Effective September 5, 2026

Privacy Policy

Fortaify builds privacy-first AI. This policy explains what information we collect, what stays on your device, how we use and share information, and the rights you have. It applies to the Fortaify website, the Glyph desktop application, and the Glyph mobile application (together, the "Services").

On-device by default

Local models run on your device. Content leaves only through features you turn on, and this policy names each one.

Minimal collection

We collect only what we need to run accounts, subscriptions, and reliability.

No sale, no training

We do not sell your personal information or train our models on your content.

1. Who We Are

Fortaify, operated by Tao Creative Labs LLC, provides the Services and is the controller of the personal information described here. You can reach us about privacy at support@fortaify.com.

2. Our Privacy Approach

Glyph is designed so that AI inference and generation can run entirely on your device. When you use a local model, your prompt and its response are not sent anywhere. We limit server-side collection to what is needed to operate accounts, process subscriptions, keep the Services reliable and secure, and support you.

Some features send content outside your device by design. That happens when you choose a cloud AI model, use internet search or page fetching, use Cloud Relay to reach your desktop from elsewhere, or use an organization feature that reports security metadata. Section 4 lists each of these and what it sends.

3. Information We Collect

We collect the following categories of information:

  • Account information: your email address, name or display name, username, and a unique account identifier, collected when you create an account or sign in with email, Apple, or Google.
  • Subscription and purchase information: your subscription status, plan, entitlements, and transaction identifiers, processed to manage Glyph Pro. Payment card details are handled by the app store or payment processor, not by Fortaify.
  • Diagnostics and crash data: crash reports, error events, performance samples, and related technical and device or installation identifiers, used to diagnose and fix problems. Our error monitoring is configured to scrub message and prompt content.
  • Support and communications: messages, attachments, and contact details you send us voluntarily.
  • Website information: standard web session, security, and usage data needed to operate the website and prevent abuse.
  • Organization information (Glyph Enterprise): if your organization uses Glyph Enterprise, we process the organization record, membership and role, seat assignment, contract and entitlement state, enrolled device registrations, and the policy versions published by your administrators.
  • Security event metadata (Glyph Enterprise): when organization policy is active, enrolled devices report metadata about policy decisions — the classification found, the action taken, the actor, the destination, the policy version, and a timestamp. These events are metadata only. They deliberately do not contain your prompts, documents, matched text, secrets, or regulated content.
  • Cloud Relay content: if you enable Cloud Relay, the messages exchanged between your phone and your desktop are written to rows in our infrastructure so your desktop can collect them. This is content, not just metadata, and it is described further in Section 4.

4. Information Processed On Your Device

The following are processed and stored on your device and are not collected by or transmitted to Fortaify:

  • Your prompts, conversations, and AI responses.
  • Documents and images you attach, and your retrieval (RAG) knowledge bases.
  • Your memories, personas, preferences, and downloaded models.

Several optional features send this content outside your device. Each is off unless you turn it on or select it:

  • Cloud AI models. If you select a cloud model instead of a local one, your prompt, attachments, and any retrieved context you include are sent to that provider under its own terms and privacy policy. Fortaify does not receive that content, and we do not control the provider's retention or training practices. The app names the destination before you send.
  • Internet search and page fetching. Your search query is sent to our search provider, and any page you fetch is requested from that website. Disable the feature if you do not want queries sent.
  • Local-network sync (GlyphNet). Content moves directly between your own devices on your network and is not sent to Fortaify.
  • Cloud Relay. If you pair over Cloud Relay so your phone can reach your desktop from outside your network, the request and response messages — which include chat content — are stored as rows in our Supabase infrastructure until your desktop collects them. They are associated with your account and are subject to Section 11. Use local-network sync instead if you do not want this content stored by us.
  • Diagnostics. Crash and error reports are sent as described in Section 3. Our error monitoring is configured to strip request payloads, prompt content, and console and network breadcrumbs.

5. How We Use Information

We use information to:

  • Provide, secure, and support the Services, and operate your account.
  • Process subscriptions, entitlements, and related transactions.
  • Diagnose crashes, improve reliability, and prevent fraud and abuse.
  • Communicate with you about the Services and respond to support requests.
  • Comply with legal obligations and enforce our Terms.

6. Legal Bases (EEA/UK)

Where the GDPR or UK GDPR applies, we process personal information to perform our contract with you (providing the Services and subscriptions), based on our legitimate interests (security, abuse prevention, and improving reliability), to comply with legal obligations, and, where required, based on your consent, which you may withdraw at any time.

7. Service Providers and Sub-processors

We share limited information with vendors that process it on our behalf, under contracts that restrict their use of it:

  • Supabase — authentication and database for accounts and entitlements.
  • RevenueCat — subscription and entitlement management.
  • Sentry — crash and error monitoring (message and prompt content is scrubbed).
  • Apple and Google — sign-in and app-store payment processing for their platforms.
  • DuckDuckGo — the provider used for optional internet search results.
  • Cloudflare — cookieless web analytics for our website (page views and page-performance measurements). It does not use cookies, does not fingerprint visitors, and does not build a profile of you across sites.
  • Hosting and infrastructure providers — website hosting and backend infrastructure.

