Privacy Policy
Glossikon is built and operated by one person, Ashley Lewis, not a company. There's no data-broker relationship, no ad network, and nothing here is sold. If you just want the short version: I collect your email address to know which languages are yours, the language data you create, and whatever you send me through a payment or feedback form. Questions or deletion requests go to [email protected].
Account & identity
Glossikon has no password of its own. Signing in on the web happens through Cloudflare Access (OAuth or an emailed PIN), which hands the app your verified email address — that's the only account field Glossikon stores. The Android app can't run that login flow itself, so after one interactive sign-in the server issues it a signed token containing that same email, valid for 90 days, so the app can stay signed in.
If you connect an AI agent (for example Claude, via Glossikon's MCP server) to your account, that connection is authorized the same way — an OAuth grant or a bearer token tied to your email — and gives that agent the same access to your languages you have.
What I collect
- Email address — your account identity, from Cloudflare Access.
- The languages you create — phonology, script, morphology, syntax, lexicon, and example sentences. This is linguistic content, not personal data about you, but it's yours and it's tied to your account.
- Billing records — if you buy tokens or lifetime access, Stripe or Google Play/RevenueCat tells the server your email, what you bought, and a transaction ID. Glossikon's server never sees or stores your card number — Stripe and Google Play handle payment details directly.
- Feedback you send — bug reports, suggestions, or a note to another user about a language they've shared. General feedback lets you leave an email optionally; feedback sent to a language's owner is tied to your account email so they can reply.
- URLs you paste for cloud import — if you use the "import from Google Drive/Dropbox/OneDrive link" feature, the server fetches that URL once to pull in the text. Only public, "anyone with the link" documents work — there's no account linking to those services.
- Ordinary web traffic — like any web server, requests to Glossikon pass through standard connection logging (IP address, timestamp, request path) as a normal part of running the service. This isn't used for tracking or profiling.
Glossikon does not run any analytics, advertising, or crash-reporting SDK, and doesn't request camera, microphone, location, or contacts access on Android.
The public gallery
Languages you create are private by default. If you choose to publish one to the gallery, its name, your email as the credited owner, and its full content (phonology, lexicon, example sentences, everything) become visible to anyone who opens that gallery page — including people who aren't signed in. Anyone can fork a published language into their own account. Sharing a language with specific people by email (rather than the public gallery) makes it visible only to those recipients. Don't publish or share anything you'd rather keep private.
How I use this
To run the app: authenticate you, store and serve your languages, process payments, and let AI-assisted features (translation, filling lexical gaps) work on the language you're editing. Feedback is used to fix bugs and prioritize features. Nothing here is used to build an advertising profile, because there isn't one.
AI processing
Text you submit for translation or lexical-gap filling is sent to a language model to generate a response. Today that model runs on infrastructure I operate directly, not a third-party AI cloud API. The server code also supports routing that processing through Anthropic's Claude API instead, and may do so in the future if that becomes the better option — if that switch happens, this policy will be updated to say so plainly.
Third-party services
These process data on Glossikon's behalf, each governed by its own privacy policy:
- Cloudflare — sits in front of the web app for authentication and network security, and sees all traffic to it. See Cloudflare's privacy policy.
- Stripe — processes web/desktop payments; handles your card details directly. See Stripe's privacy policy.
- RevenueCat & Google Play Billing — process Android in-app purchases. See RevenueCat's and Google Play's own privacy policies.
If you connect a third-party AI agent (like Claude.ai) to Glossikon via MCP, whatever that agent does with the data it fetches is governed by that provider's own privacy policy, not this one.
Where your data lives
Glossikon's database runs on infrastructure I operate directly, not a third-party cloud database provider. Traffic to the app is routed through Cloudflare, which terminates TLS in front of it.
Cookies
The only cookie Glossikon's web app sets is Cloudflare Access's authentication cookie, which keeps you signed in. There's no advertising or analytics cookie, and no cross-site tracking.
Data retention & deletion
You can delete an individual language yourself at any time from within the app, which removes it, its version history, and any shares or grants attached to it.
You can also delete your entire account yourself, from the language-select screen ("Delete account"). This immediately and permanently removes every language you own, your billing history, and any AI/MCP access or shares tied to your email — there's no recovery period, so it can't be undone once confirmed. If you'd rather have it done for you, or run into trouble, email [email protected] and I'll delete it by hand. Records required for tax/accounting purposes (e.g. that a payment occurred) may be kept as long as the law requires, separate from anything identifying you inside the app.
Children's privacy
Glossikon isn't directed at children and doesn't knowingly collect information from anyone under 13. There's no age-verification step, so if you believe a child has created an account, email [email protected] and it will be removed.
Your rights
Wherever you are, you can delete your account yourself as described above, or email [email protected] to ask what's stored under your email, correct it, or have it deleted for you. There's no automated export tool at the moment; export requests are handled by hand.
Changes to this policy
If what Glossikon collects or how it's used changes materially, this page will be updated and the effective date above will change.
Contact
Ashley Lewis — [email protected]