Privacy Policy
Version: 1.4
Review Date: 12 August 2026
Effective Date: 12 August 2026
Next Review Date: 12 August 2027
This Privacy Policy explains how Glimma AI Inc. and its subsidiaries, including Glimma AI AB, (“Glimma AI”, “we”, “our” or “us”) collect, use, disclose and protect personal data.
This Policy applies when you:
- visit our website;
- contact us or request a demo;
- use the Glimma AI platform as a customer, user or team member;
- participate in a research study, interview, usability test, prototype test or other study conducted through Glimma AI;
- download or use the Glimma AI User Research mobile application on iOS or Android, including when you access a study through an invitation link or participant identifier.
We care about privacy and aim to process personal data in a transparent, secure and responsible way.
1. Who we are
Glimma AI provides an AI-moderated research platform that helps companies conduct interviews, usability tests, prototype tests and other research activities.
Depending on the situation, Glimma AI may act either as a data controller/business or as a data processor/service provider.
When Glimma AI acts as a controller or business, we decide why and how personal data is processed. This applies, for example, when we process data about website visitors, sales contacts, customer account users, billing contacts, support requests and platform security.
When Glimma AI acts as a processor or service provider, we process personal data on behalf of our customer. This usually applies to research participant data collected in studies conducted by our customers through the Glimma AI platform. In those cases, the customer determines the purpose and lawful basis for the research study.
2. Personal data we collect
We collect different types of personal data depending on how you interact with us.
2.1 Information you provide to us
We may collect information that you provide directly to us, such as when you create an account, request a demo, fill out a form, communicate with us or participate in a research study.
This may include:
- name;
- email address;
- phone number;
- company name;
- job title or role;
- country or location;
- account login information;
- communication with us;
- survey, interview or research responses;
- any other information you choose to provide.
2.2 Information collected through research studies
When you participate in a research study conducted through Glimma AI, we may process information such as:
- screening answers;
- interview responses;
- audio recordings;
- video recordings, where video is enabled;
- screen recordings, where screen recording is enabled;
- images, video files, audio/sound files, or other media uploaded or provided by research participants as part of a study, where applicable;
- transcripts;
- translated transcripts;
- AI-generated summaries, themes and reports;
- usability testing data, such as task completion, clicks, time to click, navigation behavior and interaction with prototypes or websites;
- demographic or background information, if requested by the customer conducting the study;
- participant or study identifier;
- voice and audio responses;
- video responses;
- screen or application-window recordings;
- taps, swipes, navigation events and task completion;
- timestamps and session duration;
- permission status, such as whether microphone or screen-sharing access was granted;
- content displayed during a recorded usability task;
- system audio, if the application captures it.
The exact data collected depends on the study design set by the customer.
2.3 Information collected automatically
When you use our website or platform, we may automatically collect technical and usage information, including:
- IP address;
- device type;
- browser type;
- operating system;
- pages viewed;
- links clicked;
- access times;
- log data;
- app or platform usage data;
- error reports and diagnostic information;
- mobile app version;
- device model;
- operating-system version;
- crash and performance data;
- session and diagnostic identifiers;
- network and connectivity information.
We use this information to provide, secure, monitor and improve our services. We use error-monitoring and diagnostic tools, across our website, platform and iOS and Android mobile applications. These tools may process crash reports, error logs, stack traces, device and application information, performance data, technical request information, timestamps, pseudonymous session identifiers, IP addresses and interaction events occurring before an error. We use this information to detect and resolve technical problems, maintain security and improve the reliability and performance of our Services. We configure these tools to minimise personal data and not intentionally collect research responses, recordings, transcripts, passwords, authentication tokens or other sensitive study content.
3. Audio and video recordings
Glimma AI may process audio and, where enabled, video recordings of participants taking part in research interviews, usability tests or other studies through our platform.
Audio and video recordings are used only for purposes related to the research study, such as:
- conducting the interview or test;
- generating transcripts;
- translating responses;
- analysing research responses;
- creating summaries, themes and research reports;
- allowing the customer to review responses and research outputs.
Glimma AI does not record audio or screen content outside an active research session. During a usability test, recording may continue while the participant navigates from the Glimma AI app to the website or application being tested. Recording begins only after the participant has been informed and has actively granted the required permissions. The device displays an active recording indicator or notification while recording is in progress.
