Privacy Policy
Effective 21 September 2026 · Applies to the Gleam desktop app for Windows and to this website.
In short: Gleam runs on your computer. We run no servers, have no accounts, and collect no data about you, in the app or on this site. When you use a feature that needs an AI or voice service, your request goes directly from your computer to the service you connected, under your own account with them.
1. Who we are
Gleam is made by Brian Mwai in Nairobi, Kenya ("we", "us"). You can reach us at mwaibryn@gmail.com.
2. What we collect
Nothing. Gleam has no sign-up and no account. The app contains no analytics, crash reporting, advertising or tracking code, and does not send usage data to us. This website sets no cookies and loads no analytics, fonts or scripts from anyone else.
3. What stays on your computer
Gleam keeps its data in your Windows user folder, at %APPDATA%\Gleam:
- Your rooms: experts, groups, messages, canvas notes, and what each expert remembers and knows (their memory and knowledge graph).
- Your profile: the name, picture and short description you give Gleam. Your name and description are shared with your experts' brains so they know who they are talking to; your picture is not.
- Your API keys: sealed with Windows DPAPI, so only your Windows user account can unseal them.
- A journal of actions: a log of what Gleam did on your computer (for example "opened notepad", "clicked at 400, 220"), so you can check it.
- Routines, microphone choice and voice clips Gleam has made for instant replies.
You can read, change or delete any of it. Uninstalling Gleam and deleting that folder removes everything.
4. What goes to the services you connect
Gleam works with AI and voice services that you choose and connect with your own keys or sign-in. When you use a feature that needs one, Gleam sends what that feature needs directly from your computer to that service. We never see it.
- Anthropic (Claude API, or Claude Code on your plan): what you ask, the room's recent conversation, your experts' personas, memory, skills and relevant knowledge, and a screenshot of your screen when Gleam needs to look at it or act on it.
- OpenAI, NVIDIA, Groq: the same kinds of content, for experts you set to think with those services.
- Groq, OpenAI, NVIDIA or Fish Audio for speech-to-text: the audio of what you say while the microphone is open.
- Fish Audio for text-to-speech: the words Gleam and your experts speak.
Each service handles that data under its own terms and privacy policy, which you agreed to when you created your account with them: Anthropic, OpenAI, NVIDIA, Groq, Fish Audio. Please read them, because you pay those services directly and they decide how long they keep your requests.
Optional features that reach other services
- Casting a character looks up shows and characters on TVMaze and the Rick and Morty API, and generated avatars on DiceBear, only when you search.
- Pictures and GIFs an expert brings into a chat are downloaded from the link it gives, for example Giphy.
- Adding a skill from a link downloads that file, for example from GitHub.
- Links and websites Gleam opens on your screen are opened in your own browser, like any link you click.
5. Your screen, microphone and keyboard
- Screen: Gleam takes a screenshot only for a request you started, to see what is there, and sends it to your brain service. It is not saved to disk, except when an expert shows a screenshot in a chat message, where it is kept with that message in your rooms. Gleam's own pointers are hidden from these screenshots.
- Microphone: it opens only while you hold Right Ctrl, or while you have turned on Always-on in a room. Audio is sent to your speech-to-text service and not kept. If you use a speech model on your own computer, the temporary audio file is deleted straight after.
- Keyboard and mouse: Gleam acts only on requests you start. Anything that sends, posts, deletes, buys, installs or deploys waits for you to press Allow. Teach by showing watches clicks and the names of shortcut keys; it counts typed characters but never records which ones.
6. This website
This site is hosted on GitHub Pages. GitHub may record technical information such as IP addresses when you visit, under the GitHub Privacy Statement. We do not receive those records. Downloads of the installer are served by GitHub in the same way.
7. Children
Gleam is not meant for children under 13, and the AI services it connects to set their own minimum ages.
8. Your rights
Because we hold no personal data about you, there is nothing for us to access, correct or delete on our side. Your data is on your computer, under your control. For data held by the services you connect, contact them directly. If you are in Kenya, you have rights under the Data Protection Act, 2019, and you can contact the Office of the Data Protection Commissioner; wherever you are, you can contact us with any question.
9. Security
Keys are sealed with Windows DPAPI and never written in plain text. The app has no network service listening for connections. If you find a security problem, please tell us privately; see Security.
10. Changes
If this policy changes, we will update it on this page and change the effective date above. If a change affects what leaves your computer, we will also say so in the app's release notes.
11. Contact
mwaibryn@gmail.com · Brian Mwai, Nairobi, Kenya