Privacy Policy

Welcome! Your privacy matters to us. We've worked hard to keep this policy clear and transparent about how we handle your data.

This Privacy Policy applies to everyone who uses Glitter AI, whether you're on a free trial, free plan, or paid subscription, and to visitors of our website. If you have questions or concerns, reach out via the chat in the bottom right corner or via privacy@glitter.io.

Plain-English Summary

Heads up: This is just a summary for your convenience. The legal terms below are what actually govern our agreement.

  • What we collect: Basic account info (name, email, organization), how you use the service, and device and browser info. Payment details go straight to Stripe; we never see your full card number.
  • Your guides are yours: If you use Glitter through your employer or another organization, that organization controls the recordings and guides you create, and Glitter processes them only on its behalf under our Data Processing Addendum.
  • Why we collect it: To provide the service, process payments, keep the service secure, improve the product, communicate with you, and provide support.
  • Who we share with: Service providers that run parts of Glitter (hosting, AI, payments, support, analytics) and, for our own marketing, advertising platforms. We never sell your data. Some advertising measurement counts as "sharing" under California law, and you can opt out.
  • Security: A SOC 2 Type II audited security program protects your data. Read more at our Trust Center.
  • AI training: We never use your content or personal data to train AI models, and we don't let our AI providers do it either. Learn more about our AI security and privacy practices.
  • Data redaction: Redact sensitive information on your device before it's captured, or remove it from cloud storage after the fact; prior copies are purged within 30 days.
  • Your rights: You can access, correct or delete your data anytime, and ask us for a copy of it. If you're in the EEA, the UK, Switzerland, California or another US state with a privacy law, you have additional rights described below.
  • Questions? Email us at privacy@glitter.io

What this Privacy Policy Covers

This Privacy Policy covers how Glitter AI, Inc. ("Glitter", "we", "us") treats Personal Data that we gather when you access or use our website, applications and services (the "Services"). "Personal Data" means any information that identifies or relates to a particular individual and also includes information referred to as "personally identifiable information" or "personal information" under applicable data privacy laws, rules or regulations. This Privacy Policy does not cover the practices of companies we don't own or control or people we don't manage.

Customer Content and Our Role as a Processor

Glitter is a tool for recording your screen and voice to create process documentation. The recordings, screenshots, audio, transcripts, uploaded files and guides that you create with the Services ("Customer Content") may contain Personal Data about you and about other people, such as colleagues, customers or other individuals whose information appears on your screen.

When you use the Services on behalf of an organization (for example, your employer), that organization is the controller of Customer Content and Glitter processes it only on the organization's behalf and according to its instructions, as its processor or "service provider". Our Data Processing Addendum governs that processing, and the organization's own privacy policy explains how it uses Customer Content. If your Personal Data appears in Customer Content created by a Glitter customer, please direct your privacy requests to that customer in the first instance; we will assist them in responding.

We never use Customer Content to train or improve artificial intelligence or machine learning models, and we contractually prohibit the AI providers we use from doing so. The rest of this Privacy Policy covers the Personal Data for which Glitter is the controller: account, billing, support, usage and website visitor data.

How Glitter Uses AI

Glitter uses AI models from the providers listed on our Sub-Processors page to transcribe narration, generate and edit guide text, screen and redact sensitive information, and answer questions about a guide. To answer a question, the guide's content is sent to the model together with the question. Conversations in the guide editor are stored with the guide and are visible in the Services only to the person who asked; questions asked on a shared guide are not stored. No AI provider may use your content or questions to train or improve its models, and neither does Glitter. AI output can be inaccurate or incomplete, so review it before relying on it. Glitter's AI features do not make decisions about you that produce legal or similarly significant effects, and where the law requires it, Glitter tells you when you are interacting with AI.

Personal Data

Categories of Personal Data We Collect

This chart details the categories of Personal Data that we collect and have collected over the past 12 months:

Category of Personal Data Examples of Personal Data We Collect Categories of Third Parties With Whom We Share this Personal Data
Profile or Contact Data First and last name, email address, profile picture, organization name, job title or role Service Providers, Advertising Partners (hashed identifiers only), Analytics Partners
Payment Data Billing name and address, and the card type, expiry and last four digits of your payment card. Full card numbers are collected and stored directly by our payment processor, Stripe, and never by Glitter Service Providers (specifically our payment processing partner, currently Stripe, Inc.)
Device/IP Data IP address, type of device, operating system and browser used to access the Services Service Providers, Analytics Partners, Advertising Partners
Usage and Session Data Pages visited, features used, guide views and engagement, and replays of your interactions with the Glitter web application (session replay is disabled for HIPAA-enabled organizations) Service Providers, Analytics Partners
Support and Feedback Data Messages, feedback and voice dictation you send us through the Services or by email Service Providers

