Loading…
In force since 4 September 2026.
In plain language: what data we collect, what for, and what control you have over it.
From your account: name, email address and the plan you have active.
From your use: which screens you open and which features you use, so we can tell which part of the Platform helps and which does not. We keep the screen's name — “Forms”, “Academy” — never the full address and never what you type into a search box.
What you post in the community, because you post it for other people to read.
What we record: the name of the screen you opened — from a short list we define — how long you had it in front of you, how far down you scrolled (in steps of ten per cent), which controls you pressed — the control's name, from a list we define, never the text written on it and never the point on the screen where you pressed — how long the screen took to load and to answer you, which language you read it in, the approximate size of your screen — one of five width bands, never the exact measurement — whether you were reading it in the light or dark theme, and whether anything failed.
If you have an account, all of this is tied to it: it is the only way to know whether a feature helps one person or a hundred. You can switch it off whenever you want, with no explanation and with no loss of any feature.
We also note four signs that something is not going well: pressing the same thing several times in a row, pressing something that does not respond, something failing right after you press, and moving the pointer back and forth like someone searching without finding. Of that last one we keep only how many times you changed direction: never where the pointer went, and never where it was. They exist so we can find what breaks without you having to tell us.
What we do NOT record: anything you have typed, any fingerprint of your device, and no data from a client's case file. Your IP address is not stored anywhere: we use it for an instant, turned into an irreversible code that lives only in the server's memory, to stop a program flooding us with requests; that code disappears when the server restarts and never reaches a table or a log. We do not read your browser's name either. And we share none of this with anyone: there is not one third-party service measuring this site.
You can read the home page and the News Center without registering and without identifying yourself. We still measure how that page is used, and this is exactly what we do.
We use no tracking cookies and no cookie of any kind for measurement. When you open the page, your browser generates a random number whose only job is to tie together the events of that one visit: so we know the ten things we recorded came from one person reading, and not from ten. That number lives only in that tab's memory and disappears when you close it. We cannot relate it to your earlier visits, or to tomorrow's, or to your account if you create one later.
What we record: which bands of the page you had in front of you and for how long, how far down you scrolled in steps of ten per cent, which controls you pressed, how long the page took to load and to answer you, which language you read it in, the approximate size of your screen — one of five width bands, never the exact measurement — whether you were reading it in the light or dark theme, and whether anything failed.
What we do NOT record: your IP address, your browser's name, anything you have typed, and any fingerprint of your device. Nor where you came from: if you arrive through one of our campaign links, we do not read its tags. We share none of this with anyone: there is not one third-party service measuring this site.
You can say no, right here and with no explanation. The switch below turns measurement off in this browser immediately: no reload needed, you lose no feature, and we do not ask you again. To remember your decision we keep a single mark in this browser — nothing else, and only that — because without it we could not honour your choice the next time you come in.
This data is deleted after 90 days. What remains after that are counts — “this many visits read this band” — that no longer refer to anyone in particular.
On in this browser.
It applies immediately and no reload is needed. You lose no feature, and the choice covers this browser only: if you come in from another device, you will need to switch it off there too.
If your browser sends the Global Privacy Control (GPC) or Do Not Track (DNT) signal, we stop measuring you — whether or not you have an account, and without you having to tell us anything else.
The only thing we still record is technical failures — the error's name, nothing that was on the screen — because without them we could not fix what breaks. If you have no account, that record carries no session number and nothing that points to you. If you have an account, it carries your account, because that is the only way to know who it broke for.
We are not required to honour those signals: in the United States they bind businesses that sell or share personal information, and we do neither. We honour them because it is the right thing to do.
We use them to provide the service, maintain your account, improve the Platform and communicate with you about the service itself.
Measurement has one purpose: to know which part of the Platform helps and which does not, so we can fix it. We do not use it for advertising, to decide anything about you, or to build a profile of you.
We do not sell or share your personal information. Not for money and not for free, not for advertising, and not with anyone.
We do not ask for — and do not want — data that identifies end clients: the Platform is for information and professional work. The case files you create to organise your work are kept on your own device, inside the browser, and are not sent to our servers: we do not host them, we do not see them, and we cannot recover them or hand them to anyone.
We share them only with the infrastructure providers that let us operate: the site's hosting, the database, and the AI provider that writes the assistant's answers. Always under contract and only to deliver the service to you.
Measurement data reaches none of them: we keep it ourselves, in our own database, and there is no external analytics service.
Your question travels to the AI provider so it can write the answer, and that is where it ends: we do not keep the question, the answer, or any fragment. We only count how many times you use the assistant, to respect your plan's limit. Even so, do not include clients' personal data in what you ask it.
You can access, correct, export and delete your information.
You can also object to us measuring how you use Boxglaz, with no explanation and with no loss of any feature: the switch is in section 2 of this same page.
If you think we are not doing this right, you can complain to the data protection authority that covers you. Write to contacto@boxglaz.com and we will handle your request.
We apply role-based access control and encryption in transit, so that each person only sees inside the Platform what their role allows.
We keep your data while you have an active account and for as long as we need to meet our legal obligations; after that period we delete it or anonymise it.
Usage measurement data — both from visitors without an account and from registered people — is deleted after 90 days. After that period we keep only aggregate counts, which identify nobody. If you delete your account, we remove your identifier from all those records; the counts stay, because by then they are only numbers.
We will notify you of any material change to this policy. To exercise your rights, object to measurement, or ask us something, write to contacto@boxglaz.com. We answer within 30 days.