Glidepad privacy policy
What Glidepad knows about you, which is close to nothing, and exactly where the exceptions are.
The short version. The free version of the extension collects nothing about you. Once, on install, it asks our own server which day your three free weeks of Pro began, and the only thing that travels is a cookie holding that date. Pro also sends the licence key, with the activation identifier and browser label that go with it, to check that the key is still valid, about once a day. glidepad.app sets one cookie of its own — that date, and only in answer to the extension — and a second one only if you use Pro in this browser: an encrypted copy of your licence key and of this browser’s activation that only our server can read. It runs no analytics scripts and loads no third-party trackers. Beyond that, the only personal data we hold is a short record of each order — itemised under “Payments” below — and we never see your card details. Messages sent through the feedback form are stored without an email or IP address and deleted after twelve months.
Who is responsible
Ivan Korost, an independent developer, is the data controller for
glidepad.app and the Glidepad extension. Contact:
support@glidepad.app.
No company has been registered for Glidepad. If one is, its name and registered address will be stated here.
The extension
- What it processes. Scroll events from your touchpad — two numbers and a timestamp each — to recognise gestures. This happens in the page, in memory, and is discarded immediately. It is never written down and never leaves the machine.
- What it does not read. Page content, form fields, passwords, browsing history, the addresses of pages you visit. None of it is read, and none of it is needed to detect a swipe.
- What it stores. Your own settings: whether Glidepad handles swipes at all, the addresses you assigned to each direction, what two flicks at the top of a page do, which pinch gestures are on, whether a double swipe returns to the tab it opened last time, which of the sixteen languages the interface is in, whether the horizontal axis is inverted, and the recognition thresholds. Beside them: your licence key, if you have one, the day your first three weeks with Pro started, as our server signed it, and — while a key is active — the identifier this browser’s activation was given and the last answer the licence check came back with. For the length of a browser session it also holds the numeric id of the tab a swipe opened, with the address that tab stands for, which is what lets the next swipe return to it instead of opening a copy; both are discarded when the session ends. All of it is stored through the browser’s own storage API.
- Where those settings go. If you are signed into your browser with sync switched on, your browser copies most of the settings, the licence key and the day your free Pro days began to your browser account — that is a transfer to Google, Microsoft or Mozilla under their own privacy terms, not to us. We have no access to it and no copy of it. The axis inversion and the recognition thresholds, which are measured on this touchpad, the activation identifier, the last answer about the key and the tab ids never go there: they belong to one browser on one computer and stay on it.
-
Network. The free version makes one request, on install and
again only after a reinstall: it asks our own server on
glidepad.appwhich day your three free weeks of Pro began, so that reinstalling does not start them over. The only thing that travels is the cookie described under “Cookies” below. If Pro was bought or used in this browser before, the answer to that same request can carry the licence key, taken from the second cookie described there, and one more such request goes out when you come back from the checkout page. Once there is a key, the extension also sends that key, an identifier for this device’s activation and a label such as “Chrome on Windows” to the same server: on activation, about once a day after that, and once more when you press “Remove the key”; the first and the last of these carry the second cookie too. Our server checks with the merchant of record that the key is still paid for and answers with a status and, where there is one, the date Pro is paid up to. Nothing of this stays with us: the checks are not recorded, and neither keys nor IP addresses are logged (the one exception is the keyed hash of a key, described under “Payments”); requests are only rate-limited by IP address at the Cloudflare edge, in memory. There is no analytics, no crash reporting, no update ping beyond the browser’s own extension updates. One more address is set in advance rather than requested: when you remove Glidepad, the browser opens the feedback page on glidepad.app, and the extension’s version, its interface language and whether Pro was on are written into the fragment of that address — the part after#, which browsers do not send to any server. It reaches us only if you press Send on that page. The Feedback buttons inside the extension open the same page the same way. -
Permissions. The manifest asks for three permissions and for access
to every site.
storageholds the settings and the key described above.activeTabis used by one button: the anchor next to a swipe direction in the popup reads the address of the tab you are on, only when you click it and only for that one tab.scriptinglets the extension start itself in tabs that were already open when it was installed or updated, so gestures work there without reloading the page; what it injects is its own bundled file and nothing else. The extension does run on every site, which the browser reports as “read and change all your data on all websites”. That is the permission gestures require, because gestures happen everywhere; it is not a description of what Glidepad does with it. - Chrome Web Store Limited Use. The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. In practice there is nothing to adhere to: the extension asks for no Google API access and sends nothing except the install date and the licence key described above.
The glidepad.app website
- Hosting. Static pages served by Cloudflare Workers. Cloudflare processes IP addresses and request metadata to deliver and protect the site, as our hosting provider.
