The eight commitments
Read the headlines to get the gist. Open any commitment for what it means for your chapter and how you can verify it.
1 We collect only what hour tracking needs, and we never sell it. Identity, chapter and role, hours, and session location. Nothing sold, no data broker. ▼
GreekHours collects your identity from your sign-in provider, your chapter and role, your hours, and your location during a session. We use it to run hour tracking, reporting, and support. We do not sell personal information and we do not operate as a data broker.
How to check: Privacy Policy at greekhours.com/privacy. The full list of third parties is in the fact sheet below. Website analytics and campaign tags are disclosed there too and never receive member data.
2 Location is for verifying a session, never for tracking you. Only during a session. Deleted after 120 days. Never in a shared report. ▼
GreekHours checks your location when a session starts and while it runs. During an active session, verification can continue in the background so that leaving the study location ends the session. When no session is running, GreekHours does not collect location at all. Coordinates are converted to a place name using Google's geocoding service, which receives coordinates only and no identity. Raw coordinates and the place name are deleted 120 days after the session or at semester end, whichever protects you more. What remains is the verification result, the duration, and the hours credited.
How to check: location fields are excluded from every shared report tier. The mobile apps contain no third-party analytics or crash-reporting tools that could receive location.
3 No passwords, ever. Sign in with Apple, Google, or Microsoft. Nothing to leak. ▼
You sign in with Apple, Google, or Microsoft. GreekHours never stores a password for your account, so there is no GreekHours password to be leaked, guessed, or reused.
How to check: the sign-in screen offers only those three options. There is no "create a password" flow.
4 Encrypted in transit and at rest. TLS 1.2+ everywhere; database and backups encrypted on Microsoft Azure. ▼
Every connection uses HTTPS with TLS 1.2 or higher. The database, including uploaded photos, and its backups are encrypted at rest on Microsoft Azure with platform-managed keys.
How to check: Azure App Service and PostgreSQL configuration. Backups are retained for 7 days, so anything deleted is fully gone within a week.
5 Access is scoped by role and by chapter. Five chapter roles, each scoped to its area. No chapter sees another's data. ▼
Five roles control what a chapter member can see and do: student, Chapter Admin, Study Admin, Service Admin, and Event Admin. A student sees their own hours. Scoped admins see their area. Chapter Admins see their chapter. A separate Global Admin role is held only by GreekHours staff, for support and operations, and is not a chapter seat. Chapter data is scoped so one chapter cannot reach another's.
How to check: the roles table in the fact sheet below. A detailed role-permissions summary is available to advisors on request.
6 Your data is yours: share it on your terms, delete it on request. Read-only report links, names removable, expiring and revocable. Delete any time. ▼
Compliance reports can be shared as read-only links in three detail levels, scoped by date and category, with an expiration date and a revoke control. Anonymized Detail removes names, emails, and identifiers and uses random labels generated per report that cannot be linked across reports. Summary Only shows chapter totals with no member rows. Every level excludes location and any financial or fine detail. Any member can delete their account from inside the app, and anyone can submit a deletion request through the public form. We acknowledge deletion requests within 5 business days and complete them, or report status, within 30 days.
How to check: the report tiers and retention tables in the fact sheet. Deletion paths are linked from the Privacy Policy.
7 AI stays in bounds. Support assistant runs on Azure. Conversations deleted after 120 days. Not used to train models. ▼
Athena, the in-app support assistant, runs on Anthropic's Claude model through Microsoft Azure AI Foundry, hosted by Azure. It processes your conversation and limited chapter context to answer your question. Conversations are stored in the United States and deleted after 120 days. You can delete any conversation, or all of them, at any time. If you escalate a conversation to support, a copy is kept for 120 days. Under Microsoft's and Anthropic's enterprise terms, your content is not used to train their models. The current deployment uses Azure's Global Standard routing, which means AI processing may run in Azure regions outside the United States; your stored data does not.
