Loading document
Effective date: 6th August 2026
Entity: Glimmers Inc.
At Glimmers Inc. ("Glimmers", "we", "our", or "us"), protecting children's privacy and personal information is a core responsibility.
This Privacy Policy explains how we collect, use, store, share, protect, and process personal data when parents, guardians, children, schools, educators, or other authorised users access and use the Glimmers platform, including our mobile applications, websites, educational programs, AI-powered features, events, Olympiads, parent dashboards, and related services, collectively referred to as the "Services".
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. This acknowledgement does not replace consent where consent is required by law.
Before Glimmers processes a child's personal data, verifiable consent of the child's parent or lawful guardian will be obtained, unless a specific legal exemption applies.
Glimmers is built on the following privacy principles:
The information collected depends on the Services and features used. At the time of collection, Glimmers will provide a clear notice describing the specific personal data requested and the purpose for which it will be processed.
We may collect:
Where age or identity verification is required, Glimmers will seek only the information reasonably necessary to complete the verification and meet legal requirements.
Depending on the Services used, we may collect:
We seek to minimise the collection of personal data from children and avoid collecting precise identity details where a nickname, age range, or assigned identifier is sufficient.
We may collect content created, uploaded, recorded, or shared within the platform, including:
Private journal content and private reflections are not automatically shared with other users, schools, or educational partners.
When users interact with Lumiri or other AI-powered features, we may process:
AI interaction data may be reviewed for safety, quality assurance, support, and product testing. Personal AI interaction data will not be used to train public or general-purpose AI models unless Glimmers gives a separate notice and obtains any consent required by law.
Glimmers does not use AI interaction data to create advertising profiles or to assign medical, psychological, or personality labels to a child.
We may collect information relating to:
When users access the Glimmers app, limited technical and security information may be processed to operate accounts, maintain secure sessions, deliver notifications, and protect the Services. This may include:
The Glimmers native mobile app currently does not collect:
Glimmers may introduce crash reporting, error diagnostics, or limited product analytics tools in the near future to improve stability, security, and service quality. Where this happens, this Privacy Policy will be updated, the relevant categories of personal data and the purposes for processing them will be itemised, and any consent required by law will be obtained before the new processing begins.
Glimmers does not currently use analytics SDKs. Glimmers does not use advertising tracking SDKs or other technologies to track children across unrelated apps, websites, or services.
For subscriptions, events, or programs, payment processing may involve:
Payment card, bank, or UPI credentials are generally processed by authorised third-party payment providers and are not stored by Glimmers unless necessary, legally permitted, and protected by appropriate safeguards.
Glimmers processes personal data only for specific purposes communicated to the user. These purposes may include:
Under the Digital Personal Data Protection Act, 2023, Glimmers processes personal data only for a lawful purpose, based on valid consent or another use specifically permitted by law.
Before or at the time consent is requested, Glimmers will provide a notice that:
Where consent is the basis of processing, consent will be free, specific, informed, unconditional, unambiguous, and given through a clear affirmative action. Consent will be limited to the personal data necessary for the stated purpose.
Consent requests and notices may be made available in English or another language listed in the Eighth Schedule to the Constitution of India, where supported or required.
Parents and authorised users may withdraw consent at any time through the parent dashboard, privacy settings, a Consent Manager where supported, or the contact methods in Section 17. Withdrawing consent will be as easy as giving it. Withdrawal will not affect processing that was lawful before withdrawal.
After withdrawal, Glimmers and its Data Processors will stop the relevant processing within a reasonable period unless continued processing is required or authorised by law. Some Services may no longer be available where the personal data is necessary to provide them.
Where consent was obtained before the relevant DPDP provisions became applicable, Glimmers will provide the required notice and will continue processing only in accordance with applicable law and the user's consent choices.
Glimmers is designed for children, and a child means any individual under eighteen years of age.
Before processing a child's personal data, Glimmers will obtain verifiable consent from the child's parent or lawful guardian, unless a specific exemption under applicable law clearly applies.
To confirm that the person giving consent is an identifiable adult, Glimmers may use:
Glimmers will use due diligence during verification and will limit the information collected to what is necessary for this purpose.
Glimmers will not knowingly:
Parents and lawful guardians may review information associated with the child account, request correction or erasure, manage consent, and close the account, subject to applicable law, child-safety considerations, and the design of the relevant Service.
Where a child participates through a school or educational partner, the arrangement with that institution does not by itself replace any parental consent required from Glimmers. The roles of Glimmers and the institution will be explained in the relevant program notice or agreement.
Children are encouraged not to share passwords, home addresses, phone numbers, school schedules, financial details, or other unnecessary identifying information in journals, messages, images, audio, videos, or community features.