Categories of Sources of Personal Data

We collect Personal Data about you from the following categories of sources:

  • You
    • When you provide such information directly to us.
      • When you create an account or use our interactive tools and Services.
      • When you voluntarily provide information in free-form text boxes through the Services or through responses to surveys or questionnaires.
      • When you send us an email or otherwise contact us.
    • When you use the Services and such information is collected automatically.
      • Through Cookies (defined in the "Tracking Tools and Opt-Out" section below).
  • Third Parties
    • Vendors
      • We may use analytics providers to analyze how you interact and engage with the Services, or third parties may help us provide you with customer support.
      • We may use vendors to obtain information to generate leads and create user profiles.
    • Your organization
      • When an administrator of your organization invites you to Glitter or manages your account.
    • Single sign-on providers
      • When you sign in with Google or your organization's identity provider, we receive your name, email address and profile picture from that provider.

Our Commercial or Business Purposes for Collecting Personal Data

  • Providing, Customizing and Improving the Services
    • Creating and managing your account or other user profiles.
    • Providing you with the products, services or information you request.
    • Meeting or fulfilling the reason you provided the information to us.
    • Providing support and assistance for the Services.
    • Improving the Services, including testing, research, internal analytics and product development.
    • Personalizing the Services, website content and communications based on your preferences.
    • Doing fraud protection, security and debugging.
    • Carrying out other business purposes stated when collecting your Personal Data or as otherwise set forth in applicable data privacy laws, such as the California Consumer Privacy Act (the "CCPA").
  • Marketing the Services
    • Marketing and selling the Services, including measuring the effectiveness of our advertising.
  • Corresponding with You
    • Responding to correspondence that we receive from you, contacting you when necessary or requested, and sending you information about Glitter or the Services.
    • Sending emails and other communications according to your preferences or that display content that we think will interest you.
  • Meeting Legal Requirements and Enforcing Legal Terms
    • Fulfilling our legal obligations under applicable law, regulation, court order or other legal process, such as preventing, detecting and investigating security incidents and potentially illegal or prohibited activities.
    • Protecting the rights, property or safety of you, Glitter or another party.
    • Enforcing any agreements with you.
    • Responding to claims that any posting or other content violates third-party rights.
    • Resolving disputes.

We will not collect additional categories of Personal Data or use the Personal Data we collected for materially different, unrelated or incompatible purposes without providing you notice.

How We Share Your Personal Data

We disclose your Personal Data to the categories of service providers and other parties listed in this section. Depending on state laws that may be applicable to you, some of these disclosures may constitute "sharing" of your Personal Data for cross-context behavioral advertising. We do not sell Personal Data. For more information, please refer to the state-specific sections below.

  • Service Providers. These parties help us provide the Services or perform business functions on our behalf. They include hosting and cloud infrastructure providers, AI model providers, payment processors, email delivery providers, customer support and messaging providers, error monitoring providers and analytics providers. The vendors that may process Customer Content are listed on our Sub-Processors page.
  • Advertising Partners. These parties help us market the Services and measure our advertising. They include advertising platforms (currently Google Ads, Meta and Reddit) that receive limited data such as hashed email addresses, click identifiers and conversion events (for example, that an account was created or a subscription started), and an affiliate program provider that attributes referrals. We do not share Customer Content with Advertising Partners.
  • Parties You Authorize, Access or Authenticate. Third parties you access through the Services, single sign-on providers, and people and organizations you choose to share guides with.

We may share any Personal Data that we collect with third parties in conjunction with any of the activities set forth under "Meeting Legal Requirements and Enforcing Legal Terms" in the "Our Commercial or Business Purposes for Collecting Personal Data" section above.

Business Transfers

All of your Personal Data that we collect may be transferred to a third party if we undergo a merger, acquisition, bankruptcy or other transaction in which that third party assumes control of our business (in whole or in part). Should one of these events occur, we will make reasonable efforts to notify you before your information becomes subject to different privacy and security policies and practices.

Data that is Not Personal Data

We may create aggregated, de-identified or anonymized data from the Personal Data we collect, including by removing information that makes the data personally identifiable to a particular user. We may use such aggregated, de-identified or anonymized data and share it with third parties for our lawful business purposes, including to analyze, build and improve the Services and promote our business, provided that we will not share such data in a manner that could identify you, and we will not attempt to re-identify it.

