Privacy Policy

Last Updated: July 8, 2026

Welcome to Glyf ("we," "us," or "our"). Your privacy is critically important to us. This Privacy Policy outlines how we collect, use, disclose, and safeguard your information when you use our SaaS application, Glyf (the "Service"). We are committed to transparency and protecting your data. Please read this policy carefully. If you do not agree with its terms, please do not access or use the Service.

Data Controller: Glyf is operated by Ahmed Feyzi Genc (Germany), who determines the purposes and means of the processing described here. Full legal and contact details are in our Impressum.

1. Information We Collect

We collect information in the following ways:

1.1 User-Provided Data

  • Financial Documents: Files you upload for analysis (e.g., invoices, receipts, tickets in formats like JPEG, PNG, PDF). These documents may contain personal or sensitive information. We only process these as per your request. If you upload documents containing personal data of third parties (for example, vendors, employees, or customers named on an invoice), you are responsible for ensuring you have the right and a legal basis to process that data through the Service. If you use the Service on behalf of a business or organization, you may act as the controller of that third-party personal data. Some documents may incidentally contain special-category data (Art. 9 GDPR), such as health information on a medical invoice or religious affiliation implied by a donation receipt. Please avoid uploading documents containing special-category data where you can; where such data is present, we process it only on your instruction to provide the Service, and you are responsible for ensuring a lawful basis for it.
  • Contact Information: Your email address, which you provide when creating an account. We do not require your name or company name for basic account creation.
  • Account Credentials: Your email address (as username) and a securely hashed password if you register for an account.
  • Subscription Information: Details related to your subscription plan, such as tier, status, and usage limits (e.g., trial batches used), are stored to manage your access to the Service.

1.2 Automatically Collected Data

  • Usage Data: We maintain logs of actions you take within the Service, such as file upload timestamps and interactions with features. This data is used for operational monitoring and to ensure service stability.
  • Device & Connection Data: We may collect your browser type, IP address, and coarse geolocation (derived from IP address). This information is used where needed for security purposes (e.g., fraud prevention) and to optimize service delivery.
  • Local Storage Data: We may use browser local storage to save your preferences, such as your chosen theme (light/dark mode), to enhance your user experience.
  • Ad Click Identifiers: If you arrive at our website via an advertisement, your browser may receive a click identifier as a URL parameter. We temporarily store this in your browser's session storage and, if you create an account, associate it with your account metadata for advertising attribution purposes (see Section 3.1). This allows us to attribute subsequent conversion actions (such as subscribing) to the original ad click. The click identifier is retained for the lifetime of your account and deleted when your account is permanently removed (up to 30 days after a deletion request, consistent with our account recovery policy described in Section 4).

The data extracted from your documents (e.g., invoice numbers, dates, company names, item descriptions, quantities, prices, tax details, total costs, currency) is processed to provide the Service and is stored in connection with your account to offer features like analysis history. You have control over this data as described in Section 4.

2. How We Use Your Data

We use your information for the following specific purposes. Depending on the purpose, we process your data on one of the following legal bases under GDPR Article 6(1): (i) to perform our contract with you (Art. 6(1)(b)), such as document analysis, account management, and service notifications; (ii) our legitimate interest in operating, securing, and improving the Service (Art. 6(1)(f)), such as analytics, error monitoring, and fraud prevention; or (iii) to comply with legal obligations (Art. 6(1)(c)), such as responding to lawful requests. We use privacy-preserving analytics configurations designed to minimize personal data collection.

  • Document Analysis: To process the financial documents you upload, extract relevant data using our automated data extraction engine, and present it within the Service.
  • Service Operation & Improvement: We use aggregated, privacy-preserving usage metrics to monitor service performance, ensure stability, identify technical issues, and guide improvements to our infrastructure and core features. We do not use your specific uploaded documents or extracted data to train machine learning models or for general product development beyond these operational needs.
  • Account Management: To authenticate your access, manage your account and subscription, send essential transactional emails (e.g., password resets, subscription notifications), and provide customer support.
  • Legal & Security: To prevent fraud, ensure the security of our Service, comply with applicable legal obligations, and investigate potential abuse or violations of our terms.
  • Advertising Attribution: If you arrive via one of our advertisements and complete an action such as signing up or subscribing, we may share pseudonymized conversion data with advertising platforms to measure the effectiveness of our campaigns. This may include a hashed identifier derived from your email address and any advertising click identifier received when you arrived. These identifiers let a platform match a conversion to its own records; they are not used to give advertising platforms readable account information. This processing is based on our legitimate interest in understanding and optimising our marketing (Art. 6(1)(f), GDPR). This sharing is done server-side and uses no advertising cookies or browser pixels; the ad click identifier captured in your browser is described in Section 1.2. You may object to advertising-attribution processing at any time by contacting us at contact@glyf.pro.
  • Notify you of critical updates to the Service.
  • Respond to your comments and questions.

