Last updated: August 26, 2026
Glidebase ("we," "us," or "our") operates an AI-powered agency management platform. This privacy policy explains exactly what personal data we collect, how we use it, who we share it with, and your rights under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and other applicable privacy laws.
Data Controller: For agency account owners, Glidebase acts as the data controller for account data and as a data processor for client data managed through the platform. Agencies are the data controllers for their clients' personal data.
Our platform uses artificial intelligence to generate derived data from your content. This is automated processing that produces profiling-style output, but it is advisory only: it makes no decision about any person, and no legal or similarly significant effect follows from it, so GDPR Article 22 does not apply. A human always decides what to act on. The following data is generated:
These AI-generated insights are advisory only and do not result in decisions that produce legal or similarly significant effects. You can request all AI-derived data about you via the data export feature in your privacy settings.
We do not sell your personal data. We share data with the following third-party services strictly for the purposes described:
| Service | Purpose | Data Shared |
|---|---|---|
| Google Gemini AI | Email analysis, sentiment scoring, briefing generation, smart actions, draft suggestions | Truncated email content (up to 1000 chars per message), task summaries, client context. We do not send passwords, SMTP credentials, or financial account numbers. |
| Postmark | Inbound email processing via webhooks | Full email content as received (headers, body, sender/recipient addresses) |
| Mailgun | Alternative inbound email processing | Full email content as received (headers, body, sender/recipient addresses) |
| Lemon Squeezy | Merchant of record: checkout, payment processing, subscription management, invoicing, sales tax and VAT | Agency name, billing email and billing address. Payment card details are collected directly by Lemon Squeezy and never reach our systems. |
| DigitalOcean | Application hosting, database storage and encrypted off-site backups | All data you store in the Service, as it is the infrastructure the Service runs on |
| Sentry | Error monitoring and diagnostics | Technical error reports: the error message, stack trace and the URL where it occurred. Personally identifying context is disabled by default, so reports do not include your name, email or IP address. Not used for analytics or advertising. |
| Your agency's SMTP provider | Outbound email delivery (Gmail, Outlook, or custom SMTP) | Outbound email content, sender/recipient addresses. Uses your own SMTP credentials. |
International data transfers: Google Gemini API processes data in Google's infrastructure, which may include servers in the United States. Postmark, Lemon Squeezy, DigitalOcean and Sentry are US-based companies. The servers hosting the Service and its database are located in the United States (DigitalOcean, New York). These transfers are governed by their respective data processing agreements and Standard Contractual Clauses where applicable.
AI data usage: We use Google Gemini's API, which processes your data to generate responses but does not use your data to train Google's models per Google's API Terms of Service.
If you are in the European Economic Area (EEA) or UK, you have the following rights:
Exercise these rights from your Privacy Settings page, or contact us at support@glidebase.io.
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
We retain data for the following periods:
| Data Category | Retention Period |
|---|---|
| Account data (profile, preferences) | Until account deletion + 30-day grace period |
| Email messages | Until account deletion |
| Tasks, time logs, comments | Until account deletion |
| AI audit logs (prompts) | 90 days, then permanently deleted |
| AI abuse logs | 90 days, then permanently deleted |
| AI usage logs (token counts) | 12 months, then permanently deleted |
| Activity logs | 90 days |
| Data exports | 30 days after generation, then automatically deleted |
| Billing records | 7 years (legal requirement) |
| Encrypted backups | Up to 93 days, then permanently deleted |
| Password reset tokens | 60 minutes |
When you request account deletion, after a 30-day cancellation grace period, we permanently erase all your personal data. This includes force-deleting your account record, deleting all AI logs, anonymizing your comments and time log descriptions, and removing your avatar. Orphaned records (tasks you created, emails you sent) are anonymized to preserve data integrity for other agency members.
We implement the following security measures:
No method of electronic transmission or storage is 100% secure. If you discover a security vulnerability, please report it to support@glidebase.io.
We use essential cookies for authentication (session cookies, CSRF tokens) and functional cookies for preferences (theme). We do not use third-party advertising or tracking cookies. See our Cookie Policy for details.
If your agency grants you access to the Client Portal, you can view tasks assigned to your projects and add comments. Your portal activity (pages viewed, IP address) is logged for security purposes. The agency that invited you is the data controller for your portal data; Glidebase acts as their data processor.
Glidebase is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children.
We may update this privacy policy to reflect changes in our practices or legal requirements. We will notify you of material changes by email or through an in-app notification at least 30 days before the changes take effect. Your continued use after the effective date constitutes acceptance.
For privacy questions, data requests, or complaints:
Email: support@glidebase.io
If you are in the EU/EEA and are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.