GLOWCHECK
Last updated: June 2025
GlowCheck (“we”, “us”, “our”) builds a beauty-first product discovery and safety app. We respect your privacy and built GlowCheck to collect the minimum data needed to deliver real ingredient analysis. This policy explains what we collect, why, and your rights.
1. The data we collect
We only collect what we need to make GlowCheck work:
•
Account info — if you choose to create an account: email and a hashed password. You can use the app fully in Guest Mode without an account.
•
Scan content — product photos, barcodes, and pasted ingredient lists you submit. These are processed to generate your safety analysis.
•
Pregnancy / breastfeeding lens setting — a local toggle that adjusts the analysis. We do not store medical history.
•
Purchase records — if you unlock a Full Analysis or buy a subscription: transaction ID and amount. Card data is handled by Apple, Google, and Stripe and never touches our servers.
•
Device info — anonymous device identifier (used to keep guest scan history attached to your phone) and crash logs.
2. What we do NOT collect
•
We do not collect contacts, location, or microphone data.
•
We do not sell your data to advertisers.
•
We do not run third-party ad SDKs.
•
We do not track you across other apps or websites.
3. How we use your data
•
To run scans — ingredient text is sent to our analysis engine (powered by Anthropic Claude) along with our toxicology rules to generate the Vibe Check verdict. No personally identifying info is included in the prompt.
•
To save your history — so you can re-open past scans.
•
To process payments — via Apple In-App Purchase (iOS), Google Play Billing (Android), or Stripe (web).
•
To improve safety accuracy — anonymized, aggregate ingredient lists may be used to refine the engine. Never tied to your identity.
4. Third parties we use
•
Anthropic (Claude) — ingredient text analysis. Anthropic does not train on data sent through their API.
•
Open Beauty Facts — public product database for barcode lookups. Read-only, no personal data shared.
•
Apple / Google / Stripe — payments only. They handle card data per their own privacy policies.
•
MongoDB Atlas — our encrypted database host.
5. Data retention
Scans and account data are retained while your account is active. Delete your account from Settings or by emailing us — we will remove your records within 30 days. Anonymous aggregate analytics may persist.
6. Your rights
You can:
•
Request a copy of your data.
•
Request deletion of your data.
•
Withdraw consent at any time by deleting the app.
•
Opt out of analytics in Settings → Privacy.
GDPR (EU), UK GDPR, and CCPA (California) residents have additional rights including non-discrimination for exercising privacy rights. Contact us to exercise any right.
7. Children’s privacy
GlowCheck is intended for users 13 and older. We do not knowingly collect data from children under 13. If you believe a child has provided data, contact us and we will delete it.
8. Security
We use HTTPS for all traffic, hashed passwords (bcrypt), and access controls on the database. No system is 100% secure — if a breach affects you, we will notify you within 72 hours where required by law.
9. Changes to this policy
We may update this policy. The “Last updated” date at the top will change. Material changes will be communicated in-app.
10. Contact
Questions, requests, or complaints? Email us — we usually reply within 2 business days.
Read our Safety & Data Disclaimer →