Privacy Policy
Last updated: Aug 2, 2026
Summary
Greenlight helps friends coordinate availability, chat, share media, organize groups, and plan events.
Data we collect
- Account and profile: your username, name, login-provider identifiers and verified email address when provided, profile photo, subscription status, and optional visual theme. Discord may provide a profile-photo candidate that only you can choose to copy into your Greenlight profile. Some theme names express identity or solidarity preferences.
- Local-account security: if you choose username/passphrase sign-in, Greenlight stores a memory-hard password hash and hashes of your one-time recovery codes. Your passphrase and the displayed recovery codes are never stored in readable form. A local account does not require an email address.
- Social and app activity: contacts, contact requests, groups and membership, availability status, events, invitations, attendance, posts, comments, and reactions.
- Messages and content: chat messages, polls, voice messages, and photos, videos, or files you choose to send or upload.
- Safety and moderation: users you block, reports you submit, a snapshot of reported content, and records of moderation actions needed to investigate abuse and enforce the Community Guidelines.
- Notifications: optional browser, Apple, or Firebase device registrations used to deliver the notifications you enable.
- Calendar choices: your calendar-sync preference and identifiers needed to update or remove Greenlight events from a calendar you select. Calendar access stays under your device's permission controls.
- Service and security data: session information and limited technical logs needed to operate, secure, diagnose, and prevent abuse of the service.
- GIF search: optional search terms you submit to find a GIF. These are relayed to Giphy, and the selected media is loaded from Giphy.
How we use your data
- Provide Greenlight: authenticate you, deliver messages and media, coordinate groups and events, sync features you request, and send enabled notifications.
- Security and integrity: prevent abuse, investigate problems, and keep the service reliable.
- Support: respond when you contact us and process account or data requests.
Device permissions
Greenlight asks for permissions only when a related feature needs them. These may include notifications, camera, microphone, photo or file selection, and calendar access. You can change permissions in your device settings.
What we do not do
- We do not sell your personal data.
- We do not use your data for third‑party advertising.
- We do not track you across other companies’ apps and websites for advertising purposes.
- We do not import Discord friends or Strava followers, and provider relationships never become Greenlight contacts automatically.
Service providers and sharing
We disclose data only as needed to operate Greenlight—for example to cloud hosting and object-storage providers, login providers such as Apple, Google, Discord, and Strava when you choose one of them, Google Firebase, or browser push-delivery services, and Giphy when you use optional GIF search or media—or when required by law. We do not share data with data brokers.
Security
Greenlight uses encrypted network connections and access controls intended to protect data. Local-account passphrases are salted and hashed with a memory-hard password hashing algorithm. No online service can guarantee absolute security.
Retention
We retain account data while your account is active and as reasonably needed to provide or secure the service. Deleting your account removes your profile and connected login-provider identifiers, local credential and recovery-code hashes, and any stored Discord photo candidate; uploads that are no longer needed are scheduled for removal. Safety reports and limited audit information may be retained or de-identified where legally required or reasonably necessary to investigate abuse, protect users, or resolve security incidents.
Your choices
- Push notifications: optional. You can enable/disable notifications in your device settings and in the app.
- Local account: no outside login provider or email address is required. You are responsible for saving the one-time recovery codes shown at signup.
- Provider photo: optional. A Discord photo is copied only when you choose the import control, and you can replace or remove it later.
- Account deletion: available in Account settings or at /account/delete.
- Permissions: camera, microphone, calendar, and notification access can be withdrawn in device settings.
Community safety
Content and conduct rules are available in our Community Guidelines.
Contact
If you have questions, contact: paalhovenbentsen@gmail.com