Glimt — Privacy

Last updated: 29 July 2026 · Policy version: 2026-07-29

Glimt is built to be private by default. This policy explains, in plain language, what little data we handle, why, and the rights you have over it. Glimt is operated from Norway and follows the EU/EEA General Data Protection Regulation (GDPR).

Who we are

Data controller: [FILL IN: full legal name of the controller], [FILL IN: organisation number, or delete this clause if there is no registered enterprise], [FILL IN: postal address], Norway.

Contact: paal@dynni.no

Data protection officer: we have not appointed one. We do not believe Article 37 requires it, because our core activity is not large-scale regular and systematic monitoring of people and not large-scale processing of special categories of data. Write to the address above and you reach a person.

The short version

What we collect, why, and on what legal basis

DataWhyLegal basis
Email addressTo create and secure your account, and to sign you inContract, Art. 6(1)(b)
Username and (optional) avatarSo friends can find and recognise youContract, Art. 6(1)(b)
Date of birthTo confirm you meet the minimum age (see "Children")Legal obligation, Art. 6(1)(c), together with our duty of care to keep under-age users off a service not built for them
Friends and bål membershipTo deliver glimt to the right peopleContract, Art. 6(1)(b)
Glimt and vekeglimtThe core service. Stored only as encrypted ciphertext we cannot readContract, Art. 6(1)(b)
Delivery metadata (who sent to whom, timestamps, read status)To deliver content and show your inboxContract, Art. 6(1)(b)
Device push tokenTo notify you of new glimtConsent, Art. 6(1)(a), given when you allow notifications
A backup of your encryption key, sealed with a password only you knowSo your glimt come back if you lose, reset or replace your phoneConsent, Art. 6(1)(a), given when you choose a recovery password
Reports you file, and the evidence attached to themTo keep people safe and to meet our duties as a platformLegal obligation, Art. 6(1)(c), and legitimate interest, Art. 6(1)(f). The interest is protecting our users, children above all, from abuse, and being able to act on illegal content at all, which end-to-end encryption otherwise makes impossible

We do not collect your contacts, your location, advertising identifiers, or browsing behaviour.

Do you have to give us this?

Your email address, username, date of birth and friend list are what an account is made of. Without them there is nothing to sign in to and nothing to deliver a glimt to, so we cannot provide the service and you cannot use Glimt.

Everything else is optional and refusing costs you only the feature it belongs to:

Your encryption key, and how you get it back

Each glimt is encrypted on your device with your friend's public key before it is uploaded. Only the intended recipient's device can decrypt it. We, and anyone who might access our servers, only ever see unreadable ciphertext.

Your private key lives in your device's secure hardware keystore (iOS Keychain / Android Keystore). In normal use it never leaves the phone. There are two ways it can be brought back if the phone loses it, and both are worth knowing about because both mean your key exists somewhere other than that one device:

So losing your phone no longer means losing your glimt. Set a recovery password, and on a new phone you sign in, type the password, and your glimt are readable again. If you never set one and the automatic recovery does not apply, older glimt stay unreadable, because we genuinely cannot open them for you.

You can delete the server-side backup at any time from Settings, and deleting your account deletes it with everything else.

What happens on your device and never reaches us

Some of the most useful things Glimt does happen entirely on your phone. We mention them here because they sound like they should involve a server and they do not.

How long we keep things

Who we share data with

We use a small number of processors purely to run the service, under data-processing terms. We never share your data with advertisers or data brokers, and we do not sell it.

WhoWhat they handle
SupabaseDatabase, file storage, sign-in, server functions. Holds your account data, your delivery metadata, your encrypted content and your sealed key backup. Our project is hosted in Europe, in the Nordics
Expo, and through it Apple Push Notification service and Google Firebase Cloud MessagingDelivering push notifications: your device token and the text of the notification
Apple iCloud Keychain and Google Block StoreThe platform key escrow described above, end-to-end encrypted by the operating system

One honest detail about notifications: the text that travels through Expo, Apple and Google says who sent you something, and for a bål which fire it was. It never contains the content of a glimt. If you would rather nothing at all travelled that way, turn notifications off.

Transfers outside the EEA

Your account data and your encrypted content are stored in Europe. Our Supabase project is hosted in the Nordics, so that is where the database and the file storage physically sit.

Some of our processors are United States companies, so some data does reach the US:

The supplementary measure that actually matters here is the design of the app rather than a clause in a contract: the content of a glimt is end-to-end encrypted and never leaves your circle of friends in readable form, the key backup we store is sealed with a password we never receive, and the platform escrow is encrypted by the operating system. What crosses a border is either a token, a name in a notification, or a blob that the recipient cannot open.

Automated decision-making

There is no automated decision-making that produces legal effects for you or similarly significantly affects you in the sense of Article 22.

Two things do happen automatically, and you should know about them:

Both are protective, both are reversible, and a person reviews every report. If you think one of them hit you wrongly, write to paal@dynni.no and a person, not a machine, will answer. Our Terms explain what we tell you when we act, and how to contest it.

Your rights

Under the GDPR you can ask for access to your data, correct it, have it erased, get it in a portable form, restrict how we use it, and object to processing based on legitimate interest. Where we rely on your consent, you can withdraw it at any time, and withdrawing it does not make what we did before unlawful: turn notifications off in your device settings, or turn the key backup off in Settings.

You can delete your entire account at any time from Settings, which permanently removes your account, friends, bål, glimt and key backup. For any other request, email paal@dynni.no and we will respond within 30 days.

If you think we have got something wrong, you can complain to the data protection authority in the EU or EEA country where you live, where you work, or where the problem happened. In Norway that is Datatilsynet.

Children

Glimt is not for children under 13 (or a higher age where local law requires, such as 16 in some countries). We ask for date of birth at sign-up and block under-age accounts. See our Child Safety Standards. If you believe a child under the minimum age has an account, contact paal@dynni.no.

Changes

If we change this policy, we will update the date above and, for significant changes, let you know in the app.

Contact

paal@dynni.no

Norsk versjon