Back to Glidey

Privacy Policy

How Glidey handles account information, writing, AI requests, analytics, and your privacy choices.

Last updated 31 August 2026

Who is responsible

Glidey is an Australian-operated writing service based in Victoria, Australia (“Glidey”, “we”, “us”). We are responsible for deciding how the personal information described in this policy is handled. Privacy questions and requests can be sent to info@glidey.app.

This policy applies to the Glidey website, editor, browser extension, and related support and billing services. It does not govern websites that you choose to open from Glidey.

Information we collect

  • Account and profile. Email address, password hash held by our authentication provider, name, optional avatar, authentication provider identifiers, age confirmation, legal-policy acceptance, onboarding answers, and account settings.
  • Writing and workspace content. Documents and journals, titles, rich text and inline images, folders, tags, favourites, collections and collection rules, deleted-item history, document versions, imported files, and content you deliberately share.
  • AI content. Prompts, selected passages and nearby writing context, chat messages and reasoning shown to you, voice recordings while transcription is running, search queries, note chunks, numeric embeddings, and generated home insights. Glidey may store chat history and the note excerpts attached to it until you delete the chat or account.
  • Collaboration. Share-link tokens, permissions, collaborator and invite details, invite email addresses, anonymous guest account identifiers, and share-session activity and expiry.
  • Billing and usage. Plan, subscription status, billing interval, payment processor customer and subscription identifiers, AI request type, model category, token counts, latency, quota counters, and gateway request identifiers. Full card numbers are entered with and handled by the payment processor, not Glidey.
  • Device, security, and support. Sign-in and security data made available by our infrastructure providers, hashed extension tokens and limited device or user-agent identifiers, error diagnostics, contact messages, bug reports, attachments, and technical context you send with a support request.
  • Email preferences. Newsletter consent, subscription status, signup source, and Free or Pro audience group. Marketing email is optional and can be unsubscribed from at any time.
  • Optional public-site analytics. If you opt in, Google Analytics and Microsoft Clarity may receive page and interaction data, device/browser information, and an IP-derived approximate location from Glidey's signed-out public website. A verified payment-success page may also report completion. Separate application layouts prevent both services from loading in Documents, Journals, Chat with Documents, Settings, shared documents, onboarding, or other workspace routes.

Glidey is a general writing tool, so text you choose to enter may reveal sensitive information even though we do not ask for it. Do not use Glidey as the primary system for medical records, government identifiers, payment card data, or other information that requires a specialised regulated repository.

Profile avatars are stored at a public asset URL so they can be displayed in the app; do not use an avatar you expect to remain confidential. Bug-report attachments use a private bucket and are available only through privileged support systems.

Why we use it

  • Provide the service and perform our contract: create your account, save and sync writing, collaborate, export, provide AI features, enforce quotas, and administer billing.
  • Your consent: send optional newsletter letters, run optional analytics, and process any other feature that specifically asks for consent. You can unsubscribe from marketing email in one click and withdraw analytics consent in Cookie settings or Privacy & Security settings.
  • Legitimate interests: secure the service, prevent abuse and fraud, diagnose failures, support users, and improve reliability, balanced against your rights.
  • Legal obligations: keep required transaction records, respond to lawful requests, enforce legal rights, and investigate incidents.

Where Australian law applies, these purposes also describe why collection is reasonably necessary for Glidey's functions. We do not use your writing for targeted advertising, sell personal information, or share it for cross-context behavioural advertising.

How AI features handle your writing

AI processing is feature-driven. Autocorrect and autocomplete send the sentence or passage being worked on plus limited surrounding context. Rewrite, chat, search, collection, and insight features may send the selected text, relevant note excerpts, or a query derived from them. Voice input sends audio to the transcription service while the feature is in use. We do not intentionally send your entire library for a single response.

The optional onboarding style exercise sends the sample once for analysis. Glidey saves only a compact profile of observable writing preferences and likely correction areas; it does not save the sample itself. Glidey does not passively build or update this profile from your notes. You can skip the exercise without losing access to autocorrect.

Web search sends your search query to Firecrawl and may send result URLs back to Firecrawl to extract page content. Glidey requests that extracted page bodies are not stored in Firecrawl's cache. Unless Enterprise zero-data-retention is enabled for Glidey's Firecrawl team, Firecrawl may retain search request or result data under its API terms. Disabling page-body caching is not the same as zero-data-retention.

When a compatible semantic-search provider is enabled, Glidey extracts text into chunks, sends those chunks to an embedding API, and stores both the chunks and resulting numeric vectors in Glidey's database. Turning off automatic indexing stops future automatic indexing; existing index data remains until it is refreshed, the source document is deleted, or your account is deleted. Production semantic search uses Gemini Paid Services only after billing and the required provider configuration are confirmed, as explained in the Service Providers list.

Glidey does not use your content to train its own AI models. External AI and search services process submitted material under their API terms and our account configuration. We do not make a blanket promise that every external provider has zero retention or identical training terms; those settings and contracts must be assessed for each provider before it is enabled in production.

