Privacy Policy
Last updated: September 2, 2026
Glasser ("Glasser," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how personal information is collected, used, and disclosed when you use Glasser.
This Privacy Policy applies to the website at glasser.ai and its subdomains, the Glasser console at app.glasser.ai, the Glasser API at api.glasser.ai (including the MCP endpoint), the Glasser command-line tool, and the Glasser agent skill (collectively, the "Service"). By accessing or using the Service, you signify that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described in this Privacy Policy and our Terms of Service.
Definitions and key terms
- Company: when this policy mentions "Company," "we," "us," or "our," it refers to Super Intent, Inc. (2261 Market Street STE 46208, San Francisco, CA 94114, US), the entity responsible for your information under this Privacy Policy. Glasser is a product of Super Intent, Inc.
- Customer or You: the person or entity that registers a Glasser account or Workspace, or that uses a Glasser Key, including any Agent acting on that person's or entity's behalf.
- Workspace: the billing and access unit of the Service. A Workspace holds a prepaid balance and one or more Keys.
- Key: an API credential issued by Glasser (prefixed
gl_) that authenticates requests to the Service and binds them to a Workspace. - Agent: any automated software (for example an AI coding assistant, an LLM-based agent, or a script) that you configure to call the Service using your Key.
- Provider: a third-party API vendor whose endpoints are offered through the Glasser catalog. As of the date above, Providers include People Data Labs, Serper, and DataForSEO. The current list is shown in the catalog.
- Endpoint: a runnable third-party API operation listed in the Glasser catalog.
- Run: a single execution of an Endpoint through the Service, including the input you send, the output the Provider returns, its status, and its charge.
- Run Data: the inputs, outputs, and metadata of a Run.
- Third-Party Personal Data: personal data about people other than you that you submit in a Run input (for example, an email address you ask to enrich) or that a Provider returns in a Run output (for example, a person's name, employer, or contact details).
- Personal Data: any information that directly, indirectly, or in connection with other information allows for the identification of a natural person.
- Cookie: a small amount of data generated by a website and saved by your web browser, used to identify your browser, provide analytics, or remember information such as your login state.
- Device: any internet-connected device used to access the Service.
- IP address: a number assigned to every device connected to the Internet, which can often be used to identify the approximate location from which a device is connecting.
- Personnel: individuals employed by the Company or under contract to perform a service on the Company's behalf.
- Country: the country where the Company is based, which is the United States.
- Website: glasser.ai.
What information do we collect?
We collect information from you when you visit our website, create an account or Workspace, authorize a device or Agent, add funds to a Workspace balance, run an Endpoint, or contact support.
Information you provide
- Name and username
- Email address
- Login identity from a third-party sign-in provider you choose (for example GitHub or Google), limited to the identifiers that provider shares with us
- Billing name, billing address, and tax information
- Payment details, which are collected and stored by our payment processor, Stripe, Inc. ("Stripe"), and not by us; we receive only a payment token, the card brand, the last four digits, and the billing details Stripe shares with us
- Workspace name and settings
- Support requests and any information you include in them
Information generated by your use of the Service
- Keys and device authorizations: the Keys we issue to you, the devices and Agents you authorize through the device-authorization flow, and when they were created, used, or revoked.
- Run Data: for every Run, the Endpoint called, the input you submitted, the output the Provider returned, timestamps, status (queued, running, completed, failed, stopped), the idempotency key, the price rule and charge clause applied, and the resulting charge.
- Balance and transaction records: top-ups, promotional credits, charges, adjustments, and refunds.
- Catalog activity: searches and inspections you perform in the catalog.
- Technical logs: request identifiers, API and CLI version, error messages, and diagnostic information needed to operate and secure the Service.
The Glasser CLI and agent skill send us the information needed to authenticate you and execute the commands you run, together with the CLI version and error diagnostics.
Automatic device and usage information
We and our service providers may automatically collect information about your Device and your interaction with the Service, such as operating system, browser type and version, screen resolution, language settings, timezone, IP address and approximate location, unique identifiers, the user agent of the CLI or Agent making requests, and usage data such as pages viewed and access times.
