Glass Overlay
Overview Pricing Account

Beta draft — final versions publish with the Glass Overlay LLC launch

Privacy Policy

DRAFT — NOT LEGAL ADVICE. Generated 2026-05-31 as a starting point.

Have an attorney review before publishing, and fill every [PLACEHOLDER].

Apple requires a public Privacy Policy URL for App Store submission; host

this at [https://glassoverlay.app/privacy] (or overlaystudio.app/privacy)

and link it from the apps + checkout.

Effective date: [DATE] Operator ("we", "us"): [LEGAL ENTITY / SAMUEL TYREL FRISBY d/b/a Glass Overlay], [ADDRESS] Contact: [support@glassoverlay.app]

1. Who this covers

Glass Overlay is a Mac app, companion iPad/iPhone app, and web portal for recording and producing podcasts and video sessions. This policy covers the host/operator (our customer) and guests/participants who join a session, and viewers of a web broadcast.

2. What we collect

You give us:

  • Account & billing — name, email, and payment details. Payments are
  • processed by our merchant of record Paddle (Mac/web subscriptions) and by Apple (iOS in-app purchases); we do not store full card numbers.

  • Recordings & content — the audio, video, slides, and annotations
  • created in a session. App-based participants record locally at full quality; recordings are uploaded to our cloud storage to assemble the session bundle.

Collected automatically:

  • Session/usage data — connection times, participant counts, data/feed
  • usage for billing and reliability.

  • Device/technical data — app version, OS, IP address (used for
  • connectivity and abuse prevention).

We do NOT: track you across other companies' apps or websites, sell your personal data, or use your recordings to train models.

3. Why we use it

To provide and operate the service (host sessions, store/deliver recordings), process payments and meter usage, prevent abuse, provide support, and comply with law. Legal bases (GDPR): performance of contract, legitimate interests (security/abuse-prevention), and consent where required (e.g., recording).

4. Recordings & consent

Recordings capture other people. The host is responsible for obtaining the consent of everyone they record, including where two-party/all-party consent laws apply. We surface a recording notice/consent step to guests in the join flow, but the host warrants they have the necessary rights and consents. See the separate Recording Consent notice. We act as a processor of recording content on the host's behalf; the host is the controller.

5. Who we share it with (sub-processors)

  • Cloudflare, Inc. — cloud storage (R2), real-time media relay
  • (Realtime/Calls), and edge compute (Workers). Recordings and live media transit/are stored on Cloudflare. [US/global]

  • Paddle.com Market Ltd. — merchant of record for subscription payments
  • and tax.

  • Apple Inc. — in-app purchases on iOS.
  • `[Email/support provider, analytics, crash reporting — list each before
  • publishing]`

We share only what each provider needs. We may disclose data if required by law or to protect rights and safety.

6. Storage, location & retention

Recordings and data are stored on Cloudflare infrastructure [region]. Recordings are retained [retention window — e.g., until the host downloads the bundle, then up to N days, then deleted]. Account/billing records are retained as required for tax/accounting [period]. You can request deletion (Section 8).

7. International transfers

Data may be processed in the United States and other countries. Where required (EEA/UK), transfers rely on [Standard Contractual Clauses / appropriate safeguards].

8. Your rights

Depending on where you live (GDPR/UK GDPR, CCPA/CPRA, and others) you may have rights to access, correct, delete, port, or restrict your data, to object to processing, and to not be discriminated against for exercising them. Submit requests to [support@glassoverlay.app]; we verify identity before acting. Guests wanting a recording deleted should also contact the host (controller). California "Do Not Sell/Share": we do not sell or share personal data for cross-context behavioral advertising.

9. Security

We use encryption in transit (HTTPS/WebRTC/DTLS-SRTP), access controls, and scoped credentials. No method is 100% secure; we cannot guarantee absolute security.

10. Children

Glass Overlay is not directed to children under [13/16] and we do not knowingly collect their data.

11. Changes

We may update this policy; material changes will be posted here with a new effective date.

12. Contact

[support@glassoverlay.app] · [mailing address] · [EU/UK representative if required]

Terms Privacy EULA Recording consent

glassoverlay.com