Back to Home

Privacy Policy

Last updated: September 9, 2026

1. Who We Are and What This Covers

This Privacy Policy applies to Glaife, an AI support agent platform operated by Mitryco, LLC ("Glaife", "we", "our", or "us"). It explains how we collect, use, disclose, and protect personal data when you use our website, product, and related services.

Glaife is used in two distinct ways, and our role differs between them:

  • As a workspace. An organization signs up, configures support agents, and embeds a chat widget on its own website. For the conversations that widget handles, and for everything the organization loads into its workspace, that organization is the controller and we act as a processor on its instructions.
  • As an account holder. For the accounts of the people who sign in to Glaife to administer a workspace, and for visitors to our own website, we are the controller.

If you spoke to a support agent on a company's website and want to know what was kept, that company is the right place to ask. We hold that conversation on its behalf.

2. Information We Collect

On our own behalf, as controller:

  • Account details for workspace members, such as name, email address, organization, and role.
  • Authentication data such as sessions, and passkeys if you register one.
  • Support and communications data when you contact us.

On a workspace's behalf, as processor, Glaife stores:

  • Conversation transcripts: the messages exchanged between an end user and the workspace's agent, including anything the end user chooses to type.
  • Files an end user uploads during a conversation.
  • Technical data about an end user's session, such as IP address, browser user agent, and the address and title of the page the widget was opened from.
  • Run records for each agent reply: which tools ran, the arguments they were called with, what they returned, timings, and token costs. This is what lets a workspace audit why its agent answered as it did.
  • Configuration the workspace supplies, including agent instructions, knowledge base articles, widget appearance, and integration credentials.

What an end user ends up disclosing to an agent is determined by the workspace that configured it, not by us.

3. Legal Bases for Processing

Where required by applicable law, we rely on one or more of the following legal bases:

  • Performance of a contract with you or your organization.
  • Legitimate interests, such as securing and improving our services.
  • Compliance with legal obligations.
  • Consent, where consent is required by law.

Where we act as a processor, the workspace that deployed the agent is responsible for establishing a legal basis for the data it collects through it.

4. How We Use Information

  • Provide, maintain, and secure the Glaife platform.
  • Resolve each conversation turn: assemble the agent's instructions, run the tools it is permitted to use, and return a reply.
  • Store transcripts, run logs, and usage costs so a workspace can review and improve its own agents.
  • Authenticate users and protect accounts.
  • Escalate a conversation to a human when an agent is configured to do so.
  • Provide customer support and service communications.
  • Comply with legal obligations and enforce our terms.

We do not sell personal data, and we do not use a workspace's conversations, knowledge base, or end-user data to train AI models. Conversation content is sent to an AI model provider to generate replies. By default that provider is one we contract with as a subprocessor, under terms that prohibit training on the data; a workspace may instead connect its own model provider account, in which case the terms governing that data are between the workspace and that provider.

5. Data Sharing

We do not sell personal data, and we do not share one workspace's data with another. We may share data in limited cases:

  • With the vendors that host and operate Glaife itself: our application hosting provider, our managed Postgres database provider, the object storage provider that holds conversation attachments, the transactional email provider that delivers sign-in and invitation mail, and the AI model provider that generates replies. These are bound by confidentiality and data protection obligations, and a current list is available on request.
  • With services a workspace connects itself, such as its helpdesk, store, or order systems, or a model provider of its own choosing. Those run under the workspace's own accounts and credentials, on the workspace's own terms with those vendors. They are not our subprocessors, and we do not control their data practices.
  • With a workspace's own administrators and members, according to the roles and access controls in the product.
  • When required by law, regulation, legal process, or to protect rights.
  • In connection with a merger, acquisition, financing, or sale of business assets.

6. International Transfers

We may process and store data in the United States, the European Union, and other jurisdictions where we or our subprocessors operate. Where required, we use appropriate contractual or organizational safeguards for cross-border transfers.

7. Security

Workspaces are isolated from one another. Every conversation, knowledge base entry, and configuration row is scoped to the organization that owns it, and a session token issued for one workspace cannot address another.

  • Integration credentials a workspace stores with us are encrypted at rest with AES-256-GCM under a key held outside the database.
  • Conversation attachments live in a private bucket. Nothing is served from it directly; each download is authorized individually and streamed by the application.
  • Tools that read an individual account's data are only offered to a session whose identity has been verified, and an account identifier is never accepted from the browser or chosen by the model.

We use administrative, technical, and organizational safeguards designed to protect data against unauthorized access, loss, misuse, or alteration. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

8. Data Retention

We retain data for as long as needed to provide the services, comply with legal obligations, resolve disputes, and enforce agreements. A workspace may request deletion of its data, and deleting a workspace removes the conversations, knowledge base, configuration, and stored credentials that belong to it, subject to legal and contractual requirements and to routine backup cycles.

9. Your Rights

Depending on your location (for example, under GDPR, UK GDPR, Ukrainian data protection law, or certain U.S. state privacy laws), you may have rights to:

  • Access, correct, or delete personal data.
  • Request portability of certain data.
  • Object to or restrict certain processing.
  • Withdraw consent where processing is based on consent.
  • Appeal or lodge a complaint with a data protection authority.

To make a request, contact us using the details below. If the data you are asking about was collected through an agent on another company's website, we will forward your request to that company, which is the controller of it.

10. Children's Privacy

Glaife is intended for business use and is not directed to children under 13. We do not knowingly collect personal data from children under 13.

11. Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will always be posted on this page with an updated effective date.

12. Contact

Questions about this Privacy Policy may be directed to:

Mitryco, LLC

Representative: Dmytro Loza

1111B S Governors Ave, STE 23705

Dover, DE 19904, United States

Email: dmitry@mitryco.com