Privacy Policy
Last updated 6 September 2026
This policy applies to the Glosify web application, its APIs, and the Glosify Translator and Live Subtitles Chrome extensions.
Controller and contact
Gustav Boberg operates Glosify and is the controller for the personal data described here. Contact gusbo923@gmail.com for privacy questions or to exercise your rights.
Personal data Glosify handles
- Account and authentication data: email address, internal account ID, password hash, authentication method, security data, and identifiers received when you choose Google or Microsoft sign-in.
- Learning data: language and display preferences, quizzes, words, sentences, attempts, Anki-style study records, uploaded books and extracted page text, saved translations, and other content you create.
- Assistant data: chat messages, selected quiz, book, page, or transcript context, AI-generated replies, feedback, tool actions, and proposed or applied changes.
- Live subtitle data: tab audio you explicitly submit, recognized or translated text, language choices, timestamps, session state, and connection diagnostics. Glosify does not write live tab audio to its own persistent storage.
- Saved transcripts: when you separately enable transcript saving, finalized original-language speech, titles, timestamps, and the selected learning language. Transcript saving is off by default.
- Translator data: source text, translated text, selected or detected languages, optional dialect, register, tone, or wording preferences, and timestamps. Results are stored in Glosify only when you explicitly choose Save.
- Credits and payments: credit balance, reservations and usage transactions. If payments are enabled, Glosify stores the selected package, amount, currency, purchase status, and Stripe checkout, payment, refund, or dispute identifiers. Stripe, not Glosify, receives your card details.
- Technical and security data: IP address, request time and route, response status, device or browser information made available by the request, rate-limit events, traces, and error diagnostics.
Assistant content and operational analytics
Glosify stores saved assistant chats so you can return to them. Content capture is also currently enabled for assistant operations. This means an analytics record may contain the complete effective model request—including system instructions, replayed chat history, selected learning context, and tool schemas—as well as the model response, tool arguments, and tool results. Known secrets are redacted before storage, but these records can still contain your prompts and learning content.
Separate Azure Monitor telemetry records operational information such as model and tool names, token counts, timings, outcomes, and pseudonymous correlation identifiers. It is designed not to copy complete prompts, responses, tool arguments, tool results, tab audio, or caption text into that telemetry.
How and why the data is used
- To provide the service and perform the agreement: create and secure your account; save and synchronize your learning content; run quizzes, books, Anki, assistant, translation, subtitle, credit, and payment features; and respond to support requests.
- For legitimate interests: prevent fraud and abuse, enforce limits, protect users and infrastructure, diagnose failures, measure reliability and costs, and improve the service. Glosify balances these interests against your rights and limits content access to what is reasonably needed.
- To comply with law: keep payment, accounting, security, dispute, and compliance records where legally required.
- Based on your choice: use an external sign-in provider, capture a chosen tab for live subtitles, save a transcript, upload content, or share content with others.
AI, speech, and translation providers
Assistant requests, AI-assisted learning content, text submitted to the Translator with its optional preferences, and Enhanced live-subtitle audio are processed directly by OpenAI. Translator text is sent only when you choose Translate. ElevenLabs processes text when you choose its read-aloud voices. Generated audio is cached in memory for at most one hour and is not saved to Glosify file storage. It also processes tab audio when Scribe mode is selected or when a source transcript is requested in Enhanced mode. Standard ElevenLabs API logging is enabled, so ElevenLabs may retain service-log data under its own applicable terms and retention policy. Evolving Scribe phrases are sent through a protected Cloudflare Worker to M2M100 for translation.
Chrome captures audio only after you start subtitles for the active tab. Captions are transient unless you opt in to saving the source transcript. Google or Microsoft processes authentication data under its own policy when you choose that provider.
Service providers, disclosures, and transfers
Glosify uses Microsoft Azure for application hosting, databases, blob storage, monitoring, and identity infrastructure; Cloudflare for M2M100 translation in Scribe mode; OpenAI for the direct AI and Enhanced subtitle processing described above; ElevenLabs for read-aloud and Scribe speech features; Stripe for checkout and payment processing when enabled; and Google or Microsoft for optional sign-in. These providers process data on Glosify's behalf or as independent controllers for their own parts of the service.
Some providers may process data outside Sweden or the EU/EEA. Where Glosify is responsible for such a transfer, it relies on an applicable lawful transfer mechanism and contractual safeguards. Contact Glosify for more information. Data may also be disclosed where required by law, to protect legal rights or service security, or as part of a lawful reorganization. Glosify does not sell personal data or use it for personalized advertising.
Cookies, local storage, and external resources
The web application uses essential authentication, security, antiforgery, and language-preference cookies. The extensions store only the local settings, short-lived state, and Glosify authentication material needed for their disclosed functions. Translator settings include source and target languages and optional preferences; translation history is not stored in Chrome. Glosify does not use advertising cookies. The pages currently load font resources from Google, which causes the browser to connect to Google and disclose ordinary connection information such as the IP address.
Retention and deletion
- Account and learning content is generally kept while the account is active or until you delete the relevant item. Saved translations are retained until you explicitly delete them, or the account is deleted. You can delete supported items such as books, chats, saved translations, and saved transcripts through their in-app controls.
- To request deletion of the account and remaining account content, contact gusbo923@gmail.com. Glosify may keep limited records when required for accounting, fraud prevention, dispute handling, or another legal obligation.
- Assistant content-capture records follow the associated assistant chat and account deletion lifecycle. Deleting a chat also queues deletion of its pseudonymous Azure Monitor correlation records where configured.
- Azure Monitor's operational workspace retention target is 30 days. Database backups, provider logs, and deletion queues expire under their configured schedules and may not disappear immediately from recovery copies.
- Stripe and external sign-in providers keep their own records under their policies. Deleting Glosify data does not delete an independent copy held by those providers.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, or portability of your personal data, and you may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier processing. Glosify may need to verify your identity before completing a request.
You may complain to the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority.
Chrome Web Store Limited Use
Glosify's use and transfer of user data from its Chrome extensions adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Extension data is used only to provide and protect the disclosed translator, subtitle, and account-connection features, not for advertising or sale to data brokers. Human access is limited to the policy's permitted cases, such as your explicit consent for specific data, necessary security investigations, or legal obligations.
Changes
Material changes will be published here with a new effective date and, when appropriate, communicated in the service. Questions can be sent to gusbo923@gmail.com.