Privacy policy
This policy explains what personal data [Company legal name] ("Glassrecord", "we", "us") collects, why, who receives it, how long we keep it, and the choices and rights you have. It covers:
- our websites, including
glassrecord.comand the free scan; - the Glassrecord web app at
app.glassrecord.com; - the Glassrecord crawler, which loads public web pages;
- Protection, the script our customers install on their own websites;
- email we send and our support.
Glassrecord is a service of [Company legal name], [Address]. Contact us about privacy at [Privacy contact address].
Our role
We are the controller for personal data we collect for our own purposes: account and billing details, our websites, the free scan, product analytics, security, support, and the crawler's opt-out list.
We are a processor for personal data in Customer Data: what our customers and their members put into the app, and what Glassrecord records about the customer's sites and their visitors on the customer's behalf. Our Data Processing Agreement (glassrecord.com/dpa) governs that processing. If your data is in a customer's account, for example because an agency lists you as a client contact, that customer decides how it is used. Send requests about it to that customer. We will help them answer.
Observations of public websites. The crawler records what a public web page loads and sends. We keep those observations as facts about the website and use them for every customer who monitors that site and for free scans of it. They describe what a browser we control saw. They are not about any visitor to the site.
Personal data we collect
When you use the app
- Account details. Your name and email address. Your password and two-step verification factors are held by WorkOS, our sign-in provider, not by us. We keep your recovery codes only as keyed hashes.
- Organization details. The organizations you belong to, your role, the sites and clients you can reach, and the invitations you send and receive, including the invitee's email address.
- What you enter. Sites, pages, notes, comments, fix assignments, answers to disputes, branding, and contacts. An agency may enter a client contact's name and email address so Glassrecord can send them fix notices.
- Scan sign-in. If you give Glassrecord a test account so it can scan pages behind your site's sign-in, our app encrypts the password to a key that only the crawler holds, and it is opened only inside the crawler for the sign-in. We delete it when you remove the test account, its site, or your organization.
- Integrations. If you connect Google Tag Manager or Vanta, we keep the connection and, for Vanta, its access tokens, encrypted. If you install Protection through Cloudflare, we use your Cloudflare API token once and do not keep it.
- Sessions and security. For each signed-in session we keep a hash of its token, when it was last used, a short device description such as "Chrome on macOS" taken from the browser's user agent, and an approximate city and country from our network provider's request data. We do not store your IP address in our database. WorkOS receives your IP address and user agent when you sign in, to protect your account.
- Audit log. A record of actions taken in your organization, who took them, and when. Staff access to your organization is recorded there too.
- Billing. Your plan, subscription status, and invoices. Stripe collects and holds your payment card. We never see or store the full card number.
- Support. What you tell us when you write to support, and notes our staff keep about your organization.
When you use the free scan
- The domain you ask us to scan.
- Your email address, if you give one. It is optional. We send it two messages only: the report's link, and a notice on day 23 before the report expires. Each message carries a link to delete the address at once. Otherwise we delete it 30 days after the scan. We never use it for marketing.
- Your IP address, never stored. We use it to enforce limits on how many scans one person can ask for. We keep only a keyed hash of it combined with the date, so hashes from different days cannot be linked, and we delete even that hash after one day. Cloudflare Turnstile checks that you are a person; Cloudflare receives your IP address and browser signals for that check under Cloudflare's Turnstile privacy addendum.
- A report of a wrong finding. If you report a finding as wrong, we keep your note for our staff to review.
The report is available to anyone with its private link for 30 days and then deleted. Search engines are asked not to index it.
When you visit our websites
Our public pages, the free scan, and the pages a shared link opens do not load analytics, advertising, or session replay. They set only the cookies the site needs to work (see Cookies below). Our hosting provider, Cloudflare, processes your IP address and request details to deliver the pages and protect them from attacks.
Product analytics in the app
- With your consent, the signed-in app loads PostHog to record page views, feature flags, and, if you also allow it, a session replay. Page views record the route's template, such as
/sites/$siteId, never the full address. Session replay masks all text and every input and blocks images. We ask once, after you finish your first task, with "Allow" and "No thanks" given equal weight. You can change your choice at any time under Account, Privacy. - Global Privacy Control. If your browser sends Global Privacy Control and you have not made a choice, we record a refusal and do not ask.
- Server events. Our servers send PostHog a record of certain product actions, such as a fix marked fixed or a report shared, identified by your WorkOS user ID and your organization's ID. These events contain no name, email address, domain, URL, or scan content, and nothing is read from or written to your device. If you decline product analytics, these events are sent without linking them to you as a person.
- PostHog stores this data in its EU cloud.
