This Privacy Policy describes how Glimpse AI(“Glimpse,” “we,” “us,” or “our”) handles information in connection with the Glimpse macOS application (the “App”), our website, and related services (together, the “Services”). By using the Services you agree to this policy. If you do not agree, do not use the Services.
1. Information we collect
Information you provide
- Account information. When you create an account we collect your email address and authentication details. Your account and authentication are handled by our infrastructure provider (Supabase).
- Billing information. If you purchase a paid plan, payments are processed by our third-party payment processor (Stripe). We do not receive or store your full card number. We retain limited records such as plan, subscription status, billing period, and invoice history.
- Communications. If you contact support, we keep the messages and any information you choose to include.
Information processed on your device
- Screen content (OCR). When you summon Glimpse, the App captures the active window and converts pixels to text on your Mac using Apple frameworks (ScreenCaptureKit and Vision). This processing happens locally.
- Documents. Text you extract from files (such as PDF or DOCX) is processed locally to build context.
- Conversations. Your conversation history is stored locally on your Mac (SQLite). API keys you supply are stored in the macOS Keychain.
Information sent to AI providers
Glimpse does not send your screen content or questions anywhere until you submit a query. When you do, the relevant context and your prompt are sent to the AI model you select in order to generate a response. If you use your own provider key, your Mac sends that content directly to the provider. If you use a hosted Pro model, the content passes through a Glimpse server endpoint to the model provider and the answer is streamed back. The endpoint does not log, retain, or store the content. Model providers process requests under their own terms and privacy policies.
Optional cloud sync
If iCloud/CloudKit sync is available and enabled, your conversations and saved “memories” are synced to your private Apple CloudKit database, controlled by your Apple account. Glimpse’s servers and employees cannot access that private database.
Information collected automatically
The App does not send usage telemetry by default. Our website may collect standard technical data (such as IP address, browser type, and pages viewed) through server logs and may use privacy-respecting analytics. We do not use this data to build advertising profiles.
2. Google Account data
Glimpse can connect to your Google Account to answer questions about your calendar and email and to take actions you request. We request access only when you choose Connect Googlein Settings → Integrations. Features that are not enabled do not request their related scopes.
Google data and permissions we access
- Google Account email address (
openidandemail). We display it in Settings so you can confirm which Google Account is connected. - Primary calendar events (
calendar.events). Glimpse reads events to answer scheduling questions and creates, updates, or deletes a specific event when you ask. Glimpse does not need or request access to calendar settings, access-control lists, or your calendar list. - Sending email (
gmail.send). Glimpse can prepare an email from your request and on-screen context. Before it is sent, Glimpse shows you the recipients, subject, and full body in a compose card. The message is sent only after you review it and explicitly press Send. Glimpse does not send email autonomously or in the background, and it does not create or manage Gmail drafts. - Reading email (
gmail.readonly). In direct response to your question, Glimpse can run a Gmail search, inspect matching message headers, and read the specific message needed to answer you. Glimpse does not crawl, index, or bulk-download your mailbox and does not access it in the background.
We request gmail.readonly because narrower Gmail scopes do not provide message bodies. The gmail.metadata scope can identify that a message exists but cannot provide the content needed to answer questions about what the message says.
How the Google connection works
Google authorization tokens are stored in the macOS Keychain on your Mac. They are never transmitted to or stored on Glimpse’s servers. Calls to the Gmail and Google Calendar APIs are made directly from your Mac to Google.
How Google data is used and shared
Glimpse uses Google data only to provide the feature you request. To answer a question about your email or calendar, the relevant content is sent to the AI model you selected only after you make that request.
- Your own API key.Your Mac sends relevant content directly to the model provider you configured, such as Anthropic, OpenAI, or Google. Glimpse’s servers do not receive it.
- Glimpse hosted Pro models. Your Mac sends relevant content to a Glimpse server endpoint, which forwards it to the model provider and streams the answer back. This pass-through endpoint does not log, retain, or store message or calendar content and does not make that content available to Glimpse employees in ordinary operation.
The free tier cannot access Google data because it does not support the tool calls used by Gmail and Calendar features. We do not sell Google data, use it for advertising, or use it to train any model. Our model providers are bound by API terms that prohibit training on data submitted through their APIs. Before content is sent to a model, Glimpse runs an automatic redactor that removes detected credentials and secrets.
Storage and derived memory
- On your Mac. Conversations, including email or calendar content shown in them, are stored locally on your Mac.
- In your private iCloud database.If iCloud sync is available and enabled, conversations also sync to the private CloudKit database associated with your Apple account. This is your iCloud storage, not ours, and Glimpse’s servers and employees cannot read it.
- Derived memory. Glimpse may extract a limited number of short facts about your work, such as your role, projects, tools, or stated preferences, to personalize later answers. These facts are stored in your private CloudKit database and are not used for advertising or profiling. Conversations in which Glimpse reads your mailbox are excluded; nothing derived from email content is written to memory.
We do not maintain a server-side copy of your messages, email, or calendar.
Retention, revocation, and deletion
You can disconnect Google at any time in Settings → Integrations. This deletes the stored authorization tokens from your Keychain and ends Glimpse’s access. You can also revoke access from your Google Account permissions. Settings → Privacy → Delete all local data erases locally stored conversations and their synced copies in your private CloudKit database.
Google API Services User Data Policy
Glimpse’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In particular:
- We use Google user data only to provide or improve the user-facing features described above.
- We transfer Google user data only with your consent as necessary to provide those features, for security purposes, to comply with applicable law, or as part of a merger, acquisition, or sale of assets after obtaining your explicit prior consent.
- We do not sell Google user data or use it for advertising, retargeting, determining creditworthiness, or lending purposes.
- We do not allow humans to read Google user data unless you affirmatively agree to access to specific data, access is necessary for security or legal compliance, or the data has been aggregated and anonymized for lawful internal operations.
3. How we use information
- To provide, maintain, and secure the Services;
- To process payments and manage subscriptions;
- To respond to support requests and communicate with you;
- To detect, prevent, and address fraud, abuse, security, and technical issues; and
- To comply with legal obligations and enforce our terms.
4. Legal bases (EEA/UK users)
Where the GDPR applies, we process personal data on the basis of: performance of a contract (providing the Services you request); our legitimate interests (securing and improving the Services); compliance with legal obligations; and your consent where required (which you may withdraw at any time).
5. How we share information
We do not sell your personal information. We share it only with:
- Service providers who process data on our behalf (such as Supabase for accounts and Stripe for payments), bound by contractual confidentiality and security obligations;
- AI providers you select, solely to fulfill the requests you submit, either directly from your Mac using your API key or through the Glimpse hosted Pro pass-through described above;
- Legal and safety recipients where we believe in good faith that disclosure is required by law, regulation, legal process, or to protect rights, property, or safety; and
- Successors in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
6. Data retention
We retain account and billing records for as long as your account is active and as needed to comply with legal, accounting, or reporting obligations. Content processed on your device remains under your control. Google data follows the storage, revocation, and deletion practices described in Section 2.
7. Security
We use reasonable administrative, technical, and organizational measures designed to protect information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials and any API keys confidential.
8. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object to certain processing. California residents have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them; we do not sell or share personal information as those terms are defined under California law. To exercise any right, contact us at teamglimpseai@gmail.com. We may need to verify your identity before acting on a request.
9. International transfers
We and our service providers may process information in countries other than your own. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers.
10. Children
The Services are not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Services after changes take effect constitutes acceptance.
12. Contact
Questions about this policy or your data? Contact teamglimpseai@gmail.com, or write to Glimpse AI.