Privacy Policy
Last updated: August 26, 2026
Glasshouse is a web app that turns your X (Twitter) bookmarks into a gallery. This policy explains what it accesses, what it stores, and how to get rid of it. Short version: we read your bookmarks with your permission, we store them so they load instantly on any device, we never post anything, and you can delete everything with one click.
What Glasshouse accesses
- Your X bookmarks (read-only).When you sign in, X's official OAuth grants Glasshouse read-only access to your bookmarks, the posts in them, and their public author and media information. We request only read scopes (
bookmark.read,tweet.read,users.read,offline.access). We never post, like, follow, message, or modify anything on your account, and we cannot see your password. - Your X profile. Your X user id, display name, username and profile picture, used to show who is signed in and to attribute bookmarks you choose to share.
What we store
- Your library.The bookmarked posts (text, dates, public like/repost counts), their authors' public profile details, and links to their media on X's servers. Images and videos are loaded directly from X's CDN; we do not keep copies.
- Your X tokens. The access and refresh tokens X issues are stored encrypted at rest (AES-256-GCM) and used only to read your bookmarks. They are never shared and never exposed to your browser.
- Sync bookkeeping. Cursors, timestamps and counts so syncs can resume and stay incremental.
- Shares.If you create a public link for a bookmark, we store the link's identifier and which bookmark it points to.
- A session cookie that keeps you signed in for up to 30 days. It is essential to the service and contains no tracking.
Why we store it
To render your gallery instantly on every device you use, to sync only what changed since last time, and to keep a bookmark in your library even after it disappears from X (Glasshouse is an archive: sync never deletes; a bookmark that X no longer returns is simply marked no longer on X).
Retention & deletion
- Your data is kept until you delete your account. In Glasshouse, open the account menu and choose Delete account & data: your library, sync state, shares and X tokens are removed immediately and we ask X to revoke the token.
- Sign out only ends your session; your library stays so your next sign-in is instant.
- Disconnecting Glasshouse from your X account settings also stops all access; delete your account in Glasshouse to remove the stored copy.
Public share pages
Your library is private. A bookmark becomes visible to others only if you create a public link for it. Such a page shows that one post, its public author details, and that it was shared by you (your X username). Anyone with the link can view it; the links are unguessable and are not indexed by search engines. Choose Stop sharing at any time to revoke a link.
Analytics
- We measure product usage (page views, feature usage such as syncing, searching or opening the lightbox, and errors) with PostHog via NanoCorp, to understand what works and fix what doesn't. Usage events are tied to your X username, never to the content of your bookmarks. There is no advertising and no cross-site tracking.
What we don't do
- We do not sell, rent or trade your data.
- We do not post to X or change anything on your account.
- We do not use your bookmarks to train models or for any purpose other than showing them to you.
Legacy purchases
If you bought a license for the retired Glasshouse Mac app, payment was processed by Stripe and we hold the information Stripe shares with a merchant (your email and purchase amount) to deliver your license code and provide support. We never see or store card details.
Third parties
- X (Twitter):source of your bookmarks and media, under X's own terms and privacy policy.
- Neon hosts our database and Vercel hosts the app; both process data on our behalf.
- PostHog (via NanoCorp): product analytics.
- Stripe and Resend (via NanoCorp): payment processing and email delivery for legacy purchases.
Contact
Questions or requests, including data access or deletion: glasshouse@nanocorp.app