Skip to main content

Glovi privacy

Privacy Policy

Effective date: June 26, 2026 · Last updated: June 26, 2026

This policy explains how Glovi collects and uses personal data across the app, capture pages, AI workflows, social integrations, billing, and support.

Data deletion

1. Who we are

Glovi is a marketing workflow platform operated by Glovi AI Inc. The service helps founders create, review, schedule, publish, and measure social content, capture pages, and related growth workflows.

For privacy requests, contact paul@glovi.ai. If we appoint a separate privacy contact, EU representative, or data protection officer, this policy will be updated with those details.

2. What this policy covers

This policy covers beta.glovi.ai, authenticated workspaces, public share pages, landing and capture pages, the Glovi capture widget, social publishing integrations, support operations, and related backend services.

Customers using Glovi to collect leads or manage audiences are responsible for their own lawful notices, consents, and campaign rules. Depending on the workflow, Glovi may act as a service provider/processor for customer lead data and as an independent controller for account, billing, security, and product operations.

3. Data we collect

Account and authentication data: name, email address, user identifiers, sessions, and access-control metadata provided through Clerk.

Workspace and brand data: company name, website or app URL, target audience, positioning, brand rules, onboarding answers, strategy notes, and settings.

Content and creative data: captions, posts, briefs, comments, approvals, images, videos, landing pages, schedules, public share metadata, and generated assets.

Social and integration data: connected account identifiers, handles, scopes, encrypted OAuth tokens, Slack workspace/channel metadata, publishing state, and platform responses where you enable integrations.

Lead and audience data: form submissions, names, email addresses, UTM parameters, capture source, consent status, consent source, profile events, audience stages, and related customer-controlled records.

Technical, usage, and security data: request timestamps, endpoints, error codes, device/browser data, Sentry events if enabled, Redis/job state, API usage, and audit logs.

Payment data: Stripe checkout, subscription, invoice, plan, credit, and webhook identifiers. Glovi does not store full payment card numbers from hosted Stripe checkout.

AI processing data: prompts, workspace context, brand materials, reference images, generated outputs, embeddings, and quality-review context sent to configured AI providers to deliver the service.

Cookie and attribution data: necessary auth/session cookies and a first-party Glovi visitor identifier, gv_vid, used for same-browser landing-page conversion attribution.

4. Why we use data and legal bases

Contract: to create and secure your account, run your workspace, generate content, store assets, schedule posts, publish approved work, provide capture pages, process subscriptions, and support you.

Consent: for optional marketing communications, optional analytics or similar non-essential technologies, and consented lead/contact workflows where the law requires opt-in.

Legitimate interests: to keep the service reliable and secure, prevent abuse, debug errors, measure basic product health, protect platform integrity, and improve workflows in ways users reasonably expect.

Legal obligations: to keep billing, tax, accounting, fraud-prevention, and compliance records where required.

User authorization: to connect social, Slack, or other third-party accounts and take actions you request, such as publishing an approved post or sending a notification.

5. AI and human approval

Glovi uses AI providers to draft marketing copy, strategy, images, videos, research summaries, and recommendations from the context you provide. Depending on the enabled configuration, processors may include Google/Vertex/Gemini, OpenAI, Anthropic, and compatible model providers.

AI outputs are drafts and recommendations. Glovi is designed so users review and approve content before publishing to social channels. We do not use AI to make decisions with legal or similarly significant effects about people without human/customer review.

6. Lead capture and outreach boundaries

Glovi landing pages and widgets may collect form submissions and attribution data on behalf of a customer workspace. Form opt-in can create a mailable contact; public signals, scraped/thread-extracted contacts, or manually observed profiles are not automatically treated as mailable unless separate consent exists.

Customers must make sure their capture pages, campaigns, and outreach comply with applicable privacy, email, consumer-protection, and platform rules.

7. Cookies and consent choices

Necessary cookies and storage are used for authentication, security, session continuity, fraud prevention, billing flow, and service delivery. These cannot be disabled through the Glovi consent panel.

Optional preferences, analytics, and marketing uses are controlled by the consent preferences tool below. We store your choice in local storage with a policy version and timestamp.

The gv_vid cookie is a first-party random browser identifier used for same-browser conversion attribution from Glovi landing/capture pages. It is not intended for cross-site identity building or sale of personal data.

8. Service providers and subprocessors

We do not sell personal data. We share data with service providers needed to operate Glovi, including authentication, hosting, storage, payments, AI generation, error monitoring, email delivery, social platform APIs, Slack, and search/research providers.

Current or configurable providers include Clerk, Stripe, DigitalOcean, Google/Vertex/Gemini, OpenAI, Anthropic, Sentry, Resend, Meta/Instagram, X, Slack, Reddit, LinkedIn, Tavily, Exa, and infrastructure such as Postgres, Redis, and object storage. Some providers are used only when the relevant feature is enabled.

9. International transfers

Glovi and its providers may process data in the United States, the European Economic Area, the United Kingdom, and other locations where our providers operate.

Where required, we rely on data processing agreements, standard contractual clauses, UK transfer addenda, adequacy decisions, or other legally recognized safeguards.

10. Retention

Account, workspace, content, lead, and audience records are kept while the account or workspace is active unless deleted earlier by request or product controls.

Connected social tokens are deleted when you disconnect the account, delete your account, or the token is revoked or expires. Logs and error records are retained only as long as needed for operations, security, debugging, and legal obligations; the prior operational target is up to 90 days for standard server logs.

Billing and tax records may be kept for the period required by law. Backups and cached copies are removed on normal rotation after active deletion unless we must retain data for legal, security, or dispute reasons.

11. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to processing, withdraw consent, and receive a portable copy of your personal data.

You may also have the right to complain to your local data protection authority. We may need to verify your identity before completing a request, and we aim to respond within 30 days unless the law allows or requires a different period.

12. Deletion

You can request deletion by emailing paul@glovi.ai with the subject line Data Deletion Request and the email address associated with your account. You can also review the data deletion instructions page linked below.

Deletion covers active Glovi account, workspace, brand, generated content, stored assets, social tokens, and related records that we can identify, subject to legal retention and backup rotation. Content already published to a social platform must also be deleted on that platform.

13. Security

We use TLS for data in transit, workspace access controls, environment-gated observability, minimized PII in backend Sentry configuration, and encryption for social OAuth tokens at rest.

No internet service can be guaranteed completely secure. If you believe your data or account has been affected, contact us promptly at paul@glovi.ai.

14. Children

Glovi is not intended for children. We do not knowingly collect personal data from children. If you believe a child provided data to Glovi, contact us and we will take appropriate deletion steps.

15. Changes

We may update this policy as the service, providers, or law changes. Material changes will be communicated through the app or the email address on your account where appropriate.

Contact

For any privacy-related questions, requests, or concerns, email paul@glovi.ai.