Skip to content

Privacy

Typeglass is not released yet, so this page is shorter than it will be. It says what we hold today and what the product will hold when it ships.

Last updated 26 September 2026

On this page

1The short version

  • Typeglass is not released yet. For a visitor who is not signed in, this website does exactly one thing with personal data: it holds feature requests that shape the roadmap.
  • If you request a feature, we store the address and the request so we can prioritise what to build. Ask and we delete it.
  • This website does not store your IP address, your browser, or where you came from. To stop the feature request form being flooded, it counts submissions per minute under a one-way fingerprint of your address, made with a secret key the website holds and its database does not — so the database alone cannot turn it back into your address. That count is removed the next time anyone submits after the minute is up, and stays until someone does. The product's backend is a separate service, and it does keep one rate-limit key per caller — the bullet below says exactly what that is.
  • When the extension ships, your drafts, history and screen recordings live in your browser — not on our servers — and we never log the text you work on. Your settings and the short facts you ask the assistant to remember are kept with your account too, if you sign in, so they follow you to a second browser.

2What a feature request stores, precisely

One table: an address, a short title, a description, and optional capability tags. That is the whole list — a form that collects “just in case” is a breach waiting for a reason. Every field here changes what we build.

  • The address is never sold, never shared, and never added to a newsletter.
  • Email arti.shinde@thestackhub.com and we delete the row — not flag it, not archive it.
  • Our admin log keeps one line saying that a request was deleted, when and by whom. It holds your address only as a SHA-256 hash and a masked form like a••@example.com — enough to find that line if you ask about it — and nothing you wrote.
  • We may email you about this request only. If we ever want to send anything else, we will ask first.
WhatWhyHow long
Your email addressSo we can follow up if we need clarity, and so you can ask us to delete the requestUntil you ask us to remove it, or until the request is no longer needed for the roadmap
Title and description of the featureThis is what we read when deciding what to build nextThe same
Related capability tags — optionalHelps us cluster similar requestsThe same

3What the product will store

Typeglass is in development, so this describes what the software does today rather than a promise about a service you can buy. It is written down now because it is the reason the product is built the way it is.

  • Your drafts, translations, history and screen recordings stay in your browser's local storage. They are never uploaded.
  • Your settings are different, and only if you sign in: your profile, writing preferences and per-site rules are also kept with your account so a second browser starts where the first left off. You can delete that copy from the dashboard or the extension without losing the one on your device.
  • The text you ask it to rewrite, translate, summarise or explain passes through our backend to the model provider for that one request. It is not written to disk or to a database.
  • Before the first request that would send your text or image to our service, the extension shows a short notice and asks. Choosing Not now sends nothing; choosing Continue is remembered on that device.
  • The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. It is used only to do what you asked, and is never sold, used for advertising or used to train models.
  • A request also carries what it needs to answer the way you asked: the writing skills you switched on; on a follow-up, the earlier turns of that conversation (at most 12); for an Assistant run, your memory list and any image you attached or captured; and — only if you switch on “Use my bookmarks” for a Reply — the title, address, folder and your own note of up to five bookmarks you selected that match, never the pages themselves. None of it is stored.
  • Voice input is the one recording that leaves your device. Press the microphone and the clip you just spoke is sent to our backend and on to a speech-to-text model, which returns it as text — there is no on-device transcriber to fall back to. The audio is held for that one request and not retained, and nothing is captured until you press the button and grant Chrome's microphone permission.
  • The backend records that a request happened and how large it was — never what it said. One identifier travels with it: the key the request is metered against, which is your account id when you are signed in and a value derived from your IP address when you are not. It exists so an allowance can be counted and abuse traced, and it lives in the server logs for as long as our host keeps them.
  • Screenshots and chart images are read for one request and not retained. Text extracted from an image is held in memory for up to 24 hours so running the same image twice does not cost you a second request; it is capped, never written to disk, and gone when the process restarts.
  • Smart Bookmarks is off until you turn it on, and turning it on is what asks Chrome for permission to read your bookmarks — it is never requested at install. It files a bookmark on your device by default, using your browser's built-in model or an offline matcher. Only if you set its AI mode to “backend” does anything leave: the bookmark's title and URL, and the names of your existing folders, so the model reuses a folder of yours instead of inventing a near-duplicate. What the page itself says is read in your browser and is never part of that request.
  • When accounts exist, we will store a sign-in identifier, a plan, and a daily request counter — the minimum needed to honour an allowance.
  • If you buy a plan, you pay through Clerk Billing and Stripe processes the payment: you type your card into Stripe's own form, and it never reaches our servers. We keep which plan you are on, whether it is active, and when the current billing period starts and ends — not your card, your billing address or your Stripe account details.
  • Signed in, we also store the settings listed above, keyed to that identifier. Not your drafts, not your history, not your recordings — the preferences that decide how Typeglass writes.
  • The short facts you ask the assistant to remember are kept with your account when you sign in — up to 50 lines you typed yourself, 500 characters each, in the same database as the settings. They are content you write rather than a setting, which is why the dashboard shows you the whole list and deletes it with one button. Signed out, they never leave your browser.
  • The knowledge base is the reference material you give the assistant to look things up in — up to 200 entries of 2,000 characters each, with an 80-character name, kept with your account in that same database. When a reply uses it, the passages it drew on are part of what goes to the model provider for that request; nothing else in the base is sent. The dashboard shows every entry and deletes any of them, and it exists only while you are signed in.
  • Two pages on this site talk to the extension in your browser. The connect page asks whether it picked up the session you just created and shows you the answer; nothing is stored. The agent page asks only after you press “Continue on the web” in the extension: it collects what that panel was working on — the text, what you typed, and the answer if there was one — once, straight from the extension. The extension deletes its copy as it hands it over, it never travels in a link, and it reaches our backend only if you send it as a message. Neither page gets access to your drafts, history or settings.
  • Any diagram Typeglass draws can be opened in draw.io, Excalidraw or the Mermaid Live Editor, only when you click. draw.io and Mermaid get the diagram inside the link's #fragment: your browser never sends that part of a link to a server, nothing passes through our backend, and the editor's page reads it to draw the diagram (the link also stays in your browser history). Excalidraw, signed in to the extension, makes an end-to-end encrypted share link: the diagram is encrypted, the ciphertext is stored by Excalidraw's share service, and the key stays in the link. No model runs for it and it does not count against your allowance. Turn on “Never upload diagrams” and nothing is uploaded — the diagram is copied for you to paste into Excalidraw, with a .excalidraw download as well; that is also what happens signed out, and what this site's Excalidraw button always does. New tabs are opened without telling the destination which page you came from.
  • When you remove the extension, Chrome opens a goodbye page on this site. Its address carries nothing about you or your installation — no identifier, no version — so the visit is like any other page load, and the page asks for nothing. Builds without accounts do not set it.
  • Conversations on the web agent stay in this browser's local storage too, kept separately for each account signed in on it. They are not uploaded except as the one request you send, and the files you attach and the images it generates are not kept at all. Deleting your account clears them from the browser you delete it in; another browser keeps its copy until you clear this site's data there.

