GlassBeadGuide

Privacy Policy

Last updated: 27 February 2026

GlassBeadGuide (“we”, “us”, “our”) is committed to protecting your personal data. This policy explains what we collect, on what legal basis, how long we keep it, and what rights you have under the General Data Protection Regulation (GDPR) and applicable national law.

Data controller: GlassBeadGuide — privacy@glassbeadguide.com

GlassBeadGuide is a philosophical reflection tool, not a therapy service or medical device. It is not a substitute for professional mental health support.


1. Data we collect and why

Account data

Reflection content

Legal basis: performance of a contract — this is the core functionality of the service.

Letters to Future Self

Legal basis: performance of a contract (you explicitly requested the delivery).

Push notifications

If you enable daily notifications, your browser's push subscription token is stored to send your daily thought. Legal basis: consent (Art. 6(1)(a) GDPR). You can withdraw consent at any time in your Profile.

Analytics

We use PostHog (EU cloud, Frankfurt) to understand aggregate usage — for example, how many people complete a reflection. Analytics are enabled only after you accept cookies via the consent banner. Legal basis: consent (Art. 6(1)(a) GDPR).

PostHog is configured with IP anonymisation. No personal text from your reflections is sent to PostHog. We do not use analytics for advertising and do not sell data.

Server logs

Vercel automatically records standard server logs (IP address, request path, timestamp, response code) for security and operational purposes. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). Retained for 30 days.


2. Sub-processors

We share your data only with the processors listed below. Each operates under a Data Processing Agreement (DPA) and, where applicable, Standard Contractual Clauses (SCCs) for transfers outside the EEA.

ProcessorRoleLocationTransfer basis
SupabaseAuthentication and database hostingEU (Frankfurt)SCCs + DPA — EU region, no transfer outside EEA
AnthropicAI language model (Claude) — processes your reflection textUnited StatesSCCs + DPA
VercelApplication hosting, serverless functions, cron jobsEU edge + US originSCCs + DPA
ResendTransactional email (Letters to Future Self delivery)United StatesSCCs + DPA
PostHogProduct analytics — only if you accept cookiesEU (Frankfurt)EU cloud — no transfer outside EEA

We never sell your data or share it with any party not listed above.


3. AI processing and your content

Your reflection text is sent to Anthropic's API (Claude) to generate philosophical responses. Anthropic acts as a data processor under our DPA. Under our agreement, Anthropic does not use your content to train their models.

We do not use your reflection content to train any AI model ourselves.

Please avoid including sensitive personal data about other people (e.g. full names, contact details, health information of third parties) in your reflections.


4. How long we keep your data


5. Your rights

Under GDPR you have the following rights. To exercise any of them, email privacy@glassbeadguide.com. We will respond within 30 days (extendable to 90 days for complex requests — we will notify you within the first 30).


6. Cookies and local storage

No advertising, tracking, or third-party marketing cookies are used.


7. Security

All data is transmitted over HTTPS. Our database uses row-level security so each user can only access their own data. Access to production infrastructure is restricted to authorised personnel.

No system is entirely secure. If you discover a security issue, please report it to privacy@glassbeadguide.com.


8. Children

GlassBeadGuide is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe we have done so inadvertently, please contact us and we will delete it promptly.


9. Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date at the top. For material changes we will notify you by email or via a notice in the app at least 14 days before the change takes effect.


10. Contact

For any privacy-related question or to exercise your rights: privacy@glassbeadguide.com