Tracking Tools and Opt-Out

The Services use cookies and similar technologies such as pixel tags, web beacons, local storage and JavaScript (collectively, "Cookies") to enable our servers to recognize your web browser, tell us how and when you visit and use our Services, analyze trends, learn about our user base, measure our advertising and operate and improve our Services. Cookies are small pieces of data - usually text files - placed on your computer, tablet, phone or similar device when you use that device to access our Services. We may also supplement the information we collect from you with information received from third parties, including third parties that have placed their own Cookies on your device(s). We honor the Global Privacy Control browser signal as a valid opt-out of Targeting Cookies.

We use the following types of Cookies:

  • Essential Cookies. Essential Cookies are required for providing you with features or services that you have requested. For example, certain Cookies enable you to log into secure areas of our Services. Disabling these Cookies may make certain features and services unavailable.
  • Functional Cookies. Functional Cookies are used to record your choices and settings regarding our Services, maintain your preferences over time and recognize you when you return to our Services. These Cookies help us to personalize our content for you, greet you by name and remember your preferences (for example, your choice of language or region). On our website, the support chat (Intercom) uses Cookies of this type. Inside the Glitter application, support chat is part of the service and its Cookies are strictly necessary.
  • Performance and Analytics Cookies. These Cookies collect information about how you use the Services so that we can understand and improve them. They include Google Analytics on our website, our product analytics tool (Mixpanel) and our self-hosted session replay tool on our website. Inside the Glitter application, product analytics and session replay are how we operate the service, support customers and troubleshoot problems, so they are strictly necessary there; session replay is disabled for HIPAA-enabled organizations.
  • Targeting and Advertising Cookies. These Cookies are set by advertising platforms (currently Google Ads, Meta and Reddit) and our affiliate program provider to measure the effectiveness of our advertising and to show you relevant advertising for Glitter on other sites.

Where the law requires your consent, a banner asks you to accept or reject non-essential Cookies by category before they are set. Elsewhere, non-essential Cookies may be set when you arrive and you can turn them off at any time. In both cases you can change your choices using the "Do Not Sell or Share My Personal Information" link in the footer of our website, and we honor the Global Privacy Control browser signal as an opt-out of Targeting Cookies. You can also decide whether or not to accept Cookies through your internet browser's settings. Most browsers have an option for turning off the Cookie feature, which will prevent your browser from accepting new Cookies, as well as (depending on the sophistication of your browser software) allow you to decide on acceptance of each new Cookie in a variety of ways. You can also delete all Cookies that are already on your device. If you do this, however, you may have to manually adjust some preferences every time you visit our website and some of the Services and functionalities may not work.

To explore what Cookie settings are available to you, look in the "preferences" or "options" section of your browser's menu. To find out more information about Cookies, including information about how to manage and delete Cookies, please visit http://www.allaboutcookies.org/.

Data Security and Retention

We seek to protect your Personal Data from unauthorized access, use and disclosure using appropriate physical, technical, organizational and administrative security measures based on the type of Personal Data and how we are processing that data. Our security program is independently audited each year against the SOC 2 Type II criteria, and data is encrypted in transit and at rest. You should also help protect your data by appropriately selecting and protecting your password and/or other sign-on mechanism; limiting access to your computer or device and browser; and signing off after you have finished accessing your account. Although we work to protect the security of your account and other data that we hold in our records, please be aware that no method of transmitting data over the internet or storing data is completely secure.

Data Redaction Features

To enhance your privacy protection, Glitter provides advanced data redaction capabilities:

  • On-Device Redaction: You can redact sensitive information directly on your device before screenshots are captured and transmitted to our servers. This ensures that sensitive data never reaches our cloud storage systems.
  • Cloud-Based Redaction: You can redact information in screenshots after they are stored through our web interface. The redacted image replaces the stored screenshot, and prior versions and backup copies are purged within 30 days. Redaction cannot be undone through the Services.

These redaction features provide you with additional control over your sensitive information and support data minimization principles.

Retention

We retain Personal Data about you for as long as you have an open account with us or as otherwise necessary to provide you with our Services. Customer Content is retained for as long as your organization's subscription continues and is deleted afterwards in accordance with our Data Processing Addendum, or earlier if you or your organization delete it. Deleted content is removed from our systems, including backups, within 30 days. In some cases we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule or regulation. We may further retain information in an anonymous or aggregated form where that information would not identify you personally.

