Continue with Glaucon
Buy pay-as-you-go usage credit or subscribe. Usage credit unlocks Pro models while it lasts; subscriptions add encrypted cloud storage.
Plans
Start free, buy one-time usage credit, or subscribe. Pay as you go unlocks Pro-level models while your credit lasts; Lite and Pro add encrypted cloud sync and the file vault.
- 10 daily messages on Auto
- First confidential document analysis free
- Device-local encrypted history (passkey unlock)
- Reasoning modes & zero-retention inference
- Frontier catalog (Sonnet, GPT, Gemini)
- File vault + encrypted cloud history
- Monthly usage included · economy overflow
- Adaptive web search & Cyfr
- SAML SSO & IP allowlists
- Audit logs & admin controls
- Custom usage & support
- Security review & DPA
- Pro-level model access while credit lasts
- Usage credit never expires
- No monthly commitment or economy overflow
- Encrypted cloud history and file vault require Pro
Questions about which plan fits? sales@glaucon.ai
Access to your favorite frontier models.
For professionals who take IP and contracts seriously.
Keeping your
advantage.
Built for regulated work
NDAs, audits, and privileged matters stay out of readable server storage. Encryption and zero-retention are built into the architecture.
Your edge stays yours
Strategy, research, and unreleased numbers never become someone else’s training data or a breach headline.
Frontier without the tradeoff
Claude, GPT, Gemini, and Grok with full capability over hybrid post-quantum transport to verified hardware.
Safe against tomorrow's computers, too
Even if someone records your traffic today, a future quantum computer won't unlock it. One layer among several, already shipped.
The architecture of stealth.
-
01
Encrypted cloud and file vault Post-quantum
Your saved history and files are encrypted with a key only you hold. Not Glaucon, not a subpoena, not a stolen database can read them. That includes protection against a future quantum computer.
-
02
Cyfr™ proprietary
Glaucon’s on-device Cyfr™ layer swaps names, firms, emails, and numbers for codenames before anything leaves your browser. You stay anonymous to the AI provider. The model reasons on the structure of your problem, never the identities behind it.
-
03
Hybrid post-quantum transport Glaucon X-Wing
Live chat uses Glaucon’s X-Wing: hybrid post-quantum key agreement inside an attested handshake. Your browser verifies hardware attestation before session keys exist, then seals frames for harvest-now-decrypt-later resistance on recorded wire traffic. Prompts travel encrypted to the enclave; replies return the same way. The edge relays opaque frames only. No decryption keys on Glaucon servers. Cryptographic detail at /trust.
-
04
Edge relay, no keys relay only
Glaucon’s edge servers handle auth, billing, and rate-limiting. They relay ciphertext only. No decryption key exists on the edge. We cannot read your traffic.
-
05
TEE enclave processing AMD SEV-SNP
Inside confidential hardware whose identity your browser already verified, prompts decrypt only long enough to run inference, then replies re-encrypt on the X-Wing channel. Plaintext exists ephemerally in enclave RAM, not on Glaucon’s edge and not in durable server storage.
-
06
ZDR frontier routing zero retention
Claude, GPT, Gemini, Grok, and Nemotron run through providers contractually and structurally barred from logging or training on your words. Your account identity never crosses this line. The model reasons on your problem, never on who you are.
-
07
GPU isolated GPU TEE
When you explicitly pick GPT-OSS or Gemma, the enclave routes to US open weights in a GPU confidential environment, not OpenRouter. This is the strongest open-weight path Glaucon offers.
-
08
Passwordless by design no shared secret
Sign in with a magic link, Google, or Apple. No password to phish, reuse, or leak. Account sign-in and encryption unlock are separate: after sign-in you create a passkey that seals local history under your MEK; Pro unlocks encrypted cloud sync and the file vault with that same key.
Verify the architecture.
Every production release is dual-signed and published to a public transparency log, binding the client bundle, enclave image, and attested runtime pins. Open the trust center and prove what you are running.
The models you already trust.
Without the privacy downgrade.
Claude, GPT, Gemini, Grok, and GPU-isolated open weights on one post-quantum path to a verified AMD SEV-SNP enclave. Frontier egress is zero-retention; Open · GPU isolated stays in GPU confidential compute. Same workspace. No tradeoff.
Smart routing. Picks the best model per task.
Model access: Auto is available free. Pay as you go unlocks Pro-level models while credit lasts. Pro includes the full frontier catalog with monthly usage and economy overflow.
The work you can’t
paste elsewhere.
The privacy is what lets you actually use it. Bring the contract, the deck, the numbers that aren’t public yet.
Read what you can’t upload anywhere else
Contracts, filings, patient notes. Ask in plain language and get an answer you can trace back to the source.
It reads the numbers, not just the words
Hand it a chart, a messy table, or a spreadsheet nobody cleaned up. It finds what moved and tells you why it matters.
From question to finished work
Draft the memo. Build the deck. Model the scenario. Export it and send it.
Answers you can check
It tells you what it's sure about and what it isn't. No confident guessing dressed up as fact.
Architecture
you can check.
Professionals do not buy slogans. Your browser verifies hardware attestation inside Glaucon’s X-Wing handshake before transport keys exist. Releases are dual-signed and logged to a public transparency log, so the software you loaded matches the enclave we operate. Full cryptographic detail at /trust.
Confidential AI FAQ
Questions professionals ask
before trusting an AI.
Straight answers on encryption, hardware attestation, and public proof. Check it yourself at /trust.
Is there a confidential AI that still uses frontier models like Claude and GPT?
Yes. That is what Glaucon is for: Claude, GPT, Gemini, Grok, and other frontier models behind Glaucon’s X-Wing encrypted path to an attested AMD SEV-SNP enclave, with zero-data-retention frontier egress. Frontier quality for confidential document work — without the default retention stack of a normal consumer AI chat. Verify at /trust.
What is the most private AI for analyzing confidential documents?
Glaucon is built for uploading and analyzing highly confidential documents and data with frontier models. It combines Glaucon’s X-Wing (hybrid post-quantum live chat to attested enclaves), zero-retention frontier inference, and a zero-knowledge encrypted file vault under your passkey. Glaucon cannot decrypt your vault or history.
Can I upload sensitive contracts or diligence files to an AI safely?
That is Glaucon’s primary use case. On Pro, files go in an encrypted vault under a passkey-wrapped master key; analysis runs over Glaucon’s X-Wing path to an attested enclave with ZDR frontier models (or Open · GPU isolated when you pick those models). Glaucon stores ciphertext only and holds no decryption keys.
Does Glaucon train on my data?
No. Glaucon routes frontier and economy inference through zero-data-retention (ZDR) providers and does not use your prompts to train models. Open · GPU isolated models use a separate GPU confidential path. Live chat is not stored as readable server-side history.
Is Glaucon end-to-end encrypted?
Yes. Live chat is end-to-end encrypted between your browser and an attested enclave over Glaucon’s X-Wing (hybrid post-quantum), and replies return encrypted on the same path. Glaucon’s edge never holds decryption keys. Inside the enclave, prompts decrypt only ephemerally for inference, then egress to zero-retention frontier providers or GPU confidential open weights, depending on the model you pick. Saved cloud history and the file vault are zero-knowledge ciphertext with keys only you hold. Cryptographic detail at /trust.
