Privacy Policy
Protecting your data with transparency and care
Introduction
Glass Lane Pty Ltd (ABN 67 683 444 948, ACN 683 444 948) ("we," "our," or "us") operates the Mirror Ai blockchain research and regulatory intelligence platform ("Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy and applicable privacy legislation, including:
- Australia: Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs)
- European Union / European Economic Area: General Data Protection Regulation (GDPR) — if you are located in the EEA
- United Kingdom: UK GDPR and Data Protection Act 2018 — if you are located in the UK
Our Service is an informational research platform. It is not a financial service and we do not use your personal information for financial profiling, credit assessment, or investment recommendation purposes.
Information We Collect
2.1 Personal Information You Provide
- Account information (email address, username)
- Authentication tokens and session data
- Communication preferences
- Feedback and correspondence you send to us
2.2 Usage Information Collected Automatically
- Chat conversations, research queries, and analysis requests
- Platform interaction data (pages viewed, features used)
- Technical information (IP address, browser type, operating system, device information)
- Performance and analytics data
2.3 Early Access Program Data
As Mirror Ai is in early access, we collect additional data including:
- All user interactions for product improvement
- Feedback and error reports
- Feature usage patterns and adoption metrics
We do not collect:
- Financial account or payment card information (processed by our third-party payment processor)
- Government identifiers (passport, driver licence, tax file numbers)
- Biometric data
- Sensitive information (health, religion, political affiliation)
How We Use Your Information
We use the collected information for:
- Providing and maintaining our Service
- Improving our AI models and platform functionality through anonymized data analysis
- Training and enhancing our AI algorithms (using anonymized conversation data)
- Personalizing your experience while protecting your identity
- Communicating with you about the Service, updates, and changes
- Ensuring security and preventing fraud or misuse
- Complying with legal obligations
- Product development and early access improvement
We do not use your personal information for:
- Financial profiling, credit assessment, or investment recommendation purposes
- Automated decision-making that produces legal effects concerning you
- Selling your personal information to third parties
AI Training Disclaimer: Your conversation data may be used to improve our AI models. Your personal identity is anonymized through encryption or hashing before any training use. We do not associate training data with identifiable users. If you wish to opt out of AI training use, please contact us at privacy@glasslane.io.
Legal Bases for Processing (EEA and UK Users Only)
If you are located in the European Economic Area or the United Kingdom, we process your personal data under the following legal bases:
| Purpose | Legal Basis (GDPR Article) |
|---|---|
| Providing the Service | Article 6(1)(b) — Contractual necessity |
| AI model improvement | Article 6(1)(f) — Legitimate interest (with anonymization safeguards) |
| Communications about the Service | Article 6(1)(b) — Contractual necessity |
| Security and fraud prevention | Article 6(1)(f) — Legitimate interest |
| Compliance with legal obligations | Article 6(1)(c) — Legal obligation |
| Early access data collection | Article 6(1)(a) — Consent (where required) |
Information Sharing and Disclosure
We may share your information in the following circumstances:
- Service Providers: Third-party vendors who assist in operating our Service, including:
- Cloud infrastructure providers (hosting, storage, compute)
- AI model providers (language model APIs)
- Analytics providers
- Payment processors
- Legal Requirements: When required by law, legal process, or to protect our rights
- Business Transfers: In connection with mergers, acquisitions, or asset sales (with notice to you)
- Consent: When you provide explicit consent
We do not sell your personal information to third parties.
Data Retention
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account information | Until account deletion + 7 years | Legal obligation (record-keeping under AU law) |
| Chat conversations and queries | Anonymized after 30 days; identifiable data deleted on account closure | Product improvement and AI training |
| Anonymized training data | Retained indefinitely for AI model improvement | Cannot be linked to any individual |
| Analytics data | 26 months (Google Analytics standard) | Industry standard retention |
| Early access program data | Retained for duration of early access + 12 months | Product development |
| Feedback and correspondence | 3 years after last contact | Customer relationship management |
| Server and security logs | 90 days, then anonymized or deleted | Security monitoring |
Upon account deletion, we will remove or anonymize all identifiable personal data within 30 business days, except where retention is required by law.
