Privacy Policy
Last updated: 2026-08-25. This expanded draft is currently being reviewed by an attorney and may change before it's finalized, particularly around jurisdiction-specific requirements (CCPA, GDPR, etc.).
1. Overview. This explains what StrainDex collects, how it's used, and your choices. We collect only what's needed to run the app and don't sell personal information to advertisers or data brokers.
2. What we collect. Account info (username, email, a securely hashed password, birth date to confirm age). User content (check-ins, tasting notes, food/drink/entertainment/activity pairings, photos, recipes, grow tips). Location, only when you use "find dispensaries near me" — not stored after the search. Basic technical/error logs. A single first-party session cookie to keep you logged in — no third-party ad-tracking cookies.
3. How we use it. To run check-ins, the strain library, recipes, growing tips, dispensary search, and friends features; to keep your account secure; to send account emails like password resets; to respond to feedback you submit; to fix bugs through error monitoring; and to generate aggregate, non-identifying usage stats.
4. Who we share it with. We don't sell your data. We use service providers who each process data only to provide their service to us: our database host, our app host, our photo storage provider, our transactional email provider, our error-monitoring provider, and a dispensary-location lookup service. We may also disclose information if required by law.
5. How long we keep it. As long as your account is active. If you delete your account, your personal data is removed; any recipe or grow tip you shared publicly stays up but is reattributed to "Former user."
6. Your rights. Export your data or permanently delete your account anytime from Account Settings. Update your info directly in the app.
7. Not for minors. The Service is for adults 21+ only and isn't directed at children. We don't knowingly collect data from anyone under 21.
8. Security. We use industry-standard measures — hashed passwords, encrypted connections — but no method of transmission or storage is perfectly secure.
9. State/international privacy laws. Specific disclosures required under laws like the CCPA or GDPR are being finalized with counsel and will be added here once confirmed.
10. Changes. We may update this policy; meaningful changes will be reflected here with a new "last updated" date.
Questions about this policy? Reach out through Send Feedback.