What is Open · GPU isolated?
Explicit picker models (GPT-OSS, Gemma) route from the same attested enclave into a GPU confidential environment for US open weights, not OpenRouter. Auto and frontier models use the zero-retention path instead. This is Glaucon’s strongest open-weight tier.
Is Glaucon anonymous?
Glaucon keeps you anonymous to the AI provider. Cyfr™ swaps names, firms, emails, and identifiers for codenames on your device before anything is sent. Your account identity never crosses the inference boundary, so the model reasons on the shape of your problem, not the people in it. On by default, and yours to control.
What makes Glaucon different from ChatGPT?
ChatGPT and peers keep history on provider infrastructure by default. Glaucon is built for confidential document work with the same class of frontier models: Glaucon’s X-Wing (hybrid post-quantum E2EE) to a verified enclave, ZDR frontier egress, Cyfr™ masking, zero-knowledge cloud history and vault, GPU-isolated open weights, and passwordless auth. Verify releases at /trust.
What is zero data retention (ZDR) inference?
ZDR means frontier model providers are contractually and structurally prevented from logging or training on your queries when routed through OpenRouter with zdr: true. Glaucon uses ZDR for frontier, economy, and Nemotron models. Open · GPU isolated models use GPU confidential inference instead, with a different egress and its own attestation receipts.
Can I verify the software Glaucon serves?
Yes. Signed release manifests at /trust/release.json bind the client bundle hash and enclave pins. Entries are published to the public Sigstore Rekor log. Open /trust and click Verify this release to check signature, bundle hash, and Rekor entry in your browser.
How does hardware attestation work?
On live chat, your browser verifies a hardware attestation report inside Glaucon’s X-Wing handshake against pinned enclave identity before encryption starts. If verification fails, the session does not proceed. Measurement and certificate-chain detail at /trust.
Is Glaucon post-quantum?
End to end for confidentiality, with honest scope. Live chat uses Glaucon’s X-Wing hybrid post-quantum key agreement inside attested enclaves, so recorded wire traffic is built to resist harvest-now, decrypt-later attacks. Stored history and the file vault use authenticated encryption under keys only you hold. Production releases are dual-signed. We do not claim fully post-quantum AI: model inference hops remain classical. Limits and algorithms at /trust.
What is Glaucon’s X-Wing?
Glaucon’s X-Wing is the live-chat transport: hybrid post-quantum key agreement inside an attested enclave handshake before any session keys exist, then authenticated encryption on the wire. Honest scope: X-Wing hardens key agreement; model inference hops remain classical. Full detail at /trust.
Can Glaucon read my saved chat history?
No. Free keeps history encrypted on your device under your encryption passkey. Pro syncs that same ciphertext to the cloud and unlocks the file vault. There is no server-side key and no backdoor. Add a second passkey on another device as your safety net. You can stay unlocked on a trusted device. If you lose every passkey you configured, the data is unrecoverable, by design.
Plans
Attested live chat, encrypted on-device history under your passkey, and core models. Privacy from the first message.
Full frontier catalog, file vault, and premium monthly usage on the same confidential stack.
SSO, custom limits, dedicated support, security review, and Rekor transparency log access.
One-time usage credit with no subscription. Unlocks Pro-level models while credit lasts and never expires. Encrypted cloud history and the file vault require Pro.
See pay as you go →Confidential AI. Glaucon’s X-Wing. Zero-knowledge.
About Glaucon
Glaucon is confidential AI for professionals who need to analyze sensitive documents and data: frontier models behind Glaucon’s X-Wing transport, attested enclaves, zero-retention inference, and a zero-knowledge vault — privacy enforced by architecture, not policy promises. General-purpose productivity software, not legal, investment, medical, or regulatory advice.
What you get
Upload contracts, diligence files, research, and proprietary datasets and analyze them with Claude, GPT, Gemini, Grok, and more on Glaucon’s X-Wing path (X25519 + ML-KEM-768) to a verified AMD SEV-SNP enclave, with zero-data-retention frontier egress. Open · GPU isolated models (GPT-OSS, Gemma) continue into GPU confidential compute when you pick them. Pro includes encrypted cross-device history, the file vault for confidential materials, adaptive web search, and Cyfr masking (on by default), plus the full frontier catalog and economy overflow after your monthly premium credit budget. Start free, then Pro ($20/mo).
How live chat is protected
Signed-in chat uses Glaucon’s X-Wing attested WebSocket channel with hybrid post-quantum key agreement for harvest-now-decrypt-later resistance: your browser verifies AMD SEV-SNP attestation (required VCEK certificate chain + pinned container policy) inside the handshake before any transport keys exist, then encrypts frames to the enclave via a blind edge pass-through at wss://glaucon.ai/api/chat/ws. The edge handles auth, billing, and quotas while relaying opaque frames only — it does not hold enclave keys — and attested confidential hardware decrypts inside protected enclaves, runs inference (zero-retention frontier routing or GPU confidential open weights, depending on model tier), and returns encrypted replies. Production releases publish signed manifests to the public Rekor transparency log (verify at /trust). Live inference is ephemeral; Glaucon does not store ordinary plaintext chat history on the server.
Content–identity unlinkability: your email, user ID, plan, and billing metadata never cross the inference boundary — model providers cannot cryptographically link prompts to your Glaucon account.
History & storage
Every signed-in account creates an encryption passkey (MEK) that seals history and the file vault — like a bank vault key. Free keeps history encrypted on-device under that key. Pro syncs the same ciphertext to cloud storage (AES-GCM in D1/R2; the master key never leaves your devices) and unlocks the file vault. Add a second passkey on another device as your safety net. You can stay unlocked on a trusted device in Settings. Live chat stays on Glaucon’s X-Wing post-quantum path. Local-only remains optional for paid accounts and never wipes existing data. When you burn a thread, it is removed from device and cloud copies.
Reasoning
Glaucon steers answers toward evidence, structure, and calibrated confidence instead of engagement bait or stale consensus. Every turn follows a conclusion-first discipline: load-bearing claims up front, weak premises surfaced, and terms defined before arguing.
Cyfr (default on)
Cyfr is a client-side layer enabled by default that substitutes sensitive names with codenames before a message is encrypted. It reduces accidental PII in ciphertext; you can disable it in Settings. It does not replace your own ethics, contract, or regulatory obligations about what data may be sent to a third-party AI tool.
Scope & responsibility
Glaucon eliminates surveillance-style retention and server-side plaintext exposure at the architecture level. You remain responsible for deciding whether a given matter, dataset, or workplace policy allows third-party AI tools. Formal certifications (for example SOC 2) are available on the enterprise path — contact security@glaucon.ai.
Full detail: Privacy Policy · Terms of Service · Trust center · Security overview on the landing page.
The name
The name nods to Plato's Republic — Glaucon's Ring of Gyges, an early meditation on invisibility, identity, and what people do when they believe no one is watching. We built Glaucon for principled privacy from default surveillance — and for accountability in reasoning.
