Introduction
This Privacy Policy describes how Glaium collects, uses and discloses information, and what choices you have with respect to the information. Updates in this version of the Privacy Policy reflect changes in data protection law. In addition, we have worked to make the Privacy Policy clearer and more understandable.
When we refer to "Glaium", we mean the Glaium Inc. entity that acts as the controller or processor of your information, as explained in more detail in the "Identifying the Data Controller and Processor" section below.
Applicability Of This Privacy Policy
This Privacy Policy applies to Glaium's data infrastructure platform, MCP and API endpoints, and tools (collectively, the "Services"), glaium.io and other Glaium websites (collectively, the "Websites") and other interactions (e.g., customer service inquiries, user conferences, etc.) you may have with Glaium. If you do not agree with the terms, do not access or use the Services, Websites or any other aspect of Glaium's business.
This Privacy Policy does not apply to any third party applications or software that integrate with the Services through the Glaium platform ("Third Party Services"), or any other third party products, services or businesses. In addition, a separate agreement governs delivery, access and use of the Services (the "Customer Agreement"), including the processing of any messages, files or other content submitted through Services accounts (collectively, "Customer Data"). The organization (e.g., your employer or another entity or person) that entered into the Customer Agreement ("Customer") controls their instance of the Services (their "Account") and any associated Customer Data.
Information We Collect And Receive
Glaium may collect and receive Customer Data and other information and data ("Other Information") in a variety of ways:
Generally, no one is under a statutory or contractual obligation to provide any Customer Data or Other Information (collectively, "Information"). However, certain Information is collected automatically and, if some Information, such as Glaium setup details, is not provided, we may be unable to provide the Services.
Categories of data we process for customers
To provide the Services, Glaium collects and receives data from the sources our customers connect — including app stores, ad networks, mobile measurement partners (MMPs), analytics providers, backends, and data warehouses. Depending on the customer's configuration, this may include event and usage data, in-app purchase and subscription transactions, ad spend and ad revenue, install and attribution data, and device or advertising identifiers (such as Apple's IDFA and the Google Advertising ID). Where this data relates to an identifiable individual, it constitutes Personal Data and is processed on behalf of, and under the instructions of, the customer acting as controller.
Glaium normalizes, reconciles and structures this data and makes it available to the customer through reports, an API and an MCP endpoint. Data may be anonymized or aggregated according to the customer's policy before it is delivered for analysis, including analysis by the customer's own AI models and agents. Glaium does not use Customer Data to build advertising profiles of individuals and does not sell Customer Data.
Google Data
Collect: We may collect, or process on behalf of our customers, the following categories of data when you use or interact with our products and services: business performance reports.
Usage: We will use your data solely to provide the requested services and ensure proper functionality of our application.
Share, transfer or disclose: We do not transfer or disclose your information to third parties for purposes other than the ones provided.
Limited Usage Policy: Glaium's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How We Use Information
Customer Data will be used by Glaium in accordance with Customer's instructions, including any applicable terms in the Customer Agreement and Customer's use of Services functionality, and as required by applicable law. Glaium is a processor of Customer Data and Customer is the controller. Customer may, for example, use the Services to grant and remove access to an Account, assign roles and configure settings, access, modify, export, share and remove Customer Data and otherwise apply its policies to the Services.
Data Retention
Glaium will retain Customer Data in accordance with a Customer's instructions, including any applicable terms in the Customer Agreement and Customer's use of Services functionality, and as required by applicable law. Depending on the Services plan, Customer may be able to customize its retention settings and apply those customized settings at the Account level. Glaium may retain Other Information pertaining to you for as long as necessary for the purposes described in this Privacy Policy. This may include keeping your Other Information after you have deactivated your account for the period of time needed for Glaium to comply with (and demonstrate compliance with) legal obligations, resolve disputes and enforce our agreements.
How We Share And Disclose Information
This section describes how Glaium may share and disclose Information. Customers determine their own policies and practices for the sharing and disclosure of Information, and Glaium does not control how they or any other third parties choose to share or disclose Information.
