Glimmer — Privacy Policy
Version 1.3 · Last updated 27 September 2026 · Glimmer, by Bitlitic LLC
Glimmer is made by Bitlitic LLC ("Bitlitic", "we", "us"), and Bitlitic is the operator — the "controller", in European terms — responsible for the data described here. The Terms of Use cover the rest of the agreement — what the app is, what a subscription buys, and what a reflection is not.
The short version
Glimmer is a journal that works entirely on your phone. Your writing is stored on your device and stays there unless you do one of two specific things:
- Seal a day with AI reflections on. Sealing sends that day's text to a language model so Glimmer can read it back to you. The app asks for your permission before the first time, and you can turn AI reflections off in Settings at any time. Nothing is stored on our servers in the process, and your writing is never used to train models.
- Subscribe and sign in. That turns on cloud sync, which keeps an end-to-end encrypted copy of your entries so they survive a lost phone. We cannot read it.
If you turn AI reflections off, or never seal a day, and never sign in, nothing you write leaves your phone.
The free version also shows ads, and Glimmer Plus removes them. Ads never see anything you wrote, and they are non-personalised — Glimmer does not track you across other apps and never asks for permission to. See Ads below.
Usage and crash data never include anything you wrote, and you can switch them off in Settings. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
What leaves your phone, and what does not
| What | Leaves your phone? |
|---|---|
| Your journal entries | Only in the two cases above: a reflection you asked for, or the encrypted sync copy |
| Your voice, when you dictate | No audio ever reaches us — see Speaking instead of typing |
| Text read aloud | No. The voice runs on your phone |
| Reminders and tips notifications | No. They are scheduled on your phone and never contain your writing |
| Usage and crash data | Yes, unless you switch it off — and it never contains your writing |
| Ad requests (free plan) | Yes, but they never contain your writing and are non-personalised |
What we collect
Your journal entries
Written to your device first, always, in the app's own storage on the phone. That storage is protected by your phone's operating system and passcode, like any other app's; Glimmer does not add a second layer of encryption to the copy on the phone, though you can put the app behind Face ID, Touch ID or your device passcode with Settings → Privacy → App lock. Two things can send your entries further:
Sealing a day, with AI reflections on, posts that day's text and its mood, along with the profile answers described below (including, on Glimmer Plus, the persona you chose), to our server, which passes them to a third-party language-model provider — currently DigitalOcean Gradient serverless inference, running open models such as GLM and DeepSeek, with AI/ML API (aimlapi.com) as a backup if that is unavailable — and returns the reflection. Our server does not store any of it; it holds it only for the length of the request. The provider acts as our service provider and processes it only to produce the reflection; its own retention policy applies to what it receives, and we do not control it. We do not use your writing to train models. See AI reflections for how you consent and how to switch them off.
Cloud sync, available with a Glimmer Plus subscription and only while you are signed in, stores your entries in Google Cloud Firestore under your account (
users/{uid}/entries/{date}) — end-to-end encrypted. Each entry is sealed on your phone with AES-256-GCM before it is sent, using a key held only on your device and surfaced to you once as a recovery code. We cannot read your entries, and we cannot reset that code: lose it and the synced copy cannot be recovered by anyone, including us. The copy on your phone is unaffected. What our servers can see is which dates you have entries for and when they last synced — never their contents.Note the boundary between these two bullets: storage is end-to-end encrypted, but asking for a reflection deliberately sends that day's text, because a model cannot read ciphertext.
What you tell us about yourself
When you start, Glimmer asks what to call you, your pronouns, how you would like to be spoken to, and — if you want — what you would like it to notice. They exist so a reflection comes back in the voice you chose and about the things you asked it to notice, so each reflection request sends them with that day's text to the language-model provider described above, only the ones you filled in. Like the text, they are used for that one request and not kept by our server.
If you have Glimmer Plus and choose who your reflections sound like (Settings → Who reads it back — for example "Mother" or "Best friend"), that choice is sent with each reflection request, alongside the other profile answers, so the model can write in that voice. It is a label from a fixed list, not anything you type. It is stored with your account like your other profile answers, kept if your subscription lapses, and not used for anything else. Glimmer never asks who the real people in your life are, and the persona is not modelled on any real person.
