Last updated: August 3, 2026
Privacy Policy
This Privacy Policy explains how Glue (gluestick.sh) collects, uses, and shares information when you use our website, accounts, and software.
Glue is operated by an individual (“Operator,” “we,” “us,” or “our”). There is currently no registered company behind this Service. We are committed to protecting your privacy and, where applicable, complying with the EU General Data Protection Regulation (GDPR) and similar data-protection laws.
1. Who is responsible
The Operator of gluestick.sh is the data controller for personal data collected through the Service, except where a third party (such as Paddle) acts as an independent controller for payment processing.
2. Information we collect
2.1 Account information
When you register or sign in, we collect information such as:
- email address;
- display name (if you provide one);
- password (stored in hashed form);
- email verification and password-reset tokens as needed to operate auth flows.
2.2 Subscription and billing
If you purchase Pro, checkout is handled by Paddle.com Market Limited (Merchant of Record). Paddle collects payment details, billing address, and tax information as needed to process the transaction. We receive limited customer and subscription metadata from Paddle (for example email, country, plan, and subscription status) so we can unlock Pro features on your Account. We do not store full payment card numbers.
2.3 Product and service data
Depending on which features you use, we may process:
- Cloud backup and sync (Desktop Pro): package manifests, configuration snapshots, device registration metadata, and related synchronization data that you choose to upload so we can provide multi-device backup, restore, and sync features;
- subscription entitlement and license status;
- comments or other content you post on the website (for example blog comments);
- support messages you send to us by email.
Snapshot and sync payloads are stored only to deliver those Pro features. You can stop using sync features at any time; Account deletion requests are handled as described in Section 9.
2.4 Technical logs
Our servers and hosting providers may automatically record technical data such as IP address, browser or client type, request timestamps, and error logs needed to operate and secure the Service.
2.5 Cookies and local storage
We use essential browser storage (for example local storage) to keep you signed in and to remember language preferences. We do not use advertising cookies.
3. How we use information
We use personal data to:
- provide, maintain, and improve the Service;
- authenticate users and protect accounts;
- process subscriptions and deliver Pro features;
- respond to support requests;
- send transactional emails (verification, password reset, billing-related notices);
- monitor abuse, security incidents, and service reliability;
- comply with legal obligations.
4. Legal bases (GDPR)
Where the GDPR or similar laws apply, we process personal data only when we have a legal basis. Under GDPR Article 6, we rely on:
- Contractual necessity (Art. 6(1)(b)): creating your Account, providing the Service, and fulfilling a subscription;
- Legitimate interests (Art. 6(1)(f)): securing the Service, preventing abuse, diagnosing issues, and improving reliability — balanced against your rights and freedoms;
- Consent (Art. 6(1)(a)): where we ask for it (you may withdraw consent at any time without affecting prior lawful processing);
- Legal obligation (Art. 6(1)(c)): when we must retain or disclose information under applicable law.
5. Sharing of information
We do not sell your personal data. We share data only as needed with:
- Paddle — payment processing, tax, and invoicing as Merchant of Record;
- Hosting and infrastructure providers — to run gluestick.sh and related APIs;
- Email delivery providers — to send transactional mail;
- Authorities — when required by law or to protect rights and safety.
Open-source package downloads you initiate may contact third-party package mirrors or GitHub; those parties have their own policies.
6. International transfers
Our Service and vendors may process data in more than one country, including outside the European Economic Area (EEA). Where the GDPR applies and personal data is transferred outside the EEA, we use appropriate safeguards such as European Commission adequacy decisions or Standard Contractual Clauses (SCCs), or other lawful transfer mechanisms.
7. Retention
We keep Account and subscription records for as long as your Account is active and as needed for billing, support, security, and legal compliance. You may request deletion of your Account as described in Section 9; we will delete or anonymize personal data unless we must retain it (for example tax, dispute, or security records).
8. Security
We use reasonable technical and organizational measures to protect personal data. No method of transmission or storage is completely secure; please use a strong unique password and protect your devices.
9. Your rights (including GDPR)
Depending on where you live — and in particular if the GDPR applies to you as an EU/EEA (or UK) data subject — you have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete personal data.
- Right to erasure (“right to be forgotten”): request deletion of your personal data in certain circumstances.
- Right to restrict processing: request that we limit how we use your personal data in certain circumstances.
- Right to object: object to processing based on legitimate interests (including profiling, where applicable).
- Right to data portability: request that we provide your personal data in a structured, commonly used, machine-readable format, or transfer it to another controller where technically feasible.
- Right to withdraw consent: where processing is based on consent, withdraw it at any time.
- Right to lodge a complaint: complain to a supervisory authority in your country or EU Member State (for example your local data-protection authority).
To exercise these rights, email support@gluestick.sh from the address associated with your Account (or explain how we can verify your identity). We will respond within the timeframes required by applicable law (under the GDPR, generally within one month).
Some rights are not absolute; we may refuse or limit a request where the law allows (for example to comply with legal obligations, resolve disputes, or protect security). If we cannot fully fulfill a request, we will explain why.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them.
11. Changes
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the Service after an update means you acknowledge the revised policy.
