Glixo Code

Privacy policy

This policy explains what data Glixo Code handles, when it leaves your device, which services may receive it, and the controls available to you.

Effective 7 September 2026 Last updated 7 September 2026 Policy version 2026-09-07-v1 support@glixo.io

Scope and the product model

This policy covers the Glixo Code apps, the glixo.io site, Glixo-operated pairing and signaling services, optional telemetry, explicit safety reports, and the Android closed-beta application service.

Glixo Code is a controller for a desktop or server target that you authorize. Pairing creates an encrypted local profile on your device; it does not by itself create a Glixo-hosted customer account. Your paired target, its operator, and any model providers configured there have their own data and retention responsibilities.

Data Glixo Code handles

Local encrypted profiles. Device keys and pairing secrets are encrypted at rest on the device. They remain until you remove the local profile. Glixo does not receive the plaintext vault through ordinary pairing.

Optional telemetry, on by default. Unless you opt out in Settings → Privacy, Glixo Code may send minimal install or uninstall counts and crash diagnostics to api.glixo.dev. Crash diagnostics contain the error type, a redacted message, app version, and coarse platform. They do not intentionally include a device or account identifier, prompts, files, workspace content, paths, provider secrets, or stack traces. Opting out stops new telemetry and clears the legacy local telemetry identifier.

Pairing and signaling. When you pair, Glixo-operated services process short-lived, one-use claim and mailbox identifiers, verification state, device public keys, and signaling metadata needed to connect the selected peers. Network providers may also process IP addresses and WebRTC connection metadata. Pairing claims normally expire after about two minutes. The pairing relay does not receive the account content key in plaintext.

Notifications and presence. If you grant notification permission, the app sends its push token to the paired target. The target and Google Firebase Cloud Messaging process that token to deliver Android notifications. The paired target also receives limited device-presence information, such as platform, foreground/background state, last-seen time, delivery target, and an optional active-session identifier.

User-authorized exact-peer work. After pairing, prompts, assistant output, files or media, command input and output, heartbeat/session data, and related workspace content flow through an authenticated end-to-end encrypted peer tunnel to the target you chose. Glixo-operated pairing and signaling intermediaries do not receive that content in readable form. The target may send content required for a request to model providers or other tools configured by that target; that is a user-authorized target action, not receipt of the ordinary content by Glixo.

Report response submissions. Nothing is sent to Glixo until you choose Report response, review the exact excerpt, select a category, optionally add a note, and confirm. The optional excerpt is treated as an in-app message and the optional note as other user-generated content, used for security and compliance. The submission also includes limited context such as model label, app version, coarse platform, and a one-use report identifier. Glixo staff can read the submitted material. It is separate from telemetry and is not automatically forwarded to a model provider.

Like most public sites, glixo.io and its infrastructure process ordinary request metadata such as IP address, browser type, requested URL, and timestamps for delivery, security, and abuse prevention.

Google Play Data Safety summary. Glixo declares no Play-defined data sharing. Collected data is limited to optional response-report excerpts and notes for security/compliance; optional crash logs, diagnostics, and app-interaction telemetry for analytics; and device or other identifiers needed for pairing, core functionality, and security/compliance. Notification tokens are used only after notification permission. Exact-peer prompts, files/media, and heartbeat/session content are excluded under Google's end-to-end-encryption exception because Glixo and its intermediaries cannot read them.

Services and Google Play disclosure

  • Your paired desktop or server: receives the content and device state needed to provide the features you authorize.
  • Configured model and tool providers: receive content only when the paired target uses those providers for your request. Their policies and the target operator's settings govern that processing.
  • Cloudflare: operates pairing/signaling infrastructure and the Android beta API, and processes network and security metadata for those services.
  • Google Firebase Cloud Messaging: processes Android push tokens and notification delivery data after notification permission is granted.
  • Amazon Web Services: hosts public portal services, optional telemetry aggregates, and explicit response reports.
  • Namecheap Private Email: sends Android beta messages and receives mail sent to support@glixo.io.

These vendors act as service providers for the described functions, or receive data through a user-directed connection to the paired target. Under Google Play's Data Safety definitions, those transfers are not declared as sharing. Glixo does not sell personal data or use this product data for third-party advertising.

Retention and deletion controls

  • Local profile: kept until you remove it from that device. Removal deletes the local encrypted credentials; it does not erase the paired target, its workspace, other devices, telemetry already aggregated, or a report you explicitly submitted.
  • Pairing claims: expire after about two minutes and are single-use. Operational security logs may be retained for a limited period.
  • Push token and presence: retained by the paired target until revocation, replacement, or the target operator's cleanup. Revoke the device and disable OS notifications to stop future use.
  • Work content: follows the retention, backup, and deletion policy of your paired target and its configured providers. Use those systems' controls to remove it.
  • Telemetry: opt-out stops new submissions. Anonymous aggregate counters may be kept for historical product trends; redacted crash-signature detail expires after 90 days.
  • Report response: retained for up to 90 days, then hidden from staff access and scheduled for eventual database deletion. Email support@glixo.io with the receipt identifier to request earlier review or deletion where feasible.
  • Android beta applications: contact details and free-text answers are anonymized 90 days after the latest lifecycle milestone, or earlier after a verified deletion request. Hashed abuse-limit events are deleted after two days.

To ask about data Glixo operates, request correction, or request deletion, email support@glixo.io. We may need enough information to locate the record and verify that the request is yours. We cannot delete data held solely by a user-controlled paired target or its independently configured provider.

Security

Glixo Code encrypts local profile secrets at rest and uses TLS for public HTTPS and secure WebSocket connections. Peer connections use WebRTC's protected transport. Access to Glixo-operated records is restricted to authorized personnel and service identities. No security measure is perfect, so do not include secrets in telemetry, beta applications, or response reports, and review a report excerpt before sending it.

Android closed-beta applications

The public application form is currently disabled. While disabled, it does not accept or store applications. When opened, the form asks for the Google-account email used with Google Play, an optional device description, testing intent, and confirmations of the testing commitments and this notice.

The beta service stores lifecycle and consent timestamps, application status, locale, non-secret tester-list references, outbound-message state, and provider message identifiers. It stores keyed hashes—not the raw values—of request IP addresses and browser user-agent strings for abuse controls. Cloudflare may still process the raw request metadata to deliver and protect the service.

Email-verification links expire after 24 hours and are single-use. A human reviews verified applications before adding an approved address to the Google Play closed-test email list. Joining a list does not opt you in; you must use Google's opt-in flow yourself. You may withdraw or request deletion through support@glixo.io.

Your choices and policy changes

  • Turn anonymous telemetry off at any time in Settings → Privacy.
  • Deny or revoke notification permission in Android settings.
  • Do not pair, unpair a device, or remove its local profile.
  • Choose which desktop/server target and model providers you authorize.
  • Cancel a response report before submission or edit the excerpt and note.
  • Do not apply for, or withdraw from, the Android beta.

We may update this policy as the product or services change. Material changes will be posted at this same public URL with a new “Last updated” date. Continued use after a change is subject to the updated policy.

Back to Glixo Code