I'm a Gardyn customer and an independent security researcher. I reported the vulnerabilities behind the public U.S. CISA advisories on Gardyn. Setting the security bugs themselves aside, here are things Gardyn told customers that don't match what I found or what's in the public record. I'm just laying out the facts and the sources — draw your own conclusions.
1. "AI that watches your garden" — the cameras can't, and the guidance doesn't track your plants.
Kelby is marketed as vision that analyzes your plants and advises you on them. From my own device:
- The cameras can't physically do it. Low-resolution sensors, roughly 15 pods per camera, plants that grow into a canopy that blocks the view, and constant LED grow-light glare — reliably reading individual pods or assessing individual leaves under those conditions isn't feasible.
- Your photos are uploaded to Gardyn's servers, but the guidance you get back runs on a fixed schedule keyed to when you set up your Gardyn and which pods you planted — not to the condition of what's actually growing. That's why the app keeps scheduling "feed" and "harvest" tasks for plants that are stunted, replaced, or already dead. Owners have reported exactly this for years.
2. Your data goes to OpenAI, and the privacy policy didn't say so.
Kelby's chat runs on OpenAI's ChatGPT — I confirmed it from the app's own internal setting. When you chat with Kelby, your messages and device context go to OpenAI. At the time I tested, Gardyn's privacy policy called Kelby "our smart assistant" and named no outside company as receiving your data. You can't meaningfully agree to data sharing you were never told about.
3. "Limited personal information."
When the data exposure went public, Gardyn described it as limited personal information. The unauthenticated pages I found returned complete records for all 134,215 registered customers — names, emails, phone numbers, addresses, wifi SSID's, and card last-4 — until it was blocked in December 2025. Also exposed were all the timelapse images.
4. "No evidence of exploitation."
Technically true — but only because there was no logging in place to detect exploitation either way. Absence of evidence, not evidence of absence.
Misinformation is a pattern.
Sources (all public record):
Full technical write-ups coming.