Privacy
Last updated September 30, 2026
Green Light is built around what it doesn't collect. It never knows where you are, only which venue's code you scanned. It shows the room one letter of your name, and your light goes out on its own. This page says what we do keep, who can see it, and when it's deleted. It covers the Green Light apps for iPhone and Android and this website, app.greenlight.together-ledger.com.
Who this policy is from
Green Light is a product of Together Ledger Digital LLC, registered in Macon, Georgia, United States. We decide how the information described here is used.
For anything about your privacy or your data, including a grievance under India's Digital Personal Data Protection Act, write to legal@together-ledger.com. For help using the app, write to greenlight-support@together-ledger.com.
Who can use Green Light
You must be 18 or older, wherever you live. You give your birthdate when you sign up, and our server checks it; the app can't skip that check. We don't knowingly collect information from anyone younger, and if we learn an account belongs to someone under 18, we delete it.
What we collect, and who sees it
| Data | Why | Who else sees it |
|---|---|---|
| Email address | Your account. You type it, or it comes from Apple or Google if you sign in with them. | Nobody |
| Password, if you sign up with email | Signing in. We store a salted one-way hash, never the password, and count failed attempts so we can stop someone guessing it. | Nobody |
| Your Apple or Google account identifier, if you sign in with them | Recognising you next time | Nobody |
| A token from Apple, if you sign in with Apple | So that deleting your account also ends Green Light's access to your Apple ID. It is stored encrypted and used for nothing else. | Apple, when we hand it back to revoke that access |
| First name | So someone you match with knows who to look for | People in the same room see only its first letter. Someone you match with sees the whole first name. |
| Birthdate | Confirming you're 18 or older | Nobody |
| Your light: the venue, your vibe tag (picked from a fixed list), an optional hint about where you're sitting, and when it went on and off | Showing you to the room while your light is green | People green in the same room see your initial, your vibe tag and how many minutes you have left. Only someone you match with sees your hint. |
| Check-ins: which venue's code you scanned, and when | Putting you in that room | Nobody |
| Taps: who you tapped, and when | Telling you both when a tap is mutual | Nobody. The person you tap is never told. If they tap you too, you're both told you've matched. |
| A match: both first names, both hints, and the suggested openers | Helping you find each other | The two of you, only while both lights are on |
| A record of each match: the two accounts, the venue, when it started and ended, and why | So a report or a safety concern has something to check against | Our team only. Never shown to either of you. |
| Your answer to "Was that okay?" after a match | Spotting a bad experience. A "not great" answer also files a report. | Our team only |
| Reports: who reported whom, where, the reason, and any detail you add (up to 500 characters) | Keeping people safe | Our team only. The person reported isn't told. |
| Blocks | Keeping two people apart | Nobody sees the block itself. Its only effect is that neither of you sees the other again. |
| Sign-in sessions | Keeping you signed in for up to 30 days. On your phone it's kept in the phone's secure storage. | Nobody |
What we never collect
- Your location. The app has no location permission and never asks for one. We don't look up where you are from your network address either. The only place we know is the venue whose code you scanned.
- Photos. The camera is used only to read a venue's code. No picture is taken or kept.
- Your contacts, your phone number or your surname. The app never asks for them.
- Tracking. There are no advertising, analytics or crash-reporting tools in Green Light. We don't sell your information, share it for advertising, or build profiles from it.
Who handles it for us
These companies process information only to run Green Light:
- Cloudflare hosts the app's server, its database and this website, and receives the details any website does, such as your network address and browser. We don't keep request logs of our own. On this website, Cloudflare may add a security check that sets a short-lived cookie.
- Apple and Google confirm who you are if you sign in with them, and give us your email address and name. They also run the app stores you install from.
- Expo (650 Industries) delivers updates to the app. When the app checks for one, Expo receives your network address and the app's version.
No one else receives your information from us. These providers are based in, or process data in, the United States and other countries. If you use Green Light from elsewhere, including India, the European Union or the United Kingdom, your information is transferred to and processed in those countries.
How long we keep it
- A visit (your light, its vibe tag and hint, the check-in, and any taps) is deleted 30 days after your light went out.
- A match is deleted the moment either light goes out. Its record is kept for 30 days after that, and "Was that okay?" answers for 30 days after they're given.
- Reports are kept for 365 days after they're filed.
- Blocks are permanent, even after either account is deleted.
- Sign-in sessions end after 30 days, or when you sign out. The record of a session is deleted 90 days after it ended.
- Your account (email, first name, birthdate and sign-in) is kept until you delete it.
- Backups. Our database provider keeps a rolling history of the database for up to 30 days, so it can be restored after a failure. Deleted data leaves that history within 30 days.
If you run a venue
We keep the name, email address and phone number of each venue's contact, to vet the venue and reach them about it. Only our team sees them. They're deleted 90 days after that person stops being the venue's contact.
Deleting your account
You can delete your account in the app (Settings, then Delete account), or by writing to greenlight-support@together-ledger.com from the email address on the account. See Delete your account. Deleting takes effect immediately and can't be undone.
If your light is on, it goes out, and anyone you matched with sees only that. Your email address, first name, birthdate, password and sign-in are erased. Your visits, check-ins and taps, and every session on every device, are deleted. If you signed in with Apple, we also ask Apple to revoke Green Light's access, so it leaves the list of apps using your Apple ID; if Apple can't be reached, we keep trying for up to a week.
Some things are kept, because they're about other people's safety as well as yours:
- reports you made or that were made about you, for 365 days after each was filed
- blocks, permanently
- match records and "Was that okay?" answers, for their 30 days
- a one-way fingerprint of each way you signed in, for 90 days, so the same sign-in can't create a new account straight away. It can't be turned back into your email address.
A placeholder account row also stays, so those records still point somewhere. It holds nothing that identifies you.
If you stop using your Apple ID with Green Light in your Apple settings, Apple tells us, and we sign you out everywhere. If you delete your Apple ID itself, Apple tells us that too: a Green Light account that only Apple could open is deleted as above, and one you can also open with a password or Google keeps working without Apple.
Your rights
We use your information to provide the service you signed up for, and to keep it and the people using it safe. Wherever you are, you can:
- Get a copy of your data. The app can't download it for you yet, so write to legal@together-ledger.com from the email address on your account and we'll send it to you.
- Correct it. Write to us and we'll fix your name or anything else that's wrong.
- Delete it. Delete your account as described above.
- Ask us anything else, including to object to or limit how we use your information, by writing to legal@together-ledger.com.
- Complain to your data protection authority, such as the Data Protection Board of India, or the authority in your EU country or the UK.
We reply within 30 days, and asking never affects your account.
Changes to this policy
When this policy changes, we update the date at the top of this page.
This policy hasn't been reviewed by a lawyer. It describes what Green Light actually does, checked against its code, and we'll correct it wherever it falls short.