The data controller within the meaning of applicable data protection law (including GDPR) is:
We have not appointed a data protection officer; the threshold in Section 38(1) of the German Federal Data Protection Act (BDSG) — as a rule, at least 20 people permanently engaged in automated processing — is not met.
Your username, display name, streak and league standing are visible to other users you're connected with (friends, league members) as a core part of how the app works.
When you complete a daily challenge, your photo is sent securely to our backend and forwarded once to Cloudflare's Workers AI for automated analysis (checking whether the photo is outdoors, real, and matches the challenge). Only the photo and the challenge text are sent — no name, email address or account identifier is part of that request. The verdict (accepted/rejected and a score) is recorded against your account. We do not store the photo, on our servers or anywhere else. Cloudflare says it does not use the photo to train its models — see Cloudflare's data-usage notes for details.
We use the following services to run Touching Green. Each processes a limited slice of data as described above, under their own privacy terms:
We process account, progress and social data under Article 6(1)(b) GDPR (necessary to provide the app's core functionality). Optional ad tracking is processed only with your consent (Article 6(1)(a) GDPR / App Tracking Transparency), which you can withdraw anytime in your device's Settings.
The check described in Section 3 runs without any human involvement: an AI model decides whether your photo satisfies the daily challenge, and that determines whether your leaf is credited and your streak keeps running. This decision affects nothing beyond your progress inside the app; it carries no legal effects and no similarly significant impact within the meaning of Article 22(1) GDPR. Automated assessments can still get it wrong — if you think a rejection was incorrect, write to us and we will look at it personally.
Usernames and display names are also checked automatically against a list of prohibited terms. Here too the choice stays with you: if a name is rejected, you can pick a different one or contact us.
Some of the providers listed in Section 4 process data outside the European Union, in particular in the United States. For those transfers we rely on the following safeguards under Chapter V GDPR:
We have data processing agreements under Article 28 GDPR in place with all of the providers named above that process data on our behalf and on our instructions. You can request a copy of the relevant safeguards from us.
Despite these safeguards, it cannot be entirely ruled out that authorities in third countries will access data on the basis of the law applicable there. For the photo check that risk is limited by the fact that the request sent to Google contains no account data whatsoever — no name, no email address, no user ID.
We keep your account and progress data for as long as your account exists. To delete your account and associated data, contact us via the Help page — we will process deletion requests within a reasonable time, except where we're legally required to retain certain records (e.g. for accounting purposes).
Depending on your location, you may have the following rights under GDPR or similar laws:
To exercise any of these rights, contact us via the Help page or at jonas.polenz@software-development.net.
If you are in the EU, you have the right to lodge a complaint with your local data protection supervisory authority. If you are in Germany, you can contact the supervisory authority of your federal state — a list is available at the Federal Commissioner for Data Protection (BfDI).
Touching Green is 16+. The app is not directed at children, and we do not knowingly collect personal data from anyone under 16. The reason for this age limit is Art. 8 GDPR: from 16 you can validly consent to the processing of your data yourself; use below that age would require parental consent, which we do not support.
We ask for your date of birth when you register. We process that information solely in order to enforce the age limit (Art. 6(1)(c) and (f) GDPR); all we store is the fact that the check was passed, together with the time of that confirmation.
If you believe that a minor has created an account, please contact us — we will block it and delete the associated data.
This Privacy Policy may be updated when significant changes are made to the app or the services we use. The current version is always available on this page, and significant changes will be communicated within the app.