Privacy policy

This policy explains what personal data [Company legal name] ("Glassrecord", "we", "us") collects, why, who receives it, how long we keep it, and the choices and rights you have. It covers:

Glassrecord is a service of [Company legal name], [Address]. Contact us about privacy at [Privacy contact address].

Our role

We are the controller for personal data we collect for our own purposes: account and billing details, our websites, the free scan, product analytics, security, support, and the crawler's opt-out list.

We are a processor for personal data in Customer Data: what our customers and their members put into the app, and what Glassrecord records about the customer's sites and their visitors on the customer's behalf. Our Data Processing Agreement (glassrecord.com/dpa) governs that processing. If your data is in a customer's account, for example because an agency lists you as a client contact, that customer decides how it is used. Send requests about it to that customer. We will help them answer.

Observations of public websites. The crawler records what a public web page loads and sends. We keep those observations as facts about the website and use them for every customer who monitors that site and for free scans of it. They describe what a browser we control saw. They are not about any visitor to the site.

Personal data we collect

When you use the app

When you use the free scan

The report is available to anyone with its private link for 30 days and then deleted. Search engines are asked not to index it.

When you visit our websites

Our public pages, the free scan, and the pages a shared link opens do not load analytics, advertising, or session replay. They set only the cookies the site needs to work (see Cookies below). Our hosting provider, Cloudflare, processes your IP address and request details to deliver the pages and protect them from attacks.

Product analytics in the app

Error monitoring

When our software fails, Sentry receives the error, the route, and request details. Tokens are removed before the report is sent.

The crawler and the websites it scans

The crawler loads public pages of sites our customers monitor, sites someone asks us to scan for free, and a small set of sites we use to test our detection. It records the page's network requests, the cookies and storage set in its own browser, screenshots, and page text. It uses a fresh browser with no personal profile. It does not store cookie values or form contents, and it strips query strings from the addresses it stores, apart from a short list of parameters that show what a request sent to a third party.

A web page can show personal data, for example a staff member's name on a contact page. When it does, that data can appear in a screenshot or page excerpt the crawler keeps. We use it only to show the customer what the page showed, and it is deleted on the retention schedule below.

The crawler page (glassrecord.com/crawler) explains how to identify the crawler and how to opt out. If you ask us to stop scanning your domain, we keep the domain and your request on our opt-out list.

Protection, on our customers' websites

Protection is a script our customers install on their websites. It reports, for each page view, which third parties loaded and whether they loaded before a consent choice, after a refusal, or after acceptance. Glassrecord processes these reports as our customer's processor.

Protection's reports never contain cookie values, IP addresses, visitor or session identifiers, form contents, page addresses, or full URLs with parameters. Each report names third parties by host only, and names the page by its position in the customer's list of scanned pages, or not at all. The script sets no cookie, uses no browser storage, and keeps nothing between page views. Our endpoint reads the report and the request's Origin and Content-Type headers, and does not read or keep the visitor's IP address. We store only daily counts per site. Our network provider, Cloudflare, necessarily receives the visitor's IP address to deliver the request.

If the customer turns on a script policy, the visitor's browser may send violation reports. We keep only the blocked host, the policy directive, and whether it was blocked or reported, as daily counts.

For people in the European Economic Area, the United Kingdom, and Switzerland, we rely on these legal bases:

Purpose Data Legal basis
Provide the app: sign-in, organizations, sites, scans, findings, fixes, reports, shared links, integrations Account, organization, and usage data; Customer Data Contract with you or your organization; for Customer Data, our customer's instructions
Bill for the service Billing data Contract; legal obligation for tax and accounting records
Send account and service email Name, email address, message content Contract
Run the free scan and enforce its limits Domain, optional email address, daily hash of the IP address, Turnstile result Legitimate interest in offering a free check and preventing abuse; for the email address, your request
Crawl public websites and keep observations of them Page content, screenshots, and network records, which can include personal data a page shows Legitimate interest in showing site owners and their customers what a website does with visitors' data
Keep the opt-out list Domain and the requester's contact details Legitimate interest; legal obligation where an objection applies
Product analytics and session replay in the browser Page views, flags, masked replay Consent
Product events from our servers User ID, organization ID, event names and counts Legitimate interest in understanding and improving the product
Security, fraud prevention, and error monitoring Session details, audit log, error reports Legitimate interest in keeping the service and accounts secure
Support Your messages, support notes Contract; legitimate interest
Improve detection De-identified features from scans and staff review of findings Legitimate interest; for Customer Data, as the Data Processing Agreement allows
Comply with the law and enforce our terms Any of the above as needed Legal obligation; legitimate interest

We do not use personal data for automated decisions that have legal or similarly significant effects on you.

