Glean Privacy Notice
Glean is built for private devotion, prayer, and trusted connection. This notice explains what stays on your device, what Glean collects, and when information is shared with service providers.
Effective and last updated: July 24, 2026
The Short Version
You can use Glean’s local features without an account. Your local devotional and prayer library is not uploaded merely because you open the app. If you create an account, Glean processes account, purchase, usage, and encrypted-sync information to provide those features. Personal text is sent to an AI service only after you grant AI data-sharing permission and deliberately submit an AI request.
Information On Your Device
Devotional plans, reflections, private prayers, prayer updates, reminders, guided-reflection and Guided Prayer drafts and transcripts, notes, preferences, AI permission state, and other local settings are stored in the app’s local database or in browser storage. Gemini API keys are stored in secure device storage on Apple platforms and in browser storage on the web. Raw Reflection Guide microphone audio is processed on the device and is not uploaded by Glean. Raw Guided Prayer microphone audio is also transcribed on the iPhone and is not uploaded. Deleting the app, clearing browser storage, or losing a device may remove device-only information, so exported backup files should be protected.
Accounts And Authentication
If you create an account, Glean collects your display name and phone number directly from you and processes encrypted contact data, a normalized lookup value, a password hash, one-time-code delivery and verification records, device and session identifiers, account status, and security events. Glean uses this information to create and secure the account, authenticate devices, support recovery, prevent abuse, and respond to support requests. Glean does not store your plaintext password or one-time code.
Encrypted Synchronization
You choose which local devotionals and private prayers to synchronize. Selected records are encrypted on your device before upload. Glean stores ciphertext, record identifiers, versions, sync state, device information, and deletion markers in Supabase-hosted PostgreSQL. Ordinary synchronization does not require readable devotional or private-prayer content. Accounts configured for protected recovery include a recovery envelope that can be used only through Glean’s authenticated, audited recovery process; confidential accounts do not permit owner-assisted content-key recovery.
Private Prayer And Trusted Sharing
A private prayer is not shared automatically. When you share, Glean creates a separate request and shows you its wording and recipients before sending. Private notes, Guided Prayer transcripts, and unselected prayer text are not included in that request.
Shared prayer requests, messages, updates, acknowledgements, and selected Scripture are encrypted for approved devices in each one-to-one connection. Glean stores encrypted content plus operational metadata needed to route and order it, such as account and connection identifiers, event types, timestamps, delivery state, and key versions.
Circle names and membership are private to the person who created them. Recipients do not see the Circle or one another. Glean does not provide public people search, public prayer feeds, prayer counts, group chats, or recipient lists.
Connections, Devices, Notifications, And Safety
Glean processes display names, generated avatar information, invitation tokens or friend codes, connection state, blocks, notification preferences, device public keys, key-directory versions, and device registration records to provide invite-only connections and encrypted delivery. Display names are not unique and are not searchable.
Prayer notifications use generic wording and safe routing identifiers. They do not include prayer text, message text, Scripture text, Circle membership, or recipient lists. Your operating-system notification settings may affect whether a notification appears.
Reporting may send the selected content and necessary context to Glean’s safety systems for review. The report screen explains this before submission. Blocking prevents new contact through that connection; limited safety, audit, and legal records may be retained when necessary to prevent abuse or comply with law.
AI Processing And Permission
Before Glean sends personal text to an AI service in the Apple app, it explains what is sent, identifies the recipients, and asks you to allow AI data sharing. You can decline and continue using non-AI features, or withdraw permission at any time in Settings → Permissions.
Hosted Glean AI. When you deliberately submit a hosted AI request, Glean’s service receives the text and settings necessary to complete it. Depending on the feature, this may include your reflection, a reviewed voice transcript, guided-reflection or Guided Prayer answers, journal answers, follow-up instructions, relevant devotional content, and settings such as duration, tone, focus, tradition, and selected model. Glean sends that request to Gloo, LLC (Gloo AI), a third-party AI processor. Gloo may process it with the model provider you select—or one selected by Gloo AI Core—such as OpenAI, Anthropic, or Google. Glean uses the response only to provide the devotional, prayer-language guidance, reflection guidance, regeneration, insight, or summary you requested.
