Privacy Policy
Version 2.0 · Effective 10 July 2026.
Private by default.
Your photos, analyses, goals and journal entries are private to you. We do not sell your personal data. We do not train foundation models on your biometric-like inputs without your explicit, separate opt-in. You can export or delete your data at any time.
1. Who we are (Controller)
The data controller for Glowria (the "Service") is Glowria LTD, a private limited company incorporated in England & Wales ("Glowria", "we"). Contact: info@glowria.ai. Glowria LTD acts as the controller for personal data of users worldwide, including in the UK, the EU / EEA, and the United States. Where required, we will appoint an EU representative under Article 27 GDPR and a UK representative under UK GDPR, and publish their contact details here.
2. What we collect
- Account data — name, email, password hash, authentication provider identifiers, language, country (optional), age acknowledgement.
- User Content — photos and videos you upload, before/after images, share cards, journal entries, goals, event look plans, notes.
- Biometric-like inputs & derived signals — measurements and vectors derived from facial and body imagery for the purpose of analysis (proportions, skin descriptors, colour profile, pose). We treat these as sensitive.
- Usage & telemetry — device, browser, OS, approximate location (from IP), pages viewed, features used, timestamps, errors, crash logs.
- Analytics & experimentation events — feature interactions, funnel events, cohort assignments (pseudonymised).
- Purchases — plan, billing status, currency, payment-method metadata (full card numbers are handled by our PSP, not by us).
- Communications — support messages, notification preferences, safety reports.
- Cookies & similar — as described in Section 8.
3. Why we process it (purposes & legal bases)
Under the GDPR / UK GDPR our legal bases are:
- Performance of a contract (Art. 6(1)(b)) — to provide the Service you request, run analyses, deliver plans and coaching.
- Consent (Art. 6(1)(a), Art. 9(2)(a)) — for processing of biometric-like inputs, sensitive modules, marketing communications, non-essential analytics, and any research or model-improvement use of your data. You may withdraw consent at any time.
- Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent fraud and abuse, run essential product analytics on aggregated/pseudonymised data, protect users and Glowria, and communicate service-critical information. Where we rely on legitimate interests we balance them against your rights and you may object.
- Legal obligation (Art. 6(1)(c)) — accounting, tax, response to lawful requests, security-incident reporting.
California residents (CCPA/CPRA): categories collected mirror the list above. We do not "sell" personal information for money. We do not "share" it for cross-context behavioural advertising in the CCPA sense. You have the rights described in Section 6, including the right to opt out and the right to limit use of sensitive personal information.
4. AI processing
To generate analyses and content, we send inputs (including images or derived features) to AI models. Some models are operated by us; others are operated by vetted third-party sub-processors under contractual data-protection terms. We minimise what is sent (for example by processing images to a derived form when possible), we do not permit sub-processors to use your inputs to train their own models unless we have your explicit opt-in, and we log AI events for safety and quality control.
5. Sharing
We share personal data only with:
- Sub-processors — cloud hosting, database, storage, email, payments, analytics, error reporting, AI model providers. A current list is available on request.
- Partners you choose — when you explicitly share a report, use a partner offer, or grant partner access.
- Legal & safety — when required by law, to respond to lawful requests, to enforce Terms, or to protect the rights, property or safety of users or Glowria.
- Corporate transactions — successors in a merger, acquisition or sale of assets, subject to equivalent protection.
We do not sell personal data.
6. Your rights
Depending on your jurisdiction you have some or all of these rights:
- access to your data and a copy;
- rectification of inaccurate data;
- erasure ("right to be forgotten");
- restriction of processing;
- data portability;
- objection to processing based on legitimate interests, and to direct marketing at any time;
- withdrawal of consent, at any time, without affecting the lawfulness of prior processing;
- the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — Glowria outputs are guidance, not decisions with legal effect;
- the right to lodge a complaint with your data-protection authority (in the UK: ICO; in the EU: your national DPA).
Exercise your rights from Privacy Settings inside the app, or by emailing info@glowria.ai. We may verify your identity before responding. We respond within statutory deadlines (30 days under GDPR, extendable once).
7. Retention
We keep personal data only as long as necessary for the purposes described above. User Content and derived signals persist while your account is active and are deleted (or anonymised) within a reasonable period after account deletion, subject to shorter or longer retention for security, fraud-prevention, tax, accounting and legal-hold reasons. Backups are rotated on a rolling schedule.
8. Cookies & similar technologies
We use strictly-necessary cookies to run the Service (authentication, security, load-balancing). We use analytics and preference cookies only with your consent where required. You can manage preferences from the cookie banner or Privacy Settings.
9. International transfers
We may transfer personal data to countries outside the EEA/UK. Where we do, we rely on adequacy decisions, EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent safeguards, and we assess the destination country's laws.
10. Security
We use industry-standard technical and organisational measures: encryption in transit and at rest, row-level access control, least-privilege administration, monitoring, audit logs, and secret rotation. No system is perfectly secure; you play a part by protecting your credentials.
11. Minors
Glowria is not intended for anyone under 18. We do not knowingly collect personal data from minors. If we learn we have, we will delete it. Contact info@glowria.ai.
12. Automated decision-making & profiling
Glowria uses automated processing to generate guidance. This guidance does not produce legal or similarly significant effects about you; it is informational and can be dismissed, disabled, or overridden by you at any time. You have the right to request human review of any output that materially affected you by contacting us.
13. Changes
We may update this Policy; material changes will be announced in-app or by email. Continued use after the effective date constitutes acceptance.
14. Contact
Glowria LTD — England & Wales.
All privacy, data-protection, security and general enquiries: info@glowria.ai.
See also the Terms of Service and the AI Disclaimer.