4Who else is involved

WhoWhat they receiveWhy
TursoYour feature request, if you submitted one. Signed in: your account settings, your memory list, your knowledge base and your daily request countHolds feature requests, and the account data that follows you between browsers
ClerkYour email address and sign-in identity. Its script also loads on every page of this site, so it sees the connection even from a reader who never signs inAccounts and sessions
Stripe, through Clerk BillingOnly if you buy a plan: your card details and the billing information its payment form asks for. Clerk keeps the resulting subscription with your accountTakes the payment and renews the plan
Our hosting providerRequest metadata in server logsRuns this website
draw.io (JGraph Ltd), the Mermaid Live Editor and ExcalidrawOnly when you open a diagram in one of them: the diagram, in the link. For draw.io and Mermaid it stays in your browser; for an Excalidraw share link, Excalidraw stores it encrypted, without the keyLets you edit a diagram in the editor you prefer
A model provider (OpenAI today)The text, image or recorded audio for one request — once the extension ships — plus any knowledge-base passages that request drew onProduces the result

5Your control

  • Ask us to remove a feature request — email arti.shinde@thestackhub.com — and the row is deleted. You do not need an account to ask, and you do not have to say why.
  • Signed in, your Typeglass settings are on the dashboard: change them there or in the extension, and delete the account's copy with one button. Deleting it leaves the copy in your browser untouched.
  • The memory list is on the dashboard as well — the whole list, readable, with one button that erases every line of it. A delete is a delete, not a flag.
  • The knowledge base is on the dashboard beside it, and every entry can be removed there. Same rule: the row goes, and nothing keeps a copy.
  • Download my data, in Settings on the dashboard, gives you everything this website holds under your account as one file: your account details (name, profile picture, every email address and phone number on the account, the sign-in providers you linked, and when the account was created and last signed in), settings, memory list and knowledge base. It ends with what it does not contain — your password, two-factor settings and sessions, which only our sign-in provider holds, among them.
  • Beyond those, this site sets no analytics or advertising cookies and keeps nothing else about you. The one record left is the account itself — the email address and sign-in identity Clerk holds so that signing in is possible at all. Delete account, in Settings on the dashboard, removes it together with your settings, memory and knowledge base, and the Typeglass service then erases your plan and usage records. If a paid plan still renews, cancel it first; one you have already cancelled does not get in the way. You can also email arti.shinde@thestackhub.com and we remove it. Feature requests are not linked to your account, so deleting it leaves them in place — ask by email and we delete those too.

6Children

Typeglass is not directed at children under 13, and we do not knowingly collect their data.

7Changes

If what we collect changes, this page changes with it and the date at the top moves. Material changes are announced by email to anyone on the list.