3. Data Sharing & Disclosure

We are committed to not selling your personal information. We only share your data with third parties in the following limited circumstances:

3.1 Third-Party Processors

We engage trusted third-party service providers to perform functions and provide services to us. We ensure these providers adhere to strict data protection and confidentiality terms.

  • Service Providers: We use trusted third-party service providers to assist with document processing. These providers are bound by data protection agreements and process your data solely to provide the requested service.
  • Cloud Infrastructure (Supabase & Vercel):
    • Supabase: We use Supabase for backend services, including secure database hosting (which stores your account information, metadata about uploaded files, and the data extracted from your documents), authentication, and image storage. Compressed images of your uploaded documents are stored securely in Supabase Storage to enable features like viewing your analysis history.
    • Vercel: Our application (front-end and API routes) is hosted on Vercel. Uploads are stored in our storage provider (Supabase); any processing on hosting infrastructure is transient.
  • Traffic Analytics (Vercel Analytics): We use Vercel Analytics for aggregated, privacy-preserving usage tracking to understand general traffic patterns and service performance. This data does not identify individual users or include content from your documents.
  • Payment Processing (Stripe): We use Stripe for subscription billing and payment card handling. Stripe processes payment information directly; we do not store your card details on our servers.
  • Document Processing Providers (Data Extraction Engine Subprocessors): To extract structured fields from your receipts and invoices, we may transmit document content (such as images, PDFs, and text) to specialized document understanding service providers (for example, OCR and related extraction services). We may also use such providers as a fallback to maintain service continuity. These providers process data only on our instructions under data protection agreements, are restricted from using your content for model training or other secondary purposes, and are configured for no storage beyond the processing session, or the shortest available retention period where technically supported. The current document-processing provider is available on request.
  • Product Analytics (PostHog): We use PostHog for product analytics in fully cookieless mode. PostHog is configured to avoid collecting direct identifiers (such as names or email addresses). It tracks page views and feature usage to help us improve the Service.
  • Email Delivery (Resend): We use Resend for transactional email delivery (contact form submissions, account notifications). Your email address is processed solely for email delivery.
  • Error Monitoring (Sentry): We use Sentry for application error tracking, configured to minimize collection of personally identifiable information. It captures request metadata (timing, status codes) for debugging purposes.
  • Security Services (Cloudflare Turnstile): We use Cloudflare Turnstile for CAPTCHA verification during signup, login, and contact form submission to prevent automated abuse.
  • Infrastructure (Upstash): We use Upstash for Redis-based rate limiting. It stores hashed IP identifiers with short time-to-live values for abuse prevention.
  • Advertising Attribution (Meta Platforms): We may use Meta's Conversions API to measure the effectiveness of our advertising campaigns. When you complete a conversion action (such as signing up or starting a subscription), we may share pseudonymized conversion data with Meta, including a hashed (SHA-256) identifier derived from your email address, any ad click identifier received at landing, and technical connection data (IP address and user agent), where required for conversion matching and measurement. These identifiers are designed to be matched against Meta's own records, not to give Meta readable account information. This is done server-side; no browser Pixel or cookies are involved. For this conversion data, Meta acts as an independent controller (and, for the collection and transmission step, potentially a joint controller) under its own business-tools and advertising terms, determining its own purposes; we do not control Meta's subsequent use of it. This processing is based on our legitimate interest in assessing marketing effectiveness (Art. 6(1)(f), GDPR). The international transfer safeguards described in Section 7 apply.
  • Advertising Attribution (Google): We may use the Google Ads API to upload server-side conversion data for advertising measurement. When you complete a conversion action (such as signing up or starting a subscription), we may share pseudonymized conversion data with Google, including a hashed (SHA-256) identifier derived from your email address and any ad click identifier (gclid) received at landing. These identifiers are designed to be matched against Google's own records, not to give Google readable account information. This is done entirely server-side; no Google tags (gtag.js) or cookies are involved. For this conversion data, Google acts as an independent controller (and, for the collection and transmission step, potentially a joint controller) under its own Google Ads data-processing and controller terms, determining its own purposes; we do not control Google's subsequent use of it. This processing is based on our legitimate interest in assessing marketing effectiveness (Art. 6(1)(f), GDPR). The international transfer safeguards described in Section 7 apply.

3.2 Legal Requirements

We may disclose your information if required to do so by law or in the good faith belief that such action is necessary to: (a) comply with a legal obligation, subpoena, or valid legal process; (b) protect and defend our rights or property; (c) prevent or investigate possible wrongdoing in connection with the Service; or (d) protect the personal safety of users of the Service or the public.

3.3 Business Transfers

We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company, subject to the new entity upholding the privacy commitments made in this policy.

4. Data Retention & Deletion

4.1 Active Accounts

While your account is active, we retain your uploaded invoice data (extracted text, images) to provide our analysis history and export features. Invoice images for free and trial accounts are automatically deleted 90 days after upload. Paid subscription accounts retain images for the duration of their subscription.

