Privacy Policy
Last updated · 2026-04-17
1. Who We Are
Glarify ("Glarify", "we", "us") provides an SEO analytics workspace at glarify.net that helps website owners understand performance data from Google Search Console, Google Analytics 4, Google Tag Manager and Bing Webmaster Tools in one place.
This policy explains what we collect, why, how we store it, and how you can control or delete it. For questions, email
2. Information We Collect
Account information
- Name, email and avatar (received from Google when you sign in)
- Workspace and project names you create
- Billing details (handled by our payment processor; we never see card numbers)
Google account data (via OAuth)
When you connect a Google service, you authorize Glarify to read specific data on your behalf. We only request the scopes listed in Section 4. We never modify your Google account.
Product usage
- Pages viewed inside the app, features used, and timestamps
- Device and browser metadata (user agent, screen size, IP address)
- Diagnostic logs of API calls we make on your behalf (status codes, durations)
3. Google API Services — Limited Use Disclosure
Glarify's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data accessed through Google APIs is:
- Not sold to anyone, ever.
- Not used for advertising, including retargeting, personalized advertising, or interest-based advertising.
- Not used to develop, improve, or train generalized AI/ML models. When you use Glarify's AI features, your data is sent only to the AI provider you have configured (e.g. OpenAI, Anthropic, Google) under your own API key, and is not retained by Glarify for model training.
- Not read by humans, except (a) with your explicit consent for troubleshooting a specific support request you raised, (b) for security investigations, or (c) where required by law.
- Used only to provide and improve user-facing features within Glarify, displayed only to you and the workspace members you invite.
4. Google Scopes We Request
We request the minimum scopes needed for each feature. You can revoke any of them at any time (see Section 8).
.../auth/userinfo.email · .../auth/userinfo.profile · openid
Why: Identify your account and display your name and avatar in the app. Standard non-sensitive sign-in scopes.
.../auth/webmasters.readonly
What we read: Verified Search Console properties, search analytics (clicks, impressions, queries, pages, countries, devices), sitemaps, and index coverage status.
Why: To display Search Console dashboards, generate AI insights, and produce reports. Read-only — Glarify never adds, removes, or changes anything in Search Console.
.../auth/analytics.readonly
What we read: GA4 account/property/stream metadata and report metrics (sessions, users, conversions, page paths, traffic sources, custom dimensions including post_author when present).
Why: To combine GA4 metrics with Search Console in unified dashboards (the Authors Hub, traffic comparisons, monetization views). Read-only.
.../auth/tagmanager.readonly
What we read: Tag Manager account, container and tag configuration metadata.
Why: To help you diagnose tracking setup issues directly inside Glarify. Read-only — we never edit containers or tags.
Additional scopes for Google Business Profile may be requested in a future release; they will appear on Google's consent screen and are not requested today.
5. How We Store and Protect Data
- OAuth tokens: Google access and refresh tokens are encrypted at rest using PGP symmetric encryption (Supabase Vault) before being written to the database. They are decrypted only inside server-side functions that call the relevant Google API on your behalf.
- API responses: Search Console / GA4 / GTM responses are cached short-term to power the dashboard you are viewing. Aggregated KPI snapshots (clicks, impressions, sessions per day) are stored long-term so historical comparisons keep working.
- Transport: All traffic to Glarify uses HTTPS (TLS 1.2+).
- Access controls: Postgres Row-Level Security restricts every row to its owning user or invited workspace members. No employee accesses customer data in normal operations.
- Hosting: Data is processed by Supabase (Postgres, Edge Functions, Storage) and our hosting provider. Sub-processors are listed on request.
6. Data Retention
- Account data: retained while your account is active.
- OAuth tokens: retained until you disconnect the integration or delete your account; refreshed automatically while valid.
- Cached Google API responses: typically retained 7–30 days to power the dashboards, then purged.
- Aggregated historical metrics (KPI snapshots): retained for the lifetime of your account so you can see trend data.
- Diagnostic / API logs: retained up to 90 days.
- After account deletion: all personal data and Google data are deleted from production within 30 days; encrypted backups expire on their normal rolling schedule (≤ 35 days).
7. How We Share Information
We do not sell personal information. We share data only in these cases:
- Sub-processors we use to operate the service (Supabase for database/auth/edge functions, our hosting provider for the website, our payment processor, our transactional email provider).
- AI providers you configure (e.g. OpenAI, Anthropic, Google, Perplexity). These calls use your own API key and are governed by that provider's terms; Glarify does not retain those payloads for model training.
- Workspace members you invite. Invited members can see the dashboards, properties and Google-derived data inside that workspace, subject to their role.
- Legal requirements where we are compelled by valid legal process.
8. Your Rights and How to Revoke Access
You can at any time:
- Disconnect Google in-app: Settings → Connections → Disconnect. This deletes the stored Google tokens.
- Revoke from your Google Account: myaccount.google.com/permissions → remove Glarify.
- Delete your account: Settings → Account → Delete account. This removes your profile, workspaces, projects, tokens and personal data.
- Access, correct, export or restrict your personal data — email p*****y@g*****y.netand we will respond within 30 days.
If you are in the EU/UK you may also lodge a complaint with your local data protection authority.
9. International Data Transfers
Our infrastructure providers may process data outside your country of residence. Where such transfers occur from the EEA/UK, we rely on Standard Contractual Clauses or other appropriate safeguards.
10. Children
Glarify is not intended for users under 16. We do not knowingly collect data from children.
11. Changes to This Policy
We may update this policy as the product evolves. Material changes will be announced in-app or by email; the "Last updated" date above always reflects the current version.
12. Contact
Privacy questions, data requests, or revocation help: