Privacy Policy
Last updated: 28 August 2026
This Privacy Policy explains how Teddy App Labs (“we”, “us”, “our”) collects, uses, and protects information when you use GlowKit (the “App”). GlowKit is a private AI skin routine and progress tracker for cosmetic, non-medical self-care. We designed it so that trust comes first — especially around your scan photos.
The short version. Free users can complete one guided scan with scan-quality feedback and a locked result preview. GlowKit Pro reveals the full result and ongoing progress tools. Full cloud analysis sends the photo you choose to GlowKit's cloud service and may share it with OpenRouter and OpenAI as AI vision providers solely to create your cosmetic scan result. New scan photos are stored durably only on your device; derived results can sync privately through your GlowKit cloud account in Cloudflare D1. Apple Sign In can link that account for recovery and cross-device continuity. Glow Profile answers, daily check-ins, and reminder preferences stay on your device. My Shelf product names sync privately under your own account so your shelf survives a reinstall and follows you to a new device. Optional UV uses location only after you ask for it and does not cache raw coordinates. Glow Coach refuses medical questions on-device; other questions you type are sent to answer them. We do not sell your photos, show them in advertising, or use them to train AI models. You can delete app-owned local data from inside the App and request account data deletion at any time.
1. Information we collect
We aim to collect as little as possible. Depending on how you use the App, this may include:
- Photos you scan. Selfies or images you choose to analyze. The photo may be saved locally on your device for scan history. Full cloud analysis transmits it only for the requested processing described in Section 2; GlowKit creates no new durable cloud scan-photo copy.
- Scan results. Your GlowScore, signal breakdown, product guide, routine, locked reveal state, and progress history, stored locally and, for cloud-backed account progress, in Cloudflare D1.
- Account identifiers. GlowKit starts with a private Worker-issued cloud identity for sync. Apple Sign In can link that identity if you choose to make it recoverable across installs and devices.
- Purchase information. Your subscription, trial, restore, and Pro entitlement status, managed through Apple and RevenueCat. We do not receive or store your full payment card details.
- Local personalization. Bounded Glow Profile choices, seven-day program state, daily check-ins, routine edits, and reminder preferences stay on your device.
- My Shelf products. The product name you type plus the category, routine placement, and fragrance label you pick. These are stored on your device and mirrored through the Worker to Cloudflare D1 under your own account so your shelf survives a reinstall and appears on any device signed in to that account. Only you can read them; GlowKit does not look them up in any barcode, retailer, price, or ingredient database, does not send them to AI providers or advertisers, and never uses product names as analytics properties.
- Optional UV context. After you ask for current-area context, a location — or a city you enter — is sent to Apple services to fulfill the request. GlowKit does not cache raw coordinates. It keeps the returned place label, UV snapshot, provider attribution, and expiry locally for about 90 minutes.
- Glow Coach. Text you type is first checked on-device: anything reading as a symptom, reaction, or other medical question is refused there and never sent. Other questions are sent as written, with the recent turns of that conversation, through GlowKit's Worker with no-store handling, alongside coarse enum/count context. When you ask why your radiance changed, the request also includes your own already-revealed scan results from about the last three months — the glow score, program day, and calendar date of each — so the answer can cite your real readings; the other two questions do not include them. Images, scan IDs, product names, and clock times are not included. Glow Coach can propose a change to your own plan — a routine step, a reminder time, or a My Shelf entry — but it never makes one: the proposal appears as a card in the conversation and is written, on your device only, if you tap Apply.
- Product interaction analytics. Coarse app events such as v2 step ID, plan/baseline funnel state, bounded source/count buckets, paywall source, purchase or restore outcome bucket, check-in/weekly-loop state, and delete-data outcome. A random persistent app analytics identifier associates these events over time and is supplied to RevenueCat as the current PostHog integration attribute. It is not a GlowKit cloud account ID, Apple identity, email, or advertising identifier, but it links analytics across PostHog and RevenueCat. These events do not include photos, profile or check-in answer values, product names, typed Coach text, raw GlowScore, signal values, scan IDs, GlowKit cloud account IDs, Apple identity, email, free-form text, or ad identifiers.
- Website analytics. Public website page views, approximate region, browser/device category, referrer information, and privacy-safe App Store or product-page click events from glowkit.org, collected through Google Analytics in consent mode. Analytics cookies remain denied by default; the website writes them only if you choose Allow analytics. The tag does not send photos, scan results, GlowScore, scan IDs, account identifiers, emails, support text, or app identifiers.
- Diagnostic data. Crash, performance, and error information used to keep the App reliable and separate test/debug traffic from production usage.
- Support communications. If you email us, we keep your message and contact details to respond.
2. How we handle your photos
GlowKit has two scan paths:
- Free locked preview. Free users can complete one guided scan. The preview is generated on device and saved locally as a locked result unless you unlock Pro.
- Full cloud analysis. When full analysis runs, your selected photo is transmitted securely to GlowKit's cloud service and may be shared with OpenRouter and OpenAI as AI vision providers solely to generate your GlowScore, five visible signals, product guide, routine, and progress record.