Glimmers uses AI-powered tools, including Lumiri, to support age-appropriate reflection, creativity, learning, and safety.
AI systems may:
AI features process the information submitted for the interaction and only the limited context needed to provide the feature. Glimmers does not use AI to make decisions that produce legal or similarly significant effects for a child.
Glimmers may use AI interaction data, including questions, prompts, responses, and other content submitted to Lumiri, to improve and train Glimmers' Lumiri AI system. This processing may help Lumiri improve its ability to provide safe, accurate, age-appropriate, and helpful responses to children.
Where AI interaction data is used for model training or improvement, Glimmers will apply appropriate safeguards to protect children's personal data and will use the data only for the stated purposes described in this Privacy Policy.
Glimmers uses AI to identify patterns in your child's voluntary reflections, wellbeing activities and learning interactions to generate age-appropriate wellbeing insights and summaries for parents. These insights are designed to support children's emotional development and are not used for advertising, commercial profiling or automated decisions that produce legal or similarly significant effects.
Glimmers does not use these insights for advertising, commercial profiling or selling personal data.
AI interactions may be reviewed by authorised personnel where necessary to:
Any human review is subject to confidentiality, access controls, and role-based permissions.
AI systems do not provide therapy, diagnosis, medical treatment, crisis intervention, or emergency assistance. Parents and users should contact qualified professionals or emergency services when immediate help is required.
To help protect users, Glimmers may use automated content-screening tools, AI-assisted moderation, trained human reviewers, and community reports.
Content may be reviewed where:
Safety review is limited to the specific content, report, account event, or technical record needed for the stated safety purpose. Glimmers does not continuously track children or create behavioural profiles from moderation data.
Where reasonably necessary and proportionate, parents may be notified about significant safety concerns involving their child. In an emergency involving an immediate threat to life or health, Glimmers may share necessary information with the registered parent, an authorised safeguarding contact, or emergency services where permitted by law.
Glimmers shares personal data only where necessary for a stated purpose, permitted by law, and subject to appropriate controls.
We may use service providers to support:
Service providers may process personal data only under a valid written contract, according to Glimmers' instructions, for the authorised purpose, and with appropriate security safeguards. Glimmers remains responsible for processing carried out on its behalf as required by law.
A verified parent or lawful guardian may receive information relating to account administration, consent status, participation summaries, safety alerts, and Parent Dashboard insights. The relevant feature will explain which information is visible to the parent.
We may disclose personal data where reasonably necessary to comply with applicable law, a lawful court or regulatory order, child protection obligations, a medical or safety emergency, the investigation of an offence or cyber incident, or the establishment, exercise, or defence of a legal claim.
Where permitted, Glimmers will assess the scope and validity of a request and disclose only the information reasonably necessary for the lawful purpose.
Glimmers does not:
Service notices, parent account communications, and information about a program requested by a parent are not treated as targeted advertising to a child.
Glimmers retains personal data only for as long as it is necessary to fulfil the specified purpose for which it was collected, provide the Services, maintain the safety and security of the platform, comply with applicable laws, resolve disputes, enforce legal rights, and demonstrate compliance with applicable legal obligations.
As a general rule, personal data associated with a Parent Account or a Child Profile is retained for as long as that account or profile remains active, so that the Services can continue to be provided and a child's progress, work and settings are not lost.
When a Parent Account or a Child Profile is deleted, whether at the request of the parent or lawful guardian or by Glimmers, a grace period of thirty (30) days applies before permanent deletion.
During the thirty day grace period:
At the end of the thirty day grace period, the personal data associated with the deleted Parent Account or Child Profile is permanently deleted or irreversibly anonymized, unless continued retention is required or authorised by applicable law. Deletion at the end of the grace period does not require any further action by the parent or lawful guardian.
Where the law requires Glimmers to retain a specific record for longer, such as a consent record, a payment or tax record, a safety or moderation record, or a processing log, only that record is retained, only for the period the law requires, and only for that legal purpose. Everything else is deleted at the end of the grace period.
Deletion of a Parent Account also deletes every Child Profile linked to it, subject to the same thirty day grace period. A Child Profile may also be deleted on its own without closing the Parent Account.
Glimmers will securely erase or irreversibly anonymize personal data when:
Where Glimmers engages a Data Processor to process personal data on its behalf, Glimmers will require the Data Processor to securely erase the relevant personal data when Glimmers is legally required to erase such data, unless continued retention is required by applicable law.
