Security & Privacy
Last updated: June 21, 2026 · Service: www.greenbookmil.com
This page describes how Green Book is designed to protect your account and data during beta. It is plain-English guidance — not a certification, compliance attestation, or guarantee of military approval.
What Green Book stores
- Account data — email, profile fields you enter (display name, rank, unit), and authentication session tokens managed by Supabase
- User content — tasks, notes, roster entries, files, planner data, and other content you create in the app
- Billing metadata — subscription status, Stripe customer ID, plan type, and renewal dates (payment cards are handled by Stripe, not stored on our servers)
- Operational logs — standard server logs (IP address, user agent, timestamps) and error diagnostics needed to run and protect the service
- Analytics events — product usage events with property keys filtered to block passwords, tokens, and raw content
What Green Book does not store
- Full payment card numbers (Stripe handles card data)
- Passwords in plain text (Supabase stores password hashes)
- Classified, CUI, or mission-sensitive operational data — you should not enter it
- Third-party ad profiling data from Green Book user content
PII handling
Personally identifiable information (PII) — such as your email and profile fields — is used only to operate your account, provide features, and respond to support. Row-level security (RLS) in Supabase limits database access so users see only their own data unless explicitly shared (e.g. team workspaces).
Support and feedback submissions may include diagnostic context. We strip or redact tokens, passwords, and similar patterns before persisting diagnostics where possible.
OPSEC-sensitive data warning
Green Book is for unclassified personal and professional organization — not for classified information, controlled unclassified information (CUI), mission orders, unit locations, troop movements, or other operationally sensitive details.
Do not store information that could compromise you, your unit, or a mission if disclosed. When in doubt, leave it out. See also our Terms of Service and FAQ.
Data minimization
- Profile fields are optional beyond what you need for the app
- Analytics properties are filtered to block sensitive keys and content
- Feedback diagnostics are capped in size and scrubbed before storage
- Admin dashboards show counts and aggregates — not full user content exports by default
Admin access
A small set of authorized operators can access admin tools (Mission Control, feedback ops, beta ops). Admin routes require an admin role check. Admin surfaces display trust labels reminding operators that access is limited and unnecessary PII should not be exported.
We do not sell user data. Admin access is for operating the beta, triaging feedback, and maintaining service health — not for unrelated surveillance.
Billing security
Premium checkout runs on Stripe-hosted pages. Green Book receives webhook events to update subscription status. We do not log full card numbers or Stripe secret keys. Billing webhooks are authenticated and excluded from session middleware redirects.
User deletion and export
You can delete individual content in the app where supported. Account deletion is available in Settings and permanently removes your account and associated data subject to billing retention requirements.
For data export requests, email support@greenbookmil.com with subject line "Data export request." We will respond with what we can provide from your account data.
Incident reporting
If you believe your account was compromised, you see a security bug, or sensitive data was exposed, contact us immediately:
support@greenbookmil.com — subject: "Security incident report"
Include what happened, when you noticed it, and your account email. Do not include passwords or full session tokens in email.
What we do not claim
- No FedRAMP, DoD ATO, or military approval
- No formal SOC 2 or ISO certification at this beta stage
- No guarantee against all threats — use strong passwords and report issues promptly
Related pages
- Privacy & Trust — plain-language guide to private defaults and what not to upload
- Privacy Policy — legal privacy details, cookies, billing, ads
- Delete account — how to remove your account and data
- Terms of Service — acceptable use and OPSEC expectations
- Support — help and contact options
Contact
Security & privacy: support@greenbookmil.com