Glass Bead
Privacy policy
Effective August 29, 2026
Glass Bead is operated by Andrey Gusev, who is the controller of the information described here. Privacy questions may be sent through the operator's public contact profile.
Your public identity is a pen-name
Your email address and Google or password credential are handled by Firebase Authentication, are not stored in Glass Bead application records, and are not shown to other players. The identity Glass Bead publishes is the permanent pen-name and avatar you choose. Do not use your legal name if you do not want it to become part of your public identity.
Information the service handles
- Account data: Firebase handles a user identifier, verified email address, and sign-in provider. Glass Bead application records keep the Firebase user identifier, account status, permanent pen-name, and selected avatar, but not the email address or provider credential.
- Dialogue data: titles, openings, moves, relations, citations, source metadata, admitted media, conclusions, visibility, and AI provenance. Public dialogue data is discoverable; private and unlisted data remains subject to its read boundary.
- Private account data: bookmarks, private drafts, invitations, and the played-or-visited history shown only to the signed-in account. Functional preferences and draft recovery data may also be kept locally in your browser.
- Safety and operations data: App Check and reCAPTCHA abuse signals, rate-limit keys, request and error metadata, and content-free product-health events. Glass Bead does not persist raw IP addresses in its application database.
- Private feedback: when you choose Send feedback, Glass Bead stores the name, email address, and plain-text comment you provide, plus an optional account link derived by the server when you are signed in. The feedback remains in private storage for the maintainer to read and respond to. Daily email digest delivery is currently disabled, so feedback submissions are not currently sent through Resend.
- AI-assisted content: when you deliberately play with an AI voice, ask Why this bead?, or use model-backed Librarian or composer help, Glass Bead sends the bounded request and only the context needed for that feature to Google's Gemini service. Deterministic local and structured-resolver Librarian paths do not call Gemini. Human-created content is not used by Glass Bead for model training without explicit consent.
- Safety moderation: bounded user prompts, authored text, and model-generated text covered by the service's safety gates are sent to Google Model Armor. Its inline findings are used to allow or block the operation; Glass Bead does not include an account identifier in the content sent for moderation.
- Openverse archive lookup: when you search for archive media, Glass Bead sends the bounded search terms to Openverse from its backend. Selecting a result sends its opaque Openverse identifier so the backend can retrieve source, rights, attribution, and media evidence. Provider requests do not include your Glass Bead account identifier. Verified provenance and an admitted media copy may be retained in the archive catalog and in a dialogue that uses the work.
- Chemistry lookup data: when the Librarian cannot resolve a molecule locally, the bounded molecule name you entered is sent to the public NIH PubChem service. Glass Bead sends no account identifier, does not cache the result, and does not retain the PubChem request or response text.
The witness cookie
Accountless reading uses one strictly functional cookie so opening the same dialogue repeatedly does not inflate its witness count.
| Cookie | Purpose | Protection | Lifetime |
|---|---|---|---|
gb_installation | Creates a game-scoped HMAC used only to deduplicate witnesses. | Signed, HttpOnly, SameSite=Lax, and Secure in production; no raw identifier or IP is stored. | 12 months |
The derived witness value cannot correlate an accountless reader across games. Deleting the cookie causes a future visit to establish a new installation value.
Service providers used
Glass Bead uses these processors to operate the service:
- Firebase Authentication for account credentials and email verification;
- Cloud Firestore for dialogue and application records;
- Firebase Hosting, Cloud Run, and Cloud Storage for delivery and admitted media;
- reCAPTCHA Enterprise and Firebase App Check for abuse prevention;
- Gemini for AI-player turns, requested bead explanations, and model-backed Librarian or composer help;
- Model Armor for safety screening of covered user and model text;
- Openverse for backend-mediated archive media search and import;
- NIH PubChem for structured molecule-name and identity lookup; and
- Cloud Logging, Monitoring, Pub/Sub, and BigQuery for sanitized operations and content-free event measurements.
These providers handle information under their own applicable service terms and privacy policies.
Retention
| Record | Current retention |
|---|---|
| Notification items | 90 days |
| Invitation tokens | Stored only as hashes; invalid after 14 days |
| Rate-limit windows | One spare window after the active window closes |
| Witness deduplication records | For the life of the dialogue |
| Completed outbox delivery records | 90 days |
| Private feedback submissions | Up to 12 months in Firestore, then TTL removes them. The disabled daily digest does not currently create maintainer-mailbox or Resend copies. |
| Archive-provider operation handles | 90 days after search, repair, or terminal failure. Successful import receipts remain while needed for deduplication and your data export. |
| Dialogue and profile records | Retained while needed to operate the account. Self-service deletion erases an AI dialogue in full and removes a departing human's identity and authored content from a two-human dialogue; a legal or security hold can delay that work. |
| Recovery copies and restricted analytics | Point-in-time recovery and weekly backups may retain pre-deletion bytes for their configured windows, including the 14-week backup schedule. A restore replays the deletion ledger before traffic. Content-free raw analytics partitions expire after 400 days. |
Your choices
You may browse public dialogues without an account; manage your email or password; export or permanently delete your account from account settings; and delete a dialogue from its participant controls. A two-human dialogue requires both current participants to consent to whole-dialogue deletion. Account deletion instead removes the departing player's identity and authored content while preserving a private, non-republishable copy for the other participant. Recovery copies, logs, external processors, legal holds, and material copied by others can outlive active-record deletion for the bounded reasons described above. A permanent pen-name cannot otherwise be casually renamed without breaking attribution; see the Terms.
Children and changes
Glass Bead is not directed to children under 13, or under 16 where European law requires that age for independent consent. Material changes to this policy will be reflected on this page with a new effective date.