Security & trust
Trust center
Structural privacy you can verify — Glaucon’s X-Wing live chat, attested enclaves, zero-knowledge storage, and dual-signed releases. This page is the security architecture for review. Live posture: GET /api/config → security.
Cryptography specification
Algorithms, key hierarchy, wrapper types, envelope formats, API shapes, threat model, and structural guarantees are documented for security reviewers:
GLAUCON-CRYPTO-SPEC.md (v1.9). Request via security@glaucon.ai if GitHub access is unavailable.
Architecture
- Live chat: Glaucon’s X-Wing on
wss://glaucon.ai/api/chat/ws(hybrid post-quantum key agreement, AES-256-GCM frames) with in-handshake AMD SEV-SNP verification. The edge authenticates and blind-pass-through relays opaque frames — no decryption keys on the edge. - Cloud history & file vault: End-to-end encrypted — one account master key (MEK) sealed by your encryption passkey; the same key unlocks history and vault. D1/R2 store ciphertext + IV only. File vault is Lite/Pro. Local-only is optional in Settings. Stay unlocked available on trusted devices.
- Inference: Frontier, economy, and Nemotron use OpenRouter ZDR pool (
provider.zdr: true,data_collection: deny). Open · GPU isolated models route to GPU confidential open weights from inside the attested enclave — not OpenRouter. No user-facing non-ZDR frontier path. - TEE: Dual confidential enclaves (primary + standby failover); AMD SEV-SNP attestation with pinned
HOST_DATA(CCE policy) + UVMMEASUREMENT; AMD VCEK certificate chain required in production (ARK→ASK→VCEK via THIM or AMD KDS). - Content–identity unlinkability: Account email, user ID, plan, and billing never cross the inference boundary — providers cannot cryptographically link prompts to Glaucon accounts.
- Cyfr: Client-side codename masking on by default before encryption; optional disable in Settings.
Glaucon’s X-Wing
Glaucon’s X-Wing is the production live-chat transport: your browser verifies an AMD SEV-SNP attested enclave, then establishes hybrid post-quantum key agreement (ML-KEM-768 + X25519) before any session keys exist. Frames are sealed with AES-256-GCM (already strong against harvest-now-decrypt-later for payload confidentiality). Recorded wire traffic requires breaking both classical ECDH and the lattice KEM. The design follows the public X-Wing hybrid KEM; Glaucon integrates it into attested Noise with container policy pins and a blind edge relay. Spec for reviewers: NOISE-TRANSPORT-PQ.md. Runtime: GET /api/config → security.liveChat.pqHybrid.
Inference paths
During a chat turn, your words are readable only to you and after the encrypted path in an isolated confidential enclave — a Trusted Execution Environment (TEE). For the instant it takes to answer, processing happens in TEE hardware your browser has already verified; it remains encrypted and unreadable on Glaucon’s edge and in storage. Transport uses Glaucon’s X-Wing: live chat in the browser → attested CPU TEE → either OpenRouter zero-data-retention (ZDR) routing or a GPU confidential enclave (GPU TEE), depending on which model you choose.
If you select frontier models (e.g., GPT-5.6 or Claude Sonnet), the enclave decrypts ephemerally and routes through OpenRouter’s ZDR pool — Glaucon enforces zero-retention routing in code, and only ZDR-enrolled providers are eligible. That is an enforced routing and contractual zero-retention stack, not hardware-bound inference inside one enclave. If you select Open · GPU isolated models, the enclave routes to US open weights in an attested GPU confidential environment — structural confidentiality enforced by hardware TEE and per-response attestation, without OpenRouter.
For maximum privacy, choose GPU isolated: open weights are inferred inside attested CPU and GPU enclaves, with no frontier API provider in the path. Frontier and economy models still offer Glaucon’s strongest closed-model privacy available (E2EE to enclave, identity stripped with Glaucon’s proprietary Cyfr layer, and ZDR-only, code-enforced routing), but plaintext does cross to ZDR-enrolled upstream providers for the duration of the request, even though that data will not be retained or used for training. Account email, plan, and billing never cross the inference boundary.
| Tier | Path today | What that means |
|---|---|---|
| Frontier (Claude Opus/Sonnet, GPT-5.x, Gemini Pro, Grok, etc.) | Browser → edge (blind) → enclave → ZDR provider | Ephemeral decrypt in hardware; identity stripped; ZDR contract at provider |
| Open · GPU isolated (GPT-OSS, Gemma 4) | Browser → edge (blind) → enclave → GPU confidential | US open weights; attested GPU inference with per-response receipts; not OpenRouter |
| Nemotron (US open frontier) | Browser → edge (blind) → enclave → ZDR provider | Open weights via OpenRouter ZDR — not GPU-isolated |
| Economy (Auto overflow, internal OSS routing) | Browser → edge (blind) → enclave → ZDR provider | Same ZDR stack as frontier; pick Open · GPU isolated in the model menu for GPU confidential open weights |
Not stored: Glaucon does not persist decrypted live chat on servers. Not sent to providers: account email, user ID, plan, or Stripe metadata (gateChatPayload). Web search: off by default; when you turn on Internet research, query text may reach a search provider — see Privacy Policy.
Enterprise controls
- SAML 2.0 SSO (SP-initiated) with XML signature verification
- Per-organization IP allowlists
- Metadata-only audit logs + SIEM export (enterprise roadmap)
- Global rate limits and daily spend circuit breaker
Subprocessors
We use the following categories of infrastructure and service providers to operate Glaucon:
| Provider | Purpose | Data handled |
|---|---|---|
| Cloudflare | Edge worker, D1, KV, email routing | Account metadata, ciphertext, rate-limit hashes |
| Microsoft Azure | Confidential container (TEE gateway) | Ephemeral ciphertext for inference |
| OpenRouter | Model inference (ZDR) | Ephemeral prompts/responses per ZDR policy |
| Open · GPU isolated | GPU-isolated open-weight inference | Ephemeral prompts/responses in attested GPU confidential compute (picker only) |
| Stripe | Billing | Payment and subscription metadata |
| Optional OAuth sign-in | Email, profile per OAuth consent | |
| PostHog | Product analytics and experiments | Event metadata only (paths, tiers, funnel steps, experiment variants); no chat content; first-party edge relay |
| Finnhub | Live market quotes (Pro monitor) | Ticker symbols only — never chat content |
Certifications
SOC 2 Type II and ISO 27001 are on our enterprise roadmap. Contact security@glaucon.ai for security questionnaires and DPAs.
Transparency log
Signed release manifests bind the exact client bundle hash, paste worker source, enclave pins (HOST_DATA + UVM MEASUREMENT), and Glaucon’s X-Wing transport flags (artifacts.liveChat). Each release is dual-signed: classical ECDSA P-256 (Rekor) plus ML-DSA-65 over the same manifest bytes. Verify without trusting our word alone:
- Fetch
/trust/release.jsonand confirm the ECDSA signature (/trust/release-public-key.pem). - Confirm the ML-DSA-65 signature when
signatures.pqis present (/trust/release-pq-public-key.b64). - Hash the served
/assets/glaucon-app.jsand compare to the manifest. - Confirm live pins in
GET /api/config→securitymatch the manifest (signed-in session). - Look up the manifest hash in Rekor (button below proxies the public log).
