Privacy Policy
Privacy is the product. This page describes what we collect, where it lives, and how to reach us about it.
What we collect
When you sign in with Google or email, we receive your name, email address, and a sign-in identifier from Firebase Authentication. When you act on the platform we record your principal attestation (text version and timestamp), credit purchases and spends, and the letters you send (recipient building, message text, and delivery status). Browsing the directory requires no account and no personal data.
Where it lives
Account and activity records are stored in Google Cloud Firestore in the United States (us-central1 region group), protected by deny-all client rules: only our servers can read or write them. We never publish a member's identity, and we never publish a building owner's identity or mailing address; owner locations appear only as city and state.
What we never do
We do not sell personal data. We do not share member data with outside marketers. Owner mailing addresses from county records are used only to deliver the letters members write, never shown to members or visitors.
Retention and deletion
We keep account and transaction records while your account is active and as required for legal and audit purposes. To request deletion of your account and personal data, email tony@tgmventures.com from your account email; we confirm within 30 days. Ledger entries required for financial records are retained in de-identified form.
Contact: tony@tgmventures.com. Last updated June 2026.