← Back to Glow

Glow — Privacy Policy

Last updated 22 September 2026

Glow is a private diary for your skin. This page explains exactly what it keeps, where that lives, who else can ever see it, and how to get rid of it. It is written to be read, not skimmed past.

Who we are

Glow is made by Mina Khan, an independent developer in Columbia, Maryland, USA. There is no company behind it and no team with access to your account. If you have a question about your data, or you want a copy of it or want it deleted, email info@glowskin.health and you will be replying to the person who built the app.

The short version

What Glow collects, and why

Your account

What you tell Glow about your skin

What you record day to day

What Glow generates for you

Housekeeping

What Glow does not collect

No device location. No contacts. No Apple Health data. No advertising identifier. No browsing history. There is no analytics SDK, no crash-reporting SDK and no advertising SDK in the app at all. Glow does not know which screens you spend time on.

Your photos and skin notes are the sensitive part

Face photos and what you write about your skin are the most personal things in Glow, and they are treated that way.

Photos are uploaded to a private storage area. They are not on the public internet and cannot be reached without a temporary link the app requests for you, and the storage rule that governs them checks the account ID on every read.

Being precise about those links, because it matters: a link is a plain web address with a time limit and no sign-in attached, so while it is alive it would work for anyone holding it. Your own links last 24 hours. A link made so a provider you are sharing with can see a photo lasts one hour. Glow never puts one in an email, a message or a page address.

Your notes, treatments, routine, photos and the AI descriptions written about those photos are visible to you and to nobody else, unless you deliberately connect a provider and turn on the specific items you want them to see. That includes the photos: there is a switch for them, it starts off, and nothing shows a provider a photo of yours until you turn it on.

Sharing with a provider

If your aesthetician, nurse or clinic uses Glow for Providers, they have a code that looks like GLOW-MINA. Here is exactly what happens if you use it.

One thing travels the other way. A provider you are connected to can write pre-care and post-care notes for a treatment of yours. Those notes are filed to your account and shown to you in the app alongside that treatment, and they take precedence over the general guidance Glow writes. Glow is not a messaging service, though, so anything urgent is still worth hearing from your provider directly.

There is one more thing a provider can ask for: a plain-language summary of what you have shared with them. It is built only from the items you switched on for them — your routine, your diary notes, your treatments — and never from your photographs or the descriptions written about them. There is no button for it in the provider app yet, but the feature is live on Glow's servers, so treat it as something that can happen rather than something that cannot. Each summary is filed to your account as well as theirs, and you are entitled to every one written about you; until the app has a screen for them, email and ask, and you will be sent them.

If you are a provider

Everything above is written for the person keeping the diary. If you are the aesthetician, nurse or clinic on the other side of it, this is what Glow holds about you.

The basis for holding all of that is the contract with you as a customer of Glow for Providers. It is kept while your account exists and goes when you delete your account, by the in-app button or by email. A practice with clients still connected cannot be deleted, because only a client can end a connection: the app tells you so and names what has to happen first. What you can see of a client is never yours to keep, and the Terms of Use set out what you may and may not do with it.

The AI, and what leaves Glow

Glow uses OpenAI to do the writing and describing. Requests go to the OpenAI API from Glow's servers, not from your phone. OpenAI's API terms state that they do not use data sent through the API to train their models, and that they hold it for a limited period to watch for abuse before deleting it.

There is a second copy, and you should know about it rather than find out. Glow's requests are made in a way that leaves them stored in Glow's own OpenAI project, where they can be read back in that account's logs. A photo sent to be described sits there too. Only Mina can open that account, nothing in it is used for anything except working out why the app got something wrong, and it is covered by the same deletion request as everything else.

This is what gets sent, and when:

Turning it off

Open Profile → Privacy & data and switch off AI photo observations. From then on no photo of yours is sent anywhere. The server checks this setting on every request and refuses if it is off, so it is not just a setting on your phone. Your photos stay in your diary either way. The same screen has a switch for product recommendations.

One thing to know about the timing. The switch starts in the on position on a new account, not off, and the setup step asks for the description as soon as it opens. So if you would rather nothing of your face was ever sent, the moment to act is before then: photos are optional and can be skipped entirely, or you can turn the switch off on the photo step. Once the observations step has opened with a photo in place, that one request has already gone.

The assistant, the plan and the Learn feed are features you choose to open. If you do not use them, nothing goes out for them.

What the AI does and does not do

Glow describes what is visible in a photograph. It will say something like "visible redness across the cheeks". It will not tell you that you have rosacea, acne, melasma or anything else, because it is not qualified to and it is not allowed to. It never produces a score, a grade or a percentage. It never tells you that you need a treatment. When the picture is too dark or too blurry to judge something, it says so instead of guessing. Those rules are enforced on Glow's servers, not just requested of the model: any sentence that breaks them is thrown away before it reaches you.

Glow is not medical advice and is not a substitute for a licensed professional. If something about your skin worries you, see one.

Where your data is stored, and for how long

Everything is stored with Supabase, in their US West (Oregon) region in the United States. If you are outside the US, your data is stored in the US.

Two other services see a narrow slice. Apple handles sign-in and takes the payment, so Apple knows you subscribe to Glow; we never see your card. RevenueCat receives the subscription status from Apple and passes it to Glow so the app knows whether to let you in. What RevenueCat holds is an account identifier and whether the subscription is active — no photographs, no diary, nothing about your skin.