What dual signing proves (and what it does not)
| Layer | Post-quantum in release signing? |
|---|---|
| Release manifest integrity | Yes — ML-DSA-65 dual signature + classical ECDSA |
| Glaucon’s X-Wing live chat (ML-KEM-768 + X25519) | Attested in manifest artifacts.liveChat; verified at handshake, not re-signed per message |
| AMD SEV-SNP quote signatures | No — remain classical under AMD VCEK |
| OpenRouter / ZDR inference hop | No |
| Cloud history / file vault (AES-GCM at rest) | Already resistant — AES-256-GCM with symmetric-only key wrapping (no RSA/ECC key exchange to break); a lattice KEM here would protect nothing |
Why history & vault are already post-quantum
Harvest-now-decrypt-later is an attack on asymmetric key exchange — a future quantum computer running Shor’s algorithm breaks RSA and elliptic-curve Diffie-Hellman, so recorded key agreements can be unwound. That is exactly why Glaucon’s live-chat transport moved to hybrid ML-KEM-768 (X-Wing): it used X25519 ECDH.
Your stored history and file vault never touch that class of cryptography. A random 256-bit master key (MEK) seals every byte with AES-256-GCM, and the MEK itself is wrapped only by symmetric, hash-based material you hold — a WebAuthn passkey PRF (HMAC) and, on trusted devices, a non-extractable device key for Stay unlocked. There is no RSA or elliptic-curve key exchange anywhere in the storage path, so there is nothing for a quantum computer to break to open harvested ciphertext. Grover’s algorithm halves symmetric strength, leaving AES-256 at a ~128-bit post-quantum floor — well beyond reach. Bolting a lattice KEM onto storage would be theater: there is no public-key operation to protect. So the honest answer is not “we added post-quantum encryption at rest” — it is symmetric encryption was already quantum-resistant, and we use nothing weaker.
End to end: hybrid post-quantum on the wire (X-Wing) + quantum-resistant symmetric encryption at rest = post-quantum confidentiality from your browser to storage and back. Scope, stated plainly: this covers confidentiality. Integrity/authentication signatures (AMD SEV-SNP quote ECDSA; the inference hop) remain classical and are tracked separately above.
Dual-signed releases prove what Glaucon shipped (bundle hash, enclave pins, hybrid flags). They do not claim “fully post-quantum AI.” Spec: TRUST-RELEASE-PQ.md.
CLI: node scripts/verify-release-manifest.mjs trust/releases/<file>.json --require-pq --rekor · Workflow: npm run trust:release then npm run trust:release:publish
Residual risk
Encrypted cloud history and the file vault decrypt only after your encryption passkey unlocks the account master key (or Stay unlocked on a trusted device). Without that unlock, browser storage inspection shows ciphertext and sealed blobs — not decrypted content. Live chat plaintext exists only ephemerally in browser and attested enclave RAM during inference; Glaucon does not persist it server-side. Malware on an actively unlocked session could observe what you can see — passkeys, session sealing, and CSP mitigate but cannot eliminate that class of risk in any web E2EE product.
See also: Privacy Policy · About · Landing security overview
Privacy Policy
Overview
Glaucon is the privacy-first, E2EE, TEE, & ZDR AI solution for professionals. Frontier, economy, and Nemotron models use zero-data-retention (ZDR) routing through OpenRouter by default. Open · GPU isolated models (GPT-OSS, Gemma) route to US open weights inside an attested GPU confidential environment when you select them in the model picker. Signed-in live chat uses Glaucon's X-Wing (hybrid post-quantum key agreement) on an attested WebSocket with authenticated encryption: the browser verifies hardware attestation inside the handshake before transport keys exist. Cryptographic algorithms and pins are published at /trust. The service is designed so account identity, billing, and usage controls are separated from live chat processing, and plaintext live chat content is not stored by Glaucon as ordinary server-side chat history.
Glaucon also offers optional features that change how data is handled, including encrypted cloud history, browser-local history, account registration, file upload and local parsing, Pro subscriber API budget add-ons, and paid subscriptions through Stripe. Adaptive web search may run when a turn needs current facts (OpenRouter ZDR only). Pro live market quotes may call Finnhub with ticker symbols only (never chat content). Production releases publish signed manifests to the public Sigstore Rekor transparency log. This policy explains what data is collected, how it is used, what is stored, what is not stored, and what choices users have.
Scope
This Privacy Policy applies to:
- The Glaucon website and web app at glaucon.ai and associated subpages.
- Guest and account-based use of chat, workspaces, and file-processing features.
- Account creation, login, encrypted history sync, plan management, and billing flows.
- Support, security, abuse prevention, diagnostics, and legal compliance activities reasonably necessary to operate the service.
It does not govern third-party sites or services that may be linked from Glaucon or embedded as external processors, such as payment processors or infrastructure providers, except as described here at a high level.
Privacy architecture summary
Glaucon is built around a layered privacy model. Account/profile data is separated from live model prompts. Signed-in chat uses Glaucon's X-Wing (hybrid post-quantum key agreement) by default on same-origin WebSocket (wss://glaucon.ai/api/chat/ws); the edge authenticates and blind-pass-through relays opaque frames to attested confidential enclaves; frontier and economy inference runs with OpenRouter ZDR routing inside that enclave; Open · GPU isolated models route from the same enclave to an attested GPU confidential environment (browser and edge never call the GPU confidential path directly). Every signed-in account provisions an encryption passkey (MEK) at signup for local history; encrypted cloud sync and the file vault are Lite/Pro. TEE is used for inference only — not for storage. Account email and billing never enter model payloads. Signed release manifests publish to the public Sigstore Rekor transparency log.
At a high level:
- Account layer: stores profile, authentication, subscription, quota, and billing-linked identifiers — kept separate from live chat prompts.
- Storage layer (encrypted cloud + vault): Free accounts keep client-encrypted history on-device under the account MEK. Lite/Pro sync that same ciphertext to cloud storage (D1/R2 ciphertext only); local-only remains optional in Settings. File vault is Lite/Pro. A random per-account MEK secret encrypts history and vault and is wrapped by your WebAuthn passkey/PRF; trusted devices may keep a non-extractable stay-unlocked key. Keys never leave the browser, there is no server-side backdoor, and Glaucon cannot decrypt your history or vault.
- Inference layer: edge blind-relays ciphertext to attested TEE enclaves for decrypt, model processing, and re-encryption. Frontier, economy, and Nemotron use OpenRouter ZDR pool only. Open · GPU isolated models route from the same enclave to an attested GPU confidential environment (US open weights). Upstream API keys exist only inside the enclave. Providers receive no account email or user ID — content is unlinkable to Glaucon account identity at the inference boundary.
- Live chat layer: Glaucon's X-Wing (hybrid post-quantum key agreement) on an attested WebSocket; edge blind-pass-through relays opaque frames without decrypting; ephemeral — not stored as server-side plaintext history. Algorithms and attestation detail at /trust.
This architecture is meant to reduce data linkage and minimize retained plaintext, but no online system can guarantee absolute security or perfect anonymity in all circumstances.
Information collected
1. Account and profile information
When a user creates an account, Glaucon may collect:
- Email address.
- Passwordless authentication metadata — magic link, Google OAuth, or Apple OAuth. History passkeys are separate from account authentication and only wrap the client-held encryption key used to unlock cloud history and the file vault. The
password_hashcolumn stores sentinel values (for examplemagic:email,oauth:google), not user-chosen login passwords. Legacy password accounts (if any) use PBKDF2-SHA256 with an optional server-side pepper; encryption keys are never derived from login credentials. - Subscription status, plan, usage quota, usage counters, and quota reset timing.
- A history salt associated with encrypted history workflows.
- Sandbox display handle information in sandbox mode, where applicable.
This information is used to authenticate users, enforce subscription and quota rules, maintain account state, and support account recovery or support interactions where applicable.
2. Session and authentication data
Glaucon uses a secure session cookie for authenticated sessions. The session cookie is configured as HttpOnly, Secure, and SameSite=Strict, which helps limit client-side script access and cross-site sending.
Session records may include:
- Session identifier.
- Associated user identifier.
- Session expiration timestamp.
This data is used solely to maintain signed-in sessions, authorize account-only features, and support secure logout and session expiration behavior.
3. Live chat and workspace inputs
When a user submits a prompt, message, or workspace input, Glaucon processes the submitted content to generate a response. Message payloads are sent from the browser in an encrypted envelope using AES-GCM session encryption. In production, the edge worker relays ciphertext to a TEE gateway; decryption for inference occurs inside the attested enclave, not on the edge worker.
Depending on user actions, submitted content may include:
- Chat messages.
- Structured workspace fields for research, pitch, or M&A diligence workflows.
- Extracted text from uploaded files.
- User-selected model and routing preferences.
Glaucon does not store plaintext live chat content on its own servers as ordinary chat history in the standard live inference path. However, live content is still transmitted for processing to the selected inference route and may exist transiently in memory or ephemeral processing systems during request handling.
4. File uploads and local file processing
Users may attach files, including PDFs, text files, images, and spreadsheet files, subject to product limits and supported formats. Glaucon performs some file processing locally in the browser, including PDF text extraction and spreadsheet parsing, and strips EXIF metadata from supported image uploads before transmission.
Glaucon may therefore process:
- File names and file types.
- Extracted text content from supported files.
- Sanitized image payloads where applicable.
- Limited file-related warnings, such as local PII warnings generated on-device.
Users are responsible for ensuring they have the right to upload and process any file they submit.
5. Encrypted history data
If a user enables encrypted cloud history, Glaucon stores only ciphertext, IV values, and update timestamps in its database for that feature. Because the encryption keys are held only on your devices (passkey-wrapped) and are never transmitted to Glaucon, the service cannot read or decrypt this content: there is no server-side key and no backdoor. The same applies to encrypted file vault contents. If you lose every encryption passkey, the encrypted data is unrecoverable — by design, not by policy.
If a user selects browser-local history instead, chat history may be stored on the user’s device through browser storage mechanisms or in-memory client state depending on feature and browser behavior. Users should understand that local device access and browser environment security remain partly under the user’s own control.
6. Billing and payment information
Glaucon uses Stripe for subscription checkout, subscription activation, subscription state changes, and customer/payment linkage. Glaucon may store limited Stripe-related metadata, including:
- Stripe customer ID.
- Stripe subscription ID.
- Subscription plan and status.
- Checkout and billing state needed to activate or deactivate plans.
Glaucon does not state in the current implementation that it stores full payment card numbers on its own systems; payment processing is handled through Stripe flows.
7. Usage, quota, security, and technical data
Glaucon collects limited technical and operational data needed to run the service safely and reliably. This may include:
- Rate-limit keys derived from hashed IP information.
- Request metadata needed to detect abuse, enforce quotas, and secure the service.
- Error, debug, and diagnostic events used to investigate failures or service integrity issues.
- Browser and device context needed for security controls, rendering, or compatibility.
- Product analytics event metadata (for example page path, plan tier, funnel step, experiment variant, and coarse error codes) relayed through Glaucon’s first-party edge to PostHog. Glaucon does not send chat prompts, completions, file contents, ciphertext, email addresses, or names in analytics events. Anonymous device identifiers may be merged to an opaque account id (
u_…) after sign-in.
This operational data is used for fraud prevention, abuse prevention, reliability, diagnostics, product improvement, and legal compliance.
How Glaucon uses information
Glaucon uses collected information to:
- Provide chat, workspace, and document-analysis functionality.
- Authenticate users and maintain account sessions.
- Enforce plan limits, message quotas, and subscription access controls.
- Process subscription purchases, confirmations, and billing events through Stripe.
- Save encrypted history when the user enables that feature.
- Store browser-local or session-local state when the user chooses local history or client-side workflows.
- Detect abuse, prevent fraud, enforce security, and maintain service reliability.
- Comply with legal obligations and respond to lawful requests.
- Improve product quality, troubleshoot issues, and maintain operational integrity, using data reasonably necessary for those purposes.
Glaucon does not sell users’ personal information in the ordinary sense of selling personal data for money to third-party data brokers.
Inference routing and third-party processing
Zero-retention routing (frontier, economy, Nemotron)
Glaucon’s default route for frontier, economy, and Nemotron models is designed around zero-data-retention processing through OpenRouter. In the current implementation, the app sets provider flags intended to request ZDR behavior and deny data collection on that route (provider.zdr: true, data_collection: deny).
When the ZDR route is used, Glaucon’s intent is that prompts and completions are processed without routine retention for training and without Glaucon storing plaintext server-side chat history. That said, users should understand that third-party provider behavior is ultimately governed by the technical operation and terms of those providers, and Glaucon cannot convert an external processor into a risk-free or legally absolute black box.
Open · GPU isolated
When you explicitly select an Open · GPU isolated model (GPT-OSS, Gemma), the attested Azure enclave forwards the decrypted request to an attested GPU confidential environment for US open-weight inference. This path is not OpenRouter. Auto routing and economy overflow do not use this path. Web search is disabled on Open · GPU isolated models.
Users handling especially sensitive material should review model tier and routing settings at /trust#inference-paths.
What Glaucon stores and does not store
Glaucon does store
Depending on configuration and user choices, Glaucon may store:
- Account and login data.
- Password hashes and salts.
- Session records.
- Subscription and billing-linked identifiers.
- Message quota counters and plan state.
- Encrypted chat-history ciphertext, IV, and timestamps when encrypted cloud history is enabled.
- Security, abuse-prevention, and technical diagnostics data reasonably necessary to operate the service.
Glaucon does not ordinarily store as server-side history
In the ordinary live inference flow, Glaucon is designed not to store plaintext chat transcripts as ordinary server-side chat history. Instead, any persistent history storage is either browser-local or ciphertext-only, depending on the user’s settings.
Important qualification
Privacy and retention claims in this policy refer to ordinary operation as implemented in the product architecture shown in the current codebase. They do not mean that no data ever exists transiently in memory, on the network, in security tooling, in third-party payment systems, or as required by law, nor do they override technical incident response, fraud prevention, or legal process where applicable.