Who receives information

We disclose only what is reasonably needed to these categories of recipients:

  • Cloud database, authentication, storage, hosting, content-delivery, and security providers.
  • AI inference, embedding, transcription, and web-search API providers when you invoke the related feature.
  • Stripe for checkout, subscription management, fraud prevention, and payment records.
  • Resend for contact, bug-report, and account-related product email.
  • Loops for the optional newsletter audience and subscription preferences.
  • Google Analytics and Microsoft Clarity only after optional consent, only on the signed-out public site and a verified payment-success page, and never inside the private workspace.
  • Error-monitoring services, configured to omit request bodies and default personal information.
  • Professional advisers, regulators, courts, law enforcement, or a business successor where legally required or reasonably necessary.

Our current Service Providers list identifies the providers, purposes, locations, and required privacy configurations. A link to another site, or an embedded service you choose to use, may also connect directly to that provider under its own policy.

Sharing and staff access

A person with an active share link can open the linked document. Anonymous visitors receive a guest account so permissions can be enforced. Edit links permit changes to the writing but do not transfer ownership or permit folder, trash, or journal metadata changes. Revoke a link to invalidate its active share sessions.

Glidey is not end-to-end encrypted. Authorised operators and infrastructure providers can technically access server-stored content using privileged systems. Glidey does not provide a routine admin screen for browsing users' notes. Operational access must be limited to people who need it for a user-requested support task, security incident, or legal obligation. For ordinary support inspection, you can grant access for 24 hours in Privacy & Security settings and revoke it sooner; the support tool requires a written reason and records an audit event. Infrastructure project access should use individual accounts, MFA, least privilege, periodic review, and provider audit logs.

International processing

Glidey is operated from Australia and uses global providers, so information may be processed outside your country, including in Australia, the United States, and locations used by our contracted providers. For EEA/UK transfers, Glidey must use an applicable adequacy decision, Standard Contractual Clauses, or another lawful safeguard. For Australian information, we take reasonable steps required by APP 8 before disclosure to an overseas recipient. Contact us for the safeguard relevant to your data.

Retention and deletion

  • Account data, active writing, AI chats, search chunks, embeddings, settings (including an optional derived typing-calibration profile), and workspace metadata remain while the account is open unless you delete the relevant item earlier. The onboarding reference passage and your typed attempt are analysed once but are not stored.
  • Documents moved to Trash are eligible for automatic permanent deletion after 30 days and can be purged immediately. Version history is capped at 50 snapshots per document and is deleted with the document.
  • Share sessions expire after 30 days unless renewed by use of a still-active link. Revoking the link revokes associated sessions.
  • AI usage logs, unused waitlist entries, contact-form submissions, and completed or denied export-request records are automatically eligible for deletion after 24 months. Other support and security records are kept only while needed for the request, incident, dispute, or legal compliance, and account-linked records are deleted with the account.
  • Payment processors may retain transaction and tax records for periods they are legally required to keep them, even after a Glidey account is deleted.
  • The required Supabase Pro configuration keeps daily database backups for 7 days. These backups do not include Storage objects. A deleted record may therefore remain in an encrypted backup until rotation; backups are used only for disaster recovery and deletion events must be replayed after restoration.
  • Cloudflare Worker logs rotate after 3 days on Free or 7 days on Paid; Netlify function logs rotate after 24 hours or up to 7 days by plan; Sentry is required to use no more than 30 days of event history; optional GA4 event/user data is required to use 2-month retention, although standard aggregate reports may remain longer.

Account deletion cancels the linked payment-customer relationship, removes known Glidey database records, avatars, and private bug-report attachments. Deletion can fail safely if a required provider cannot be reached, so the app does not report success while known data is left behind.

Your choices and rights

In the app you can correct profile data, export documents, manage shares, revoke extension sessions, change analytics consent, empty Trash, and delete your account. You can also ask us to access, correct, delete, restrict, or provide a portable copy of personal information, or object to processing. Some rights depend on your location and lawful exceptions apply. We verify requests through the signed-in account or confirmed account email.

EEA/UK users may complain to their local data protection authority. Australian users may first complain to us and, if unresolved, to the Office of the Australian Information Commissioner. Eligible US residents may appeal a refused request where local law provides that right. We do not discriminate for exercising a privacy right.

Cookies, local storage, and Global Privacy Control

Authentication cookies and local device storage are necessary to keep you signed in, preserve preferences, cache editor state, and protect the service. Optional Google Analytics remains off until you accept it. A browser Global Privacy Control signal is treated as a denial of optional analytics. You can reopen Cookie settings from the site footer or change the Analytics control in app settings. Rejecting optional analytics does not reduce core functionality.

Security

Glidey uses provider-managed encryption in transit and at rest, hashed passwords, private storage for support attachments, tenant-scoped database policies, server-only privileged credentials, expiring share sessions, and redaction of request bodies from error reports. No internet service is perfectly secure. Glidey has not completed an independent security audit and should not be described as end-to-end encrypted.

Children

Glidey is for adults and is not directed to children. Users must confirm they are at least 18 to create or continue using an account. We do not collect a date of birth. If you believe a person under 18 has used Glidey, contact us so we can investigate and delete the account.

Australia's developing Children's Online Privacy Code treats people under 18 as children and is broader than social media. Although under-18s are not eligible for Glidey, we will continue assessing whether the service is likely to be accessed by children and will review it against the final Code before it applies.

Changes and contact

We will give advance notice by email or in the app when a material change affects how we use information. Minor clarifications appear here with a new date. Questions, complaints, and rights requests can be sent to info@glidey.app.