Audio and video data will not be used for marketing or promotional purposes.
4. Mobile app permissions and recordings
The Glimma AI User Research mobile application may request access to certain device features when these are needed to conduct a research study.
Microphone access: The app uses the microphone to record spoken responses and enable the participant to communicate with the AI moderator. Microphone access is used only during an active research session.
Camera access: The app uses the camera to record video responses and enable the participant to communicate with the AI moderator. Camera access is used only during an active research session.
Screen recording or screen sharing: Some mobile usability studies require participants to share or record their device screen or a selected application window while completing research tasks. Screen recording helps the customer understand navigation, taps, task completion, hesitation and usability difficulties.
Screen recording starts only after the participant actively approves the system permission. On supported Android devices, the app may use a foreground service to maintain screen recording and microphone access while the participant navigates through the application or website being tested. A system notification or recording indicator remains visible while recording is active.
Audio playback: The app may use media playback functionality to play questions, instructions or responses from the AI moderator during the research session.
Participants can stop the recording or leave the study at any time. Device permissions can also be withdrawn through the iOS or Android settings. Withdrawing a required permission may prevent the participant from completing the study.
Glimma AI does not activate the microphone or screen recording outside an active research session and does not use these permissions for advertising or unrelated monitoring.
5. AI processing and analysis
Glimma AI uses AI to support research activities, including AI-moderated interviews, follow-up questions, transcription, translation, summarisation, theme generation and report creation.
Customer and participant data is processed only to provide the Glimma AI service and related research outputs.
We do not use customer or participant data to train AI models.
Glimma AI does not use facial recognition, biometric identification, biometric enrolment or identity matching as part of its service.
Where optional features for fraud prevention, duplicate detection, participant verification or platform integrity are enabled, these will be used only for the stated purpose, subject to appropriate safeguards and, where required, additional information to participants.
6. Third-party artificial intelligence processing
Glimma AI uses OpenAI (OpenAI, L.L.C.; for participants in the EEA and UK, OpenAI Ireland Limited) to provide certain AI-powered features. OpenAI is the only third-party AI provider to which we send content you submit.
With your permission, we send the following to OpenAI, solely to process your request and provide the requested AI functionality:
- Recordings of your voice, where a study asks you to answer out loud, so your speech can be converted to text;
- Your answers—the resulting transcripts, your typed and survey responses, your ranking and rating choices, any image you annotate during a task, and any notes taken during your interview—so they can be transcribed, summarised, categorised and analysed for the research team running the study.
We do not send screen recordings, camera (video) recordings, or files you upload to OpenAI. Those are stored by Glimma AI and made available only to the research team running your study.
Where a study uses a live interview, your voice, and your camera if the study uses one, reaches us over LiveKit Inc., which transmits audio and video in real time but does not analyse them.
We ask for your permission before sending any personal data to OpenAI. If you do not give permission, no personal data is sent to OpenAI—but you will not be able to take part in the study, because analysing your responses is an essential part of the research you are being asked to join. You are free to decline and leave at that point.
OpenAI acts as our processor under a data processing agreement and applicable data protection requirements and is required to provide appropriate protection for personal data. Content submitted through OpenAI's API is not used to train OpenAI's models.
Retention. The research organisation running your study decides how long your responses and recordings are kept. Their own privacy notice, and the consent information provided to you for that study, govern that period. Where an organisation has not set a period, Glimma AI applies a default of 180 days after which the data is deleted on Glimma AI platform. To find out the exact period that applies to you, ask the research organisation that invited you, or contact us at support@glimma.ai. Separately, OpenAI retains data submitted through its API for up to 30 days for abuse and misuse monitoring, and then deletes it, unless it is required to retain it by law.
7. How we use personal data
We use personal data for the following purposes:
| Purpose | Examples of data | Legal basis / reason |
|---|---|---|
| To provide the Glimma AI platform | Name, email address, login activity, authentication data, platform activity, technical logs and error logs | Contract, legitimate interest or business purpose |
| To conduct research studies on behalf of customers | Research responses, audio, video, screen recordings, transcripts, usability data | Determined by the customer when Glimma acts as processor/service provider |
| To communicate with customers and users | Name, email, company, messages | Contract, legitimate interest, business purpose or consent |
| To manage sales and demo requests | Name, email, phone number, company, role, communication history | Legitimate interest, business purpose or steps before entering into a contract |
| To provide support | Contact details, messages, technical information | Contract, legitimate interest or business purpose |
| To improve and develop our services | Platform usage data, feedback, technical logs | Legitimate interest or business purpose |
| To protect the security of our services | IP address, logs, access data, security events | Legitimate interest, legal obligation or business purpose |
| To comply with legal obligations | Billing data, accounting records, legal requests | Legal obligation |
| To send marketing communications | Name, email, company, phone number, preferences | Consent or legitimate interest, depending on the situation |
Where we rely on legitimate interest, we assess that our interest does not override your rights and freedoms.
