Skip to main content

Security

How GLODA handles your data

A plain statement of what GLODA stores, where it runs, and what it does — and does not — do with your searches. We state only what we can stand behind. For how to verify a solicitation and report a suspicious notice, see Trust & Verification; the full data-practices detail is in the privacy policy.

What we store

Two kinds of data. The market data GLODA indexes — the public notice text a source publishes, its structured fields, the retrieval timestamp and a content hash — is described field by field on the methodology page.

Your account data is what you give us or create in the product: your email and plan, your saved views, alerts and bookmarks, and the activity needed to run the service. Product analytics is retained for up to 12 months and then deleted; billing records are kept where law requires. The full retention schedule is in the privacy policy.

No secondary use

Your searches, saved views and alerts are yours. GLODA does not sell them, and does not use them to train machine-learning models. They exist to run the service you pay for — nothing is quietly repurposed.

AI model provider

Where GLODA uses a language model — to extract fields from thin notice text, and to compile cited answers — it calls Anthropic’s API using Claude Haiku 4.5. Under Anthropic’s commercial terms, inputs and outputs sent to the API are not used to train Anthropic’s models, and the relationship is covered by Anthropic’s Data Processing Addendum.

Model output is always labelled as such and is held to the quoting rule on the methodology page: an extracted field is kept only when its quote is found word for word in the source notice. The model may not add facts beyond the notice.

Hosting & residency

GLODA runs on a dedicated virtual private server hosted by Hostinger, with the application, its MySQL database and its backups on infrastructure GLODA operates. The deployment region follows the server’s configuration. GLODA does not run on, and does not replicate your account data to, third-party analytics warehouses.

Encryption & access

All traffic to gloda.org is served over HTTPS (TLS); the public site and the application are not reachable over plain HTTP.

Database credentials and service secrets live in a server environment file readable only by the service account — never in the codebase or in client-side JavaScript. Access to the database and its backups is restricted to the operator.

Account deletion

You can delete your account from your account settings. Deletion removes your profile and account data on the schedule set out in the privacy policy; audit and billing records that law requires us to keep are retained for no longer than necessary and then removed.

Answers never guess

GLODA’s answer endpoint returns a cited answer or it returns unsupported. It does not fabricate a response when the index does not support one. A confident wrong answer on a terminal is worse than no answer, so the product is built to say so.

What we do not claim

GLODA does not hold a SOC 2 or ISO 27001 certification, and this page does not claim one. It describes the practices actually in place today. If a formal attestation is a requirement for your organisation, write to sales@gloda.org and we will tell you honestly where things stand.