The Chinese translation is provided for convenience. Switch to 中文 above to read it.
1. Overview
Gleanbox is a local-first capture and recall application provided by Nixlight. You can use its core features without creating a Gleanbox account. We do not operate an advertising network, sell your personal information, or provide a hosted AI proxy.
This policy applies to the Gleanbox mobile applications and this website. Third-party services that you choose to use have their own privacy policies.
2. Data stored on your device
Gleanbox may store the following information locally:
- raw captures in your collection inbox, including text, photos, screenshots, audio, and video;
- processed knowledge entries, explanations, notes, tags, deck relationships, practice history, and FSRS scheduling data;
- app preferences, reminder settings, and local search indexes;
- AI and Git configuration, with secret keys and access tokens stored through the operating system's secure storage where supported; and
- a local Premium entitlement cache so paid features remain available when you are offline.
SQLite is used as a rebuildable local index. Your processed learning data is represented in portable files so it can be exported or synchronized. Raw collection inbox material is kept separate and is not included in Git sync.
Manual ZIP exports contain the data selected by the app at the time of export. After you save or share an export, its security and retention depend on the location you choose.
3. Device permissions
Gleanbox asks for permissions only when a related feature needs them:
- Camera and photo library: to capture a scene or choose an existing image.
- Microphone: to record audio or video with sound.
- Notifications: to deliver review reminders that you enable.
You can change these permissions in iOS or Android system settings. Denying a permission disables the related capture or reminder feature but does not prevent you from using the rest of the app.
4. Bring-your-own AI
AI is optional. If you configure Gemini or another OpenAI-compatible endpoint and request an explanation, Gleanbox sends the prompt and the text or media needed for that request directly from your device to the provider you selected. Nixlight does not proxy, receive, or store that request.
Your API key is stored locally using the operating system's secure storage and is sent only to the configured endpoint. Generated results are saved locally with the knowledge entry so repeated reviews do not need another AI request.
Your provider may log, retain, or use submitted content under its own terms and privacy policy. Review those policies before sending sensitive material. For example, see the Google Privacy Policy when using Gemini. A custom endpoint is controlled by its operator, not by Nixlight.
5. Premium Git sync
If you purchase Premium and configure Git sync, Gleanbox connects directly to the Git repository and host you specify. It may upload processed entries, decks, review history, settings needed to reconstruct your learning data, and processed media attached to those entries.
Raw collection inbox content is not synchronized to Git. It remains local working material until you process it into a knowledge entry.
Your repository URL, username, and access token are stored on your device; secrets use secure storage where supported. Your Git host can process repository content, network information, account identifiers, and access logs under its own policies. Refer to your provider's policy, such as the GitHub Privacy Statement or the policy provided by GitLab or another host.
You are responsible for choosing an appropriate repository visibility. We strongly recommend a private repository and a narrowly scoped access token.
6. Diagnostics and purchases
Crash diagnostics
Release builds use Sentry to report crashes and serious errors. Reports may include a pseudonymous installation or device identifier, device model, operating system, app version, error message, stack trace, and related technical context. Gleanbox disables default personally identifiable information, screenshot attachments, performance tracing, and profiling. We use these reports to diagnose reliability problems.
Sentry processes this information under its privacy policy.
Premium purchases
Apple App Store or Google Play processes your payment. Gleanbox uses RevenueCat to verify the one-time Premium entitlement and restore purchases. RevenueCat and the relevant app store may receive purchase status, product identifiers, platform information, and a pseudonymous app user identifier. Nixlight does not receive your full payment card details.
See the RevenueCat Privacy Policy, Apple Privacy Policy, or Google Privacy Policy.
Website
This website does not use advertising or analytics cookies. It stores only your English or Chinese display preference in local browser storage. A future hosting provider may process ordinary server logs such as IP address, browser type, and request time for security and delivery.
7. Retention, security, and international processing
Local data remains on your device until you delete it, clear local data, or uninstall the app, subject to your device backups. Git data remains in your repository and Git history until you remove it according to your host's tools. AI, diagnostics, purchase, and hosting providers apply their own retention schedules.
We use reasonable technical safeguards, but no device, network, repository, or storage system can be guaranteed completely secure. Third-party providers may process information in countries other than yours.
8. Your choices and rights
You can:
- use Gleanbox without an account, AI key, or Premium purchase;
- review, edit, export, or delete learning data in the app;
- clear all local data from Settings;
- disable system permissions or reminders;
- remove AI or Git credentials; and
- manage or delete synchronized data through your chosen Git host.
Because Nixlight does not maintain a Gleanbox account containing your learning library, we generally cannot access, retrieve, or delete that local or repository data for you. For diagnostic or purchase-related privacy requests, contact us with enough information to understand the request without sending your learning content or secret credentials.
9. Children
Gleanbox is a general learning tool and is not directed specifically to children. If local law requires parental or guardian consent for a minor to use connected AI, Git, purchase, or other third-party services, that consent must be obtained before those services are configured.
10. Changes to this policy
We may update this policy as Gleanbox changes. We will revise the effective date above and provide additional notice in the app or on this site when a change is material.
11. Contact
Questions or privacy requests can be sent to support@nixlight.com.