If you are signed in they are stored with your account so your next phone knows them too. If you are not, they stay on this device like everything else.
Your account
Accounts are optional: Glimmer works fully without one. If you create one, whether with an email and password, through Sign in with Apple, or through Google, it is managed by Firebase Authentication, a Google service acting as our service provider. It holds your email address, a user id, the sign-in method you used and, for an email account, a securely hashed password that we never see. We use it to identify you across devices.
Firebase Authentication also sends the emails that verify your address and reset your password. You can change your password in the app, and Log out everywhere signs every device out of your account at once, which revokes their sign-in sessions on our side.
Purchases
Subscription status is handled by RevenueCat, as our service provider, and by the App Store or Google Play, which take the payment under their own terms. We receive whether you have an active subscription; we never see your payment details. RevenueCat identifies you by your account id.
When RevenueCat confirms a payment, our server also adds it to aggregate revenue figures in Bitlitic Ops, our own analytics system (see Usage analytics): the product id, the store, the amount and the currency. No card or payment details, and no account id.
Reports about a reflection
Every reflection has a Report this reflection button, for a reading that was wrong, hurtful or inappropriate. A report sends us the reflection's text and the reason you picked — the words the model wrote, not the words you wrote. Your journal entry is never included in a report. Reports are stored on our server so a person can review them and improve how reflections are written, and are deleted after 12 months at the latest.
Usage analytics
Glimmer uses Firebase Analytics, a Google service acting as our service provider, to understand how the app is used — which screens are opened, how often a day gets sealed, whether a reflection came back successfully, and which plan someone is on. If you are signed in, these events are recorded against your account id so we can tell one person's usage from another's.
None of it ever includes what you wrote. No entry text, no reflection, no mood or reading of your mood, no name, nothing from the onboarding questions, nothing you searched for. Analytics events carry only counts and fixed labels — "a day was sealed, it had 3 pages and 412 words". The current event call sites do not send journal or profile text. A length filter also discards longer strings, but does not replace reviewing each event.
Firebase Analytics also processes app-instance and device identifiers (on Android, including the advertising ID), device and app information, and approximate geography derived from network information. Ad display (which placement showed an ad, and the revenue Google reports for it) and rewarded-edit events are included in our usage analytics.
We also never send the date you journalled about. Screen names are recorded as patterns, so the editor is entry/[date] and never the day itself.
The same screen views and events — plus a few of our own, such as finishing onboarding, seeing the Glimmer Plus offer, or completing a purchase (with its product id, price and currency) — also go to Bitlitic Ops, our own analytics system. It is a self-hosted copy of Umami, at analytics.ops.bitlitic.com, that Bitlitic runs itself on a virtual server rented from Hostinger in Boston, USA. With each event it receives your phone's operating system and device type, screen size and language, the app version, and an approximate location (country, region and city) worked out from your IP address. It does not store the IP address itself — visits are grouped using a hash that changes every month — and it receives no advertising identifier, no account id, no name or email, and nothing you wrote. Bitlitic Ops data is not sold or shared with third parties, and is not used for advertising or to follow you across other apps or websites.
Our website, bitlitic.com — including these Glimmer pages — measures its own visits with Bitlitic Ops too. What it records, and for how long, is described in the Bitlitic website privacy policy.
You can switch it off. Settings → Share usage & crash data is on by default; turn it off and Glimmer stops sending analytics events and crash reports from that phone, to Firebase and to Bitlitic Ops alike. Bitlitic Ops sends nothing until the app knows your answer, and nothing if it is off. Nothing else in the app changes.
Crash reports
If the app crashes, or hits an error it cannot recover from, Firebase Crashlytics, a Google service acting as our service provider, sends a report so we can find and fix it: the technical trace of where it failed, your phone model, operating system and app version, and a random installation identifier. Reports are not linked to your account, and they never include what you wrote. Development builds send none. The same Share usage & crash data switch turns them off.
