Privacy Policy
Effective Date: July 20, 2026
Last Updated: July 20, 2026
This Privacy Policy explains how GleanMark collects, uses, discloses, and retains personal information when you visit or use the Service.
1. Scope and Our Roles
This Privacy Policy applies to GleanMark websites, applications, software, AI features, public-record products, communications, and related services (the “Service”). GleanMark is operated by TMZap Incorporated. This Policy does not govern a third party's independent practices or a customer's use of information after exporting it from the Service.
GleanMark's legal role depends on the information and how it is used:
- Controller. We determine the purposes and means of processing for account administration, billing, communications, security and fraud prevention, analytics and session replay, public-record profiles and entity matching, and authorized product-improvement activities.
- Processor or service provider. We process private Customer Content on behalf of a business customer solely to provide requested Service features—for example, uploaded Office Actions, private client portfolios, matter notes, Markus conversations, and legal drafts and analyses.
If an organization separately authorizes GleanMark to use identifiable Customer Content for model training or fine-tuning, GleanMark acts as an independent controller for that authorized improvement use. Enterprise customers may request a data processing addendum or negotiate stricter processor-only treatment.
2. Information We Collect
Account, organization, and commercial information
We collect identifiers and account details such as name, email address, organization, job role, profile information, login and authentication data, subscription plan, billing status, accepted policy versions, acceptance timestamps, and organization permissions. Stripe processes payment-card details; GleanMark generally receives transaction, customer, invoice, and subscription information rather than full card numbers.
Customer Content
We collect information you submit, upload, import, save, generate, or share through the Service, including search queries, watched marks, portfolios, client and matter information, Office Actions and other documents, notes, instructions, prompts, AI conversations, reports, drafts, analyses, exports, feedback, and support messages. Customer Content may include personal information about clients, employees, trademark owners, attorneys, correspondents, declarants, and other people.
Public-record and derived information
We collect government, court, and other publicly available records, including USPTO records. Public information can still be personal information under applicable law. We may derive profiles, relationships, categories, scores, statistics, similarity measures, entity matches, and other analytics from public records and Service data.
Technical, usage, and communications information
We collect device and browser type, operating system, IP address, approximate location, identifiers, referring pages, pages and features used, clicks, navigation, timing, errors, network-request metadata, session and authentication events, preferences, and interactions with emails and support. We may also receive information from integrations you connect or authorize.
3. Sources of Information
We collect information:
- directly from you and other authorized users of your organization;
- automatically from browsers, devices, cookies, local storage, logs, analytics, and session replay;
- from public sources such as the USPTO, courts, government datasets, and public websites;
- from service providers such as authentication, payment, analytics, communications, support, hosting, and AI providers; and
- from referrals, integrations, partners, customers, or other people who provide information lawfully.
4. How We Use Information
We use information to:
- provide, personalize, operate, support, and administer the Service;
- perform searches, matching, monitoring, alerting, analytics, retrieval, drafting, AI processing, and requested workflows;
- create and maintain accounts, organizations, subscriptions, usage records, and legal-acceptance records;
- process payments, enforce usage limits, prevent account sharing, and manage commercial relationships;
- communicate about the Service, support requests, security, transactions, product changes, and marketing preferences;
- protect the Service, customers, and others; detect fraud, abuse, security events, and technical failures; and enforce agreements;
- test, evaluate, diagnose, analyze, develop, and improve features, search, matching, retrieval, analytics, AI, and workflows;
- build, correct, and analyze public-record profiles, entity associations, statistics, and derived datasets;
- comply with law, respond to lawful process, establish or defend legal claims, and complete corporate transactions; and
- create and use aggregated or properly de-identified information for lawful business purposes.
5. AI Features and Diagnostic Logs
When you use an AI feature, we may send relevant inputs, documents, instructions, and context to an AI provider or model host to generate the requested result. Depending on the feature and current configuration, providers may include OpenAI, Anthropic, Google, xAI, and Fireworks AI or another open-model host. We configure our business integrations so outside AI providers are not permitted to train their general-purpose models using Customer Content submitted through GleanMark.
We may retain full AI inputs and outputs in restricted diagnostic logs for up to 90 days to secure, debug, evaluate, and improve Service features. After 90 days, raw diagnostic content is deleted or properly de-identified. We may retain non-content technical metadata longer, including provider, model, timing, latency, token usage, cost, feature or function, and success or error information.
Customer-visible saved conversations, reports, drafts, analyses, and documents are separate from hidden diagnostic copies and follow the retention practices in Section 9. AI outputs can reproduce or infer personal information and may be inaccurate; review them before use or disclosure.
6. How We Disclose Information
We may disclose information:
- To service providers and subprocessors that support hosting, databases, authentication, storage, payments, analytics, replay, error monitoring, customer support, communications, and AI processing. They may process information only for authorized services and under applicable contractual restrictions. See our current Subprocessor List.
- Within a Customer organization according to its membership, workspace, sharing, and administrator settings, or as directed by authorized users.
