Liff
Privacy policy
Last updated 9 October 2026
What Liff collects, why, where it goes and how long we keep it. This covers the Liff app for Android, your Liff account and this website.
Who we are
Liff is made by Glassly. Glassly is the trading name of a sole trader in the United Kingdom, who is the controller of your personal data under UK data protection law (the UK GDPR and the Data Protection Act 2018). The operator’s name and address are in Contact and our details.
Your Liff account is also a Glassly account: signing in on glassly.dev with the same Google account opens the same account. What you do on glassly.dev is covered by the Glassly privacy policy.
For anything about your data, write to support@glassly.dev. We don’t have a data protection officer, and aren’t required to.
What we collect and why
Your account
When you sign in with Google, Google gives us your name, email address, the link to your profile picture and your Google account ID. We use them to create your account, keep you signed in and know it’s you, and we note when you last used Liff. You don’t need an account to use the Things already on your phone: you need one to make, change or try a Thing.
What you ask for
- The words you type or say to make or change a Thing. While you type, Liff sends your words as you go, so it can show what it understood before you tap Make it.
- Your answers to the questions Liff asks while it makes a Thing.
- When you point at part of a Thing, the words that part shows on screen, where it is and which screen it’s on. Those words can include your own information, if that’s what the part shows.
- Photos you add. We send each one to an AI model that describes it in words, and Liff works from those words. We don’t keep the photo.
When you speak instead of typing, your phone’s own speech recognition service (on most Android phones, Google’s) turns what you say into words, under its own terms. We only receive the words, never the recording.
Your Things
The Things we make for you: their code, name, colour and design, what you asked for, the conversation about each change, and earlier versions, so you can go back. We also note when you open each of your Things (the first and last time, and on which days), so we can see whether the Things Liff makes stay useful.
Liff AI in your Things
When a Thing uses Liff AI, it sends what it needs answered: its own instructions, your words or the conversation so far, and any photos you give it. We pass them to an AI model, send the reply back to the Thing, and keep none of it. The conversation stays in the Thing on your phone.
For each reply we keep a record without its words: which Thing it was for, how big it was, what it cost us and how many of your replies for the day are left. Liff sends your phone’s time zone, so your replies refill at your own midnight. If what you write suggests you may be at risk of hurting yourself, Liff shows you where to get help, and we count how many times that happens each day across all of Liff, without the words or who it was. If you report a reply, we keep its text with your report.
Your plan and what you make
Your plan, how many Things you’ve made this month, and a record of each make and change.
Error reports from your Things
When a Thing hits an error, Liff sends us the error and the last lines the Thing logged, so we can see what went wrong and fix it. Those lines can include what the Thing was showing, such as a name, a place or an event, if that is what it was working with. We can also ask a Thing for its recent lines when we are fixing it. Liff’s AI can then fix the Thing on its own, for free.
Technical details
When the app or this website talks to our servers, we receive your IP address and what was asked for, and the app tells us which version of Liff’s engine it runs. Our servers log this to run and protect the service, and when you sign in, the log also notes your email address. We don’t collect advertising IDs.
Feedback and reports
When you send feedback or report a Thing in Liff: what you wrote, the reason you chose, which Thing it is about and your account, so we can act on it. Once a day, what was sent reaches our support inbox by email, without your name or email address.
When you write to us
Your email address and what you tell us, so we can help.
Why we’re allowed to
- To give you Liff
- Your account, what you ask for, your Things, your plan, and what a Thing sends to Liff AI. We need these to do what you ask (contract).
- To keep Liff working and safe
- Error reports, technical details, the days you open your Things, the record of each Liff AI reply, feedback and reports, and the content check described below. We have a legitimate interest in fixing problems, making Liff better, keeping Liff AI fair for everyone and preventing misuse, and we keep it to what’s needed.
- Because the law says so
- Records of payments, which we must keep for tax (legal obligation).
What stays on your phone
- Things that work offline keep what you put in them on your phone, and we can’t see it there. If one hits an error, its error report can carry some of what it was showing.