Cookies, local storage, and browser-side data
Glaucon uses cookies and browser-side storage for product functionality. These mechanisms may include:
- Authenticated session cookies used to keep users signed in.
- Browser-local history storage when that mode is selected.
- Local settings, dismissals, UI preferences, and workflow state stored on-device where the app uses browser storage.
Disabling cookies or browser storage may impair some features, especially login, account persistence, chat history behavior, and product settings.
Legal bases and purpose limitation
Where privacy laws require a legal basis, Glaucon generally processes information on one or more of the following grounds, as applicable:
- To perform the service requested by the user, including chat, account management, encrypted history sync, and billing support.
- To pursue legitimate interests in operating, securing, improving, and defending the service, provided those interests are not overridden by applicable user rights.
- To comply with legal obligations, law enforcement requests, tax obligations, fraud prevention duties, or dispute resolution needs.
- Based on consent where a feature depends on a user’s optional selection, such as enabling certain history behavior or choosing a non-default route.
Glaucon seeks to limit use of collected data to the purposes described in this policy and not to repurpose data in ways materially inconsistent with those purposes without additional notice.
Sharing of information
Glaucon may share information with the following categories of recipients to operate the service:
- Infrastructure and hosting providers, including Cloudflare-based systems used to deliver the web application and worker infrastructure.
- AI inference providers used to process prompts and return responses under the selected route (OpenRouter ZDR for frontier/economy/Nemotron; attested GPU confidential inference for Open · GPU isolated models).
- Payment processors, including Stripe, for checkout, subscription, billing, fraud controls, and payment operations.
- Security, diagnostics, and abuse-prevention tools reasonably required to protect the service and users.
- Professional advisers and acquirers where reasonably necessary for legal, tax, audit, corporate transaction, or restructuring purposes.
- Governmental or legal authorities when required by law, court order, subpoena, or good-faith belief that disclosure is necessary to comply with legal obligations or protect rights, safety, and platform integrity.
Glaucon does not describe itself in the current implementation as a data broker, advertising network, or behavioral ad platform, and this policy does not authorize such use.
Data retention
Retention varies by data type and user choice.
- Account, subscription, and security data may be retained for as long as reasonably necessary to maintain the account, comply with legal obligations, resolve disputes, enforce agreements, or protect the service.
- Encrypted cloud history remains stored until deleted by the user, removed under product rules, or deleted in connection with account deletion or service changes, subject to backups or legally required retention.
- Browser-local history remains on the user’s device until the user deletes it, clears storage, changes browser state, or the browser removes it.
- Rate-limit and abuse-prevention data may be retained briefly or longer depending on security needs, implementation details, and legal requirements.
No retention period in this policy should be read as a guarantee of immediate deletion from every cache, backup, log, or processor environment.
User controls and choices
Users may have the ability to:
- Use Glaucon in guest or sandbox modes where available.
- Create or avoid creating an account.
- Rely on ZDR routing through OpenRouter for frontier, economy, and Nemotron models.
- Select Open · GPU isolated models for attested GPU confidential inference when configured.
- Use encrypted cloud history and file vault (Lite / Pro / Enterprise default) or switch to local-only history in Settings.
- Delete encrypted history through the product’s history delete functionality.
- Log out and clear sessions.
- Manage subscription status through the account and billing flows.
Users are responsible for understanding the privacy implications of their chosen settings, especially when selecting model tiers or local device storage modes.
Access, correction, deletion, and privacy rights
Depending on applicable law, users may have rights to request access to, correction of, deletion of, or restriction of certain personal information. Users may also have rights to object to certain processing, withdraw consent where consent is the basis, or request portability where technically applicable.
Glaucon will evaluate such requests in light of applicable law, technical feasibility, account security, fraud prevention, legal obligations, and the fact that some server-side stored history may exist only as ciphertext. A request may therefore be fulfilled, partially fulfilled, denied, or require additional identity verification.
Requests may be submitted through the contact method specified by Glaucon. If no dedicated privacy contact is yet published, the operator should add one before commercial launch.
Sensitive data and professional use
Glaucon is built for privacy-sensitive work, but users should not assume that any internet-based tool is automatically appropriate for every regulated or privileged data category. Users remain responsible for assessing whether they are permitted to use Glaucon for any specific dataset, client matter, legal work product, trade secret, health information, financial information, employment information, export-controlled material, or other regulated information.
The existence of Cipher, encrypted history, or ZDR routing does not by itself guarantee compliance with any particular legal, regulatory, ethical, or contractual obligation.
Security measures
Glaucon uses security controls reflected in the current implementation, including AES-GCM request envelopes, CSP nonces, strict session-cookie settings, input validation, rate limiting, hashed IP-based rate-limit keys, and encrypted history storage patterns. These safeguards are intended to reduce risk, but no method of transmission, storage, or processing can be guaranteed perfectly secure.
Users should also protect their own devices, browsers, passwords, and local storage environment, because privacy outcomes depend partly on user-side operational security.
International processing
Glaucon may use service providers and infrastructure that process data in multiple jurisdictions depending on deployment, user location, and vendor configuration. By using the service, users understand that their information may be processed in jurisdictions that may differ from their home jurisdiction, subject to applicable safeguards and legal requirements.
Children
Glaucon is not intended for children under 13, and the service should not be used by minors where prohibited by applicable law or contractual restrictions. If Glaucon learns that personal information has been collected from a child in violation of applicable law, it may take steps to delete that information and restrict the account.
Changes to this policy
Glaucon may update this Privacy Policy from time to time to reflect product changes, legal developments, security practices, or operational needs. When material changes are made, Glaucon may update the effective date and provide additional notice where required by law.
Contact
Questions, requests, or complaints regarding this Privacy Policy may be sent to the addresses below.
Preferences
Settings
Appearance, chat defaults, and data controls
Account
Sign in for encrypted live chat. New accounts get a free trial on economy models, then subscribe to Pro for the full frontier catalog and encrypted cloud sync.
Profile
Email:
Verify your email to secure account recovery and billing notices.
Plan:
Monthly usage
Included usageCredits — heavier models consume more of your budget.
Billing
Buy pay-as-you-go usage credit for Pro-level models, or subscribe to Pro for encrypted cloud history, the file vault, and monthly usage.
Compare subscriptions and pay as you go
Password
For security, password changes are only done through a one-time link emailed to you. The link expires in 1 hour.
Your encryption passkey is separate from this login password. After a password reset, unlock with your passkey (or Stay unlocked on this device) to open encrypted history.
Encryption key
Your encryption passkey unlocks encrypted history and the file vault on this account — like signing into a bank vault. Live chat stays on Glaucon’s X-Wing post-quantum path.
Encryption setup
Delete account
Permanently deletes your profile, sessions, encrypted cloud history, and cancels any active subscription. This cannot be undone.
Terms of Service
Agreement to these terms
These Terms of Service govern access to and use of Glaucon, including the web application, website, account features, paid plans, workspaces, file-processing tools, and related services. By accessing or using Glaucon, a user agrees to be bound by these Terms and by the applicable Privacy Policy.
