Glimt — Privacy
Last updated: 29 July 2026 · Policy version: 2026-07-29
Glimt is built to be private by default. This policy explains, in plain language, what little data we handle, why, and the rights you have over it. Glimt is operated from Norway and follows the EU/EEA General Data Protection Regulation (GDPR).
Who we are
Data controller: [FILL IN: full legal name of the controller], [FILL IN: organisation number, or delete this clause if there is no registered enterprise], [FILL IN: postal address], Norway.
Contact: paal@dynni.no
Data protection officer: we have not appointed one. We do not believe Article 37 requires it, because our core activity is not large-scale regular and systematic monitoring of people and not large-scale processing of special categories of data. Write to the address above and you reach a person.
The short version
- Your glimt (photos, videos, captions) and your weekly vekeglimt are end-to-end encrypted. We cannot see their content, even on our own servers.
- We do not show ads, we do not track you across apps or the web, and we never sell your data.
- There is no algorithm and no public feed. What you share goes only to the friends you chose.
What we collect, why, and on what legal basis
| Data | Why | Legal basis |
|---|---|---|
| Email address | To create and secure your account, and to sign you in | Contract, Art. 6(1)(b) |
| Username and (optional) avatar | So friends can find and recognise you | Contract, Art. 6(1)(b) |
| Date of birth | To confirm you meet the minimum age (see "Children") | Legal obligation, Art. 6(1)(c), together with our duty of care to keep under-age users off a service not built for them |
| Friends and bål membership | To deliver glimt to the right people | Contract, Art. 6(1)(b) |
| Glimt and vekeglimt | The core service. Stored only as encrypted ciphertext we cannot read | Contract, Art. 6(1)(b) |
| Delivery metadata (who sent to whom, timestamps, read status) | To deliver content and show your inbox | Contract, Art. 6(1)(b) |
| Device push token | To notify you of new glimt | Consent, Art. 6(1)(a), given when you allow notifications |
| A backup of your encryption key, sealed with a password only you know | So your glimt come back if you lose, reset or replace your phone | Consent, Art. 6(1)(a), given when you choose a recovery password |
| Reports you file, and the evidence attached to them | To keep people safe and to meet our duties as a platform | Legal obligation, Art. 6(1)(c), and legitimate interest, Art. 6(1)(f). The interest is protecting our users, children above all, from abuse, and being able to act on illegal content at all, which end-to-end encryption otherwise makes impossible |
We do not collect your contacts, your location, advertising identifiers, or browsing behaviour.
Do you have to give us this?
Your email address, username, date of birth and friend list are what an account is made of. Without them there is nothing to sign in to and nothing to deliver a glimt to, so we cannot provide the service and you cannot use Glimt.
Everything else is optional and refusing costs you only the feature it belongs to:
- Notifications. Say no and Glimt still works, you just find new glimt when you open the app.
- The key backup. Say no and Glimt still works, but if you lose your phone your old glimt cannot be brought back, by you or by us.
- Camera, microphone, photos. These are permissions you give the app on your own device, not data you give us. Refuse one and the feature that needs it stops. Nothing else changes, and you can change your mind at any time in your device settings.
Your encryption key, and how you get it back
Each glimt is encrypted on your device with your friend's public key before it is uploaded. Only the intended recipient's device can decrypt it. We, and anyone who might access our servers, only ever see unreadable ciphertext.
Your private key lives in your device's secure hardware keystore (iOS Keychain / Android Keystore). In normal use it never leaves the phone. There are two ways it can be brought back if the phone loses it, and both are worth knowing about because both mean your key exists somewhere other than that one device:
- A backup on our servers, sealed with your password. When you choose a recovery password, your phone derives a key from it (Argon2id), seals your private key with that (XSalsa20-Poly1305), and stores the sealed blob on our servers, one row per account. The password is never sent to us and we never see it. What we hold is a blob that is useless to us and useless to anyone who takes our database. There is no reset: if you forget the password, nobody, including us, can open it.
- Your platform's own key store. On iOS your key is also kept as a synchronising iCloud Keychain item; on Android in Google Block Store. This is the same mechanism iMessage uses. Apple and Google hold the material but it is end-to-end encrypted by the operating system and they cannot read it. The entry is scoped to your account and to that one device, so it recovers that device, it does not copy your key onto another one.
So losing your phone no longer means losing your glimt. Set a recovery password, and on a new phone you sign in, type the password, and your glimt are readable again. If you never set one and the automatic recovery does not apply, older glimt stay unreadable, because we genuinely cannot open them for you.
You can delete the server-side backup at any time from Settings, and deleting your account deletes it with everything else.
What happens on your device and never reaches us
Some of the most useful things Glimt does happen entirely on your phone. We mention them here because they sound like they should involve a server and they do not.
