Privacy policy

GlowMinder looks at your face and asks about your health. That earns you a plain description of what happens next, so this policy is written to be read rather than survived.

Last updated: 26 August 2026

The short version

There is no sign up, so we never learn your name unless you type it in, and never your email. Your skin photos are sent to an AI provider for analysis and are not kept afterwards. Your skin profile, health flags, scan results, and routine live on our servers. Your shelf, your saved product checks, your chat with Glow, and your daily water log stay on your phone. You can delete everything from inside the app in one tap, and it happens immediately.

GlowMinder is not medical advice

GlowMinder gives skincare and wellness guidance, built with a dermatologist and generated by AI from the information you give us. It does not diagnose conditions, and it is not a substitute for professional medical, dermatological, or pharmaceutical advice. If something on your skin is painful, spreading, bleeding, changing quickly, or simply worrying you, see a dermatologist or a doctor. Never delay getting medical care because of something you read in this app.

1.Who we are

GlowMinder is a skincare and wellness app published by Twozed Ltd, registered in England and Wales (company number 12329369), Office 12 Initial Business Centre, Wilson Business Park, Manchester M40 8WN, United Kingdom. In data protection terms we are the controller of the personal data described here.

The quickest way to reach us is the form on our support page. For privacy specifically, email privacy@glowminder.app.

2.You do not have an account

GlowMinder has no sign up, no password, and no email login. The first time you open the app it creates an anonymous identity for that device and everything you do is attached to it. We do not know who you are, and we cannot connect your data to any other service you use.

Two consequences worth understanding:

  • Your data is tied to one device. If you delete the app, reset your data, or move to a new phone, you start fresh and the old profile cannot be recovered or transferred.
  • Because we hold no email address for you, we cannot identify you from an email you send us. Deletion and data requests are therefore handled inside the app, where your identity is already proven. See section 9.

3.What we collect, and why

Everything below comes from something you actively do in the app. There is no background collection, no contact list access, no advertising identifier, and no third party tracking SDK.

Skin scan photos. When you run a skin scan you take one to three photos of your face. They are sent to our AI provider for analysis and are not stored on our servers or in the app afterwards. What we keep is the result: your skin type, the concerns detected, how severe each one is, which areas of the face they affect, and a written summary. See section 5 for the full detail on photos.

Product photos. When you check a product, the photo of the label goes to our AI provider so the brand, product name, and ingredient list can be read off it. We keep the extracted text, not the photo.

Your skin and lifestyle profile. What you answer during setup and can edit later: an optional first name, your age, gender, country and city, skin type, the concerns you want to work on and how severe they are, your routine experience, how complex a routine you want, the products you already use, the supplements you take and any halal, vegan, gluten free, or acne safe filters you want applied, your water goal, and your typical sleep.

Health flags. Whether you are pregnant, breastfeeding, trying to conceive, taking acne medication (and its name, if you give it), and whether you use hormonal birth control. This is health data and we treat it as sensitive. It exists for one reason: to keep ingredients that are not safe for you out of your routine and to flag them when you check a product. It is stored as a dated history so that a routine generated last month can be explained by the flags that were true at the time.

Coarse location.With your permission, your approximate coordinates, or the city you pick from a list if you would rather not share GPS. They are used to pre-fill your country and to fetch today’s real UV index and temperature so your SPF advice matches where you actually are. The coordinates are stored on your device only. When the app asks for weather, they are rounded to roughly one kilometre before they are sent, and we do not keep a history of where you have been.

Routine and tracking. Your generated routine, and which morning, evening, and supplement steps you tick off each day. This is what powers your streak and your progress view.

Scan history. Each completed scan is appended to a history of results (skin type, concerns, severities, areas, summary) so the app can show you how your skin is trending. Again: results only, never the photos.

Reminders.If you turn reminders on, we store the times and weekdays you chose, your timezone, and your device’s notification token. Today the reminders themselves are scheduled and fired by your phone’s operating system, so nothing about an individual reminder leaves your device.

Technical logs and product analytics. Every AI request is logged with your anonymous id, which task ran, which model answered, how many images were sent, token counts, cost, and whether it succeeded. That log exists so we can spot failures and control spend. Separately, a small set of product events (setup started, setup completed, paywall opened, purchase attempted, and so on) is recorded with your anonymous id, the app version, and the platform. There are no third party analytics scripts.