Error monitoring
When our software fails, Sentry receives the error, the route, and request details. Tokens are removed before the report is sent.
The crawler and the websites it scans
The crawler loads public pages of sites our customers monitor, sites someone asks us to scan for free, and a small set of sites we use to test our detection. It records the page's network requests, the cookies and storage set in its own browser, screenshots, and page text. It uses a fresh browser with no personal profile. It does not store cookie values or form contents, and it strips query strings from the addresses it stores, apart from a short list of parameters that show what a request sent to a third party.
A web page can show personal data, for example a staff member's name on a contact page. When it does, that data can appear in a screenshot or page excerpt the crawler keeps. We use it only to show the customer what the page showed, and it is deleted on the retention schedule below.
The crawler page (glassrecord.com/crawler) explains how to identify the crawler and how to opt out. If you ask us to stop scanning your domain, we keep the domain and your request on our opt-out list.
Protection, on our customers' websites
Protection is a script our customers install on their websites. It reports, for each page view, which third parties loaded and whether they loaded before a consent choice, after a refusal, or after acceptance. Glassrecord processes these reports as our customer's processor.
Protection's reports never contain cookie values, IP addresses, visitor or session identifiers, form contents, page addresses, or full URLs with parameters. Each report names third parties by host only, and names the page by its position in the customer's list of scanned pages, or not at all. The script sets no cookie, uses no browser storage, and keeps nothing between page views. Our endpoint reads the report and the request's Origin and Content-Type headers, and does not read or keep the visitor's IP address. We store only daily counts per site. Our network provider, Cloudflare, necessarily receives the visitor's IP address to deliver the request.
If the customer turns on a script policy, the visitor's browser may send violation reports. We keep only the blocked host, the policy directive, and whether it was blocked or reported, as daily counts.
How we use personal data and our legal bases
For people in the European Economic Area, the United Kingdom, and Switzerland, we rely on these legal bases:
| Purpose | Data | Legal basis |
|---|---|---|
| Provide the app: sign-in, organizations, sites, scans, findings, fixes, reports, shared links, integrations | Account, organization, and usage data; Customer Data | Contract with you or your organization; for Customer Data, our customer's instructions |
| Bill for the service | Billing data | Contract; legal obligation for tax and accounting records |
| Send account and service email | Name, email address, message content | Contract |
| Run the free scan and enforce its limits | Domain, optional email address, daily hash of the IP address, Turnstile result | Legitimate interest in offering a free check and preventing abuse; for the email address, your request |
| Crawl public websites and keep observations of them | Page content, screenshots, and network records, which can include personal data a page shows | Legitimate interest in showing site owners and their customers what a website does with visitors' data |
| Keep the opt-out list | Domain and the requester's contact details | Legitimate interest; legal obligation where an objection applies |
| Product analytics and session replay in the browser | Page views, flags, masked replay | Consent |
| Product events from our servers | User ID, organization ID, event names and counts | Legitimate interest in understanding and improving the product |
| Security, fraud prevention, and error monitoring | Session details, audit log, error reports | Legitimate interest in keeping the service and accounts secure |
| Support | Your messages, support notes | Contract; legitimate interest |
| Improve detection | De-identified features from scans and staff review of findings | Legitimate interest; for Customer Data, as the Data Processing Agreement allows |
| Comply with the law and enforce our terms | Any of the above as needed | Legal obligation; legitimate interest |
We do not use personal data for automated decisions that have legal or similarly significant effects on you.
Language models. Some app features send excerpts of scanned pages to Anthropic's API to classify a page or name a third party's purpose. We never send cookie values, form values, or query strings, and free scans never use these features. [Confirm with Anthropic's commercial terms that API inputs are not used for training, and state it here.]
Aggregate statistics. We keep de-identified, aggregate statistics from scans, such as how often a kind of tracker loads before consent across many sites. They do not identify any person.
Who receives personal data
- Sub-processors that host and run the service for us. The list, with each one's purpose and location, is at
glassrecord.com/subprocessors. - Your organization. Other members of your organization can see your name and role. Viewers see names, not email addresses.
- People you share with. A shared report, proof record, or fix link can be opened by anyone who has it until it expires or you revoke it.
- Services you connect, such as Vanta or Google Tag Manager, receive what the integration sends at your request.
- Glassrecord staff see a limited set of account facts to run the service. They see an organization's sites, findings, and evidence only under a time-limited access grant, which the organization's audit log records, or when the organization opens support access. Staff also review how scanned pages are classified, which shows pages from every customer's scans.
- Legal and safety. Authorities or others when the law requires it, or to protect rights, safety, or the service.
- A successor. A buyer or successor in a merger, acquisition, or sale of assets, under this policy's protections.
