glidepay is live on Arc mainnetLaunch note
Mainnet

Security model

Your glidepay account is a Circle developer-controlled smart account on Arc. Circle holds the keys and signs transactions. glidepay's server asks Circle to sign when you confirm a payment or an automation you set up runs. You sign in with email or Google. Here's what that means and where the trust boundaries are.

Who holds the keys

Circle, through its Developer-Controlled Wallets infrastructure. Keys are never shown in the app, and no keys or secrets live in the app. Transactions are signed server-side: glidepay sends a signing request over Circle's API and never handles private keys itself.

The trade-off versus a self-custody wallet is trust. There's no seed phrase to lose or leak, and you can sign in again on any device, but you rely on glidepay and Circle to operate your wallet honestly. On mainnet, that trust covers real money.

Your PIN

  • A 6-digit PIN confirms any money going out of your balance.
  • The PIN is stored hashed on the server. It's never sent to the app, and glidepay can't read it back.
  • Resetting the PIN requires re-verifying your email first.

Automations and approvals

Automations (auto-save, scheduled sends and the balance ceiling) only run on rules you set. Automated payments above an amount you choose, or to someone who isn't in your contacts, wait for your approval. See Automations & Savings.

Tokens you didn't expect

Anyone can send any token to a public address. glidepay counts only USDC, EURC and cirBTC in your balance, at live market prices. Any other token still shows up, labelled Unverified, is never counted in your balance, and can still be sent. Look-alike "USDC" tokens are flagged Possible scam and hidden by default.

Payments are final

Payments on Arc are final and can't be reversed. Check the @paytag or address on the confirm screen before you enter your PIN. Billy shows a confirm card before any money move for the same reason.

What we store about you

  • Your email (from Clerk)
  • Optional display name, avatar, pay tag
  • Your Circle wallet IDs (your Arc account, your Savings account, and receive chains as they're enabled)
  • A hash of your PIN, never the PIN itself
  • Transaction history we've recorded (off-chain mirror of on-chain events)
  • Saved contacts, payment requests, scheduled sends and automation rules
  • Push notification subscription (if enabled)
  • Recent Billy chat history (last ~80 messages)

Full detail: see the in-app Privacy Policy.

What we don't store

  • Private keys, seed phrases, signing credentials. Circle's domain, not ours.
  • Marketing trackers, behavioural analytics, device fingerprints
  • Card / bank details. There's no fiat onramp.

On-chain data

Everything you do on Arc is public: wallet address, transaction hashes, amounts. Anyone with a block explorer can see them. This is true of every wallet on every public blockchain.

Closing your account

Closing your account requires your PIN and an empty balance, so money can't be left behind by mistake. Send or bridge your funds out first. Closing deletes your glidepay profile, its related records and your sign-in account.

Idempotency & double-spend protection

Every send through /api/sendchecks for a duplicate (same recipient, amount, token, last 10s) and short-circuits if one exists. Money-out chat intents require an explicit confirmation tap. Webhook retries from Circle can't trigger duplicate Universal Receive sweeps. The claim is atomically locked by a DB unique constraint.

Disclosure

Found a security issue? Email support@glidepay.cash before disclosing it publicly, and we'll coordinate a fix with you.

Related: Architecture, FAQ.