Third-Party Personal Data
The Service exists to let you (or your Agent) send inputs to Providers and receive outputs back. Those inputs and outputs frequently contain Third-Party Personal Data. We process Third-Party Personal Data only to route your Run to the Provider, return the result to you, record the Run, bill you for it, and protect the Service from abuse. See "Your responsibilities for Third-Party Personal Data" below.
How do we use the information we collect?
Any of the information we collect from you may be used in the following ways:
- To create and administer your account, Workspace, and Keys
- To authenticate requests from you and your Agents
- To route your Runs to the relevant Provider and return the results
- To calculate, display, and charge the price of each Run, maintain your balance, and process top-ups and refunds
- To provide the run history, balance history, and other records you can retrieve through the console, CLI, or API
- To respond to support requests and disputes about charges
- To prevent, detect, and investigate fraud, abuse, unauthorized use of Keys, and violations of our Terms of Service or a Provider's terms
- To monitor the reliability, latency, and error rates of Endpoints and Providers
- To improve the Service, including the catalog, documentation, and agent skill
- To send service, security, and billing notices
- To send periodic product emails, from which you can unsubscribe at any time
- To comply with legal obligations
We do not use the content of your Run inputs or outputs to train machine-learning models, and we do not sell Run Data.
Providers and third-party data sharing
Glasser is a broker. When you run an Endpoint, we send the input you provide to the Provider that operates that Endpoint, and the Provider returns the output to us, which we return to you. This is the core function of the Service and happens for every Run.
What data is sent to a Provider
- The input you (or your Agent) submit for that Run, exactly as needed to execute the Endpoint. This may include Third-Party Personal Data.
- Technical metadata required for reliability and security, such as request identifiers and timestamps.
We do not send your account name, email address, payment details, or Workspace identifiers to Providers. Providers see Glasser as the caller; they do not see which Glasser Customer made the request.
Why this data is sent
- To execute the Run you requested and return the Provider's result to you.
- To let the Provider enforce its own rate limits and abuse controls.
Provider terms and privacy practices
Each Provider processes the data it receives under its own terms and privacy policy, which are available on the Provider's website. By running an Endpoint, you agree that the relevant Provider may process the input under those terms. Providers may retain query logs for their own operational and legal purposes; we do not control that retention.
Protection standard
We require Providers with whom we have a wholesale relationship to maintain appropriate contractual, technical, and organizational safeguards for the data we send them. Where we act as your processor for Third-Party Personal Data, we will enter into a data processing agreement on request; contact us at support@glasser.ai.
Your responsibilities for Third-Party Personal Data
You decide what inputs to send and what to do with the outputs. For Third-Party Personal Data contained in Run Data, you are the data controller (or "business" under the CCPA) and Glasser acts as your processor (or "service provider") for the limited purposes described above. You are responsible for:
- Having a lawful basis to submit the input and to receive, store, and use the output under the laws that apply to you, including the GDPR, the UK GDPR, the CCPA/CPRA, and applicable anti-spam and telemarketing laws;
- Honoring rights requests from the individuals concerned, such as access, correction, deletion, and objection, for the data you hold;
- Complying with each Provider's terms on permitted uses of its data, including restrictions on resale and on use for eligibility decisions regulated by the Fair Credit Reporting Act or similar laws.
If an individual contacts us about data that you obtained through the Service, we will refer them to you where we can identify you, and we may delete the relevant Run Data from our systems.
Do we share the information we collect with other third parties?
Beyond Providers, we may share information with:
- Service providers that perform functions on our behalf, such as cloud hosting, database storage, email delivery, payment processing (Stripe), fraud detection, analytics, and customer support. These providers may access personal information only to perform those services for us and are required to protect it.
- Corporate Affiliates, meaning any entity that directly or indirectly controls, is controlled by, or is under common control with the Company. Information shared with Corporate Affiliates is treated in accordance with this Privacy Policy.
