Privacy policy
Who we are
iGlow is operated by StellarClouds Private Limited.
Account data
When you sign in with Google we store your Google account ID, email address, name, profile picture URL and time zone. We use them to identify your account and to enforce your plan's limits: a weekly number of AI runs (the week runs Monday to Sunday, India time), a smaller number per 5-hour window, and a weekly or monthly AI spending cap.
SAP tenant data
iGlow talks to your SAP Integration Suite tenant from inside your own browser tab using your existing session. Your SAP session cookies never leave that tab and are never sent to iGlow. Free features (iFlow overview, credential check, script browser, snapshots) run entirely in your browser. Snapshots are stored locally in your browser and are never uploaded. The side panel also keeps your recent chats in your browser; deleting a chat from the history list removes that local copy.
Stored in your browser only
Your DEV/QA/PRD tag for each tenant, your settings, your sign-in tokens (a short-lived access token and a 30-day refresh token), and any SAP service keys you add in the Test tab. Service keys are used only to send test calls from your browser to your tenant's runtime; they are never sent to iGlow's servers or shown to the AI. This storage is closed to scripts running in web pages.
What is sent to iGlow servers, and when
In these cases only:
- When you use the chat: your messages and what the assistant reads from your tenant to answer, such as parts of the iFlow, scripts, error texts and message or trace excerpts.
- Automatically, when the Chat tab lists failed messages for the iFlow you have open: the error text of each recent failed message and the iFlow's step names, so iGlow can label the likely cause. This happens without a click; it is shown as a label next to each failed message.
- When you ask the Test tab to suggest a request body: the iFlow's steps and the scripts they use.
- To suggest a new chat: when you send a message in a long chat, the recent messages are checked to see whether you started a different task.
- To suggest your next message: after a chat answer, your last two questions and the assistant's answers to them (text only, each shortened), and the names of the tools the assistant used (not their results), are sent to suggest a short next message.
- When something breaks in the side panel: a short error report (error name and code, a masked error message, the iGlow and Chrome versions, and the chat run ID). It never includes your messages, iFlow content or payloads. We use it only to find and fix bugs.
Before anything is sent, iGlow masks emails, phone numbers, card and IBAN-like numbers, tokens, passwords and authorization headers. Names, addresses and customer numbers inside message content are not masked. You can see exactly what was sent for each chat run.
Chat history
iGlow stores your AI chats on its servers: your questions, the answers, and the tool calls and tool results the assistant used (for example a deploy result or an SAP error message). What is stored is what was sent to the model, after the masking described above, with secrets and credentials removed again on our side; very large results such as iFlow XML are cut short. Stored chats are kept for 90 days and then deleted. You can see them in the side panel history.
Support access to your chats
iGlow support staff read your stored chats only if you allow it. When you first sign in, iGlow asks whether support may read your chats to help you with problems. The default is no. You can change your answer at any time in the side panel under Settings → Privacy, and a change applies at once.
Model providers
AI runs are processed by Google (Gemini API). Some runs may use a model from another maker (for example Anthropic) through OpenRouter. The short checks (the failed-message label and the new-task check) may be processed by TypeSafe (typesafe.ai). We send these providers only what the run needs, after masking.
Chrome Web Store Limited Use
The use of information received from Google APIs and from your browser will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. iGlow uses your data only to provide its single purpose: an assistant for SAP Integration Suite. We do not sell your data, do not use or transfer it for advertising, credit checks or any purpose unrelated to that single purpose, and people read it only with your explicit consent (see "Support access to your chats"), for security reasons, or when the law requires it.
Hosting
Backend in Frankfurt (Fly.io); database in AWS eu-central-1 (Neon).
Retention
Account data is kept while your account exists; chat history for 90 days; usage records for billing for as long as the law requires. Delete your account at any time by contacting support at hello@stellarclouds.com.
We never sell your data
We don't sell, rent or share your data for advertising.