Overview
Africore Lab ("we", "our", "us") operates Gliiz AI (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. Please read it carefully. By using the Service, you consent to the practices described in this policy.
Information We Collect
Account Information
When you register, we collect your name, email address, password (hashed), and profile data. We also collect billing information processed securely by our payment provider.
Platform Credentials & Tokens
When you connect social and advertising platforms (Instagram, Facebook, TikTok, LinkedIn, YouTube, WhatsApp, Google Ads, Meta Ads, TikTok Ads, LinkedIn Ads) or the Canva design tool, we store OAuth access tokens on your behalf. These tokens are encrypted at rest and used solely to publish content, read analytics, and manage interactions you authorize. We never use these tokens outside the scope of your explicit actions.
Google Drive Files (BYOS)
If you connect your own Google Drive (the "Bring Your Own Storage" feature, available on Agency and Enterprise plans), we request only the drive.file scope: Gliiz AI can read, create, or modify only the files and folders it creates itself in your Drive to copy your generated visuals and videos, never your entire Drive. You can revoke this access at any time from Settings → Accounts or from your Google account's own security settings.
Telegram Identifiers (Turbo)
If you link your Telegram account to the Turbo assistant, we store the conversation identifier (chat ID), your Telegram username and first name as provided by the Telegram API, and the content of messages exchanged with the assistant, to power the conversational messaging and unified Inbox.
Your Contacts' & Prospects' Data
If you use the prospecting features (email and SMS campaigns), you provide us with the contact details (name, email, phone number) of your own contacts and prospects. We process this data as a processor, on your behalf and per your instructions; you remain the data controller for this data and must have a valid legal basis to contact them.
Authentication
Depending on the sign-in method you choose, we also process your email and password (hashed), profile information provided by Google when signing in with Google Sign-In, or a passkey (WebAuthn) public key if you enable passwordless authentication. We never receive your Google password or your passkey's private key, which never leaves your device.
Content & Usage Data
We store content you create (posts, creatives, videos, captions), scheduling data, automation rules, and analytics data fetched from connected platforms. We also collect usage logs (feature interactions, errors) to improve the Service.
Technical Data
IP address, browser type, device identifiers, and cookies are collected automatically for security, fraud prevention, and service performance purposes.
How We Use Your Information
- To provide and operate the Service on your behalf
- To publish, schedule, and manage content on connected social platforms
- To generate AI-powered content, creatives, videos, and automated replies
- To send email and SMS prospecting campaigns on your behalf to your own contacts, with unsubscribe management
- To sync your creations to your own Google Drive when you enable that option (BYOS)
- To process payments and manage subscriptions
- To send transactional emails (account security, billing receipts, important product updates)
- To detect and prevent fraud, abuse, or unauthorized access
- To comply with legal obligations
- To improve the platform through aggregated, anonymized analytics
Third-Party Platform Integrations
Gliiz AI integrates with the Meta (Facebook & Instagram), TikTok, LinkedIn (personal profile and Company Page), YouTube (Google), and WhatsApp Business APIs, the Google Ads/Meta Ads/TikTok Ads/LinkedIn Ads advertising platforms, and Canva (read-only access to your designs and profile). When you connect these platforms:
- We request only the permissions strictly necessary for the features you enable
- Access tokens are stored encrypted and scoped to your account only
- We act as a data processor on your behalf; you remain the data controller for your audience data
- Data fetched from these platforms (analytics, DMs, comments) is used exclusively to power your dashboard and automations
- You can disconnect any platform at any time from Settings → Accounts, which immediately revokes our access
- Each platform's own privacy policies govern how they handle the underlying data
Google Drive (Bring Your Own Storage)
On Agency and Enterprise plans, you can connect your own Google Drive so your generated creations (visuals, videos) are automatically copied there, in addition to being stored on Gliiz AI.
- We request exclusively the https://www.googleapis.com/auth/drive.file scope: access limited to files and folders Gliiz AI creates itself, never your entire Drive or your existing files
- By connecting Google Drive, you agree to be bound by Google's Terms of Service: https://policies.google.com/terms
- Our access, use, and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy
- You can revoke Gliiz AI's access to your Google Drive at any time from Settings → Accounts or from Google's security settings: https://security.google.com/settings/security/permissions
- Removing the connection does not delete files already copied to your Drive: they belong to you and remain under your sole control
YouTube API Services
Gliiz AI uses YouTube API Services to let you upload videos and read basic channel data on your own behalf when you connect your YouTube account.
- By connecting YouTube, you agree to be bound by the YouTube Terms of Service: https://www.youtube.com/t/terms
- Our access, use, and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy
- We only request the youtube.upload and youtube.readonly scopes needed to publish content and display your channel in Gliiz AI, never anything broader
- You can revoke Gliiz AI's access to your Google/YouTube account at any time from Google's security settings: https://security.google.com/settings/security/permissions
Data Sharing & Disclosure
We share your data only in the following circumstances:
- Infrastructure & Hosting: Supabase (database & auth), Vercel (hosting & cookieless performance analytics).
- AI Providers: only the prompts, images, and videos you submit are transmitted, to generate your content, DeepSeek, Groq, Google Vertex AI (Gemini), Anthropic (Claude, used for quality control on some generations), and fal.ai (image/video generation and editing).
- Payment: Paddle (card payments, acting as Merchant of Record) and PawaPay (mobile money for African markets); we do not store raw payment credentials.
- Communications: Resend (transactional email and email campaigns), Twilio (sending prospecting SMS).
- Security & Reliability: Cloudflare Turnstile (bot protection for forms), BetterStack (technical monitoring and error logs).
