Privacy Policy

What Glattice handles, which providers receive it, and where the limits are.

Last updated: August 15, 2026
Glattice sells software. We do not sell customer data or use board content to train Glattice models. If you choose an AI feature, the prompt and relevant board content are sent to Google Gemini to perform that request.

1. Information we handle

Glattice handles account and profile information, authentication-provider details, spaces and memberships, board content, cards, facets, comments, change history, uploaded media, notification preferences, billing identifiers and subscription status, and messages you send to support. Technical requests also produce ordinary service and security logs.

2. Why we use it

We use this information to authenticate you, provide and synchronize boards, enforce permissions and plan limits, process subscriptions, deliver requested notifications, answer support requests, prevent abuse, and maintain the service.

3. Service providers

Vercel hosts the web application. Supabase provides Postgres, authentication, storage, Realtime, and edge functions. Stripe processes subscriptions and receives billing information. Purelymail delivers transactional and notification email. Google receives identity information when you choose Google sign-in and receives AI request data only when you invoke an AI feature.

4. AI processing

The AI Command Bar uses Google Gemini. When you invoke it, Glattice sends your prompt and the board text needed for the request to Gemini. Private image URLs are redacted before that request. We do not use board content to train a Glattice model, but Google processes the submitted data as our AI provider under its own service terms.

5. Storage and security

Connections use TLS and our providers manage encryption at rest. Postgres row-level security separates spaces and users, and protected actions are checked on the server. Glattice is not end-to-end encrypted or zero-knowledge.

6. Operator access

Glattice as the service operator can technically access stored content. That capability is necessary to operate, secure, troubleshoot, and comply with legal obligations for the service. Row-level security prevents one customer from reading another customer’s rows; it is not a claim that the operator cannot access the database.

7. Export scope

JSON and CSV export are available inside an open board on every plan. They cover the documented board structure and content, including cards, facets, values, assignments, and dates. They do not export your account, comments, or change history. Media references may be temporary signed URLs that expire.

8. Retention and deletion

There is not currently a self-service account-deletion control or a published fixed retention schedule. Contact privacy@glattice.app to request access, correction, or deletion. Some records may need to remain for billing, security, backup, or legal reasons; we will explain the applicable limit when responding to a request.

9. Browser storage and analytics

Glattice uses browser storage for the authenticated session and preferences such as theme, language, the current space, and the remembered sign-in method. We do not currently run third-party marketing analytics on the application.

10. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive personal information. Contact us to make a request. We may need to verify that the request comes from the account holder.

11. Contact

Questions and privacy requests can be sent to privacy@glattice.app.