G
Glimpse
Data Security

How Glimpse handles your data

What we collect, where it's stored, and who can access it — in plain language. We'd rather tell you what we can verify than make claims we can't back up.

What We Collect

The data behind your dashboard

Every field below maps directly to something Glimpse's dashboard actually displays or uses.

Brand entity information

The brand or product name, type, and URL you register for tracking — the starting point for everything Glimpse monitors.

Collected mentions

Author handle, platform, publish time, message content, engagement count, detected language, and sentiment for every mention Glimpse's crawler picks up.

Integrity signals

A bot score and troll score are calculated per mention, so inauthentic activity is flagged rather than mixed silently into your real feedback.

Account credentials

A username and authenticated session token per login — dashboards are never accessible without one.

Alert configuration

Recipient email address, health-score thresholds, and any webhook URLs you add for Slack, Microsoft Teams, or n8n.

Storage & Access

Where it lives, and who can see it

Stored in a dedicated database

Glimpse's backend persists data in MongoDB, running as its own service separate from the application server, with data written to a persistent volume rather than in-memory or ephemeral storage.

Authenticated access only

Every dashboard — Brand, Admin, and Superadmin — requires a login. There is no public or anonymous access to brand data.

Role-based permissions

Accounts are assigned Admin, Operator, or Viewer roles, each scoped to a specific level of access — not everyone with a login sees or changes the same things.

You control where alerts go

Slack, Microsoft Teams, and n8n alert integrations only send data to webhook URLs you explicitly configure yourself. Glimpse doesn't push your data anywhere you haven't set up.

Still Being Formalized

What we haven't published yet

We intentionally don't publish claims here we can't stand behind. Formal answers on hosting region and provider, encryption-at-rest specifics, backup policy, subprocessors beyond the integrations you configure yourself, data retention and deletion periods, and any compliance certifications are in progress — if one of these is a blocker for your evaluation, reach out and we'll get you a direct answer.

Have a data security question?

Reach out and we'll get you a direct, honest answer.

Data Security FAQs

Access is role-based: Admin, Operator, and Viewer roles control what a given account can see and change, and every dashboard requires an authenticated login — there is no public access to brand data.

Alert delivery integrations (Slack, Microsoft Teams, n8n) only send data to destinations you explicitly configure with your own webhook URLs — Glimpse doesn't push your data anywhere you haven't set up yourself.

Yes — Admin, Operator, and Viewer are distinct roles with different scopes, so not every account with a login has the same level of access to settings or data.

Reach out directly — this page deliberately doesn't publish claims about hosting, encryption specifics, or compliance certifications that haven't been formally confirmed yet, but we can answer specific questions directly.

In a dedicated MongoDB database, run as its own service separate from the application server, with data written to persistent storage rather than kept only in memory.

Retention and deletion periods haven't been formally published yet — this is one of the specifics on our "still being formalized" list. Reach out if a defined retention period is a requirement for your evaluation.