Privacy Policy
Last updated 2026-10-03
Glimmer is an anonymous one-to-one chat app published by ByteLoft ("we"). This policy explains what we collect and why.
Who is responsible
ByteLoft, a sole proprietorship registered in the Republic of Korea (business registration number 317-08-03221), is responsible for your data.
- Address: 2-677A, 47 Gangnam-daero 112-gil, Gangnam-gu, Seoul 06121, Republic of Korea
- Email: [email protected]
What we collect
Device identifiers and settings. When you first open Glimmer it creates a random installation ID and secret on your device. We store the ID, the secret's hash, the app version, the device language, the country your connection comes from, and when the app was first and last used. We do not ask for your name, phone number, email, contacts, photos or location.
Chats. We store the text of your messages, who sent them and when, and the result of automatic safety screening, so that chats can be delivered, restored after a reconnect and reported.
Safety records. When you report, we keep a copy of the recent conversation as evidence. We also keep who reported whom and why, and whom you blocked. If someone reports you, the report and the evidence come to us from that person, not from you.
Usage records. We record events such as starting a search, starting an AI chat, sending a message (not its text), leaving, reporting and blocking, to run and improve the service.
AI starts and rewards. We record your daily free AI start and, when you watch a rewarded ad, a hashed form of the ad's reward token and Google's transaction ID.
Network addresses. Your IP address is used briefly to limit abuse and to determine your country. We do not store it in readable form. The country lookup runs on our server with IP Geolocation by DB-IP (CC BY 4.0).
Age signal from Google Play. When you tap Start, Glimmer asks Google Play whether it has confirmed your age. Google Play answers with an age range, that confirmation is needed, or that it shares nothing. The answer is used only on your device to decide whether a chat can start. We do not send it to our servers, store it or use it for ads.
Data requests. When you ask for your data from the app, we record a request number with your installation ID and the time. If you email us, we receive your email address and message.
How we use it
- To connect you with another person or an AI character, deliver messages and restore a chat.
- To keep people safe: automatic screening, reports, blocks and bans.
- To limit abuse and the cost of AI chats, and to offer the service only in its launch countries.
- To show ads and grant rewards.
- To find and fix crashes.
Who processes it
| Recipient | What | Why |
|---|---|---|
| OpenAI | The text of messages in chats, for automatic safety screening. In AI chats, up to the last 40 messages and a pseudonymous identifier derived from your installation ID | Safety screening and AI character replies. Our requests ask OpenAI not to store them for its API state; OpenAI may keep API data for up to 30 days to monitor abuse |
| Google AdMob | Device and advertising data collected by Google's ads SDK, and the reward token of a rewarded ad | Showing ads, measuring them, preventing fraud and verifying rewards. Where the law requires consent, Google's consent message asks you first; you can change the choice in Settings. In Canada and Mexico, ads are not personalized |
| Google Firebase Crashlytics | Crash and error reports: stack traces, device model, OS, app version, which screen and state the app was in, and an identifier Firebase creates for the app installation. Our reports carry no chat text | Fixing crashes |
| Our hosting providers | The data we store on our servers, listed in "What we collect" | Running the service |
Our servers and these providers may be outside your country. We use the providers under their data processing terms.
How long we keep it
| Data | Kept for |
|---|---|
| Chat messages | 48 hours after they are sent |
| Report evidence (copy of the conversation) | 90 days after the report |
| Usage events | 400 days |
| Crash reports | 90 days in Crashlytics, after which Firebase starts deleting them from its active and backup systems |
| Database backups | Our daily server backups let us restore the service to any point in the last 7 days. Deleted data normally leaves the backups about 8 days later. If a daily backup fails, the last good backup is kept until a newer one succeeds, so it can stay longer |
| Installation record, chat and block records, AI start and reward records | Until you ask us to delete them, and at most 400 days after the app was last used |
| Report records without evidence (who reported whom, reason, outcome) | 400 days after the report |
| Emails you send us | General questions: 90 days after they are resolved. Data requests: our record of handling them, 2 years after the request is closed |
Your choices and rights
- You can leave or block anyone at any time, and delete the app to remove the data stored on your device.
- You can ask us to access, correct or delete the data linked to your device, or to stop using it. Ask from the app (Settings → Request data deletion): the email it opens carries a request number the app registered with our service, which shows us the request came from your device. See Contact. We answer within 15 days. Depending on where you live you may also complain to your data protection authority.
- Evidence of a report may be kept for its retention period even after a deletion request when we need it to protect others or to meet a legal obligation.
Canada
- The person in charge of protecting personal information is ByteLoft's representative, reachable at [email protected].
- Your data is processed outside Canada, including outside Québec, by us and by the providers listed above.
- Ads shown in Canada are not personalized: Glimmer asks Google for non-personalized ads only. Google may still use data to limit how often an ad is shown, to measure ads and to prevent fraud.
New Zealand
- Our privacy officer is ByteLoft's representative, reachable at [email protected].
- Our hosting providers, OpenAI and Firebase Crashlytics process data on our behalf under their data processing terms, outside New Zealand. We remain responsible for that data.
- Google AdMob's SDK collects device and advertising data for Google's own purposes as described in Google's privacy policy.
- Some data about you comes from someone else: a report another person files about you, and the age signal from Google Play. This policy is our notice of that collection.
- You may complain to the Office of the Privacy Commissioner.
Mexico
- The Spanish aviso de privacidad is our full privacy notice for Mexico.
- ByteLoft, at the address above, is responsible for your personal data.
- Ads shown in Mexico are not personalized.
- You can ask to access, correct or delete your data, or object to its use (ARCO rights), from the app as described above. We answer within 15 calendar days and carry out an accepted request within 15 calendar days of our answer.
Children
Glimmer is for adults (18+). We do not knowingly collect data from children. When Google Play tells the app that you are under 18, Glimmer does not start a chat. See our child safety standards.
Changes
We will update this page when our practices change and show the date at the top.