Privacy Policy
Version 2026-09-02
1. Who we are and what we control
This Privacy Policy explains how Glassly("we", "us", "our") handles personal data when you use our hosted app-builder service (the "Service"). It covers data about you — the account holder.
Glasslyis the trading name of a sole-trader business established in the United Kingdom. The operator's full legal name and address for service of documents are set out in Section 12.
For the purposes of the UK General Data Protection Regulation and the Data Protection Act 2018, we are the data controller for personal data we collect about your account (sign-in details, prompts you submit, billing data, and the credentials you give us to operate the Service).
For personal data your generated apps process about their end users, you are the controller. Generated apps run on the end user's own device and connect directly to a Supabase project. Once that is your own project, the data does not flow through our servers and we are not a processor of it. While an app is still on the free starter backend (a Supabase project we custody for you until the app moves to your own), we host that project on your behalf and act only on your instructions with respect to its data — when the app graduates we migrate the data to your own project and delete the starter one. While a starter backend is asleep (idle), we hold a complete backup of it — its database records, including account details of people who signed in to your app, its uploaded files, and (encrypted) any signing or integration secrets — in our own database, solely so we can restore the backend when the app is next used. That backup is deleted when the backend wakes, and in any case when the app or your account is deleted. Either way, you are responsible for providing your end users with their own privacy notice and lawful basis.
Business customers (for example, organisations building apps for their own users or staff) who require a Data Processing Agreement covering the account data we hold about your team's accounts can request one at support@glassly.dev.
We have not appointed a statutory Data Protection Officer (we are not required to under UK GDPR Art. 37). Privacy queries, including the rights set out in Section 9, should be directed to support@glassly.dev.
2. What personal data we collect
- Account data from Google Sign-In: your Google account ID, email address, display name and avatar URL.
- Usage data: app descriptions and prompts you submit, the apps and screens we generate for you, credit balance, request logs (limited to operational metadata such as timestamps, IP, error codes — not the contents of your prompts unless required to investigate a specific issue).
- Supabase connection data: the project reference, URL and publishable (anon) key of the Supabase project you connect, plus the access token and (if you provide it) service-role key we need to operate the Service on your behalf. Tokens and service-role keys are encrypted at rest.
- Third-party integration credentials (e.g. Stripe or OpenAI keys you connect to your generated apps) are stored in your own infrastructure, not ours.
- App distribution and push credentials.If you generate mobile apps, you may give us credentials we need to sign and distribute them on your behalf, or to deliver push notifications — for example an Apple App Store Connect API key, iOS push credentials from Apple, or Firebase credentials from Google. We use these only to operate the Service on your instructions and keep them encrypted at rest.
- Tester device identifiers.If you invite a tester to install a preview build using our enrollment link, the tester's iPhone returns a unique device identifier (UDID), plus basic model and operating system information, so the device can be added to your Apple Developer team. We do not keep a separate copy beyond what is needed to register it with Apple on your behalf. You are responsible for making sure your testers understand and consent to this before they install the enrollment profile.
- Debugging data. When you run a development build of your app and use the built-in debug tools, that build sends us its device logs, error reports and (if you record one) screen recordings of the problem, so the AI can investigate and fix it. These auto-expire on a rolling 7-day basis.
- Billing data for paid plans: handled by Stripe. We store your Stripe customer ID and subscription status. We never see your card details.
- Cookies / local storage: a JWT in your browser's
localStorageto keep you signed in, and a small flag recording your acceptance of these terms before sign-in. These are strictly necessary for the Service to operate, so under the Privacy and Electronic Communications Regulations Reg. 6(4) we do not require a separate consent banner for them. We also set one small first-party cookie on your first visit that records which site referred you (for example a search engine or an AI assistant) and the page you landed on, kept for 30 days and containing nothing that identifies you; if you later create an account, that referral source is stored with it so we can understand where people find us. We do not use advertising cookies.
We do not intentionally collect special category data (data revealing health, biometrics, ethnicity, political opinions, etc.) and ask that you do not include such information in prompts. If you do, we will treat it like the rest of your prompt content but cannot offer additional safeguards required by Art. 9 UK GDPR.
3. Credentials we handle on your behalf
To build, sign, distribute and monetise the apps you create, you may give us credentials for third-party services. We only ever ask for a credential when you choose to use the feature that needs it, and we ask for the narrowest key that will do the job.
The following rules apply to every credential class below:
- Storage. Secret credentials are stored in your own Supabase Vault— never in our own database. Integration secrets (for example Stripe or RevenueCat keys) always require your own Supabase to be connected, so you own where they live from day one. The only exception is build and signing material (your Android keystore, Apple keys) for apps still on the free starter backend we custody for you: that lives in the platform-custodied starter project's Vault until your app graduates, at which point graduation migrates it into your own Supabase. Public keys are not secret by design and simply live in the app and its configuration.
- Access. We use these credentials server-side only, to act on your behalf on your instructions. We never sell or share them.
- Deletion. A credential is removed when you delete the integration it belongs to, delete the app, or delete your account. An account-deletion flow is available from your account settings.
What each credential is for:
- Supabase access(management / OAuth access tokens and project keys) — so we can apply schema, deploy functions and manage your project's configuration for you. The access/management token is a secret; your publishable (anon) key is public.
- Stripe keys (publishable, secret, webhook signing) — so your app can take payments while we wire up checkout, webhooks and subscription logic. The secret and webhook signing keys are secrets; the publishable key is public.
- RevenueCat keys (a V2 secret API key, plus the public SDK keys) — so we can set up your in-app subscriptions automatically (apps, products, entitlement and offering) and your app can read them. The V2 secret API key is a secret; the SDK keys are public.
