1. Scope
This policy applies to askglyph.com, the Glypy web API, Glypy Desktop, and related account, billing, download, and asset services operated by Borealbit under the Glypy product name.
2. Information we process
- Account information: name, email address, authentication identifiers, and session metadata.
- Product information: workspaces, projects, prompts, selected settings, asset metadata, and files you explicitly upload or choose to store.
- Usage information: API key prefix and scope, model and task type, token or image counts, credits spent, timestamps, errors, and rate-limit activity.
- Billing information: customer, subscription, invoice, purchase, and credit-ledger records. Payment card details are handled by the payment provider, not stored by Glypy.
- Technical information: IP-derived security hashes, user agent, download events, and operational logs needed to secure and run the service.
3. Local and cloud boundaries
Glypy Desktop is local-first. Complete local project folders, full agent transcripts, intermediate files, runtime logs, checkpoints, and local authentication stores remain on your device unless you explicitly upload, store, or sync them.
Cloud systems store account records, browser and client session hashes, workspace and project metadata, assets you explicitly store, AI usage, credits, subscription state, and release-download records.
4. How information is used
- Provide authentication, downloads, AI generation, asset storage, billing, and support.
- Authorize access, enforce scopes and rate limits, prevent abuse, and investigate security incidents.
- Measure reliability and credit usage, reconcile purchases, and improve product workflows.
- Meet legal obligations and enforce the Terms of Service.
Glypy does not sell personal information. Private project content is not made public by default.
Optional website analytics
With your permission, we use Microsoft Clarity to understand interactions with our public website through heatmaps and session recordings. Clarity processes interaction, device, browser, and page information, and uses cookies after you allow analytics. We keep advertising storage consent denied. This does not measure app installs or purchases.
Recording is disabled before consent, for signed-in visits, account pages, and URLs containing query parameters. User-specific content and form fields are masked. Native app content, prompts, and generated assets are not part of this website analytics integration. Your choice lasts up to 180 days. Use Analytics preferences at the bottom of a public page to decline or withdraw permission; withdrawal reloads the page to stop recording.
Learn how Microsoft processes this information in the Microsoft Privacy Statement.
5. Service providers
Glypy uses infrastructure, database and authentication, object storage, AI model, payment, and app-distribution providers. They process information only to supply their services and under their own contractual and security obligations.
6. Retention and deletion
Information is retained while your account is active and as needed for security, billing, legal, and operational purposes. Revoked API keys and client sessions remain as limited audit records. Billing and transaction records may be retained when required by law.
You may request access, correction, export, or deletion through the support channel provided in the Glypy app. Some records may be retained where deletion would conflict with legal, fraud-prevention, or accounting requirements.
7. Security
Glypy uses hashed API keys and client tokens, one-time authorization codes, access controls, private-by-default asset storage, and transport encryption. No system is perfectly secure; protect secrets and revoke credentials you no longer use.
8. International processing and children
Service providers may process information in countries other than your own. Glypy is not directed to children under 13, and we do not knowingly collect their personal information.
9. Changes and contact
Material changes will be posted here with a revised date. Privacy requests can be submitted to support@askglyph.com or through the official support channel shown in Glypy Desktop or your account experience.