International Data Transfers

Glitter is based in the United States, and we and our service providers store and process Personal Data in the United States, which may not provide the same level of data protection as the laws of your country. When you provide Personal Data to us directly from the EEA, the UK or Switzerland, we apply the GDPR, the UK GDPR or the Swiss FADP directly to that processing, as described in the section for users in those regions below. When our business customers in the EEA, the UK or Switzerland transfer Customer Content to us, the transfer is protected by the European Commission's 2021 Standard Contractual Clauses, the UK International Data Transfer Addendum and the Swiss adjustments incorporated in our Data Processing Addendum. Where we transfer Personal Data onward to service providers, we do so under written contracts that require appropriate safeguards.

Personal Data of Children

As noted in the Terms of Use, we do not knowingly collect or solicit Personal Data about children under 16 years of age; if you are a child under the age of 16, please do not attempt to register for or otherwise use the Services or send us any Personal Data. If we learn we have collected Personal Data from a child under 16 years of age, we will delete that information as quickly as possible. If you believe that a child under 16 years of age may have provided Personal Data to us, please contact us at privacy@glitter.io.

Additional Information for Users in the EEA, the UK and Switzerland

This section applies if you are located in the European Economic Area, the United Kingdom or Switzerland. Glitter AI, Inc. is the controller of the Personal Data described in this Privacy Policy, other than Customer Content, for which the Glitter customer on whose behalf we process it is the controller. Our contact details are at the end of this Privacy Policy.

  • Performance of a contract: to create and manage your account, provide the Services, process payments and provide support (Article 6(1)(b) GDPR).
  • Legitimate interests: to secure the Services and prevent fraud and abuse, to understand how the Services are used and improve them, to communicate with business users about the Services, and to market the Services to businesses, in each case where our interests are not overridden by your rights (Article 6(1)(f) GDPR).
  • Consent: for non-essential Cookies and similar technologies where consent is required, and for marketing communications where consent is required. You can withdraw consent at any time (Article 6(1)(a) GDPR).
  • Legal obligation: to comply with laws that apply to us, such as tax, accounting and law enforcement obligations (Article 6(1)(c) GDPR).

Your rights

Subject to applicable law, you have the right to: access the Personal Data we hold about you; have inaccurate Personal Data corrected; have your Personal Data erased; restrict our processing of your Personal Data; receive the Personal Data you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another controller; object to processing based on our legitimate interests, including profiling, and to direct marketing at any time; withdraw consent at any time, without affecting the lawfulness of processing before withdrawal; and not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions about you. To exercise these rights, contact us at privacy@glitter.io. We will respond within the time required by applicable law and may need to verify your identity first. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work or the place of an alleged infringement, with the UK Information Commissioner's Office, or with the Swiss Federal Data Protection and Information Commissioner.

California Resident Rights

If you are a California resident, you have the rights set forth in this section. Please see the "Exercising Your Rights" section below for instructions regarding how to exercise these rights. Please note that we may process Personal Data of our customers' end users or employees in connection with our provision of certain services to our customers. If we are processing your Personal Data as a service provider, you should contact the entity that collected your Personal Data in the first instance to address your rights with respect to such data.

If there are any conflicts between this section and any other provision of this Privacy Policy and you are a California resident, the portion that is more protective of Personal Data shall control to the extent of such conflict. If you have any questions about this section or whether any of the following rights apply to you, please contact us at privacy@glitter.io.

Access

You have the right to request certain information about our collection and use of your Personal Data over the past 12 months. In response, we will provide you with the following information:

  • The categories of Personal Data that we have collected about you.
  • The categories of sources from which that Personal Data was collected.
  • The business or commercial purpose for collecting, selling or sharing your Personal Data.
  • The categories of third parties with whom we have shared your Personal Data.
  • The specific pieces of Personal Data that we have collected about you.

If we have disclosed your Personal Data to any third parties for a business purpose over the past 12 months, we will identify the categories of Personal Data shared with each category of third party recipient. If we have sold or shared your Personal Data over the past 12 months, we will identify the categories of Personal Data sold or shared to each category of third party recipient.

Correction and Deletion

You have the right to request that we correct inaccurate Personal Data that we maintain about you, and to request that we delete the Personal Data that we have collected about you. Under the CCPA, the right to deletion is subject to certain exceptions: for example, we may need to retain your Personal Data to provide you with the Services or complete a transaction or other action you have requested. If your deletion request is subject to one of these exceptions, we may deny your deletion request.

