Privacy Policy

Last updated September 14, 2026

The short version

Gnome collects what a neighborhood marketplace actually needs: a way to sign you in, the listings and photos you post, the messages you send about a pickup, and roughly where you are so we can show you what’s nearby. Neighbors see your display name, your town, and an approximate map pin — never your exact address unless you deliberately publish a public farm stand or business address, and never your email or phone number. We don’t sell or rent your information to advertisers or data brokers. Gnome may show Google-served ads in public discovery areas such as Browse, but not in selling, orders, messages, billing, or Zordy. Google handles the consent choices required for those ads. On the website only, Gnome also offers optional Meta Pixel measurement so we can tell whether Facebook and Instagram ads are working. The Pixel stays off unless you allow it, and it is not included in the iPhone or Android apps.

Who we are

Gnome (Gnome Farmers Market) is operated by Boone Systems LLC, Ohio, USA. This policy covers the Gnome mobile app and gnomefarmersmarket.com. Reach us any time at daniel@boonesystems.com.

What we collect

Account and contact details. Your email address — it’s how you sign in. On the website you can use a password or a one-time sign-in link; in the app you sign in with a code emailed to you, or with Apple or Google. When you first join, Gnome’s welcome conversation asks for your first name, last name, best email for order notices, and mobile number. A verified mobile number is required before posting, requests, messages, and Market setup unlock. Your full last name, contact email, and phone are kept in a private record that other users cannot read. What neighbors see is your display name. When you give us a first and last name — in the welcome chat, or later in your profile — we build that name ourselves as your first name plus a last initial, like “Daniel M.”, and the full last name never leaves the private record. If you signed in with Apple or Google, or skipped the welcome chat, your display name starts as whatever your account supplied (which may be a full name or the front of your email address) until you set it. You can change it at any time in your profile.

Your Market and profile. When you post, Gnome creates your Market — its name, description, photo and banner, your town, county and state, and any website or social links you add. You can also save a contact email, a phone number, and a pickup address for your Market. A private-residence or custom pickup address is owner-onlyand is released to a buyer only after you confirm their order. If you choose a public business or farm stand, you can deliberately show that address publicly.

Seed Drop waitlist. If you choose to join, we store the email address you provide, your five-digit ZIP code, the Drop size you would consider, whether you joined from the website, iPhone app, or Android app, and when you consented. If you are signed in, the entry is linked to your Gnome account. We use it only to measure launch demand and email you when Seed Drop opens in your area. Joining is not an order, reservation, subscription, or payment. To limit automated abuse, the server also keeps an opaque fingerprint made from request details for up to 24 hours; the raw IP address is not stored in the waitlist.

Listings, photos, and messages. Everything you write in a listing — title, description, category, price or trade terms, quantity, any promoted Market Deal, and up to five photos — plus the messages you exchange with a neighbor about a claim or a pickup, and any report or feedback you send us. Photos you upload are re-encoded before they leave your device, which strips camera metadata, including the GPS coordinates an iPhone stores in a photo.

Location. If you allow it, the app takes a single coarse reading of your device’s position to sort listings by distance, and can fill in your town, state, and ZIP for your profile. A listing you post from the app stores the coordinates you posted it from so distance math works — those exact coordinates are locked at the database level and are never readable by anyone but you and us. See Location, in detail below.

Orders, pickups, and deliveries. If you order from a seller, we store the items, times, and amounts of that order. If you save a delivery address, we store the address, any delivery notes, and coordinates for it so the seller’s delivery fee can be calculated. Delivery addresses are private to you; the seller receives the address for a specific order only once that order is confirmed.

Payments and subscriptions. Subscriptions started in the iOS app are processed by Apple, while website payments are processed by Stripe. Payment credentials are entered with those providers and never touch Gnome’s servers — we don’t see or store them. We keep the minimum subscription metadata needed to provide access: the plan or add-on, provider and transaction or subscription identifiers, status, billing period, environment, and amount where applicable.

Permits and seller credentials. Some categories require a license or permit. If you submit one, we store what you type — state, county, credential type, issuing agency, credential number, issue and expiration dates, and your notes — and the document file itself. See Seller permits and documents below.

Push notifications. If you turn them on, we store a push token for that device and which platform it is, so we can reach you about claims, messages, and orders.

Zordy and AI features. The garden planner, the listing assistant, the in-app help gnome, and the welcome conversation use AI. We store your side of those conversations and the assistant’s replies so the conversation has a memory, along with usage counts (which feature, how many requests, how long they took) to enforce daily limits and watch costs. We do not store the photos you send to an AI feature except as part of a draft listing you asked it to make.