- Sensitive-content blurring. Glimt checks a photo or video for nudity on the device itself and blurs it behind a warning. No image is uploaded for this, no result is stored, and nothing is sent to us. This is live on iPhone, on iOS 17 or later, and only when "Sensitive Content Warning" is switched on in iOS Settings, because Apple gates the analyser behind that switch. On Android it is not there yet: we are building an on-device model for it, and until that ships an Android phone does not blur or warn. We would rather say that plainly than let a vague sentence imply a protection that is not there.
- Writing down what you say. A voice glimt can be transcribed so someone who cannot hear it can read it. That runs on your phone and the audio never leaves it.
- Your photo library. Picking a photo to send, or saving a glimt you received, is a permission you give the app on your device. We never receive your photo library, only the single encrypted glimt you chose to send.
How long we keep things
- Glimt are deleted after they are viewed, and unopened glimt are automatically deleted after about 30 days.
- Vekeglimt are removed after roughly three weeks.
- Account data (email, username, friends) is kept until you delete your account.
- Your sealed key backup is kept until you turn it off or delete your account.
- Your push token is kept until you turn notifications off or delete your account.
- Report evidence is kept only as long as needed to review and act on the report, then deleted. Material that has to be preserved for a law-enforcement or child-protection obligation is kept for as long as that obligation requires.
Who we share data with
We use a small number of processors purely to run the service, under data-processing terms. We never share your data with advertisers or data brokers, and we do not sell it.
| Who | What they handle |
|---|---|
| Supabase | Database, file storage, sign-in, server functions. Holds your account data, your delivery metadata, your encrypted content and your sealed key backup. Our project is hosted in Europe, in the Nordics |
| Expo, and through it Apple Push Notification service and Google Firebase Cloud Messaging | Delivering push notifications: your device token and the text of the notification |
| Apple iCloud Keychain and Google Block Store | The platform key escrow described above, end-to-end encrypted by the operating system |
One honest detail about notifications: the text that travels through Expo, Apple and Google says who sent you something, and for a bål which fire it was. It never contains the content of a glimt. If you would rather nothing at all travelled that way, turn notifications off.
Transfers outside the EEA
Your account data and your encrypted content are stored in Europe. Our Supabase project is hosted in the Nordics, so that is where the database and the file storage physically sit.
Some of our processors are United States companies, so some data does reach the US:
- Supabase Inc. is a US company even though our project is hosted in Europe, so support and operations access can happen from outside the EEA. Their data processing agreement incorporates the European Commission's Standard Contractual Clauses (Decision 2021/914).
- Expo, Apple and Google receive your device push token and the notification text so a notification can be delivered, and Apple and Google hold the platform-escrowed key material described above. These transfers rest on the EU-US Data Privacy Framework where the recipient is certified under it, and otherwise on the Commission's Standard Contractual Clauses.
The supplementary measure that actually matters here is the design of the app rather than a clause in a contract: the content of a glimt is end-to-end encrypted and never leaves your circle of friends in readable form, the key backup we store is sealed with a password we never receive, and the platform escrow is encrypted by the operating system. What crosses a border is either a token, a name in a notification, or a blob that the recipient cannot open.
Automated decision-making
There is no automated decision-making that produces legal effects for you or similarly significantly affects you in the sense of Article 22.
Two things do happen automatically, and you should know about them:
- An account reported by three different people is banned automatically, without waiting for a human. The ban stops that account posting anything new. It does not delete the account, and taking an account down completely is a step a person performs by hand.
- While a report is being looked at, a reported account can be hidden.
Both are protective, both are reversible, and a person reviews every report. If you think one of them hit you wrongly, write to paal@dynni.no and a person, not a machine, will answer. Our Terms explain what we tell you when we act, and how to contest it.
Your rights
Under the GDPR you can ask for access to your data, correct it, have it erased, get it in a portable form, restrict how we use it, and object to processing based on legitimate interest. Where we rely on your consent, you can withdraw it at any time, and withdrawing it does not make what we did before unlawful: turn notifications off in your device settings, or turn the key backup off in Settings.
You can delete your entire account at any time from Settings, which permanently removes your account, friends, bål, glimt and key backup. For any other request, email paal@dynni.no and we will respond within 30 days.
If you think we have got something wrong, you can complain to the data protection authority in the EU or EEA country where you live, where you work, or where the problem happened. In Norway that is Datatilsynet.
Children
Glimt is not for children under 13 (or a higher age where local law requires, such as 16 in some countries). We ask for date of birth at sign-up and block under-age accounts. See our Child Safety Standards. If you believe a child under the minimum age has an account, contact paal@dynni.no.
Changes
If we change this policy, we will update the date above and, for significant changes, let you know in the app.