The service is operated by Glaucon LLC, a Texas limited liability company ("Glaucon," "we," "us," or "our"). These Terms are a binding agreement between Glaucon LLC and the user ("you").
If a user does not agree to these Terms, that user must not access or use the service. If a user accesses or uses Glaucon on behalf of an organization, that user represents that the user has authority to bind that organization to these Terms.
The service
Glaucon is the privacy-first, E2EE, TEE, & ZDR AI solution for professionals. Frontier, economy, and Nemotron models use zero-retention inference through OpenRouter. Open · GPU isolated models route to an attested GPU confidential environment when explicitly selected. Chat requires a registered account. New accounts receive a limited trial, then a Pro subscription. Signed-in live chat uses browser-to-enclave encryption through a hardware-backed Trusted Execution Environment (TEE). The service includes AI chat, dynamic reasoning modes, file parsing and document-assisted workflows, optional web research, encrypted history options, and paid plans through Stripe.
Glaucon may add, remove, suspend, or modify features, models, pricing, quotas, limits, and interface elements at any time. Chat and core features require a registered account.
Eligibility
A user must be at least 18 years old, or the age of majority in the user’s jurisdiction if higher, to use Glaucon for paid, professional, or account-based purposes. If a user is under that age, the user may not use the service unless applicable law permits and a parent or guardian has validly agreed, but Glaucon may still restrict or prohibit such use.
A user may not use Glaucon if that user is barred from using the service under applicable law, sanctions restrictions, export control restrictions, or other legal limitations.
Accounts and security
An account is required to use Glaucon chat. Users must create an account with accurate, current, and complete information, including an email address and password. The user is responsible for maintaining the confidentiality of login credentials, securing devices and browsers used to access the service, and promptly reporting suspected unauthorized account use.
Glaucon may suspend, restrict, or terminate an account if Glaucon reasonably believes that the account has been compromised, is being used in violation of these Terms, creates security risk, or is involved in fraud, abuse, or unlawful conduct.
Privacy, routing, and data handling
Glaucon is designed so account identity, billing, and usage controls are separated from live model prompts, and plaintext live chat content is not stored by Glaucon as ordinary server-side history. Signed-in live chat uses Noise attested browser-to-enclave encryption; the edge relays ciphertext only.
By using Glaucon, a user acknowledges that:
- Frontier, economy, and Nemotron models are sent through OpenRouter with ZDR provider flags inside the TEE gateway; Open · GPU isolated models route to an attested GPU confidential environment when selected. Upstream processors may still handle data according to their own technical systems and applicable terms.
- Adaptive web search runs through OpenRouter under the same ZDR configuration; search queries do not include account identity.
- Encrypted cloud history stores ciphertext and related metadata, while browser-local history may store data on the user's own device.
- Signed-in live chat routes through a Noise attested confidential channel so the edge blind-pass-through relays opaque frames only.
- Payment and billing data are processed through Stripe-based flows.
Additional details about data handling appear in the Privacy Policy, which is incorporated into these Terms by reference.
No professional advice
Glaucon provides software tools and AI-generated outputs for information, drafting assistance, organization, and analytical support. Glaucon does not provide legal advice, investment advice, accounting advice, tax advice, medical advice, employment advice, regulatory advice, or any other licensed professional service.
No attorney-client, fiduciary, auditor-client, physician-patient, broker-client, or other special professional relationship is created through use of the service. Any output generated through Glaucon must be independently reviewed by a qualified human professional before being relied upon for important personal, business, or compliance decisions.
AI output limitations
AI systems can be inaccurate, incomplete, misleading, outdated, or inconsistent. A user must not treat Glaucon output as a substitute for independent judgment, source verification, or professional review.
A user is solely responsible for:
- Evaluating the accuracy and suitability of outputs.
- Verifying facts, calculations, and conclusions.
- Deciding whether and how to use outputs in any workflow, communication, or transaction.
- Ensuring that final work product complies with applicable law, contract, ethics rules, and professional standards.
User content and responsibility
A user may submit prompts, text, files, workspace fields, chat instructions, and other content to the service. The user retains responsibility for all such content and for the consequences of submitting or using it.
A user represents and warrants that:
- The user has all rights, permissions, and authority necessary to submit the content to Glaucon and to authorize any processing requested by the user.
- The content and the user’s use of the service do not violate any law, regulation, court order, confidentiality duty, contract, export restriction, sanctions rule, privacy right, intellectual property right, or third-party right.
- The user will not submit content that the user is prohibited from sharing with Glaucon or its processors.
If a user chooses to use Glaucon with confidential or contract-restricted material, the user is solely responsible for determining whether that use is permitted and appropriate.
Acceptable use
A user may not use Glaucon to:
- Violate any law or regulation.
- Infringe intellectual property, privacy, confidentiality, publicity, or other rights.
- Commit fraud, deception, impersonation, identity theft, or social engineering.
- Generate, facilitate, or distribute malware, phishing content, credential theft tools, spyware, destructive code, or other harmful code.
- Circumvent security features, rate limits, quotas, authentication controls, or usage restrictions.
- Probe, scan, exploit, scrape, or overload the service in a way that disrupts service integrity or harms others.
- Use the service to make solely automated decisions about employment, credit, insurance, housing, education, medical treatment, or law enforcement without appropriate lawful safeguards and human review.
- Upload or process material in violation of obligations owed to clients, employers, counterparties, courts, regulators, or other protected parties.
- Misrepresent AI-generated output as verified fact where doing so could mislead others in a material way.
Glaucon may investigate suspected misuse and may suspend or terminate access, preserve relevant records, or cooperate with law enforcement where reasonably appropriate.
User responsibility
Glaucon is general-purpose AI productivity software. It is not certified for any specific regulated industry or professional licensing regime. Users are solely responsible for ensuring their use complies with applicable laws, contracts, and workplace policies.
The presence of ZDR routing or encrypted history does not by itself create compliance with any statute, regulation, or contractual security schedule.
Subscriptions, pricing, and billing
Glaucon offers free access, one-time pay-as-you-go usage credit, Glaucon Pro ($20/mo), Enterprise plans by agreement, and legacy Lite plans for existing subscribers only. Pay-as-you-go packs are currently $5, $10, or $20. Plan features and model access are described on the plans page and at checkout. All live inference uses the same zero-retention routing path.
New accounts currently receive 10 daily messages on Auto and one free confidential document analysis. Pay-as-you-go credit unlocks Pro-level models while the balance lasts, never expires, and does not include economy overflow or encrypted cloud storage. Lite and Pro subscriptions include encrypted cloud history and the file vault; Pro includes a monthly premium API budget and may continue in economy mode after that budget is used, subject to economy caps and billing-cycle resets.
If a user purchases a paid subscription:
- The user authorizes Glaucon and its payment processor to charge the applicable subscription fees, taxes, and any other disclosed amounts.
- Subscriptions may renew automatically unless cancelled before the next billing cycle according to the applicable checkout or account flow.
- Plan features, prices, and included model access may change prospectively.
- Failure of payment, chargeback activity, fraud concerns, or account abuse may result in downgrade, suspension, cancellation, or access restriction.
