Privacy Policy
Glitch Privacy Policy describing how user information is collected, used, and shared across the platform.
Glitch Privacy Policy
DRAFT — pending outside-counsel review. Do not publish as-is. See LAUNCH-P0-02 in docs/GAP-ANALYSIS.md.
Effective: 2026-XX-XX — draft pending counsel
This Privacy Policy describes how Jawahar Prasad (“Glitch,” “we,” “us,” or “our”) collects, uses, and shares information when you use the Glitch platform, including the CLI, TUI, web dashboard, pipeline engine, registry, firmware layer, and all related services (the “Service”).
By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, do not use the Service. This policy should be read alongside our Terms of Service and Acceptable Use Policy.
We may update this Privacy Policy from time to time. Material changes will be
posted at heyglitch.ai/privacy with at least 30 days’ advance notice.
See the Changelog at the bottom of this document.
1. What We Collect
1.1. Account Information
| Data point | When collected | Purpose |
|---|---|---|
| Email address | OAuth sign-up (Pro/Team/Enterprise) | Account identity, billing, support |
| Display name | OAuth profile (if provided) | Personalization |
| OAuth provider ID | GitHub or Google sign-in | Authentication |
| Organization name | Team/Enterprise account creation | Multi-user account management |
Hobby-tier users who do not sign in provide no account information to us.
1.2. Usage Telemetry
| Data point | Collected by default? | Purpose |
|---|---|---|
| Pipeline run count (anonymized) | Yes (opt-out) | Product analytics |
| Stage count per run (anonymized) | Yes (opt-out) | Product analytics |
| Accumulated cost per run (anonymized) | Yes (opt-out) | Product analytics |
| Error events and stack traces | Yes (opt-out) | Bug triage via Sentry |
| CLI command usage (anonymized) | Yes (opt-out) | Feature prioritization |
Telemetry is opt-out. You can disable all telemetry at any time:
# Environment variable (immediate, session-scoped)
export GLITCH_TELEMETRY=0
# Persistent CLI setting
glitch telemetry off
When telemetry is disabled, no data is sent to our servers or to Sentry. Hobby-tier users may also run the Software fully offline.
Telemetry data is anonymized before transmission. We do not associate telemetry events with your account identity unless you have explicitly opted in to a diagnostics program.
1.3. Billing Information
| Data point | Stored by | Purpose |
|---|---|---|
| Payment method (card number, expiration) | Stripe only | Payment processing |
| Billing address | Stripe only | Tax calculation, fraud prevention |
| Subscription tier and status | Glitch + Stripe | Entitlement enforcement |
| Invoice history | Glitch + Stripe | Billing records |
We do not store credit card numbers. All payment data is handled by Stripe in accordance with PCI DSS Level 1 compliance. We receive only a tokenized reference to your payment method from Stripe.
1.4. Support Correspondence
If you contact us for support, we collect:
- Email address and name (from your message)
- Content of your correspondence
- Any logs or screenshots you voluntarily attach to a support ticket
Support data is used solely to resolve your issue and improve the Service.
2. What We Do NOT Collect
This section is as important as what we do collect.
| Category | Detail |
|---|---|
| API keys | BYOK users’ API keys (OpenAI, Anthropic, Google, etc.) never leave your machine. Keys are read by the local CLI/agent process and sent directly to the model provider. They do not transit our servers. |
| Pipeline content | Prompt text, agent outputs, and pipeline artifacts for Hobby and Pro tiers are never sent to our servers. Pipeline execution happens locally or in your cloud runner; content is not relayed through api.heyglitch.ai for these tiers. |
| Source code | We do not collect, read, or index the source code you are editing. The firmware layer operates locally on your machine. |
| Keystroke or screen data | We do not log keystrokes, capture screenshots, or record terminal sessions. |
For Team and Enterprise tiers, pipeline run metadata (status, stage names, timing, cost) may be synced to the registry for the web dashboard and scheduling features. Pipeline content (prompts, outputs) is not synced unless you explicitly use a shared-registry feature that stores pipeline definitions.
3. How We Use Your Information
We use the information we collect to:
- Provide the Service — account management, billing, pipeline execution, firmware intelligence.
- Improve the Service — analyze anonymized usage patterns to prioritize features and fix bugs.
- Communicate with you — transactional emails (billing receipts, password resets), product announcements (opt-out available), and support responses.
- Enforce our Terms — detect and prevent fraud, abuse, and violations of our AUP.
- Comply with legal obligations — respond to lawful requests from government authorities.
We do not sell your personal information. See Section 6 (CCPA) for the formal notice.
We do not use your data to train AI models. See Terms of Service, Section 5.3 for the explicit commitment.
