gloss

Draft for legal review. Not yet in effect.

Privacy Policy

Standby Ops LLC · Draft of October 3, 2026 · Covers Gloss. Other Standby Ops apps get their own section here when they launch.

This policy has two parts. Part 1 covers how Standby Ops LLC handles personal information in every app. Part 2 says exactly what Gloss collects and why. Where they differ, Part 2 wins for Gloss.

Part 1: Standby Ops LLC

Who we are

Standby Ops LLC is a company in the District of Columbia, USA. We publish Gloss. "We", "us" and "our" mean Standby Ops LLC. Contact: [email protected]. Security problems: [email protected].

What we never do

  • We never sell your personal information.
  • We never use it for advertising, and we don't let advertisers or data brokers have it.
  • We never use your content to train or improve AI models, and our AI provider doesn't either.
  • We never share one person's content with another person.

Who we share with

We share personal information only:

  • with the service providers listed on our vendor list, only so they can run our apps for you, under contracts that limit what they can do with it;
  • when you ask us to, such as connecting an app you chose;
  • when the law requires it, such as a valid court order, or to protect someone's safety or our users' security;
  • if Standby Ops LLC is sold or merged, with the buyer, who must keep this policy's promises. For Google user data, we ask you first.

How we protect it

Encryption in transit and at rest, keys held outside our database, each user's data isolated in the database, and the smallest access we can manage. No system is perfect. If a breach affects you, we tell you and, where the law requires, the authorities. See Security.

Your choices and rights

You can see, export, correct and delete your information. In Gloss, most of this is in Settings (Part 2 explains each). You can also email [email protected]. We answer within 30 days and won't treat you differently for asking. Some US states give you more rights, such as knowing what we collect and limiting how sensitive information is used. We give those rights to every user.

Children

Our apps are not for children under 13, and we don't knowingly collect their information. If you think a child under 13 gave us information, email us and we delete it. Gloss is for university students, and some are 17: see "Students under 18" in Part 2.

Where data is processed

Our apps are for people in the United States. We and our service providers process data in the United States. The production hosting provider for Gloss is not chosen yet; this section will name it before launch.

Changes

If we change this policy in a way that matters, we tell you in the app or by email before the change takes effect.

Part 2: Gloss

Gloss reads a student's school email, course site calendar, student org calendar, class schedule and syllabi, and turns them into one list of what's due with reminders. Everything below is what the Gloss code does today.

What Gloss collects, and why

Your account

  • Login email, first name (from Apple or Google if you sign in with them, or what you type), a backup email if you add one, and your school email once you verify it with a code. Why: to sign you in, recover your account and find your school.
  • Your school. Why: to use the right course site, email provider, time zone and term dates.
  • Sign in with Apple or Google: the account id Apple or Google gives us and the email on it. Why: to sign you in. We keep Apple's sign in token only so we can revoke it when you delete your account.
  • Whether you are under 18 (a yes or no, never your birth date). On iPhone, this comes from Apple's age range signal. Why: so we never send marketing to minors.
  • When you agreed to the terms, this policy and AI processing, and which version. Why: to show what you agreed to.
  • Your plan and purchases: which plan (Free, Plus monthly, a term pass, or a free month earned by inviting classmates), where you bought it (the App Store or our website through Stripe), when it started and ends, whether it renews, and the amount and date of each payment. Why: to unlock what you paid for and show your receipts in Plan and spending. We never see or store card numbers: Apple and Stripe handle payment details.
  • Invites: your invite code, and how many classmates joined with it (counts only; you never see who). Why: to give the free month for inviting classmates. Rewards need a verified school email.

Your devices

  • For each signed in device: its model name (like "iPhone 16"), platform, app version, a random id the app makes on install, a push notification token, and when it was last used. Why: to show your signed in devices, sign them out, and send reminders.
  • We never store your IP address. We keep a keyed scramble of it (a hash) in security records and for rate limits. Why: to stop abuse.

