1. Information we handle
Glattice handles account and profile information, authentication-provider details, spaces and memberships, board content, cards, facets, comments, change history, uploaded media, notification preferences, billing identifiers and subscription status, and messages you send to support. Technical requests also produce ordinary service and security logs.
2. Why we use it
We use this information to authenticate you, provide and synchronize boards, enforce permissions and plan limits, process subscriptions, deliver requested notifications, answer support requests, prevent abuse, and maintain the service.
3. Service providers
Vercel hosts the web application. Supabase provides Postgres, authentication, storage, Realtime, and edge functions. Stripe processes subscriptions and receives billing information. Purelymail delivers transactional and notification email. Google receives identity information when you choose Google sign-in and receives AI request data only when you invoke an AI feature.
4. AI processing
The AI Command Bar uses Google Gemini. When you invoke it, Glattice sends your prompt and the board text needed for the request to Gemini. Private image URLs are redacted before that request. We do not use board content to train a Glattice model, but Google processes the submitted data as our AI provider under its own service terms.
5. Storage and security
Connections use TLS and our providers manage encryption at rest. Postgres row-level security separates spaces and users, and protected actions are checked on the server. Glattice is not end-to-end encrypted or zero-knowledge.
6. Operator access
Glattice as the service operator can technically access stored content. That capability is necessary to operate, secure, troubleshoot, and comply with legal obligations for the service. Row-level security prevents one customer from reading another customer’s rows; it is not a claim that the operator cannot access the database.
7. Export scope
JSON and CSV export are available inside an open board on every plan. They cover the documented board structure and content, including cards, facets, values, assignments, and dates. They do not export your account, comments, or change history. Media references may be temporary signed URLs that expire.
8. Retention and deletion
There is not currently a self-service account-deletion control or a published fixed retention schedule. Contact privacy@glattice.app to request access, correction, or deletion. Some records may need to remain for billing, security, backup, or legal reasons; we will explain the applicable limit when responding to a request.
9. Browser storage and analytics
Glattice uses browser storage for the authenticated session and preferences such as theme, language, the current space, and the remembered sign-in method. We do not currently run third-party marketing analytics on the application.
10. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive personal information. Contact us to make a request. We may need to verify that the request comes from the account holder.
11. Contact
Questions and privacy requests can be sent to privacy@glattice.app.