1. Overview
GlideflowAI is operated by Nova Meridian LLC, a limited liability company formed in Wyoming, United States. Nova Meridian LLC ("GlideflowAI," "we," "us," or "our") is the controller of the personal data described here and runs an OpenAI- and Anthropic-compatible API gateway for independent developers. This Privacy Policy applies to our marketing website, dashboard, documentation, API gateway, payment flows, support communications, and related services.
The request path is intentional and public: our gateway receives your request, authenticates it, meters usage, and forwards it to the upstream model provider you selected.
2. What we collect
We collect the information needed to operate accounts, route requests, calculate usage, process payments, prevent abuse, and provide support.
- Account data
- Email address, account identifiers, and login or authentication-related records.
- Usage and metering metadata
- Token counts, timestamps, selected model, request channel or endpoint, status, and calculated cost for each request. We use this metadata for billing, service operation, troubleshooting, fraud prevention, and abuse controls.
- Request content
- Your prompts, files or other inputs, and model outputs pass through our gateway so we can forward the request and return the response. We do not store the content of your prompts or of the model's outputs, and we do not use that content to train models. What we keep is the metering metadata above. The upstream provider you selected does receive the content, and handles it under its own policies, as described in sections 3 and 4.
- Payment and billing data
- Where a payment is made by card, the card number and security code go directly to our third-party payment processor; GlideflowAI does not see or store the full card number or CVV/CVC. We keep limited billing metadata such as amount, currency, date, payment method, card brand and last four digits, plus the reference identifiers our processor returns for that transaction. We also keep records of top-up orders that were started but not completed.
- Technical data
- IP address, browser or client information, basic request and error logs, and security signals used to keep the service available and detect misuse. Our website infrastructure and analytics tooling may also collect basic visit and device information.
3. How your requests flow
- Your application sends a request to the official GlideflowAI gateway.
- The gateway authenticates your API key.
- We meter the request, including model, token usage, and cost metadata.
- We forward the request to the upstream model provider you selected and return its response.
Each upstream provider has its own systems, terms, and privacy practices. You decide which provider and model to use and what content is appropriate to send through the complete routing chain.
4. Third-party providers
We share request content and the metadata required to serve it with the upstream model provider selected by your request. This may include different LLM providers across our model catalog. Review the terms and privacy policy of the provider behind a model before sending sensitive or confidential content.
We also use service providers for payment processing, hosting, security, email, support, and website analytics where needed to operate GlideflowAI. Providers may process information in jurisdictions other than your own, subject to their terms and applicable law.
We may also disclose information when required by law or when reasonably necessary to protect users, the service, or the rights and safety of others.
6. Payments and billing
Credits
Glideflow runs on prepaid credits. You add a balance, and usage is deducted from it at the prices published in the dashboard and on our pricing page. Credits buy access to the service; they are not a deposit, a stored-value account, or a cash equivalent.
How payments are handled
Payments are handled by a third-party payment processor rather than by us. Card numbers and security codes are submitted directly to that processor and are never seen or stored by GlideflowAI. The processor's handling of that data is governed by its own privacy policy and terms, which we identify at checkout. Which payment methods are available at any given time is shown in your dashboard, not here.
What we store
For each top-up or charge, we store the amount, currency, date, and payment method. For card payments, we also store the card brand, the last four digits, and the reference identifiers our processor returns so the transaction can be matched later. We use this information for billing history, receipts, refunds, accounting, support, and fraud prevention.
Refunds
See our Refund Policy for eligibility and the request process.
7. Data retention
We retain account, usage, metering, billing, payment-reference, security, and support records for as long as reasonably needed to provide the service, maintain billing and refund history, prevent fraud and abuse, resolve disputes, and meet legal, tax, accounting, or operational obligations. We do not state a fixed retention period where the appropriate period depends on the record and the reason it is needed.
If you request account deletion, we will close or remove the active account data that is no longer needed. We may retain limited billing, transaction, security, or legal records where necessary, and may de-identify or aggregate information that no longer needs to be linked to your account.
8. International data transfers
GlideflowAI serves developers worldwide, so running the service means your personal data can be processed in more than one country. We, and the providers we rely on for hosting, security, payments, email, and support, may process your data outside the country you live in.
If you are in the European Economic Area or the United Kingdom, that means your personal data may be transferred outside the EEA and the UK. Where the destination is not covered by a European Commission adequacy decision under Article 45 of the GDPR, we rely on standard contractual clauses adopted by the European Commission under Article 46, together with the technical and organisational measures described in section 10.
Every request you send is separately forwarded to the upstream model provider you selected. Those providers run their own infrastructure, in their own regions, under their own policies.
9. Not for regulated data
GlideflowAI is built for independent developers and is not positioned as a regulated-data service. Do not send medical records, financial records, government data, unnecessary personally identifiable information, or other regulated or highly sensitive data unless your own legal and compliance review has approved the full path through GlideflowAI and the selected upstream provider.
10. Security
Official GlideflowAI endpoints use HTTPS to protect data in transit. No internet service can guarantee absolute security, and you are responsible for protecting account credentials and API keys, keeping keys out of client-side code and public repositories, rotating exposed keys, and limiting each key to the workload that needs it.
For practical controls, read Securing AI Agents.
11. Your choices and rights
Depending on where you live, you may have rights to ask about, access, correct, export, or delete personal data associated with your account. You can also revoke API keys, stop using the service, or request account deletion.
Send a request from the email address associated with your account to [email protected]. We may need to verify your identity before completing a request, and some records may remain where retention is required for billing, fraud prevention, security, or legal obligations.
12. Your privacy rights (GDPR and UK GDPR)
Depending on your location, including the European Economic Area and the United Kingdom, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, and to request a copy of your data in a portable format. Where processing is based on consent, you may withdraw that consent at any time.
To exercise these rights, contact us at [email protected]. We will respond within the timeframe required by applicable law. You also have the right to lodge a complaint with your local data protection authority. Payment data handled by our payment provider is subject to that provider's own privacy terms, as described in section 5.
13. US state privacy disclosures
Residents of California and of other US states with comprehensive privacy laws may have rights to know what personal data we collect, to access or delete it, to correct it, to obtain a portable copy, and not to be discriminated against for exercising those rights.
The categories we collect are described in section 2: identifiers such as your email address and account ID, commercial information such as credits purchased and usage records, internet activity such as request metadata and website analytics, and geolocation inferred at the level of an IP address. We collect them for the purposes in section 2 and share them with the recipients in sections 4 and 6.
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes that require a right to limit under California law. To exercise a right, email [email protected] from your account address; we may need to verify your identity first, and you may use an authorised agent.
14. Eligibility
GlideflowAI is a developer tool intended for adults. It is not directed to children, and you must be at least 18 years old, or the age of majority where you live, to create an account. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, email [email protected] and we will delete it.
15. Governing law
This Privacy Policy and any dispute arising from it are governed by the laws of the State of Wyoming, United States, without regard to its conflict-of-laws rules. Nothing here removes rights you hold under the mandatory law of your own country of residence, including the right to complain to your local data protection authority.
16. Changes to this policy
We may update this policy when our services, providers, payment methods, or legal obligations change. The current version will be posted here with a revised last-updated date. Where appropriate, we may also provide notice through the website, dashboard, or account email.
17. Contact
For privacy questions or requests, email [email protected].
