Privacy Policy

Effective September 23, 2026

Independent project, with no affiliation to any government body. Greenridge is a private, independent hobby project. It is not affiliated with, endorsed by, operated by, or connected in any way to the Maryland Department of Natural Resources, Maryland State Parks, the National Park Service, Green Ridge State Forest, or any other government agency or official body. All campsite information is crowd-sourced and advisory only. Nothing in this app constitutes an official service, reservation system, or authoritative record of any kind.

This policy explains what information the app collects, how it is used, and your choices. It applies to the Greenridge web app, iOS app, and Android app.

1. Information you provide

Account

When you create an account you provide an email address and choose a password. Credentials are managed via a third-party authentication service. Your email is used for account verification, password reset, and login code delivery, and for one thing more only if you switch it on: the seasonal digest, a short note about four times a year (Settings → Email). When you switch it on we record the time you did, so we can show that each email was asked for; every issue carries a one-click unsubscribe link, and switching it off in Settings does the same. The digest carries no advertising and we do not track whether it was opened. We do not sell or share your email with third parties for marketing.

Signup sheet photos

You can photograph the physical campsite sign-up clipboard at Green Ridge HQ and upload it to help keep availability data current. When you do:

  • The image is read server-side by third-party services: an AI model from Anthropic or OpenAI, and Amazon Textract (OCR), to extract campsite numbers and stay dates. The app asks for your permission before your first sheet photo is sent, and sends nothing if you decline. Names and permit numbers on the sheet are never published or shown to other campers. The records we keep hold site numbers and stay dates only: the last-name and permit-number columns are discarded during processing and never written into them. To be precise about how: the AI model is instructed not to return those columns, while OCR necessarily reads every word on the page in order to find the ones we want, so with OCR those columns pass through server memory before being dropped. The photo itself is kept as described next.
  • The photo itself is retained so an administrator can check a parse against the original. It is stored as uploaded apart from metadata removal, so any handwriting visible in the photo — including names — is still visible in the stored image. Only administrators can view stored sheet photos.
  • If the photo carries a location, the server reads it once to confirm the photo was taken near the HQ clipboard (an anti-abuse check with a radius of roughly half a mile). The location comes from one of two places: GPS coordinates your camera embedded in the file, or, when you take the photo with the camera inside the iOS app and have allowed location access, your phone's current position, which the app attaches to the photo at the moment you take it. Either way the coordinates are used only for that check and are not stored. What is kept is a short note for reviewers when the check could not pass: that the photo had no location, or roughly how many miles from HQ it was taken.
  • Camera metadata (including any embedded GPS coordinates) is then stripped from the photo before it is stored.
  • A fingerprint of the stripped image is stored to detect duplicate uploads.

Site photos, comments, reviews, and road condition reports

Photos you contribute to a campsite page, comments and reviews you post, and road condition reports you submit are associated with your account by an internal identifier (not your email). A review is published with the display name you chose, or as “A camper” if you never set one — never with your email address. Camera metadata is stripped from contributed photos before storage. You can edit or delete your contributions at any time from the site page or your account settings; road condition reports also expire automatically after 7 days.

Reviews quoted from public posts elsewhere (Reddit, YouTube, Google Maps) are labelled as such and are not connected to any account here.

Private notes, trips, and journal

Private site notes, trip plans, and journal entries are synced to our server so they follow your account across devices. They are visible only to you, never shown publicly, and deleted when you delete your account.

Favorite sites

If you are signed in, your starred sites are synced to our server so they persist across devices. If you are not signed in, favorites are stored only in your browser's local storage and never leave your device.

Username and profile photo (optional)

You can choose a public username (3–20 letters, numbers or underscores) and either pick one of the built-in avatars or upload a profile photo. Both appear beside your comments and reviews. An uploaded profile photo is checked by an automated moderation service (§3) before it is shown, and one it cannot clear waits for a person to look at it; camera metadata is stripped first. We never ask for your real name, and we never show your email address publicly.