How to check: the Athena delete controls in the app. Microsoft's Azure AI data-handling documentation is available on request.
8 We monitor, we respond, we tell you. Security reports assessed within 1 business day. Chapters notified within 72 hours of a confirmed incident. ▼
GreekHours runs application logging and monitoring, and logs are written so they do not contain coordinates or personal details. Security concerns can be reported to security@greekhours.com or through the standard security.txt contact file. We begin assessing any security report within 1 business day. If we confirm an incident that affects chapter data, we notify your chapter's designated contacts within 72 hours of confirmation, unless law requires a delay. Every incident is documented with what happened, what we fixed, and what we changed.
How to check: greekhours.com/security and security.txt. Send a test message; you will get a reply.
Fact sheet
For the reader who wants to check the details.
Third parties that touch data
| Third party | What it receives | Whose data |
|---|---|---|
| Microsoft Azure | Hosting, database, backups, logs, AI processing | Members and officers |
| Anthropic Claude via Azure AI Foundry (Azure-hosted) | Athena support conversations and limited chapter context | Members and officers who use Athena |
| Apple, Google, Microsoft | Sign-in identity | Members and officers |
| Apple and Google | Push notification delivery tokens | Members and officers |
| Google Geocoding | Session coordinates, to produce a place name; no identity | Members, during sessions |
| Stripe | Subscription billing | Chapter officers only |
| Website analytics and campaign tags | Website visits and marketing attribution | Website visitors only; never member data |
The mobile apps contain no third-party analytics, advertising, or crash-reporting tools.
Roles
| Role | Sees and does |
|---|---|
| Student | Own hours and sessions |
| Study Admin, Service Admin, Event Admin | Their area, for their chapter |
| Chapter Admin | Their chapter |
| Global Admin (GreekHours staff, not a chapter role) | Support and operations |
Shared report tiers
| Tier | Shows | Never shows |
|---|---|---|
| Full Detail | Members by name, hours by category, compliance status | Location, financial or fine detail |
| Anonymized Detail | Random per-report labels, hours by category, compliance status, date-only "as of" | Names, emails, identifiers, exact timestamps, location, financial detail |
| Summary Only | Chapter totals | Any member rows |
All tiers: read-only link, date and category scoping, expiration, revocation, rate-limited.
Retention schedule
| Data | Kept for | Then |
|---|---|---|
| Raw session coordinates and place name | 120 days after the session or semester end, whichever protects you more | Deleted; result, duration, hours remain |
| Photo evidence location data | Location metadata stripped on upload | Deleted |
| Athena conversations | 120 days after last use or semester end, whichever protects you more | Deleted; members can delete sooner |
| Escalated support transcripts | 120 days | Deleted |
| Shared report links | 120 days from creation or end of semester, whichever is sooner | Expires; can revoke sooner |
| Dormant account with no chapter | No sign-in for two semesters | Notice, then deleted 30 days later |
| Chapter whose subscription lapsed | Access ends at lapse; data kept two semesters | Notice, then deleted; can request sooner |
| Application logs | 90 days; no coordinates or personal details | Expire |
| Database backups | 7 days | Roll over; deleted data gone within a week |
Reporting a security concern
Found something? Tell us.
Email security@greekhours.com or use our machine-readable contact file at /.well-known/security.txt.
We begin assessing every report within 1 business day, keep you informed while we investigate, and let you know when it is resolved. We do not pursue action against good-faith researchers who avoid accessing data that is not theirs, degrading the service, or social engineering, and who give us reasonable time to fix an issue before disclosing it.
Scope
This is an operational trust summary, verified against the live system. It is not a legal contract; the Terms of Service and Privacy Policy govern.
Chapters with institution-specific requirements should route final review through their campus process.
This page is re-verified against production once per semester and after any architecture change. The verification date at the top is the last time every statement was checked.
Need a copy to share?
Download the full pledge or the one-page summary to hand to a chapter, an advisor, or a national office.