- Successors in the event of a merger, acquisition, asset sale, or other business reorganization, or in the event that we discontinue our business or enter bankruptcy or a similar proceeding, provided that the recipient agrees to adhere to this Privacy Policy.
- Government, law enforcement, or private parties as we, in our sole discretion, believe necessary or appropriate to respond to claims or legal process (including subpoenas), to protect our rights or the rights of a third party, to protect the safety of the public or any person, to prevent or stop illegal, unethical, or legally actionable activity, or to comply with applicable court orders, laws, rules, and regulations.
Sub-processors
The following third parties process personal data on our behalf in connection with the Service. All are located in the United States unless stated otherwise.
| Sub-processor | Purpose | Data |
|---|---|---|
| Stripe, Inc. | Payment processing, invoicing, tax calculation | Billing name and address, payment method, transaction records |
| Cloudflare, Inc. | Network security, DNS, content delivery | IP address, request metadata |
| People Data Labs, Serper, DataForSEO (Providers) | Executing the Endpoints you run | Run inputs, as described under "Providers and third-party data sharing" |
We also use hosting, database, email-delivery, and product-analytics providers that process data only on our instructions. Before we add a sub-processor that materially processes Customer data, we will update this Privacy Policy and give notice through the Service or by email. Connecting to or running a Provider's Endpoint is your instruction and authorization to transmit the relevant Inputs to that Provider.
We may share aggregated or de-identified usage statistics, such as the number of Runs per Endpoint or category, publicly or with partners. Such statistics do not identify you or any individual contained in Run Data.
We do not share your personal information with advertisers, and we do not sell personal information.
How do we use your email address?
By providing your email address, you agree to receive service, security, and billing emails from us, such as device-authorization confirmations, low-balance notices, receipts, and notices of changes to the Service or these policies. You may also receive product and marketing emails, which you can stop at any time by using the unsubscribe link in the email or by contacting us. We only send marketing emails to people who have authorized us to contact them, and we do not send unsolicited commercial email. We may use your email address for customer audience targeting on advertising platforms where permitted; you can opt out by contacting us.
How long do we keep your information?
We keep your information only as long as we need it to provide the Service to you and to fulfill the purposes described in this policy, and afterwards only as required for our legal, tax, accounting, and dispute-resolution obligations.
- Account and Workspace information: for the life of your account, then for up to 60 days after deletion, except as retained in backups or as required by law.
- Balance and transaction records: for the period required by tax and accounting law, typically up to seven years.
- Run Data: Run inputs and outputs are retained for 90 days to support run history, dispute resolution, and abuse prevention, after which the input and output bodies are deleted or de-identified. Run metadata (Endpoint, timestamps, status, charge) is retained with your transaction records. You may request earlier deletion of Run inputs and outputs by contacting us.
- Technical logs: typically 30 to 90 days.
When we no longer need information and have no legal obligation to keep it, we delete it or de-personalize it so that we can no longer identify you.
How do we protect your information?
We implement administrative, technical, and physical safeguards to protect the information we hold. All traffic to the Service is encrypted in transit using TLS. Keys are shown to you once at creation and stored by us only in hashed form. Device authorization uses a short-lived code that you approve in your browser so that your Agent never handles your login credentials. Payment card details are handled by Stripe and are never stored on our servers. Access to production systems is restricted to authorized Personnel who are bound by confidentiality obligations.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If applicable law imposes any non-disclaimable duty to protect your personal information, you agree that intentional misconduct will be the standard used to measure our compliance with that duty. If we become aware of a breach of security affecting your personal data, we will notify affected Customers and any regulator we are required to notify without undue delay. You are responsible for keeping your Keys confidential, for revoking Keys that may have been exposed, and for the actions of any Agent you authorize.
Could my information be transferred to other countries?
The Company is incorporated in the United States, and the Service is hosted there. Providers and service providers may be located in other countries. Information collected through the Service may therefore be transferred to, stored in, and processed in the United States and other countries that may not have data-protection laws equivalent to those of your country. Where required, we rely on appropriate transfer mechanisms such as the European Commission's standard contractual clauses and the UK International Data Transfer Addendum. To the fullest extent allowed by applicable law, by using the Service you consent to this transfer and hosting.
