Last updated 29 August 2026
Privacy notice
Glass Box carries things people are reluctant to say at work, so this document is specific about what is stored, what is shown to whom, and what is genuinely not visible. Where a protection has a limit, the limit is stated rather than left to be discovered.
Draft, pending legal review. This describes what Glass Box actually does, written from the code rather than from a template — which is the part a lawyer cannot do for you. Some of the wording is the market-standard answer, included so a review starts from a position rather than a gap. None of it has been read by a lawyer, and it is not legal advice.
Who we are
Glass Box is built and run from Utah, in the United States. There is no registered company behind it yet, so there is no company number to quote and no registered office to give, and it is not yet offered as a commercial service. Both of those change before anybody is asked to pay for it, and this section changes with them.
For anything about this notice, or about data held about you, write to [email protected]. Signed in, Your data answers most questions immediately — you can read everything held about you and ask for it to be erased without waiting for anybody to reply.
Glass Box has no establishment in the EU or the UK and is not offered there. If it is, Article 27 requires a representative in each for data subjects and regulators to contact, and their name and address are published in this section before that happens.
Two different roles, and why it matters to you
Glass Box is sold to an organization, and most of the data in it is about that organization's employees. That splits our responsibilities in two, and the split decides who you should ask about what.
- For your employer's workspace data — the messages, topics, check-ins, commitments and reports inside a team — your employer is the data controller and we are their processor. We act on their documented instructions. If you want your account or your contributions deleted, we will normally refer you to them, because it is not our decision to make. What we are bound to do is set out in the data processing addendum.
- For our own account and billing data — who signed the contract, subscription records, support correspondence — we are the controller and you can come straight to us.
What we collect
Everything below is here because the product does not work without it. There is no analytics, no advertising, no profiling and nothing gathered on the chance it turns out to be useful later — the table is the whole list, and each row says what stops working if it is removed.
| What | Why | Kept for |
|---|---|---|
| Name, work email, job title, team and role | To create an account, place you on a team, and decide what you can see | While the account exists |
| Password | To sign you in. Stored only as a scrypt hash with its own salt — we cannot read it and cannot tell you what it is | While the account exists |
| The original text of anything you write, with whatever names you used | So you can read back what you actually sent and compare it with the rewritten version. Encrypted at rest. See the limits of anonymity below | While the account exists |
| A record of what the rewriter changed, before and after, for each message | So you can see exactly what was taken out rather than take it on trust. It contains the words that were removed, including names, so it is treated as carefully as the original and is shown to nobody but you | While the account exists |
| Nicknames you tell us you are known by | So the rewriter scrubs them too. A message that says “Bex” is not anonymous just because your account says Rebecca | While the account exists |
| A tone score for each message, from one to minus one | Derived from the words, not from you, and used for the trend charts a team sees about itself. It is never attached to your name anywhere | While the workspace exists |
| What you type when you say a topic is not settled, before it is rewritten | The room is shown the rewritten version. The original is kept for the same reason as any other message you write, and shown to nobody but you | While the workspace exists |
| Whatever you were asked for to confirm you are a real colleague | So the person running the organization can tell a new hire from a stranger with a link. Visible to them and to nobody else | While the account exists |
| Whether your email address has been confirmed, and a hash of any reset or confirmation link outstanding | To let you recover an account, and to make sure the address is yours. The link itself is never stored, only its hash | A day after the link expires |
| The rewritten, de-identified version of what you write | This is the version anyone else in your organization can read | While the workspace exists |
| Weekly check-in scores | A number from one to five, against your name, so your organization can tell when somebody is struggling. This one is deliberately not anonymous and the interface says so at the point of answering | 13 weeks |
| Proposals, votes, situations, evidence, readings, commitments | The team-facing features that carry them | While the workspace exists |
| Activity records (what happened to a topic, and when) | So a team can see that what they raised was seen and answered. Deliberately stores no author — it says “a teammate” or “the team's leader” and nothing more | 13 months |
| Session records: a hash of your session token, a truncated user agent, times | To keep you signed in and to let you see your own sessions | 30 days after expiry |
| Failed sign-in records: your email address and a value derived from your IP | To stop somebody working through a password list against your account. This is a security measure and we do not use it for anything else | 30 days |
| Invitation records: a hash of the link, the position offered, expiry | To let somebody join. The link itself is never stored — only its hash — so it cannot be looked up or re-sent by us | Until used or expired, then 30 days |
| Billing details | To take payment. Card details are handled by our payment processor and never reach our servers | 7 years, as tax law requires |
The limits of anonymity — read this part
Glass Box exists so that people can raise things they would not say in a meeting. It is worth being exact about how far that protection goes, because a promise that quietly stops short is worse than a smaller promise kept.
What is true. Nobody in your organization — including your team's leader and whoever administers the account — is ever shown the original of a message. What they read is the rewritten version, with names, pronouns, identifying details and heat removed, and a topic is not shown to a leader at all until three different people have raised something under it. That gate counts people rather than messages, so three posts from one frustrated person cannot open a topic that identifies them. The screens that show a leader anything never load the original text — it is not hidden in the interface, it is not fetched. Who wrote what is read on the server, and only to count how many different people have spoken under a topic; that count is what reaches the page, never the identity it was counted from.
What is also true. The original text, with whatever names you typed, is stored in our database alongside a reference to your account. It is there so that you can read back what you sent. It follows that:
- the pairing of you and your original words exists in our database and in its backups for as long as the account exists — encrypted, so that a copy of the database on its own does not reveal it, but present;
- it is encrypted with a key held by the application rather than by the database, so a stolen backup or a leaked dump does not open it — but anybody who can run our application code has both halves, and a small number of our staff can. Access is limited to those who need it to operate the service, and is logged — see the security overview;
- it could be reached by anyone who compromised that database, and it could be compelled by a lawful order;
- if you take a message back within fifteen minutes, it stops being visible to anyone, including you, but the record is retained for thirty days so that the weekly counts your leader was given still reconcile. After that it is deleted outright.