AI consent. When you agree to the AI notice before your first scan, we record the moment you agreed, the version of the notice, and a copy of the exact text you saw.

Purchases. Nothing yet. Paid plans are not switched on, so no purchase or billing data is collected today. See section 6.

4.What never leaves your phone

Several parts of the app are deliberately device only. We do not hold copies, we cannot read them, and they are lost if you reinstall the app. That is the trade we chose.

  • Your shelf.The products you add by hand, including any photos you take of them, which are written to the app’s private storage on your device.
  • Saved product checks.The history of your “should I buy this?” results.
  • Your conversations with Glow.The in-app assistant’s thread is stored on the device. Individual messages are sent to the AI provider to get an answer, along with recent turns for context, but the conversation itself is never saved on our servers.
  • Your daily water log. Only the goal you set is saved on our side, because your routine uses it. What you drank on a given day stays local.
  • Your profile picture and your weather coordinates.

5.Your photos, precisely

  • Photos are sent from your phone to whichever AI provider is handling the analysis, and the result comes back. They are never written to our database or file storage, and the app does not keep a copy in your photo library unless you took the picture there yourself.
  • We store a one way fingerprint (a SHA-256 hash) of each scan photo alongside its result. If you submit the exact same image again you get your saved result back instead of paying for a second analysis. A fingerprint is a fixed string of characters and cannot be turned back into a photo.
  • We do not use your photos to train AI models, and we do not permit our providers to train on them.
  • Providers may hold an input briefly for their own abuse monitoring under their own policies, which are linked in section 7. That retention is theirs, not ours, and is measured in days.

You are asked to agree to this before your first scan, and you can withdraw that agreement at any time under Me, then AI consent. Withdrawing turns the AI features off; the rest of the app keeps working.

6.AI, and what it means for you

Everything personalised in GlowMinder is AI generated

Your skin analysis, your product verdicts, your routine, and every reply from Glow are produced by large language models from your inputs. They are confident by nature and they can be wrong. Treat them as a well informed starting point, not a verdict, and check anything that matters with a professional.

The models run on third party infrastructure, never on our own hardware. Which provider handles a given request depends on our server side configuration and on which provider is available at that moment: if the first one fails, the request falls through to the next. All of them are listed in section 7 so the list stays true whichever one answers.

When we ask an AI provider about a product whose label we could not read, the provider runs a web search for that product’s ingredient list. Only the brand and product name are sent for that search. Nothing about you goes with it.

7.Who else receives your data

We do not sell your data, we run no advertising, and we share nothing with third parties for marketing. The companies below process data on our behalf so the app can work.

Supabase

Backend

Hosts our database, anonymous authentication, and the server functions that talk to the AI providers. Everything described in section 3 as stored on our servers is stored with Supabase.

Their privacy policy

OpenAI

AI provider

May receive your skin photos and product photos for analysis, and your skin profile as text, depending on which model in our chain handles the request.

Their privacy policy

Anthropic

AI provider

May receive your skin photos and product photos for analysis, your skin profile as text for routine generation and product verdicts, and the messages you send to Glow along with recent turns of that conversation.

Their privacy policy

Google

AI provider

Used as a fallback when another provider fails. May receive your skin photos, product photos, and your skin profile as text, depending on the task.

Their privacy policy

Open-Meteo

Weather and city lookup

Receives approximate coordinates, rounded to roughly one kilometre, to return today's UV index and temperature. When you search for your city during setup, your device contacts their geocoding service directly with the text you typed, which means they also see your device's IP address for that request. No account data, profile, or photo is ever sent.

Their privacy policy

Expo

App platform

Builds and distributes the app and delivers over the air updates. Holds the notification token for your device. Reminders are currently scheduled on your phone rather than sent through Expo's push service.

Their privacy policy

Apple and Google

App stores

Distribute the app and, once paid plans exist, will handle payment. Their own privacy terms apply to your relationship with them as the store.

RevenueCat

Subscriptions, not yet active

The subscription library is present in the app but is not configured, so no data reaches RevenueCat today. When paid plans launch it will receive your anonymous id and the purchase events belonging to it, never your skin data. This page will be updated before that happens.

Their privacy policy

We may also disclose data if the law requires it, or to protect our rights, safety, or property. If our business is ever sold or merged, your data may transfer with it, and we will say so here first.