Your school email, if you connect it

  • You connect by signing in on Google's or Microsoft's own page. We never see your password.
  • Gloss reads your inbox only, starting from 30 days back or the start of your term, whichever is later. It can't send, delete, move or change email.
  • For each email it reads, Gloss stores: the sender's name and address, the subject, when it was sent and received, a link to open it in Gmail or Outlook, and the text of the body (up to 6,000 characters). It does not store attachments or the To and Cc lists.
  • The subject and body are encrypted with a key unique to you and deleted 30 days after Gloss fetched the email.
  • What stays after 30 days, until you disconnect or delete your account: the sender's name and address, the dates, the link to open it, a one line summary, and whether it looked important, sensitive or like phishing.
  • What Gloss found in the email, such as "Midterm moved to Monday, 2 PM": the deadline or event, its title, date, place and class, and a one line summary. These stay in your list until you delete them, disconnect that email, or delete your account. If AI can't read an email clearly, its subject (up to 140 characters) can become the title of an item for you to sort.
  • Why: to find deadlines, exam changes and events, and to show you the emails that matter.

Calendar links

  • The private calendar links you paste from your course site or student org platform, and the events they contain. The link is encrypted with keys held outside our database and never shown or logged. Why: to keep your deadlines and events up to date.

Your schedule and syllabi

  • Schedule text you paste is read by our own code, without AI.
  • Schedule screenshots and PDFs are read with AI (see below) and are not stored: once they are read, they are gone. We keep the classes, meeting times, rooms, instructors and dates we find, after you confirm them.
  • Syllabi you paste or upload are read by our own code, and with AI only if you allowed AI reading. The syllabus file is kept, encrypted with a key unique to you, because it is pinned in that class's study library; replacing the syllabus deletes the old file. We keep the dates, grade weights, office hours and the class's AI policy we find, after you confirm them.
  • Why: to build your classes and find every dated item in a syllabus.

Reminders and settings

  • Your notification settings, and the reminders we sent you (their title and text). Why: to send reminders once, never twice.

Support

  • What you send us. If you can't sign in and use the support form, we keep your email, name, school and message to answer you.

Crash reports

  • When the app or our servers crash, an error report goes to Sentry. Reports from the iPhone app, the desktop app and our servers have email text, email addresses (including encoded forms, like the ones in web addresses), tokens and calendar links removed before they are sent. Our server logs have the same things removed.

Study features

  • Files you add to a class's study library (PDFs, Word files, photos, text) are stored encrypted with a key unique to you, and the text we find in them is kept so the study tutor can answer from them. Removing a file from the library deletes it.
  • Your questions to the study tutor and its answers, encrypted with your key. Messages that sound like a crisis are never stored and never sent to AI.
  • Lecture recordings you upload are turned into text by Groq, a speech to text service, only if you allowed it in a separate permission that names Groq. The audio is deleted right after, whether or not it worked, and only the text is kept. If you turn that permission off, recordings waiting to be turned into text are deleted without being sent.
  • Grades you type. Why: to calculate your grade in Plus.

What Gloss doesn't collect: your location, contacts, calendar from your phone, microphone, health data, or any advertising id. Gloss has no analytics or advertising tools and does not track you across other apps or websites. If we ever add privacy friendly product analytics, we update this policy first.

How Gloss uses AI

Gloss uses Claude, an AI made by Anthropic, to read some of your information. Anthropic is the only AI provider that reads your email, schedules and syllabi.

  • What goes to Anthropic: emails that pass our filters (the sender's name and address, subject, sent time and up to 6,000 characters of the body), schedule screenshots and PDFs you upload, and syllabus text.
  • What doesn't: newsletters, promotions and automated email are sorted out first by our own rules. Pasted schedule text never goes to AI.
  • Sensitive email: Gloss looks for words and senders that mark health, counseling, disability, Title IX, conduct, financial aid and visa office email. Email that matches is never sent to AI and never shows in notifications. The check works by matching words and senders, so it can miss an email.
  • Your permission: before you connect your school email, Gloss asks your permission on a screen that names Anthropic. Our servers check that permission before anything of yours goes to Anthropic or Groq: without it, nothing is sent, from any feature.
  • Turning it off: Settings, then AI permissions, has a switch for each AI provider. Turning one off stops it at once: nothing more is sent, email waiting to be read is held (you see it in Mail), and an answer already on its way back is thrown away. Gloss then works on your calendars and schedule only. Turning it back on lets the held email be read.
  • No training: Anthropic's commercial terms say it doesn't train its models on the data we send. We never use your data to train AI either.
  • Safety: email and file text is treated as information, never as instructions. AI answers must fit a strict format and can't make Gloss do anything on its own.

