Lustig Fairchild
Tokonoma · Version 1.0 · Effective 15 August 2026
Most privacy policies are long because the app behind them collects a great deal and the document has to account for all of it. This one is short for the opposite reason. Tokonoma has no account, no server and no analytics. Nothing you record about your trees is ever sent to us, and there is nothing about you for us to hold.
This summary is written to be read. The sections below are the full statement, and where the two differ, the sections govern.
The apps described here are published by Lustig Fairchild, an independent app developer established in Bulgaria, in the European Union. For the purposes of the General Data Protection Regulation, Lustig Fairchild is the controller of any personal data processed in connection with the apps — which, as the rest of this document explains, is none.
Lustig Fairchild is a trading name used by a single natural person, whose identity is registered with Apple as the seller of the apps and is available to a supervisory authority on request.
Lustig Fairchild
Bulgaria, European Union
lustigfairchild@abv.bg
Writing to support@tokonoma.app reaches the same address. Please put the app's name in the subject line. We have not appointed a Data Protection Officer, and are not required to: we carry out no large-scale or systematic processing of personal data.
This policy covers, and covers only:
The two are separate apps sharing one codebase. Everything in this document is true of both. Other apps published by Lustig Fairchild have their own policies and behave differently; nothing here should be read as describing them.
We collect no personal data whatsoever. We do not receive your name, your email address, a device identifier, an advertising identifier, an IP address, a crash report, a usage statistic, or any information about your trees.
This is not a policy choice that could quietly change with an update. It is a property of how the app is built. The app contains no networking code of any kind — no HTTP client, no embedded web view, no analytics framework, no advertising framework, no software development kit from any third party. There is no address for your data to be sent to, because the app has no ability to send it.
The one network capability present is Apple's iCloud synchronisation, described in Section 5. It moves your records between your own devices, through your own Apple account. It does not pass through us.
Everything the app holds is stored locally on your device, in the app's own private storage area, which other apps cannot read.
| What | Where it is kept | Who can read it |
|---|---|---|
| Your plants — names, species, style, stage, the year you acquired them, and the photograph you chose for each | On your device; also in your private iCloud if sync is on | You, on your own devices |
| Your diary entries, milestones and notes | On your device; also in your private iCloud if sync is on | You, on your own devices |
| Your growth measurements — trunk, nebari, height | On your device; also in your private iCloud if sync is on | You, on your own devices |
| Your care sheets, including any edits you make to the seeded species guides | On your device; also in your private iCloud if sync is on | You, on your own devices |
| Three small settings: whether you have seen the language picker, how you prefer plants sorted, and your chosen interface language | On your device only, in the app's standard preferences store | You |
None of this is personal data about you in the ordinary sense — it is a record about trees. It becomes personal data only in the sense that it belongs to you and sits on your device. We hold no copy of any of it.
If you are signed in to iCloud and have iCloud Drive enabled, the app keeps your records in step across your iPhone, iPad, Mac and Apple Vision Pro. This uses Apple's CloudKit private database.
The word private is doing real work there. A CloudKit private database sits inside your own Apple account. The developer of an app has no access to it: we cannot read it, list it, export it, or know that it exists. We receive no notification when you add a tree, and no count of how many you keep.
Apple processes this data as part of providing iCloud to you, under Apple's own privacy policy and your iCloud terms — a relationship between you and Apple, not one we are party to.
You can turn sync off at any time in Settings → [your name] → iCloud on iOS, or System Settings → [your name] → iCloud on macOS. With sync off, the app keeps working and your records simply stay on the one device.
The app declares the background capability that lets Apple wake it to deliver silent iCloud change notifications. This exists solely so that a change made on your iPad appears on your iPhone. It carries no message content, and no push notification from us — we have no means of sending you one.
You can attach a photograph to each plant. The app uses Apple's system photo picker, which runs outside the app, in a separate process. You see your library; the app does not. Only the single image you deliberately choose is handed back.
Because of this, the app never requests access to your photo library, and iOS never shows you a permission prompt for it. The app in fact declares no system permission requests at all — no photos, no camera, no location, no contacts, no microphone. If you are ever prompted for a permission by something claiming to be Tokonoma, it is not our app.
Photographs you attach are stored with your plant records, on your device and in your own iCloud. Any location or camera information embedded in a photograph by your camera stays inside that image file, in your own storage, and is neither read nor used by the app.
The app can send you four notifications a year — one at each solstice and equinox, suggesting you photograph your trees. They are off until you switch them on, and they are the only notifications the app sends.
These are local notifications: they are scheduled by the app on your own device and delivered by your own device. They do not come from a server, they involve no message being sent to or from us, and no notification token of yours ever reaches us.