Can I access, update, correct, or delete my information?
You can view and update most account and Workspace information, and view your run history and balance history, in the console or through the CLI and API. You can revoke Keys and device authorizations at any time.
You may also contact us to (1) access or correct the personal information we hold about you, (2) change your communication preferences, or (3) delete your account and the personal information we maintain about you. To protect your privacy and security, we may take reasonable steps to verify your identity before acting on a request. Deletion will not affect information we have already provided to Providers or other third parties in accordance with this Privacy Policy, information we are required to retain by law, or copies that persist in backups for a limited period.
If you are an individual whose data was obtained by a Customer through the Service, please contact that Customer. You may also contact us, and we will assist as described above.
Personnel
If you are a Company worker or applicant, we collect information you voluntarily provide to us and use it for human-resources purposes, including administering benefits and screening applicants. You may contact us to update or correct your information, change your communication preferences, or receive a record of the information we hold about you.
Sale of business
We reserve the right to transfer information to a third party in the event of a sale, merger, or other transfer of all or substantially all of the assets of the Company or any of its Corporate Affiliates, or of the portion of the business to which the Service relates, or in the event that we discontinue our business or enter bankruptcy, reorganization, or a similar proceeding, provided that the third party agrees to adhere to the terms of this Privacy Policy.
Governing law
This Privacy Policy is governed by the laws of the State of California and the United States, without regard to conflict-of-laws provisions. You consent to the exclusive jurisdiction of the courts located in California in connection with any action or dispute arising under or in connection with this Privacy Policy, except where the dispute-resolution provisions of our Terms of Service apply or where you have non-waivable rights under the law of your place of residence.
By using the Service or contacting us directly, you signify your acceptance of this Privacy Policy. If you do not agree to this Privacy Policy, you should not use the Service. Continued use of the Service following the posting of changes to this Privacy Policy that do not significantly affect the use or disclosure of your personal information will mean that you accept those changes.
Your consent
By using the Service, registering an account, adding funds to a Workspace, or running an Endpoint, you consent to this Privacy Policy and agree to its terms, including the transfer of Run inputs to Providers as described above.
Links to other websites
This Privacy Policy applies only to the Service. The Service may contain links to other websites, including Provider websites and documentation, that are not operated or controlled by us. We are not responsible for the content, accuracy, or privacy practices of such websites. Your browsing and interaction on any other website is subject to that website's own rules and policies.
Cookies and similar technologies
We use cookies, local storage, and session identifiers on glasser.ai and app.glasser.ai to keep you signed in, remember your preferences, protect against cross-site request forgery, and understand how the website is used. Essential cookies are required for the console to function; analytics cookies are non-essential. We do not place personal information in cookies.
You can set your browser to block cookies and similar technologies, but this may block essential cookies and prevent the console from functioning properly. Disabling a cookie does not delete it from your browser; you will need to do that yourself through your browser settings.
The API, CLI, and MCP endpoint do not use cookies; they authenticate with your Key.
Payment details
Payment card and other payment details are collected and stored by Stripe under its own security standards, including PCI DSS, and are subject to Stripe's privacy policy at https://stripe.com/privacy. We do not store full card numbers. We retain transaction records as described under "How long do we keep your information?"
Children's privacy
The Service is not directed to anyone under the age of 18, and we do not knowingly collect personal information from anyone under the age of 13. If you are a parent or guardian and believe your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from a child under 13 without verification of parental consent, we will take steps to remove that information from our servers.
Changes to this Privacy Policy
We may change the Service and our policies, and we may need to update this Privacy Policy so that it accurately reflects them. Unless otherwise required by law, we will notify you (for example, through the Service or by email) before material changes take effect and give you an opportunity to review them. If you continue to use the Service after the changes take effect, you will be bound by the updated Privacy Policy. If you do not agree, you can delete your account.