Usage and diagnostics. Coarse product events — “listing created,” “claim started,” “order completed,” a ZIP typed into the website’s search box — so we can tell what people actually use. The Garden Planner usage event records only non-content metadata, such as the question length and whether a photo was attached, not the question text itself. There are no session recorders in the mobile apps or website. The website stores your sign-in session in your browser’s local storage. It also offers optional Meta Pixel measurement, described below. The Pixel and its cookies stay off unless you choose Allow measurement. When advertising is enabled, Google AdSense on the web or AdMob in the mobile Browse feed may receive an IP address, general location inferred from it, device and browser identifiers, ad interactions, and crash or performance diagnostics. Gnome’s mobile ad requests are configured as non-personalized and do not request the Android advertising ID.

Public, private, and administrative

Public. Your display name (“Daniel M.”, or whatever it is currently set to — see above), your avatar, your town, county and state, when you joined, your Market’s name, description, photos and links, your active listings with their photos and text, and an approximate map pin. Anyone on the internet can see these — no account required.

Private to you. Your sign-in email, your full last name, your contact email and phone, your exact coordinates, your delivery addresses, your Market’s exact pickup address, your saved payment relationship with Stripe, your device push tokens, your AI conversations, your permit documents, and your messages (visible only to you and the neighbor you’re talking to).

Administrative. Some records exist so Gnome can be run safely and legally: permit reviews and their decisions, moderation reports, account status, plan and billing state, and audit logs of admin actions. Gnome staff can see these. Other users cannot.

What goes to the AI provider — and what doesn’t

Gnome’s AI features run on Google’s Gemini models. Google is the only AI provider Gnome uses. Requests go from our servers to Google’s API — your device never talks to Google directly, and neither your account id nor your sign-in email travels with the request.

What is sent: what you type into an AI conversation; photos you deliberately attach to the listing assistant or the “check my plant” flow; the town or region you give the garden planner, after street addresses and exact coordinates are rejected, coarsened, or redacted; and a small, deliberately minimal pack of context about your own account — your Market’s name and plan, how many active listings you have, your town, county and state, and, if you have a seed order, its status, tracking number, and the varieties in it. So the assistant can tell you what neighbors are looking for, it is also given a count of recent public “wanted” posts by category in your state — aggregate demand, never anyone’s post text, name, or contact details.

What is not sent: your sign-in email, your password, your phone number, your exact coordinates, your delivery or pickup addresses, your permit documents, your payment details, or the contents of your private messages with neighbors. In the welcome conversation, any email address or phone number you type is stripped out of the text before it is sent to Google — the model never receives it. Your name is part of that conversation, because the assistant is asking for it.

We use Google’s free service tier, which does not carry the data-use protections of Google’s paid tier. Treat anything you send to an AI feature as something Google may review or use to improve its services. That is exactly why we keep what we send minimal — and why you should not paste anything sensitive into an AI chat.

How we use your information

To run the marketplace: showing your listings to neighbors, matching “wanted” posts to nearby offers, arranging claims, pickups, and deliveries, and sending the notifications you’d expect. To sign you in and keep your account yours. To calculate delivery distance and fees. To answer your AI questions and draft listings you asked for. To review seller permits where the law requires one. To bill paid plans. To keep the community safe — reviewing reports, blocks, and abuse. And to understand, in aggregate, which parts of Gnome people use, so we can make it better. We do not use your private account, Market, listing, message, location, order, payment, or AI content to build advertising profiles or send that content to an ad provider.

Who else handles your information

We keep the list short on purpose. Each of these does a specific job:

Supabase — our database, authentication, file storage, and server functions, hosted in the United States. Almost everything described above lives there. Supabase also delivers the sign-in emails.

Google — the Gemini models behind Gnome’s AI features, Google Sign-In if you choose it, Google Maps Platform for optional seller pickup-address suggestions, and Google AdSense or AdMob when ads are enabled. For address suggestions, Gnome’s server sends the partial address you type to Google; if you choose a suggestion, it requests the formatted address and coordinates. Your Gnome account id is not included in that provider request. Google processes this under its Privacy Policy and the Google Maps/Google Earth Additional Terms. Google’s advertising services may process the network, device, consent, ad-interaction, and diagnostic information described above under its own Privacy Policy. Gnome does not send Google your listing text, private messages, contact details, exact location, payment details, or AI conversations for ad targeting.

