Glimpse Privacy Policy
DRAFT — NOT YET IN EFFECT. This is a working draft of the Glimpse Privacy Policy made available for transparency during early development. It has not been reviewed by counsel and is not legally binding until the Effective date below is populated and the document is published to all users via the in-app notice mechanism described in Section 10. Until then, no representations are made about its completeness or accuracy.
Effective date: to be populated on publication Operator: Glimpse (the "Service"), operated by Syncraflow / Takudzwa Makoni ("we", "us", "our"). Contact: takudzwa.makoni@syncraflow.com
This Privacy Policy describes what personal information Glimpse collects, how we use it, who we share it with, and the choices you have. Words like "you", "your", and "user" mean the natural person using the Service.
1. What we collect
1.1 Account data
- Email address — required to create an account; used for sign-in, security notifications, and account-recovery emails.
- Username + display name — public identifiers you choose.
- Phone number — only when you choose phone sign-in; used as an authentication factor, not for marketing.
- Avatar / bio — optional self-supplied profile content.
1.2 Content you create
- Saved places, visits, items (dishes), notes, photos, collections, shares. This is the core data Glimpse exists to store and surface back to you.
- Provenance / sources — when you save a place, we ask "where did you hear about this?" so you can credit the friend, post, or list that recommended it.
1.3 Imported content
- URLs you submit (Instagram / TikTok / Maps links etc.) — we fetch the page metadata, send it to a third-party AI extraction service to identify places mentioned, then store the resulting structured data. The original URL and extraction result are kept so re-imports are deduplicated. Our agreements with that service prohibit it from using your content to train models.
1.4 Device and usage data
- Device type, OS version, app version, locale, timezone.
- Approximate IP address — used for security (rate limiting, abuse detection, audit logging) and to derive coarse geolocation for content delivery.
- Crash reports — stack traces, device state, and a short trail of recent user actions, collected when the app crashes so we can diagnose and fix bugs. We do not include the content of your saves or notes.
- Product analytics — page views, taps on key actions, and feature usage counts. We do not collect the content of your notes or messages. You can disable analytics collection at any time in Settings → Privacy.
1.5 Optional location data
- If you grant location permission, your device location is used in-memory to centre the map around you and surface nearby saved places. We do not store a continuous location history. We store the postcode you optionally enter as your "home area" so the map can centre on a sensible region before you grant permission.
1.6 Push tokens
- When you accept push notifications, your device's push delivery token is stored against your account so we can send share and planned-visit reminders. You can revoke push permission in OS settings; we delete the token on revocation.
1.7 Information from third parties
- Place data providers — when you search for or save a place, we send the query (place name or partial address) to a third-party place data service, which returns the canonical name, address, geocoordinates, photos, and rating. The query and the returned record are stored in your account.
2. Why we collect it (lawful bases under GDPR / UK GDPR)
We process your personal data for the following purposes and on the following legal bases:
| Purpose | Lawful basis |
|---|---|
| Providing the Service (storing your saves, displaying your map, delivering shares) | Contract — to perform the Terms of Service you agreed to |
| Authentication + account recovery | Contract + legitimate interest in account security |
| Abuse prevention, rate limiting, audit logging | Legitimate interest in keeping the Service secure |
| Product analytics + crash diagnostics | Consent (you can opt out in Settings) + legitimate interest in fixing bugs |
| Push notifications you opted into | Consent |
| Legal compliance (responding to lawful requests, DMCA) | Legal obligation |
For Australian users, the Australian Privacy Principles apply; this table maps roughly to APP 3 + APP 6 purposes. For California users, see Section 8 below on CCPA.
3. Who we share data with
Glimpse does not sell personal data. Period.
We engage service providers to help us run the Service. Each is contractually bound to use the data only for the purpose we direct, to apply appropriate security, and not to use your data to train AI models or build their own profiles of you. We share data with the following categories of service providers:
- Cloud infrastructure providers — hosting our application servers, databases, file storage, and audit logs.
- Identity and authentication providers — verifying your email or phone at sign-in and managing account sessions.
- Place data providers — returning canonical restaurant details for the places you search for or save.
- AI extraction providers — converting unstructured content (the URLs you import) into structured place records.