In short: the protection is against your colleagues and your management chain, which is who it is designed to protect you from. It is not a guarantee against us, against a breach, or against a court. If you need protection at that level, this is not the right tool and we would rather tell you so here than let you find out later.
Cookies and tracking
Glass Box sets three cookies and runs no analytics, no advertising pixels, no session recording and no third-party tracking of any kind. There is nothing to consent to, which is why you are not asked.
gb_session— your sign-in. Strictly necessary. HTTP-only, so no script can read it, and sent over TLS only.gb_team— which of your teams you are currently looking at. Strictly necessary for a person who belongs to more than one.gb-theme— light or dark, set only when you pick one. A preference you asked for, stored so the first paint is right.
None of them profile you and none are shared. If we ever add analytics, this section changes and you will be asked before any non-essential cookie is set.
Who we share it with
We do not sell personal information, and we do not share it for cross-context behavioral advertising. The only third parties involved in running the service are our infrastructure providers, listed in full on the subprocessors page. We will publish that page's changes in advance so a customer can object.
We may disclose data where we are legally required to. Where we are permitted to tell the affected customer first, we will.
Where it is processed
The database is hosted by Neon in AWS us-east-2 (Ohio, United States), and the application by Render. Payments are processed by Stripe. Everything is therefore processed in the United States. Glass Box is not offered in the EEA or the UK, and nothing here is aimed at people there. If that changes, the honest fix is an EU region rather than the paperwork that avoids one — Standard Contractual Clauses and a transfer impact assessment are what the alternative costs, and moving the database is cheaper than both.
Your rights
Depending on where you live, you may have the right to ask for a copy of your data, to correct it, to have it deleted, to receive it in a portable format, to restrict or object to how we use it, and to withdraw consent where consent is what we rely on. If you are in the EEA or UK you can also complain to your data protection authority; if you are in California you may have the rights to know, delete, correct, and to limit the use of sensitive information, and we will not discriminate against you for exercising them.
How to use them. Signed in, open the account menu and choose Your data. You can download everything we hold about you immediately, and request that your account and contributions be erased. If the data belongs to your employer's workspace we will pass the request to them and support them in answering it within the statutory deadline. Otherwise write to [email protected] and we will respond within one month. The Your data page does not wait on that: it answers immediately, whoever you are.
If you are in California
The CCPA, as amended by the CPRA, asks for some things to be said in particular words. Ours are short, because the honest answers are short.
- We do not sell personal information, and we never have. We do not share it for cross-context behavioral advertising either. There is no “Do Not Sell or Share My Personal Information” link on this site because there is nothing for it to switch off — no advertising network, no data broker, no pixel.
- Categories we collect: identifiers (name, work email, account id); professional information (job title, team, role); internet activity limited to what keeps you signed in and stops password guessing; and the content you write, which is the substantial one. We do not collect precise geolocation, biometrics, or the contents of your mail or messages elsewhere.
- Sources: you, and the organization that gave you an account. Nowhere else — we buy no data and enrich from no third party.
- Sensitive personal information: not requested and not used to infer anything about you. Your weekly check-in score is a number you choose to give, against your name, and it is used for nothing but showing your organization how the team is doing.
- Your rights: to know, to delete, to correct, to opt out of sale or sharing (which does not arise), and to limit the use of sensitive information. Exercise the first three from Your data in the account menu, immediately and without asking us. We will not discriminate against you for using any of them.
- Authorized agents may make a request on your behalf with written permission we can verify.
If you are in the EEA or the UK
- Lawful basis. For your employer's workspace data, your employer decides the basis; in most deployments it is legitimate interests, and they should have documented the balancing test. For our own account and billing data, our basis is performance of a contract and, for security records, legitimate interests in keeping accounts from being broken into.
- Transfers. Data currently sits in the United States. Where it leaves the EEA or UK, the transfer is made under the European Commission's Standard Contractual Clauses (2021/914), with the UK Addendum where UK data is involved, plus a transfer impact assessment. The addendum has the detail.
- Complaints. You can complain to your national supervisory authority, and you do not have to come to us first — though we would rather you did, because we can usually fix it faster.
- No automated decision-making. Nothing here profiles you or makes a decision about you without a person involved. The rewriting that removes names from a message is text processing, not a decision about a person, and the author sees and approves its output before anything is stored.
How long we keep things
The table above gives the period for each kind of record, and each of those periods is applied by a job that runs hourly rather than by anybody remembering. Resolved discussion threads are deleted three weeks after they are resolved, by the same job.
A workspace whose subscription has ended is deleted 60 days later, and that runs on its own. Writing stops when the paid period does; everything stays readable and exportable for the whole 60 days. Nothing is deleted without being told first: the person who runs the organization is written to a month before, a week before and the day before, and the workspace is only removed once that last notice has actually been delivered. A workspace we could not reach is kept rather than deleted. The banner inside the product carries the same date, because whoever opens the workspace is not always whoever the mail went to.
You do not have to wait for any of that. Whoever runs the organization can erase all of it immediately from the danger zone on the People page, and anybody can download their own data from Your data at any point. Backups roll off on their own schedule, described in the security overview.
Security
Set out in full on the security overview: what protects your data, and where the current limits are.
Children
Glass Box is a workplace tool sold to organizations. It is not directed to children and we do not knowingly collect data from anyone under 16. If you believe a child has an account, tell us and we will remove it.
Changes
We will post changes here and update the date at the top. Where a change materially reduces your protection we will tell affected customers before it takes effect.

