Back to home

Privacy Policy

Effective date: 9 June 2026

1. Who we are

Manager (“Manager”, “we”, “our”, or “us”) is a task and meeting management platform operated by Glie, Lda. (Portugal), available at glie.ai. This policy explains what information we collect, how we use it, and the rights you have over it.

For any privacy-related question, or to exercise your rights, contact us at privacy@glie.ai.

2. Scope

This policy applies to personal data we process when you use Manager — the marketing site, the application, and the Google integrations described in Section 6.

Important — Google user data is governed solely by Section 6. The purposes (Section 4), legal bases (Section 5), and sharing and disclosure categories (Section 7) described in this policy do not apply to data obtained through Google APIs. Our access to, use of, storage of, sharing of, and retention of Google user data is governed exclusively by Section 6 and by the Google API Services User Data Policy, including the Limited Use requirements.

3. Data we collect

3.1 Data not obtained from Google APIs

  • Account data: your name, email address, hashed password, and optional two-factor authentication settings. Authentication is handled by our own application (Auth.js / NextAuth) with passwords hashed using bcrypt; we never store passwords in plain text.
  • Workspace content: tasks, meetings, comments, contacts, files, and other content you or your workspace members create inside Manager.
  • Billing data: subscription and payment-method details are processed and stored by Stripe. We do not receive or store full card numbers.
  • Usage and technical data: log files, IP address, browser type, and actions performed in the app, used for security, debugging, and abuse prevention.
  • Push subscriptions: if you enable browser notifications, the push subscription provided by your browser, used to deliver Web Push notifications.
  • Cookies: strictly necessary session cookies for authentication and functional cookies to remember your preferences (such as language). With your consent, we also set first-party analytics cookies (PostHog) to understand how Manager is used and improve it; these load only after you accept them in the cookie banner, and declining leaves every feature working. We do not use advertising or cross-site tracking cookies.

3.2 Data obtained from Google APIs

If, and only if, you choose to use a Google integration, we access certain Google user data. The categories, scopes, purposes, storage, retention, and revocation for that data are described in full in Section 6.

4. How we use your data

This section describes the use of data *not* obtained from Google APIs. For Google user data, see Section 6.

  • To provide, operate, maintain, and improve the Manager service.
  • To authenticate you and secure your account (including two-factor authentication).
  • To process payments and manage subscriptions (via Stripe).
  • To send service communications — daily summaries, invitations, security and billing notices — by email and, where enabled, Web Push.
  • To detect, investigate, and prevent fraud, abuse, and security incidents.
  • To comply with applicable legal obligations.

5. Legal bases

This section describes the legal bases for data *not* obtained from Google APIs (under the GDPR and the Brazilian LGPD). For Google user data, see Section 6.

  • Performance of a contract: to provide the service you signed up for (account, workspaces, tasks, meetings, billing).
  • Legitimate interests: to secure the platform, prevent abuse, and improve the product, balanced against your rights.
  • Consent: for optional features you explicitly enable, such as browser notifications and analytics cookies. You may withdraw consent at any time.
  • Legal obligation: to retain billing records and respond to lawful requests.

6. Google user data

This section governs all data we access through Google APIs. It is self-contained: it overrides and is independent from Sections 4, 5, and 7. If you never connect a Google account, none of this section applies to you.

6.1 Integrations we offer

  • Sign in with Google — an optional way to authenticate, as an alternative to email and password.
  • Google Calendar & Google Tasks two-way sync — an optional integration you enable from Account → Calendar, which keeps your Manager meetings and tasks in sync with your Google Calendar and Google Tasks.

6.2 Scopes we request (verbatim)

  • Sign in with Google (OpenID Connect): `openid`, `https://www.googleapis.com/auth/userinfo.email`, `https://www.googleapis.com/auth/userinfo.profile`
  • Calendar & Tasks integration: `https://www.googleapis.com/auth/calendar`, `https://www.googleapis.com/auth/tasks`, `https://www.googleapis.com/auth/userinfo.email`

6.3 Scopes we do not request

We do not request access to Gmail, Google Drive, Google Contacts, Google Photos, location history, or any Google data other than the scopes listed in Section 6.2.

