Glossa

Privacy Policy

Last updated: May 2026

1. Information We Collect

When you create an account, we collect your email address and display name via Firebase Authentication (Google sign-in). When you use Glossa, we store:

  • Books you upload (PDFs stored in Azure Blob Storage)
  • Your reading progress, saved vocabulary, highlights, and game scores
  • Language preferences (known and target languages)
  • Subscription and billing status (managed by Stripe — we do not store card numbers)

2. How We Use Your Information

  • To provide the reading, translation, and vocabulary features
  • To track your learning progress (streaks, achievements, spaced repetition)
  • To process payments and manage your subscription via Stripe
  • To improve the service (aggregated, anonymized usage patterns)

3. Third-Party Services

We use the following third-party services that may process your data:

  • Firebase (Google) — authentication
  • Azure (Microsoft) — hosting, file storage, translation, text-to-speech
  • OpenAI — AI-powered translations and summaries
  • Stripe — payment processing

Each service operates under its own privacy policy. We do not sell your data to any third party.

4. Data Storage and Security

Your data is stored in a PostgreSQL database and Azure Blob Storage. All connections use TLS encryption. We follow industry-standard security practices, but no system is 100% secure.

5. Your Rights

You may:

  • Export your vocabulary and reading data at any time
  • Delete your account and all associated data by contacting us
  • Update your profile information from within the app

6. Cookies and Local Storage

Glossa does not use advertising, analytics, or cross-site tracking cookies. We do not embed Google Analytics, Facebook Pixel, or similar trackers. Under the Norwegian Electronic Communications Act (ekomloven §2-7b) and the EU ePrivacy Directive, the items below are either strictly necessary to deliver the service or store preferences you set yourself, so no consent banner is required.

Strictly necessary

  • __cf_bm — set by Cloudflare for bot detection and security. First-party cookie, ~30 minutes, no personal data.
  • Firebase Authentication token — stored in your browser's localStorage under keys prefixed firebase:authUser:. Required to keep you signed in. Cleared when you log out.

Preferences you set

The following are stored only in your browser's localStorage and never sent to advertisers:

  • reader_settings — font size, theme, gloss reveal level, reading mode.
  • streak_last_celebrated, streak_pending_celebration — prevents replaying streak milestone animations.
  • uiTranslate_* — cached translations of UI labels into your target language, so they load instantly on return visits.

Payment processing

When you start a subscription, you are redirected to Stripe Checkout on stripe.com. Any cookies set during checkout are first-party to Stripe and governed by Stripe's privacy policy. Glossa does not see or store your card details.

You can clear all browser storage for readglossa.com at any time from your browser's site settings. Doing so will sign you out and reset your reader preferences.

7. Changes to This Policy

We may update this policy from time to time. We will notify registered users of significant changes via email.

8. Contact

For privacy-related questions, email us at [email protected].

HomeTerms of ServicePrivacy Policy