepted in transit or breached at rest on a server. Where data does move — an entitlement check, or a copy you choose to export — it travels over an encrypted connection. We limit access to any personal data to those who need it, and we weigh any future crowd feature against the reconstruction risks in section 7.
15. Changes to this policy
If we change how we handle data we will update this page and, for material changes, tell you in the app before the change takes effect. The date at the top shows when the current version came into effect. This version is effective 24 July 2026.
16. Contact
Questions, requests and complaints about your data go to privacy@touchgrass.consulting, addressed to Touch Grass AB as data controller.