Privacy Policy
This policy explains what Gloss Read at https://www.glossread.com ("the Service") collects, why, and who else sees it. The Service is operated by Bart Solutions Limited, EASEY COMMERCIAL BUILDING, 253-261 HENNESSY ROAD, WANCHAI, HONG KONG ("we", "us"), the data controller for the purposes of this policy.
1. What we collect
Your email address. Given when you sign in. It identifies your account and is the only personal detail we ask for.
Sign-in codes. A six-digit code, stored only as a hash, valid for ten minutes, with a count of wrong attempts. We never store passwords.
The passages you read. The text you paste, the gloss, translation and any AI explanations or proofreading made from it, and the language pair used. These are kept so your history works and reopening a passage costs you nothing.
Usage records. The number of characters each passage and each AI answer counted as, and when. These are what your monthly allowance is measured against, and they remain after a passage is deleted.
Billing details. If you subscribe, we store your Stripe customer and subscription identifiers, your plan, its status and its period. Card details go to Stripe directly; we never see or store them.
Your settings. The toolbar switches, the pronunciation mode, the reading speed, the interface language, and whether you have seen the one-time notices about what AI answers cost.
Technical records. Ordinary web server logs, and our own application log, which records what the glossing pipeline did. The application log includes the text of sentences being processed, so that a problem can be diagnosed afterwards. It rotates automatically (currently [2 MB, three files kept]), so these entries are short-lived.
We do not use advertising or third-party analytics, and we do not build profiles of you.
2. Why we may use it
Purpose What it covers
Providing the Service Glossing your passages, keeping your history, remembering your settings
Signing you in Sending and checking the code, keeping you signed in
Billing Plans, allowances, payments through Stripe
Keeping it working Diagnosing failures, preventing abuse and excessive use
Legal obligations Accounting records, responding to lawful requests
Where the law requires a legal basis (for example the GDPR), ours is: performing our contract with you (providing the Service and billing), our legitimate interests (keeping the Service working and preventing abuse), and legal obligation (records we must keep).
3. Who else sees your data
We do not sell your data. We share it only with the providers that make the Service work:
Provider: What it receives What for
DeepSeek: The passage text you gloss, and the sentence you ask about Producing the gloss, translation, explanations and proofreading
Stripe: Your email address, plan and payment details you enter with them Taking payment and managing subscriptions
Resend: Your email address and the sign-in code Delivering the sign-in email
Alibaba Cloud, Singapore: Everything stored by the Service Hosting the server and database
These providers operate in other countries, including mainland China, the United States, Ireland and Singapore, so your text and email address are processed outside Hong Kong. We share only what each provider needs.
A note on identical passages. To avoid glossing the same text twice, a gloss is stored against the exact text, language pair and AI model that produced it, and may be served to any account that submits exactly the same text in the same pair. Two people who paste the same page of a book see the same stored gloss; nobody can browse another account's history, and a passage you delete is never served again. Please do not paste confidential material.
4. How long we keep it
Passages and their glosses: until you delete them, or your account is closed. Deleting a passage removes its text, translation and explanations immediately; the character counts stay, so your usage record remains correct.
Usage and billing records: for as long as needed for accounting and tax, typically seven years.
Sign-in codes: ten minutes, then they are useless; the rows are cleared periodically.
Your account: until you ask us to close it.
5. Cookies and local storage
We use no advertising or tracking cookies. What the Service sets is:
Name Purpose Lasts
sessionid Keeps you signed in 30 days
csrftoken Protects forms and requests from cross-site abuse 1 year
glossread_lang Remembers your interface language 1 year
glossread.session (browser storage, not a cookie) Keeps the passage you were reading on this device, so it is there after a refresh Until you clear it or open another passage
Clearing your browser storage removes the last item; the Service still works.
6. Your choices and rights
See and correct your data. Your passages and usage are visible in the app; write to us for anything else.
Delete passages yourself, at any time, from the history panel.
Close your account by writing to [email protected]; we delete your passages and glosses, keeping only what accounting or law requires.
Complaints: you may complain to your data protection authority — in Hong Kong, the Office of the Privacy Commissioner for Personal Data.
7. Security
Traffic is served over HTTPS. Sign-in codes are stored hashed and expire, and there are no passwords to steal. Access to the server and database is limited to [the people who run the Service]. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authority as the law requires.
8. Children
The Service is not directed at children under 12. If you believe a child has given us personal data, write to [email protected] and we will delete it.
9. Changes to this policy
We may update this policy. The date at the top shows when it last changed. If a change materially affects how we use your data, we will give notice by email or on the website.
10. Contact
Email: [email protected]
