PRIVACY POLICY.
This policy explains how Glyphic handles information across the browser extension, website, account services, synchronized workspace, and public community features.
WHO THIS POLICY COVERS.
This policy applies to Glyphic's website, browser extension, account and synchronization services, and public discussion features. Glyphic is operated from Canada. For privacy questions, access or correction requests, or deletion requests, contact hello@glyphic.ca with the subject “Privacy request.”
- Policy effective date: July 18, 2026
- Privacy contact: hello@glyphic.ca
- This policy does not govern websites you visit or third-party services you choose to open
SIGN-IN USES ONLY THE IDENTITY DATA NEEDED FOR YOUR ACCOUNT.
You can create or access a Glyphic account with email and password or Google Sign-In. If you choose Google, Google and Glyphic's authentication provider supply basic account identity data such as your Google account identifier, email address, name, and profile image. Glyphic uses that information to authenticate you, create or match your account, prefill profile setup, protect account access, and communicate about the service. Glyphic does not request access to Gmail, Google Drive, contacts, calendars, or other Google content, and does not use Google user data for advertising.
- Requested Google scopes are limited to openid, email, and profile
- Google account data is not sold or used to train advertising profiles
- Disconnecting Google does not automatically remove content already stored in your Glyphic account
WHAT YOU PUBLISH IS VISIBLE BY DESIGN.
When you choose to participate publicly, Glyphic stores and displays your public profile, annotations, selected quotes, enough nearby page context to locate an annotation, comments, reactions, votes, follows, Space memberships, public Space images, and discussion placement. Public content can be seen, copied, quoted, or reshared by other people. Deleting a public contribution removes it from Glyphic's active public surfaces, but copies made by other people or retained for safety and legal purposes may remain.
- Private notes do not become public unless you make an explicit public action
- Moderated content may be hidden while its author retains a recoverable copy
- Reports, blocks, and moderation records are not public
ACCOUNT SYNC IS PRIVATE, BUT NOT END-TO-END ENCRYPTED.
If you connect this device to your account, Glyphic can synchronize notebooks, references, collections, library state, private annotations, private workspace images, notification preferences and read state, and account recovery metadata. Server access controls restrict this data to the signed-in account and authorized service operations. Synced private data is encrypted in transit and protected by the hosting provider's safeguards, but it is not end-to-end encrypted and may be accessible to authorized infrastructure operators when necessary to run, secure, or support the service.
- You choose whether to connect local workspace data to your account
- Signing out pauses account writes but leaves local data on that device
- Downloaded backups are files on your device and should be stored privately
MOST READING WORK HAPPENS LOCALLY IN YOUR BROWSER.
Glyphic reads the text of the current page locally so it can place, repair, and navigate highlights. It does not create or upload a general browsing-history log. Page text, a selected quote, and nearby context leave the device only when needed for content you choose to create, publish, or synchronize. Theme and panel preferences, feed-ranking activity, onboarding progress, local notebook version history, and celebration state remain on the device unless a feature states otherwise.
- Website access is used to render the panel and anchor highlights
- Local storage keeps the workspace available between sessions
- Clearing extension data or uninstalling Glyphic can remove device-only information
DATA SUPPORTS THE FEATURES YOU ASK GLYPHIC TO PROVIDE.
Glyphic uses information to authenticate accounts; synchronize authorized data; publish and display public contributions; place highlights; provide search, feeds, notifications, and Spaces; deliver password reset, welcome, security, and opted-in social emails; operate optional marketing email when you consent; prevent fraud and abuse; moderate public content; troubleshoot failures; and comply with legal obligations. Glyphic does not sell or rent personal information and does not serve behaviorally targeted advertising.
- Optional product and community marketing requires a separate opt-in
- You can change social and marketing email preferences in Settings
- Standard request metadata may be processed for security, reliability, and abuse prevention
SOME FEATURES REQUIRE SPECIALIZED PROCESSORS.
Glyphic shares information with service providers only as needed for the feature involved: Supabase provides authentication, database, storage, synchronization, and realtime infrastructure; Google provides optional sign-in; OpenAI evaluates public text and attached public GIF media for safety; KLIPY provides GIF search and media; Cloudflare hosts parts of the website and provides Turnstile checks for selected account flows; and Resend delivers account and opted-in notification email. These providers process information under their own terms and privacy commitments. Glyphic may also disclose information when required by law, to protect users or the service, or as part of a business reorganization with appropriate notice and safeguards.
- Private notebooks, references, and private comments are not sent to OpenAI or KLIPY
- Turnstile is limited to selected signup, password sign-in, and recovery flows
- Public moderation may continue through a narrow fallback queue during a provider outage
KEEP INFORMATION ONLY AS LONG AS THERE IS A REASON TO KEEP IT.
Account and synchronized workspace data is generally retained while your account remains active or until you delete it or request deletion. Public contributions remain until you delete them, moderation removes them, or the service removes them under its policies. Security, abuse, moderation, transaction, and delivery records may be retained longer when reasonably necessary to protect the service, investigate reports, prevent repeat abuse, resolve disputes, or meet legal obligations. Deleted information may remain for a limited time in backups, caches, and provider logs before it is overwritten or anonymized.
- Use in-product controls to delete individual content where available
- Email hello@glyphic.ca to request account-level access, correction, export, or deletion
- Device-only data must also be cleared on each device where it is stored
GLYPHIC USES LAYERS OF SAFEGUARDS, NOT IMPOSSIBLE PROMISES.
Glyphic uses transport encryption, account authorization, row-level access controls, restricted service credentials, input limits, moderation, anti-abuse controls, and operational testing to protect information. No service can guarantee absolute security. Glyphic and its providers may process information in Canada, the United States, or other countries where they operate; privacy laws and government access rules can differ from those in your home jurisdiction.
- Never include secrets or highly sensitive information in public content
- Protect exported backups and devices that contain local workspace data
- Report suspected security or privacy issues to hello@glyphic.ca
YOU CAN CONTROL SHARING, COMMUNICATIONS, AND ACCOUNT DATA.
Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to certain processing of personal information, withdraw consent, and complain to a privacy regulator. Glyphic may need to verify your identity before completing a request and may retain limited information where law or legitimate safety needs require it. Withdrawing consent does not affect processing already completed lawfully.
- Keep work private or make a deliberate public contribution
- Turn optional marketing and social email on or off
- Download a local backup and use Settings to clear supported local state
GLYPHIC IS NOT DIRECTED TO CHILDREN UNDER 13.
Glyphic is not designed for children under 13, and we do not knowingly collect personal information from a child under 13. A higher minimum age may apply where local law requires it. If you believe a child has provided personal information contrary to these limits, contact hello@glyphic.ca so the account and information can be reviewed.
THE POLICY CHANGES WHEN THE PRODUCT'S DATA PRACTICES CHANGE.
Glyphic may update this policy as features, providers, legal requirements, or operating practices change. Material changes will be identified by a new effective date and, when appropriate, by an in-product or account notice. The current version will remain available at glyphic.ca/privacy-policy.