- On-device photo durability. New prepared scan photos are stored durably only on your device. GlowKit does not create new D1 or R2 scan-photo objects.
- Optional account recovery. Apple Sign In can link your GlowKit cloud account so synced metadata and derived results can follow your account across installs and devices.
We never sell your photos, share them with advertisers, or use them to train machine-learning models. New saved scan photos remain private to your device and can be deleted through the local data flow.
3. Face data and AI providers
GlowKit does not collect Face ID templates, biometric identifiers, faceprints, or identity verification data. The only face data GlowKit collects is the selfie or face photo you choose for a scan and the cosmetic visual signals derived from that photo, such as GlowScore, clarity, hydration, texture, even tone, radiance, product guidance, and routine suggestions.
We use this face data only to provide the scan you request, improve scan-quality feedback, create cosmetic and non-medical results, save your private progress history, and support account recovery or sync if you link Apple Sign In.
For full Pro cloud analysis, your selected photo is sent to GlowKit's Cloudflare Worker and may be shared with OpenRouter and OpenAI as AI vision providers. They receive the image and prompt needed to return the cosmetic analysis and act as service providers for this purpose. OpenRouter requests are configured to prefer zero-data-retention routes where available. OpenAI API inputs and outputs are not used to train OpenAI models by default and may be retained by OpenAI for a limited abuse-monitoring period under OpenAI's API terms. GlowKit does not authorize any AI provider to use scan photos for advertising or model training.
New scan photos are stored durably only on your device; scan metadata and derived results
may sync through the Worker to Cloudflare D1. The Worker creates no new R2
scan-photo objects. R2 is retained for recoverable account-deletion state and defensive
cleanup under the current V4 identity. Old unlinked private/ data from retired
builds is handled separately by the owner. Local scan photos and results remain on your device until
you delete them in the App or remove the App; synced metadata and results remain until
account deletion or an applicable deletion request completes.
To prevent automated anonymous-account creation, GlowKit sends a random device-local app identifier stored in iOS Keychain and necessarily receives the request network address. The identifier persists across sign-out, local data reset, and relaunch and may survive app reinstallation. The Worker does not write either raw value to D1; D1 keeps only separate server-HMAC values and the attempt time. The most recent 60 seconds enforce at most 3 account mints per device-local identifier and 30 per network. Rows become eligible for deletion after five minutes and are removed by an every-minute bounded scheduled cleanup or a later auth request; a service failure or backlog can delay cleanup. This security ledger is not used for analytics, advertising, or cross-app tracking.
4. How we use information
We use information only to operate and improve GlowKit, specifically to:
- Run scan-quality checks and create your locked scan preview or full Pro result.
- Generate your GlowScore, 5-signal breakdown, product guide, and explainable routine.
- Show your progress trend, scan history, and before/after comparisons.
- Build your local seven-day plan, save one editable daily check-in, keep your reminder choices, and keep your manual shelf available across your own devices.
- Provide optional UV context and bounded Pro cosmetic Coach guidance when you request them.
- Manage your subscription and restore-purchase requests, and measure purchase/restore conversion and reliability.
- Understand activation, scan reliability, paywall conversion, and privacy-control usage through coarse product analytics.
- Understand which public website pages are useful through consent-mode website analytics.
- Maintain reliability, prevent abuse, separate debug/test traffic, and fix problems.
- Respond to your support requests.
5. Sharing & service providers
We do not sell your personal information. We share data only with service providers who help us run the App, and only as needed to provide the service. These may include:
- OpenRouter and OpenAI, which may perform the AI vision analysis described above for full Pro cloud scans and may answer a no-store Glow Coach request containing a bounded intent, coarse context, and — for the radiance question only — your own scan scores from about the last three months with their program days and calendar dates.
- Cloudflare, which provides Worker hosting, D1 account data storage, and R2 storage for recoverable deletion state and defensive cleanup under the current V4 identity. Any old unlinked
private/data is a separate owner-managed retirement task. - Apple, which processes payments, manages App Store subscriptions, may provide OS-level diagnostics, and fulfills optional WeatherKit/location or city-geocoding requests.
- RevenueCat, which manages Pro entitlements, restore status, and subscription access. GlowKit supplies the persistent random app analytics identifier as the current PostHog integration attribute so purchase/restore outcomes can be joined for analytics.
- PostHog Cloud US, which provides product interaction analytics dashboards for coarse app events associated over time by that persistent random app analytics identifier.
- Google Analytics, which provides website traffic analytics for glowkit.org in consent mode. Ad storage, ad user data, ad personalization, and analytics storage are denied by default.
- Diagnostics providers, which help us understand crashes, performance, and errors.
These providers are bound by contractual obligations to protect your information and use it only for the services they provide to us. We may also disclose information if required by law or to protect rights and safety.