Language models. Some app features send excerpts of scanned pages to Anthropic's API to classify a page or name a third party's purpose. We never send cookie values, form values, or query strings, and free scans never use these features. [Confirm with Anthropic's commercial terms that API inputs are not used for training, and state it here.]

Aggregate statistics. We keep de-identified, aggregate statistics from scans, such as how often a kind of tracker loads before consent across many sites. They do not identify any person.

Who receives personal data

We do not sell personal data, and we do not share it for cross-context behavioral advertising.

International transfers

We are based in [Country]. Our main database and stored files are in the United States. PostHog stores analytics in the European Union. The crawler loads pages from the United States and from Germany. When we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss equivalents, or on the recipient's certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. [Confirm which mechanism applies to each transfer, and whether Glassrecord will self-certify under the Data Privacy Framework.]

How long we keep personal data

Data How long
Account details While the account exists. Deleting your account removes your memberships, sessions, trusted browsers, and recovery codes, deletes your WorkOS user and your PostHog profile, and releases your email address. Your name stays on audit log entries you made.
Sessions 30 days, or until you sign out or end them
Trusted browsers 30 days
An organization's records While the organization exists. After a plan is cancelled, records stay readable for one year and are then deleted. A deleted organization disappears at once and is purged 30 days later.
A removed site Deleted one year after its removal, or at once if an Owner or Admin deletes it
Page captures and page markup 90 days after anything last cited the page load, unless an open finding, a proof record, or a legal hold still cites it
Screenshots and evidence cited by findings The organization's retention period, one year by default, counted from the last time a report, finding, or proof cited it
Proof records and the evidence they cite While the proof record's site and organization exist
Protection counts Daily counts while the organization exists; hourly counts 90 days
Free scan email address 30 days, or until you delete it with the link in either message
Free scan IP address hash One day
Free scan report, findings, and screenshots 30 days
Observations of public websites Kept as facts about the site, without a set end date [counsel: confirm this position]
Billing and tax records As long as tax and accounting law requires [Confirm period]
Opt-out list While the opt-out applies
Error reports in Sentry [Sentry retention for our plan]
Analytics in PostHog [PostHog retention for our plan]

A legal hold can stop deletion while it applies.

Security

We protect personal data with measures that include: encryption in transit; access tokens and integration credentials encrypted at rest under keys only our servers hold; share links, invitation links, and session tokens stored only as hashes; two-step verification for members of organizations that require it and for all staff; time-limited, audited staff access to customer data; separate environments for testing and production; and a crawler that cannot reach private network addresses. No method of transmission or storage is completely secure. [Add certifications only once obtained.]

If a breach affects your personal data, we will notify you and the authorities as the law requires.

Your rights

Depending on where you live, you may have the right to:

In the app, you can change your name and email address, export your own data under Account, and delete your account. An organization's Owners and Admins can export all of its records. For anything else, write to [Privacy contact address]. We will verify your identity before acting, and we answer within one month, or within the period the law where you live sets, such as 45 days under California law. An authorized agent may make a request for you with your signed permission.

If your data is in a customer's account, we will pass your request to that customer.

Complaints. You may complain to your data protection authority. In the United Kingdom, that is the Information Commissioner's Office. We would like the chance to address your concern first.

EU and UK representatives. [Name and address of the Article 27 representatives, if appointed.]

Cookies and similar technologies

Our websites and app set these cookies. All are needed for the service to work and none are used for advertising.

Cookie Purpose Lifetime
session Keeps you signed in 30 days
sign_in Carries a sign-in in progress 15 minutes
trusted Remembers a browser you chose to trust for two-step verification 30 days
google_state Protects the Google sign-in step against forgery 15 minutes
preferences Remembers display preferences, such as the theme 400 days
held_join, held_transfer Holds an invitation or transfer link you opened while you sign in 15 minutes

PostHog, when you allow product analytics, keeps its identifiers in your browser's local storage, not in cookies. They are removed when you decline or leave the signed-in app. Cloudflare Turnstile, on the free scan pages only, may use browser storage for its check. [Confirm the complete cookie list with our own scanner before publishing, as the plan requires.]

Children

Glassrecord is a service for businesses. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.

Changes to this policy

We will post any change on this page with a new effective date. If a change materially affects how we use personal data, we will tell account holders by email or in the app at least 30 days before it takes effect.

This version takes effect on [Date].

Contact

[Company legal name] [Address] [Privacy contact address]