- A Thing can use your contacts, calendar, location or step count only after you allow it, and only for what you asked it to do. If that Thing keeps its data online, or you asked it to use a service on the internet, what it uses goes there too.
- Liff keeps a picture of each Thing to show on its home screen and in your recent apps. The pictures stay on your phone.
- Your sign-in is kept in your phone’s encrypted storage.
- Depending on your phone’s backup settings, Android may back up some of Liff’s settings, such as your Things’ names and colours, to your Google account.
Uninstalling Liff removes everything it kept on your phone.
Things that keep their data online
Some Things keep their data online. Each one gets its own database, apart from everyone else’s: either in your own Supabase account, if you connect one, or in one we run for you with Supabase, in London. We only work with it when you ask Liff to make or change that Thing, for example when a change needs to add to its tables. While it does, Liff’s AI can look at what is stored there, to see what the change needs.
When an online Thing we run hasn’t been used for a while, we put its database to sleep and keep a full copy in our own database, so it can wake up as it was the next time you open it.
If a Thing lets other people sign in, their email address and password (stored scrambled) are kept in that Thing’s database, which the Thing’s maker controls in Liff.
A Thing can also connect to other services on the internet if you asked for that, like a Thing that shows live prices. Those services receive what the Thing sends them, under their own terms.
AI and the services that make your Things
Liff uses AI models to understand what you ask for and to make and change your Things. For that, we send AI models what you asked for (your words, your answers, the part you pointed at and descriptions of your photos), the Thing’s code and its error reports, what an online Thing has stored when a change needs to look at it, and details of how the work is going. They go through OpenRouter, which passes each request to a company that runs the model. Each photo you add goes the same way to a model that reads images, once, to describe it in words.
We also use AI to check each request against our rules before anything is made, and to write the short updates you see while a change is on its way. When what you ask for names something specific, like a game, a team’s season or a local service, Liff looks it up on the web before deciding what to make, through OpenRouter, using Perplexity’s search. Each search is made from the words you typed (the thing you named, and what your Thing needs to know about it), and carries nothing else about you or your account. While it works, the AI can also search the web (through OpenRouter, using Exa) for what it needs to build your Thing. It writes each search itself, and another AI model, also reached through OpenRouter, reads the results and sums them up.
When a Thing uses Liff AI, what it sends goes the same way: through OpenRouter to a company that runs the model, which writes the reply. Liff adds its own rules to every request, so the reply follows them whatever the Thing asks.
We don’t use what you give us to train AI models, and we don’t sell it. The companies that run the models process it to answer each request, under their terms with OpenRouter. Some of these companies keep requests for a time under their own policies, and they can be in the United States, China or other countries.
Our content check can refuse a request it decides breaks our rules. That decides only whether Liff makes that Thing; it has no legal or similarly significant effect on you. If you think it got it wrong, tell us.
Who else handles your data
These companies handle your data to do these jobs for us:
- OpenRouter, Inc.
- Passes requests to the AI models that make, change and check your Things. United States.
- The companies that run the AI models
- Answer each request. Which one depends on the model and who is available. Some of these companies keep requests for a time under their own policies, and they can be in the United States, China or other countries.
- Sign-in with Google, our email inbox, and the scanning some Things do (ML Kit, below). United States and other countries.
- Resend, Inc.
- Sends our emails. United States.
- DigitalOcean
- The servers Liff runs on. London, United Kingdom.
- MongoDB, Inc.
- Our database, where your account and Things are kept.
- Supabase, Inc.
- The databases of online Things we run for you. London, United Kingdom.
- Cloudflare, Inc.
- Our domain names, and storage for our encrypted database backups.
They use your data only for these jobs, apart from the requests some of the AI model companies keep under their own policies.
When a Thing scans a barcode or a document, it uses Google’s ML Kit, which sends Google technical details so Google can keep it working: your phone’s model and Android version, Liff’s version, an identifier for this install of Liff, and how the scan performed. It doesn’t send the pictures. The app also includes Google’s Firebase messaging library, which Liff doesn’t use yet and doesn’t start.
