The privacy of your data — and it is your data, not ours — matters deeply to us. This policy explains what data we collect, how we handle it, and your rights. We never sell your data — never have, never will.
Our guiding principle is to collect only what we need. Users sign in with Google (via Supabase Auth). Glotix (https://glotix.ai) accesses the following from your Google account:
To deliver AI dubbing and text-to-speech, we also process:
When you sign in with Google, we ask for identifying information such as your name, email address, and profile picture. That is so you can personalize your account and access your files. We will never sell your personal info to third parties, and we will not use your name in marketing statements without your permission either.
Glotix does not store or use your geolocation. IP addresses are recorded temporarily at the API level for security (e.g., to prevent abuse), but are not associated with your Google profile.
We use persistent first-party cookies and browser storage (including session tokens) to keep you signed in, remember preferences, and support in-house analytics. A cookie is a piece of text stored by your browser to help it remember your login information, site preferences, and more. You can adjust cookie retention settings in your browser. To learn more about cookies, including how to view which cookies have been set and how to manage and delete them, please visit www.allaboutcookies.org.
We do not use third-party advertising cookies on the Glotix app.
We don't collect any characteristics of protected classifications including age, race, gender, religion, sexual orientation, gender identity, gender expression, or physical and mental abilities or disabilities.
Our default practice is to not access your information. The only times we will ever access or share your info are:
Accessing a user's account when investigating potential abuse is a measure of last resort. We have an obligation to protect the privacy and safety of both our customers and the people reporting issues to us. We do our best to balance those responsibilities throughout the process. If we discover you are using our products for a restricted purpose, we may report the incident to the appropriate authorities.
At Glotix, we apply the same data rights to all customers. Currently some of the most privacy-forward regulations in place are the European Union's General Data Protection Regulation ("GDPR") and California Consumer Privacy Act ("CCPA") in the US. Glotix recognizes all of the rights granted in these regulations, except as limited by applicable law. These rights include:
Many of these rights can be exercised by signing in and directly updating your account information, or by deleting files from My Files.
If you have questions about exercising these rights or need assistance, please contact us at privacy@glotix.ai. For requests to delete personal information or know what personal information has been collected, we will first verify your identity using a combination of at least two pieces of information already collected including your user email address. If an authorized agent is corresponding on your behalf, we will first need written consent with a signature from the account holder before proceeding.
All data is encrypted via SSL/TLS when transmitted from our servers to your browser. Database backups are also encrypted. Most data are not encrypted while they live in our database (since it needs to be ready to send to you when you need it), but we go to great lengths to secure your data at rest. Media files are stored on Cloudflare R2 with access controlled via signed URLs and account authentication.
We may update this policy as needed to comply with relevant regulations and reflect any new practices. The "Last updated" date at the top will change when we do.
Have any questions, comments, or concerns about this privacy policy, your data, or your rights with respect to your information? Please get in touch by emailing us at privacy@glotix.ai and we'll be happy to answer them!