Privacy Policy
Last updated: April 2026
1. Overview
HerbAlly is a free, public resource — no account, registration, or login is required. We are committed to protecting your privacy and being transparent about what data we collect and how we use it.
2. Information We Collect
Because HerbAlly does not require accounts, we collect minimal data:
- Chat messages: Chat messages: Questions you type in the Virtual Herbalist are sent to our AI providers to generate responses. We do not store these messages on our servers.
- Usage analytics: Usage analytics: We collect anonymous, aggregate analytics (page views, popular herbs, general region) to improve the service. No personally identifiable information is collected.
- Cookies: Cookies: A single cookie (herbally-locale) stores your language preference (English or French). No tracking cookies are used.
We do not collect names, email addresses, or any other personal information. We have no accounts, passwords, or user profiles.
3. How We Use Your Information
- Provide and maintain our services
- Generate AI responses in the Virtual Herbalist (messages are not stored)
- Improve our herb database and AI responses using anonymous analytics
- Remember your language preference across visits
- Ensure the security and integrity of our platform
4. Third-Party Services
HerbAlly uses the following third-party services:
- Supabase — Database hosting (Canada region). Data stored: herb profiles, interaction data. No personal user data.
- OpenRouter — AI processing. Data sent: chat messages you type. Data stored: none (messages are processed and discarded).
- Vercel — Application hosting. Data stored: none (serverless functions). Vercel may collect anonymous CDN logs.
- Stripe — Payment processing for donations. HerbAlly never sees or stores your card details.
5. Cookies
HerbAlly uses a single cookie:
- herbally-locale — Stores your language preference (en or fr). Expires after 1 year.
We do not use Google Analytics, Facebook Pixel, or any third-party tracking cookies.
6. Data Retention
Since we do not collect personal data, there is no personal data to retain. Chat messages are processed in real-time and not stored. Anonymous analytics are aggregated and cannot be traced to individuals.
7. Your Rights (GDPR)
Even though we collect minimal data, we respect your rights under GDPR and other privacy laws:
- Right of Access: You can request information about any data we process.
- Right of Deletion: Since we do not store personal data, there is nothing to delete. Chat messages are never stored.
- Right to Complain: Contact our Data Protection Officer at privacy@herbally.app.
8. Security
We implement appropriate technical measures to protect our platform, including HTTPS encryption, Row-Level Security on our database, and regular security reviews.
9. Changes to This Policy
We may update this policy periodically. Changes will be posted on this page with an updated date.
10. Contact
For privacy questions, contact us at privacy@herbally.app.