Meta Platforms — on gnomefarmersmarket.com only, and only after you choose to allow measurement, the Meta Pixel receives the page you visited, when you visited it, referral and ad-attribution information, browser and device details, network information, and a small set of conversion events such as creating a web account or successfully creating a listing. Gnome does not deliberately send Meta your name, email address, phone number, listing text, messages, exact location, or payment details. Meta may connect Pixel activity with information it already has and processes that information under its own Privacy Policy. The Pixel is not installed in the Gnome iPhone or Android apps.

Stripe — website payments and subscriptions. Stripe collects your card and billing details directly and keeps its own record of the transaction under its own privacy policy.

Apple — Sign in with Apple if you choose it, App Store subscriptions and purchase history, the app’s map view, and Apple’s geocoding when the app turns coordinates into a town name on an iPhone.

Expo — the push-notification service that relays alerts to your device (and from there through Apple or Google), and the over-the-air update service for the app. Push notifications travel through these services in readable form, and can include an item title, a neighbor’s display name, an order time and amount, or the first part of a chat message. If that matters to you, turn off notification previews on your phone’s lock screen, or turn Gnome notifications off entirely.

OpenStreetMap (Nominatim) — turns a buyer delivery address or a searched place name into coordinates. The address text is sent to that public service to be looked up; no account information goes with it.

Beyond these, we share personal information only when you ask us to, when it’s part of a transaction you started (a confirmed order releasing a pickup address to the buyer), or when we are legally required to. If Gnome is ever sold or merged, information would transfer with the business, and we’d say so here first.

Selling, ads, and tracking

We do not sell or rent your personal information for money, and Gnome may display Google-served ads in the public Browse experience. We keep those ads out of seller setup, posting, orders, messages, billing, and AI features. Mobile ad requests are non-personalized. On the website, Google’s consent message lets people consent, decline, or manage their ad choices where required. If you allow the optional Meta Pixel, its disclosure of website activity to Meta may count as “sharing” or targeted advertising under some state privacy laws. We use it to attribute, measure, and improve ads for Gnome on Facebook and Instagram. You can decline it before it loads, turn it off later, or use a Global Privacy Control signal. Sellers can also pay to boost their own Gnome listings. The other thing worth naming plainly is the AI provider’s free tier described above, where Google may use what is sent to improve its services.

Location, in detail

The app asks for location only when you use a feature that needs it, and takes a single balanced-accuracy reading rather than tracking you in the background. Coordinates attached to a listing are stored in a column that has been explicitly revoked from every client — the app and the website literally cannot read it. What is published instead is a rounded pair of coordinates, cut to two decimal places, which places you somewhere inside roughly a half-mile to a mile square. That is what the map pin, the browse list, and every distance figure are built from, which is also why distances are shown as approximate.

When a signed-in seller uses pickup-address suggestions, the partial address is sent through Gnome’s server to Google Maps Platform. If the seller selects a result, Gnome receives and stores its formatted address and precise coordinates so the pickup location can work on the map. The seller can instead type and save an address manually; that path does not call Google and clears any older coordinates rather than pretending the typed text was verified.

Your exact address only ever reaches another person because you chose to send it: a pickup address released to a buyer whose order you confirmed, a delivery address released to the seller who is bringing your order, or something you typed into a message. Photos are stripped of embedded GPS data before upload on both the app and the website.

Seller permits and documents

Permit and license documents go into a private storage area, not the public one. Only you and Gnome’s reviewers can open them, and reviewers do so through short-lived links rather than a permanent public address. Other sellers can never see them. We keep them because a reviewer needs to check the credential and because expiry has to be tracked. When you delete your account, your credential records and the uploaded documents are deleted with it.

How long we keep it

We keep your information for as long as your account exists. Listings that expire stay in your history as expired rather than vanishing; messages stay with the claim they belong to. When you delete your account, we delete your profile, listings, claims, messages, device tokens, credential records and documents, listing photos, AI conversations, contact record, and your product events. A few things survive: feedback you sent us stays, with your account link removed; Apple or Stripe keeps its own record of any payment it processed, which we can’t delete on the provider’s behalf; and the daily counters we use to rate-limit AI features still hold a per-day request count against your old account id. Those counters are a fix we owe you, not a decision.

To protect the seller address lookup from automated abuse, Gnome keeps the signed-in user id, whether the request was a suggestion or a selected-address lookup, and its time for about 24 hours. Those counters contain no address, search text, or Google place id and are also deleted with the account.

A Seed Drop waitlist entry linked to a signed-in account is deleted with that account. If you joined while signed out, or simply want to leave the list without deleting Gnome, email daniel@boonesystems.com from the waitlist address and we will remove it.

