Security
How GLODA handles your data
A plain statement of what GLODA stores, where it runs, and what it does — and does not — do with your searches. We state only what we can stand behind. For how to verify a solicitation and report a suspicious notice, see Trust & Verification; the full data-practices detail is in the privacy policy.
What we store
Two kinds of data. The market data GLODA indexes — the public notice text a source publishes, its structured fields, the retrieval timestamp and a content hash — is described field by field on the methodology page.
Your account data is what you give us or create in the product: your email and plan, your saved views, alerts and bookmarks, and the activity needed to run the service. Product analytics is retained for up to 12 months and then deleted; billing records are kept where law requires. The full retention schedule is in the privacy policy.
No secondary use
Your searches, saved views and alerts are yours. GLODA does not sell them, and does not use them to train machine-learning models. They exist to run the service you pay for — nothing is quietly repurposed.
AI model provider
Where GLODA uses a language model — to extract fields from thin notice text, and to compile cited answers — it calls Anthropic’s API using Claude Haiku 4.5. Under Anthropic’s commercial terms, inputs and outputs sent to the API are not used to train Anthropic’s models, and the relationship is covered by Anthropic’s Data Processing Addendum.
Model output is always labelled as such and is held to the quoting rule on the methodology page: an extracted field is kept only when its quote is found word for word in the source notice. The model may not add facts beyond the notice.
Hosting & residency
GLODA runs on a dedicated virtual private server hosted by Hostinger, with the application, its MySQL database and its backups on infrastructure GLODA operates. The deployment region follows the server’s configuration. GLODA does not run on, and does not replicate your account data to, third-party analytics warehouses.
Encryption & access
All traffic to gloda.org is served over HTTPS (TLS); the public site and the application are not reachable over plain HTTP.
Database credentials and service secrets live in a server environment file readable only by the service account — never in the codebase or in client-side JavaScript. Access to the database and its backups is restricted to the operator.
Account deletion
You can delete your account from your account settings. Deletion removes your profile and account data on the schedule set out in the privacy policy; audit and billing records that law requires us to keep are retained for no longer than necessary and then removed.
Answers never guess
GLODA’s answer endpoint returns a cited answer or it returns unsupported. It does not fabricate a response when the index does not support one. A confident wrong answer on a terminal is worse than no answer, so the product is built to say so.