- Push notification providers — delivering reminders and share notifications to your device.
- Crash diagnostics and product analytics providers — receiving anonymous device and usage data when the app crashes or when you interact with key features.
- Mobile distribution providers — distributing the Glimpse app binaries and over-the-air updates to your device.
- App marketplaces (Apple App Store, Google Play) — handling payment processing when you subscribe to a paid plan. We receive subscription state only, never your payment details.
A current list of named sub-processors is available on request by emailing takudzwa.makoni@syncraflow.com.
We share data with other users of the Service when you direct us to: shares, public link views, follower visibility on your profile. We never share private content with other users without your action.
We may share data with law enforcement or other parties when legally compelled (subpoena, court order, lawful regulatory request). We will challenge overly broad requests and will notify you unless prohibited by law.
We may share aggregated, de-identified data (e.g. "X% of users in Adelaide save Italian restaurants") in research or marketing contexts. This is data from which you cannot be identified.
4. International transfers
Our infrastructure runs in cloud regions that include the United States. If you are located outside the US, your data will be transferred to and processed in the US. We rely on:
- Standard Contractual Clauses approved by the European Commission for EU / UK transfers, in place with each of our sub-processors.
- For Australian users, our sub-processors operate under Cross-Border Disclosure obligations equivalent to the Australian Privacy Principles (APP 8).
5. Retention
- Account data is retained while your account is active.
- Audit log entries are retained for 90 days then deleted.
- Encrypted database backups are retained for 7 days, then rotated out automatically.
- Account deletion is immediate and cascades through every owned record (saves, visits, items, collections, shares, follows, activities, exports). Any traces in encrypted backups age out within 7 days.
- Sources (your recommendation attributions to friends) are cross-user data — if you delete your account, your name is removed from sources attributed to you, but the source record itself stays with the friend who saved the place.
6. Your rights
Depending on your location you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data (right to erasure). The in-app Settings → Danger Zone → Delete account is the fastest way.
- Export your data (right to portability). Settings → Data & Privacy → Export My Data produces a Markdown bundle. Larger or alternative format requests: takudzwa.makoni@syncraflow.com.
- Object to certain processing (e.g. analytics — toggle off in Settings → Privacy → Share usage data).
- Withdraw consent for any consent-based processing at any time, without affecting the lawfulness of past processing.
- Lodge a complaint with your supervisory authority. Australian users: oaic.gov.au. UK users: ico.org.uk. EU users: see your national DPA.
We respond to verifiable requests within 30 days.
7. Children
Glimpse is not intended for children under 13 (or under 16 in the EU). We do not knowingly collect personal data from children below these ages. If you believe a child has provided us with personal data, contact takudzwa.makoni@syncraflow.com and we will delete it.
8. California residents (CCPA / CPRA)
Glimpse does not sell or share (as those terms are defined under CCPA / CPRA) personal data. California residents have the same access / deletion / correction rights described in Section 6, plus the right not to be discriminated against for exercising them.
To request information about the categories of personal data we collected in the prior 12 months and the categories of recipients, email takudzwa.makoni@syncraflow.com.
9. Security
We apply security practices appropriate to the sensitivity of the data we hold, including:
- HTTPS / TLS encryption in transit for every connection between your device and our servers and between our servers and our sub-processors;
- encryption at rest for the database, file storage, and backups;
- authentication and access controls on every API endpoint, so that one user cannot read or modify another user's content;
- rate limiting, input sanitisation, and abuse protections on user-supplied content;
- regular dependency and container vulnerability scanning, and a patch process for security advisories;
- audit logging on sensitive actions (account deletion, plan changes, list publication, export creation).
No system is ever 100% secure. If you become aware of a vulnerability, please report it to takudzwa.makoni@syncraflow.com and give us a reasonable opportunity to remediate before disclosing it publicly.
10. Changes
We may update this Policy. Material changes will be announced in-app and by email to the address on file at least 14 days before they take effect. The "Effective date" at the top is the canonical version marker.
11. Contact
- Privacy questions: takudzwa.makoni@syncraflow.com
- Account deletion: Settings → Danger Zone → Delete account
- Data export: Settings → Data & Privacy → Export My Data
- DMCA / copyright: see the separate DMCA Policy