Who is responsible
Sansa Group AB, Gothenburg, Sweden, is the controller of the personal data processed in Glimt. Glimt is made by Sansavision, a division of Sansa Group AB. For anything about your data, email privacy@glimt.my.
The short version
- Your clips, photos, voice and projects are used only to make your project.
- They are never used to train AI, and we don't sell your data.
- AI steps run through OpenRouter and the AI providers it connects to, which get only what that step needs.
- Glimt is hosted on Cloudflare, with data stored in the EU where we can choose.
- You can see, export or delete your data. Glimt is for adults, 18+.
What we collect
Account
Your email address, sign-in records, your confirmation that you are 18 or older, and your plan.
Your content
What you describe (your goals and edits), and what you upload or make: clips, photos, logos, audio, scripts, storyboards, generated images, voice-overs, captions, music and exported videos.
Usage and billing
How many AI credits and songs you use, and, once paid plans open, your subscription and payment status. Card details are handled by our payment provider; we never see or store your full card number.
Technical data
IP address, browser and device details, and logs we need to keep Glimt secure and working.
Support
What you tell us when you email us.
We don't use advertising or cross-site tracking cookies. We use only the cookies Glimt needs to work, such as keeping you signed in and protecting sign-in from abuse.
How we use it, and why
| Purpose | Legal basis (GDPR) |
|---|---|
| Run your account and make, edit, store, share and export your videos | Contract |
| Count AI credits and songs, and handle billing | Contract; legal obligation for bookkeeping |
| Keep Glimt secure, prevent abuse and enforce the age limit and acceptable use | Legitimate interests; legal obligation |
| Fix problems and improve reliability, using logs and aggregate usage (not your media) | Legitimate interests |
| Answer your questions | Contract; legitimate interests |
| Product news by email, if you choose to receive it | Consent (withdraw any time) |
Your media and AI training
Your media is used only for your project. We don't use your content to train AI, and we don't let it be used for anyone else's training either: we only send content to AI providers to do a step of your project, and we configure Glimt to use routes that don't train on it.
When an AI step runs (for example making an image, voicing a line or timing captions), we send only what that step needs, such as the text of a scene or a single audio file.
Who processes data for us
We use a small number of service providers (subprocessors), under contracts that limit how they use your data:
| Provider | What for | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting the site and app, storage for your media and projects, databases, background jobs, email delivery and bot protection | Global network; databases and storage in the EU where available |
| OpenRouter, Inc. | Routing AI requests (planning, scripts, images, voice, captions and music) to AI providers | United States |
| AI providers reached through OpenRouter | Doing a single AI step with the input for that step | Varies by provider (mainly United States and EU) |
| Payment provider (from when paid plans open) | Checkout, subscriptions, invoices and receipts | EU and United States |
When data leaves the EU/EEA, we rely on adequacy decisions (such as the EU–US Data Privacy Framework) or the European Commission's standard contractual clauses. We'll keep a current list of subprocessors on this page.
We share content with other people only when you choose to, for example with a share link or by inviting a collaborator. We may disclose data if the law requires it.
How long we keep it
- Your account data, for as long as you have an account.
- Your projects and media, until you delete them or your account.
- When you delete something, we remove it from our active systems, and from backups as they cycle out.
- Billing records, for as long as bookkeeping law requires (in Sweden, generally seven years).
- Security logs, for a limited period. We'll publish exact retention periods before launch.
Your rights
Under the GDPR you can ask us to:
- give you a copy of your personal data, or send it to you in a portable format;
- correct data that is wrong, or delete your data;
- restrict or object to some processing, including processing based on legitimate interests;
- stop using your data for anything you consented to.
Email privacy@glimt.my; we answer within one month. You can also complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or your local data protection authority.
Security
Data is encrypted in transit, media is served through signed, expiring links, and access inside our team is limited to people who need it. No system is perfectly secure; if something goes wrong that affects you, we'll tell you and the authorities as the law requires. Report security issues to security@glimt.my.
Adults only
Glimt is for people aged 18 and over, and we don't knowingly collect data from anyone younger. If we learn that an account belongs to someone under 18, we delete it.
Changes and contact
We'll post changes here and update the date at the top, and tell you directly about important ones. Questions: privacy@glimt.my, or Sansa Group AB, Gothenburg, Sweden.