PRIVACY POLICY
Clear choices for your identity and data.
Effective August 1, 2026. This notice applies to GlobalCitizen.digital and identity-linked experiences initiated from cz.cool.
Information we process
Account email, display name, profile settings, language and reading preferences, community content, project participation, messages, live-chat data, and files you choose to upload.
Layered application consent
Saving minimum application fields requires an explicit application-data choice. Opening the camera, storing a selfie, or submitting a selfie requires a second, standalone selfie and face-presence choice. Neither is preselected, and each is recorded with its version, purpose, language, grant time, and any withdrawal time in a downloadable consent receipt.
Digital-citizen applications and selfies
A consented selfie is kept in private object storage; the database stores its key, type, size, review state, and application ownership. The browser may check only whether a face is visible. We do not infer age, sex, gender, ethnicity, emotion, or identity and do not create a face template. A selfie is not government identity verification. You can independently withdraw selfie consent and delete the image; an issued credential retains only its minimal credential and audit record.
Minors and data minimization
The current Digital Citizen application pilot accepts individuals age 18 or older based only on a self-declared birth date. It does not infer age from a face, collect guardian data, or accept minor applications or selfies. The public field-level inventory states the purpose, access role, current retention, and deletion rule for every application-data category.
How it is used
To authenticate you, maintain your profile, deliver community and messaging features, administer the community-credential application, protect the platform, and improve the experience.
Service providers
Clerk supports authentication. OpenAI processes only the content you deliberately submit to Guru features. Hosting, database, and object-storage providers process data required to operate the service. Any future higher-assurance identity provider will require a separate, explicit notice and consent before use.
Wallets and credentials
Wallet binding is optional. A wallet is linked only after an explicit signature challenge; we do not request or store private keys or seed phrases. Community IDs and future passport NFTs are platform credentials, not government identity documents or passports.
Your choices
Use the authenticated in-app Privacy Request Center to request access, correction, export, deletion of eligible data, consent withdrawal, or credential revocation. A request records what you are asking for; it does not automatically delete data, revoke a credential, or guarantee an outcome. Minimal issued-credential or consent-audit records may be retained when necessary for audit integrity, security, dispute resolution, and applicable legal obligations.
Submit and track a privacy request
Sign in to use the in-app channel and follow the status of requests owned by your account.