Effective September 5, 2026
Fortaify builds privacy-first AI. This policy explains what information we collect, what stays on your device, how we use and share information, and the rights you have. It applies to the Fortaify website, the Glyph desktop application, and the Glyph mobile application (together, the "Services").
Local models run on your device. Content leaves only through features you turn on, and this policy names each one.
We collect only what we need to run accounts, subscriptions, and reliability.
We do not sell your personal information or train our models on your content.
Fortaify, operated by Tao Creative Labs LLC, provides the Services and is the controller of the personal information described here. You can reach us about privacy at support@fortaify.com.
Glyph is designed so that AI inference and generation can run entirely on your device. When you use a local model, your prompt and its response are not sent anywhere. We limit server-side collection to what is needed to operate accounts, process subscriptions, keep the Services reliable and secure, and support you.
Some features send content outside your device by design. That happens when you choose a cloud AI model, use internet search or page fetching, use Cloud Relay to reach your desktop from elsewhere, or use an organization feature that reports security metadata. Section 4 lists each of these and what it sends.
We collect the following categories of information:
The following are processed and stored on your device and are not collected by or transmitted to Fortaify:
Several optional features send this content outside your device. Each is off unless you turn it on or select it:
We use information to:
Where the GDPR or UK GDPR applies, we process personal information to perform our contract with you (providing the Services and subscriptions), based on our legitimate interests (security, abuse prevention, and improving reliability), to comply with legal obligations, and, where required, based on your consent, which you may withdraw at any time.
We share limited information with vendors that process it on our behalf, under contracts that restrict their use of it:
Cloud AI model providers you choose in the app are not our sub-processors. They receive content because you selected them as a destination, and they act under their own terms with you. Our current sub-processor list, including the role each provider plays, is published in this policy and in the Trust Center. Automated change-notification subscriptions are in development; material changes to the register are announced in the Trust Center.
These providers are service providers or processors acting on our behalf and are not permitted to use your information for their own purposes.
We do not sell your personal information. We may share information:
We do not use your private, on-device Glyph content to train Fortaify models. Local AI models run on your device and are not used to send your content to us for training. We do not train on Cloud Relay content or on organization security events. We may use aggregated, de-identified operational data to improve reliability and prevent abuse. If you send content to a third-party cloud model, that provider's training and retention practices are governed by your agreement with them, not by this policy.
On our website we use cookies for sign-in sessions and security. For measurement we use Cloudflare Web Analytics, which is cookieless: it records page views and page-performance metrics without setting a cookie, without fingerprinting your device, and without identifying you or following you to other sites. We also use Google Analytics on the website, which does set cookies. You can control cookies through your browser settings where available. Analytics is not used inside the Glyph desktop or mobile apps.
We retain account and subscription information for as long as your account is active and as needed to provide the Services, and afterward only as required for legal, tax, security, fraud-prevention, and dispute-resolution purposes. Diagnostic data is retained for a limited period. On-device content remains under your control on your device until you remove it.
Cloud Relay messages are retained in our infrastructure while a pairing is active. Removing the pairing or deleting your account removes them; you can also avoid this storage entirely by using local-network sync instead.
Under Glyph Enterprise, your organization sets retention for content on enrolled devices. A no-retention policy keeps conversation content in memory only and disables the titles and summaries that would otherwise reconstruct it. Organization security events are metadata only and are retained for the period your organization's contract specifies. Legal-hold administration is available: an active hold is delivered to enrolled devices in the signed policy and preserves in-scope data from the deletion paths that enforce holds. Coverage across every persistence path is still being completed.
We use administrative and technical safeguards, including TLS 1.2 or higher for the website and API. At-rest encryption is provided by the hosting and database providers and depends on the selected plan; we do not claim application-level field encryption. Organizations that self-host the software control their own TLS, database encryption, and key management. No system is completely secure; please keep your device, operating system, and account credentials protected.
If you use Glyph through an employer, school, firm, or other organization under a Glyph Enterprise contract, that organization administers your use of the Services and acts as the controller of the information described in this section. We process it on their behalf under our agreement with them.
A Data Processing Addendum is available to organization customers. Where an organization requires a Business Associate Agreement, that is handled through the Enterprise Regulated contracting and compliance-review process; it is not available through self-service purchase.
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to restrict or object to certain processing, and to withdraw consent. To exercise these rights, contact support@fortaify.com or use the account-deletion resource below. We will not discriminate against you for exercising your rights.
California residents: under the CCPA/CPRA you have the right to know, delete, and correct your personal information, and to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.
You can delete your account and associated personal data from within the app in Settings, or from the web at fortaify.com/delete-account without needing the app. We will process deletion requests and may retain a limited amount of information only where required for legal, security, or fraud-prevention purposes.
Fortaify is operated in the United States. If you access the Services from outside the United States, your information may be processed in the United States or by our compliant service providers, using appropriate safeguards where required by law.
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will delete it.
The Services may link to or integrate third-party websites and services with their own privacy practices. This policy does not cover those third parties, and we encourage you to review their policies.
We may update this policy as our practices evolve. We will update the effective date above and provide reasonable notice of material changes.
For privacy questions or requests, contact support@fortaify.com.