Pay-as-you-go packs are one-time purchases unless otherwise stated. Unless otherwise required by law or separately agreed in writing, subscription fees and completed usage-credit purchases are non-refundable after the applicable service period or credit delivery begins. A user is responsible for reviewing the current plan terms on the plans page and at checkout.
Quotas, limits, and availability
Glaucon may enforce trial limits, API budgets, rate limits, file limits, feature limits, model limits, or environment-specific restrictions. The current implementation includes account-based trial tracking, subscription API budgets with optional economy overflow for Pro, per-minute rate limiting, file-count and file-size limits, and plan-gated model access.
Glaucon does not guarantee uninterrupted availability, specific response times, or error-free operation. Maintenance, outages, third-party dependency failures, model changes, abuse controls, infrastructure incidents, and legal or security events may affect service availability or performance.
Intellectual property
Glaucon and its related software, interface, branding, logos, design elements, compilations, and service materials are protected by intellectual property and other applicable laws. Subject to these Terms, Glaucon grants the user a limited, non-exclusive, non-transferable, revocable right to access and use the service for its intended purposes.
A user may not copy, modify, distribute, sell, lease, sublicense, reverse engineer, decompile, create derivative works from, or exploit the service except as permitted by law or by Glaucon in writing.
As between Glaucon and the user, the user retains rights in user-submitted content, subject to the rights necessary for Glaucon and its processors to operate the service, provide outputs, enforce the Terms, maintain security, and comply with law.
Feedback
If a user provides feedback, suggestions, bug reports, ideas, or improvement proposals regarding Glaucon, Glaucon may use them without restriction or compensation, except to the extent prohibited by law. This does not transfer ownership of the user’s underlying confidential content, but it does permit use of the feedback itself to improve the service.
Suspension and termination
Glaucon may suspend, restrict, or terminate access to all or part of the service at any time, with or without notice, if Glaucon reasonably believes that:
- The user has violated these Terms.
- The user has created legal, financial, operational, or security risk.
- Continued service would harm Glaucon, its users, its processors, or third parties.
- The account is inactive, unpaid, fraudulent, or subject to a legal restriction.
A user may stop using the service at any time and may cancel a subscription through the available account or billing workflow, subject to the billing rules in these Terms and at checkout.
Disclaimers
The service is provided on an as is and as available basis to the fullest extent permitted by law. Glaucon disclaims all warranties, whether express, implied, statutory, or otherwise, including implied warranties of merchantability, fitness for a particular purpose, title, non-infringement, quiet enjoyment, accuracy, security, availability, and results from use of the service.
Without limiting the foregoing, Glaucon does not warrant that:
- The service will be uninterrupted, secure, or error-free.
- Outputs will be accurate, complete, lawful, or fit for any particular use.
- Any privacy, anonymity, encryption, ZDR, or security feature will prevent all disclosure, access, incident, or regulatory risk.
- The service is suitable for any particular regulated, privileged, or mission-critical workflow.
Limitation of liability
To the fullest extent permitted by law, Glaucon and its affiliates, officers, employees, contractors, licensors, and processors will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of profits, revenues, business, goodwill, data, contracts, opportunities, or savings, arising out of or related to these Terms or the use of or inability to use the service, even if advised of the possibility of such damages.
To the fullest extent permitted by law, the aggregate liability of Glaucon arising out of or relating to these Terms or the service will not exceed the greater of:
- The amount paid by the user to Glaucon for the service during the 12 months before the event giving rise to the claim, or
- 100 U.S. dollars.
Some jurisdictions do not allow certain limitations, so some of the above may not apply to particular users to the extent prohibited by law.
Indemnification
A user agrees to defend, indemnify, and hold harmless Glaucon and its affiliates, officers, employees, contractors, licensors, and processors from and against claims, liabilities, damages, judgments, losses, costs, and expenses, including reasonable attorneys’ fees, arising out of or related to:
- The user’s content.
- The user’s use or misuse of the service.
- The user’s violation of these Terms.
- The user’s violation of law or third-party rights.
- The user’s processing of confidential, regulated, or restricted material without sufficient authority.
Governing law
These Terms and any dispute arising out of or relating to them or the service are governed by the laws of the State of Texas, without regard to its conflict-of-laws principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
Dispute resolution and arbitration
Please read this section carefully — it affects your legal rights.
Before filing any claim, you agree to first contact Glaucon at legal@glaucon.ai and attempt to resolve the dispute informally for at least 30 days.
Except for the matters excluded below, any dispute, claim, or controversy arising out of or relating to these Terms or the service that cannot be resolved informally will be resolved by binding individual arbitration administered by the American Arbitration Association (AAA) under its Consumer Arbitration Rules. The arbitration will be conducted in English, by a single arbitrator, in Travis County, Texas, or remotely by videoconference at either party's election. Judgment on the award may be entered in any court of competent jurisdiction.
Excluded from arbitration: (a) individual claims qualifying for small-claims court; (b) claims for injunctive or equitable relief regarding intellectual property, unauthorized access, or misuse of the service, which may be brought in court.
Class action waiver. All disputes must be brought in the parties' individual capacity, and not as a plaintiff or class member in any purported class, collective, consolidated, or representative proceeding. The arbitrator may not consolidate claims or preside over any form of representative proceeding. If this waiver is found unenforceable as to a particular claim, that claim (and only that claim) must proceed in court, and the waiver remains enforceable for all other claims.
30-day opt-out. You may opt out of this arbitration agreement by emailing legal@glaucon.ai with the subject "Arbitration Opt-Out" from the email associated with your account within 30 days of first accepting these Terms. Opting out does not affect any other provision of these Terms.
Venue
For any dispute not subject to arbitration, you and Glaucon consent to the exclusive jurisdiction and venue of the state and federal courts located in Travis County, Texas, and waive any objection to such venue.
Notices
Legal notices to Glaucon must be sent in writing to: Glaucon LLC, 605 West 9th Street, Suite 1015, Austin, Texas 78701, USA, with a copy to legal@glaucon.ai. Glaucon may provide notices to you via the email address on your account or through the service; notices are deemed given when sent.
Miscellaneous
These Terms, together with the Privacy Policy, constitute the entire agreement between you and Glaucon regarding the service. If any provision is held unenforceable, it will be modified to the minimum extent necessary and the remainder will remain in effect. Glaucon's failure to enforce a provision is not a waiver. You may not assign these Terms without Glaucon's prior written consent; Glaucon may assign them in connection with a merger, acquisition, or sale of assets. Nothing in these Terms creates any agency, partnership, or joint venture. Sections that by their nature should survive termination (including ownership, disclaimers, limitation of liability, indemnification, and dispute resolution) survive.
Changes to these terms
Glaucon may modify these Terms from time to time. When material changes are made, Glaucon may update the effective date and provide additional notice where required by law.
Continued use of the service after updated Terms become effective constitutes acceptance of the updated Terms, except where applicable law requires a different form of consent.
Contact
Glaucon LLC
605 West 9th Street, Suite 1015
Austin, Texas 78701, USA
Legal: legal@glaucon.ai · Privacy: privacy@glaucon.ai · Abuse: reportabuse@glaucon.ai






