Skip to content Documentation index for agents (llms.txt)
Glotto Beta
Get started

Privacy Policy

Last updated

Glotto, Inc. (“Glotto”, “we”) operates the website at glotto.dev and the hosted Glotto service. This policy explains what personal data we collect, why, how long we keep it, and who else processes it.

This policy covers the marketing site and the hosted product. It does not cover the SDKs, docs sites, or MCP servers Glotto generates for you and that you host yourself — those run in your infrastructure, under your own policy.

What we collect

Website visitors

We use first-party, cookieless analytics. No cookies are set, nothing is written to browser storage, and no cross-site or cross-session profile is built — so there is no consent banner, because there is nothing to consent to.

Data Why Retention
Page path (no query string, no fragment) Understand which pages are read Retained in aggregate by our analytics sub-processor
Coarse event counts (page view, “get started” click) Understand which parts of the site work As above
Client error type Fix broken pages As above
IP address Unavoidably visible to any web server; used to serve the request and for abuse prevention. It is not stored by us as an identifier Transient

Each event carries an ephemeral identifier generated per page load and held only in memory. We do not stitch it to an identity, and we honour Do Not Track and Global Privacy Control — with either set, no analytics event is sent at all.

Account holders

To create and operate an account we process:

Data Why Legal basis (GDPR)
Email address Authentication — we sign you in with a one-time magic link, so the address is load-bearing, not optional Performance of a contract
Organisation name and membership Scope your projects and permissions Performance of a contract
Single sign-on identifiers, where your organisation uses SSO Federated authentication Performance of a contract
Billing contact and payment status Take payment and issue receipts Performance of a contract; legal obligation for tax records
Audit log entries — who did what, and when Security, and the audit trail our customers’ own reviews require Legitimate interests

We do not sell personal data, and we do not use it to train machine-learning models.

Customer content

Your API specifications, generated SDKs, documentation, and configuration are your content. We process them only to deliver the service you asked for — generating, verifying, and publishing your developer surface — and under your instructions. They are classified Confidential, encrypted in transit and at rest, and accessed by us only where least-privilege operation of the service requires it.

If your specification or configuration contains personal data, we process it as a processor on your behalf. See the Sub-processors page for who else is involved.

Where your data is processed

The hosted service runs in Microsoft Azure’s East US 2 region (Virginia, United States) across every environment. The database has no public endpoint — it is reachable only from within our private network. Customers with data-residency or isolation requirements that this does not meet can be served by a dedicated single-tenant deployment; contact us.

Who else processes it

Every third party that processes customer or personal data on our behalf is listed, with what it receives and where it processes it, on the Sub-processors page. That page is kept in step with our infrastructure by an automated check, so it cannot quietly fall behind the systems it describes.

How long we keep it

  • Account, organisation, and project data — for the life of the account. On account closure it is deleted, together with its single sign-on, billing, and usage records.
  • Billing records — retained as long as tax and accounting law requires, after account closure.
  • Audit logs — retained as an append-only trail, because their value is that they cannot be edited after the fact.
  • Secrets and credentials — kept only while in active use, and destroyed on revocation.
  • Backups — roll off on our standard backup retention window.

How we protect it

Data is encrypted in transit and at rest. Secrets live in a managed secrets store, never in source control, and an automated scan rejects any change that would commit one. Access is least-privilege and multi-factor. Outbound network access from our own services is denied by default and allowed only on the protocols the service actually needs, and URLs you supply to us are validated before we fetch them.

Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict processing of your personal data, to object to processing, and to withdraw consent. Under the GDPR you may also lodge a complaint with your supervisory authority. Under the CCPA/CPRA, we do not sell or share personal data as those terms are defined, and we will not discriminate against you for exercising a right.

You can delete your account — and the personal data attached to it — from the product at any time. For anything else, or to make a request on behalf of someone else, email privacy@glotto.dev. We will verify the request and respond within the period the applicable law allows.

To report a security vulnerability, email security@glotto.dev instead.

Children

The service is for software developers and organisations. It is not directed at children, and we do not knowingly collect personal data from anyone under 16.

Changes

We will update this page when our processing changes, and revise the “last updated” date above. Where a change materially affects you as a customer, we will also notify you directly.

Contact

Glotto, Inc. — privacy@glotto.dev