Privacy Policy
Effective 9 October 2026 · Version 2026-10-09
Glimyo is operated by Amigo Softcom LLP, a limited liability partnership registered in India, LLPIN AAY-3370. Registered office: C1202 Bestech Park View Spa, Sector 47, Gurgaon, Haryana, India — 122018. For privacy questions or grievances, contact Shashank Jain at shashank@amigo.gg. Contact and grievance process.
This policy explains the current service. Accepting our Terms does not opt you into optional analytics or advertising. Those choices remain separate and can be withdrawn in Privacy choices.
Starter packs and first-party measurement
The jewellery, beauty, and ethnic-wear starter packs prepare and resize phone photos locally and keep the prepared photo in your browser before signup. Brand and product text is sent to render template previews. Local drafts are restored for up to 24 hours; a pending phone verification is restored in the same tab for up to 10 minutes without storing the code; you can discard them on the page. After phone verification and saving, the photo and three posts are stored in your private workspace. We report aggregate business totals from the records needed to provide the service: accounts, products, saved packs, creatives and publishing outcomes. These records exist so you can use your workspace, independently of optional analytics.
Aggregate traffic and optional journey analytics
For recognised public pages, we increment a daily counter by page and known campaign link. This request sends no cookies or referring URL. The counter stores no IP address, browser information, visitor identifier or account ID, and cannot connect visits to signups. Reloads count again. We skip marked test traffic, known owner sessions, recognised bots and Global Privacy Control requests where detectable. Daily counters are retained for about 90 days.
Separately, Glimyo journey analytics is off until you allow it in Privacy choices. It records visits, sample tries, uploads, previews, verified sign-ins, signups, packs, download starts, share handoffs and repeat use for 90 days. These events use a random browser-session identifier and allowlisted category/source/campaign/creative labels; signed-in events are linked to your account ID. Event records exclude phone numbers, photos, captions and raw referring URLs. A photo hash on saved packs helps identify repeat creation with a different product. QA sessions are excluded from acquisition reports. You can withdraw at any time to stop future journey collection and clear browser-session attribution; existing events expire through the 90-day retention process. Historical events collected before this separate choice was introduced remain labelled as legacy in internal reporting. Journey analytics, Google Analytics and Meta ad measurement have separate opt-ins, each lasting 30 days.
Guided studio, product, and brand drafts are kept on this device for up to 24 hours and are scoped to your workspace. Product photos are prepared locally and uploaded when you save the product. A pending phone sign-in is restored in the same tab for up to 10 minutes without storing the verification code. This is a summary of how the current Glimyo app uses your information.
Optional Meta ad measurement
Ad measurement is off until you choose to allow it. If enabled, Glimyo sends server-confirmed new-account registrations and saved starter-pack events to Meta through its Conversions API, along with the event time, a deduplication identifier, the category page address without its query string, your IP address, browser information, and a Meta ad click identifier when available. We do not include your phone number, photos, product names, captions, or purchase values. We do not load a Meta browser pixel in this release. Sample and QA activity are excluded.
Use “Privacy choices” at the bottom of the page to decline later. Declining cancels pending transmissions; it cannot recall events already received by Meta. We respect the Global Privacy Control request header. Your browser-session preference expires after 30 days. Delivery payloads are encrypted and cleared after delivery, rejection, cancellation, or at most about 25 hours; limited delivery status records are kept for up to 90 days. Backups can retain earlier records. Meta processes received data under its own policies.
Phone sign-in
We store your verified phone number to identify your account and recover your workspace when you sign in on another device. Twilio receives your phone number and verification code to deliver and validate sign-in messages. Glimyo does not store the SMS code.
Your brand and content
Your brand details, logos, uploaded product photos, captions, and saved creatives are stored on our DigitalOcean server. They are scoped to your account. When you continue with photo-based onboarding after sign-in, your product photo is sent to OpenAI to suggest a neutral name and category for you to confirm. We save that suggestion and a single-attempt marker with the product; it does not overwrite your product details until you confirm them. You can enter details manually if suggestions are unavailable. When you choose an AI product scene, your product image, brand and product details, and scene preferences are sent to OpenAI to identify the product, plan a relevant scene, write suggested copy, and generate the image. Template creation does not send a generation request to OpenAI.
Product photoshoots and image quality checks
Catalogue and detail layouts use your original photo or an optional reviewed cutout without generative image editing. When you choose “Prepare product cutout”, your photo and a short category are sent to Meta’s SAM service to identify product edges; the extracted image is stored privately for your review. Lifestyle and gifting scenes use your complete original photo. OpenAI receives that photo and your scene preferences to plan an editing brief and generate a new scene. AI can change fine product details; these scenes do not guarantee unchanged product pixels. Original photos and generated results are then sent to OpenAI for advisory checks of product fidelity, lighting, contact shadows, perspective and realism. We store the brief, model identifiers, scores and results with the creative. The same quality check applies to new AI product scenes. A quality check cannot approve or publish content. A feedback revision starts again from the original photo and uses one separately confirmed image-credit attempt; both versions remain saved. There is no automatic regeneration. Older background-only photoshoots used cutout compositing and remain identified by their original method.
