Privacy policy

Last updated 11 September 2026

  1. 01Who we are
  2. 02What we collect
  3. 03How the AI reads what you write
  4. 04How we use it
  5. 05Who we share with
  6. 06How long we keep it
  7. 07Your rights
  8. 08Apple's privacy label
  9. 09Security
  10. 10Children
  11. 11Changes
  12. 12Contact

01Who we are

Growth Forging Limited, a company registered in the Republic of Cyprus, makes glissa and is the data controller for it. For any privacy question, or to use a right described below, write to [email protected].

02What we collect

On your phone, and only there

Glissa has no account and no sign-in. Everything the app knows about you is stored on your phone, in the app's own storage: your quiz answers, your name if you gave one, your check-in taps, your dares, your vents and their replies, your number and its history, and your reminder time. None of it is uploaded to us. If you delete the app, all of it is deleted with it, and we cannot bring it back.

What leaves your phone

WhatWhere it goesWhy
What you type in the vent, the questions already asked in that vent, and the names of your four patternsOur server, then OpenAITo write the reply you get, only after you have agreed on the consent sheet. Never your name, your taps or your number.
A proof that your phone is a real iPhone running glissa, and a key identifierApple, then our serverSo our server only answers our app. The identifier is not tied to you and cannot be used to find you.
Event names: which screen, which step of the quiz, a plan picked, a dare done or skipped, a check-in started or left, the model out of reachPostHogTo see where people get stuck and fix it. An event is a name and a few small facts. Never your words, your answers, your number or your name.
A random identifier for your install, and what you boughtRevenueCat, and AppleSo the app knows your subscription is active, on this phone and after you restore it on a new one.
Standard device facts: model, iOS version, app version, language, time zonePostHog and RevenueCatSent with the two items above, the way any app does.

Reminders are scheduled on your phone by the app itself. There is no push server and no push token.

The vent is a free text field. You may choose to write about relationships, health, or anything else. Everything in this policy applies to that text however personal it is.

On glissa.io

The website runs PostHog with no cookies: which pages you saw, where you tapped, how far you scrolled, the link you arrived from, and a replay of the visit in which anything you type is hidden. When the link you came from carries the name of the account that posted it, that name travels with your tap on Download, so we can tell which video sent people to the app. The website does not know who you are, and the feature form is left out of every replay.

03How the AI reads what you write

The vent's questions, its ending, and the read of anything you type in a check-in come from a language model. The app asks you once, on a consent sheet, before any of it is sent. Say no and the vent uses written questions instead, and nothing leaves your phone.

When you say yes, the app sends what you wrote, the questions already asked in that vent, and the names of your four patterns to our own server, which sends them to OpenAI and returns the reply. OpenAI processes it under its API terms: it does not use it to train its models, and it keeps it for up to 30 days to check for abuse, then deletes it. Our server keeps none of it. It logs only that a request was accepted and whether a reply came back.

You can withdraw consent in the app under You, and the vent goes back to the written questions.

04How we use what we collect

We do not sell your data, show you ads, build a profile of you for anyone, or share what you write with anyone other than the AI provider that writes your reply.

05Who we share with

Only the companies that run a piece of the app, each with only what it needs, each under a contract that binds it to protect it and to use it for us alone.

CompanyWhat it doesWhat it receives
OpenAIWrites the vent's repliesThe text described in section 03. Not used for training. Held up to 30 days for abuse checks, then deleted.
CloudflareRuns our serverThe requests described above pass through it. Cloudflare keeps standard request logs for a short period.
AppleSells the app, handles payment, proves your phone is realYour purchase, under Apple's own terms. The attestation, which Apple issues and we verify.
PostHogProduct analytics, for the app and for glissa.ioThe event names described above and the website visits, in the United States. Never your text.
RevenueCatKeeps track of subscriptionsA random install identifier and your purchase state.

We may also disclose data if the law requires it, to protect our rights or someone's safety, or as part of a sale of the business, in which case we would tell you first.

Some of these companies are outside your country. Where data leaves the European Economic Area or the United Kingdom, we rely on the safeguards the law provides, among them the European Commission's Standard Contractual Clauses.

06How long we keep it

07Your rights

Because your data lives on your phone, most of what the law gives you a right to ask for is already in your hands: you can see it, correct it in the app, and delete it by deleting the app. For anything we hold, write to [email protected] and you can ask us to:

If you live in the EEA or the UK, you can also complain to a supervisory authority. In Cyprus that is the Office of the Commissioner for Personal Data Protection. If you live in California, you have the rights the CCPA gives you, and we do not sell or share personal information for advertising. We answer every valid request within 30 days and may ask you to confirm it came from you.

The legal bases we rely on

Performance of a contract, to give you the app you downloaded. Consent, for sending what you write to the AI, and for reminders. Legitimate interests, to keep the app secure and to understand how it is used, where those interests do not override your rights. Legal obligation, where the law requires.

08Apple's privacy label

On the App Store, glissa declares that it collects usage data and identifiers for analytics and for app functionality, not linked to your identity, and purchase history for app functionality. Your vent text is user content that is processed to provide the feature and is not collected by us. Glissa does not track you across other companies' apps or websites.

09Security

Everything between the app and our server travels over TLS, and every request carries a signature from a key that lives in your phone's Secure Enclave, so a request that did not come from a real iPhone running glissa is refused. On your phone, the app's data sits inside iOS's app sandbox and is protected by your device passcode. As with any app, someone with full access to an unlocked phone could read what is on it. No system is perfect. If you think something is wrong, write to us.

10Children

Glissa is written for adults. We do not knowingly collect personal data from anyone under 13, or under the age your country sets for consent. If you think a child has used the vent and written something to the AI, write to us and we will ask OpenAI to delete it.

11Changes to this policy

When we change it, the date at the top changes. For anything that matters, the app tells you before it takes effect. Using the app after that means you accept the new version. If you do not, delete the app.

12Contact

Growth Forging Limited
Registered in the Republic of Cyprus
[email protected]