Greenlyz

Website & download privacy

Updated September 27, 2026. This notice covers Greenlyz website downloads and optional Greenlyz product newsletters, not the contents of your self-hosted OneStop library.

Download activity

We record the request time, file and release, platform, public IP address, approximate country/region/city when supplied by Cloudflare, coarse browser/operating system, referring site origin, and server response status. IP estimates are not GPS and can be inaccurate with VPNs or shared networks. We do not infer a person's name or email address from an IP.

Detailed requests are retained for up to 30 days or the newest 10,000 records, whichever limit comes first. Retries and range requests are separate events. Server responses do not prove a completed download or installation. Cached downloads may not reach our server. Earlier anonymous site analytics are separate.

Operational download reports

We also record successful origin-served page and download requests, excluding query strings, fragment tokens and private routes. A daily keyed hash of network address and browser information groups observations approximately; it does not identify a person or verified browsing session and may combine visitors on shared networks. New report observations are encrypted at rest and retained for up to 7 days or 20,000 observations. A private daily summary, including download/referral counts, approximate locations and related page paths, is emailed through Brevo to [email protected] from [email protected]. It does not include subscriber email addresses, raw IP addresses or grouping identifiers. Provider and administrator mailbox copies have separate retention. Cached traffic and historical browsing before installation cannot be reconstructed.

Optional email updates

You can download without providing an email. If you opt in, we retain your email, selected platform, consent wording, request/confirmation times and subscription status to send one newsletter covering releases and features across all Greenlyz LLC products. Earlier OneStop-only subscribers are not silently moved to the all-products newsletter; they must request and confirm that change. You must confirm by email before receiving announcements. Unconfirmed requests expire after 48 hours and are removed during routine cleanup.

We use our configured email provider, Brevo, to deliver confirmation messages and updates. Each update contains an unsubscribe link, which stops future announcements without a login. We retain unsubscribe status to avoid sending further updates until you explicitly opt in and confirm again. Confirmed subscriptions remain until you unsubscribe or request deletion.

Recognizing a confirmed subscriber

After confirmation in your browser, we set a secure, HTTP-only subscriber cookie for up to 30 days. It allows subsequent download requests in that browser to be associated with the confirmed email. Downloads on another browser or without the cookie remain unidentified. We do not match anonymous downloads to emails based on IP address.

Subscriber storage

The subscriber and newsletter store is encrypted at rest with AES-256-GCM, using a separate key supplied through Doppler. Authorized email sending and admin views decrypt records in memory. This does not protect against a compromised running server or administrator. Exports, older backups and email-provider copies require separate safeguards.

Access and choices

Detailed records and subscriber lists are available only to authorized administrators through the server-local admin interface. Exports, backups and provider logs have separate retention and must be managed by the administrator. We do not sell the subscriber list. Contact [email protected] about privacy, deletion or email preferences. Removing your cookie does not unsubscribe you; use the link in an update email.

Downloads and optional signup ยท OneStop application privacy