- Consented Analytics: Google Analytics is only loaded if you accept analytics cookies from our consent banner; see the Cookies section.
- Legal Requirements: If required by law, court order, or to protect the rights, property, or safety of our users or the public.
- Business Transfers: In the event of a merger or acquisition, your data may be transferred with prior notice.
- With Your Consent: Any other sharing requires your explicit, informed consent.
Data Retention
We retain your data for as long as your account is active or as necessary to provide the Service. Upon account deletion, your account is deactivated immediately and:
- Your personal data (profile details, connected social accounts and their access tokens, and any photo or audio message you personally uploaded or sent) is permanently erased within 30 days
- AI-generated visuals and videos (Studio and automated workflows) are retained as platform deliverables, except any generated visual that incorporates a personal reference photo you uploaded, which is erased along with the rest of your personal data
- The text of your VIBE and Turbo (Telegram) conversations is retained (with any attached media removed); the link to your Telegram account is deleted as soon as you disconnect Turbo
- Files already synced to your personal Google Drive (BYOS) remain under your sole control and are not deleted by us, including after account deletion
- Email/SMS campaign suppression (unsubscribe) lists are retained indefinitely to durably honor opt-out requests, even after the sender's account is deleted
- Billing records are retained for 7 years to comply with accounting regulations
- Anonymized aggregated statistics may be retained indefinitely
Data Processing Table
Account data
Contract- Data
- Name, email, password (hashed)
- Purpose
- Authentication & account management
- Retention
- Account lifetime + 30 days
OAuth tokens
Consent- Data
- Social network access tokens and advertising account tokens (Google Ads, LinkedIn Ads, Meta Ads, TikTok Ads)
- Purpose
- Publishing & content management, ad campaign management
- Retention
- Until revoked
Created content
Contract- Data
- Posts, flyers, captions, media
- Purpose
- Providing the Service
- Retention
- Account lifetime + 30 days
Analytics data
Contract- Data
- Metrics, engagement, statistics
- Purpose
- Dashboard & reporting
- Retention
- Rolling 12 months
Technical data
Legitimate interest- Data
- IP address, browser, device ID
- Purpose
- Security & fraud prevention
- Retention
- 90 days
Billing
Legal obligation- Data
- Payment history
- Purpose
- Subscription management
- Retention
- 7 years (legal obligation)
Google Drive files (BYOS)
Consent- Data
- Files created by Gliiz in your Drive (drive.file scope only)
- Purpose
- Syncing your creations to your own storage
- Retention
- Under your sole control; we do not delete them
Telegram identifiers (Turbo)
Consent- Data
- Chat ID, username, first name, messages
- Purpose
- Conversational assistant & unified Inbox
- Retention
- Until Turbo is disconnected
Contacts & prospects
Contract (processor)- Data
- Name, email, phone number of your own contacts
- Purpose
- Email/SMS prospecting campaigns on your behalf
- Retention
- Per your instructions; suppression list kept indefinitely
Compliant with GDPR (EU) 2016/679 · Updated September 2026
| Category | Data | Purpose | Retention | Legal basis |
|---|---|---|---|---|
| Account data | Name, email, password (hashed) | Authentication & account management | Account lifetime + 30 days | Contract |
| OAuth tokens | Social network access tokens and advertising account tokens (Google Ads, LinkedIn Ads, Meta Ads, TikTok Ads) | Publishing & content management, ad campaign management | Until revoked | Consent |
| Created content | Posts, flyers, captions, media | Providing the Service | Account lifetime + 30 days | Contract |
| Analytics data | Metrics, engagement, statistics | Dashboard & reporting | Rolling 12 months | Contract |
| Technical data | IP address, browser, device ID | Security & fraud prevention | 90 days | Legitimate interest |
| Billing | Payment history | Subscription management | 7 years (legal obligation) | Legal obligation |
| Google Drive files (BYOS) | Files created by Gliiz in your Drive (drive.file scope only) | Syncing your creations to your own storage | Under your sole control; we do not delete them | Consent |
| Telegram identifiers (Turbo) | Chat ID, username, first name, messages | Conversational assistant & unified Inbox | Until Turbo is disconnected | Consent |
| Contacts & prospects | Name, email, phone number of your own contacts | Email/SMS prospecting campaigns on your behalf | Per your instructions; suppression list kept indefinitely | Contract (processor) |
Compliant with GDPR (EU) 2016/679 · Updated September 2026
Security
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.3) and at rest (AES-256) for all sensitive data
- OAuth token encryption with rotating keys
- Role-based access controls and least-privilege principles
- Regular security audits and dependency scanning
- Two-factor authentication available for all accounts
Your Rights
Depending on your location, you may have the following rights under GDPR, CCPA, or applicable laws:
- Right to Access: Request a copy of all personal data we hold about you
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data ('right to be forgotten')
- Right to Portability: Receive your data in a structured, machine-readable format
- Right to Restriction: Limit how we process your data in certain circumstances
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: At any time, without affecting prior processing
Children's Privacy
The Service is not directed to children under 16. We do not knowingly collect personal data from minors. If you believe a minor has provided us with data, contact us immediately and we will delete it.
Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or a prominent notice in the platform at least 14 days before taking effect. Continued use of the Service after changes constitutes acceptance.
Contact Us
For privacy-related questions, data requests, or to report a concern, contact the Africore Lab privacy team:
- Email: contact@africorelab.com
- Response time: within 30 days for standard requests, 72 hours for urgent security matters
Questions about your privacy?
Our team is here to help with any data or privacy-related questions.
Contact Privacy Team
