Trust & security
Your customer feedback, handled with care
GliddeSignal only works if you can hand it real customer voices. Here's exactly how that data is treated — stated plainly, not buried in a policy.
01Commitments
What we commit to
Never used to train models
Your feedback is not used to fine-tune or train shared models. The corrections you make stay scoped to your own project and only steer your future runs.
Isolated to your account
Every request enforces per-account ownership on your projects, runs, and feedback, so your data is never exposed to another customer.
You stay in control
Delete projects and runs from inside the product whenever you like — deleting a project removes its associated artifacts.
This page describes how the product works today. It complements — and doesn't replace — our Privacy Policy. Read the Privacy Policy.
02Subprocessors
Who else touches your data
A short list, each doing one job. We name them rather than describing them vaguely, because "trusted third parties" isn't something you can evaluate.
Supabase
- What it does
- Managed Postgres database and authentication
- What it sees
- Your account, projects, uploaded feedback, runs, and generated output
OpenAI
- What it does
- Embeddings, clustering labels, memo and action generation
- What it sees
- The feedback text in a run, plus your product context, sent per request
Lemon Squeezy
- What it does
- Payments, subscriptions, and invoicing
- What it sees
- Billing email and subscription state. Card details go to them, never to us
Vercel
- What it does
- Application hosting and scheduled syncs
- What it sees
- Request logs; no feedback content is stored outside the database
Resend
- What it does
- Receiving mail sent to your project's email-in address
- What it sees
- The emails you forward, in transit
Brevo
- What it does
- Transactional email — run-complete notices, account mail
- What it sees
- Your email address and the notification's contents
03Details
The operational detail
Encryption
Traffic to the site and app is TLS-encrypted end to end. Data at rest sits in managed Postgres with the provider's disk-level encryption. Integration credentials — your Zendesk OAuth client secret, your Intercom Access Token, your Google Play service-account key, and your Linear and Jira tokens — are encrypted before they're stored and are never returned to the browser after you save them.
Where your data is processed
Your feedback is stored in managed Postgres in Supabase's Seoul region (ap-northeast-2), and the application that reads and writes it runs on Vercel in Washington, D.C. (iad1) — so a run moves your feedback between those two regions. Embeddings, cluster labels and generated text are produced by OpenAI's API, whose default processing is in the United States. The contact and subscribe forms on this marketing site write to a separate database in Supabase's Singapore region (ap-southeast-1); it holds email addresses and messages, never product feedback.
Who can see it
Beyond the per-account isolation above: internally, access to production data is limited to the people who operate the service, and is used only to investigate a problem you've reported.
Retention and deletion
Your data stays while your account is active. Deletions propagate out of routine database backups as those backups age out on the provider's rolling schedule, so a deletion is not instantly erased from every backup copy — ask us if you need that confirmed in writing.
Integration scopes and revocation
Source integrations read only what they need: recent Zendesk tickets (a read-only OAuth scope), the conversations your customers open in Intercom (never the ones your team starts), a chosen Slack channel, your app's public App Store reviews, and the reviews for the one Android app you nominate on Google Play. Tracker integrations create issues and nothing else. Disconnect any integration from its project's Integrations tab, and revoke the credential at the provider too — that's the step that guarantees it, and we'd rather tell you to do both.
Reporting a vulnerability
If you've found something, email us and we'll acknowledge it. We don't run a paid bounty, and we'd rather say so than imply one. Please don't run automated scans against production or test with another customer's data.
Data processing agreement
A DPA is available on request for teams that need one before uploading customer data. Ask and we'll send it.
What we don't claim
No SOC 2 report, no ISO 27001 certificate, no HIPAA readiness. None of those exist for this product yet, and a security page is the last place to imply otherwise. When one does, it'll be named here with its date.
Ask us anything specific
Security questionnaires, a DPA, processing regions, or a vulnerability report — all go to the same place, and a person reads it.
→Begin
Put your feedback to work — safely.
Upload a batch and see the problems worth fixing, knowing exactly how your data is handled.
14 days · no credit card required