Privacy Policy — GLM 5 | How We Collect, Use & Protect Your Data

Learn how GLM 5 at glm5.app collects, uses, stores, and protects your personal data, including account details, AI content, attribution analytics, session replay, payments, cookies, and your privacy choices.
Oct 24, 2025

Introduction

Last updated: 26 August 2026

Welcome to GLM 5 at glm5.app. We provide AI chat, reasoning, coding assistance, image generation, video creation, music generation, and related API services (collectively, the "Service"). This Privacy Policy explains what data we collect, why we use it, who receives it, how long we keep it, and the choices available to you.

This Policy is informational. Where applicable law requires consent for non-essential analytics, advertising, or session replay, we ask for that consent separately and respect your choice.

Information We Collect and Why

We collect data needed to provide, secure, support, and responsibly improve the Service.

  1. Account and contact information

    • What: Name, email address, authentication provider, account identifier, profile settings, account status, and support contact details.
    • Why: To create and secure your account, authenticate you, provide support, prevent abuse, and send important service notices.
  2. Prompts, uploads, settings, and outputs

    • What: Text prompts, chat messages, files or reference media you upload, generation settings, model selection, job identifiers, timestamps, status, and generated outputs.
    • Why: To perform the requested AI task, deliver and retain your history, restore interrupted work, troubleshoot failures, and improve Service quality where permitted.
    • Analytics boundary: We do not intentionally copy prompt text, chat or generated content, uploaded-file contents, filenames, private media URLs, or raw model responses into Google Analytics, Microsoft Clarity user properties, or our behavioral analytics event properties.
  3. Service usage, device, and security data

    • What: Pages and features used, clicks on identified controls, generator type and model, job state, credit or quota state, timestamps, session duration, browser, operating system, device category, language, coarse country, and diagnostic or security logs.
    • Network data: Servers may process an IP address to deliver and secure the Service. Behavioral analytics uses a shortened or anonymized address, or a one-way hash, rather than storing the full IP address as an analytics dimension.
    • Why: To operate the Service, understand product friction, monitor performance, enforce limits, detect fraud or abuse, and investigate errors.
  4. Traffic source and attribution data

    • What: First- and last-touch source, UTM source/medium/campaign/term/content, referring origin and path, filtered landing-page path, entry point, campaign/ad-group/creative dimensions, and advertising click identifiers such as gclid, gbraid, wbraid, gclsrc, fbclid, msclkid, and ttclid when present.
    • Identifiers: With analytics enabled, we may use pseudonymous visitor/session identifiers and Google Analytics client/session identifiers to join a visit to later sign-up or purchase events. Authenticated events may use an internal pseudonymous account identifier; we do not use an email address as the analytics user identifier.
    • Filtering: Analytics landing paths retain useful campaign, product, model, plan, provider, and source parameters while removing unrelated or potentially sensitive parameters such as email addresses, access tokens, authorization codes, secrets, and URL fragments.
    • Why: To distinguish direct, organic, referral, advertising, and campaign traffic; measure conversion by source; prevent duplicate conversion reporting; and evaluate marketing effectiveness.
  5. Payment, checkout, subscription, and credit data

    • What: Product and plan selected, billing interval, credits, displayed price, charged amount and currency, payment provider, discount, order/subscription/transaction/invoice identifiers, checkout status, payment status, renewal/upgrade/top-up status, cancellation state, payment email or name returned by a processor, and timestamps.
    • Payment-friction analytics: We may retain normalized, low-cardinality fields such as payment-method category, card brand, wallet type, provider status, failure or decline code, network-status category, whether additional authentication such as 3-D Secure was required, checkout age, and the source entry point that led to the checkout.
    • What analytics excludes: Full card numbers, security codes, card fingerprints, card last-four digits, bank-account credentials, raw processor payloads, billing-address text, free-text processor error messages, invoice URLs, and customer email or name are not copied into behavioral analytics or sent as analytics event parameters.
    • Processors: Full payment credentials are collected and handled by the selected payment processor, not by GLM 5. We receive the limited records needed to complete the order, grant credits, manage the subscription, handle refunds or disputes, and meet accounting or legal obligations.
  6. Cookies and local storage

