Privacy Policy
In one paragraph
We collect the minimum data needed to run LLM Glow: your account info, the brands and phrases you choose to track, billing details (handled by Stripe), and standard product analytics. We never sell your data, and we never use your data to train AI models. Customer data is hosted in the EU on AWS (Frankfurt) by default. You can export or delete everything at any time.
1. Who we are
LLM Glow Sp. z o.o. is the data controller for personal data we collect about visitors to our website and users of our Service.
Registered office: ul. Próżna 9, 00-107 Warsaw, Poland. Email: privacy@llmglow.com.
2. Data we collect
2.1 Account data
- Name, email address, company, password hash;
- Profile preferences (language, theme, notification settings);
- Team members you invite, their roles and permissions.
2.2 Customer Data (your tracked content)
- Brand definitions, aliases, competitors, and phrase libraries you configure;
- Raw LLM responses retrieved on your behalf, and the visibility, sentiment, and share-of-voice scores we derive from them;
- Audit logs of who in your workspace viewed or edited what.
2.3 Billing data
Card details are collected and stored by Stripe under Stripe's privacy policy; we receive only the last four digits, card brand, and billing address.
2.4 Product telemetry
Page views, feature events, error reports, IP address, and approximate location (country/city). We use first-party analytics (Plausible, EU-hosted) and Sentry for error monitoring.
3. How we use it
- To provide the Service — run scheduled queries, compute scores, deliver alerts (legal basis: contract);
- To bill you — process payments via Stripe (legal basis: contract);
- To support you — answer tickets, debug issues (legal basis: legitimate interest);
- To improve the product — aggregated, de-identified analytics (legal basis: legitimate interest);
- To send service emails — security, billing, product changes (legal basis: contract);
- To send marketing emails — only with your consent, with one-click unsubscribe.
4. AI training — explicitly
X-No-Training hint where supported.
5. Sharing & sub-processors
We share data only with the sub-processors listed below, each under a Data Processing Agreement that meets GDPR Article 28 standards:
- AWS (eu-central-1, Frankfurt) — primary hosting;
- Stripe (Ireland / US) — payment processing;
- Postmark (EU region) — transactional email;
- Plausible (EU) — privacy-friendly analytics;
- Sentry (EU region) — error monitoring;
- OpenAI, Anthropic, Google, Perplexity, xAI, Mistral — to fulfil your queries.
We do not sell personal data, ever.
6. Retention
- Account data: kept while your account is active and 30 days after deletion;
- Raw LLM responses: 90-day rolling window by default; configurable up to 2 years on Enterprise;
- Aggregated scores: kept for the life of your account so historical charts work;
- Billing records: 7 years (tax-law requirement);
- Server logs: 30 days.
7. Security
We are SOC 2 Type II certified. We encrypt data in transit (TLS 1.3) and at rest (AES-256). Production access is restricted to a small on-call team, requires SSO + hardware security keys, and is logged. Penetration tests are run twice a year by an independent firm.
8. Your rights under GDPR
If you are in the EEA, UK, or Switzerland, you have the right to:
- Access a copy of your personal data;
- Correct or update it;
- Delete it (subject to legal retention obligations);
- Object to or restrict processing;
- Port it to another service in a machine-readable format;
- Withdraw consent for marketing at any time;
- Lodge a complaint with the Polish Data Protection Authority (UODO) or your local supervisory authority.
To exercise any of these, email privacy@llmglow.com. We respond within 30 days.
9. International transfers
Customer Data stays in the EU (Frankfurt) by default. When sub-processors process data outside the EU, we rely on the EU Standard Contractual Clauses and (for the US) the EU-US Data Privacy Framework where applicable. Enterprise customers may opt for US-only or APAC-only data residency.
10. Cookies
We use a minimal set of first-party cookies: a session cookie to keep you signed in, a CSRF token, and a preference cookie for theme/language. We do not use third-party advertising or tracking cookies. See our cookie banner for details and to change your preferences.
11. Children
The Service is not directed at children under 16, and we do not knowingly collect their data.
12. Changes to this policy
We post material changes here and notify you by email at least 14 days in advance. Older versions are archived and available on request.
13. Contact & DPO
Privacy questions: privacy@llmglow.com
Data Protection Officer: Anna Kowalska, dpo@llmglow.com
Postal: LLM Glow Sp. z o.o., ul. Próżna 9, 00-107 Warsaw, Poland