GDPR & Privacy Notice
Last updated: October 2026
1. Who We Are & Our Philosophy
In short We are fully based in the EU. We hold your data to make our app run smoothly, not to sell it to advertisers or brokers.
superglass operates under European jurisdiction. We act as a Data Processor for the information you upload (such as meeting notes and audio recordings) and a Data Controller for your basic account information (like your name and email address). Our business model is simple: you pay us for a software service. We do not sell, rent, or monetize your data to any third parties.
2. The Data We Collect & Why
In short We only collect basic profile info and the notes you want our AI to classify for your pipeline.
We collect and process the following categories of personal data. Unless stated otherwise, the legal ground is contractual necessity:
- Account Data: Name, business email address and company name.
- Customer Content: Text notes, typed summaries, or audio recordings that your sales reps upload or record within the app.
- Integration Data: If you connect them: the authentication tokens that let us read and update your Salesforce data and read your Microsoft Teams meeting transcripts.
- Waiting-list Data: If you request early access: your email, name, company and language, plus the campaign and referring site of your visit that day. Legal ground: inviting you is a step you asked us to take before a contract; recording the campaign and referring site rests on our legitimate interest in knowing which campaigns bring people in, and you can object to it at any time. To be removed from the list, email us.
3. Where Your Data Lives (Data Localization)
In short Your data is stored on our servers in France. A few named services process some of it for us, some outside the EU, under GDPR safeguards.
All personal data and customer content is stored on our servers in France, encrypted in transit (TLS) and at rest (AES-256). To run superglass we rely on the services below. Each one processes your data on our instructions.
- Cloudflare: Delivers our website and app and protects them from attacks. All traffic to superglass passes through it.
- Resend: Sends our emails: sign-in and verification links, invitations and waiting-list emails.
- OpenRouter, with Google and Anthropic models: Run the AI that reads your notes, answers your questions and helps build your methodology.
- OpenAI: Transcribes the audio notes you record.
- Microsoft and Salesforce: Only if you connect them: we read your Teams meeting transcripts, and read and update your Salesforce data.
Cloudflare, Resend, OpenRouter, Google, Anthropic and OpenAI are US companies, and Microsoft and Salesforce may also process data outside the EU. Where your data leaves the EU, the transfer relies on the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.
4. The AI Processing Boundary (EU AI Act Compliance)
In short Locked-box processing. Your conversations are siloed and will never be used to train public or foundational models.
In compliance with the EU AI Act and safety standards:
- Zero Public Training: Your text inputs, meeting summaries, and audio files are processed via secure, private enterprise APIs. Your data is isolated and is never used to train public or foundational third-party AI models.
- No Automated Sole Decision-Making: Our AI provides data classification and coaching recommendations, but a human sales rep always reviews, edits, and approves the data before it is saved or pushed to Salesforce.
5. Data Retention
In short Profile info stays while you use the app. Voice recordings are deleted as soon as they've been turned into text.
- Account Data: Retained for the duration of your active subscription and deleted within 30 days of account termination, unless required otherwise by financial auditing laws.
- Voice Recordings: Voice recordings are deleted as soon as they've been turned into text, and also if processing fails. We never keep the recording or its transcript. The note made from it stays in your workspace, as part of your account data.
- Waiting-list Data: Deleted 12 months after you join if you haven't been invited, or 6 months after your invite if you haven't created a workspace. Once you create a workspace, it is kept as account data.
6. Your GDPR Rights
In short You have complete control. Email us anytime to download your data profile, correct an issue, or delete everything.
Under the GDPR, you have full rights over your personal data. You can exercise these at any time by contacting us:
- Right to Access & Portability: You can request a copy of all data we store about you.
- Right to Erasure ("Right to be Forgotten"): You can request that we permanently delete your account and associated personal data.
- Right to Rectification: You can request that we correct any inaccurate personal information.
- Right to Object: You can object to processing based on our legitimate interest, such as the campaign attribution on the waiting list.
- Right to Lodge a Complaint: You can complain to the data protection authority of the EU country where you live or work.
To exercise these rights, please drop us a quick note at [email protected].