    • Essential storage: Used for login, security, locale, checkout recovery, and other functionality you request.
    • Analytics storage: With analytics enabled, used for pseudonymous visitor/session continuity, attribution, measurement, and consent state.
    • Typical durations: The analytics-consent choice and pseudonymous visitor cookie may last up to 395 days; campaign-attribution cookies generally last up to 30 days; session identifiers expire sooner or when their session ends. Browser or provider settings may shorten these periods.
  7. Support communications

    • What: Messages and attachments you send to support, plus related account or transaction context needed to resolve the request.
    • Why: To respond, troubleshoot, prevent abuse, and improve customer experience.

Analytics and Session Replay

First-party analytics

Our first-party event system records structured product and payment-funnel events such as page or pricing views, plan and provider selection, checkout creation, checkout-provider failure, payment-attempt failure, completed purchase, renewal, upgrade, top-up, cancellation, generation lifecycle, and quota friction. Events are linked using internal identifiers where available and are deduplicated so repeated browser or payment-provider callbacks do not count the same business event multiple times.

Client-supplied event data is filtered in the browser and filtered again on the server. Fields shaped like email, phone, address, password, API key, token, secret, prompt, message content, uploaded-file URL, raw payload, raw error, stack trace, or sensitive URL are removed before analytics persistence or third-party forwarding.

Google Analytics and advertising features

We use Google Analytics 4 and may use Google advertising features, including Google Signals, to measure traffic, purchases, and campaign effectiveness and, where permitted, support cross-device reporting or remarketing. We and Google may use first-party cookies and consent-aware measurements for these purposes.

We do not intentionally send Google Analytics your name, email address, phone number, prompt or chat content, uploaded-file contents, raw payment-provider errors, or full payment credentials. Server-side sign-up and payment events use real Google client/session identifiers when available and a pseudonymous internal identifier where needed to avoid losing the conversion fact.

In the EEA, United Kingdom, and Switzerland, analytics and advertising storage defaults to denied until you make a choice. Google tags may send limited cookieless consent or measurement pings where supported; they do not receive our server-side Measurement Protocol conversion events while consent is pending or denied. Outside those regions, analytics may operate on an opt-out basis where permitted, and an explicit decline is honored globally.

You can manage your choices through Cookie Settings, your browser, Google Ad Settings, or the Google Analytics Opt-out Browser Add-on. See Google's Privacy Policy and how Google uses information from sites that use its services.

Microsoft Clarity

We use Microsoft Clarity for consent-aware session replay and interaction analysis. Clarity may receive pseudonymous session or internal account identifiers, page navigation, clicks, scrolling, device/browser details, coarse location, and low-cardinality account state such as signed-in status or credit bucket.

We explicitly mask chat history and composition, image and video prompts, negative prompts, music style and prompt fields, and lyrics in replay. We do not deliberately identify Clarity users with email addresses or names. Clarity receives consent updates through Google Consent Mode and Clarity Consent V2 where supported. See the Microsoft Privacy Statement.

How We Use Information

We use information to:

  • provide, personalize, maintain, and improve the Service;
  • complete AI jobs, restore interrupted workflows, and deliver outputs;
  • process purchases, subscriptions, upgrades, renewals, credits, refunds, and disputes;
  • understand traffic sources and the steps where users abandon or fail to complete payment;
  • measure marketing and product effectiveness without placing user content in analytics;
  • monitor reliability, debug failures, enforce limits, and protect against fraud, abuse, or security threats;
  • communicate about accounts, transactions, support, and permitted marketing; and
  • comply with law and enforce our Terms of Service.

