Data Safety
Transparency about your data — last updated: March 31, 2026
This page provides a clear summary of the data GlowAI collects, shares, and how it is protected. It mirrors the information declared in our Google Play Data Safety section and Apple App Privacy labels.
Data Collected
Personal Information
Photos & Media
Health & Fitness Data
Financial Information
Device & App Data
Consent & Audit Records
Data Shared with Third Parties
GlowAI shares data with the following processors strictly for providing services. We do not sell your data.
Data: Facial photos (EXIF stripped, no name/email attached)
Purpose: Skin analysis scoring, mole ABCDE assessment
Retention: Not stored by Google — processed and discarded
Data: Facial photos (EXIF stripped)
Purpose: Aging simulation generation
Retention: Processed and discarded — results stored by GlowAI for 30 days
Data: User ID, subscription events, product IDs
Purpose: Subscription lifecycle management across App Store and Google Play
Retention: Per RevenueCat retention policy
Data: All user data (encrypted at rest)
Purpose: Database hosting, authentication, file storage
Retention: Until account deletion + grace period
Data: Push notification tokens, device platform
Purpose: Push notification delivery
Retention: Until token deactivated
Data: Request metadata, server logs
Purpose: Application hosting and delivery
Retention: Per Vercel retention policy
Security Practices
All data transmitted between your device and our servers uses HTTPS/TLS encryption.
All data stored in our database and file storage is encrypted at rest.
Location and device metadata is automatically removed from all uploaded photos before processing.
Your name, email, and account details are never sent to AI processors — only the photo itself.
Database policies enforce that each user can only access their own data.
Passwords are hashed using bcrypt. Sessions use short-lived JWTs with automatic refresh.
Data Deletion
You can request deletion of your account and all associated data at any time:
- In-app: Go to Privacy & Data settings and tap "Request Account Deletion"
- On web: Visit your Privacy Dashboard and use the "Delete My Account" feature
- By email: Send a request to privacy@glowai.app
Deletion requests include a 30-day grace period during which you can cancel the request. After the grace period, all data is permanently and irreversibly deleted, except where retention is required by law (e.g., payment records for tax purposes).
Related legal documents: