Your card details never touch our servers
All payments - subscriptions, credit top-ups, and domain purchases - are processed by Stripe, a PCI DSS Level 1 certified payment processor (the highest level of certification in the payments industry). When you enter your card number, it goes directly from your browser to Stripe. We never receive, see, or store your full card details - we only keep a reference to your subscription so we know what plan you're on.
SSL on every site, automatically
Every site published with Glint is served over HTTPS with a valid SSL certificate - both on your free yoursite.glint.fyi address and on any custom domain you connect or buy. Certificates are issued and renewed automatically by Cloudflare; there is nothing to configure, nothing to renew, and no way to accidentally publish an insecure site. Visitors always see the padlock.
The Glint app itself (your account, editor, and billing pages) is HTTPS-only as well.
Where your data lives
Your account details, chat history, and site content are stored in a managed Postgres database hosted by Supabase in the United States. Your published site files and uploaded images are stored on Cloudflare's distributed storage network and served from data centres close to your visitors.
Access to production data is limited to the operator of the service, protected by strong authentication. Passwords are hashed by our authentication provider - we never see or store your password in readable form. We don't sell your data, and we don't use your content to train AI models (nor allow our AI providers to). The full list of the service providers we use is in our Privacy Policy.
Backups & version history
Every time the AI edits your site, the previous version is saved. You can look back through your site's history and restore an earlier version at any point - a bad edit is never a disaster.
Underneath that, our database is backed up automatically on a rolling basis by our database provider, and published site files are stored redundantly across Cloudflare's network. If you delete a site or your account, the opposite applies: serving stops immediately and your files are purged from storage, normally within about 48 hours.
Your domain is yours
When you buy a domain through Glint, it is registered in your name - you are the legal registrant and owner of record, not us. WHOIS privacy is included at no charge (where the domain ending supports it), so your personal contact details stay out of the public directory.
You are never locked in: you can turn auto-renewal off at any time, and you can transfer your domain to another registrar whenever you like - we'll give you the transfer authorization code, and your site keeps being served for 30 days after the transfer so you can move DNS without downtime. Renewal pricing is disclosed before you buy, not discovered afterwards.
How we protect published sites
Sites are served through Cloudflare, which provides DDoS protection and a global content-delivery network as standard. Each published site is delivered with a Content Security Policy - a browser-level allow-list that restricts what the page can load and where it can send data, which limits what any injected or malicious script could do. Before a site version goes live, automated checks validate it (broken images, dead links, malformed embeds) so bad deploys are caught before your visitors see them.
Account security & monitoring
Sign-in is handled by our authentication provider with industry-standard password hashing and secure session tokens. The service is rate-limited to prevent abuse, and we run continuous error and uptime monitoring with alerting - you can see our live uptime for every part of the service, updated every two minutes, at status.glint.fyi.
An honest note on certifications
Glint is a small company, and we won't pretend otherwise: we do not yet hold our own SOC 2 or ISO 27001 certification. What we do instead is build exclusively on providers who hold them - Stripe (PCI DSS Level 1), Supabase (SOC 2 Type II), and Cloudflare (SOC 2 Type II, ISO 27001) - and keep our own attack surface small. If a breach ever creates a real risk of harm to you, we will notify you and the relevant authorities as required by law.
Found a vulnerability?
If you believe you've found a security issue in Glint, please tell us at [email protected]. We read every report, respond quickly, and won't take legal action against good-faith research. Please give us a reasonable chance to fix the issue before disclosing it publicly.