Glyph legal
Privacy policy.
The short version
- We collect what sign-in and billing need: your email, your name, your plan. There are no passwords to store.
- The customer data you send is processed for one purpose — running your workspace. It is never sold, never used for advertising, and never used to train AI models.
- A short list of infrastructure providers touches data to run the service. Each sees only what its job requires.
- Email hello@glyph.app to see, export, or delete everything we hold.
Two kinds of data
Glyph holds two very different kinds of data, and this policy treats them differently. The first is data about you, the account holder: what we need to sign you in, bill you, and run the product. For that data, we decide how it is used, and this policy is the full story.
The second is the data you send about your customers: profiles, events, survey responses, and notes. That data belongs to you and your business. We process it on your instructions to run your workspace, and for nothing else.
Data about you
- Sign-in
- Your email address and name. Sign-in is passwordless — a one-time code and link sent to your email — so there is no password to store, and we never store one.
- Billing
- On Growth, payments run through Stripe. We keep your plan, subscription status, and invoice history; your full card details go to Stripe directly and never reach us.
- Product usage
- What your workspaces use — survey sends, generated drafts, active customers — so plan limits work and we can see what is earning its place.
- Errors and logs
- When something fails, an error report with the request context around it goes to Sentry so we can fix it.
- Page analytics
- Aggregate page analytics from Vercel. No cookies, no tracking you across sites.
The customer data you send
Profiles, events, survey responses, and notes arrive in Glyph because you send them — through the SDK with your workspace's write key, through surveys your customers answer, or typed into the workspace after a call. From that data Glyph derives its analyses: customer signals, pain points, and aggregate sentiment.
We use this data to run your workspace, and for nothing else. It is never sold, never shared for advertising, and never used to train AI models. You control what arrives, and you can delete it at any time.
How AI processing works
Glyph's analyses are generated by AI models, routed through OpenRouter. When an analysis runs, the customer context that job needs — the relevant events, responses, and notes — is sent to the model, and the output is stored in your workspace with its evidence attached.
We use model providers under terms that do not permit your data to be used for training, and we do not train models on it ourselves.
The providers that run Glyph
A small set of infrastructure providers processes data on our behalf. Each sees only the data its job requires:
- Vercel
- Hosts the application in Sydney and provides cookieless page analytics.
- Stripe
- Processes subscription payments and holds card details so we don't have to.
- Resend
- Delivers the email we send: sign-in codes, surveys, and the outreach you approve.
- OpenRouter
- Routes AI analysis jobs to the models that run them.
- Sentry
- Collects error reports so we can find and fix failures.
- Upstash
- Provides rate limiting and caching for the ingestion service.
If you need more detail than this list gives — data processing agreements, security controls — email us before connecting sensitive data and we will answer directly.
Where data lives
Workspace data — your account and the customer data you send — is stored on infrastructure in Australia. Some processing happens elsewhere: the providers above run where they run, so payments, email delivery, AI analysis, and error reports are processed in the United States.
If you are in the EU or UK, using Glyph therefore transfers data to Australia and the United States. Our providers commit to EU-approved safeguards (standard contractual clauses) for those transfers.
We do not currently offer other data-residency options. If your situation requires one, email us before connecting data.
How long data is kept
Account and workspace data is kept while your account is active. Customer data you delete from a workspace is removed from production systems promptly; when you delete your account, all of its data is removed from production systems within 30 days, and backups expire on a rolling schedule after that.
If you want an export before deleting anything, ask and we will provide one.
Security
Data is encrypted in transit, and encrypted at rest by our hosting providers. SDK write keys are scoped to a single workspace, so a key can only write to the workspace it belongs to. Access to production data is limited to what operating the service requires.
No one can honestly promise perfect security, so we won't. If we learn of a breach affecting your data, we will tell you without undue delay.
Your rights
You can ask to see the data we hold about you, correct it, export it, or delete it. Email hello@glyph.app and we will act on verified requests within 30 days.
If you are in the EU, UK, or another jurisdiction with data-protection law, you have these rights by statute, along with the right to complain to your supervisory authority. We do not sell personal information as defined by the CCPA or similar laws.
If you're a customer of a Glyph user
If data about you is in Glyph, it was sent by a business you dealt with, and we process it on that business's behalf. Requests about it — access, correction, deletion — should go to that business, and we will help them honor what they ask. If reaching them is not possible, email us and we will do what we can.
Cookies
Glyph sets one kind of cookie: the session cookie that keeps you signed in. There are no advertising cookies and no cross-site tracking.
Children
Glyph is not directed at children under 16, and we do not knowingly collect their data. If you believe a child's data has reached us, email us and we will delete it.
Changes to this policy
Updates are posted here with a new effective date. For material changes we will email you before they take effect. The current version always lives at glyph.app/privacy.
A question this policy doesn't answer?
Email us. A founder reads every message and will give you a direct answer.