Website import
When you submit a public store URL after sign-in, Glimyo reads a limited number of public pages and copies supported product and logo images into your private workspace for preview. No store password, Shopify connection or AI request is used for this import. You confirm the brand settings and select a product before they are applied. The import is a one-time snapshot and does not sync later store changes. Import records and preview images are stored on our server with your workspace. Protected or unsupported sites can be skipped by uploading a photo instead.
Shopify connection
If you connect Shopify, Glimyo requests read-only product access. Selected product images, descriptions, and starting prices are copied into your workspace. Store access credentials are encrypted on our server and used to fetch your catalog. Disconnecting removes those credentials and stops imports; products already imported remain in your workspace. Imports do not automatically sync later store edits.
Instagram publishing and statistics
If you connect an Instagram professional account, Glimyo stores its account identifier, username, encrypted access token and token expiry. We request profile/media access, permission to publish, and performance insights. You authorize each post or schedule after reviewing the exact image and caption. Glimyo keeps a publishing snapshot, delivery status, the Instagram post identifier and the metrics Instagram makes available. A short-lived signed image link lets Meta fetch only that publishing snapshot. Automatic statistics updates run for 30 days after publication.
Disconnect Instagram in Social to remove its stored credentials, cancel pending posts and stop future statistics collection. A post already being sent may finish, and published posts remain on Instagram. Existing publishing history remains in your workspace. Meta deauthorization or a signed data-deletion request deletes the connection and its publishing snapshots and statistics; original Glimyo creatives remain. For additional deletion requests, contact shashank@amigo.gg. Server backups may retain older records.
Connected agents
You can authorize a personal agent to read selected workspace data, create template drafts, edit copy, or export images. Agents receive only the permissions you approve; they do not receive your phone number, browser session, or provider keys. Connections expire after 30 days and can be revoked in Connected agents. Revocation stops future access but cannot recall data an agent already received. The agent’s own privacy terms apply to its copies. Glimyo stores action names and outcomes for up to 90 days, without prompts or credentials in this activity history.
Optional Google Analytics
Google Analytics is off until you separately allow it in Privacy choices. It measures page visits, product uploads, previews, verified signups, saved packs and downloads or shares. Google receives a cookie identifier and browser/device information and processes your IP address. We send only recognised page paths and campaign labels, never phone numbers, OTPs, photos, captions, product details, internal account IDs or raw URL parameters. Google advertising signals and personalisation are disabled. Your Analytics choice and Analytics cookies expire after 30 days. You can decline or withdraw through Privacy choices; this stops future collection but does not delete data already received by Google. Global Privacy Control disables optional measurement. See how Google uses data from sites that use its services.
Sessions and security
We use an essential cookie for your signed-in session and request protection. Sign-in sessions expire after 30 days; signing out revokes that session. We keep limited verification records and rate-limit counters to prevent repeated or abusive requests. Expired verification records are removed after about a day.
Your requests and choices
Use Account & privacy to request access to, correction of, or deletion of your information, or to raise a grievance. You receive a reference and can read our response there. If you cannot sign in, email shashank@amigo.gg. We may verify account ownership before sharing or deleting information. Never send an OTP, password or provider access token. Read the deletion process.
Requests are reviewed by our support and grievance contact. Submitting a deletion request does not immediately erase your account or stop scheduled posts. Cancel posts and disconnect integrations in Social if needed. Request messages are encrypted in our database and accessible to authorized support operators. Closed request records are removed from the active database after 180 days; open requests remain until handled. We keep the Terms and Privacy versions acknowledged during verified sign-in or workspace acceptance, with the time and account identifier. This does not record consent to optional measurement.
Retention, backups and international processing
Workspace content and imported previews remain while your account is active, unless removed through a request. Security and access logs may include IP addresses and request information. Retention required for security, legal obligations or disputes can differ from optional analytics retention. Backups can contain earlier copies; erasure from active storage is not immediate erasure from every backup. Our response to a deletion request will explain completion, remaining copies and any necessary retention rather than promise an unverified deletion date.
Our hosting, communications, AI, analytics and connected-platform providers may process information outside India under their service arrangements. A provider’s location and retention can differ from Glimyo’s. We use providers to deliver the features described here; we do not sell your uploaded photos or use them in public marketing without permission. You control disclosures to personal agents and social platforms through their connection and publishing flows.
Eligibility and updates
Glimyo is intended for business users aged 18 or older. Do not upload children’s personal information or content you are not authorized to use. Tell our privacy contact if you believe an account or upload breaches this restriction. Material changes will be identified by an updated date and version, with additional notice or a new choice where required. Keep access to your verified phone number; changing it currently requires contacting support.
Open your studio