Errors are also reported to Bitlitic Ops, our own error reporting: the app sends them with OpenTelemetry to otel.ops.bitlitic.com, and they are stored in our own Grafana stack on the same Hostinger server in Boston. A report carries the error message, the stack trace, your platform and operating system, and the app version — no account id, no name or email, nothing you wrote. The same switch turns these off too.
Our API server sends Bitlitic Ops its own technical request logs, traces and performance metrics, so we can see when it is slow or failing. Like any server log, these can include the IP address a request came from, and for a few account actions (such as signing out of every device) your account id. They never include the body of a request, so never the text of a day you sent for a reflection.
Ads
The free version of Glimmer shows ads, supplied by Google AdMob. These are the only places they appear:
- On the dashboard and on Insights — one ad, marked "Ad", shown as a card among your graphs or between past reflections. It is never shown next to support or crisis information.
- In the calendar — a banner inside the list of days: one after your first week, then at most one a month, between months, as you scroll further back. They are hidden while you are searching.
- After you seal a day — one full-screen ad, once the day is already saved, never before.
- When you choose to watch one, to reopen a sealed day for editing. That one is always your choice, and nothing happens if you skip it.
- Now and then while you browse — one full-screen ad after several moves between the tabs, at most once every few minutes, and only as you arrive on the dashboard or the calendar.
- When you come back to Glimmer — one full-screen ad, at most once every four hours, when you return to the dashboard or the calendar after being away for a while. Never the first time you use the app, never when you open it from a reminder, and never if app lock is on.
Every full-screen ad can be closed, and there are always at least three minutes between any two of them.
There are never ads in the editor while you write. Glimmer Plus removes all of them.
Ads never see what you wrote. Google is not sent your entries, your reflections, your mood, your name, or anything from the onboarding questions. No journal content of any kind reaches an ad request.
The ads are non-personalised. Glimmer asks Google for non-personalised ads on every request, without exception, and never asks for permission to track you across other apps — which is why iPhone never shows you the "Allow Glimmer to track you?" prompt. Non-personalised ads are chosen from the context they appear in rather than from a profile of you, so what you see is not based on your interests or your history in other apps.
Google's ad SDK processes IP addresses (which can estimate approximate location), device identifiers, ad and app interactions, and diagnostic/performance data. It uses this information for advertising, measurement and fraud prevention, under Google's privacy policy. Non-personalised advertising does not mean no device data is collected. In regions where consent is required, the app requests a consent form before ads, and you can change your answer at any time in Settings → About → Ad privacy choices.
Checks that the app is genuine
When the app talks to our server, it attaches a short-lived token showing that it is a genuine, unmodified copy of Glimmer. The token comes from Google's Firebase App Check, which asks Apple's App Attest on iPhone, or Google Play Integrity on Android, to vouch for the app. This is what keeps other people from using our reflection service without the app. The check is about the app and the device, not about you, and it never carries anything you wrote. Apple and Google process what they need to answer under their own privacy policies. Our server records only whether a request passed and which of our apps sent it, never the token, your account, or what you wrote.
Reminders and tips notifications
Glimmer's notifications are local notifications, scheduled on your phone itself. Nothing about them is sent to us or to a push service, and Glimmer has no push token for your device. There are three kinds, and each is a separate choice in Settings that is off until you turn it on:
- Daily reminder — a short nudge at the time you pick.
- Last-call nudge — an optional second line late in the evening, only if that day's page is still blank.
- Tips & Glimmer Plus — occasional tips about using Glimmer, at most once a week. For the free plan these may include a note about Glimmer Plus; subscribers get tips only. You are asked to agree to these separately before they are switched on.
Their text is fixed copy that never includes anything from your journal — not your words, your mood or your reflections. To choose which line to show, the app looks only, on the phone, at whether today already has an entry, how many days in a row you have written, and whether a recent reflection was flagged as sensitive (in which case the notifications stay plain and tips pause for a week). None of that leaves your phone. Turn any of them off, or change the reminder's time, in Settings; "Delete all data on this device" cancels every one that is scheduled.
