Privacy Policy
Last updated: January 2026
1. Introduction
Glyphia ("we", "our", or the "Platform") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information in compliance with global data protection regulations, including the General Data Protection Regulation (GDPR).
2. Data We Collect
2.1 Identification Data
- Full name
- Email address
- Profile picture (when provided)
- Username (nickname)
2.2 Account and Subscription Data
- Type of subscription plan
- Payment history
- Subscription status
- Number of exports completed
2.3 Device Data
- Unique device identifier (fingerprint)
- Browser type and operating system
- IP address (when necessary)
- Date and time of last access
2.4 Usage Data
- Images processed by the engine (temporarily in memory)
- Export settings utilized
- Interactions with the platform
3. Legal Basis and Purposes
We collect and process your data based on the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Authentication and account management | Performance of a contract (Art. 6(1)(b)) |
| Payment processing | Performance of a contract (Art. 6(1)(b)) |
| Authorized device control | Legitimate interest (Art. 6(1)(f)) |
| Platform usage analytics | Consent (Art. 6(1)(a)) |
| Marketing communications | Consent (Art. 6(1)(a)) |
| Fraud prevention | Legitimate interest (Art. 6(1)(f)) |
4. Cookies and Similar Technologies
We use cookies to:
- Essential Cookies: Required for authentication, security, and basic operations.
- Analytics Cookies: Help us understand how you use the platform (requires consent).
- Marketing Cookies: Used to customize content and advertisements (requires consent).
You can manage your cookie preferences at any time through our cookie consent banner or within your browser settings.
5. Data Sharing
We share your data only with the following trusted third parties:
- Clerk: Authentication provider (data processor)
- Convex: Real-time cloud database (data processor)
- Payment Processors: To handle secure financial transactions
We do not sell, rent, or share your personal data with third parties for their marketing purposes without your explicit consent.
6. Data Security
We implement appropriate technical and organizational security measures, including:
- Encryption in transit (HTTPS/TLS)
- Secure authentication via OAuth 2.0 / Clerk
- Device-based access control
- Monitoring of suspicious activities
- Regular and secure backups
7. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access: Request confirmation and access to your data.
- Right to Rectification: Request correction of incomplete or inaccurate data.
- Right to Erasure (Right to be Forgotten): Request deletion of unnecessary data.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Withdraw Consent: Revoke your consent at any time.
- Right to Information: Know which entities we share your data with.
To exercise these rights, please contact us via email at: privacy@glyphia.app
8. Data Retention
- Account data: Retained for as long as your account is active.
- Payment records: Retained for 5 years (for tax and legal compliance).
- Processed images: We do not store your uploaded images; they are processed entirely locally.
- Access logs: Retained for 6 months.
9. International Data Transfers
Your data may be processed on servers located in the United States (Convex, Clerk). These international transfers are performed based on Standard Contractual Clauses (SCCs) and appropriate safety measures to ensure data protection.
10. Minors
Glyphia is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If you are a parent or guardian and believe your child has provided personal data to us, please contact us immediately.
11. Changes to this Policy
We may update this policy periodically. We will notify you of any significant changes by email or through a prominent notice on the platform.
12. Contact
For questions regarding this policy or the processing of your personal data:
Data Protection Officer (DPO):
Email: privacy@glyphia.app
13. Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a competent data protection supervisory authority.
