Privacy Policy

LAST UPDATED · 25 JULY 2026
This policy explains what Glowbit collects, why, who we share it with, and what you can demand from us. It describes what the product actually does — every item below maps to a real field in our database or a real request to a named provider.

1. Who we are

Glowbit is operated by SUNIKO ("we", "us"). SUNIKO is the data controller for the personal data described here.

For anything in this policy — access, deletion, complaints, questions — write to [email protected]. We answer within 30 days, as required by the GDPR.

2. What we collect

Account data. When you sign up we store:

  • Your name and email address.
  • Whether your email has been verified.
  • A cryptographic hash of your password — never the password itself.
  • Your profile image URL, if you set one.
  • Account creation and update timestamps.

Session data. Each time you sign in we create a session record containing a session token, its expiry, the IP address the request came from, and the browser user agent string. We keep this to let you stay signed in, to show you your active sessions, and to investigate suspicious sign-ins.

Content you create. Displays and their configuration (text, styles, palettes, animations), playlists, schedules, walls and their layouts, canvas artwork, and the public share identifiers you generate. This is the substance of the service; we process it to store it, render it, and deliver it to the screens you connect.

Connected screen data. When you pair a TV, browser or kiosk, that device reports its own screen resolution, pixel density and browser user agent so we can render your sign correctly on it. We store this alongside the screen record together with a pairing token and last-seen timestamps.

Billing data. If you subscribe, we store your subscription status, plan, renewal date and the identifiers our payment provider gives us. Card numbers and payment credentials never reach our servers — they are handled entirely by Lemon Squeezy, which acts as merchant of record for the sale.

API keys and referrals. If you create API keys we store their hashed form and metadata. If you take part in the referral programme we store the link between the referring and referred accounts.

Support correspondence. If you email us, we keep that message and our reply so we can follow up.

Analytics. If — and only if — you consent, Google Analytics sets cookies and collects usage data such as pages viewed, approximate location derived from IP, device type and referring site. Decline and none of this is collected; the product behaves identically.

4. Cookies and local storage

Strictly necessary. A session cookie keeps you signed in. Without it the product cannot work, so it is set without consent — as the ePrivacy rules allow.

Analytics. Google Analytics cookies are set only after you accept them. They are not set by default and they are not set at all if you decline.

Local storage. We keep a few small values in your browser rather than on our servers: your active workspace, unsaved editor drafts, which product tours you have seen, your cookie choice, and — on a paired screen — that screen's pairing token. These never leave your device except where the product needs them to serve a request.

Public share pages and the TV player load no analytics at all: they are broadcast surfaces, not visits.

5. Who we share data with

We do not sell personal data and we do not share it for advertising. We use a small set of providers who process data on our instructions:

  • Hetzner (Germany) — hosting and database storage. Your account data and content live on servers in the European Union.
  • Lemon Squeezy (United States) — payments and subscription management, as merchant of record. They receive your billing details directly.
  • Resend (United States) — transactional email such as verification, password reset and welcome messages. They receive your email address and the message content.
  • Sentry (United States) — error monitoring. Crash reports may include your account identifier and the URL where the error happened; we strip authentication headers and tokens before sending.
  • Google Analytics (United States) — usage measurement, only with your consent.

We may also disclose data where the law compels us to, or to establish or defend legal claims.

6. International transfers

Our servers are in Germany, inside the EU. Lemon Squeezy, Resend, Sentry and Google are based in the United States, so using them involves transferring personal data outside the European Economic Area. Those transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

7. Retention

  • Account data and content: kept while your account exists.
  • Sessions: deleted when they expire or when you sign out.
  • Deleted displays, walls and canvases: removed from our database when you delete them.
  • Billing records: kept as long as tax and accounting law requires, typically longer than the account itself.
  • Error reports: retained by Sentry for up to 90 days.
  • Analytics: retained by Google for up to 14 months.

Delete your account and we remove your personal data and content, except where we are legally required to keep records. Backups roll off on their own schedule.

8. Your rights

If you are in the EEA or the UK you have the right to:

  • Access the personal data we hold about you.
  • Correct data that is wrong or incomplete.
  • Delete your data (the “right to be forgotten”).
  • Restrict or object to how we process it, including on legitimate-interest grounds.
  • Receive your data in a portable, machine-readable form.
  • Withdraw consent for analytics at any time, without giving a reason.
  • Complain to your national data protection authority.

Write to [email protected] to exercise any of these. We will not charge you or make the service worse because you did.

9. How we protect data

Traffic runs over TLS. Passwords are stored only as hashes. API keys are stored hashed. Authentication headers and tokens are stripped from logs and crash reports before they leave our servers. Access to production systems is limited to people who need it.

No system is perfectly secure. If a breach affects your rights, we will notify the relevant authority within 72 hours and tell you directly where the law requires it.

10. Children

Glowbit is not intended for children. You must be at least 16 years old to create an account. If we learn we hold data from someone younger, we delete it.

11. Changes to this policy

We may update this policy as the product changes. The date at the top always reflects the current version. For changes that materially affect your rights we will tell you by email or in the product before they take effect.

12. Contact

SUNIKO — [email protected]

See also our Terms of Service.