Who we are
Glider is operated by Future Version Limited, company number 11739018. We are the controller of personal information processed to operate Glider.
The Station House, 15 Station RoadSt. Ives, Cambs, PE27 5BH, UK
For privacy questions or requests, email support@glider.game.
This notice covers the Glider website and its game features. A save code is a persistent identifier; we do not assume information is anonymous simply because we do not ask for a name.
Your progress
On your device
Glider uses browser storage to remember your coins, unlocked and equipped gliders, designs, personal bests, flight counts, rewards, selected world and settings. It also remembers whether you have completed the touch tutorial. The browser can cache game files and fonts so you can play offline.
When you choose cloud saves
Creating or restoring a cloud save sends your game progress and settings to our save service. We store them with your save code, a server-side PIN hash, creation and update times, a revision number, and information needed to limit incorrect PIN attempts.
Your browser remembers the code and PIN so progress can sync automatically when you return and while you play. The save service receives the PIN to check access; the save record stores a hash rather than the original PIN. We do not require your name, email address or date of birth to create a save.
Keep your code and PIN private. Anyone who has both can access and change that save. Please do not include your PIN in an email to us.
Previous coin purchases
Glider is free to play and new coin-pack sales are paused. Existing purchased balances and unlocks stay with their cloud save. We retain previous pack prices, payment references, transaction times, refunds and dispute status for accounting and payment support. Your browser may cache the remaining purchased balance.
Stripe processed previous payments and may retain payment details, name, email, billing address and connection information. We can access transaction and customer details through Stripe to provide receipts, resolve payment issues and meet accounting obligations. We also keep the name and email supplied at checkout with completed purchases in our private payment records, so we can find transactions and provide support. Our game does not receive or store your full card number or security code. We send Stripe an order reference and the selected pack, never your cloud-save code or PIN.
Analytics & connections
The homepage shows the total distance explored by all players, including guests. During a flight, the game sends a random identifier for that flight, its start time and the metres travelled to Supabase. These reports do not contain a save code, PIN or player identifier. Your device keeps the latest total and a temporary queue of unsent reports so it can retry after a lost connection without counting twice.
We also use distance records already held in cloud saves to establish the shared total's historical starting point. Each save contributes its recorded distances once; restoring it on another device does not count those records again. Only the combined total is shown publicly.
When a returning guest has older progress that has not already encountered distance tracking or cloud sync, the game can add the combined distance of their saved personal bests once. It sends only that distance and a random import receipt, not their full game save. The browser remembers the decision and receipt so later visits, new records and connection retries do not repeat the import.
We use Umami, served through stats.glider.game, to understand visits and how game features are used. The game sends events such as world selection, starting and ending a flight, ring collection, settings changes, glider choices and use of cloud saves. Events can include the world, glider, control type and gameplay statistics.
The installed iOS and Android apps also send Umami app-launch and gameplay events to this endpoint. App reports use fixed Android/iOS page labels without query strings or referrers. They do not include your save code, PIN, name, email or full progress snapshot. The app supplies a random identifier for each app session instead of using IP/browser properties for visitor identification. It keeps that identifier and its analytics session token only in memory and drops offline analytics rather than storing them for later. Vercel Web Analytics and Speed Insights remain limited to the website.
Our game events do not include your save code or PIN. Umami may also process page and referrer addresses, browser and device information, language, approximate location and session identifiers. Its standard tracker does not use cookies; that does not mean that no information is processed.
We also use Vercel Web Analytics to measure visits and page views, and Vercel Speed Insights to understand loading speed, responsiveness and layout stability. These services process page addresses, browser and device details, approximate location, and performance measurements; Web Analytics also processes referrers and visit timestamps. We remove query strings and fragments from the page addresses we send, and do not send save codes, PINs or progress snapshots to either service.
Vercel Web Analytics uses a request-derived identifier for aggregated visitor statistics, without third-party cookies, and discards visitor sessions after 24 hours. Speed Insights measurements are not associated with an individual visitor. See Vercel's Web Analytics privacy information and Speed Insights privacy information.
The website loads fonts from Google Fonts. Requests to the website, font service, analytics endpoint and Supabase services disclose connection information, such as an IP address and browser details, to the services receiving them. Hosting and security services may keep technical request logs.
Why we use information
We use progress and settings to run the game, remember your choices and provide the cloud synchronisation you request. Technical information helps us deliver the website, investigate faults and prevent misuse. Analytics helps us understand which features work well. If you contact us, we use your email address and the information you send to respond.
