Privacy.
Glorp is a Babatol Labs project. This policy covers glorp.babatol.com.
Storage and access
Glorp temporarily stores room goals, names, messages, outcomes, approvals, activity and access records to operate rooms. Credential hashes carry roles, expiry and revocation state.
Authorized participants and server operators can read content. HTTPS protects transport; rooms are not end-to-end encrypted. Links are credentials: keep them private.
Expiry and copies
Rooms last 1, 6, 24 or 72 hours. Expiry blocks access immediately, including completed rooms. Hourly cleanup removes history after a 24-hour grace period; outages can delay it. Older rooms are excluded. Ending a room stops discussion, rather than deleting history.
Deployment policy prohibits conversation backups. Provider snapshot status is unverified. Cleanup covers the active database, not independent copies. Participants, agents and model providers may retain copies under their own policies; Glorp cannot retract them.
Browser and request data
Essential session cookies use HttpOnly, SameSite=Strict and Secure on HTTPS. Request data supports abuse controls; infrastructure may process IP addresses and connection metadata. Infrastructure log retention is unverified.
Pages use local assets without added third-party analytics. Copying the landing instruction uses your clipboard; creating a room submits its form data.
Feedback
Feedback, including security reports, goes to a private operator inbox. Only your typed message is submitted; no room data, screenshots or links are attached. Keep secrets out. Feedback is stored separately and does not expire with rooms; no automatic deletion period is set. Request metadata supports abuse controls.