Skip to content

Trust & security

Your customer feedback, handled with care

GliddeSignal only works if you can hand it real customer voices. Here's exactly how that data is treated — stated plainly, not buried in a policy.

01Commitments

What we commit to

Never used to train models

Your feedback is not used to fine-tune or train shared models. The corrections you make stay scoped to your own project and only steer your future runs.

Isolated to your account

Every request enforces per-account ownership on your projects, runs, and feedback, so your data is never exposed to another customer.

You stay in control

Delete projects and runs from inside the product whenever you like — deleting a project removes its associated artifacts.

This page describes how the product works today. It complements — and doesn't replace — our Privacy Policy. Read the Privacy Policy.

02Subprocessors

Who else touches your data

A short list, each doing one job. We name them rather than describing them vaguely, because "trusted third parties" isn't something you can evaluate.

Supabase

What it does
Managed Postgres database and authentication
What it sees
Your account, projects, uploaded feedback, runs, and generated output

OpenAI

What it does
Embeddings, clustering labels, memo and action generation
What it sees
The feedback text in a run, plus your product context, sent per request

Lemon Squeezy

What it does
Payments, subscriptions, and invoicing
What it sees
Billing email and subscription state. Card details go to them, never to us

Vercel

What it does
Application hosting and scheduled syncs
What it sees
Request logs; no feedback content is stored outside the database

Resend

What it does
Receiving mail sent to your project's email-in address
What it sees
The emails you forward, in transit

Brevo

What it does
Transactional email — run-complete notices, account mail
What it sees
Your email address and the notification's contents

03Details

The operational detail

Encryption

Traffic to the site and app is TLS-encrypted end to end. Data at rest sits in managed Postgres with the provider's disk-level encryption. Integration credentials — your Zendesk OAuth client secret, your Intercom Access Token, your Google Play service-account key, and your Linear and Jira tokens — are encrypted before they're stored and are never returned to the browser after you save them.

Where your data is processed

Your feedback is stored in managed Postgres in Supabase's Seoul region (ap-northeast-2), and the application that reads and writes it runs on Vercel in Washington, D.C. (iad1) — so a run moves your feedback between those two regions. Embeddings, cluster labels and generated text are produced by OpenAI's API, whose default processing is in the United States. The contact and subscribe forms on this marketing site write to a separate database in Supabase's Singapore region (ap-southeast-1); it holds email addresses and messages, never product feedback.

Who can see it

Beyond the per-account isolation above: internally, access to production data is limited to the people who operate the service, and is used only to investigate a problem you've reported.

Retention and deletion

Your data stays while your account is active. Deletions propagate out of routine database backups as those backups age out on the provider's rolling schedule, so a deletion is not instantly erased from every backup copy — ask us if you need that confirmed in writing.

Integration scopes and revocation

Source integrations read only what they need: recent Zendesk tickets (a read-only OAuth scope), the conversations your customers open in Intercom (never the ones your team starts), a chosen Slack channel, your app's public App Store reviews, and the reviews for the one Android app you nominate on Google Play. Tracker integrations create issues and nothing else. Disconnect any integration from its project's Integrations tab, and revoke the credential at the provider too — that's the step that guarantees it, and we'd rather tell you to do both.

Reporting a vulnerability

If you've found something, email us and we'll acknowledge it. We don't run a paid bounty, and we'd rather say so than imply one. Please don't run automated scans against production or test with another customer's data.

Data processing agreement

A DPA is available on request for teams that need one before uploading customer data. Ask and we'll send it.

What we don't claim

No SOC 2 report, no ISO 27001 certificate, no HIPAA readiness. None of those exist for this product yet, and a security page is the last place to imply otherwise. When one does, it'll be named here with its date.

Ask us anything specific

Security questionnaires, a DPA, processing regions, or a vulnerability report — all go to the same place, and a person reads it.

Begin

Put your feedback to work — safely.

Upload a batch and see the problems worth fixing, knowing exactly how your data is handled.

14 days · no credit card required