Effective: September 17, 2026
This Privacy Policy explains how GLASSOCIAL, LLC (the “Company”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal information in connection with the Glas / AuthenSnap mobile application and related services (the “Service”). It is incorporated into our Terms of Service.
By using the Service, you acknowledge this Privacy Policy. The Service is intended only for adults 18 and older (see Section 14). If you do not agree with this Policy, do not use the Service.
1. Who We Are (Controller)
For the purposes of the EU/UK General Data Protection Regulation (GDPR) and similar laws, the data controller is GLASSOCIAL, LLC, 30 N Gould St, Ste R, Sheridan, WY 82801-6317. Contact: isaacl@glassocial.com.
2. Personal Information We Collect
We collect the following categories of personal information. Not every category applies to every user; collection depends on how you use the Service.
a. Information you provide
| Data | Examples | Where |
|---|---|---|
| Account & identity | Email address; phone number (SMS-verified); username; display name; profile and cover images | Registration, profile setup |
| Authentication | Credentials via email/password; Google Sign-In and Apple Sign-In identifiers and, where you permit, name/email from those providers | Sign-up / sign-in |
| User Content | Photos, videos, audio, captions, comments, tags, direct messages, and any media or text you upload, post, mint, or share | In-app creation |
| Wallet information | External blockchain wallet address you provide (e.g., for exporting items or receiving payouts) | Wallet / payout features |
| Payment & payout data | Handled by third-party processors; may include billing details and, for payouts, identity-verification (KYC) information such as legal name, date of birth, and country of residence collected by our regulated payout/identity partners | Purchases, cash-out |
| Communications | Messages you send to other users; support requests and correspondence with us | Messaging, support |
b. Information collected automatically
| Data | Examples |
|---|---|
| Device & technical | Device model, operating system and version, app version, language, time zone, and general diagnostic information |
| Push tokens | Firebase Cloud Messaging (FCM) / Apple Push (APNs) device tokens used to send notifications, plus your notification preferences |
| Usage & social graph | Actions such as posts, likes, reactions, comments, follows/followers, blocks, views, “collect” and pay-per-view activity, referral activity, and rewards/points balances |
| Transaction & token data | In-app virtual-currency balances (spendable and earned), transaction/ledger records, and on-chain data such as wallet addresses, token IDs, and transaction hashes |
| Log data | IP address and server logs associated with API requests (as part of normal server operation and security) |
We currently do not use third-party advertising, analytics, or cross-app tracking SDKs, and we do not request device location or contacts. (If this changes, we will update this Policy and obtain any required consent.)
c. Media metadata
Media you upload may contain metadata (such as EXIF, including in some cases device or location data). Our media library integration is configured not to attach location data, and our servers are designed to strip metadata from the derivative media used for public distribution / minting to reduce exposure of sensitive information.
d. Sensitive information
Please do not upload special-category or sensitive information (e.g., government IDs, health, precise location, or content revealing race, religion, or similar) except where a feature specifically requests it (for example, identity information required by a regulated payout/KYC provider). Any identity-verification data collected for payouts is processed by our third-party providers for legal compliance purposes.
3. Sources of Personal Information
We collect personal information (a) directly from you; (b) automatically from your use of the Service and your device; (c) from other users (e.g., when someone messages, follows, mentions, or reports you); and (d) from third-party providers, such as authentication providers (Google, Apple), payment processors, and identity-verification/payout partners.
4. How We Use Personal Information
We use personal information to:
- create and manage your account and authenticate you (including phone verification and enforcing one-account-per-phone / anti-fraud controls);
- operate, provide, and maintain the Service and its social, messaging, content, token, and rewards features;
- host, process, transcode, and deliver your User Content, and mint or record items on blockchain / IPFS where you use those features;
- moderate content and promote safety — including automated/AI analysis of images and video and transcription of audio to detect prohibited or harmful content, plus handling of user reports, auto-flagging, and blocking (see Section 13);
- send you push notifications and service communications, and, where permitted, transactional messages;
- process purchases, manage virtual-currency balances, and facilitate payouts through our providers, including required identity verification (KYC/AML);
- personalize and improve the Service, develop new features, and conduct debugging and analytics on our own systems;
- protect the Service, prevent fraud and abuse, enforce our Terms, and ensure security; and
- comply with legal obligations and respond to lawful requests.
5. Legal Bases (GDPR / UK GDPR)
Where GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Service you request (account, content hosting, messaging, transactions).
- Legitimate interests — to secure and improve the Service, prevent fraud and abuse, moderate content, and operate our business, balanced against your rights.
- Consent — where required, for example for certain notifications or optional features; you may withdraw consent at any time without affecting prior processing.
- Legal obligation — to comply with laws, including financial-compliance (KYC/AML), tax, and safety/reporting obligations.
- Vital interests / public interest — in limited safety situations (e.g., reporting CSAM or preventing imminent harm).
7. Blockchain and Decentralized Storage
When you mint, export, or otherwise use blockchain/IPFS features, certain data is written to public, distributed, and effectively permanent systems. This may include your media and its metadata, wallet addresses, pseudonymous identifiers (such as a one-way hash derived from your user ID), token IDs, and transaction hashes. We cannot control, modify, or delete information once it is recorded on a blockchain or propagated across IPFS nodes and gateways. Deleting your account or content within the app does not remove data already published to these networks. The Service currently operates on a test blockchain network, and such tokens have no monetary value.
