GlowHost logo GlowHost
PRIVACY POLICY

How GlowHost handles information

This policy describes the information GlowHost receives, why it is used, when it may be shared, and the choices available to users.

Effective: August 2, 2026 Privacy requests: [email protected]

1. Information we collect

  • Linked account information: Appwrite or Discord account identifiers, display names, usernames, verified email addresses when provided, activation status, plan, and project limit.
  • GDPS information: project names, random folder codes, selected core, settings, staff roles, logos, tags, announcements, public status, switcher options, download links, database details, and content stored by the GDPS.
  • Communications: emails, support requests, abuse reports, and messages you choose to send.
  • Technical information: IP address, request time, browser or user-agent data, referring page, cookies, error details, and server or security logs generated when the service is used.

GlowHost does not ask for your Google or Discord password. Authentication is completed by those providers.

2. Google user data

When you select Continue with Google, GlowHost uses Appwrite to request Google's standard openid, userinfo.email, and userinfo.profile scopes. GlowHost receives and stores only the Appwrite user ID associated with the login, your Google display name, your email address, and your email verification status.

This Google user data is used only to create or locate your GlowHost account, sign you in, prevent duplicate-account abuse, enforce GDPS limits, associate projects with their owner, secure the account, and respond to support requests. GlowHost does not request or access Gmail, Google Drive, Calendar, Contacts, payment information, passwords, or other Google content.

GlowHost does not store Google OAuth access tokens or refresh tokens. After the OAuth callback, GlowHost retrieves the basic account identity from Appwrite, deletes the temporary Appwrite session, and creates a separate HTTP-only GlowHost session. Google identity data remains in the GlowHost account database while the account is active or as otherwise described in the retention section.

Google user data is not sold, used for advertising, or transferred for unrelated purposes. It is disclosed only to Appwrite and Google as needed to complete authentication, to infrastructure providers needed to operate GlowHost, when you direct us to disclose it, or when required for security or valid legal process.

GlowHost's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

3. How we use information

We use information to authenticate users, provision and host GDPS projects, generate credentials, enforce limits, send optional activation messages, provide dashboards, show public projects, prevent abuse, investigate errors, secure the service, respond to support, and comply with valid legal obligations.

GlowHost does not sell personal information and does not use personal information for cross-context behavioral advertising.

4. Information you make public

If public listing is enabled, a GDPS name, logo, tags, status, core, announcements, switcher information, and download links may be available to anyone. GDPS gameplay endpoints and player-provided content may also be accessible through the hosted server.

Do not place email addresses, private credentials, personal information, or unsafe files in public fields. Database passwords and private dashboard account details are not intended for public display.

5. When information is shared

Information may be processed by providers needed to operate GlowHost, including:

  • Appwrite and Google for Google sign-in and account verification.
  • Discord for bot activation and linked Discord identity.
  • Google reCAPTCHA for abuse and bot prevention.
  • Email, DNS, proxy, and infrastructure providers for message delivery, connectivity, security, logging, and hosting.
  • GDPS software and external links when a project owner enables third-party integrations or publishes links.

We may also disclose information when required by law, to respond to valid legal process, to protect users or the service, to investigate fraud or abuse, or during a reorganization of the service. Providers receive only the information reasonably needed for their function and operate under their own policies.

6. Cookies and similar technology

GlowHost uses an HTTP-only session cookie to keep users signed in and a short-lived OAuth state cookie to protect Google sign-in from request forgery. reCAPTCHA and authentication providers may set their own cookies or collect device information under their privacy policies.

Blocking required cookies may prevent sign-in, dashboard access, or protected forms from working.

7. Retention and deletion

Account and GDPS information is generally kept while the account or project is active and as reasonably needed for operation, security, dispute handling, and legal obligations. Operational logs are kept only as long as reasonably useful for those purposes.

Deleting a GDPS is designed to remove its active hosted files and managed database. Some information may remain temporarily in logs, cached systems, or backups when they exist, and may be retained when required for security or legal reasons.

8. Security

GlowHost uses measures such as generated database passwords, access-controlled dashboards, server-side OAuth handling, HTTP-only cookies, reCAPTCHA, and encrypted public connections where available. No online system is completely secure, so users should protect linked accounts and report suspected compromise promptly.

9. Access, correction, and deletion choices

You can edit many GDPS settings or delete projects in the dashboard. You may email [email protected] to ask about access to, correction of, or deletion of personal information associated with your GlowHost account.

We may need to verify your identity before completing a request. Some information may be retained when an exception or legal obligation applies. Where applicable law provides additional privacy rights, GlowHost will process verified requests in accordance with that law and will not discriminate against users for exercising those rights.

10. Children's privacy

GlowHost is a general-audience service and is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 provided personal information, contact us so the account and information can be reviewed and removed as appropriate.

11. International use, changes, and contact

GlowHost and its providers may process information in countries other than your own. Privacy protections may differ by location, subject to applicable law.

We may update this policy as the service changes. The effective date will be updated and material changes may also be announced on the site or Discord. For privacy questions or requests, email [email protected].