We do not sell personal data, and we do not share it for cross-context behavioral advertising.
International transfers
We are based in [Country]. Our main database and stored files are in the United States. PostHog stores analytics in the European Union. The crawler loads pages from the United States and from Germany. When we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss equivalents, or on the recipient's certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. [Confirm which mechanism applies to each transfer, and whether Glassrecord will self-certify under the Data Privacy Framework.]
How long we keep personal data
| Data | How long |
|---|---|
| Account details | While the account exists. Deleting your account removes your memberships, sessions, trusted browsers, and recovery codes, deletes your WorkOS user and your PostHog profile, and releases your email address. Your name stays on audit log entries you made. |
| Sessions | 30 days, or until you sign out or end them |
| Trusted browsers | 30 days |
| An organization's records | While the organization exists. After a plan is cancelled, records stay readable for one year and are then deleted. A deleted organization disappears at once and is purged 30 days later. |
| A removed site | Deleted one year after its removal, or at once if an Owner or Admin deletes it |
| Page captures and page markup | 90 days after anything last cited the page load, unless an open finding, a proof record, or a legal hold still cites it |
| Screenshots and evidence cited by findings | The organization's retention period, one year by default, counted from the last time a report, finding, or proof cited it |
| Proof records and the evidence they cite | While the proof record's site and organization exist |
| Protection counts | Daily counts while the organization exists; hourly counts 90 days |
| Free scan email address | 30 days, or until you delete it with the link in either message |
| Free scan IP address hash | One day |
| Free scan report, findings, and screenshots | 30 days |
| Observations of public websites | Kept as facts about the site, without a set end date [counsel: confirm this position] |
| Billing and tax records | As long as tax and accounting law requires [Confirm period] |
| Opt-out list | While the opt-out applies |
| Error reports in Sentry | [Sentry retention for our plan] |
| Analytics in PostHog | [PostHog retention for our plan] |
A legal hold can stop deletion while it applies.
Security
We protect personal data with measures that include: encryption in transit; access tokens and integration credentials encrypted at rest under keys only our servers hold; share links, invitation links, and session tokens stored only as hashes; two-step verification for members of organizations that require it and for all staff; time-limited, audited staff access to customer data; separate environments for testing and production; and a crawler that cannot reach private network addresses. No method of transmission or storage is completely secure. [Add certifications only once obtained.]
If a breach affects your personal data, we will notify you and the authorities as the law requires.
Your rights
Depending on where you live, you may have the right to:
- know what personal data we hold about you and get a copy;
- correct it;
- delete it;
- receive it in a portable format;
- object to or restrict our use of it, including use based on legitimate interest;
- withdraw consent at any time, without affecting earlier processing;
- opt out of the sale or sharing of personal data, or of targeted advertising (we do neither);
- appeal our answer to your request;
- not be treated differently for using these rights.
In the app, you can change your name and email address, export your own data under Account, and delete your account. An organization's Owners and Admins can export all of its records. For anything else, write to [Privacy contact address]. We will verify your identity before acting, and we answer within one month, or within the period the law where you live sets, such as 45 days under California law. An authorized agent may make a request for you with your signed permission.
If your data is in a customer's account, we will pass your request to that customer.
Complaints. You may complain to your data protection authority. In the United Kingdom, that is the Information Commissioner's Office. We would like the chance to address your concern first.
EU and UK representatives. [Name and address of the Article 27 representatives, if appointed.]
Cookies and similar technologies
Our websites and app set these cookies. All are needed for the service to work and none are used for advertising.
| Cookie | Purpose | Lifetime |
|---|---|---|
session |
Keeps you signed in | 30 days |
sign_in |
Carries a sign-in in progress | 15 minutes |
trusted |
Remembers a browser you chose to trust for two-step verification | 30 days |
google_state |
Protects the Google sign-in step against forgery | 15 minutes |
preferences |
Remembers display preferences, such as the theme | 400 days |
held_join, held_transfer |
Holds an invitation or transfer link you opened while you sign in | 15 minutes |
PostHog, when you allow product analytics, keeps its identifiers in your browser's local storage, not in cookies. They are removed when you decline or leave the signed-in app. Cloudflare Turnstile, on the free scan pages only, may use browser storage for its check. [Confirm the complete cookie list with our own scanner before publishing, as the plan requires.]
Children
Glassrecord is a service for businesses. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.
Changes to this policy
We will post any change on this page with a new effective date. If a change materially affects how we use personal data, we will tell account holders by email or in the app at least 30 days before it takes effect.
This version takes effect on [Date].
Contact
[Company legal name] [Address] [Privacy contact address]