Exercising Your Rights

To exercise the rights described above, you or your Authorized Agent (defined below) must send us a request that (1) provides sufficient information, such as your email address, Account UCID (unique customer identifier) and UUID (unique user identifier) to allow us to verify that you are the person about whom we have collected Personal Data, and (2) describes your request in sufficient detail to allow us to understand, evaluate and respond to it. Each request that meets both of these criteria will be considered a "Valid Request." We may not respond to requests that do not meet these criteria. We will only use Personal Data provided in a Valid Request to verify your identity and complete your request. You do not need an account to submit a Valid Request.

We will work to respond to your Valid Request within 45 days of receipt. We will not charge you a fee for making a Valid Request unless your Valid Request(s) is excessive, repetitive or manifestly unfounded. If we determine that your Valid Request warrants a fee, we will notify you of the fee and explain that decision before completing your request.

You may submit a Valid Request using the following methods:

Email us at: privacy@glitter.io

You may also authorize an agent (an "Authorized Agent") to exercise your rights on your behalf. To do this, you must provide your Authorized Agent with written permission to exercise your rights on your behalf, and we may request a copy of this written permission from your Authorized Agent when they make a request on your behalf.

Personal Data Sales and Sharing Opt-Out

We do not sell your Personal Data, and have not done so over the last 12 months. We may "share" limited Personal Data (such as hashed email addresses, device identifiers and conversion events) with advertising platforms for cross-context behavioral advertising, as described under "How We Share Your Personal Data". You can opt out of sharing by using the "Do Not Sell or Share My Personal Information" link in the footer of our website and rejecting Targeting and Advertising Cookies, or by emailing privacy@glitter.io. To our knowledge, we do not sell or share the Personal Data of minors under 16 years of age. We do not use or disclose sensitive personal information for purposes that require a right to limit under the CCPA.

We Will Not Discriminate Against You for Exercising Your Rights Under the CCPA

We will not discriminate against you for exercising your rights under the CCPA. We will not deny you our goods or services, charge you different prices or rates, or provide you a lower quality of goods and services if you exercise your rights under the CCPA. However, we may offer different tiers of our Services as allowed by applicable data privacy laws (including the CCPA) with varying prices, rates or levels of quality of the goods or services you receive related to the value of Personal Data that we receive from you.

Other State Law Privacy Rights

Residents of Other US States

If you are a resident of a US state with a comprehensive privacy law (such as Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah or Virginia), you may have the right to: confirm whether we process your Personal Data and access it; correct inaccuracies; delete your Personal Data; obtain a copy of your Personal Data in a portable format; and opt out of targeted advertising, the sale of Personal Data and profiling in furtherance of decisions that produce legal or similarly significant effects. We do not sell Personal Data or engage in such profiling. To exercise these rights, or to opt out of targeted advertising, use the methods described under "Exercising Your Rights" and "Personal Data Sales and Sharing Opt-Out". If we deny your request, you may appeal by emailing privacy@glitter.io with the subject line "Privacy Appeal", and we will respond in writing within the period required by your state's law. If your appeal is denied, you may contact your state attorney general.

California Resident Rights

Under California Civil Code Sections 1798.83-1798.84, California residents are entitled to contact us to prevent disclosure of Personal Data to third parties for such third parties' direct marketing purposes; in order to submit such a request, please contact us at privacy@glitter.io.

Nevada Resident Rights

If you are a resident of Nevada, you have the right to opt-out of the sale of certain Personal Data to third parties who intend to license or sell that Personal Data. You can exercise this right by contacting us at privacy@glitter.io with the subject line "Nevada Do Not Sell Request" and providing us with your name and the email address associated with your account. Please note that we do not currently sell your Personal Data as sales are defined in Nevada Revised Statutes Chapter 603A.

Changes to this Privacy Policy

We're constantly trying to improve our Services, so we may need to change this Privacy Policy from time to time, but we will alert you to any such changes by placing a notice on the Glitter website, by sending you an email and/or by some other means. Please note that if you've opted not to receive legal notice emails from us (or you haven't provided us with your email address), those legal notices will still govern your use of the Services, and you are still responsible for reading and understanding them. If you use the Services after any changes to the Privacy Policy have been posted, that means you agree to all of the changes. Use of information we collect is subject to the Privacy Policy in effect at the time such information is collected.

Contact Information

If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your Personal Data or your choices and rights regarding such collection and use, please do not hesitate to contact us at:

  • Glitter AI, Inc., 1111B S Governors Ave STE 7606, Dover, DE 19904, United States
  • privacy@glitter.io
  • https://www.glitter.io

Last updated: September 19, 2026