References to video recordings may include recordings of the participant's screen. The Glimma AI User Research mobile application does not access or record the device camera unless a specific study clearly informs the participant that camera recording is enabled and obtains the required permission. Camera access can be also requested to scan the QR code of the study.
8. When our customer is responsible for the research study
In many cases, Glimma AI provides the platform to an enterprise customer who designs and conducts the research study.
In those situations, the customer is normally the data controller under GDPR and the business under applicable U.S. state privacy laws. This means the customer is responsible for:
- deciding the purpose of the research study;
- determining the lawful basis or legal reason for processing;
- informing participants about the study;
- deciding what personal data is collected;
- deciding how long study data should be retained;
- responding to participant privacy rights requests, where applicable.
Glimma AI processes the data on the customer's behalf and according to the customer's instructions, our agreement with the customer, any applicable data processing agreement, and applicable data protection law.
Where required, Glimma AI enters into a Data Processing Agreement or similar data protection terms with the customer. This agreement regulates how Glimma AI may process personal data on behalf of the customer, including instructions, confidentiality, security measures, subprocessors, international transfers, assistance with privacy rights requests, and deletion or return of personal data.
If you participated in a study and want to exercise your privacy rights, you may contact either the customer who invited you to the study or Glimma AI. If Glimma AI is acting as processor or service provider, we may need to forward your request to the relevant customer.
9. Sharing of personal data
We may disclose personal data in the following situations:
With our customers
If you participate in a research study, your responses, recordings, transcripts, translations, summaries and related research outputs may be shared with the customer responsible for the study.
Mobile research data—including voice responses, screen recordings, interaction data, transcripts and AI-generated research outputs—may be made available to the organisation that commissioned or conducts the study and to its authorised research team members. The customer can download recordings and downloaded copies become subject to the customer's own retention policy.
With service providers and subprocessors
We use trusted service providers to help us operate, host, secure and improve our services. These may include providers for:
- cloud hosting and infrastructure;
- database hosting;
- AI processing;
- transcription and translation;
- email delivery;
- analytics;
- security monitoring;
- customer support;
- payment and billing, where applicable;
- error monitoring and diagnostic providers.
These service providers may only process personal data according to our instructions and for the purposes described in this Policy or our agreements with customers.
With authorities or legal advisors
We may disclose personal data where required by law, legal process, court order or government authority, or where necessary to protect our legal rights.
In connection with business changes
We may disclose personal data in connection with a merger, acquisition, financing, restructuring or sale of all or part of our business, subject to appropriate confidentiality and data protection safeguards.
With your consent
We may disclose personal data where you have given us consent or asked us to do so.
10. Sale or sharing of personal data
Glimma AI does not sell personal data. Glimma AI does not share personal data for cross-context behavioral advertising as defined under California privacy law.
11. International transfers
Glimma AI operates internationally, including through Glimma AI Inc. in the United States and Glimma AI AB in Sweden.
Where technically and operationally available, Glimma AI aims to host and store customer and research data in the region selected by the customer or otherwise associated with the relevant customer workspace. For example, data associated with EU/EEA customers is intended to be hosted and stored in the EU/EEA where available.
Some personal data may nevertheless be processed, accessed, or transferred outside the selected, associated, or hosted region, including outside the EU/EEA and in the United States. This may occur where we use service providers and subprocessors for infrastructure, hosting, AI processing, transcription, translation, email delivery, security, analytics, support, or similar services.
Where personal data is transferred to a jurisdiction that has not been recognised as providing an adequate level of protection under applicable data protection law, Glimma AI uses appropriate safeguards. These may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or other UK-approved transfer mechanisms, Swiss transfer adaptations, transfer impact assessments, supplementary technical and organisational measures, contractual commitments, access restrictions, encryption, or another lawful transfer mechanism.
