Information We Collect
GrownMT collects account information such as username, email address, password hash, profile details, posts, comments, grow diaries, uploaded media, messages, reports, and moderation activity needed to run the platform.
Cookies and Sessions
We use session cookies to keep you logged in and CSRF tokens to protect forms. The age gate stores confirmation in localStorage and a cookie so the prompt does not appear on every visit.
Account Data
Your account data is used to authenticate you, show your profile, connect posts and uploads to your account, support messaging, and let moderators manage community safety.
Media Uploads
Uploaded photos and videos are stored on the server and metadata is stored in the database. Public uploads connected to posts or diaries may be visible to other visitors.
Private Messages
Messages are stored in the database so conversations can be displayed to participants. Users may only access conversations they belong to. Admin access should be used only for legitimate safety, legal, or support needs.
Security Practices
Passwords are hashed with PHP password hashing, database writes use prepared statements, uploads are type-checked, and private actions use CSRF protection. No system can be guaranteed perfectly secure.
Third-Party Services
If SMTP email is enabled, password reset emails may be processed through the configured email provider. If analytics or additional third-party services are added later, this policy should be updated before use.
Analytics and Cookies
The current local project does not require third-party analytics. If analytics are added, they should be disclosed here with opt-out information where required.
Your Rights
Depending on your location, you may have rights to access, correct, export, or delete personal data. Contact us with privacy requests using the Contact Us page.
Data Retention
We retain account and community data while needed to operate the platform, maintain safety, resolve reports, comply with legal obligations, or preserve community context.
Contact
For privacy questions or data requests, use the contact form and include enough account information for us to identify your account. Do not include your password.