Privacy Policy
Glint is a parent-first family utility. The product is designed around parent approval, Apple's Family Controls APIs, and a narrow data footprint.
Current Product Scope
Glint is currently in a pilot and TestFlight proof stage. This policy describes source candidate 1.0 (65), which remains on hold until its exact signed archive, Apple processing, and physical-device evidence exist. Builds 54 through 64 are historical and do not attest Build 65. The product boundary is one guardian and one child across a guardian device and one managed child iPhone or iPad in Protected mode. The guardian verifies an email address with a one-time code, creates the family, and pairs the child device with a separate one-time family code. Sign in with Apple is not the guardian login.
- No advertising or third-party ad tracking.
- No child photos are collected, uploaded, or processed in the current build.
- AI/photo verification is not included in the current build.
- Task requests, guardian decisions, family rules, earned-minute credits, and credit acknowledgements sync between the paired iPhones. The spendable balance and consumption history stay on the child iPhone.
- Apple Screen Time selection tokens and enforcement stay only on the child iPhone.
- Screen Time, missions, rules, approvals, earned minutes, limits, recovery, and account deletion are free. The current release candidate has no in-app purchases, subscriptions, paywall, or service call to action.
Screen Time and Family Controls
On iOS, Glint uses Apple's Family Controls, FamilyActivityPicker, ManagedSettings, DeviceActivity, DeviceActivityMonitor, and ShieldConfiguration APIs to help a parent or guardian manage selected apps on the child's device.
App selections are handled as opaque Apple tokens. In the current release candidate, those Screen Time selection tokens stay local to the child device and its App Group. Glint does not upload readable app identities to a backend.
Information We Collect
For the first public iOS release, we collect only the information needed to authenticate the guardian, pair the family, synchronize the product loop, and enforce the family's rules:
- Account identifiers. A guardian provides an email address to create and recover the family account. Supabase Auth stores the address, and our transactional email provider processes the address and one-time code to deliver and verify login. The native apps do not persist or log the code or CAPTCHA token. Cloudflare Turnstile processes the challenge token, and Supabase verifies it as part of the authentication request. A paired child device uses an anonymous authentication identifier.
- Family setup. Family, guardian, and child display names; the child's birth year; family timezone; child device name; and a hash derived from a random identifier created on that device.
- Product activity. Pairing and authorization state, task requests, guardian approvals or rejections, family rules, bedtime and daily-limit settings, earned-minute ledger entries, device heartbeat state, and limited security, consent, and deletion records.
- Deletion reconciliation. The current client does not send purchase or subscription data to RevenueCat. To honor account deletion for families who may have used an earlier binary, our trusted backend can send the exact guardian identifier to RevenueCat solely to erase a legacy customer record. RevenueCat does not receive Screen Time tokens, child profile, tasks, rules, approvals, or earned minutes.
For the website waitlist and pilot recruiting, we may separately collect a parent email address, optional pilot-fit answers, and basic technical request information needed to operate the website and API.
How We Use Information
- To authenticate the guardian and maintain the paired family account.
- To synchronize task requests, guardian decisions, family rules, earned-minute credits and acknowledgements, and device status. Spendable balance and consumption stay local to the child iPhone.
- To apply the family's Screen Time agreement on the child iPhone and troubleshoot the TestFlight pilot.
- To protect accounts, prevent abuse, honor deletion requests, and improve reliability.
- To invite families who separately joined the website waitlist to the Phase 0 pilot.
Sharing
We do not sell personal data. We do not share child data for advertising, and we do not use family data to track people across other companies' apps or websites.
- Apple provides Screen Time APIs and TestFlight. Glint does not use Sign in with Apple for guardian login. Family Controls distribution depends on Apple assigning the entitlement to Glint’s developer account and App IDs.
- Supabase provides email authentication, database, and server functions for pairing and the minimized family sync. A dedicated transactional email provider delivers guardian sign-in codes on our behalf.
- Cloudflare provides the public website and Turnstile abuse-prevention challenge used for guardian OTP requests and anonymous child authentication.
- RevenueCat is not used by the current client for checkout, entitlements, purchases, or restore. It may receive the exact verified guardian identifier only from the trusted deletion worker to erase a legacy customer record.
- Website infrastructure providers process waitlist or privacy-request data only to operate those services.
Retention and Deletion
Family account data is kept while the family uses Glint. A confirmed deletion starts from the in-app guardian flow after Glint durably stores the trusted deletion intent. The backend removes family records, reconciles authentication, and attempts deletion of any legacy RevenueCat customer record before guardian authentication is removed. After the server confirms deletion, the app removes the exact subject's current local connection state and also attempts to erase retired weekly-review files and signed access-cache records left by earlier builds. If protected local storage cannot be cleared, Glint reports that local cleanup is still pending so it can be retried; it does not present that device cleanup as complete. Limited security and deletion records may be retained where needed to prevent abuse or satisfy legal obligations.
A retained Sign in with Apple profile from an earlier build is not accepted as email authority and is never linked automatically to a new email account. The app offers an explicit local reset for that exact saved credential generation. This removes the old profile only from the iPhone; it does not delete or transfer the server-side family. A separately verified in-app deletion or privacy request is required for server deletion.
Glint 1.0 (65) has no Apple subscription to cancel. If a family has an Apple subscription from an earlier binary, deleting a Glint account does not automatically cancel it; the guardian must manage it separately through Apple's subscription settings.
Waitlist and pilot contact data is kept only while it is useful for the pilot or product launch. A parent can ask us to review or delete their family's information through the privacy request form below. Photo-processing retention is not active because photo tasks are not shipped in the current build.
Children
Glint is designed for parent-authorized family use. Parents and guardians control setup, consent, task approval, and Screen Time management. If you believe a child provided information without a parent or guardian, contact us and we will review and delete it where appropriate.
Contact
Use this parent-only form for privacy questions, access requests, or deletion requests. Do not include a child's name, photos, payment information, or other sensitive details.