1. Introduction
This Privacy Policy explains how GlassBreakr ("we", "us", "our") collects, uses, and protects your personal data when you use our website (glassbreakr.com) and software. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and applicable EU data protection laws.
2. Data Controller
The data controller responsible for your personal data is:
- Entity: ZMLabs — Zahia Melouane (sole proprietor), SIRET 102 950 359 00012
- Address: Sète, France
- Email: contact.zmlabs@proton.me
View the full legal notice (publisher details)
3. Data We Collect
We collect the following categories of personal data:
- Account Data: Email address, name (optional), hashed password, account creation date, and tier information when you create an account.
- Contact Data: The email address and message you submit through our contact form.
- Technical Data: IP address (for rate limiting and security purposes only, not stored persistently), browser type, and device information.
- Cookie Data: Necessary cookies for session management, and optional analytics/marketing cookies only with your explicit consent.
The GlassBreakr desktop software runs entirely locally on your machine. No screen captures, game data, or usage telemetry are sent to any server.
4. Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR Article 6:
- Consent (Art. 6(1)(a)): For optional cookies (analytics, marketing) and marketing communications.
- Contract Performance (Art. 6(1)(b)): To provide you with our services, manage your account, and process purchases.
- Legitimate Interest (Art. 6(1)(f)): For security measures (rate limiting, fraud prevention) and improving our services.
- Legal Obligation (Art. 6(1)(c)): To comply with applicable laws, such as retaining financial transaction records.
5. How We Use Your Data
- To create and manage your user account
- To process payments and deliver purchased licenses
- To respond to your contact form submissions
- To prevent abuse through rate limiting
- To send service-related communications (account confirmations, security alerts)
- To improve our website and services (only with your consent for analytics)
6. Data Sharing & Third Parties
We do not sell, rent, or trade your personal data. We share data only with the following service providers, strictly for the purposes of operating our service:
- Vercel: Website hosting (processes HTTP requests including IP addresses)
- Cloudflare (Workers + D1): Authentication service and accounts database (stores your email and hashed password)
- Resend: Transactional account emails — email verification and password reset (EU servers)
- Google: Sign-in with Google (only if you use it)
- Stripe: Payment processing (handles payment card data directly — we never see or store your full card number)
Each provider is contractually bound to process your data only as instructed and to maintain appropriate security measures.
7. Data Retention
- Account data: Retained until you delete your account.
- Contact submissions: Retained for 2 years, then automatically deleted.
- Technical logs (rate limiting): Stored in memory only; automatically purged within 60 seconds of expiry.
8. Your Rights Under GDPR
As a data subject, you have the following rights under the GDPR:
- Right of Access (Art. 15): Request a copy of all personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten") (Art. 17): Request deletion of your personal data.
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format (JSON).
- Right to Restriction of Processing (Art. 18): Request that we limit how we process your data.
- Right to Object (Art. 21): Object to processing based on legitimate interest.
- Right to Withdraw Consent (Art. 7): Withdraw consent at any time (e.g., cookie preferences).
You can exercise your right to access and erasure directly from your Dashboard. For other requests, email contact.zmlabs@proton.me. We will respond within 30 days.
9. Data Security
We implement appropriate technical and organizational measures to protect your data:
- All connections use HTTPS with HSTS (HTTP Strict Transport Security)
- Passwords are hashed with PBKDF2-SHA256 (never stored in clear)
- Security headers: CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
- CSRF protection on all API routes
- Rate limiting on sensitive endpoints
- Regular security reviews and dependency updates
10. International Data Transfers
Some of our service providers (Vercel, Cloudflare, Google, Stripe) process data on servers located in the United States. These transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring an adequate level of data protection as required by GDPR Article 46.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via a notice on our website. The "Last updated" date at the top of this page indicates the most recent revision. Continued use of our services after changes constitutes acceptance of the updated policy.
12. Contact & Complaints
For any questions or requests regarding this Privacy Policy or your personal data, contact us at: contact.zmlabs@proton.me
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority. In France, this is the CNIL (Commission Nationale de l'Informatique et des Libertés): www.cnil.fr
© 2026 ZMLabs. All rights reserved.