SlowStem
SlowStem

Privacy Policy

Last updated: July 4, 2026

SlowStem is the anti-doomscroll plant community, and that philosophy extends to your data: we collect what’s needed to run the service and nothing more. We don’t sell your personal information, we don’t show ads, and we don’t use third-party advertising trackers or analytics.

1. Overview

This policy explains what SlowStem (operated by SlowStem LLC, a Virginia limited liability company — “we,” “us”) collects when you use the site, how it’s used, and the choices you have. It applies to everything on SlowStem: the community feed, the marketplace, the daily game, and messaging.

SlowStem is operated from, and intended for users in, the United States, and your data is stored in the United States. We don’t target the service to users in the European Economic Area or the United Kingdom.

2. What we collect

  • Account: email address, username, and password (stored as a secure hash by our auth provider — we never see your plain-text password). If you enable two-factor authentication, the related security factors.
  • Profile: display name, bio, avatar, favorite genera, and anything else you choose to add. Your profile, posts, and collection showcase are visible to other members.
  • Content you create: posts, photos, comments, likes, listings, wants, reviews, reports, and direct messages.
  • Marketplace activity: listings, offers, orders, and order status. If you buy something, the shipping address you enter at Stripe checkout is shared with us and the seller so the plant can reach you. If you sell, your city (if you list one for local pickup) is shown with your listings and converted to approximate map coordinates so buyers can search by distance.
  • Game and collectible activity: Sprout plays, streaks, seeds, and Plant Mail collectibles.
  • Preferences: notification and email settings, saved posts, follows, blocks, and mutes.
  • Technical data: our hosting provider (Vercel) keeps standard server logs (IP address, browser type, pages requested) for security and reliability. We do not run analytics or tracking scripts on top of that.

We also show a short reminder at the point of collection when you do something that shares more sensitive data — for example, entering a shipping address, turning on distance-based local search, or starting seller verification — so it’s clear what is being collected and why.

3. How we use it

  • To run SlowStem — accounts, feed, marketplace, game, messages.
  • To send the emails you’ve chosen in your notification settings (and essential account emails like password resets).
  • For safety: reviewing reports, enforcing the Community Guidelines and Terms, and preventing fraud and abuse.
  • To comply with legal obligations.

We don’t use your data for advertising, and we don’t train AI models on your content.

4. Who we share it with

Other members:your public profile, posts, comments, listings, ratings, and shop page are visible to others. When you buy or sell, the other party sees what’s needed to complete the order (usernames, order details; the seller sees the buyer’s shipping address).

Service providers that process data on our behalf, under their own contractual and legal safeguards:

  • Supabase — database, authentication, and photo storage.
  • Stripe — payment processing, seller onboarding and payouts, and subscription billing (see Stripe’s privacy policy).
  • Resend — sending email notifications.
  • Vercel — hosting and server logs.
  • OpenStreetMap Nominatim — when a city name is typed for a listing or a local search, that city text (never your account identity) is sent to the geocoding service to find its coordinates.

Legal:we may disclose information if required by law, or to protect the safety and rights of SlowStem and its members. If SlowStem is ever acquired or merged, member data may transfer as part of that transaction under this policy’s protections.

5. Payments

Card details go directly to Stripe on Stripe’s own pages — we never see or store your card number. Sellers complete identity verification through Stripe or another verification provider. Depending on the marketplace and verification process, SlowStem may receive or access seller identity, contact, tax, banking-verification, and account-status information needed to operate the marketplace, prevent fraud, make payouts, and comply with law. We do not receive a seller’s full bank login credentials or a buyer’s full card number.

6. Cookies and local storage

We use only essential cookies: the authentication cookies that keep you signed in. Your light/dark theme choice is stored in your browser’s local storage. There are no advertising, analytics, or cross-site tracking cookies. We currently use no nonessential cookies.

7. Private messages

Direct messages are private between you and the recipient — they’re not visible to other members. They are stored on our servers and are not end-to-end encrypted. SlowStem personnel may access messages where reasonably necessary to investigate a report, prevent fraud or abuse, provide support you’ve asked for, protect users or the service, or comply with law. Please don’t share sensitive information (like card numbers) in messages.

8. Retention and deleting your account

We keep your data while your account is active. You can permanently delete your account at any time from Settings — this removes your profile, posts, comments, collection, and game progress. Some records survive deletion where the law or the integrity of past transactions requires it — chiefly order and payment records (kept for tax and accounting), and reports needed for safety. Most accounts can be deleted directly in Settings; accounts with marketplace history may require an assisted closure so we can remove the public account while retaining legally required transaction records. Stripe retains its own transaction records under its policies.

Roughly how long we keep the main categories of data:

CategoryApproximate retention
Account and profileLife of the account, plus a short backup window
Posts, photos, comments you deleteRemoved promptly; backups expire within ~30 days
Orders and tax recordsUp to 7 years, or as tax/accounting law requires
Reports and enforcement recordsA limited period based on severity
Server / security logsTypically 30–180 days, longer if needed for an investigation
Direct messagesLife of the account, subject to deletion and backup expiry
Legal acceptance recordsLife of the account, plus a limited period afterward

These are our targets; where the law requires a longer period, that controls.

9. Your rights and choices

  • Access and correction: most of your data is directly visible and editable in your profile and settings. You can ask us for a copy of the rest.
  • Deletion: delete your account at any time from Settings (§8).
  • Email choices: notification emails can be turned off per-category in Settings → Notifications.
  • State privacy rights:where the CCPA or another applicable privacy law applies, residents may have rights to access, correct, or delete personal information and to exercise them without discrimination. Even where we’re not legally required to, we generally try to honor reasonable access, correction, and deletion requests. We don’t sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of.

How to make a request. Email support@slowstem.co from the address on your account (or tell us how to reach the account) so we can verify it’s really you; an authorized agent may act for you with your written permission. We aim to respond within 45 days and will tell you if we need more time. We may decline a request where the law lets us — for example, records we’re required to keep — and will explain why. Where a right of appeal applies, we’ll tell you how to appeal.

10. Children

SlowStem is an 18+ service. It isn’t directed to children, and we don’t knowingly collect data from anyone under 18. If you believe someone under 18 has an account, contact us and we’ll remove it.

11. Security

All traffic is encrypted in transit (HTTPS). We use access controls, including row-level security, designed to restrict unauthorized access to data, and optional two-factor authentication is available in Settings. No system is perfectly secure — if we learn of a breach affecting your data, we’ll notify you as required by law.

12. Changes to this policy

If we change this policy in a material way — for example, adding a new category of data collection — we’ll give notice on the site or by email before the change takes effect. The “Last updated” date above always reflects the current version.

13. Contact

SlowStem LLC (Virginia). Privacy questions and requests: support@slowstem.co. Signed-in members can also use the in-app Send feedback form.