07 / Privacy
A small site should collect a small amount.
Effective September 4, 2026. Genuine Good is published by Win The Night™ Foundation. This page explains what the current site receives, why it receives it, and the choices available to you.
What we receive
You can read stories and play games without an account. If you sign in with Google, we receive the verified Google account identifier, email address, and name returned for the sign-in session. Google sign-in or the site host's ChatGPT-compatible authentication provides access to the owner-only studio only when the identity is on our owner allowlist. A reader account does not automatically provide owner access. We use these values to establish a session, show account controls, and protect owner areas. We do not receive your Google or ChatGPT password.
Newsletter delivery
When you subscribe, we store the email address, delivery choice daily delivery setting, consent time, and subscription state. Submitting the form with the consent checkbox is the confirmation and signup event; we do not require a second confirmation click. Resend processes the address and delivery events for us, including accepted, delivered, bounced, complaint, and suppression signals. We send only to eligible confirmed subscribers. Every digest has a one-click unsubscribe link, and unsubscribed or suppressed addresses are blocked from future digests.
Search, hosting, and basic operations
Search sends your query to the site so we can return matching released stories. The application does not currently use an advertising SDK, a cross-site behavioral profile, or an account-linked pageview analytics system. Our hosting and infrastructure providers may still process technical request data needed to deliver and secure the site, such as an IP address, browser or device details, referring URL, requested URL, timing, and error information, under their own policies.
The free grant preview uses a one-day rate-limit bucket derived from a hash of the connecting address and user-agent. The app stores the bucket, count, and timestamps, not the raw address or user-agent. We do not use search terms or that bucket to build a reader profile.
Cookies and local storage
Google sign-in uses an essential, HTTP-only session cookie and short-lived cookies while an OAuth sign-in is completed. The browser may also store your theme choice, typography preference, and game scores or progress in local storage. The current games do not send that local game state to our server. Clearing browser storage removes those device-local settings and saves.
Genuine Good Grants and payment records
Genuine Good Grants uses public Grants.gov records and the x402 payment flow on Base with USDC. To operate paid requests, we retain the payment and settlement identifiers needed to verify the request and keep accounting records. For a 30-day API pass, the service retains a SHA-256 hash of the bearer token, activation and expiration times, usage count, and settlement identifiers; the raw token is not recoverable from that hash. Some blockchain transaction details are public and may be outside our control. Do not place API tokens, payment signatures, Social Security numbers, taxpayer IDs, passwords, or confidential case files in grant fields.
Messages, tips, and planned services
A message you send to our support address may include the email address, message, and files you choose to include. Please do not use ordinary email for confidential personal information. Tips are leads, not permission to publish a person’s identity or private details. Human grant research is not currently offered; the current paid product is the Genuine Good Grants API.
Who helps us operate
We use service providers needed for the current product, including Google for reader sign-in, Resend for newsletter mail and delivery events, hosting and database infrastructure for the site, and Grants.gov for public grant records. Links to other sites, such as source publishers and government pages, take you to services with their own terms and privacy practices. We do not sell newsletter lists or use them for unrelated targeted advertising.
Retention, deletion, and corrections
We keep information for as long as it is reasonably needed for the purpose described here, security, accounting, dispute handling, or legal obligations. We do not promise a fixed deletion schedule. Suppression and unsubscribe records may need to remain so we do not mail you again. Payment, provider, hosting, and public blockchain records may be retained by those systems separately.
Signed-in readers can use My account to change newsletter delivery or delete the Genuine Good newsletter record and its confirmation tokens. That action does not delete a Google or ChatGPT account, external provider records, hosting logs, or blockchain records. To request access, correction, or deletion of information we control, emailhello@genuinegood.onlinewith the relevant address and details. We may need to verify the request before acting.
Children and security
Genuine Good is intended for a general audience, not specifically for children under 13. We do not knowingly ask children under 13 for personal information. If you believe a child sent us personal information, contact us at the address below so we can review it. We use reasonable safeguards for this pilot, including protected sessions and server-side controls, but no online service or email transmission is perfectly secure.
Questions and story corrections
For a privacy question or a correction to this page, emailhello@genuinegood.online. For a story correction, include the article URL, the specific statement, and a source that supports the requested change. We review correction requests; a request does not guarantee a change.