Basic Google profile and email, or basic Discord identity only. No passwords, messages, servers, or contacts.
Your account data
has one job.
Glowhost uses the minimum identity and operational information needed to sign you in, assign projects, run hosting, prevent abuse, and provide support.
Glowhost does not sell personal information or use it for behavioral advertising.
Glowhost does not store Google or Discord OAuth access or refresh tokens.
Contact us to request access, correction, or deletion of account information.
1. Information we collect
- Linked account information: Google or Discord account identifiers, display names, usernames, verified email addresses when provided, activation status, plan, and project limit.
- GDPS information: project names, random folder codes, selected core, settings, staff roles, logos, tags, announcements, public status, switcher options, download links, database details, and content stored by the GDPS.
- Communications: emails, support requests, abuse reports, and messages you choose to send.
- GlowAI conversations: prompts, automatically redacted prompt text, model replies, timestamps, and a random browser-session identifier used to preserve chat history.
- Technical information: IP address, request time, browser or user-agent data, referring page, cookies, error details, and server or security logs generated when the service is used.
Glowhost does not ask for your Google or Discord password. Authentication is completed by those providers.
2. Google user data
When you select Continue with Google, Glowhost directly requests Google's standard openid, email, and profile scopes. Glowhost receives and stores only your stable Google account ID, display name, email address, and email verification status.
This Google user data is used only to create or locate your Glowhost account, sign you in, prevent duplicate-account abuse, enforce GDPS limits, associate projects with their owner, secure the account, and respond to support requests. Glowhost does not request or access Gmail, Google Drive, Calendar, Contacts, payment information, passwords, or other Google content.
Glowhost does not request or store Google OAuth access tokens or refresh tokens. Google Identity Services returns a signed identity token, the Glowhost server verifies it and discards the raw response, and Glowhost creates a separate HTTP-only session. Google identity data remains in the Glowhost account database while the account is active or as otherwise described in the retention section.
Google user data is not sold, used for advertising, or transferred for unrelated purposes. It is disclosed only to Google as needed to complete authentication, to infrastructure providers needed to operate Glowhost, when you direct us to disclose it, or when required for security or valid legal process.
Glowhost's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
3. Discord user data
When you select Continue with Discord, Glowhost uses Discord's OAuth2 authorization-code flow and requests the identify and guilds.join scopes. Discord may provide your stable user ID, username, and display name, and permits Glowhost to add that account to the public Glowhost Discord server.
Glowhost uses this information only to create or locate your dashboard account, preserve projects previously linked through Discord, join the public community server, enforce account limits, secure the service, and provide support. Glowhost does not request a list of your other servers, messages, friends, contacts, email, or Discord password.
The Discord access token is used during the callback to retrieve your identity and request membership in the public Glowhost server, then it is discarded. Glowhost does not store Discord OAuth access tokens or refresh tokens.
4. How we use information
We use information to authenticate users, provision and host GDPS projects, generate credentials, enforce limits, send optional activation messages, provide dashboards, show public projects, prevent abuse, investigate errors, secure the service, respond to support, operate GlowAI conversations, and comply with valid legal obligations.
GlowAI sends the current prompt and a limited amount of conversation history to its model so it can answer in context. Common secret patterns are redacted before model processing, but automatic redaction is not guaranteed to find every secret.
Glowhost does not sell personal information and does not use personal information for cross-context behavioral advertising.
5. Information you make public
Every hosted GDPS is listed publicly. Its name, logo, tags, status, core, announcements, switcher information, and download links may be available to anyone. GDPS gameplay endpoints and player-provided content may also be accessible through the hosted server.
Do not place email addresses, private credentials, personal information, or unsafe files in public fields. Database passwords and private dashboard account details are not intended for public display.
8. Retention and deletion
Account and GDPS information is generally kept while the account or project is active and as reasonably needed for operation, security, dispute handling, and legal obligations. Operational logs are kept only as long as reasonably useful for those purposes.
GlowAI keeps at most 40 conversation messages for up to 30 days from the latest activity. Using Reset chat deletes the active conversation immediately. Rate-limit records use a one-way hash derived from the connecting IP and expire after one day; infrastructure security logs may follow the provider's shorter or separate operational retention.
Deleting a GDPS is designed to remove its active hosted files and managed database. Some information may remain temporarily in logs, cached systems, or backups when they exist, and may be retained when required for security or legal reasons.
9. Security
Glowhost uses measures such as generated database passwords, access-controlled dashboards, server-side OAuth handling, HTTP-only cookies, reCAPTCHA, encrypted public connections, GlowAI origin checks, prompt-size limits, and per-connection rate limits. No online system is completely secure, so users should protect linked accounts and report suspected compromise promptly.
10. Access, correction, and deletion choices
You can edit many GDPS settings or delete projects in the dashboard. You may email [email protected] to ask about access to, correction of, or deletion of personal information associated with your Glowhost account.
We may need to verify your identity before completing a request. Some information may be retained when an exception or legal obligation applies. Where applicable law provides additional privacy rights, Glowhost will process verified requests in accordance with that law and will not discriminate against users for exercising those rights.
11. Children's privacy
Glowhost is a general-audience service and is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 provided personal information, contact us so the account and information can be reviewed and removed as appropriate.
12. International use, changes, and contact
Glowhost and its providers may process information in countries other than your own. Privacy protections may differ by location, subject to applicable law.
We may update this policy as the service changes. The effective date will be updated and material changes may also be announced on the site or Discord. For privacy questions or requests, email [email protected].