Related: Terms of Service · Refund Policy
最后更新:2026 年 8 月 3 日
隐私政策
本《隐私政策》说明 Glue(gluestick.sh)在您使用我们的网站、账户与软件时,如何收集、使用和共享信息。
Glue 由个人运营(“运营者”“我们”)。目前本服务背后没有注册公司。 我们致力于保护您的隐私,并在适用范围内遵守欧盟《通用数据保护条例》(GDPR)及其他类似数据保护法律。
1. 责任主体
gluestick.sh 的运营者是通过本服务收集的个人数据的数据控制者;但第三方(例如 Paddle)在支付处理中作为独立控制者的情况除外。
2. 我们收集的信息
2.1 账户信息
注册或登录时,我们可能收集:
- 电子邮箱;
- 显示名称(如您提供);
- 密码(以哈希形式存储);
- 为完成验证与重置流程所需的邮箱验证及密码重置令牌。
2.2 订阅与账单
若您购买 Pro,结账由 Paddle.com Market Limited(销售记录商)处理。 Paddle 会收集完成交易所需的支付信息、账单地址与税务信息。 我们从 Paddle 接收有限的客户与订阅元数据(例如邮箱、国家/地区、方案与订阅状态),以便在您的账户上解锁 Pro 功能。 我们不存储完整银行卡号。
2.3 产品与服务数据
视您使用的功能,我们可能处理:
- 云备份与同步(Desktop Pro): 您选择上传的软件包清单、配置快照、设备注册元数据及相关同步数据,用于提供多设备备份、还原与同步功能;
- 订阅权益与许可状态;
- 您在网站发布的评论或其他内容(例如博客评论);
- 您通过邮件发给我们的支持消息。
快照与同步数据仅用于提供上述 Pro 功能。 您可随时停止使用同步功能;账户删除请求按第 9 节处理。
2.4 技术日志
我们的服务器与托管服务商可能自动记录 IP 地址、浏览器或客户端类型、请求时间戳、错误日志等运行与保障服务安全所需的技术数据。
2.5 Cookie 与本地存储
我们使用必要的浏览器存储(例如 localStorage)以维持登录状态并记住语言偏好。 我们不使用广告 Cookie。
3. 我们如何使用信息
我们使用个人数据以:
- 提供、维护并改进本服务;
- 进行用户身份验证并保护账户;
- 处理订阅并交付 Pro 功能;
- 响应支持请求;
- 发送事务性邮件(验证、密码重置、账单相关通知);
- 监控滥用、安全事件与服务可靠性;
- 遵守法律义务。
4. 处理依据(GDPR)
在 GDPR 或类似法律适用时,我们仅在具备合法依据的情况下处理个人数据。 依据 GDPR 第 6 条,我们依赖:
- 履行合同所必需(第 6(1)(b) 条):创建账户、提供服务及履行订阅;
- 合法利益(第 6(1)(f) 条):保障服务安全、防止滥用、诊断问题并提升可靠性——并在此与您的权利与自由进行权衡;
- 同意(第 6(1)(a) 条):在我们征求同意时(您可随时撤回,不影响撤回前已合法进行的处理);
- 法律义务(第 6(1)(c) 条):依法必须保留或披露信息时。
5. 信息共享
我们不会出售您的个人数据。仅在必要时与以下方共享:
- Paddle — 作为销售记录商进行支付处理、税务与开票;
- 托管与基础设施提供商 — 用于运行 gluestick.sh 及相关 API;
- 邮件发送服务商 — 用于发送事务性邮件;
- 主管机关 — 在法律要求或为保护权利与安全时。
您发起的开源包下载可能连接第三方包镜像或 GitHub;这些第三方有各自的政策。
6. 跨境传输
我们的服务与供应商可能在多个国家/地区处理数据,包括欧洲经济区(EEA)以外。 在 GDPR 适用且个人数据被传输至 EEA 以外时,我们将采用适当保障措施,例如欧盟委员会充分性认定、标准合同条款(SCCs),或其他合法传输机制。
7. 保留期限
在账户有效期间,以及为账单、支持、安全与合规所需,我们会保留账户与订阅记录。 您可按第 9 节所述请求删除账户;除非我们必须保留(例如税务、争议或安全记录),我们将删除或匿名化个人数据。
8. 安全
我们采取合理的技术与组织措施保护个人数据。 任何传输或存储方式都无法做到绝对安全;请使用强且唯一的密码,并保护好您的设备。
9. 您的权利(含 GDPR)
视您所在地法律——尤其当您作为欧盟/欧洲经济区(或英国)数据主体且 GDPR 适用时——您对个人数据享有以下权利:
- 访问权:要求获取我们持有的关于您的个人数据副本。
- 更正权:要求更正不准确或不完整的个人数据。
- 删除权(“被遗忘权”):在特定情形下要求删除个人数据。
- 限制处理权:在特定情形下要求我们限制对个人数据的使用。
- 反对权:反对基于合法利益的处理(包括在适用时的画像分析)。
- 数据可携权:要求以结构化、常用且机器可读的格式提供个人数据,或在技术可行时传输给其他控制者。
- 撤回同意权:处理基于同意时,可随时撤回同意。
- 投诉权:向您所在国家/地区或欧盟成员国的监管机构投诉(例如当地数据保护机构)。
行使上述权利,请使用与账户关联的邮箱发送至 support@gluestick.sh (或说明我们如何核实您的身份)。 我们将在适用法律要求的时限内答复(GDPR 下通常为一个月内)。
部分权利并非绝对;在法律允许时,我们可能拒绝或限制请求(例如为履行法定义务、解决争议或保障安全)。 若无法完全满足请求,我们会说明理由。
10. 儿童
本服务不面向 16 岁以下儿童,我们也不会故意收集其个人数据。
11. 变更
我们可不时更新本隐私政策。 更新时将修改页面顶部的“最后更新”日期。 更新后继续使用本服务,即表示您知悉修订后的政策。