Privacy Policy
Last updated: August 8, 2026
This policy explains what data Glotier (glotier.com, operated by Oguzhan Tusen) collects, how we use it, and your rights. We keep it minimal: we never sell your data, and we never see or store your card details.
What we collect
Account data: your email address, used for passwordless sign-in and product emails. Usage data: the websites and links you submit, the brands and questions you track, the product profile you fill in (including any free-text description, pricing and story you enter), and basic logs needed to run and secure the service. If you upload a logo for a client report we store that image. We store a hashed version of your IP address to rate-limit the free check; we do not store the address itself.
Payment data: handled entirely by Lemon Squeezy, our Merchant of Record. We receive confirmation of a purchase and the email used, but we never receive or store your card or bank details.
What we do not collect or invent
Most of what Glotier reads is public: web pages, search results and the answers assistants give. The exceptions are the credentials you choose to give us. If you connect an App Store Connect key or your own AI provider key, we use it to call that service as you, only for the features you asked for, and you can remove it at any time. We never fabricate numbers about you or a competitor.
How we use your data
To provide the service (run analyses, track ranks, show your dashboard), to send product and account emails, to secure the service and prevent abuse, and to apply your plan limits. We do not sell or rent your personal data to anyone.
Processors we rely on
Cloudflare (hosting, database and key storage), Resend (transactional email), and Lemon Squeezy (payments and invoicing, as Merchant of Record). To run a check we send your question and the retrieved page text to search and model providers: Serper and Exa for web search, and OpenRouter, which routes to OpenAI, Google and Perplexity models. DeepSeek, Google, Mistral and Groq may be used for the structured extraction step. If you connect your own key we call that provider directly instead, which today can be OpenAI, Anthropic, Google or Perplexity. If you connect App Store Connect we call Apple. Each processes data only to provide their part of the service.
Google user data
If you sign in with Google, we receive your verified email address and basic profile (your name and profile picture) from Google, and we use them only to create or sign you into your Glotier account and to send account and product emails. We never receive your Google password.
If you connect Google Analytics, you grant read-only access (the analytics.readonly scope) and we store a Google refresh token, encrypted at rest and scoped to your account, so the Traffic tab can read the metrics you authorize: sessions and users, the default channel grouping, and your top pages and countries. We read these live to render your dashboard, we do not copy your Analytics figures into our database, and we never write to or change anything in your Google Analytics.
Who we share Google user data with: no one. We do not sell, rent, or share it with any third party. It is processed only on our infrastructure provider Cloudflare, to run the sign-in and Traffic features you turned on. We do not send Google user data to the search or AI model providers we use to run checks.
We use Google user data only to provide and improve these user-facing features. We do not use it for advertising or ad personalization, we do not sell or transfer it to data brokers or information resellers, we do not use it to determine credit-worthiness or for lending, and we do not use it to train, retrain, fine-tune, or improve any generalized or non-personalized AI or machine-learning model.
You can disconnect Google Analytics at any time, which revokes and deletes the stored token, and you can revoke Glotier's access at any time from your Google Account permissions page. When you disconnect or delete your account we delete the associated Google data we hold. Glotier's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Cookies
We use only essential cookies needed to sign you in and keep your session. We do not use advertising or cross-site tracking cookies.
How we keep your data safe
In transit and at rest. Everything runs over HTTPS, and the sensitive things we store are encrypted at rest with AES-GCM: any API keys you add, and the Cloudflare and Google refresh tokens behind the Traffic tab. They are stored separately per account and are never logged or shown back to you. To be precise rather than flattering: the encryption key is held by Glotier, so this protects you against a database leak and against other users, not against Glotier itself.
Your data is yours alone. Every read of your measurements, tracked products and connected accounts is scoped to your signed-in account at the database layer, not only in the interface, so one customer can never load another's data. We review our own code specifically for this.
Read-only, revocable connections. The Cloudflare and Google Analytics connections use read-only scopes, so we can read the metrics you authorize and nothing else, we never write to or change your accounts, and you can disconnect at any time, which deletes the stored token.
Safe when we read a link you give us. The audit and check features fetch pages as text only: no JavaScript runs, nothing is rendered, and no file is downloaded or executed, so a hostile page is just bytes we read and discard. We fetch only public http and https addresses, refuse requests to internal or private network addresses, and re-check the destination after every redirect, so a link cannot steer our servers somewhere they should not go.
Sessions and payments. Your login session is an HttpOnly, Secure, SameSite cookie, and payments run through Lemon Squeezy as Merchant of Record, so your card details never touch our servers.
Retention. We keep account data while your account is active, and delete it on request.
Your rights
You can request access to, correction of, or deletion of your personal data at any time. Email [email protected] and we will action it. If you are in the EU, UK, or Turkey, you have the rights granted by GDPR and KVKK, including the right to complain to your local authority.
Questions about this policy? Email [email protected].