Cloud AI model providers you choose in the app are not our sub-processors. They receive content because you selected them as a destination, and they act under their own terms with you. Our current sub-processor list, including the role each provider plays, is published in this policy and in the Trust Center. Automated change-notification subscriptions are in development; material changes to the register are announced in the Trust Center.

These providers are service providers or processors acting on our behalf and are not permitted to use your information for their own purposes.

8. How We Share Information

We do not sell your personal information. We may share information:

  • With the service providers described above, to operate the Services.
  • To comply with law, legal process, or lawful government requests, and to protect rights, safety, and security.
  • In connection with a merger, acquisition, financing, or sale of assets, subject to this policy.

9. AI Training

We do not use your private, on-device Glyph content to train Fortaify models. Local AI models run on your device and are not used to send your content to us for training. We do not train on Cloud Relay content or on organization security events. We may use aggregated, de-identified operational data to improve reliability and prevent abuse. If you send content to a third-party cloud model, that provider's training and retention practices are governed by your agreement with them, not by this policy.

10. Cookies and Analytics

On our website we use cookies for sign-in sessions and security. For measurement we use Cloudflare Web Analytics, which is cookieless: it records page views and page-performance metrics without setting a cookie, without fingerprinting your device, and without identifying you or following you to other sites. We also use Google Analytics on the website, which does set cookies. You can control cookies through your browser settings where available. Analytics is not used inside the Glyph desktop or mobile apps.

11. Data Retention

We retain account and subscription information for as long as your account is active and as needed to provide the Services, and afterward only as required for legal, tax, security, fraud-prevention, and dispute-resolution purposes. Diagnostic data is retained for a limited period. On-device content remains under your control on your device until you remove it.

Cloud Relay messages are retained in our infrastructure while a pairing is active. Removing the pairing or deleting your account removes them; you can also avoid this storage entirely by using local-network sync instead.

Under Glyph Enterprise, your organization sets retention for content on enrolled devices. A no-retention policy keeps conversation content in memory only and disables the titles and summaries that would otherwise reconstruct it. Organization security events are metadata only and are retained for the period your organization's contract specifies. Legal-hold administration is available: an active hold is delivered to enrolled devices in the signed policy and preserves in-scope data from the deletion paths that enforce holds. Coverage across every persistence path is still being completed.

12. Data Security

We use administrative and technical safeguards, including TLS 1.2 or higher for the website and API. At-rest encryption is provided by the hosting and database providers and depends on the selected plan; we do not claim application-level field encryption. Organizations that self-host the software control their own TLS, database encryption, and key management. No system is completely secure; please keep your device, operating system, and account credentials protected.

13. Organization Accounts (Glyph Enterprise)

If you use Glyph through an employer, school, firm, or other organization under a Glyph Enterprise contract, that organization administers your use of the Services and acts as the controller of the information described in this section. We process it on their behalf under our agreement with them.

  • Your administrator sets the rules. They publish a signed policy that your enrolled device enforces: which AI destinations you may send content to, which file types are blocked, whether conversation content may be stored, and what happens when policy is unavailable. These rules apply to your use of the app and cannot be turned off from within it.
  • What your administrator can see. Security events are metadata: that a classification was found, what action policy took, which destination was involved, which device and account it came from, and when. Your administrator does not receive your prompts, your documents, your conversations, or the text that triggered a decision.
  • Devices. Enrolled devices are registered with your organization, and your administrator can revoke a device, which removes its access and its cached organization policy.
  • Your rights. Requests to access, correct, or delete information held under your organization's account are directed to that organization. We will refer you to them and support them in responding.

A Data Processing Addendum is available to organization customers. Where an organization requires a Business Associate Agreement, that is handled through the Enterprise Regulated contracting and compliance-review process; it is not available through self-service purchase.

14. Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to restrict or object to certain processing, and to withdraw consent. To exercise these rights, contact support@fortaify.com or use the account-deletion resource below. We will not discriminate against you for exercising your rights.

California residents: under the CCPA/CPRA you have the right to know, delete, and correct your personal information, and to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.

15. Deleting Your Account and Data

You can delete your account and associated personal data from within the app in Settings, or from the web at fortaify.com/delete-account without needing the app. We will process deletion requests and may retain a limited amount of information only where required for legal, security, or fraud-prevention purposes.

16. International Data Transfers

Fortaify is operated in the United States. If you access the Services from outside the United States, your information may be processed in the United States or by our compliant service providers, using appropriate safeguards where required by law.

17. Children

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will delete it.

18. Third-Party Links and Services

The Services may link to or integrate third-party websites and services with their own privacy practices. This policy does not cover those third parties, and we encourage you to review their policies.

19. Changes to This Policy

We may update this policy as our practices evolve. We will update the effective date above and provide reasonable notice of material changes.

20. Contact

For privacy questions or requests, contact support@fortaify.com.