Questions
The awkward ones first, answered with the limit rather than the pitch. If you are about to type something about your manager into a product owned by your employer, the second section is the one to read.
What it actually does
- What is Glass Box for?
- Teams stop saying things because saying them costs something. Glass Box takes what somebody actually wants to say, removes who said it and the heat around it, and hands a leader the substance on its own — so there is nothing left to dismiss except the problem. Then it counts whether anything was done.
- Is this AI?
- No, and not in a hedging way. The rewriting is eight passes of hand-written rules — patterns and word lists. There is no model anywhere in the product, nothing is sent to a third party, and the same input always produces the same output. You can read what changed, every time.
The part that matters — who can see what
- Can my manager see who wrote something?
- No. What a leader reads is the rewritten version, with names, pronouns and details that would identify you taken out. Those screens never load the original or the author reference — that is enforced by the database queries rather than by hiding something in the interface.
On top of that, a topic is not shown to a leader at all until three different people have raised something under it. It counts people, not messages, so three posts from one frustrated person cannot open a topic that points at them. - So is it completely anonymous?
- No, and anybody telling you otherwise is selling something. Here is the exact shape of it.
What is true: nobody in your organization — not your manager, not whoever administers the account — is ever shown the original of a message.
What is also true: the original, with whatever names you typed, is stored alongside a reference to your account, so that you can read back what you actually sent. It is encrypted, so a stolen copy of the database does not open it. But whoever operates the service could technically read it, and it could be compelled by a lawful order.
The privacy notice sets this out in full, under “The limits of anonymity”. It is the section worth reading before you type anything you would regret. - Why keep the original at all?
- So you can check it. Every rewrite is shown to you before it is sent, and the before-and-after of every change is kept and included in your own data export — you can always see exactly what was taken out of your words. A rewriter you cannot audit is one you have to take on faith, and this product is not asking for faith.
- Can I put my name on something?
- Yes, and it is a choice on every message. What the rewriter protects against is blame, not people knowing who is speaking — it takes the person being talked about out of the sentence whether or not you sign it. Saying “here is how this landed for me” is frequently the only way a leader can actually come and talk to you.
Your data
- What happens if I take a message back?
- You can withdraw a message within fifteen minutes. It immediately stops being visible to anybody, including you, and it stops counting toward the three-voice gate — a withdrawn message cannot hold a topic open. The row survives only until the week it belongs to has been closed off in a report, so the numbers somebody already read stay true, and then it is deleted.
- Can I get my data out, or delete it?
- Yes to both, immediately, without asking anybody. Sign in and open Your data in the account menu. The export includes the originals of your own messages, because they are yours and they are the part you most need to see in order to judge whether you trust this.
- How long is anything kept?
- Every kind of record has a stated period, and they are enforced by a job rather than by intention — the periods live in the code, and a test checks them against what the privacy notice publishes, so the document and the system cannot quietly disagree.
- Do you use what we write for anything else?
- No. No analytics, no advertising pixels, no third-party trackers, no profiling, and nothing is used to train anything. There is no external script in the product at all — the content security policy has nowhere to send data even if something tried.
Getting started
- How do I set it up?
- Create an organization, invite the people on your team, and then leave it alone — topics are not configured in advance, they are created by whoever first raises something. Once you are signed in, the help page walks through inviting people, placing them on teams, and how a week runs.
- What does it cost?
- Per person, per month, and the rate falls as the organization grows. The pricing page shows the tiers and what it costs us to run, which is unusual to publish and is there so the number is explicable rather than just asserted.
- What is not built yet?
- Quite a lot, and it is all listed on the security page rather than left to be discovered — no single sign-on, no SOC 2 report, no independent penetration test yet, and the service runs as one instance without automatic failover. A security team will find those anyway, and would rather read them here.
Something not answered here
Write to [email protected]. If it is about what happens to data, the privacy notice is more precise than this page and is written to be read rather than to be agreed to.

