Privacy Policy

GreenTea is a non-profit social network built to fix what people hate about social media — and that includes how their data gets treated. This page explains, in plain language, what we collect, why, who we share it with, and the control you have. No dark patterns, no buried surprises.

1. Who we are

GreenTea is operated by Nick Houghton and friends in Canada. We run GreenTea as a non-profit social network and donate its profit to fighting climate change.

Questions about this policy or your data? Email us at greenteaadmin@gmail.com.

2. Scope

This policy covers the GreenTea app and website — what we collect when you use GreenTea, how we use it, who we share it with, and the choices and rights you have. It does not cover third-party services we link to, which have their own privacy policies.

3. Information we collect

Account and profile information. When you register, we collect your email address and a password (stored only as a secure hash, never in plain text). Your profile can also include a username, bio, location, website, pronouns, birthdate, interests, an avatar image, and your time zone — most of these are optional and fully under your control, and you can edit or remove them any time.

Content you create. Posts, comments, likes, saved posts, and any images or video you upload. Uploaded media is stored with our storage provider (see Section 7).

Connections and invitations. Your connections and Circles, and — if you invite someone — the email address you enter for that invitation. We use it only to send the invite and to mark it as “joined” if they register. We don’t use it for anything else.

Location information. GreenTea handles location in two separate ways:

Usage and activity. How you interact with the service — for example, discovery-feed views and impressions that power Open Water, and, only if you opt in to ads, ad impressions and clicks recorded to maintain your Impact contribution counter.

Device and technical information. Like most online services, our servers automatically receive certain information when you connect, such as your IP address and device or browser type. To keep you signed in, we store a login token on your own device (in your browser’s local storage on the web, or secure device storage in the app) — we do not use cookies to log you in. Cookies and similar ad identifiers come into play only through the advertising networks, and only if you turn ads on (see Section 4).

4. Advertising and cookies

Ads are strictly opt-in. By default you see no ads, and the advertising networks aren’t loaded for your account at all. You can turn ads on or off any time from your profile, and no feature is ever locked behind ads.

If you opt in, ads are served by Google AdMob (in our iOS and Android apps) and Google AdSense (on the web).

Consent (EEA, UK, and similar regions). Where the law requires it, before any ad is requested we show a consent message using Google’s certified consent tooling (built on the IAB Transparency & Consent Framework), and ads are only served in line with the choices you make there.

Google’s handling of data in connection with ads is governed by Google’s own policies. You can read more at Google’s Privacy & Terms and at How Google uses information from sites or apps that use our services.

We do not sell your personal information.

5. How we use your information

Where the GDPR or UK GDPR applies, we rely on:

7. How we share information

We share information only as needed to run the service:

We do not sell personal information, and we do not share it for third-party advertising beyond the opt-in ad serving described above.

8. Data retention

We keep your information for as long as your account is active, or as long as we need it to provide the service. Some records are kept on shorter cycles — for example, raw advertising-event records are pruned on a rolling window of around 30 days, since the running Impact total (not the raw events) is what your profile shows. When you delete your account, we delete or anonymise your personal information, except where we’re legally required to keep some of it.

9. How we protect your information

Passwords are stored as secure bcrypt hashes, sign-in uses signed, expiring tokens, and access to data is restricted. No system is ever perfectly secure, but we take reasonable measures to protect your information.

10. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, export (port), or restrict the processing of your personal information, and to object to certain processing or withdraw consent.

Some of these you can do yourself, right now:

To exercise any of these rights, email greenteaadmin@gmail.com, and we’ll respond as required by applicable law. Canadian users have rights under PIPEDA and, in Québec, under Law 25; EEA/UK users have rights under the GDPR/UK GDPR.

11. Children’s privacy

GreenTea is not directed to children. You must be at least 13 years old to use the service. We don’t knowingly collect personal information from children under this age; if we learn that we have, we’ll delete it.

12. International data transfers

We and our service providers may process your information in countries other than where you live, including outside the EEA/UK and Canada. Where required, we rely on appropriate safeguards for those transfers.

13. Contact

Questions or requests? Email greenteaadmin@gmail.com. For privacy-specific requests, putting “Privacy” in the subject line helps us route them quickly.