Glean records operational information such as the request type, model or routing choice, credit cost, token counts, timing, and success or failure status. Glean does not intentionally put prompt or output text in application logs or the credit ledger. A successful hosted result may remain encrypted on Glean’s server until your device acknowledges delivery or for up to 24 hours, whichever comes first.
Gemini with your own key. On Apple platforms, the app sends the prompt and your API key directly to Google’s Gemini API. In the web experience, Glean’s compatibility service transiently receives the key, prompt, and response to forward the request; Glean does not intentionally persist them. Google’s terms and privacy practices apply.
Copy and import. If you copy a prompt into another AI service, you choose the recipient and that service’s terms apply. Importing the returned content does not send it to Glean unless you later select it for encrypted sync or submit it in another hosted AI request.
Review Gloo’s Privacy Statement and the privacy terms of any selected model provider for more information about their processing.
Purchases, Credits, And Service Records
Apple processes in-app purchases and provides Glean with signed transaction identifiers, product, purchase, expiration, refund or revocation state, environment, and account-binding information. Glean stores transaction and entitlement history, credit grants and usage, current balances, reconciliation records, and limited fraud, support, and audit information. Glean does not receive your full payment-card details.
How Glean Uses Information
Glean uses information to provide local and synchronized devotional and prayer features, trusted one-to-one connection, authenticate and recover accounts, deliver verification messages, fulfill user-requested AI processing, process and reconcile purchases, display balances and usage, provide support, improve reliability, prevent fraud and abuse, comply with law, and protect the service. Glean does not sell your devotional, prayer, or conversation content or use it to create a public profile.
Service Providers And Protection
Glean shares only the information needed for contracted or user-requested functions. Current providers include Supabase for hosted database infrastructure, Telnyx for verification messaging, Gloo AI and applicable model providers for hosted AI, Google for Gemini requests, and Apple for purchases and platform services. Glean requires providers that receive personal data to protect it consistently with this notice and to provide the same or equal protection required by applicable App Store privacy rules. Glean may also disclose information when legally required or necessary to protect rights, safety, users, or the service.
Retention And Deletion
- Device-only data remains until you delete it, clear the app or browser profile, or remove the app.
- Encrypted sync content remains while the account or record is active and is removed through the account or record deletion workflow.
- Hosted AI result ciphertext remains until delivery is acknowledged or for up to 24 hours.
- Short-lived one-time codes, sessions, and recovery material expire or are removed according to their security purpose.
- Apple transaction, credit, entitlement, refund, security, and accounting evidence may be retained as required for purchase restoration, fraud prevention, disputes, accounting, or law.
- Managed database backups age out according to the infrastructure provider’s backup schedule.
In-app account deletion immediately revokes sessions, erases routable identity and credentials, removes synchronized ciphertext and usable content keys, and deletes pending AI results. Glean retains only limited pseudonymous financial and audit evidence when needed for the purposes above.
Your Choices And Rights
You can use local features without an account, choose what to synchronize, export local data, use copy/import instead of an integrated AI service, allow or revoke AI data sharing, manage sessions, and delete your account in the app. Depending on where you live, you may also have rights to access, correct, delete, restrict, or receive information. Contact support@thegleanpractice.com to make a privacy request. Glean may need to verify that the request belongs to you.
Security, Changes, And Contact
Glean uses TLS, password hashing, one-time-code verification, session protection, on-device encryption for synchronized devotional, private-prayer, and shared-prayer content, restricted database access, redacted logging, and audited security operations. No system is perfectly secure. Protect your device, account password, Gemini keys, and exported backups. Glean will update this notice and its date when practices materially change, and will request new permission before a material expansion of third-party AI processing. Questions and privacy requests may be sent to support@thegleanpractice.com.