Privacy Policy

DRAFT — requires attorney review. Last updated: 2026-04-16.

DRAFT notice. This Privacy Policy is a good-faith draft published during Gluecron's pre-launch phase. It has not been reviewed by privacy counsel. Article 13 GDPR disclosures, sub-processor lists, and retention schedules are provisional and will be finalized before general availability.

1. Data we collect

2. How we use it

3. Data controller

The data controller is Gluecron (entity name placeholder — DRAFT; final legal entity name and registered address to be inserted prior to launch). Contact: support@gluecron.com.

4. Sub-processors

We engage the following sub-processors to operate the Service. This list is current as of the date above and may change; we intend to provide 30 days' notice of material changes.

Sub-processorPurposeData categories
Neon (neon.tech)Managed PostgreSQL (primary database)Account data, metadata, telemetry
AnthropicClaude API (AI features)AI prompts (including code snippets you submit)
Resend (if enabled)Transactional email deliveryEmail address, message contents
Fly.io / RailwayApplication hosting (compute)All transient request data
Cloudflare (if fronting)CDN, DDoS mitigation, DNSIP address, request metadata

DRAFT — requires attorney review; sub-processor list must be verified against signed DPAs prior to launch.

5. Data retention

6. GDPR compliance (EU / UK residents)

If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your data under the following lawful bases (GDPR Art. 6): (a) performance of a contract (providing the Service to you); (b) our legitimate interests in securing and improving the Service; (c) compliance with legal obligations; and (d) where required, your consent (which you may withdraw at any time).

Article 13 disclosures. The identity of the controller, data categories, purposes, retention, recipients, and your rights are described throughout this Policy. International transfers of personal data outside the EEA/UK will rely on the EU Standard Contractual Clauses ("SCCs") or another approved transfer mechanism.

Your rights include access, rectification, erasure, restriction, portability, and objection. You may lodge a complaint with your local supervisory authority. DRAFT — requires attorney review.

7. CCPA / CPRA compliance (California residents)

If you are a California resident, you have the right to (a) know what personal information we collect, use, disclose, and sell or share; (b) delete your personal information, subject to legal exceptions; (c) correct inaccurate personal information; (d) opt out of the sale or sharing of personal information (we do not sell personal information); and (e) non-discrimination for exercising these rights.

8. Right to erasure / access

To exercise any of the rights above, email support@gluecron.com. We intend to respond within thirty (30) days. We may need to verify your identity before acting. Some data (e.g., audit logs required for security, legal holds) may be exempt from deletion.

9. Cookies

We use only strictly necessary cookies (session authentication, theme preference, CSRF). We do not use advertising cookies. We do not use third-party analytics cookies on our marketing surfaces.

10. Children

The Service is not directed to children under 18. We do not knowingly collect personal information from children under 13 (COPPA, U.S.) or 16 (GDPR, EEA). If you believe a child has provided us information in violation of this Policy, contact us and we will delete it.

11. Breach notification

In the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we intend to notify the relevant supervisory authority within 72 hours of becoming aware, as required by GDPR Art. 33, and to notify affected users without undue delay where required.

12. Changes to this Policy

We intend to provide thirty (30) days' notice of material changes to this Policy, by email or by posting a notice in the Service.


See also: Terms of Service · Acceptable Use Policy · DMCA Policy