Back to Glidely
Legal

Privacy Policy

Last updated

This Privacy Policy explains how Glidely collects, uses, protects, and discloses personal information and workspace data and how you can control it.

In short

  • Applies to: All accounts, workspaces, boards, chat, files, and billing data
  • Payments: Processed by Lemon Squeezy (Merchant of Record)
  • Contact: support@glidely.site

Information we collect

We collect account details (name, email address, password hash, profile avatar, preferences), workspace metadata (workspace names, board titles, list structures, card tasks, comments, checklists, chat transcripts, file references), and technical metrics (IP address, browser type, device identifiers, and session timestamps).

Payment and financial information

Payments and subscriptions are processed by Lemon Squeezy, our payment partner and Merchant of Record. Glidely never receives or stores your card number, expiry date or security code. Lemon Squeezy shares with us only what we need to manage your plan, such as your email, plan and subscription status.

How information is used

Information is used strictly to provide, maintain, and optimize Glidely services: authenticating users, synchronizing live card movements across devices, providing workspace team chat, applying plan limits, managing subscriptions through Lemon Squeezy, preventing fraud, and delivering customer support.

Service providers and data processors

We use trusted providers to run Glidely: Google Firebase (hosting, sign-in and database), Cloudflare (file storage and server functions), Google Analytics (usage statistics) and Lemon Squeezy (payments). They process data only to provide their services to us.

Data retention and deletion

Account and workspace information is retained as long as your account remains active. Deleted cards, lists and boards stay in the Recycle Bin until someone restores them or deletes them permanently. You may request complete account deletion at any time by contacting support@glidely.site.

Your privacy rights (GDPR & CCPA)

Depending on your jurisdiction, you possess rights to access the personal information we hold about you, receive a copy of your data in a structured format (JSON/CSV), request rectification of inaccuracies, object to processing, or request complete erasure of your data.

Cookies and security protocols

Glidely uses browser storage to keep you signed in, remember your preferences and keep your account secure. We use Google Analytics to understand how the site is used; it sets its own cookies. We do not sell user data.

Data protection mechanisms for sensitive data

Glidely implements rigorous administrative, technical, and physical security measures to safeguard all sensitive user data, with particular emphasis on information accessed via Google APIs:

  1. Cryptographic Protection in Transit: All data exchanged between user clients, Glidely infrastructure, and Google APIs is strictly encrypted using Transport Layer Security (TLS 1.3 / TLS 1.2) over HTTPS. Plaintext transmissions or unencrypted HTTP traffic are unconditionally blocked.
  2. Cryptographic Protection at Rest: All workspace records, user metadata, and file references stored within Glidely databases and storage systems are encrypted at rest using industry-standard Advanced Encryption Standard (AES-256).
  3. OAuth Credential and Token Isolation: Google OAuth 2.0 access tokens and temporary credentials are treated as highly confidential. Tokens are transmitted solely over TLS-encrypted channels, stored only in your own browser, automatically expire within 60 minutes, and are never logged, exposed to third parties, or recorded in plain text.
  4. Strict Access Controls & Tenant Isolation: Google user data is logically separated per user and workspace. Multi-tenant access controls ensure that data from one user’s Google account is never exposed to or accessible by other workspace members unless explicitly shared by the user.
  5. Human Access Restrictions: Human review or access to Google user data by Glidely staff is strictly forbidden. Personnel may only access Google user data under limited circumstances: (a) with the user’s explicit, affirmative written consent to resolve a specific technical support issue; (b) where required for internal security audits or investigating abuse; or (c) where strictly mandated by applicable legal obligations or court orders.
  6. Retention and Automatic Deletion: Sensitive data obtained from Google APIs is retained only for the duration necessary to deliver the requested feature. Users can revoke Glidely’s access to their Google account at any time either within Glidely Workspace Settings or directly via Google Security Settings (https://myaccount.google.com/permissions). Upon disconnection or upon account deletion request (support@glidely.site), all cached Google authentication tokens and associated synchronized metadata are permanently purged from Glidely systems within 24 hours.
  7. Prohibition on Advertising & AI Model Training: Data obtained through Google APIs is never sold, leased, or transferred to third parties or data brokers. It is never used for serving personalized, retargeted, or interest-based advertising. Furthermore, Glidely never uses Google user data to train, retrain, or improve generalized artificial intelligence (AI) or machine learning (ML) models.
  8. Adherence to Google Limited Use Policy: Glidely’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google API Limited Use disclosure

Glidely's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

Specifically, when you connect Google services or access Glidely using Google authentication, our use of Google user data is strictly governed by the following permissions and protections:

  1. Minimum Scope Access (Least Privilege):
    • Google Calendar (https://www.googleapis.com/auth/calendar.events): Glidely accesses your calendar solely to sync task due dates and schedule Google Meet video conference events for cards you designate. Glidely does not read other personal calendar events.
    • Gmail (https://www.googleapis.com/auth/gmail.send): Glidely uses this permission exclusively to transmit user-composed emails directly from task cards. Glidely never reads, stores, or monitors your incoming emails or inbox messages.
    • Google Drive (https://www.googleapis.com/auth/drive.file): Glidely requests only per-file access to create new Google Docs/Sheets on your behalf or to link files you specifically select via the Google Picker API. Glidely does not have broad read/write access to your general Google Drive.
  2. No Sale or Advertising: Glidely never sells your Google user data to any third party. Furthermore, we never use or transfer information received from Google APIs to serve personalized, retargeted, or interest-based advertising.
  3. Prohibited AI Training: Glidely does not use Google user data to train, retrain, or fine-tune generalized artificial intelligence (AI) or machine learning (ML) models.
  4. Restricted Transfer: We do not transfer Google user data to third parties except as strictly necessary to provide or improve the core features of Glidely, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with explicit user notification.
  5. Human Access Restrictions: Human access to Google user data is strictly prohibited, except where: (a) you provide explicit affirmative consent for troubleshooting or support; (b) it is required for internal security audits or investigating system abuse; or (c) it is necessary to comply with applicable legal obligations.

For more details, please review the official Google API Services User Data Policy.

Contact and inquiries

For any questions regarding this Privacy Policy, your personal data, data protection mechanisms for sensitive data, or to exercise your privacy rights, email support@glidely.site.

We collect only what we need to run Glidely, and we never sell your data.

If you have any questions about this page, email us at support@glidely.site.

NextTerms of Service