Privacy Policy
Last updated: 17 September 2026
The short version
- We collect what is needed to run your account and to read the channels you connect. Nothing else.
- We do not sell data, we do not advertise, and there is no third-party tracking on this site.
- Statistics about your own channels are kept indefinitely — that is the whole point of GlideDay — and they go when your account does.
- You can export or delete everything yourself from your account.
1. Who is responsible
GlideDay (glideday.com) is a personal project in closed beta, run by an individual established in Greece. There is no company behind it, and it is not sold.
That individual is the controller of the personal data described here. For anything in this policy, including a request to exercise the rights in section 9, write to [email protected]; every such message is read by the person who runs the service.
2. What this policy covers
It covers the GlideDay website and the GlideDay application: the account
area, the scheduling and analytics application at /app, the
JSON API, and the MCP endpoint that lets an AI assistant read your own
data on your behalf.
It does not cover the platforms you connect GlideDay to — Google, Meta, TikTok, X and the rest. What they do with your data is governed by their own policies, and connecting one of them is you instructing us to talk to it on your behalf.
3. What we collect
a. Your account
- Your username and email address.
- Your password, stored only as a one-way hash — we cannot read it.
- Two-factor secrets and passkey public keys, if you enable them.
- Sessions and access tokens, with the time and the device or client they were issued to.
- A record of sign-ins, failed sign-ins and lockouts, with the IP address and browser they came from.
- An activity log of significant actions on the account — a sign-in, a password change, a connection made or removed.
Sign-in records and the activity log exist for security: they are how a break-in is noticed and how you can check whether one happened.
b. Your organisation
GlideDay is organised around organisations rather than individuals: an organisation owns the sites, the connected channels and the history, and one or more people belong to it. We store the organisation's name and who is a member of it. Anyone in your organisation can see everything that belongs to it.
c. What you enter
- The websites you register: their address, name and timezone.
- The social accounts you register: the platform and the handle.
- Content you schedule — text, links and any media you attach — together with when it is to be published and where.
d. Credentials for the platforms you connect
When you connect a platform, it gives us an access token and usually a refresh token, together with the identity of the account that granted them and the scopes you approved. These are stored encrypted and are used for one thing: making the calls you asked for. We ask for read scopes wherever reading is all a feature needs.
e. The numbers we collect for you
This is what GlideDay is for. On a schedule, we read statistics about your channels — audience size, reach, views, sessions, search queries and impressions, per-post performance — and store each reading as a row: the moment, the channel, the metric, the value, and how confident we are in it.
These are aggregate numbers about your own properties. We do not collect the profiles, messages, comments or contact details of the people who follow or visit you, and we do not build profiles of them.
f. X (Twitter) profiles
X has no usable free API, so for an X account you register we read the follower and following counts from the public profile page — the same page anybody can open. We store no other part of it. Every such reading is recorded as low confidence, because a public page can change shape without notice, and a reading that fails is stored as nothing at all rather than as a zero.
g. Technical records
Our servers keep ordinary web and error logs: the request, the time, the IP address, the browser, and any error raised. They exist to keep the service up and to investigate abuse.
4. What we do not do
- We do not sell or rent personal data, to anyone, for any purpose.
- We do not show advertising and we do not profile you for it.
- There is no third-party analytics, no advertising pixel and no social widget on this site. Every script and stylesheet it loads is served from our own domain.
- We do not use your content to train AI models. The MCP endpoint reads your own data for an assistant you point at it, and nothing leaves the account that way unless you send it.
5. Why we are allowed to process it
- To perform our contract with you (Article 6(1)(b) GDPR): running your account, connecting the platforms you asked for, collecting the statistics, publishing what you scheduled.
- Our legitimate interests (Article 6(1)(f)): keeping the service secure and available, preventing and investigating abuse, and understanding faults. Security logging is the main example.
- Your consent (Article 6(1)(a)): where a feature is genuinely optional — connecting a platform is your explicit instruction, and withdrawing it is one click on the connection.
- Legal obligation (Article 6(1)(c)): accounting and tax records, once there is anything to account for.
6. Cookies and local storage
GlideDay sets no advertising or analytics cookies. What it does set:
- A session cookie, so that the server knows you are signed in. It is deleted when you sign out.
- A "remember me" cookie, only if you tick that box, so a session survives closing the browser.
- Your browser's local storage holds your access token for the application at
/appand your choice of light or dark theme. Both stay in your browser; the theme never reaches us.
All of these are either strictly necessary for a service you asked for or a preference you set yourself, which is why you are not being asked to consent to a banner full of things you did not.
7. How long we keep it
- Statistics about your channels: indefinitely, on purpose. Platforms throw their own history away — Search Console keeps sixteen months, most social platforms far less — and keeping it after they have is the reason GlideDay exists. This data is not deleted on a timer. It is deleted when you delete the channel or the account.
- Account data: for as long as the account exists, and then deleted.
- Platform tokens: until you disconnect the platform or delete the account, at which point they are deleted and, where the platform supports it, revoked.
- Sign-in and security records: a limited period appropriate to their purpose — long enough to investigate an incident, not indefinitely.
- Server logs: a short rolling window.
- Records we must keep by law, such as invoices, for as long as the law says.
8. Who else sees it
We share personal data only with:
- Our hosting provider — Hetzner, in Germany — which stores the database and runs the application.
- The platforms you connect, and only to make the calls you asked for.
- An email provider, to deliver the messages the service sends you.
- Authorities, where we are legally required to, and no further than required.
Each of these acts on our instructions under a written agreement, except the platforms, which are independent controllers of what happens on their side.
9. Transfers outside the EEA
The service runs on servers in Germany, so hosting involves no transfer outside the European Economic Area.
The platforms you connect are mostly established in the United States, so when you connect one, the requests we make on your behalf and the data they return cross that border under their own transfer arrangements — standard contractual clauses and, where it applies, the EU–US Data Privacy Framework. Not connecting a platform is the way to avoid that transfer.
10. Your rights
Under the GDPR you have the right to:
- ask what we hold about you and get a copy of it;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to processing based on legitimate interests;
- receive your data in a portable, machine-readable form;
- withdraw a consent at any time, without affecting what was done before you withdrew it.
Two of these do not need to be asked for. Your account has Export my data, which produces a machine-readable copy of your account, your sessions, your tokens and their activity, and Delete account, which removes it. For anything else, write to [email protected] and we will answer within one month.
If you think we have got this wrong, you can complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) — https://www.dpa.gr/ — or to the supervisory authority where you live.
11. How it is protected
- Everything travels over HTTPS.
- Passwords are hashed, never stored or logged in the clear.
- Platform tokens are encrypted at rest.
- Two-factor authentication and passkeys are available on every account, and sessions and tokens can be revoked individually.
- One organisation cannot read another's data: that boundary is enforced in the data layer rather than per screen, and it is covered by automated tests that fail the build if it stops holding.
No system is perfect. If a breach occurs that is likely to put your rights at risk, we will notify the supervisory authority within 72 hours and tell you without undue delay.
12. Children
GlideDay is a tool for people running a brand's channels. It is not directed at children and accounts are not knowingly created for anyone under 16.
13. Changes to this policy
We will update this page when the service changes, and the date at the top will say when. If a change materially affects your rights we will tell account holders by email rather than leaving it to be noticed.
14. Contact
[email protected] for privacy; [email protected] for everything else. The Terms of Use are the other half of this agreement.