-
Cookies. Two from us, both only for the extension. When the
extension asks which day your free Pro days began, our server answers with a cookie
named
gp_windowonglidepad.appholding exactly that date: the day in UTC, signed so it cannot be edited. Everyone who installed Glidepad on the same day gets an identical cookie, so it identifies no one, and our server neither stores nor logs it. It isHttpOnly, is sent back only to that one address (/api/license/window) and expires 400 days after the extension last asked. It is set only in answer to the extension: visiting glidepad.app sets no cookie, except for the return from the checkout described next, and neither our pages nor any other website can set or read it. Deleting your cookies forglidepad.appremoves it. -
The licence cookie. The second cookie,
gp_license, belongs to Pro. It is set when you come back from the checkout through the link the merchant of record signs for that return, and again each time Glidepad activates a licence key in this browser. It holds an encrypted copy of your licence key, the identifier of this browser’s activation and, after a purchase, a random identifier for activating it; only our server can decrypt it, and it keeps no copy. That is what lets a reinstalled Glidepad switch Pro back on by itself and take the same place on the key instead of a new one. It isHttpOnly, is sent back only to/api/license/, and expires 400 days after the last activation; “Remove the key” deletes it, and so does deleting your cookies forglidepad.app. On its own it switches nothing on: the extension gets the key only by asking our server, and our server hands it only to Glidepad itself, never to another extension or a website. No tracking pixels, no session cookies, no consent banner. Cloudflare may set a short-lived security cookie of its own where its bot protection is switched on; it carries no identifier we can read and is not used to track you. - Analytics. No analytics service, no script, no profile of you. We do count requests to a couple of our own pages on our own side, in our own database, to see whether anyone is interested in the paid version. What is stored is a number per day and nothing else — no cookie, no identifier, no IP address, no user agent, and nothing leaves our hosting.
-
Fonts. Typefaces are loaded from Google Fonts, so your browser makes
a request to
fonts.googleapis.comandfonts.gstatic.com, and your IP address is visible to Google in the process. Nothing else is sent, and no cookie is set by that request. - The live gesture check. Runs entirely in your browser. The numbers it shows are never transmitted anywhere.
Payments
Purchases are handled by Freemius, Inc., our merchant of record: an authorised reseller that becomes the seller of the licence. It collects your name, email, billing address, tax location and payment details as an independent controller of that data, under its own privacy notice. We never see or hold your card details.
The licence key itself is issued by the merchant of record at the moment of payment and delivered to you in the receipt email and in its own purchase portal; we do not hold a copy of it. What reaches us is a notification of each order. From it we keep the order identifier, which plan it is, the last five characters of the key — enough to recognise your order in an email exchange — the date, the status (paid, refunded or disputed), the subscription identifier, the provider’s own identifier for the licence — an opaque string that is neither the key nor usable in its place — the date the subscription is paid up to, and a keyed hash of the key. The hash cannot be turned back into the key or used in its place; it lets our server recognise your key and keep Pro working to the end of the paid period even if the merchant of record ever stops answering. We do not keep your email address, your name, your country, your IP address or the full key. When you write to support, your order is found by the email address you paid with in the merchant of record’s own dashboard, not in anything of ours.
Sale records are kept only as long as the tax law of the place the business is registered in requires records of a sale to be kept — several years in any jurisdiction it could end up being. The exact period is named here once that registration exists. The “paid up to” date is kept for as long as the key can still be activated.
Feedback
The form at glidepad.app/feedback/ stores each message in our own database on Cloudflare: the text, the reason you picked, and a line of technical detail — Glidepad’s version, its interface language and whether Pro was on, taken from the page address when the extension opened it, plus your browser, its major version and your operating system, read by the page when you press Send. There is no email address, no IP address, no cookie and nothing that ties a message to a licence key or a device. Sending is rate-limited by IP address at the Cloudflare edge, in memory, as with the licence checks. Each message is deleted twelve months after it arrives.
The form has no email field. If you want an answer, write to support@glidepad.app instead — that is support email, below. Since a message carries nothing that identifies you, we can find it only by its text: quote it and we will delete it.
Support email
If you write to us, we keep the correspondence for as long as it takes to resolve the matter and a reasonable period after, then delete it.
Your rights
You can ask for a copy of what we hold about you, ask for it to be corrected or deleted, object to processing, or ask for it in a portable form. One email to support@glidepad.app is enough; there is no form and no fee, and the answer usually arrives the same week. If you are in the EEA or the UK you may also complain to your national data protection authority.
International transfers
The site is served from Cloudflare’s global network, so data may be processed outside your country; Cloudflare relies on standard contractual clauses for those transfers. The merchant of record also processes payment data outside your country, relying on standard contractual clauses as its own privacy notice (linked under “Payments”) describes.
Children
Glidepad is not directed at children under 16 and we do not knowingly collect their data.
Changes
If this policy changes, the date at the top changes with it. Changes that affect what we collect are announced on this page before they take effect.