International Data Transfers
Your information may be transferred to and processed in countries other than Australia, including:
| Country | Purpose | Safeguards |
|---|---|---|
| Australia | Primary operations and data storage | Privacy Act 1988 (Cth) |
| United States | AI model processing (via third-party providers) | Standard Contractual Clauses (SCCs) or equivalent |
| European Union | GDPR compliance and data processing | Adequacy decision or SCCs |
When we transfer your personal information internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding corporate rules where applicable
- Verification that the recipient jurisdiction has an adequacy determination from the relevant authority
Data Security
We implement technical and organizational measures to protect your personal information, including:
- Data Encryption: Personal identifiers are encrypted or hashed to protect user privacy. Data in transit is encrypted using TLS 1.2 or higher
- Secure Authentication: JWT-based authentication with secure password hashing
- Access Controls: Role-based access controls, least-privilege principle, and session management
- Network Security: Isolated network environments and secure communication protocols
- Data Anonymization: User identities are anonymized for AI training and improvement purposes
- Incident Response: We maintain a security incident response plan and will notify affected users and relevant authorities as required by law
While we implement industry-standard security measures, no method of transmission over the internet or electronic storage is 100% secure. We continuously monitor and improve our security practices.
Your Rights
Australian Users (Privacy Act 1988)
Under the Privacy Act 1988 (Cth), you have the right to:
- Access your personal information
- Correct inaccurate or incomplete information
- Request deletion of your personal information
- Restrict processing of your information
- Object to processing for direct marketing
- Request data portability (a copy of your data in a structured format)
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC)
EEA and UK Users (GDPR)
If you are located in the EEA or UK, you have the additional rights to:
- Withdraw consent at any time (where processing is based on consent)
- Data portability (Article 20)
- Restrict processing (Article 18)
- Object to processing (Article 21)
- Not be subject to automated decision-making (Article 22)
- Lodge a complaint with your local data protection authority
Data Deletion Process: To request deletion of your data, contact us at privacy@glasslane.io. We will confirm your identity and permanently remove all personal data, including conversation history, within 30 business days. Note that anonymized data used for AI training cannot be retroactively identified or removed — this is a technical limitation of the anonymization process.
Response Timeframe: We will respond to your request within 30 days. If we need more time, we will notify you within that initial period.
Children's Privacy
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you become aware that a child has provided us with personal information, please contact us and we will take steps to delete that information.
Cookies and Analytics
Our Service uses the following types of cookies and similar technologies:
- Essential/Functional Cookies: Required for the Service to function (session management, authentication)
- Analytics Cookies: Used to understand how users interact with the Service (page views, feature usage, error tracking)
- Preference Cookies: Remember your settings and preferences
You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of the Service.
We use the following analytics providers:
- Google Analytics (anonymized IP addresses, data retention 26 months)
- In-platform analytics (server-side, no third-party sharing)
We do not use cookies for advertising, cross-site tracking, or profiling purposes.
Data Protection Officer
Glass Lane Pty Ltd has appointed a Data Protection Officer who can be contacted at dpo@glasslane.io. The DPO is responsible for overseeing our data protection practices and can assist with any questions about this Privacy Policy or your privacy rights.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify users of any material changes by posting the new Privacy Policy on this page and updating the effective date. For significant changes, we may also notify you by email. Your continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.
Contact Information
If you have any questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:
Glass Lane Pty Ltd
Email: privacy@glasslane.io
Data Protection Officer: dpo@glasslane.io
Website: glasslane.io
Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
Phone: 1300 363 992
Email: enquiries@oaic.gov.au
Relevant EEA Supervisory Authority
If you are located in the EEA and wish to lodge a complaint, you may contact your local data protection authority. A list of EEA data protection authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en