- Apple App Store Connect keys (App Store Connect API keys and
.p8private keys, for build/upload and for In-App Purchase) — so we can sign, build and upload your iOS app and configure its in-app purchases. These are secrets. - Android signing keystore — so we can sign your Android app for direct install and produce the signed release package you upload to Google Play yourself. This is a secret.
- Push credentials (Firebase service credentials, APNs keys) — so your app can deliver push notifications to your users. These are secrets.
4. Why we use it (lawful bases)
We process the personal data described above on the following lawful bases (UK GDPR Article 6):
- Contract (Art. 6(1)(b)): to operate the Service, run app generation, communicate with your Supabase project on your behalf, bill paid plans, and send you service emails about your account and your apps, for example when a build is ready to install, when something in a run needs your answer, or before your test backend pauses or is removed. These are factual service messages, not marketing.
- Legitimate interests (Art. 6(1)(f)): keeping the Service secure, preventing abuse, debugging, basic product analytics. You can object — see Section 9.
- Legal obligation (Art. 6(1)(c)): tax records, responding to lawful requests.
- Consent (Art. 6(1)(a)): where we explicitly ask, for example before sending optional product updates.
Automated decision-making. The Service does not make decisions about you that produce legal or similarly significant effects within the meaning of UK GDPR Art. 22. AI-generated app code is created at your request and reviewed by you before use; it is not used to evaluate or take decisions about you as an individual.
5. Sub-processors and data sharing
We share personal data only with the providers needed to deliver the Service, on contractual terms requiring confidentiality and appropriate security:
- OpenRouter, Inc. (USA) — the AI gateway through which your prompts and app descriptions are sent to the model providers that generate your apps. We use routing terms that do not permit the models to be trained on your content. Subject to OpenRouter's privacy policy.
- Exa Labs, Inc. (USA) — web search used when the builder researches documentation for an integration you request. It receives the search queries, not your prompts or account data.
- Google LLC (USA) — sign-in only; we receive your basic profile after you authenticate.
- Stripe Payments Europe Ltd (Ireland) — payment processing for paid plans.
- Supabase Inc. (USA) — we connect to your Supabase project on your behalf using the credentials you provide. We are not party to your relationship with Supabase.
- Apple Inc.(USA) — where you generate iOS apps, we use Apple's developer and push notification services on your instructions and within your own Apple Developer account. We are not party to your relationship with Apple.
- Google LLC(USA) — additionally to sign-in, where you configure Android push notifications, your apps' pushes are delivered via Google's push infrastructure using credentials you provide.
- Resend, Inc. (USA, sending from EU infrastructure): delivers the service emails described in Section 4. It receives your email address and the content of those messages, nothing more. Subject to Resend's privacy policy.
- Cloudflare, Inc. (USA) — hosts the app builds behind the install links you share with your testers, so they can install directly on their device. Install links are unguessable and served from our own domain.
- A cloud database provider (USA) — hosts the database that stores your account and connection metadata.
We do not sell personal data and do not use it for advertising profiling.
6. International transfers
Several of our sub-processors (notably the AI provider, Google, Apple, and our database host) are based outside the UK. Where personal data is transferred internationally we rely on the UK International Data Transfer Agreement (or the EU Standard Contractual Clauses with the UK Addendum), and on the providers' own UK/EU data residency options where available.
7. Retention
- Account data: kept while your account is active. Deleted within 30 days of account deletion.
- Generated apps and prompts: kept while your account is active. You can delete individual apps from your dashboard at any time.
- Supabase connection data (project ref, encrypted access token, etc.): kept until you disconnect or delete your account.
- App distribution and push credentials you upload: kept while the corresponding app exists in your account. Deleted alongside the app.
- Tester device identifiers: registered with your Apple Developer team for as long as you have iOS preview builds for that app, and removed from the team when you delete the app.
- Preview build files: rolled on a most-recent-N basis per app; older preview builds are deleted automatically.
- Debugging data from development builds (device logs, error reports, screen recordings): rolling 7 days.
- Operational logs: rolling 30 days.
- Starter-backend project data: deleted when the app graduates to your own Supabase project (after the data is migrated across) or when you delete the app. We may keep a short-term recovery copy of the migrated data to protect against a failed migration, and delete it once the migration is confirmed healthy.
- Billing records: retained for 6 years to meet UK tax obligations.
8. Security
We use industry-standard encryption in transit and at rest, and follow least-privilege access controls internally. No system is 100% secure; please report suspected vulnerabilities to support@glassly.dev.
If we become aware of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in line with UK GDPR Art. 34, and will report to the Information Commissioner's Office where required under Art. 33.
9. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17), subject to lawful retention obligations;
- restrict processing (Art. 18) or object to it (Art. 21) — including direct marketing;
- data portability (Art. 20);
- withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, email support@glassly.dev. We aim to respond within one month, extendable by up to two further months for complex or numerous requests in line with UK GDPR Art. 12(3); if we need that extra time we will tell you within the first month and explain why.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint. We'd appreciate the chance to address your concern first.
10. Children
The Service is intended for business users aged 16 and over and is not directed at children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. The version number above will change and, when it does, you will be asked to review and re-accept on next sign-in. Material changes will also be communicated by email where reasonable.
12. Service provider details
Glassly is a trading name of Haroon Khan, a sole trader established in the United Kingdom.
Address for correspondence and service of documents: available on request by email.Email: support@glassly.devPublished under reg. 6 of the Electronic Commerce (EC Directive) Regulations 2002 and Part 41 of the Companies Act 2006.
See also our Terms of Service.