Privacy Policy
How we handle your data — on this website and in the Glowé app.
[square brackets] are placeholders and must be replaced with the
provider's actual information. This page is a carefully structured template but not legal advice — have it reviewed by a lawyer before publication.
1. Responsible Party
The responsible party under the General Data Protection Regulation (GDPR) is:
Doaa Attia (Sole Proprietorship)
Wilhelm-Diess-Weg 3a
94081 Fürstenzell, Germany
Email: Glowe.skinapp@gmail.com
Data Protection Officer: We are not required by law to appoint a data protection officer.
2. Quick Overview
- This website uses no cookies and includes no analytics, tracking, or advertising services. There is therefore no cookie banner.
- Fonts are delivered locally. There is no connection to Google Fonts or any other font CDN.
- Your skin images do not leave the purpose of analysis. They are not sold, not used for advertising, and not used to train public models.
- You can delete everything — individual scans or your entire account, directly in the app.
3. Data Processing on This Website
3.1 Server Log Files
When you access this website, the hosting provider automatically stores information in server log files that your browser transmits: page accessed, date and time, data transferred, referrer, browser type and version, operating system, and IP address in shortened form.
Purpose: technically flawless delivery, security, and defense against attacks.
Legal basis: Art. 6 (1) (f) GDPR — legitimate interest in secure operation.
Storage duration: [e.g. 7 days], thereafter automatic deletion.
3.2 Cookies and Tracking
This website uses no cookies, no local storage for analysis purposes, no pixels, and no third-party integrations. Consent under § 25 TDDG is therefore not required.
3.3 Contact via Email
If you write to us, we process your email address and message content to handle your inquiry.
Legal basis: Art. 6 (1) (b) GDPR (pre-contractual or contractual) or Art. 6 (1) (f) GDPR (processing general inquiries).
Storage duration: until the matter is fully resolved, then within statutory retention periods.
3.4 Links to Apple App Store
The download buttons are simple links. No data is transmitted to Apple until you actively click. After clicking, Apple's privacy policy applies.
4. Data Processing in the App
| Data Category | Purpose | Legal Basis |
|---|---|---|
| Account data (email or Apple Relay address, account ID) | Create account, login, assign your scans | Art. 6 (1) (b) GDPR |
| Skin images (selfies) and derived score values | Creation of your skin analysis and history | Art. 9 (2) (a) GDPR (explicit consent) |
| Routine data (checked steps, streak, reminder times) | Display and update of your 14-day plan | Art. 6 (1) (b) GDPR |
| Purchase and subscription data (receipt, expiration date, status) | Unlock Glowé Pro, restore purchases | Art. 6 (1) (b) GDPR |
| Crash and error diagnostics (device model, iOS version, stack trace) | Stability and bug fixes | Art. 6 (1) (f) GDPR |
| Push token (only when reminders are enabled) | Sending your routine reminders | Art. 6 (1) (a) GDPR (consent) |
We do not process payment data. Purchases run entirely through the Apple App Store; Apple only provides us with information about whether a subscription is active and an anonymous purchase identifier.
5. Skin Images as Health Data
Photos of your skin can provide insights into your health status and are therefore considered special category personal data under Art. 9 GDPR. We process them exclusively based on your explicit consent, which you provide before your first scan in the app and can revoke at any time with future effect.
Specifically, this means:
- Images are transmitted and stored encrypted.
- They are used exclusively to create your analysis and history.
- They are not sold, not shared with advertising networks, and not used to train general or public AI models.
- Use to improve our models only occurs if you separately and voluntarily agree to it in settings — consent is off by default, and withdrawal has no effect on your app access.
- You can delete any individual image and your entire account in the app.
6. Recipients and Data Processors
We use carefully selected service providers who process data on our behalf. All of them have data processing agreements in place under Art. 28 GDPR.
| Service Provider | Service | Location |
|---|---|---|
| Netlify, Inc. | Website delivery | USA / EU |
| Supabase (open-source PostgreSQL) | Accounts, scans, routine data | EU |
| Perfect Corp | Evaluation of skin images | USA |
| Apple Inc. | App distribution, payment processing, push delivery | USA / EU |
7. Transfers to Third Countries
When data is processed outside the EU or EEA, this only occurs if an adequacy decision from the EU Commission is in place (such as the EU-U.S. Data Privacy Framework for certified U.S. companies) or appropriate safeguards exist under Art. 46 GDPR — in particular the EU Commission's Standard Contractual Clauses, supplemented by technical measures such as encryption.
8. Storage Duration
- Server log files: [e.g. 7 days]
- Scans and score history: until your deletion or account deletion
- Account data: for the duration of your account; after deletion, backups roll out within 30 days
- Invoices and tax-relevant documents: 6 or 10 years under §§ 147 AO, 257 HGB
9. Your Rights
You have the following rights against us:
- Access to data stored about you (Art. 15 GDPR)
- Correction of inaccurate data (Art. 16 GDPR)
- Deletion (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability in a common format (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of given consent with future effect (Art. 7 (3) GDPR) — the lawfulness of processing up to that point remains unaffected
To exercise these rights, contact Glowe.skinapp@gmail.com. We respond within one month.
Independent of this, you have the right to lodge a complaint with a data protection authority, in particular in the EU member state where you reside or where you believe a violation has occurred (Art. 77 GDPR). Our competent supervisory authority is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Wagmüllerstraße 25
80538 Munich
Germany
10. Changes to This Policy
We update this privacy policy if our processing or the legal situation changes. For material changes, we notify you in advance in the app. The version published here always applies.