Legal

Privacy Policy

Last updated: 28 August 2026

This Privacy Policy explains how Teddy App Labs (“we”, “us”, “our”) collects, uses, and protects information when you use GlowKit (the “App”). GlowKit is a private AI skin routine and progress tracker for cosmetic, non-medical self-care. We designed it so that trust comes first — especially around your scan photos.

The short version. Free users can complete one guided scan with scan-quality feedback and a locked result preview. GlowKit Pro reveals the full result and ongoing progress tools. Full cloud analysis sends the photo you choose to GlowKit's cloud service and may share it with OpenRouter and OpenAI as AI vision providers solely to create your cosmetic scan result. New scan photos are stored durably only on your device; derived results can sync privately through your GlowKit cloud account in Cloudflare D1. Apple Sign In can link that account for recovery and cross-device continuity. Glow Profile answers, daily check-ins, and reminder preferences stay on your device. My Shelf product names sync privately under your own account so your shelf survives a reinstall and follows you to a new device. Optional UV uses location only after you ask for it and does not cache raw coordinates. Glow Coach refuses medical questions on-device; other questions you type are sent to answer them. We do not sell your photos, show them in advertising, or use them to train AI models. You can delete app-owned local data from inside the App and request account data deletion at any time.

1. Information we collect

We aim to collect as little as possible. Depending on how you use the App, this may include:

2. How we handle your photos

GlowKit has two scan paths:

We never sell your photos, share them with advertisers, or use them to train machine-learning models. New saved scan photos remain private to your device and can be deleted through the local data flow.

3. Face data and AI providers

GlowKit does not collect Face ID templates, biometric identifiers, faceprints, or identity verification data. The only face data GlowKit collects is the selfie or face photo you choose for a scan and the cosmetic visual signals derived from that photo, such as GlowScore, clarity, hydration, texture, even tone, radiance, product guidance, and routine suggestions.

We use this face data only to provide the scan you request, improve scan-quality feedback, create cosmetic and non-medical results, save your private progress history, and support account recovery or sync if you link Apple Sign In.

For full Pro cloud analysis, your selected photo is sent to GlowKit's Cloudflare Worker and may be shared with OpenRouter and OpenAI as AI vision providers. They receive the image and prompt needed to return the cosmetic analysis and act as service providers for this purpose. OpenRouter requests are configured to prefer zero-data-retention routes where available. OpenAI API inputs and outputs are not used to train OpenAI models by default and may be retained by OpenAI for a limited abuse-monitoring period under OpenAI's API terms. GlowKit does not authorize any AI provider to use scan photos for advertising or model training.

New scan photos are stored durably only on your device; scan metadata and derived results may sync through the Worker to Cloudflare D1. The Worker creates no new R2 scan-photo objects. R2 is retained for recoverable account-deletion state and defensive cleanup under the current V4 identity. Old unlinked private/ data from retired builds is handled separately by the owner. Local scan photos and results remain on your device until you delete them in the App or remove the App; synced metadata and results remain until account deletion or an applicable deletion request completes.

To prevent automated anonymous-account creation, GlowKit sends a random device-local app identifier stored in iOS Keychain and necessarily receives the request network address. The identifier persists across sign-out, local data reset, and relaunch and may survive app reinstallation. The Worker does not write either raw value to D1; D1 keeps only separate server-HMAC values and the attempt time. The most recent 60 seconds enforce at most 3 account mints per device-local identifier and 30 per network. Rows become eligible for deletion after five minutes and are removed by an every-minute bounded scheduled cleanup or a later auth request; a service failure or backlog can delay cleanup. This security ledger is not used for analytics, advertising, or cross-app tracking.

4. How we use information

We use information only to operate and improve GlowKit, specifically to:

5. Sharing & service providers

We do not sell your personal information. We share data only with service providers who help us run the App, and only as needed to provide the service. These may include:

These providers are bound by contractual obligations to protect your information and use it only for the services they provide to us. We may also disclose information if required by law or to protect rights and safety.

6. Data retention

Local scan photos, scan results, routines, Glow Profile, seven-day programs, check-ins, reminder choices, and history remain on your device until you delete them in the App or remove the App. My Shelf is kept both on your device and under your account until you delete the product, choose Delete GlowKit app data, or request account data deletion; a deleted product leaves a removal marker with its name cleared for up to 60 days so your other devices stop showing it. GlowKit does not cache raw UV coordinates; the returned snapshot and place label expire after about 90 minutes. Coach conversations are kept on your device until you delete them or choose Delete GlowKit app data, and GlowKit retains no server-side conversation; to keep per-account Coach request limits enforceable we do keep a server-side record of each request's time, its bounded intent category, and a one-way hash of your account reference — never your wording, the answer, or your raw account id — and only about a day of that history is used before older entries are removed. The independent anonymous-auth security ledger keeps only HMAC device-local-identifier and network subjects plus attempt times. Rows become deletion-eligible after five minutes and are removed by the bounded cleanup described above. Because the ledger exists before a GlowKit account is created and has no user link, account deletion cannot identify or immediately clear a particular row, does not reset that short abuse-prevention window, and does not rotate the separate Keychain identifier. Cloud-synced scan metadata, derived results, and account history remain available until you request account data deletion. AI providers process scan photos to return the requested result; GlowKit does not authorize them to use scan photos for advertising or model training. Purchase records are retained by Apple and RevenueCat under their policies. Product interaction analytics, website analytics, support emails, and diagnostics are kept only as long as needed for the purposes described above, then deleted or aggregated. In-app account deletion removes this device's local app analytics identifier and clears the current RevenueCat PostHog join attribute. It does not delete or rewrite historical PostHog or RevenueCat analytics/subscription events; those follow the disclosed retention practices and may remain linked.

7. Your choices & rights

To exercise any of these rights, contact us at turhan@teddyapplabs.com.

If you want the practical version of how GlowKit works alongside this policy, start with these pages:

Browse the full GlowKit guides library for more cosmetic, non-medical reading on product decisions and steadier progress tracking.

8. Security

We use industry-standard safeguards, including encryption in transit, to protect your information. No method of transmission or storage is completely secure, but we work to protect your data and limit what we collect in the first place.

9. Children

GlowKit is not directed to children under 13 (or the minimum age required in your region). We do not knowingly collect personal information from children. If you believe a child has provided us with information, please contact us so we can remove it.

10. International users

We may process and store information in countries other than your own. Where we transfer data internationally, we take steps to ensure it receives an appropriate level of protection consistent with this policy and applicable law.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the App. Continued use of GlowKit after an update means you accept the revised policy.

12. Contact us

Questions about privacy? Reach our team at turhan@teddyapplabs.com. For general help, see our Support page.

Teddy App Labs · GlowKit (bundle ID com.teddyapplabs.glowkit) · glowkit.org

A note on health. GlowKit provides general wellness and cosmetic insight only. It is not a medical device and does not diagnose, treat, or cure any condition. See our Terms of Use for details.