Where Glimma AI processes personal data on behalf of a customer, international transfers are also governed by the applicable customer agreement, Data Processing Agreement, subprocessors list, and documented customer instructions. Where Standard Contractual Clauses are used, the applicable module is determined by the roles of the parties and the nature of the transfer.
Where Glimma AI engages service providers or subprocessors that process, access, or receive personal data, Glimma AI is responsible for assessing and managing those engagements within the scope of its role and control. This includes taking reasonable steps to apply appropriate contractual, technical, and organisational safeguards designed to support an appropriate level of protection, consistent with applicable data protection law, applicable customer agreements, and Glimma AI's information security and privacy commitments.
12. Data retention
We retain personal data only for as long as necessary for the purpose for which it was collected, unless a longer period is required by law, contract or legitimate business need.
Typical retention periods include:
| Data type | Retention |
|---|---|
| Customer account data | Retained while the account is active and for a reasonable period after account closure |
| Sales and demo contact data | Retained while we have an active business relationship or for a reasonable period after last interaction |
| Support communication | Retained as needed to provide support, resolve issues and maintain business records |
| Research participant data | Retained according to the customer's instructions, study settings and applicable agreement |
| Audio and video recordings | Deleted within 6 months after the study is completed, unless the customer requests earlier deletion or a longer retention period is required by law or agreed in writing with a valid legal basis. |
| Transcripts, translations and research outputs | Retained according to the customer agreement or study settings |
| Security logs | Retained for a limited period needed for security, troubleshooting and audit purposes |
| Billing and accounting data | Retained as required by applicable accounting and tax laws |
| Backups | Deleted or overwritten according to our backup retention routines |
| Mobile screen recording | Deleted within six months after study completion unless the customer requests earlier deletion or another period is lawfully agreed |
| Mobile interaction data | Retained according to the customer agreement and study setting |
| Mobile crash and diagnostic logs | Retained for a limited period required for troubleshooting, security and performance monitoring |
When personal data is no longer needed, we delete it, anonymise it or securely dispose of it.
13. Security
We use technical and organisational measures designed to protect personal data from unauthorised access, loss, misuse, alteration or disclosure.
These measures may include:
- access controls;
- role-based permissions;
- encryption in transit;
- encryption at rest where appropriate;
- logging and monitoring;
- secure development practices;
- vendor review;
- backup routines;
- incident response procedures.
Access to personal data is limited to authorized personnel and service providers who need access to provide, maintain or support the service. No system is completely secure, but we take reasonable steps to protect personal data and continuously improve our security practices.
14. Cookies and website analytics
We use cookies and similar technologies as described in our Cookie Policy. We may use cookies and similar technologies on our website and platform to:
- operate the website and platform;
- remember preferences;
- understand website usage;
- improve our services;
- support security and performance;
- measure marketing effectiveness, where applicable.
Where required by law, we ask for your consent before using non-essential cookies. You can manage cookie preferences through your browser settings or, where available, through our cookie banner.
15. Your privacy rights
Depending on where you are located and the type of processing involved, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of your personal data;
- object to certain processing;
- request restriction of processing;
- request data portability;
- withdraw consent where processing is based on consent;
- object to direct marketing.
If you withdraw consent, this does not affect processing that took place before the withdrawal.
Research participants do not normally create a Glimma AI account. To request access to or deletion of mobile research data, participants may contact privacy@glimma.ai or the organisation that invited them to the study. Participants should provide the study or participant identifier where available.
To exercise your rights, contact us at privacy@glimma.ai.
If your request relates to a research study where Glimma AI acts as a processor or service provider, we may forward your request to the customer responsible for the study.
16. Additional notice for U.S. residents
This section applies to residents of the United States where applicable U.S. state privacy laws give individuals additional rights.
Depending on your state of residence, you may have the right to:
- know what personal information we collect, use, disclose or share;
- access personal information we hold about you;
- request correction of inaccurate personal information;
- request deletion of personal information;
- receive a copy of your personal information in a portable format;
- opt out of the sale of personal information;
- opt out of sharing personal information for cross-context behavioural advertising;
- opt out of certain targeted advertising, where applicable;
- limit certain uses of sensitive personal information, where applicable;
- appeal a decision we make about a privacy request, where applicable;
- not be discriminated against for exercising your privacy rights.
