Privacy Policy
1. Who we are
GSS Environmental ("GSS", "we", "us") operates this environmental monitoring dashboard as a pilot project focused on Kampala, Uganda. This policy explains what personal data we collect, how we use it, and your rights.
2. Data we collect
When you sign in with Google we receive the following from Google's OAuth service:
- Google subject ID a stable, opaque identifier for your Google account
- Email address
- Display name
- Profile picture URL
We do not receive or store your Google password. We also store a session token (a random 32-byte value) in a secure, HttpOnly cookie that identifies your active session.
3. How we use your data
- To authenticate you and associate AI analysis history with your account
- To display your name and picture in the dashboard navigation
- To enforce access to the monitoring dashboard (authenticated users only)
We do not sell, rent, or share your personal data with third parties for advertising purposes.
4. Environmental data
Sensor readings, external intelligence data, and AI analysis results are stored in our Cloudflare D1 database associated with your monitoring site. This data is environmental and does not contain personal information. AI queries you submit are stored so you can review your analysis history.
5. Third-party services
The dashboard integrates with the following third-party services. Their own privacy policies apply:
- Google Identity Services: sign-in and ID-token verification (Google Privacy Policy)
- Cloudflare Workers / D1 / AI: backend infrastructure and AI inference (Cloudflare Privacy Policy)
- Tomorrow.io: weather data
- OpenAQ: observed air-quality data
- Open-Meteo: modelled atmospheric data
- WeatherAPI: weather alerts and fallback weather data
6. Data retention
Session tokens expire after 30 days of inactivity. You may request deletion of your account and associated data at any time by contacting us. Environmental telemetry data is retained for the duration of the pilot project.
7. Cookies
We set one first-party cookie (gss_session) that is:
- HttpOnly: not accessible to JavaScript
- Secure: only sent over HTTPS
- SameSite=None: required for cross-origin requests to the Cloudflare Worker
- Valid for 30 days
We do not use tracking, analytics, or advertising cookies.
8. Your rights
Depending on your jurisdiction you may have rights to access, rectify, or erase your personal data. To exercise any of these rights, or to ask questions about this policy, please contact the project team through the repository or site administrator.
9. Changes to this policy
We may update this policy as the pilot evolves. The "last updated" date at the top of this page will reflect any changes. Continued use of the service after changes constitutes acceptance of the updated policy.
10. Pilot disclaimer
This service is a research and monitoring pilot. Environmental readings are indicative only and must not be used for emergency, medical, legal, or regulatory decisions. See also our Terms of use.