6.4 How we use Google user data

We use Google user data solely to provide the features above:

  • Email and profile (sign-in): to authenticate you and to create or identify your account using your name, email address, and avatar.
  • Calendar: to read your calendar list and events so we can display and import them, and to create, update, and delete the calendar events that correspond to meetings you manage in Manager.
  • Tasks: to read your task lists and tasks, and to create, update, and delete the tasks that correspond to tasks you manage in Manager.
  • userinfo.email (integration): to record which Google account a calendar connection belongs to.

We use Google user data only to provide and improve these user-facing features, at your direction. We do not sell it, we do not use it for advertising, we do not use it to train generalized or AI/ML models, and we do not allow humans to read it, except: (a) with your prior consent for specific data; (b) as necessary for security purposes or to comply with applicable law; or (c) where the data has been aggregated and anonymized.

6.5 Storage and encryption

Google OAuth access and refresh tokens are encrypted at rest using AES-256-GCM before being stored in our database. Synced event and task content is stored in our database only as needed to provide the synchronization feature.

6.6 Retention and revocation

Google tokens and synced data are retained only while the connection is active. You can revoke our access at any time by:

  • disconnecting the integration in Account → Calendar, which revokes the token with Google and deletes the stored tokens; or
  • removing access from your Google Account at myaccount.google.com/permissions.

When you disconnect, or when you delete your account, we delete the stored Google tokens and stop accessing your Google data.

6.7 Limited Use commitment

Manager’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6.8 “Sign in with Google” vs. the Google APIs integration

These are two separate, independent authorizations. Sign in with Google uses OpenID Connect for authentication only — it identifies you and does not grant any access to your Google Calendar or Google Tasks. The Calendar & Tasks integration is a separate consent that you grant explicitly, and only then do we access calendar and task data. You can use either without the other, and revoking one does not affect the other.

7. Sharing and disclosure

This section describes sharing of data *not* obtained from Google APIs. Google user data is never shared except as described in Section 6.

We share non-Google data with the following sub-processors:

  • Stripe — payment processing. Governed by Stripe’s Privacy Policy.
  • PostHog — first-party product analytics, loaded only with your consent and processed on PostHog’s EU Cloud. Governed by PostHog’s Privacy Policy.
  • Email delivery (SMTP relay) — transactional emails (summaries, invitations, security and billing notices) are sent through an SMTP relay provider.
  • Object storage — an S3-compatible storage provider hosts files and images you upload.
  • Hosting infrastructure — the provider that runs our application and database.

We may also disclose non-Google data: (a) to comply with the law or a valid legal request; (b) to protect the rights, safety, and security of Manager, our users, or the public; and (c) in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honour this policy and will notify you of any change in control or applicable policy.

We do not sell your personal data, and we do not share Google user data with any of the third parties listed above.

8. International transfers

Manager and its sub-processors may process data in countries other than your own, including outside the European Economic Area. Where personal data is transferred internationally, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, to ensure a comparable level of protection.

9. Data retention

We retain your account and workspace data for as long as your account is active. You may request deletion of your account and associated data at any time by contacting privacy@glie.ai. Billing records may be retained for up to 7 years to meet legal and accounting obligations. Google tokens and synced Google data are retained only as described in Section 6.6.

10. Your rights

Depending on where you live (including under the GDPR in the EEA/UK and the LGPD in Brazil), you have the following rights over your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion of your data.
  • Portability: receive your data in a structured, machine-readable format.
  • Restriction and objection: restrict or object to certain processing.
  • Withdraw consent: where processing is based on consent, withdraw it at any time.
  • Complaint: lodge a complaint with your local data protection authority (for example, the ANPD in Brazil, or your EU supervisory authority).

To exercise any of these rights, email privacy@glie.ai. You can also revoke Google access directly, as described in Section 6.6.

11. Security

We use industry-standard security measures, including TLS encryption in transit, AES-256-GCM encryption of OAuth tokens at rest, hashed passwords (bcrypt), non-root container processes, and security headers (HSTS, CSP, X-Frame-Options). Access to production systems is restricted to authorised personnel. No method of transmission or storage is completely secure, but we work to protect your data using these safeguards.

12. Children

Manager is not directed to children. We do not knowingly collect personal data from children under the age required by your jurisdiction (16 in much of the EEA; 13 in several other regions). If you believe a child has provided us with personal data, contact us at privacy@glie.ai and we will delete it.

13. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email or via a notice in the app, and the effective date above will be updated. Your continued use of Manager after the effective date constitutes acceptance of the updated policy.

14. Contact

For privacy questions, requests, or complaints, contact us at privacy@glie.ai.