8.Where your data lives, and how long

Data on our side is held in our Supabase project, encrypted in transit with TLS and at rest by the platform. Access to the production database is limited to the people who run GlowMinder, and row level security is enabled on the tables that hold user data so one anonymous identity cannot read another’s.

We are established in the United Kingdom, and several of the companies in section 7 are not. Our AI providers (OpenAI, Anthropic and Google) are based in the United States, and Supabase, Expo and Vercel process data outside the UK as well. Those transfers rely on the UK International Data Transfer Addendum to the European Commission’s standard contractual clauses, on the clauses themselves, or on an equivalent safeguard in each provider’s terms.

How long we keep things:

  • Your profile, health flags, scan results, routine, and completion history:for as long as your device’s identity exists. All of it is deleted the moment you delete your account.
  • Product analytics events: deleted automatically after 90 days.
  • The scan result cache (the photo fingerprints in section 5): kept while your account exists and deleted with it.
  • AI request logs: the record of which task ran, on which model, how many tokens it used and what it cost is kept indefinitely as an operational and billing record. When you delete your account it is cut loose from you and everything about you is stripped out of it: the link to your identity, the per-frame capture diagnostics from your photos, the classification of why a photo could not be read, and any provider error text. What is left describes our systems, not you.
  • Skin scan photos: nothing to keep. We never stored them.
  • Messages you send us through the website: kept while we are dealing with your question. If you later delete your account, the email address on any message linked to it is removed.
  • A deletion record: when an account is deleted we keep a dated log entry recording that a deletion happened, so we can prove we honoured it. It holds no skin data, no profile, and no photos.

9.Deleting everything

One tap, immediate, and all or nothing

Open the app, go to Me, and choose Delete account. Your profile, your health flags and their full dated history, your scan history, the cached fingerprints of your photos, your routine, your completion history, your consent record, your reminder settings and your notification token are all deleted from our servers immediately. Everything held on the device goes at the same moment: your shelf and its photos, your saved product checks, your conversation with Glow, your water log and your profile picture.

The erasure runs as a single database transaction. It either completes in full or changes nothing at all, so there is no state in which some of your data is gone and the rest survives. There is no waiting period, no email to confirm, and no way for us to undo it.

Afterwards the only record that still names you is the deletion log entry described in section 8, which exists so we can show the erasure happened. Everything we keep beyond that, the AI request logs and the funnel analytics, has been stripped of anything that identifies you or describes your skin. We verified this by searching every table in the database for a deleted account’s identifier.

Use the app. Because GlowMinder accounts are anonymous and hold no email address, nothing you submit on the web can be matched to your account automatically. The web form exists for people who have already uninstalled, and it opens a request that a person handles by hand rather than an erasure that happens on its own. If the app is still on your phone, the in-app option is the only route that erases you immediately and with certainty.

10.Your rights

We are a UK controller, so the UK GDPR and the Data Protection Act 2018 govern what we do with your data. Under them you have the right to access your data, correct it, receive a portable copy, object to or restrict how we use it, withdraw consent, and have it erased. If you are in the European Economic Area you hold the equivalent rights under the EU GDPR, and we apply them the same way.

In practice, the app is built so that most of these do not need us: everything we hold about you is what you entered and what your scans returned, all of it visible and editable in the app, and erasure is the one tap in section 9. If you want a copy of your data or want to exercise a right the app does not cover, write to privacy@glowminder.app from inside the app so we can tie the request to your identity. We will answer within one month.

If you think we have handled your data badly, please tell us first so we can fix it. You can also complain to the UK Information Commissioner's Office (ICO), which is our supervisory authority. If you are in the European Economic Area you may complain to your own national data protection authority instead.

11.Children

GlowMinder is built for people aged 13 and over, and the app will not let you continue setup with an age below 13. We do not knowingly collect data from anyone younger. If you believe a child has used the app and given us data, contact privacy@glowminder.app and we will delete it. Where local law sets a higher minimum age for consenting to this kind of processing, that higher age applies.

12.Changes to this policy

When our practices change, this page changes with them and the date at the top moves. If a change materially affects how your data is used, in particular anything to do with your photos, we will tell you in the app and ask for your agreement again where consent is the basis for it.

13.Contact

Privacy questions: privacy@glowminder.app. Anything else: the form on our support page, or hello@glowminder.app.