4.2 Inactive Accounts

If you do not log in for 30 days, your account is considered dormant. We will send reminder notifications at 45, 60, 67, and 75 days of inactivity. After 75 days of inactivity, your account is suspended and you will have 15 days to reactivate by logging in. After 90 total days of inactivity, your account and all associated data are permanently deleted.

Users with active paid subscriptions are exempt from inactivity policies as long as their subscription remains active.

4.3 Account Deletion by User

You may request account deletion at any time through your account settings. Upon requesting deletion, your account enters a 30-day grace period during which your data is preserved and you may cancel the deletion request. After 30 days, your account data is permanently deleted from our active systems, including profile information, analysis records, invoice images, and tags, subject to the limited retained records described in Section 4.4 and normal backup rotation (Section 4.6).

4.4 Data Retained After Deletion

After permanent deletion, the following is retained:

  • Audit logs containing a one-way cryptographic hash of your email address (not the email itself) for security compliance purposes, retained for up to 3 years.
  • A one-way cryptographic hash of your email address for fraud- and trial-abuse-prevention purposes (GDPR Art. 6(1)(f)), stored as a keyed hash (HMAC) to resist brute-force lookups and not intended to be reversible. We retain this hash only for as long as the abuse-prevention purpose requires, and review its continued necessity periodically. Because it is a non-reversible keyed hash that we do not use to look you up, re-identify you, or contact you, its retention is limited to that single purpose.

4.5 Right to Data Portability

You may export your data at any time through your account settings, including during the account deletion grace period and while your account is suspended. Exported data includes your profile, all invoice analysis records, and tags in JSON format. Payment and billing records are managed by our payment processor (Stripe) and are accessible through your billing portal.

4.6 System Backups

System backups and operational logs are purged on a rolling basis, typically within 30 to 90 days.

5. Security Measures

We implement robust security measures to protect your data:

  • Encryption in Transit: All communications between your device and our Service, and between our internal services, use TLS (HTTPS) encryption.
  • Encryption at Rest: Data stored in our databases (managed by Supabase) is encrypted at rest. Temporary files generated during processing are handled securely and deleted promptly after processing completes.
  • Access Controls: Access to production systems and user data is strictly limited to authorized personnel who require it for their job responsibilities. We employ role-based access controls and other technical measures to enforce these limitations.
  • Secure Development Practices: We follow secure coding practices and regularly review our application for potential vulnerabilities.
  • Regular Reviews: We regularly review and update our security practices to adapt to new threats and best practices.

While we are dedicated to securing your data, please remember that no method of transmission over the Internet or method of electronic storage is 100% secure. We strive to use commercially acceptable means to protect your Personal Information, but we cannot guarantee its absolute security.

6. Your Data Rights

We respect your rights over your personal data. Depending on your location and applicable laws, you may have the following rights:

  • Access & Portability: You have the right to request access to the personal data we hold about you and to receive a copy of it, where feasible, in a portable format.
  • Correction (Rectification): You have the right to ask us to correct any inaccurate or incomplete personal data we hold about you.
  • Deletion ("Right to be Forgotten"): You have the right to request the permanent deletion of your personal data, as outlined in Section 4.
  • Object to or Restrict Processing: You may have the right to object to or request the restriction of processing of your personal data under certain conditions.
  • Opt-Out of Marketing Communications: If we send marketing communications, you will have the right to opt-out at any time by following the unsubscribe instructions in the communication or by contacting us.
  • Lodge a Complaint: If you are located in the EEA, you have the right to lodge a complaint with your local data protection authority (in Germany, the supervisory authority of your federal state).

To exercise any of these rights, please contact us at contact@glyf.pro. We will respond within one month of receipt, a period that may be extended by up to two further months where necessary given the complexity or number of requests, in accordance with applicable data protection laws.

We do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing. Automated checks are used only to prevent trial and signup abuse; if such a check affects you, you may contact us for human review.

7. International Data Transfers

We are committed to keeping your data within the European Union wherever possible. Our primary database and file storage (Supabase) and our product analytics (PostHog, EU instance) are hosted within the EU/EEA, and we follow GDPR practices for data protection.

Some providers are established outside the EU/EEA or may process data there — including Vercel, Stripe, Sentry, Resend, Cloudflare, Upstash, Meta, and Google. For those transfers we rely on the EU–U.S. Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses together with supplementary measures. The specific safeguard relied on for a given provider is available on request.

8. Children's Privacy

Our Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information without appropriate parental consent, we will take steps to delete such information. If you believe we might have any information from or about a child, please contact us at contact@glyf.pro.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make material changes, we will notify you by updating the "Last Updated" date at the top of this policy and, where feasible, by email or through a notice within the Service.

10. Contact Us

If you have any questions, concerns, or comments about this Privacy Policy or our data practices, or if you wish to exercise your rights, please contact us at:
Email: contact@glyf.pro