6. Data retention
Local scan photos, scan results, routines, Glow Profile, seven-day programs, check-ins, reminder choices, and history remain on your device until you delete them in the App or remove the App. My Shelf is kept both on your device and under your account until you delete the product, choose Delete GlowKit app data, or request account data deletion; a deleted product leaves a removal marker with its name cleared for up to 60 days so your other devices stop showing it. GlowKit does not cache raw UV coordinates; the returned snapshot and place label expire after about 90 minutes. Coach conversations are kept on your device until you delete them or choose Delete GlowKit app data, and GlowKit retains no server-side conversation; to keep per-account Coach request limits enforceable we do keep a server-side record of each request's time, its bounded intent category, and a one-way hash of your account reference — never your wording, the answer, or your raw account id — and only about a day of that history is used before older entries are removed. The independent anonymous-auth security ledger keeps only HMAC device-local-identifier and network subjects plus attempt times. Rows become deletion-eligible after five minutes and are removed by the bounded cleanup described above. Because the ledger exists before a GlowKit account is created and has no user link, account deletion cannot identify or immediately clear a particular row, does not reset that short abuse-prevention window, and does not rotate the separate Keychain identifier. Cloud-synced scan metadata, derived results, and account history remain available until you request account data deletion. AI providers process scan photos to return the requested result; GlowKit does not authorize them to use scan photos for advertising or model training. Purchase records are retained by Apple and RevenueCat under their policies. Product interaction analytics, website analytics, support emails, and diagnostics are kept only as long as needed for the purposes described above, then deleted or aggregated. In-app account deletion removes this device's local app analytics identifier and clears the current RevenueCat PostHog join attribute. It does not delete or rewrite historical PostHog or RevenueCat analytics/subscription events; those follow the disclosed retention practices and may remain linked.
7. Your choices & rights
- Delete GlowKit app data. Settings → Privacy & data → Delete GlowKit app data immediately clears the listed local scans/photos and results, routine edits/checks, Glow Profile, programs, daily check-ins, My Shelf, GlowKit reminder schedules/preferences, cached UV context, app preferences, the free-preview marker, and anonymous analytics/funnel state. For a signed-in account it durably queues deletion of that current account's synced Shelf and routine; the cloud purge completes only while a session for that exact account is available, and ordinary logout cancels a pending purge to avoid cross-account deletion. This control does not delete or unlink the account, erase an App Store purchase, cancel a subscription, or rotate the separate Keychain abuse-prevention identifier.
- Delete your GlowKit account. In version 4.0, the account-deletion service is active. Settings → Privacy & data → Delete GlowKit account deletes the authenticated identity, its app-owned Cloudflare data, and the listed local feature data after server confirmation; attempts Apple-token revocation when Apple is linked; and supports retry/recovery if interrupted. It removes this device's local app analytics identifier and clears the current RevenueCat PostHog join attribute, but it does not delete or rewrite historical PostHog or RevenueCat analytics/subscription events. Those events follow the disclosed retention practices and may remain linked. It does not cancel Apple billing or erase Apple's purchase history; eligible purchases remain restorable. You may also contact us to exercise an applicable deletion right.
- Access & correction. You may request a copy of, or correction to, the personal information we hold about you.
- Website analytics choice. You can allow analytics cookies, keep measurement cookieless with Only necessary, or change the choice later from the Analytics choices control on the website. Advertising storage, ad user data, and ad personalization remain denied in either case.
- Withdraw consent. You can stop scanning at any time; without photos, no new analysis takes place. Optional location and notification permissions can be withdrawn in iOS Settings without blocking independent GlowKit features.
- Regional rights. Depending on where you live (for example under GDPR or the CCPA), you may have additional rights, including to erasure or to object to certain processing.
To exercise any of these rights, contact us at turhan@teddyapplabs.com.
Related pages
If you want the practical version of how GlowKit works alongside this policy, start with these pages:
Support and scanning tips
See setup help, restore guidance, better-scan tips, and contact details in one place.
Why your skin looks different in every selfie
Understand the lighting and angle variables that affect cosmetic progress photos.
Browse the full GlowKit guides library for more cosmetic, non-medical reading on product decisions and steadier progress tracking.
8. Security
We use industry-standard safeguards, including encryption in transit, to protect your information. No method of transmission or storage is completely secure, but we work to protect your data and limit what we collect in the first place.
9. Children
GlowKit is not directed to children under 13 (or the minimum age required in your region). We do not knowingly collect personal information from children. If you believe a child has provided us with information, please contact us so we can remove it.
10. International users
We may process and store information in countries other than your own. Where we transfer data internationally, we take steps to ensure it receives an appropriate level of protection consistent with this policy and applicable law.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the App. Continued use of GlowKit after an update means you accept the revised policy.
12. Contact us
Questions about privacy? Reach our team at turhan@teddyapplabs.com. For general help, see our Support page.
Teddy App Labs · GlowKit (bundle ID com.teddyapplabs.glowkit) · glowkit.org
A note on health. GlowKit provides general wellness and cosmetic insight only. It is not a medical device and does not diagnose, treat, or cure any condition. See our Terms of Use for details.