What we do not collect
We do not request precise GPS location or access to your contacts. Approximate location and SDK diagnostic data are processed as described above. We do not sell your journal or share it with data brokers, and nothing you write is ever used to target advertising — not to you, and not to anyone else.
We do not ask for the iPhone advertising identifier (IDFA) and never request permission to track you across other companies' apps or websites.
On Android, Google's ad system does use your device's advertising ID — to stop you seeing the same ad repeatedly and to detect fraud, not to build a profile of you. Firebase Analytics reads it too, to measure how the app is used. You can reset it, or switch it off entirely, in Settings → Google → Ads on your phone.
AI reflections: your choice
Reflections are optional, and they are the one feature that deliberately sends your writing off the phone, so Glimmer asks first.
- Consent. Before the first reflection is requested, the app explains what will be sent (that day's text, its mood and the profile answers you filled in), who it goes to (our server and the language-model provider named above), and that it is not stored by us or used for training — and asks you to agree. Nothing is sent unless you do.
- Switching it off. Settings → AI reflections turns them off at any time. With it off, sealing a day still works and still saves the day; no entry leaves the phone for a reflection. You can turn it back on whenever you like, and withdrawing consent does not affect reflections you already have.
- Reporting. If a reflection is wrong or upsetting, tap Report this reflection. The report carries the reflection's text and your reason — never your entry — as described in Reports about a reflection.
Reading aloud happens on your phone
Glimmer's voice is a model that runs on your device. Text you have read aloud is never sent anywhere to be spoken — that is the reason for the one-time download the app asks you about before it starts.
Speaking instead of typing
You can dictate an entry rather than type it. Glimmer keeps no recording: the words land on the page as you say them, nothing is written to a file, and the microphone closes the moment you stop.
The listening itself is your phone's, not ours. On Android, Glimmer offers dictation only where the phone can transcribe offline, which is why it may first ask to download a language. On iPhone it uses Apple's dictation — the same one behind the microphone key on your keyboard — which stays on the device wherever iOS is able to, and otherwise passes what you said to Apple to be turned into text, under Apple's privacy policy rather than this one. On neither platform does the audio reach us.
Reflections, and the crisis safety net
A reflection is a piece of writing about your writing. It is not medical, psychological, or mental-health advice, and nothing in Glimmer is a substitute for a professional. If you are in danger, contact your local emergency services or a crisis line — in the US you can call or text 988.
Glimmer has a safety net for this: when a sealed day shows signs of a crisis, the reflection points you to a helpline and the app shows a card with ways to reach one straight away, alongside the usual reflection. It is worth being precise about what that is and is not. Two checks decide it, both inside the same request as the reflection: a check for specific phrases, and the language model's own reading of the entry, which is asked to point to a crisis line only when the writing shows real crisis. It changes what comes back to you and nothing else. No one reads your journal, and nothing is reported to anyone. Our server keeps no record of it: the flag is saved only with that day's reflection on your phone, and inside the end-to-end encrypted copy if you use cloud sync. With AI reflections switched off, this check does not run, because nothing is sent.
Who processes your data for us
Every company below works on our behalf, under a contract that limits what it may do with your data to providing its service to us — a service provider under US state privacy laws and a processor under the GDPR — except where the entry says otherwise.