Under Article 6 GDPR a controller must have a lawful basis for each processing operation. We carry out almost none, and the table below is short as a result.
| Operation | Lawful basis |
|---|---|
| Storing your plant records, diary and photographs locally on your own device so the app can function | Art. 6(1)(b) — performance of the contract you entered into when you installed the app. This is also arguably outside the GDPR's scope entirely, being processing you carry out on your own device for your own purposes. |
| Synchronising those records through your own iCloud account | Art. 6(1)(a) — your consent, given by signing in to iCloud and enabling it, and withdrawable at any time in your device settings. |
| Sending you four seasonal photography reminders | Art. 6(1)(a) — your consent, given at the iOS notification prompt, withdrawable at any time in Settings. |
| Replying to an email you send us | Art. 6(1)(f) — our legitimate interest in answering correspondence addressed to us. We keep only the message you sent. |
Article 11 applies to us. We do not, and cannot, identify any user of the app. We hold no identifier that would let us connect a person to any data, because we hold no data. We are therefore not obliged to acquire additional information about you purely in order to comply with the Regulation — and we will not do so, since collecting identifying information in order to prove that we hold none would be absurd.
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), and the right to withdraw consent at any time (Art. 7(3)).
We want to be straightforward about what these mean here. We cannot fulfil an access or erasure request in the usual way, because we hold nothing to disclose or erase. That is not an evasion; it is the whole design of the app. What you actually have is more direct than a request to us:
If you believe we hold personal data about you, write to us and we will answer honestly and promptly. You are also entitled to complain to a supervisory authority — see Section 18.
The apps are suitable for all ages and are not directed at children in particular. They collect no personal data from anyone, of any age, which means they collect none from children. No parental consent mechanism is required under Article 8 GDPR or under the United States Children's Online Privacy Protection Act, because there is no collection to consent to.
We transfer no personal data anywhere, internationally or otherwise, because we receive none. Chapter V of the GDPR is therefore not engaged on our side.
Where your own iCloud data is physically stored is a matter between you and Apple, governed by Apple's privacy policy and the iCloud terms you accepted. We have no involvement in, visibility of, or control over it.
We operate no retention period, because we retain nothing. Your records persist for exactly as long as you keep them, on your device and in your iCloud, and vanish when you delete them.
If you write to us by email, we keep that correspondence only as long as needed to deal with what you wrote about, and no longer than 24 months afterwards, unless a longer period is required to establish, exercise or defend a legal claim.
The strongest security measure available to an app is not to hold data at all, and that is the one we have taken. Beyond it, your records rest on the protections your own device provides: the app's private storage area, isolated from other apps, and the device encryption that applies when your device is locked with a passcode, Face ID or Touch ID. Data in your iCloud is protected by Apple's encryption in transit and at rest.
We keep no database, so there is no database of ours to breach. In the unlikely event of a personal data breach affecting anything we do hold — realistically, only email correspondence — we will notify the Bulgarian supervisory authority within 72 hours as required by Article 33, and notify affected individuals directly where Article 34 requires it.
On the App Store, both apps are declared as “Data Not Collected”. We commit in this document to that declaration remaining accurate. Apple's label concerns data collected by the developer or its third parties; since we and our third parties collect none, the label and this policy say the same thing.
If a future version of either app ever needed to collect anything, this policy would be revised and the App Store declaration updated before that version shipped — not after.
We collect no personal information as defined by the California Consumer Privacy Act, and none of the categories listed in Cal. Civ. Code § 1798.140. We have not sold or shared personal information in the preceding twelve months, and we do not sell or share it now. We collect no sensitive personal information, including no precise geolocation. Because we collect nothing, we have no obligation to offer a “Do Not Sell or Share My Personal Information” link — but you retain your rights to know, delete, correct and to non-discrimination, and may exercise them at the address in Section 18.
The UK GDPR and the Data Protection Act 2018 apply on materially the same terms as set out above. UK residents may complain to the Information Commissioner's Office, ico.org.uk.
The revised Federal Act on Data Protection applies on materially the same terms. The competent authority is the Federal Data Protection and Information Commissioner.
The Lei Geral de Proteção de Dados applies on materially the same terms. We carry out no processing operation requiring a Brazilian representative.
PIPEDA applies on materially the same terms. No personal information is collected, used or disclosed.
The Privacy Act 1988 and the Australian Privacy Principles apply on materially the same terms. No personal information is collected, and no APP entity handling occurs.
The Act on the Protection of Personal Information (Japan) and the Personal Information Protection Act (South Korea) apply on materially the same terms. No personal information is collected, and none is transferred to a third party.
If this policy changes, the version number and effective date at the top of the document change with it, and the current text always lives at tokonoma.app/privacy/.
We will not make a change that begins collecting personal data quietly. Any such change would be announced in the app's release notes and reflected in the App Store privacy declaration before the version making the change was released.
Lustig Fairchild
Bulgaria, European Union
lustigfairchild@abv.bg
Write to us about anything concerning your data, this policy, or the apps generally. We answer personally.
If you are in the European Union and believe your data protection rights have been infringed, you may lodge a complaint with a supervisory authority — in the Member State where you live, where you work, or where the alleged infringement took place. Our lead supervisory authority is the Commission for Personal Data Protection of Bulgaria (Комисия за защита на личните данни), cpdp.bg.
Matters about the licence itself, rather than about data, are dealt with in the End User Licence Agreement.