Feedback you send

The in-app feedback form sends your message, a contact email if you give one (your account email if you are signed in), which page you were on, and whether you were using the web or iOS app. So that you can read our reply, the app also stores a random token on your device and sends it with the message; it identifies the conversation, not you or your device, and is not an advertising identifier.

Your site history

If you are signed in, the app keeps a short list of the campsites you have been involved with (sites on sign-up sheets you photographed, sites you wrote notes on, submitted photos of, or planned a trip to) and when, so it can offer them back to you. It is visible only to you and is deleted with your account.

2. Information collected automatically

Server logs

Our server records standard HTTP request logs: timestamp, request path, HTTP status code, and source IP address. Logs are used to diagnose errors and detect abuse. They are not shared with third parties and are rotated regularly.

Device location (optional)

On the Sites list and Map pages, the app can show your current position relative to campsites using your device's GPS or network location. If you opt in to the HQ clipboard prompt in Settings, the app also periodically checks your approximate position to notice when you are near the HQ clipboard. These checks run entirely on your device, and your position is not sent to our server for them. The one time the app sends a location is when you photograph the sign-up sheet with the camera in the iOS app: the photo carries where it was taken, for the check described in §1, and those coordinates are not stored. The app requests permission before accessing location and you can deny or revoke it at any time in device settings.

Compass and motion sensors (optional)

Some views can turn with your phone: the compass rose on a campsite page (so the contour map and the night sky face the way you are facing) and “Point at the sky” in the nature guide. These read the phone's orientation sensors only while that view is on screen and the app is in the foreground, and only after you switch them on; the readings never leave your device. iOS asks for permission the first time; you can revoke it in device settings.

Reminders and notifications (optional)

If you enable the clipboard photo reminder, the app schedules a local notification on your device during an HQ visit window. Notification scheduling happens entirely on-device; nothing about it is sent to our server. You can turn reminders off in Settings or revoke notification permission in device settings.

Offline storage

The app stores cached site data, availability data, and pending photo uploads in your browser or app storage. This data stays on your device. Pending uploads are transmitted when you reconnect; you can clear them from account settings.

3. Third-party services

When you use the app your device makes direct requests to most of the following external services; where the table says so, our own server makes the request instead and your device is never in contact with them. Each has its own privacy policy.

ServicePurposeData sent by your device
OpenStreetMapStandard map layerMap tile coordinates (zoom/pan position); no account data
Open-MeteoWeather and air quality — current conditions, the overnight low, and the hourly forecast behind the stargazing verdictNothing — requested by our server, not your device
Third-party authentication serviceAccount managementEmail address, password (hashed), login codes
Anthropic or OpenAI (server-side only)Reading signup sheet photos; asked for before your first uploadNot sent from your device; the server forwards stripped images on your behalf
Anthropic or OpenAI (server-side only)Identifying a plant, insect or animal from a photo you take in the nature guideNot sent from your device; the server forwards the photo on your behalf, keeps the result for up to 60 days, and deletes it with your account. This feature is switched off in the current release.
Anthropic or OpenAI moderation (server-side only)Checking comments, reviews and profile photos before they are shown to other peopleNot sent from your device; the server forwards the text or image you are publishing, and keeps only the verdict
Email delivery serviceSending account emails (sign-in codes, password resets, the optional seasonal digest)Your email address and the message; sent by our server, not your device
Amazon Textract (server-side only)Reading signup sheet photos (OCR); asked for before your first uploadNot sent from your device; the server forwards stripped images on your behalf

In this app — everything under /app/, which is where your account, your photographs and your location are — we do not use analytics services, session recording, Google Analytics, Facebook Pixel, or advertising pixels.

On the public pages — the greenridge.app home page, the campsite reference pages under /sites/, and the shortlist pages such as /river-campsites/, which need no account and hold nothing about you — we use Google Analytics to see whether people are finding them. That is measuring pages, not people: there is nothing there to attach to you, because you have not told those pages anything. There is no advertising tag and no advertising audience built from these pages — Analytics is configured with Google signals and ad personalisation switched off, so it cannot share what it sees with an ad network even if somebody turned that on in an account somewhere. It is the only place any analytics runs, and the distinction is the point rather than a technicality.