Depending on the data and your location, we rely on one or more of the following:

  • Contract: To provide the Service you request, authenticate your account, process payments, deliver credits or subscriptions, and provide support.
  • Consent: For non-essential analytics, advertising features, and session replay where consent is required. You may withdraw consent at any time without affecting processing already lawfully performed.
  • Legitimate interests: To secure and improve the Service, prevent fraud, maintain reliable billing and attribution, measure aggregate business performance, and diagnose product or payment failures, after considering privacy impact and user expectations.
  • Legal obligations: To maintain records, respond to lawful requests, comply with tax/accounting rules, and handle disputes.

Information Sharing and Disclosure

We do not sell your personal information. Depending on applicable law, some analytics or advertising disclosures may be treated as "sharing" for cross-context behavioral advertising; you can opt out through Cookie Settings and the controls described above.

We disclose data only as needed to:

  • Service providers, including hosting, database, AI-model, observability, email, customer-support, analytics, security, and payment providers, under appropriate contractual and confidentiality obligations;
  • Legal and safety recipients when required by law or reasonably necessary to protect GLM 5, users, or others; and
  • Business-transfer recipients in a merger, acquisition, financing, reorganization, or asset transfer, subject to appropriate notice and safeguards.

Data Storage, Retention, and Security

We use encryption in transit, access controls, secret-management practices, logging, data minimization, and other technical and organizational safeguards. No system is perfectly secure, and we cannot guarantee absolute security.

Retention depends on purpose:

  • account and content history is kept while needed to provide the Service or until deletion, subject to backups, fraud prevention, disputes, and legal limits;
  • order, payment, subscription, refund, tax, and accounting records may be retained for the period required by applicable law or legitimate dispute-prevention needs;
  • first-party analytics and attribution records are kept only while reasonably useful for product, security, source, and payment-funnel analysis, then deleted or de-identified where feasible;
  • Google Analytics, Microsoft Clarity, payment processors, and other providers retain data under their own configured retention periods and policies; and
  • aggregated or de-identified statistics may be retained longer when they no longer reasonably identify an individual.

Choosing Decline or withdrawing consent stops new consent-dependent first-party collection, clears unsent analytics events and local anonymous analytics/attribution identifiers, and sends consent updates to supported third-party tools. Essential account, security, order, subscription, fraud-prevention, and legal records are not deleted merely by changing a cookie preference. You may separately request access or deletion as described below.

Your Choices and Rights

  • Cookie and analytics choices: Open Cookie Settings at any time to accept, decline, or withdraw analytics and advertising consent. You can also manage cookies in your browser; disabling essential cookies may affect functionality.
  • Account updates: Update account details in your profile or contact support.
  • Access, correction, portability, and deletion: Request a copy, correction, export, or deletion of personal information, subject to identity verification and legal or operational exceptions such as security, fraud prevention, billing, tax, and dispute records.
  • Objection or restriction: Where applicable, object to or ask us to restrict processing based on legitimate interests.
  • Marketing: Use the unsubscribe link to stop non-essential marketing email. We may still send transactional or security messages.
  • Complaint: Depending on your location, you may complain to your local data-protection authority.

International Transfers

When information is transferred across borders, we use safeguards required by applicable law, such as contractual protections, provider data-processing terms, and transfer mechanisms where applicable.

Children's Privacy

GLM 5 is not directed to children under 13 or the minimum age required in their jurisdiction. We do not knowingly collect personal information from children in violation of applicable law. Contact us if you believe a child has provided data so we can investigate and delete it where required.

Changes to This Policy

We may update this Privacy Policy periodically. Changes are effective when posted on glm5.app. If a change is material, we will provide reasonable notice through the Service, by email, or by another appropriate method.

Contact Us

For privacy questions, rights requests, or concerns about these practices, contact:

This Privacy Policy does not limit any rights you have under applicable law, and it does not replace a consent choice presented through Cookie Settings.