Glimma AI does not sell personal information and does not share personal information for cross-context behavioural advertising.
To submit a U.S. privacy request, contact us at privacy@glimma.ai.
We may need to verify your identity before responding to your request. You may also be able to use an authorised agent to submit a request on your behalf, where permitted by applicable law.
If we deny your request, you may have the right to appeal our decision by contacting us again at privacy@glimma.ai with the subject line “Privacy Appeal.”
California law gives consumers rights such as the right to know, delete, correct, opt out of sale/share, limit certain uses of sensitive personal information and non-discrimination for exercising privacy rights.
17. Categories of personal information for U.S. privacy purposes
For U.S. privacy law purposes, we may collect the following categories of personal information:
| Category | Examples |
|---|---|
| Identifiers | Name, email address, phone number, IP address, account identifiers |
| Customer records information | Company, role, billing or business contact details |
| Commercial information | Subscription, account, billing or customer relationship information |
| Internet or network activity | Device information, browser information, pages viewed, links clicked, platform usage, logs |
| Audio, electronic or visual information | Audio recordings, video recordings, interview responses |
| Professional or employment-related information | Company name, job title, professional role |
| Inferences or derived data | AI-generated themes, summaries, research insights or analytical outputs |
| Sensitive personal information, where applicable | Information that may be included in research responses, depending on the study design |
We collect and disclose these categories for the purposes described in this Policy, including providing the platform, conducting research studies on behalf of customers, improving services, maintaining security, providing support and complying with legal obligations.
18. Sensitive personal data
Glimma AI does not require participants to provide sensitive personal data as part of its standard service.
However, some research studies may involve questions or responses that include sensitive information, such as health information, political opinions, religious beliefs, ethnicity, sexual orientation or other special category or sensitive personal data.
Where this occurs, the customer responsible for the study is responsible for ensuring that there is a valid lawful basis or legal reason and that participants receive appropriate information before taking part.
Participants may decline to answer questions or withdraw from a study in accordance with the information provided for that study and applicable law.
We do not use sensitive personal information for purposes other than providing and securing the service, complying with law, or as otherwise disclosed to you.
19. Biometric information
Glimma AI does not use facial recognition, biometric identification, biometric enrolment or identity matching as part of its research service.
Audio and video recordings may be processed to conduct research interviews, generate transcripts, analyse responses and create research outputs. These recordings are not used to identify participants unless a specific optional verification or fraud-prevention feature is enabled and appropriate notice, safeguards and legal basis are in place.
The U.S. Federal Trade Commission has highlighted that companies should avoid misleading claims and implement reasonable privacy and security measures when using biometric information technologies.
20. Children's data
Glimma AI is not intended for use by children without appropriate consent or authorisation.
We do not knowingly collect personal data from children where parental, guardian or other legally required consent is needed, unless such consent has been obtained by the customer responsible for the study.
For users or participants in the United States, we do not knowingly collect personal information online from children under 13 unless verifiable parental consent or another legally valid basis has been obtained, where required. COPPA applies to operators of websites or online services directed to children under 13, and to operators that have actual knowledge that they collect personal information from children under 13.
If we become aware that personal data from a child has been collected without appropriate consent, we will take steps to delete or restrict the data as required by applicable law.
21. Marketing communications
We may send marketing communications to business contacts, customers and prospective customers where permitted by law.
You can opt out of marketing emails at any time by using the unsubscribe link in the email or by contacting us at privacy@glimma.ai.
We will still be able to send service-related messages, such as security notices, account updates and important information about the platform.
22. Complaints
If you have questions or concerns about how we process personal data, please contact us first at privacy@glimma.ai.
You may also have the right to lodge a complaint with a data protection or privacy authority.
If you are in Sweden, you can contact the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten, at imy@imy.se.
If you are in the United States, you may be able to contact your state attorney general or applicable state privacy regulator.
23. Changes to this Policy
We may update this Privacy Policy from time to time.
The latest version will always be available on our website. If we make material changes that affect your rights or how we process personal data, we will take reasonable steps to inform you, such as by email, platform notification, or website notice.
24. Contact
For questions about this Privacy Policy or how we process personal data, please contact:
Email: privacy@glimma.ai
For privacy-related questions, you may also contact our privacy contact:
Jazgul Ismailova
CEO, Glimma AI
Email: jazgul@glimma.ai