- For legal, safety, and enforcement purposes when we reasonably believe disclosure is required by law or process, needed to protect rights, safety, or the Service, or appropriate to investigate fraud, abuse, or a violation.
- For a corporate transaction such as financing, due diligence, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate safeguards.
- With your authorization or at your direction.
We do not sell personal information for money or share it for cross-context behavioral advertising as those terms are defined by current U.S. state privacy laws. We may publicly display information from public records and derived public-record profiles as part of the Service.
7. Analytics and Session Replay
We use product analytics and privacy-masked session replay, including in authenticated workflows that may involve Customer Content. These tools help us understand navigation, diagnose errors and failed requests, evaluate feature use, improve usability, prevent abuse, and support customers. Current providers include PostHog and, where enabled, Google Analytics.
Session replay is configured to mask input values and page text and to exclude network-request headers and bodies. It may still record interface structure, clicks, navigation, timing, technical identifiers, request URLs and status, and other interaction metadata. No masking system is perfect; do not enter unnecessary sensitive information into the Service.
In the United States and other jurisdictions that permit a default analytics model, analytics and masked replay may operate by default, including for authenticated users. The authenticated product does not currently offer a general U.S. analytics opt-out. In the EEA, United Kingdom, Switzerland, and other locations where consent is required, we ask for consent before enabling nonessential analytics and replay. See our Cookie Policy for more information.
8. Public Records and Profiles
GleanMark uses public records to create searchable records, profiles, associations, alerts, counts, and analytics. We may normalize names, deduplicate records, link filings to people or organizations, and infer relationships. This processing can produce incorrect, incomplete, or outdated associations.
Individuals and organizations may request review of an apparent incorrect association by emailing privacy@gleanmark.com with supporting information. We will consider reasonable, supported corrections, but do not guarantee every requested change, perfect accuracy, or removal of accurate public information merely because it is unwelcome. Source-record corrections generally must be directed to the agency or publisher responsible for the source.
9. Retention and Deletion
We retain information only as long as reasonably necessary for the purposes described in this Policy, including providing and administering the Service, security and fraud prevention, billing, accounting and tax, legal compliance, dispute resolution, enforcement, product operation, and legitimate business purposes. The period depends on the information, why we use it, Customer instructions, legal obligations, and technical systems.
When information is no longer reasonably necessary, we delete or de-identify it. Account deletion may begin with a recovery period, and deletion from backups and dependent systems may occur on later operational cycles. Some information may be retained longer where reasonably needed for legal, security, billing, audit, or dispute purposes. We do not promise that every record or backup permanently disappears on a single fixed day.
Raw AI diagnostic content follows the separate maximum 90-day period described in Section 5. Aggregated or properly de-identified information may be retained without the same limitation.
10. Security and Incidents
We use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the Service and information. Measures may include encryption in transit, access restrictions, authentication, monitoring, provider controls, backups, and incident-response procedures. No method of storage, transmission, or security is perfect, and we cannot guarantee that information will always remain secure or available.
We promptly investigate suspected security incidents and take reasonable containment and remediation steps. We notify affected customers, individuals, regulators, or others when required by applicable law, without unreasonable delay and within legally applicable deadlines. We may provide phased updates as material facts become available. Notice may be delayed or limited where law permits or requires, including at law enforcement's request or where notice would impede an investigation.
11. International Transfers
GleanMark is based in the United States, and we and our providers may process information in the United States and other countries. Those countries may have different data-protection laws. Where required, we use an approved transfer mechanism or another lawful basis for international transfers, such as standard contractual clauses or a provider's recognized certification.
12. Privacy Rights and Choices
Depending on where you live and subject to legal exceptions, you may have rights to request access, correction, deletion, portability, restriction, or objection, or to withdraw consent. You may also have a right to complain to a data-protection authority. These rights apply only where the relevant law grants them.
To make a request, email privacy@gleanmark.com. You may request a copy of your personal information or reasonably exportable Customer Content. We may verify identity and organizational authority, protect other users' and organizations' rights, and apply security and legal exceptions. Exports may exclude GleanMark intellectual property and aggregated or de-identified information and may be provided in a reasonably usable format such as CSV, JSON, PDF, or original uploaded files.
You can update certain account information and communication preferences in the Service. Unsubscribing from marketing does not stop transactional, security, billing, legal, or Service communications. Authorized agents may submit requests where applicable law permits and required verification is provided. We do not discriminate against people for exercising applicable privacy rights.
13. Children
The Service is intended for adults and is not directed to children under 18. We do not knowingly collect personal information directly from a child under 13. If you believe a child provided personal information without appropriate authorization, contact us so we can evaluate and address it.
14. Changes and Contact
We may update this Policy as our Service and practices change. For a material change, we will require authenticated users to review and affirmatively accept the updated Terms and Policy before continuing to use the Service; the change takes effect for that user upon acceptance. Other changes may take effect when posted. The “Last Updated” date identifies the current version.
Questions and privacy requests may be sent to:
TMZap Incorporated d/b/a GleanMark7 Rye Ridge Plaza, Suite 660
Rye Brook, NY 10573
privacy@gleanmark.com