The UK GDPR basis for operating and securing the service, responding to ordinary support enquiries and improving the game is our legitimate interests in those activities, subject to a balancing assessment. Handling a legal obligation, including applicable data-rights requests, may instead rely on that obligation.
Processing a purchase and delivering its coins is necessary to perform the purchase contract you request. Accounting records are kept to meet legal obligations. Payment security and investigating disputed transactions also serve our legitimate interests in protecting players and the service.
Our service providers
- SupabaseHosts cloud saves, purchased-coin records and the shared flight-distance total, configured in Dublin, Ireland. Data processing information.
- VercelHosts and delivers the website and payment endpoints, and provides Web Analytics and Speed Insights. Payment functions are configured in Dublin, Ireland. Data processing information.
- StripeHosts optional coin checkout, processes payments and handles payment security, refunds and disputes. Stripe's privacy information.
- UmamiProvides the analytics software used by our analytics endpoint at stats.glider.game.
- Google FontsDelivers the website's typeface to your browser. Google's privacy information.
Our communications providers also handle messages you send us. We may need to disclose relevant information to comply with a legal requirement or protect the service.
A database in Ireland does not mean every service processes information only in Ireland. Suppliers may use international infrastructure or support teams. Their published processing terms describe transfer mechanisms such as standard contractual clauses and the UK Addendum.
Keeping & deleting data
On your device: progress and remembered cloud credentials remain until you clear the site's storage, the browser removes it, or the game replaces that information. Cached game files can also be removed through your browser's site-data controls.
Cloud saves: there is currently no automatic expiry. Starting a new game creates a new save and keeps the previous cloud save available through its old code and PIN. Clearing browser storage does not delete the copy held by the cloud-save service.
Purchases: purchased balances and unlock records remain linked to their original save, including after starting a new game. Purchase records currently have no automatic expiry. Records needed for company accounting must normally be retained for six years from the end of the relevant financial year, and sometimes longer. We may also need records to maintain an active coin balance or resolve a dispute. A deletion request does not remove records we must retain by law.
Use Delete cloud save in the save dialog, or open the deletion flow here. Restore the save with its code and PIN if necessary, then confirm deletion. This permanently removes the cloud profile, its PIN hash, progress, designs, unlocks and remaining coin wallet, and resets this device. Other devices lose access to that cloud save; copies already stored on those devices may remain locally. Deletion does not automatically refund payments. Required financial records remain as described above. For help, contact support@glider.game without sending your PIN.
A deletion receipt records a random request identifier, a hash of the save code and the deletion time, so a lost response can be retried safely. It contains no PIN or saved progress. Receipts become eligible for removal after 30 days and are removed in bounded batches during later deletion requests.
Our public distance endpoint processes the caller’s IP address into a keyed hash to enforce request limits. Its rate-limit table stores that hash, a time window and a request count, not the raw IP address. Old counters become eligible for removal after ten minutes and are removed during later requests. This does not change the aggregate distance or identify individual flights.
Shared flight distance: reports can be retried for up to 30 days. Individual flight receipts become eligible for removal after 31 days and are cleared in batches as new reports arrive. We retain the combined total and hourly distance totals for activity reporting; these totals contain no player identifiers. On your device, successfully sent reports are removed from the queue; expired reports are discarded when the game next checks it. The queue is limited to 512 flights, and the cached total remains until replaced or your site's storage is cleared.
Receipts for one-time imports of older guest records remain while we retain the shared statistic, so an old retry cannot count twice. These contain a random receipt, the imported distance and the import time. Your browser keeps its import decision and receipt until its site storage is cleared.
Your choices & rights
You can play using local progress without creating a cloud save. Browser storage controls let you remove local game data. If you reopen the game after clearing site data, you will need your code and PIN to restore a cloud save.
Depending on the circumstances and applicable law, you may request access to your personal information, correction, deletion, restriction or portability.
You can object to processing based on legitimate interests. Contact support@glider.game to exercise your rights or raise a concern. We may need to verify your request, and some rights are subject to exceptions. You do not have to create a named account just to play.
You can also complain to the UK's Information Commissioner's Office, or another supervisory authority where you have that right.
Children & parents
The game does not ask players to enter their age, real name or email address. Children, parents and carers can contact us with privacy questions or requests about a child's information. Avoid sending unnecessary personal details in a support message.
Changes to this notice
We will update this page when how we handle information changes, and bring material changes to players' attention where required. The date at the top shows when this notice was last updated.