3a. Microphone and sound recordings

The “What did I hear?” feature records a short clip from your microphone, and only while you are holding the record control. The clip is uploaded to our server, compared against a reference library of forest sounds, and kept for 14 days so a match can be re-checked or corrected — then deleted. Nothing listens in the background, and the microphone is never opened except by that one deliberate action. This feature is switched off in the current release; this section describes what it does when it is on.

4. How we use your information

  • Provide the service: authenticate your account, sync favorites, display availability data, show contributed photos, comments, and reviews.
  • Improve accuracy: review parsed signup sheet data for quality and correct misreads.
  • Safety and abuse prevention: detect duplicate uploads, rate-limit submissions, investigate reports of harmful content.
  • Service operation: diagnose errors and monitor uptime.

We do not use your data for advertising, and we do not sell it.

5. Data retention

  • Account data: retained while your account is active. Deleted within 30 days of account deletion.
  • Availability snapshots: kept as a historic record of campsite occupancy patterns. They hold site numbers and dates; names and permit numbers are never written into them (see §1).
  • Sheet photo archives: retained for quality review. Rejected or superseded snapshots are purged periodically.
  • Server logs: rotated on a rolling basis; not retained beyond operational need.
  • Comments, reviews, and contributed photos: retained until you delete them or until your account is deleted.
  • Road condition reports: expire automatically after 7 days; removed sooner if you delete them or your account.
  • Sound recordings: the clips you record in “What did I hear?” are uploaded so the match can be computed and re-checked, and are deleted after 14 days.
  • Private notes, trips, and journal entries: retained until you delete them or your account.
  • Site history and profile photo: deleted with your account; you can remove your profile photo at any time.
  • Feedback: kept so the conversation can continue. Messages sent while signed in are deleted with your account; to remove messages sent while signed out, contact us.

6. Your rights and choices

  • Access and export: contact us to request a copy of data associated with your account.
  • Delete your account: you can delete your account from the Account page. This removes your credentials, synced favorites, and account-linked contributions within 30 days. Anonymised availability data (campsite numbers and dates with no personal identifier) derived from your sheet uploads may be retained as part of the historic record.
  • Location: deny or revoke location permission at any time in your device or browser settings. The app works without it.
  • Local data: clear browser or app storage at any time from device settings to remove cached data and pending uploads.
  • Username and profile photo: change your username or remove your profile photo at any time on the Account page.

7. Children

Greenridge is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has submitted personal information, contact us and we will delete it.

8. Data security

All data in transit is encrypted via HTTPS. Passwords are hashed by our authentication provider; we never see your plaintext password. Camera metadata including GPS is stripped from all uploaded images before storage.

9. Disclaimer: availability data and official affiliation

Greenridge is an independent private project and is not affiliated with, endorsed by, or connected to the Maryland Department of Natural Resources, Maryland State Parks, the National Park Service, Green Ridge State Forest, or any other government or official body.

Availability information is crowd-sourced from photos of the physical sign-up clipboard at Green Ridge State Forest HQ. It is advisory only, may be incomplete or out of date, and has no official standing. The physical clipboard at HQ is the only legal registration record. This app does not reserve, book, or confirm campsites. Always verify with the ranger station before travelling.

10. Changes to this policy

If we make material changes we will update the effective date at the top of this page. For significant changes, we will also notify you at your account email. Continued use of the app after changes take effect constitutes acceptance.

11. Who runs Greenridge, and contact

Greenridge is built and run independently by Feedback-Loupe, where the story of how it was made is told. To reach the person who makes it: chris@feedback-loupe.com.

Privacy questions and data requests: admin@feedback-loupe.com

The same page is in the app at greenridge.app/app/privacy; this one is generated from it.