Third-party services
The Service makes available third-party content and data, including Provider Endpoints and the data they return ("Third-Party Services"). You acknowledge and agree that the Company is not responsible for Third-Party Services, including their accuracy, completeness, timeliness, validity, copyright compliance, legality, or quality. Third-Party Services are provided subject to the relevant third party's terms and conditions, and you access and use them at your own risk.
Tracking technologies
Cookies
We use cookies to enhance the performance and functionality of the console. Without these cookies, you would be required to enter your login details every time you visit.
Local storage
Local storage provides web applications with methods for storing client-side data, similar to cookies but with greater capacity and without information being sent in HTTP request headers. We use it to remember console preferences.
Sessions
We use sessions to identify the areas of the console you have visited and to keep you signed in.
Information about the General Data Protection Regulation (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, this section explains how we handle your data under the GDPR and equivalent laws. We have implemented GDPR controls as our baseline standard for all our operations worldwide.
Our roles
- For your account, Workspace, billing, and usage information, we are the controller.
- For Third-Party Personal Data contained in Run Data, you are the controller and we are your processor, acting only on your instructions as expressed through your Runs and these policies. Providers act as independent controllers or licensors of the data they return.
Lawful bases
We process your account and usage information to perform our contract with you (providing the Service and billing you), to comply with legal obligations (tax, accounting, and law-enforcement requests), and for our legitimate interests (securing the Service, preventing fraud and abuse, and improving the Service). We send marketing emails on the basis of your consent, which you can withdraw at any time.
Your rights
You have the right to access your personal data, to receive a copy of it in a portable format, and to have it corrected, deleted, or restricted, and to object to certain processing. You also have the right to lodge a complaint with your local supervisory authority. To exercise these rights, contact us at support@glasser.ai. We will respond within one month.
Retention and deletion
We retain personal data as described under "How long do we keep your information?" When you delete your account, we dispose of your personal data in accordance with our Terms of Service and this Privacy Policy and will not hold it longer than 60 days, except as required by law or as retained in backups for a limited period.
Data processing agreement
If you use the Service to process Third-Party Personal Data of individuals in the EEA, the UK, or Switzerland, you may request our data processing agreement, which includes the standard contractual clauses and the UK Addendum where applicable, by contacting support@glasser.ai.
California residents
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"), requires us to disclose the categories of Personal Information we collect and how we use it, the categories of sources from which we collect it, and the third parties with whom we share it, which we have explained above.
California residents may exercise the following rights:
- Right to know and access. You may submit a verifiable request for information regarding (1) the categories of Personal Information we collect, use, or share; (2) the purposes for which those categories are collected or used; (3) the categories of sources from which we collect Personal Information; and (4) the specific pieces of Personal Information we have collected about you.
- Right to correct. You may request that we correct inaccurate Personal Information.
- Right to delete. You may submit a verifiable request to close your account and delete the Personal Information we have collected about you, subject to legal retention requirements.
- Right to opt out of sale or sharing. We do not sell Personal Information, and we do not share it for cross-context behavioral advertising.
- Right to limit use of sensitive personal information. We use sensitive personal information only for the purposes permitted by the CCPA.
- Right to equal service. We will not discriminate against you for exercising your privacy rights.
If you make a request, we will respond within the time required by law. To exercise these rights, contact us at support@glasser.ai. You may designate an authorized agent to make a request on your behalf.
California Online Privacy Protection Act (CalOPPA)
CalOPPA requires us to disclose the categories of Personal Information we collect and how we use it, the categories of sources from which we collect it, and the third parties with whom we share it, which we have explained above. We do not respond to "Do Not Track" browser signals because there is no industry standard for them; however, we honor Global Privacy Control signals where required by law. We do not sell the Personal Information of our users.
Contact us
If you have any questions about this Privacy Policy, your data, or a Provider's handling of data you sent through the Service, contact us:
Email: support@glasser.ai
Mail: Super Intent, Inc., 2261 Market Street STE 46208, San Francisco, California 94114, United States