Meta controls how long it keeps activity already received through the Pixel under its own policy. Turning measurement off stops Gnome from sending new Pixel events from that browser and removes the known first-party Meta cookies from gnomefarmersmarket.com; it does not erase information Meta already received.

Google controls how long it keeps information processed by AdSense and AdMob under its own policy. Changing an ad-consent choice controls future ad processing; it does not require Google to erase information already processed for security, fraud prevention, reporting, or legal duties.

Deletion is not instantaneous everywhere. Our database provider keeps routine backups, so a copy of deleted rows can persist in those backups for a period before they cycle out. Photos are removed from storage as part of account deletion; deleting a single listing removes the listing but may leave the photo file reachable by its direct link for a while.

Security

Access to data is enforced in the database itself, row by row, rather than trusted to the app — that is why your private contact details, addresses, exact coordinates, and permit documents are unreadable by other users even if a screen misbehaves. Traffic is encrypted in transit, and our storage provider encrypts data at rest. Sensitive operations run on our servers with keys that never reach your device.

To be straight with you: messages between neighbors are not end-to-end encrypted. They are stored on our servers, and Gnome staff and our database provider are technically able to access them — we do so only to investigate abuse, a report, or a problem you asked us to look into. No system is perfectly secure, and we won’t pretend otherwise.

Your choices and controls

You can edit or delete any listing, edit or clear your profile and Market details, add or remove delivery addresses, block another user, report a listing or a person, and turn push notifications off in your phone’s settings or by declining the permission. Location permission can be revoked at any time from your phone’s settings; Gnome keeps working, it just can’t sort by distance. Email us for a copy of your data, a correction, a deletion, or removal from the Seed Drop waitlist, and we’ll take care of it.

For optional Meta measurement, use Privacy choices in the footer of any page. You can allow it, keep it off, or revoke a previous choice at any time. Gnome also treats an enabled Global Privacy Control browser signal as an instruction to keep the Pixel off. Your choice is saved in this browser’s local storage so we do not have to ask on every page.

Where Google requires an advertising choice, its consent message lets you consent, decline, or manage options before eligible ads are served. The mobile Browse ad includes a privacy-choices control whenever Google says one is required. You may still see limited, non-personalized ads after declining personalized advertising where the law permits them.

Deleting your account

In the mobile app, go to Profile → Settings → Delete my account. On the web, use gnomefarmersmarket.com/delete-account — sign in there and confirm. Either way it is permanent, it takes two confirmations, and it removes your listings and conversations for everyone, not just from your view. If you can’t sign in at all, email daniel@boonesystems.com from your account’s email address and we will delete it for you.

What Zordy can and can’t do for you

Zordy is a helpful gardener, not an authority. It guesses at plants, pests, and varieties from a photo and it is sometimes wrong. It does not know your local ordinances, your state’s cottage food or egg or meat rules, or whether a plant is safe to eat. Never rely on it to identify a foraged plant or mushroom, to judge whether food is safe, to diagnose an illness in a person or an animal, or to tell you what you are legally allowed to sell. Drafts it writes for your listing are yours to check before you publish — nothing is ever posted on your behalf without your approval, and you remain responsible for what your listing says.

Children

Gnome is not for children under 13, and we don’t knowingly collect information from them. You must be at least 13 to use Gnome and at least 18 to sell. If you believe a child under 13 has an account, email us and we will remove it.

State privacy rights

Depending on where you live — California, Colorado, Connecticut, Virginia, Utah, Texas, and a growing list of other states — you have the right to know what personal information we hold about you, to get a copy, to correct it, to have it deleted, and to not be treated worse for asking. Gnome does not sell personal information for money and does not profile you for decisions with legal effects. The optional Meta Pixel and some Google advertising activity may count as sharing or targeted advertising in some states. You can keep Meta measurement off through Privacy choices in the footer or by enabling Global Privacy Control, and use Google’s ad-consent controls where shown. To exercise any other right, email daniel@boonesystems.com — we’ll verify you through your account email and respond within the time your state allows. If we turn a request down, reply and tell us why you disagree; a person will look at it again.

Changes to this policy

When this policy changes we update the date at the top. If a change is material — a new category of information, a new company handling your data, a genuinely new use — we’ll say so here in plain language and, where it matters, in the app before it takes effect.

Contact

Boone Systems LLC, Ohio, USA — reach a human at daniel@boonesystems.com. Questions about this policy are always welcome, and so is being told we got something wrong.