glassline.ai
PricingLoginGet Started

Privacy Policy

Glassline.ai β€” Last updated: September 2026


1. Who We Are

Glassline.ai ("Glassline", "we", "us") is a decision governance platform. For data protection enquiries, use our contact form and select Privacy as the reason.

2. Scope of This Policy

This Privacy Policy explains how Glassline collects, uses, stores, and protects personal data in connection with the Glassline platform, accessible at glassline.ai.

Glassline acts as a data controller when you register an account directly (profile, password, subscription). Glassline acts as a data processor when an organization subscribes and invites its members β€” in that case, the subscribing organization is the data controller.

3. Personal Data We Collect
3.1 Account and Profile Data

First and last name, email address, hashed password, timezone preference, organization name, and team membership.

3.2 Decision and Collaboration Data

Decision titles, descriptions, context notes, your scoring inputs across five factors (Impact, Strategic Alignment, Risk Reduction, Effort, Confidence), optional rationale text, endorsements, uploaded attachments, and action timestamps.

3.3 Technical Data

IP address and session tokens (used for authentication and security only). API request logs retained for 30 days. We do not use third-party analytics, advertising cookies, or behavioral tracking. We do not sell personal data.

4. How We Use Your Personal Data

We use your data to provide and operate the Service (contract performance), to authenticate sessions (contract performance), to send transactional emails such as invitations and scoring notifications (contract performance), and for platform security and fraud prevention (legitimate interests). We do not use your data for automated decision-making or profiling.

5. Immutable Decision Records β€” Important Notice

Glassline's core function is to create permanent, tamper-proof organizational memory of governance decisions. When an organization locks a decision, Glassline generates an immutable Snapshot that captures the complete record: who participated, scores, rationales, and outcomes.

Right to erasure and Snapshots: If you exercise your right to erasure, Glassline will anonymize your personal identity (name and email) across all Snapshots you appear in, replacing your name with "[Deleted User]". The structural decision record is retained for the organization's legitimate governance purposes.

Public shareable links: A decision's owner or an organization administrator may generate a public, unauthenticated link to a Locked decision's Snapshot. Anyone with that link β€” including people outside your organization β€” can view the Snapshot, including participant display names, scores, and rationale text, without a Glassline account. Your individual endorsement detail is excluded from a public link; it remains visible only to the decision owner and organization administrators inside the application. A public link stays active until the decision owner or an administrator revokes it.

6. Data Sharing and Sub-Processors

We do not sell, rent, or trade personal data. We share personal data only with the following sub-processors, under contractual data protection obligations:

  • Brevo (Sendinblue) β€” transactional email delivery (invitations, notifications) β€” France / EU
  • Contabo GmbH β€” application, database, and file storage hosting β€” Frankfurt, Germany / EU
  • Cloudflare, Inc. β€” DNS resolution and inbound email forwarding for our domain only; application traffic is not proxied through Cloudflare β€” global network, EU-directed

We do not use sub-processors outside the European Economic Area (EEA) without appropriate safeguards in place (Standard Contractual Clauses or equivalent), and we will update this list when sub-processors change.

7. Your Rights

Under GDPR you have the right to: access your personal data (export via My Profile β†’ "Download my data"); rectification (update via My Profile); erasure/right to be forgotten (request via My Profile β†’ "Request account deletion"); restriction of processing; data portability; and to object to processing.

To exercise your rights, visit your profile settings or use our contact form (select Privacy as the reason). If you believe your rights have been violated, you may lodge a complaint with a supervisory authority β€” in Greece, the Hellenic Data Protection Authority (www.dpa.gr).

8. Data Retention

Active user data is retained while your account exists. On account deletion, your personal identifiers are anonymized immediately. Organizational data is retained for 90 days after an organization is deactivated, then permanently deleted. Authentication and API request logs are retained for 30 days.

9. Cookies

Glassline uses only essential session cookies required for authentication and secure operation. No advertising, analytics, or tracking cookies are set. The cookie consent banner you see on first visit is for transparency β€” essential cookies cannot be disabled while using the Service.

10. Security

Glassline uses HTTPS for all data transmission. Passwords are stored as bcrypt hashes and are never stored in plain text. Session tokens are rotated on use and invalidated on logout and account anonymization. We conduct regular security reviews.

11. Children

Glassline is a professional B2B tool intended for use by adults in an organizational context. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has provided us with personal data, contact us via the contact form and we will delete it.

12. Changes to This Policy

We will notify registered users of any material changes to this Privacy Policy by email and by displaying a notice in the application at least 14 days before the change takes effect. The "last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after a change takes effect means you accept the updated policy.

13. Contact

For privacy enquiries or data subject requests, use our contact form and select Privacy as the reason. For enterprise customers seeking a Data Processing Agreement (DPA), use the same contact form β€” a DPA is required before organizational data is processed on any paid subscription.

For privacy-related requests or concerns, contact us at privacy@glassline.ai