Retention periods vary depending on the category of personal data and the purpose for which it is processed. Glimmers maintains a separate Data Retention and Deletion Policy that specifies retention periods for different categories of data, including but not limited to:
The applicable retention period for each category of personal data is determined based on the specified purpose for processing, operational necessity, legal obligations, security requirements, and applicable regulatory requirements.
Where required by the Digital Personal Data Protection Rules, 2025 or any other applicable law, Glimmers will retain applicable processing records, personal data, associated traffic data, and security or processing logs for the minimum period prescribed by law, including retaining certain records for at least one year from the date of processing where applicable. Such records will be securely erased after the applicable retention period unless a longer period of retention is required or authorised by law.
Child-generated content, including journals, reflections, AI conversations, artwork, uploaded media, mood check-ins, learning activities, and other content voluntarily created within the Services, will be retained only for as long as necessary to provide the Services, support the child's learning journey, enable parent-approved features, maintain platform safety, or until deleted by the parent or in accordance with this Privacy Policy and the Data Retention and Deletion Policy, unless continued retention is required or authorised by law.
Where personal data is no longer required for the purpose for which it was collected, Glimmers may irreversibly anonymize the information so that it can no longer identify any individual. Anonymized information is not personal data and may be retained for legitimate research, statistical analysis, service improvement, safety enhancement, product development, and performance analytics.
After the thirty day grace period has ended and personal data has been permanently deleted, it may remain in encrypted backup systems for a limited period solely for disaster recovery, business continuity, and security purposes. During this period, such information will not be used for normal business operations and will be securely overwritten or permanently deleted in accordance with Glimmers' backup retention schedule.
Glimmers periodically reviews the personal data it holds to ensure that information is not retained longer than necessary and that all retention and deletion practices remain consistent with applicable legal and regulatory requirements.
Glimmers implements appropriate technical and organisational measures designed to protect personal data against unauthorised processing, access, disclosure, alteration, destruction, loss, or loss of availability.
All personal data stored by Glimmers is encrypted at rest.
These measures may include:
No system can guarantee absolute security. Users are responsible for protecting account credentials and informing Glimmers promptly about suspected unauthorised access.
If Glimmers becomes aware of a personal data breach, it will investigate, contain, mitigate, and document the incident.
Where required by law, Glimmers will notify each affected Data Principal without delay through the user account or a registered communication channel. The notice will explain, to the best of Glimmers' knowledge:
Where required, Glimmers will notify the Data Protection Board of India without delay and provide the detailed information required by law within seventy-two hours of becoming aware of the breach, unless the Board permits a longer period.
Subject to applicable law, parents, lawful guardians, and authorised users may exercise the following rights:
For a child account, the verified parent or lawful guardian may exercise applicable rights on behalf of the child.
To protect users, Glimmers may request reasonable information to verify the identity and authority of the person making a request. Requests should use accurate information and must not impersonate another person or be false or frivolous.
Requests may be submitted through:
Glimmers will respond within the period published in its grievance process and, once the relevant DPDP Rules apply, within a reasonable period not exceeding ninety days. Glimmers aims to resolve ordinary privacy requests and grievances within thirty days, subject to verification and legal complexity.
A Data Principal should first use Glimmers' grievance redressal process before approaching the Data Protection Board of India. If the grievance is not resolved, the Data Principal may submit a complaint through the Board's official mechanism when available.
Personal data may be processed or stored in India or in another country where Glimmers or an authorised service provider operates. Hosting and processing locations may include India and other approved jurisdictions in which Glimmers' cloud, AI, payment, and communication providers operate, including data centre and AI service regions located in the United States and other permitted jurisdictions.
Where personal data is transferred outside India, Glimmers will:
Current information about principal hosting locations, processing regions, and material service providers is disclosed through the Glimmers Trust and Safety Center, and is also available on request, subject to security and confidentiality considerations.
The Services may contain links to or integrations with third-party services. Glimmers is not responsible for the privacy practices of an independent third party.
Before a third-party service is integrated into a child-facing feature, Glimmers will assess its role, data practices, and security requirements. Users should review the third party's privacy information before using an external service.
Glimmers may update this Privacy Policy when the Services, processing activities, service providers, or legal requirements change.
Where a change introduces a new purpose, a new category of personal data, a new material recipient, or another change that requires consent, Glimmers will provide a new notice and obtain fresh consent before the new processing begins.
Where material changes occur, parents or authorised users may be notified by email, in-app notice, account notification, or another registered communication channel. The current version will be available through the Glimmers Trust and Safety Center and will state the date of the latest update.
By using the Services or providing parental consent, you acknowledge that you have read and understood this Privacy Policy. Consent, where required, will be requested separately through a clear affirmative action.