| Company | What it does for Glimmer | Role |
|---|---|---|
| Google — Firebase Authentication | Accounts, sign-in, verification and password emails | Service provider / processor |
| Google — Cloud Firestore | Stores your account profile and the end-to-end encrypted sync copy | Service provider / processor |
| Google — Firebase Analytics | Usage analytics (can be switched off) | Service provider / processor |
| Google — Firebase Crashlytics | Crash reports (can be switched off) | Service provider / processor |
| Google — Firebase App Check | Confirms requests come from the genuine app | Service provider / processor |
| DigitalOcean — Gradient serverless inference | Writes reflections (primary language-model provider) | Service provider / processor |
| AI/ML API (aimlapi.com) | Writes reflections if the primary provider is unavailable | Service provider / processor |
| Hostinger | Hosts our API server, which relays reflection requests and stores reflection reports; and hosts the server in Boston, USA on which we run Bitlitic Ops, our own analytics and error reporting | Service provider / processor |
| RevenueCat | Tracks subscription status | Service provider / processor |
| Google — AdMob, and its consent tool | Serves non-personalised ads in the free version | Service provider / processor for ad serving; Google acts as an independent controller for some of its own purposes, such as fraud prevention and measurement, under its own policy |
| Apple (App Store, App Attest) and Google (Google Play, Play Integrity) | Take subscription payments; vouch that the app is genuine | Independent controllers, under their own privacy policies |
Bitlitic Ops is not a separate company: we run it ourselves, and Hostinger only provides the server it runs on. Nothing in it is sold or passed to anyone else.
We may also disclose information where the law requires it — for example, in response to a valid court order — or to protect the safety of a person or the security of the service, and to a successor if Glimmer changes hands, who would be bound by this policy.
Legal bases for processing
If you are in the European Economic Area, the United Kingdom or Switzerland, data protection law requires us to name the legal basis for each thing we do with your personal data. Here they are:
- Performing our contract with you (GDPR Art. 6(1)(b)):
- creating and running your account, including verification, password changes and Log out everywhere;
- storing and returning your end-to-end encrypted sync copy;
- checking and restoring your Glimmer Plus subscription;
- answering your support requests and account-deletion requests.
- Your consent (Art. 6(1)(a) and, because a journal can reveal things such as your health, your explicit consent under Art. 9(2)(a)):
- sending a sealed day, its mood and your profile answers to the language-model provider to write a reflection. You give it on the consent screen and withdraw it with Settings → AI reflections;
- where the law requires consent for ads, showing ads, through the consent form. You change it in Settings → About → Ad privacy choices.
- Our legitimate interests (Art. 6(1)(f)), balanced against yours:
- usage analytics and crash reports, to understand and fix the app. You can object at any time with Share usage & crash data;
- technical logs, traces and performance metrics from our server, to keep it running and find faults;
- showing non-personalised ads to pay for the free version, where consent is not required;
- checking that requests come from the genuine app, and rate-limiting, to keep the service secure and stop abuse;
- reviewing reflection reports you send, to make reflections safer and better.
- Legal obligations (Art. 6(1)(c)): keeping records and responding to lawful requests where the law requires us to.
Reminders, last-call nudges and tips notifications are processed only on your phone, so no legal basis on our side is needed for them.
International transfers
Bitlitic is based in the United States, and our service providers process data in the United States and other countries. When personal data from the European Economic Area, the United Kingdom or Switzerland is transferred to a country that has not been found to protect it adequately, we rely on the Standard Contractual Clauses approved by the European Commission (with the UK Addendum, and the Swiss adjustments, where they apply) in our agreements with those providers, or on another lawful mechanism, such as a provider's certification under the EU–US Data Privacy Framework. You can ask us for a copy of the relevant safeguards at the address in Contact.
Keeping and deleting
On your phone. Entries stay until you delete them. Deleting the app removes everything on the device. Nothing below touches this copy — it is yours, it is the original, and no decision we make about our servers reaches it.
On our servers. Synced entries and your account profile are kept for as long as the account exists. That is the whole retention rule, and these are the three edges of it:
- You delete the account (Settings → Account → Delete account) and your account and every entry synced to our servers are erased, permanently and immediately. The journal on your phone is deliberately left alone — the app never needed an account to hold it. Delete the app as well if you want that copy gone.
- Your subscription lapses and the synced copy is kept, so it is still there if you subscribe again. Sync stops; nothing is thrown away.
- The account goes quiet. An account with no sign-in for 24 months may be deleted, and we will email the account address first so it is never a surprise.
Reflection reports are kept for up to 12 months. Analytics events, which never contain anything you wrote, are retained by Firebase Analytics under Google's own retention settings for the property. Crash reports are kept by Firebase Crashlytics for 90 days. Purchase records are kept by RevenueCat, Apple and Google under their own policies, and deleting your account does not remove them.