Google user data

Gloss's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain words, for Gmail data (Google scope gmail.readonly):

  • We use it only to show you your deadlines, events and the emails that matter, inside Gloss.
  • We transfer it only to Anthropic, to read it for you, and only as described above. We never transfer it for any other reason, except for security, to comply with the law, or in a merger where you agree first.
  • No person at Gloss reads it, unless you ask us to look at a specific item, it's needed for security or the law requires it.
  • We never use it for ads, never sell it, and never use it to train or improve AI models.

Microsoft user data

For Outlook email (Microsoft Graph permission Mail.Read) we make the same promises as for Google user data above.

Notifications and your lock screen

"Hide details on lock screen" is on unless you turn it off. While it's on, a reminder for anything Gloss found in, or changed because of, an email shows no title or text on your lock screen, only "Gloss: you have an update". Reminders from your course site show the deadline's title. Email we mark sensitive never appears in notifications, on the lock screen, in widgets, in calendar export or in AI app connectors, whatever the setting.

Your school

We don't share your information with your school. When students answer setup questions (like which course site the school uses), we save the answer for the school so the next student skips the question, and we count how many students at a school connected, without saying who.

On your device

The app keeps a copy of your recent data in its private storage on your device, for up to 7 days, so it works offline. Signing out erases it. Sign in tokens are kept in the iPhone Keychain or your computer's secure storage.

How long we keep it

WhatHow long
Email subject and body30 days after Gloss fetched it
Email sender, dates, link and one line summaryUntil you disconnect that email or delete your account
Deadlines and events found anywhereUntil you delete them or your account
Calendar links and their eventsUntil you remove the link or delete your account
Schedule screenshots and PDFsNot stored; read, then gone
Syllabus and library filesUntil you remove them from the library, replace the syllabus, or delete your account
Lecture recording audioDeleted right after it is turned into text
Account, devices, settingsUntil you delete your account
Support form messages sent without an accountUntil we've answered and no longer need them
Crash reportsSentry's retention for our plan

Disconnecting and deleting

  • Disconnect Gmail: Gloss stops Gmail's new mail alerts, asks Google to revoke its access, and deletes its sign in tokens, every stored email for that account, the deadlines and events found only in that email, and the email's summaries on items your course site also has.
  • Disconnect Outlook: Gloss deletes its Microsoft new mail subscription, its sign in tokens, every stored email for that account, the deadlines and events found only in that email, and the email's summaries. Microsoft doesn't let an app withdraw its own access to mail; to also remove Gloss from your Microsoft account, go to myapps.microsoft.com.
  • Delete your account (Settings, then Delete account): first undoes Gloss's access outside (stops Gmail's alerts and revokes Gloss at Google, deletes Microsoft's new mail subscription, revokes Sign in with Apple), then deletes your data from our database and every file you uploaded, and destroys your personal encryption key (so your stored email, files and email sign in tokens can't be read again, even from a backup). It leaves your school's shared setup answers and counts, which don't identify you.
  • Export: Settings, then Export my data, gives you a file with everything we hold about you, without secrets like tokens.
  • An App Store subscription keeps billing until you cancel it with Apple, even after you delete your account.

Students under 18

Some university students are 17. Gloss doesn't ask for your birth date. On iPhone it reads Apple's age range signal, and if you are under 18 we never send you marketing. Some schools don't let students under 18 connect outside apps to their email; Gloss respects that when it knows.

This website

joingloss.app sets no cookies and runs no analytics or trackers. Cloudflare, which hosts it, processes your IP address to deliver the pages; we don't receive it. The waitlist stores only your email address and that you agreed, with the date, and we use it only to tell you when Gloss opens where you are.

Contact

Questions or requests: [email protected]. Standby Ops LLC, District of Columbia, USA.