If you buy Liff Plus, you pay in Liff through Google Play, under Google’s own terms and privacy policy: we never see your card details, and Google tells us what you bought, so we can give you Liff Plus. Liff doesn’t use credits. Anything you buy on glassly.dev, for Glassly’s web builder, is covered by Glassly’s privacy policy.
We don’t sell your data or share it for advertising. We’ll only give it to anyone else if the law requires us to.
Data outside the UK
Some of these companies are outside the UK. When your data leaves the UK, we rely on the protections UK law recognises: adequacy regulations (for example for the European Economic Area, or for US companies certified under the UK Extension to the EU-US Data Privacy Framework), or the UK International Data Transfer Agreement or Addendum to the EU standard contractual clauses. Ask us for a copy of the safeguard that applies.
How long we keep it
- Your account
- Until you delete it.
- Your Things, what you asked for, the conversations about changes and when you opened them
- While your account exists.
- Earlier versions of a Thing
- 30 days.
- Descriptions of your photos
- 24 hours if unused. Once a make or change uses one, it stays with that Thing’s history until you delete your account.
- What a Thing sends to Liff AI, and the replies
- Not kept. A reply you report is kept with your report.
- The lines a Thing logged
- 7 days.
- The errors in your Things, and how we fixed them
- While your account exists.
- Working files from making and changing a Thing
- 14 days.
- Online Things we run for you
- Until you remove the Thing or delete your account.
- Feedback and reports
- 1 year, or until you delete your account if that’s sooner.
- Our backups
- Replaced every night; each copy is kept for 14 days.
- Server logs, which include your IP address and, when you sign in, your email address
- Only as long as we need them to run and protect the service.
- Records of payments and plans, and of each make, change and Liff AI reply (never what was said)
- After your account is deleted, we keep them for at least 6 years, for accounting and tax.
Your rights
Under UK data protection law you can ask us:
- for a copy of the personal data we hold about you;
- to correct it if it’s wrong;
- to delete it;
- to limit what we do with it, or to stop, where we rely on our legitimate interests;
- to give it to you, or to someone else, in a format a computer can read.
Write to support@glassly.dev from the email address you sign in with. It’s free, and we’ll answer within a month (we’ll tell you if a complicated request needs longer). You can delete your account yourself at any time: see Delete your account.
If you’re unhappy with how we’ve handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint. We’d be grateful for the chance to put it right first.
Children and young people
Liff is for people aged 13 and over. We don’t knowingly collect data from anyone under 13. If you think someone under 13 has given us their data, tell us and we’ll delete it.
If you’re under 18, this whole policy applies to you just as it does to everyone else: we don’t sell your data, show you ads or track you across other apps and websites. If any of it isn’t clear, write to us, or ask a parent or another adult you trust. You can delete your account whenever you like.
Keeping it safe
Everything between the app, this website and our servers is encrypted, our database and backups are encrypted where they’re stored, and only the people who run Liff can reach them. No system is perfectly secure: if something goes wrong that puts you at risk, we’ll tell you, and the Information Commissioner’s Office, as the law requires. To report a security problem, write to support@glassly.dev.
This website
liff.si sets no cookies, uses no analytics and loads nothing from other companies: even its fonts come from here. Like any website, our server receives your IP address and the page you asked for, and keeps them in its logs for a short time to run and protect the site.
The Google Play buttons tell Google Play that you came from this site, so Google Play can show us how many installs came from here. That doesn’t identify you.
Changes to this policy
When this policy changes, we’ll update the date at the top. If a change matters to you, we’ll tell you by email or in Liff before it applies.
Contact and our details
Liff is made by Glassly. Glassly is a trading name of Haroon Khan, a sole trader established in the United Kingdom.
Published under regulation 6 of the Electronic Commerce (EC Directive) Regulations 2002 and Part 41 of the Companies Act 2006.