Skip to content

Last updated October 4, 2026

Privacy Policy

We keep this simple, but Daylily Catalog does collect some data so the site can work. This page explains what we collect, why we use it, who helps us process it, how long we keep it, and what control you have.

Data We Collect

Account data: your sign-in ID, email address, profile image, and basic account details from our sign-in provider.

Catalog data: grower profile details, public catalog copy, location, list names and descriptions, listing names and descriptions, prices, private notes, listing status, uploaded photo URLs, image order and status, list membership, and linked cultivar details.

Buyer inquiry data: buyer email, optional buyer name, message text, selected cart items, item quantities, item prices, and the seller being contacted.

Billing data: Stripe customer IDs, checkout and billing portal activity, subscription status, invoice and payment status. Stripe handles full card details, not Daylily Catalog.

Photo safety checks: when image moderation is enabled, we send a resized copy of the selected photo to OpenAI to check for unsafe content. Diagnostic logs can include the check result, category scores, file size, image type, and record identifiers. Some check events and errors also go to our analytics and error providers.

Site health and product usage data: page views, search terms and filters, button clicks, upload events, request metadata, browser or device information, error reports, performance information, and rate-limit data. Rate-limit data can include hashed IP-derived and email-derived keys.

Browser file tools can read and store files and work-in-progress data on your device. When a tool needs information from Daylily Catalog, it sends only the values needed for that request, such as names or saved identifiers used for matching. We do not send file contents through product analytics.

When you build a catalog preview, we can retain a limited diagnostic sample of the first six nonempty spreadsheet rows, the detected column mapping, and aggregate import results in server logs. We use this sample to troubleshoot and improve the importer. We do not retain the complete workbook through this logging.

AI Plugins And Remote MCP

Our plugin lets an AI client, such as ChatGPT or Codex, read public catalogs. If you connect your account, it can also read your own catalog. An active member who grants write access can create and edit listings and lists, add one listing to a list, link a cultivar, change basic profile fields, and reorder existing photos. A listing can become public when you ask the client to publish it.

Public tools may receive search text and filters such as cultivar name, hybridizer, color, parentage, seller slug, listing ID, listing slug, list ID, price filters, photo filters, cursor, and limit. They return public catalog, listing, image, list, seller, price, count, cultivar, and Daylily Catalog URL data.

Member tools require the user to connect their Daylily Catalog account. Those tools may receive IDs, cursor and limit values, and catalog filters like title, description, status, list ID, price, photo availability, cultivar name, hybridizer, year, color, parentage, bloom habit, bloom season, foliage type, form, fragrance, ploidy, and broad search text. Broad owner searches can search private notes.

Member tools may return data from the connected user account, including profile title, slug, description, rich profile content, location, record version timestamps, list IDs, list titles, list descriptions, list statuses, listing IDs in lists, listing titles, listing slugs, listing prices, listing descriptions, private notes, listing statuses, cultivar reference IDs, listing version timestamps, linked cultivar names and traits, image IDs, image URLs, image order, image status, and list membership.

Write tools receive the fields you ask to change. These can include titles, descriptions, prices, private notes, visibility, profile location, list and cultivar IDs, image IDs and order, a request ID for retry protection, and the current record version. Results return the saved record identifiers, changed catalog fields, record version, and dashboard links. OAuth client identifiers and granted permissions are used to check access. Tool results do not return sign-in identifiers, account emails, billing records, authentication tokens, or internal request logs.

Deletion, removal from a list, photo removal, and cultivar unlinking require review in the dashboard. Adding photos, changing the profile URL, and editing the profile story also use the dashboard. The client can receive a link with the relevant record IDs and screen location. Opening that link does not make the change. Remote tools do not send buyer messages, process payments, or upload image files.

Tool inputs and outputs go to the AI client you choose. OpenAI receives them when you use ChatGPT or Codex. Your client provider applies its own data controls and retention rules to those copies. Daylily Catalog receives the tool requests sent to our server, not your full conversation history or ChatGPT memories. We use these requests to complete your authorized catalog work.

To prevent duplicate creates, we store a hashed record identifier and a fingerprint of the create input. This receipt does not contain the full input. It has no automatic expiry. Deleting the created record does not delete its retry receipt.

How We Use Data

We use data to sign users in, run dashboards, publish public catalog pages, let buyers contact sellers, process memberships and billing, send transactional emails, prevent abuse, keep the site secure, understand product usage, fix errors, and complete authorized AI tool requests.

We do not sell personal data. AI tools can use private catalog data only for the connected account and the operations you authorize.

Recipients And Service Providers

We use service providers to run the site: Clerk for sign-in, Stripe for billing, AWS SES for email, PostHog for analytics when enabled, Sentry for error reports when enabled, Cloudflare for web delivery and R2 image storage, AWS S3 for older photos and database backups, Turso for databases, and our hosting providers for app operation. OpenAI processes photo safety checks when enabled. The AI client provider you connect also receives tool data, including OpenAI when you use ChatGPT or Codex.

Buyer inquiries are emailed to the selected seller and may also be copied to Daylily Catalog admin inboxes for abuse prevention, delivery troubleshooting, and support.

Public catalog data is intentionally visible to anyone who can view the public catalog pages or call public read-only tools.

Retention

We keep account, profile, list, listing, image, and catalog data until the user deletes it or asks us to remove it. Hiding a record removes it from the public catalog but keeps it in the account. Public pages and caches can take a short time to update. Deleted data can remain in database backups until those backups are removed. Create-request retry receipts have no automatic expiry.

Billing records are retained for operational, tax, accounting, and legal reasons. Buyer inquiry emails are retained by the email recipients and email providers. Rate-limit buckets store hashed keys and timestamps for abuse prevention. Logs, analytics, and error reports are kept only as long as needed for operations, security, debugging, and product improvement.

Work saved only in your browser remains on that device until the tool clears it or you clear the browser's site data.

User Controls

Growers can edit profile, list, listing, private note, price, status, and image data in the dashboard. Growers can hide listings or lists from the public catalog by changing their status.

Users can manage billing through the Stripe billing portal. Users can disconnect or revoke ChatGPT app access from their ChatGPT or connected-app settings. Disconnecting stops future tool access; it does not delete copies already held by the AI client provider. Users can contact us for help with access, correction, export, deletion, or account closure.

Contact

For privacy requests or questions, contact [email protected].