8. International Data Transfers
We and our providers may process personal information in the United States and other countries that may have data-protection laws different from yours. Where we transfer personal information out of the European Economic Area, the United Kingdom, or other regions with transfer restrictions, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) or other lawful transfer mechanisms. You may request more information at isaacl@glassocial.com.
9. Data Retention
We retain personal information for as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, prevent fraud and abuse, and enforce our agreements. Retention periods vary by data type and context. When no longer needed, we delete or de-identify personal information. Note: data published to blockchain/IPFS cannot be guaranteed deleted (see Sections 7 and 12).
10. Security
We implement technical and organizational measures designed to protect personal information, which may include encryption in transit, access controls, server-side signing for blockchain operations, and encryption of designated private content. No system is perfectly secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and any external wallet keys. If we become aware of a data breach affecting your personal information, we will notify you and regulators as required by applicable law.
11. Your Choices
- Profile & privacy settings — you can edit profile information and set your account to private.
- Notifications — you can manage push notifications in the app and in your device settings.
- Blocking & reporting — you can block other users and report content.
- Account deletion — you can delete your account (see Section 12 and how to delete your account).
- Communications — you may opt out of non-essential communications; some transactional messages are required to use the Service.
12. Your Privacy Rights
Depending on where you live, you may have some or all of the rights below. To exercise a right, contact isaacl@glassocial.com. We will verify your request and respond within the time required by law. You may authorize an agent to act on your behalf where permitted. We will not discriminate against you for exercising your rights.
Account deletion mechanics. When you delete your account, we delete or de-identify personal information associated with your account from our active systems on a best-effort basis, including removing your posts and their sub-records, your social interactions on others’ content, your stories and stored media, and (for custodial items) burning associated on-chain tokens where technically possible. As described in Sections 7 and 9, information already recorded on a blockchain or propagated on IPFS cannot be guaranteed erased. Some records may be retained as required by law or for fraud-prevention, security, or dispute-resolution purposes.
a. United States — California (CCPA/CPRA) and other state laws
California and certain other U.S. state residents may have the right to:
- Know / access the categories and specific pieces of personal information we collected, the sources, purposes, and categories of recipients;
- Delete personal information we collected, subject to exceptions;
- Correct inaccurate personal information;
- Opt out of “sale” or “sharing” of personal information and of targeted advertising. We do not sell your personal information for money and do not use cross-context behavioral advertising. To the extent any data disclosure is deemed a “sale” or “share” under applicable law, you may opt out by contacting isaacl@glassocial.com;
- Limit use of sensitive personal information (we use it only for permitted purposes such as providing the Service and legal compliance); and
- Non-discrimination for exercising your rights.
Notice at collection: the categories of personal information we collect and our purposes are described in Sections 2 and 4. We do not knowingly collect or sell the personal information of individuals under 18.
b. European Economic Area / United Kingdom (GDPR / UK GDPR)
You may have the right to: access; rectification; erasure (“right to be forgotten”); restriction of processing; data portability; object to processing based on legitimate interests or to direct marketing; withdraw consent; and not be subject to solely automated decisions with legal or similarly significant effects (see Section 13). You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office).
c. Canada (PIPEDA)
You may have the right to access and correct your personal information and to withdraw consent, subject to legal and contractual restrictions. We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act. You may direct concerns to us and, if unresolved, to the Office of the Privacy Commissioner of Canada.
d. Other jurisdictions (global)
If you are located elsewhere, you may have similar rights under your local law. We aim to honor valid requests consistent with applicable law — contact isaacl@glassocial.com.
13. Automated Decision-Making and Content Moderation
We use automated and AI-based systems to help moderate content and protect the Service. For example, uploaded images and videos may be automatically analyzed (and audio in videos transcribed) to detect prohibited or harmful content, and content may be automatically flagged or restricted based on such analysis, user reports, and engagement signals. These systems assist human review and enforcement of our Terms. Where required by law, you may have the right to request human review of, express your view on, or contest a decision that produces a legal or similarly significant effect — contact isaacl@glassocial.com.
14. Children’s Privacy
The Service is not intended for anyone under 18, and we do not knowingly collect personal information from minors. If you believe a minor has provided us personal information, contact isaacl@glassocial.com and we will take appropriate steps to delete it and terminate the account. Our Child Safety Standards explain how we prevent, remove, and report child sexual abuse and exploitation.
15. Third-Party Services and Links
The Service integrates and links to third-party services (see Section 6). Their handling of your information is governed by their own privacy policies, which we encourage you to review. We are not responsible for third-party practices.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice (e.g., by updating the “Last Updated” date, posting in-app notice, or emailing you). Your continued use of the Service after changes take effect constitutes acknowledgment of the updated Policy.
18. Contact Us
For privacy questions or to exercise your rights:
GLASSOCIAL, LLC
30 N Gould St, Ste R, Sheridan, WY 82801-6317
Email: isaacl@glassocial.com