Security
Glaium takes security of data very seriously. Glaium works hard to protect Other Information you provide from loss, misuse, and unauthorized access or disclosure. These steps take into account the sensitivity of the Other Information we collect, process and store, and the current state of technology. Given the nature of communications and information processing technology, Glaium cannot guarantee that Information, during transmission through the Internet or while stored on our systems or otherwise in our care, will be absolutely safe from intrusion by others.
Age Limitations and Children's Data
To the extent prohibited by applicable law, Glaium does not allow use of our Services and Websites by anyone younger than 16 years old. If you learn that anyone younger than 16 has unlawfully provided us with personal data, please contact us and we will take steps to delete such information.
The Services are intended for use by businesses and are not directed to children. Where a customer's apps or games are directed to, or knowingly used by, children, the customer is responsible for complying with applicable children's privacy laws — including the U.S. Children's Online Privacy Protection Act (COPPA), which applies to children under 13, and the equivalent GDPR protections for children under 16 — and for obtaining any parental or guardian consent those laws require. Customers must not send Glaium the personal data of children through the Services unless they have a valid legal basis and the required consents in place, and should configure the Services to exclude or anonymize such data where appropriate.
Changes To This Privacy Policy
Glaium may change this Privacy Policy from time to time. Laws, regulations and industry standards evolve, which may make those changes necessary, or we may make changes to our business. We will post the changes to this page and encourage you to review our Privacy Policy to stay informed. If we make changes that materially alter your privacy rights, Glaium will provide additional notice, such as via email or through the Services. If you disagree with the changes to this Privacy Policy, you should deactivate your Services account. Contact the Customer if you wish to request the removal of Personal Data under their control.
International Data Transfers
Glaium may transfer your Personal Data to countries other than the one in which you live. For additional information about Data Transfers please contact Glaium's privacy team at legal@glaium.io.
Privacy Contact
For any privacy-related questions, or to exercise your rights under this Privacy Policy, please email our privacy team at legal@glaium.io.
Identifying The Data Controller And Processor
Data protection law in certain jurisdictions differentiates between the "controller" and "processor" of information. In general, Customer is the controller of Customer Data. In general, Glaium is the processor of Customer Data and the controller of Other Information. Different Glaium entities provide the Services in different parts of the world. Glaium Inc., a US company based in Delaware, is the controller of Other Information and a processor of Customer Data relating to Authorized Users who have Accounts for Glaium Services.
Your Rights
Individuals located in certain countries, including the European Economic Area, have certain statutory rights in relation to their personal data. Subject to any exemptions provided by law, you may have the right to request access to Information, as well as to seek to update, delete or correct this Information. You can usually do this using the settings and tools provided in your Services account. If you cannot use the settings and tools, contact Customer Service for additional access and assistance.
To the extent that Glaium's processing of your Personal Data is subject to the General Data Protection Regulation, Glaium relies on its legitimate interests, described above, to process your data. Glaium may also process Other Information that constitutes your Personal Data for direct marketing purposes and you have a right to object to Glaium's use of your Personal Data for this purpose at any time.
Data Protection Authority
Subject to applicable law, you also have the right to (i) restrict Glaium's use of Other Information that constitutes your Personal Data and (ii) lodge a complaint with your local data protection authority. If you are a resident of the European Economic Area and believe we maintain your Personal Data within the scope of the General Data Protection Regulation (GDPR), you may direct questions or complaints to your local data protection authority. See our GDPR details here.
US State Privacy Rights
If you are a resident of California or another U.S. state with a comprehensive consumer privacy law (such as the CCPA/CPRA), you may have the right to know what personal information we hold about you, to request access or deletion, to correct inaccuracies, and to opt out of the "sale" or "sharing" of personal information and of targeted advertising. Glaium does not sell personal information for money. Because Glaium generally processes personal information as a service provider or processor on behalf of its customers, requests to exercise these rights are usually directed to the customer that controls the relevant data. Where Glaium is the controller of Other Information, you may contact us at legal@glaium.io and we will respond as required by applicable law. We will not discriminate against you for exercising these rights.
Contacting Glaium
Please also feel free to contact Glaium if you have any questions about this Privacy Policy or Glaium's practices, or if you are seeking to exercise any of your statutory rights. You may contact us at legal@glaium.io.