Privacy Policy
This policy explains what glowapp collects, why, who processes it, and the choices you have. It applies to the glowapp mobile app and website (the "Service"), operated by Cool App Company Ltd ("glowapp", "we") — the data controller for the processing described here.
1. What we collect
- Account data — email address, name (if you provide it), and login details. An account is required to use the Service. If you sign in with Apple and choose "Hide My Email", we only ever receive Apple's private relay address, never your real one.
- Face images and scan results — the photos you take for a skin scan and the analysis generated from them (scores, detected attributes, progress history).
- Product scans — photos of product labels and the resulting ingredient matches.
- Answers you give — skin goals, routine preferences, and messages you send to Glow AI.
- Usage and device data — how you use the app (screens viewed, features used), device type, app version, and crash logs.
- Push notification data — if you allow notifications, a push token identifying your device, plus your device language and time zone so messages arrive in your language at a reasonable hour.
- Referral and creator data — a referral code you enter, and the contact and social-account details you submit if you apply to our creator program.
2. How we use your data
- To provide the Service: generate your skin analysis, build your routine, check products, and answer your questions.
- To show your progress over time and what your skin could reach.
- To operate, secure, and improve the Service, including analytics.
- To send push notifications, if you allow them: reminders to scan, your results when they are ready, and tips about your routine. You can turn them off at any time in the app's settings or in your device settings.
- To communicate with you: service emails about your account, scans, and purchases, which we always send; and marketing emails with skincare tips and offers for our own products.
Marketing email. We tell you we may send it when you create your account, and every marketing email carries an unsubscribe link. Where the law requires a basis, we rely on the customer relationship you have or are entering into with us (often called "soft opt-in") for messages about our own similar products, and on your consent where that basis is not available. Unsubscribing stops all marketing email and does not affect your account or your service emails.
We do not sell your personal data, and we do not use your face images for advertising.
3. Face images and third-party AI (important)
When you scan your face, your photo is sent to Google's Gemini API — a third-party AI service operated by Google — to generate your skin analysis. The same applies to product-label photos. This processing is required for the Service to work; if you do not want your face image processed this way, do not use the scan features.
Google processes these images on our behalf under a data-processing agreement and does not use your images to train its models under our API terms. By starting a scan, you consent to your face image being processed this way. You can withdraw that consent at any time by deleting your scans or your account, and withdrawing it does not affect processing that already happened.
4. Processors we use
- Google (Gemini API) — AI analysis of face and product photos.
- Amplitude, Inc. — product analytics (usage events, device data) so we can understand and improve how the app is used.
- Supabase — hosting, database, and storage of your account data and images.
- Adapty — subscription management, purchase analytics, and the email service that sends our account and marketing messages. Your email address is shared with Adapty for this purpose.
- OneSignal — push notifications. We send OneSignal your account identifier and it holds the push token for your device so we can reach you with scan reminders and tips. No face images or scan results are ever sent to OneSignal.
- Sentry — crash and error reporting (device type, app version, and diagnostic data) so we can find and fix bugs.
- ScrapingDog — web search we use to find where a skincare product is sold and at what price. We send product names, not personal data.
- Apple — App Store payments, and Sign in with Apple if you use it.
- Google — Sign in with Google, if you use it.
All processors act under contracts that limit their use of your data to providing their service to us. Where data leaves your region, we use appropriate safeguards such as Standard Contractual Clauses.
5. How long we keep your data
We keep your account data, scans, and history while your account is active, to show your progress & potential — comparing today's scan with earlier ones is the core of the Service.
- Delete anytime: you can delete your account, including every face image and scan, in Settings → Account → Delete account (or by emailing us). Deletion is permanent, and your data is removed from our systems without undue delay.
- We may retain limited records where the law requires it (for example, purchase records for tax purposes).
6. Referrals and creator applications
If you enter a referral code, we record the link between your account and the account that referred you so we can apply the reward. If you apply to our creator program, we collect the contact and social-account details you submit and use them only to assess and administer your application. Both are optional features — you can use the Service without them.
7. Your rights
Depending on where you live (including under the GDPR and CCPA), you have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent at any time. Use the in-app controls or email us; we respond within the legally required time. You can also complain to your local data-protection authority.
To stop marketing email, use the unsubscribe link in any marketing message, or email us and we will do it for you. You have the right to object to direct marketing at any time, free of charge.
8. Children
The Service is not directed at children under 13 (or the higher minimum age that applies in their country, such as 16 in parts of the EEA), and we do not knowingly process their data. If you believe a child has used the Service, contact us and we will delete the data.
9. Security
Data is encrypted in transit and at rest, access is limited to those who need it, and face images are held in a private storage bucket hosted in the EU (AWS eu-north-1, Stockholm) that is not publicly accessible and can only be read with per-user authorization. No system is 100% secure, but we treat face data as sensitive and protect it accordingly.
10. Changes to this policy
If we make material changes, we will notify you in the app or by email before they take effect. The date at the top shows the latest version.
11. Contact
Privacy questions or requests: contact@coolappcompany.com.