In Bitlitic Ops, error reports and server logs are kept for 30 days and request traces for 14 days, then deleted automatically. Performance and revenue metrics are kept for up to 90 days, or less if their storage fills first. The Ops services' own operating logs are rotated out automatically once they reach a few tens of megabytes. Analytics events there, which never contain anything you wrote or your account id, are kept for 14 months and then deleted automatically.
Your rights
Everyone
You can see and take your writing at any time: Settings → Export produces a complete JSON backup or a printable PDF, without an account and without asking us. That is the access and portability route, and it is faster than any request we could answer.
You can delete your account and everything synced to it yourself, immediately, at Settings → Account → Delete account. If you cannot reach that control, email customer-service@bitlitic.com from your account's address and we will do it — the out-of-app route is written out at https://bitlitic.com/#/glimmer/delete-account. Note that deleting the account does not cancel an App Store or Google Play subscription; cancel that in the store.
And these switches are yours, in the app, at any time:
- Settings → AI reflections — stop sending entries for reflections.
- Settings → Share usage & crash data — stop analytics and crash reports.
- Settings → About → Ad privacy choices — change your ad consent, where it applies.
- On Android, Settings → Google → Ads on the phone — reset or delete the advertising ID.
European Economic Area, United Kingdom and Switzerland
You have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to our processing of it, to receive it in a portable format, and to withdraw consent at any time without affecting what was done before you withdrew it. You also have the right to complain to your local data protection authority, though we would like the chance to fix it first. We answer within one month.
United States
Depending on the state you live in — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and others with comprehensive privacy laws — you may have the right to:
- know what personal information we collect, use and disclose, and get a copy of it;
- have it corrected or deleted;
- opt out of the sale of your personal information, its sharing for cross-context behavioural advertising, and its use for targeted advertising or profiling;
- limit the use of sensitive personal information;
- not be treated differently for using any of these rights;
- appeal if we turn down your request.
We do not sell or share personal information for cross-context behavioural advertising, and we do not use it for targeted advertising or for profiling that produces legal or similarly significant effects. Every ad is non-personalised. Anything sensitive in your journal is used only to give you the reflection you asked for. So there is nothing to opt out of — but the switches above are there anyway, and you can also use Ad privacy choices and Share usage & crash data to limit what the ad and analytics SDKs receive.
In the last 12 months we have collected the categories described in What we collect: identifiers (email, account id, device and app-instance ids), commercial information (subscription status), internet or other electronic network activity (app usage and ad interactions), approximate geolocation derived from IP address, the content you choose to send (a sealed day for a reflection; an encrypted sync copy we cannot read), and the information you give about yourself during onboarding. We disclosed them for business purposes only to the service providers listed above.
To make a request, email customer-service@bitlitic.com from the address on your account, or tell us how to identify you if you do not have one. We verify a request by matching it to that address. You may use an authorised agent, who must show us your signed permission. We answer within 45 days. If we turn you down, reply to our answer to appeal, and we will respond within the time your state's law allows; if you disagree with the outcome, you can contact your state attorney general.
Security
Your connection to our server is encrypted in transit (TLS). The sync copy is end-to-end encrypted with a key only your devices hold. Our server does not store the text of your reflection requests, and our own staff cannot read your synced journal. The journal on your phone is protected by your phone's own security and, if you turn it on, Glimmer's app lock. No system is perfectly secure, and if something goes wrong that affects your data we will tell you and the authorities as the law requires.
Children
Glimmer is not directed at children under 13 and we do not knowingly collect their information. If you believe a child under 13 has given us personal information, write to us and we will delete it.
Changes to this policy
When this policy changes, we change the version and date at the top and post the new version at https://bitlitic.com/#/glimmer/privacy. If a change is material — for example, if more of your writing would leave your phone, or a new kind of company would receive it — we will tell you in the app before it takes effect, and ask again where your consent is needed.
Contact
Questions about privacy, your rights or account deletion can be sent to customer-service@bitlitic.com.
Bitlitic LLC, Ohio, United States.