Privacy policy
Last updated 11 September 2026
- 01Who we are
- 02What we collect
- 03How the AI reads what you write
- 04How we use it
- 05Who we share with
- 06How long we keep it
- 07Your rights
- 08Apple's privacy label
- 09Security
- 10Children
- 11Changes
- 12Contact
01Who we are
Growth Forging Limited, a company registered in the Republic of Cyprus, makes glissa and is the data controller for it. For any privacy question, or to use a right described below, write to support@glissa.io.
02What we collect
On your phone, and only there
Glissa has no account and no sign-in. Everything the app knows about you is stored on your phone, in the app's own storage: your quiz answers, your name if you gave one, your check-in taps, your dares, your vents and their replies, your number and its history, and your reminder time. None of it is uploaded to us. If you delete the app, all of it is deleted with it, and we cannot bring it back.
What leaves your phone
| What | Where it goes | Why |
|---|---|---|
| What you type in the vent, the questions already asked in that vent, and the names of your four patterns | Our server, then OpenAI | To write the reply you get, only after you have agreed on the consent sheet. Never your name, your taps or your number. |
| A proof that your phone is a real iPhone running glissa, and a key identifier | Apple, then our server | So our server only answers our app. The identifier is not tied to you and cannot be used to find you. |
| Event names: which screen, which step of the quiz, a plan picked, a dare done or skipped, a check-in started or left, the model out of reach | PostHog | To see where people get stuck and fix it. An event is a name and a few small facts. Never your words, your answers, your number or your name. |
| A random identifier for your install, and what you bought | RevenueCat, and Apple | So the app knows your subscription is active, on this phone and after you restore it on a new one. |
| Standard device facts: model, iOS version, app version, language, time zone | PostHog and RevenueCat | Sent with the two items above, the way any app does. |
Reminders are scheduled on your phone by the app itself. There is no push server and no push token.
The vent is a free text field. You may choose to write about relationships, health, or anything else. Everything in this policy applies to that text however personal it is.
On glissa.io
The website runs PostHog with no cookies: which pages you saw, where you tapped, how far you scrolled, the link you arrived from, and a replay of the visit in which anything you type is hidden. When the link you came from carries the name of the account that posted it, that name travels with your tap on Download, so we can tell which video sent people to the app. The website does not know who you are, and the feature form is left out of every replay.
03How the AI reads what you write
The vent's questions, its ending, and the read of anything you type in a check-in come from a language model. The app asks you once, on a consent sheet, before any of it is sent. Say no and the vent uses written questions instead, and nothing leaves your phone.
When you say yes, the app sends what you wrote, the questions already asked in that vent, and the names of your four patterns to our own server, which sends them to OpenAI and returns the reply. OpenAI processes it under its API terms: it does not use it to train its models, and it keeps it for up to 30 days to check for abuse, then deletes it. Our server keeps none of it. It logs only that a request was accepted and whether a reply came back.
You can withdraw consent in the app under You, and the vent goes back to the written questions.
04How we use what we collect
- To run the app. Write the vent's replies, keep your subscription working, keep our server answering only our app.
- To improve it. Look at where people stop in the quiz or leave a check-in, in aggregate, and change the screens that lose them. These numbers never include what anyone wrote.
- To answer you. When you write to support.
- To meet the law. Where we are required to.
We do not sell your data, show you ads, build a profile of you for anyone, or share what you write with anyone other than the AI provider that writes your reply.
05Who we share with
Only the companies that run a piece of the app, each with only what it needs, each under a contract that binds it to protect it and to use it for us alone.
| Company | What it does | What it receives |
|---|---|---|
| OpenAI | Writes the vent's replies | The text described in section 03. Not used for training. Held up to 30 days for abuse checks, then deleted. |
| Cloudflare | Runs our server | The requests described above pass through it. Cloudflare keeps standard request logs for a short period. |
| Apple | Sells the app, handles payment, proves your phone is real | Your purchase, under Apple's own terms. The attestation, which Apple issues and we verify. |
| PostHog | Product analytics, for the app and for glissa.io | The event names described above and the website visits, in the United States. Never your text. |
| RevenueCat | Keeps track of subscriptions | A random install identifier and your purchase state. |
We may also disclose data if the law requires it, to protect our rights or someone's safety, or as part of a sale of the business, in which case we would tell you first.
Some of these companies are outside your country. Where data leaves the European Economic Area or the United Kingdom, we rely on the safeguards the law provides, among them the European Commission's Standard Contractual Clauses.
06How long we keep it
- What is on your phone stays as long as the app does. Delete the app and it is gone.
- Text sent to OpenAI is deleted by OpenAI within 30 days.
- Analytics events are kept by PostHog under its retention settings. Write to us with your install and we ask for them to be removed.
- The attestation key record on our server stays while the app talks to it, and expires when it stops.
- Support emails are kept as long as we need them to help you.
07Your rights
Because your data lives on your phone, most of what the law gives you a right to ask for is already in your hands: you can see it, correct it in the app, and delete it by deleting the app. For anything we hold, write to support@glissa.io and you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct it or delete it;
- stop using it, or object to a use;
- withdraw a consent you gave.
If you live in the EEA or the UK, you can also complain to a supervisory authority. In Cyprus that is the Office of the Commissioner for Personal Data Protection. If you live in California, you have the rights the CCPA gives you, and we do not sell or share personal information for advertising. We answer every valid request within 30 days and may ask you to confirm it came from you.
The legal bases we rely on
Performance of a contract, to give you the app you downloaded. Consent, for sending what you write to the AI, and for reminders. Legitimate interests, to keep the app secure and to understand how it is used, where those interests do not override your rights. Legal obligation, where the law requires.
08Apple's privacy label
On the App Store, glissa declares that it collects usage data and identifiers for analytics and for app functionality, not linked to your identity, and purchase history for app functionality. Your vent text is user content that is processed to provide the feature and is not collected by us. Glissa does not track you across other companies' apps or websites.
09Security
Everything between the app and our server travels over TLS, and every request carries a signature from a key that lives in your phone's Secure Enclave, so a request that did not come from a real iPhone running glissa is refused. On your phone, the app's data sits inside iOS's app sandbox and is protected by your device passcode. As with any app, someone with full access to an unlocked phone could read what is on it. If you think something here is wrong, or you have found a hole in it, write to us and we will answer.
10Children
Glissa is written for adults. We do not knowingly collect personal data from anyone under 13, or under the age your country sets for consent. If you think a child has used the vent and written something to the AI, write to us and we will ask OpenAI to delete it.
11Changes to this policy
When we change it, the date at the top changes. For anything that matters, the app tells you before it takes effect. Using the app after that means you accept the new version. If you do not, delete the app.
12Contact
Growth Forging Limited
Registered in the Republic of Cyprus
support@glissa.io