Privacy Policy
Your face stays on your phone.
Last updated August 17, 2026
The short version
- Camera frames never leave your iPhone. Form tracking runs entirely on-device. No photo or video of your face is uploaded, stored on our servers, or shared.
- Photos you save stay on your device too. Journal photos and habit check-in snapshots are written to Glowera's private storage on your phone and are never uploaded.
- If you create an account, some data does sync. Your progress, your habits and the text of your journal entries go to our server so they survive reinstalling.
- No ads, no trackers, no data sales. Glowera contains no advertising networks and no third-party analytics or tracking SDKs.
Who we are
Glowera is built and operated by [YOUR FULL LEGAL NAME], a sole proprietor based in [YOUR STATE], United States, who is the data controller for the purposes of GDPR. You can reach us any time at support@glowera.app.
What never leaves your device
- Camera and TrueDepth frames. Processed in memory during a session and discarded immediately.
- Your photos. Progress photos, journal photos and habit-verification snapshots are stored in Glowera's own folder in your device's Application Support directory. They are not uploaded, and they are not included in the sync described below.
- Product analytics. Glowera records which features you use to a log file on your own device. There is no remote analytics backend — these events are not transmitted to us or to anyone else.
- Everything, before you sign in. Glowera's source of truth is local storage on your phone. The app works fully offline and with no account at all; syncing is an addition, not a requirement.
What syncs when you sign in
Creating an account is optional and exists so your progress survives a reinstall or a new phone. When you are signed in, we store the following on our servers:
- Account: a user ID, your email address, and your name if your sign-in provider gives it to us. (Apple returns your name and email only on the very first authorization.)
- Progress: XP, coin balance, earned badges, completed challenges and combo bonuses.
- Habits: your habit list and the history of which days you completed them.
- Journal entries — text only: what you wrote, the prompt you answered, mood, how your skin felt, tags, dates and session length. Journal photos are not uploaded.
- Face-scan results: the numeric scores your scan produced, plus the goals and preferences you chose during onboarding. No image, and no face template or biometric identifier, is ever uploaded.
- Purchase status: whether you hold an active subscription. Apple handles payment; we never see your card details.
Your face and the camera
During a coaching session the front camera analyses your face in real time to score your form. This happens entirely on your device using Apple's on-device vision frameworks. Frames are processed in memory and discarded immediately. Glowera does not record video, does not build a face template, and does not perform biometric identification — the analysis measures how you are moving, not who you are, and it is never used to recognise or identify a person.
If you are signed in, the numbers your scan produces (your Glow Score and related sub-scores) do sync as described above. The imagery they were derived from does not.
How we use AI
Glowera uses AI, and it runs on your iPhone.
- Form tracking is on-device computer vision. The "AI coach" is a model running locally against camera frames. Nothing is uploaded.
- Coach voices are pre-recorded audio files shipped inside the app. We generated them with a text-to-speech service before release, from our own scripts. The app makes no calls to that service, and nothing about you is ever sent to it.
- We do not send your face, your progress, or anything you write to a large language model.
AI output can be wrong. Glowera is a wellness tool, not medical or cosmetic advice, and makes no outcome guarantees.
Third parties who process your data
- Supabase — hosts our database and authentication, and therefore stores everything listed under "What syncs when you sign in."
- Apple — App Store purchases, Sign in with Apple, push notifications, and crash and performance diagnostics (subject to your iOS analytics setting).
- Google — only if you choose Sign in with Google.
We use no advertising networks, no marketing trackers and no third-party analytics SDKs. We have never sold personal information, and we do not share it for cross-context behavioural advertising.
Why we're allowed to process this (GDPR lawful basis)
- Performance of a contract — creating your account, syncing your data across devices, and delivering a subscription you paid for.
- Legitimate interests — keeping the service secure and preventing abuse.
- Consent — camera access, photo access and notifications, each of which iOS asks you for separately and you can revoke at any time in Settings.
Your rights and choices
- Delete everything: in the app, Profile → Settings → Delete Account permanently erases your account and all synced data from our servers.
- Access or export: email us and we'll send you a copy of your data.
- Correct: most data is editable in the app; email us for anything that isn't.
- Withdraw permissions: revoke camera, photo or notification access in iOS Settings at any time. The app keeps working; the features needing that access stop.
- If you're in the EEA or UK you also have the rights to object, to restrict processing, and to data portability, and you may lodge a complaint with your local supervisory authority. If you're in California you have the rights to know, delete, correct and opt out under the CCPA/CPRA, and we will not discriminate against you for exercising them. We honour all of these requests regardless of where you live.
Retention
We keep your synced data for as long as your account exists. Deleting your account removes it from our production systems immediately and from backups within 30 days. Deletion requests sent by email are completed within 30 days. Data that never left your device is gone the moment you delete the app.
Security
Data in transit is encrypted with TLS, and data on our servers is encrypted at rest. Access is restricted per-user at the database level, so one account cannot read another's rows. Data on your device is protected by iOS sandboxing, encryption at rest, and your passcode or Face ID.
Children
Glowera is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has created an account, email us and we'll delete it.
Changes
If we materially change how we handle your data, we'll update this page and note it in the app before the change takes effect.