4. Third-Party Service Providers
We share limited information with the following third-party providers, solely to operate the Service:
| Provider | Purpose | Data shared | Their privacy policy |
|---|---|---|---|
| Stripe | Payment processing | Billing info, subscription status | stripe.com/privacy |
| Sentry | Error monitoring | Anonymized error events, stack traces | sentry.io/privacy |
| GitHub | OAuth authentication | OAuth token (scoped to email + profile) | docs.github.com/site-policy/privacy-policies |
| OAuth authentication | OAuth token (scoped to email + profile) | policies.google.com/privacy | |
| Instatus | Status page (status.heyglitch.ai) | No user data shared; public status only | instatus.com/policies/privacy |
We require all third-party providers to protect your data in accordance with this Privacy Policy and applicable law. We do not sell, rent, or trade your personal information to third parties.
5. GDPR — Rights for EU/EEA Users
If you are located in the European Union or European Economic Area, the General Data Protection Regulation (“GDPR”) grants you the following rights:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you. |
| Rectification | Request correction of inaccurate or incomplete personal data. |
| Erasure | Request deletion of your personal data (“right to be forgotten”). |
| Portability | Request your data in a structured, machine-readable format. |
| Objection | Object to processing of your data for specific purposes. |
| Restriction | Request that we limit processing of your data. |
| Withdraw consent | Where processing is based on consent, withdraw it at any time. |
To exercise any of these rights, contact us at privacy@heyglitch.ai. We will
respond within 30 days (extendable by 60 days for complex requests, with
notice).
Legal basis for processing: We process your data under the following bases:
- Contract performance — to provide the Service you subscribed to.
- Legitimate interest — to improve the Service, prevent fraud, and maintain security.
- Consent — for optional telemetry and marketing communications.
- Legal obligation — to comply with tax, accounting, and regulatory requirements.
EU data residency: At launch, data is processed and stored in the United States. EU-region hosting is planned post-launch (see LAUNCH-P2-05 in GAP-ANALYSIS.md). In the interim, data transfers from the EU to the US are governed by Standard Contractual Clauses (SCCs). See our DPA template for details.
Supervisory authority: You have the right to lodge a complaint with your local data protection authority.
6. CCPA — Rights for California Residents
If you are a California resident, the California Consumer Privacy Act (“CCPA”) grants you additional rights.
6.1. No Sale of Personal Information
We do not sell your personal information. We have not sold personal information in the preceding 12 months and have no plans to do so.
6.2. Your Rights
- Right to know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to delete: Request deletion of personal information we have collected from you.
- Right to opt out of sale: Not applicable — we do not sell personal information.
- Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights.
6.3. How to Exercise Your Rights
Submit a request to privacy@heyglitch.ai or by mail to our physical address
(see Section 10). We will verify your identity and respond within 45 days
(extendable by an additional 45 days with notice).
COUNSEL NOTE: We treat all Hobby users as consumers for CCPA purposes. This is the conservative choice — counsel should confirm whether Hobby-tier users using Glitch for commercial side projects qualify as “consumers” under CCPA’s household-use definition. We chose consumers to avoid under-counting.
7. Data Retention
| Data type | Retention period |
|---|---|
| Account information | Until you delete your account |
| Telemetry data | 90 days after collection |
| Server logs | 30 days |
| Backup snapshots | 90 days post-GA (nightly snapshots) |
| Billing records | As required by tax law (typically 7 years) |
| Support correspondence | 2 years after ticket closure |
When you request account deletion, we will:
- Delete your account data within 30 days.
- Remove your data from active systems.
- Remove your data from backups within the next backup rotation cycle (up to 90 days).
Some data may be retained longer if required by law (e.g., tax records) or to resolve ongoing disputes.
8. Security
We implement industry-standard security measures to protect your data:
- Encryption in transit: All data transmitted between your device and our servers uses TLS 1.2 or higher.
- Encryption at rest: Data stored on our servers is encrypted using AES-256 or equivalent.
- Access controls: Internal access to user data is restricted to personnel who need it to provide the Service, and is logged.
- Secret scrubbing: Our Sentry integration includes a
beforeSendfilter that removes API keys, tokens, and other secrets from error reports before transmission. - SOC 2 Type 1: Audit is in progress (LAUNCH-P2-01 in GAP-ANALYSIS.md). We will publish a trust report upon completion.
If you discover a security vulnerability, please report it to
security@heyglitch.ai. We do not currently have a formal bug bounty program but
will acknowledge and credit responsible disclosures.
9. Children’s Privacy
The Service is not directed to children under 13. We do not knowingly collect
personal information from children under 13. If we learn that we have collected
personal information from a child under 13, we will delete it promptly. If you
believe a child under 13 has provided us with personal information, contact us
at privacy@heyglitch.ai.
10. Contact
- Privacy inquiries:
privacy@heyglitch.ai - General support:
support@heyglitch.ai - Mailing address: [PLACEHOLDER — TBD pending entity formation]
Changelog
| Date | Description |
|---|---|
| 2026-04-23 | Initial draft. |