Legal

Privacy Policy

Last updated: 20 June 2026

This Privacy Policy explains how Teddy App Labs (“we”, “us”, “our”) collects, uses, and protects information when you use GlowKit (the “App”). GlowKit is a private AI skin routine and progress tracker for cosmetic, non-medical self-care. We designed it so that trust comes first — especially around your scan photos.

The short version. Free users can complete one guided scan with scan-quality feedback and a locked result preview. GlowKit Pro reveals the full result and ongoing progress tools. Full cloud analysis sends the photo you choose to GlowKit's cloud service and may share it with OpenRouter and OpenAI as AI vision providers solely to create your cosmetic scan result. The prepared scan photo and cosmetic result can be stored privately under your Supabase account so progress can sync. Apple Sign In can link that account for recovery and cross-device continuity. We do not sell your photos, show them in advertising, or use them to train AI models. You can delete local scan history from inside the App and request account data deletion at any time.

1. Information we collect

We aim to collect as little as possible. Depending on how you use the App, this may include:

2. How we handle your photos

GlowKit has two scan paths:

We never sell your photos, share them with advertisers, or use them to train machine-learning models. Saved scan photos are private to your device or account and can be deleted through the local or account data flow.

3. Face data and AI providers

GlowKit does not collect Face ID templates, biometric identifiers, faceprints, or identity verification data. The only face data GlowKit collects is the selfie or face photo you choose for a scan and the cosmetic visual signals derived from that photo, such as GlowScore, clarity, hydration, texture, even tone, radiance, product guidance, and routine suggestions.

We use this face data only to provide the scan you request, improve scan-quality feedback, create cosmetic and non-medical results, save your private progress history, and support account recovery or sync if you link Apple Sign In.

For full Pro cloud analysis, your selected photo is sent to GlowKit's Cloudflare Worker and may be shared with OpenRouter and OpenAI as AI vision providers. They receive the image and prompt needed to return the cosmetic analysis and act as service providers for this purpose. OpenRouter requests are configured to prefer zero-data-retention routes where available. OpenAI API inputs and outputs are not used to train OpenAI models by default and may be retained by OpenAI for a limited abuse-monitoring period under OpenAI's API terms. GlowKit does not authorize any AI provider to use scan photos for advertising or model training.

Synced scan photos are stored privately in Cloudflare R2; scan metadata and derived results are stored in Supabase. Local scan photos and results remain on your device until you delete them in the App or remove the App. Cloud-synced photos, metadata, and results remain until you request account data deletion.

4. How we use information

We use information only to operate and improve GlowKit, specifically to:

5. Sharing & service providers

We do not sell your personal information. We share data only with service providers who help us run the App, and only as needed to provide the service. These may include:

These providers are bound by contractual obligations to protect your information and use it only for the services they provide to us. We may also disclose information if required by law or to protect rights and safety.

6. Data retention

Local scan photos, scan results, routines, and history remain on your device until you delete them in the App or remove the App. Cloud-synced scan photos, scan metadata, and account history remain available until you request account data deletion. AI providers process scan photos to return the requested result; GlowKit does not authorize them to use scan photos for advertising or model training. Purchase records are retained by Apple and RevenueCat under their policies. Product interaction analytics, support emails, and diagnostics are kept only as long as needed for the purposes described above, then deleted or aggregated.

7. Your choices & rights

To exercise any of these rights, contact us at [email protected].

8. Security

We use industry-standard safeguards, including encryption in transit, to protect your information. No method of transmission or storage is completely secure, but we work to protect your data and limit what we collect in the first place.

9. Children

GlowKit is not directed to children under 13 (or the minimum age required in your region). We do not knowingly collect personal information from children. If you believe a child has provided us with information, please contact us so we can remove it.

10. International users

We may process and store information in countries other than your own. Where we transfer data internationally, we take steps to ensure it receives an appropriate level of protection consistent with this policy and applicable law.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the App. Continued use of GlowKit after an update means you accept the revised policy.

12. Contact us

Questions about privacy? Reach our team at [email protected]. For general help, see our Support page.

Teddy App Labs · GlowKit (bundle ID com.teddyapplabs.glowkit) · glowkit.org

A note on health. GlowKit provides general wellness and cosmetic insight only. It is not a medical device and does not diagnose, treat, or cure any condition. See our Terms of Use for details.