Glow keeps what you record for as long as your account exists, because a skin diary is only useful if it remembers. There is no automatic clear-out and nothing expires on its own, apart from a cache of product information, which is about products rather than about you.

If you stop using Glow and want everything gone, you can delete your account in the app, or email and ask. Nothing is deleted just because a subscription lapses, so that your diary is still there if you come back.

Deleting your data

To delete your account, open Profile → Privacy & data and press "Delete my account and all my data". You type the word delete to confirm, and then it goes: your sign-in account, your profile and skin profile, your routine, your check-ins, your diary notes, your treatments, the AI descriptions, your conversations with the assistant, your usage counts, any provider connections and the care plans filed to you, and the photo files themselves. The photo files live in separate storage from the rest, so they are removed as their own step first, and the app checks that the folder is empty before anything else is touched. It happens while you wait rather than within 30 days, nothing is kept back, and it cannot be undone.

If you signed in with Apple, deleting your account also tells Apple to unlink Glow from your Apple account, so Glow stops appearing under Settings → Apple Account → Sign in with Apple. If Apple cannot be reached at that moment your account is still deleted — your deletion is never held up by someone else's servers — and you can remove Glow there yourself.

Two things worth knowing about that button. If the delete does not finish, nothing is deleted and you stay signed in, so you can press it again. And if you own a practice on Glow for Providers that still has clients connected, it stops and tells you — only a client can end a connection, so those have to go first.

"Clear this device" is a different button, on the same screen. It takes your routine, check-ins, notes, photos and treatments off the phone and signs you out, and leaves your account untouched: sign back in and it all comes back. Deleting a single photo or note works the same way — it goes from the phone, and the copy held on your account stays, because Glow only ever adds to the account, never removes from it. If you have no account at all, the only button you see is "Delete everything on this device", and that really is everything, because nothing was ever stored anywhere else.

If you would rather not use the button, or something goes wrong, email info@glowskin.health from the address you signed up with and ask for your account to be deleted. It is done by hand, finished within 30 days and normally much sooner, you get a note back confirming it, and it cannot be undone either.

To get a copy of your data, email the same address and ask. You will get a machine-readable file of everything on your account, including your photos, within 30 days. There is no charge.

Children

Glow is not for children under 13, and accounts should not be created for them. In the UK and the EU the age at which someone can agree to a service like this without a parent is set country by country, anywhere between 13 and 16, and 16 in several. If you are under that age where you live, a parent or guardian has to agree for you.

To be straight about how this is enforced today: it is not. Glow does not ask for a date of birth and does not block sign-up by age. The only age question is an optional age range during onboarding, and picking "Under 18" does not stop anything (it only stops the app writing about fine lines). If you are a parent or guardian and you believe a child under 13 has an account, email info@glowskin.health and it will be deleted, photographs included, without needing anything further from you.

No ads, no selling, no tracking

Glow has never shown an advert and does not plan to. Your data is not sold, rented or licensed to anyone, and it is not shared with data brokers, ad networks or social platforms. There is no analytics, advertising or tracking code in the app, and nothing you do in Glow is followed across other apps or sites.

The same goes for this page. It loads no fonts, scripts, images or anything else from another company's servers — you can check that in View Source — so reading it tells nobody but the host that you did.

Three companies handle your data because Glow could not run otherwise, and each only does the job it is given: Supabase stores it, OpenAI processes the text and images described above, and Resend delivers your sign-in email. Apple handles payment when subscriptions go live, and Glow never sees your card details. Nobody in that list is allowed to use your data for their own purposes.

The website

These pages and the web version of Glow are served by Vercel. There are no tracking or advertising cookies. If you sign in to the web version, your browser keeps your sign-in token in its own storage so that you stay signed in; signing out clears it. Vercel keeps standard server logs, which include IP addresses, for a short period for security and reliability.

If you are in the UK or the EU

UK and EU data protection law gives you the right to see the personal data held about you, to have mistakes corrected, to have it deleted, to limit or object to how it is used, and to take it elsewhere in a portable format. You can also withdraw consent at any time: for AI photo observations that is the switch in Privacy & data, and for provider sharing it is the switches in the Share tab.

The legal bases, named properly rather than waved at. For your account, your email address and the ordinary running of the app — the parts it cannot work without — Glow relies on Article 6(1)(b), performing the contract with you. Your face photos, your skin profile, any medications you list and the treatments you log are special category data under Article 9, and for those Glow relies on Article 9(2)(a), your explicit consent, given by choosing to enter them into a diary that exists for that purpose. Sending a photo to be described, and sharing anything with a provider, each rest on a further consent you give with a switch, and withdrawing either leaves the rest of the app working.

Two honest notes about those switches, because a consent you did not notice giving is not much of a consent. AI photo observations starts in the on position on a new account rather than off, so the way to prevent a description is to skip the photo or turn the switch off before you reach the observations step. Provider sharing works the other way round and is the model the rest should follow: a new connection starts with every switch off, and nothing is shared until you turn one on yourself.

Your data is stored in the United States. Transfers out of the UK and EU rely on the standard contractual clauses that Supabase and OpenAI have in place.

To exercise any of these rights, email info@glowskin.health. You get an answer within 30 days. If you are unhappy with the answer, you can complain to your national data protection authority, or to the Information Commissioner's Office in the UK.

If you are in California

California law gives you the right to know what personal information is collected about you and why, to get a copy of it, to have it deleted, to have inaccuracies corrected, and to limit the use of sensitive personal information. Your face photos and health-related notes count as sensitive personal information, and Glow only uses them to provide the features you asked for.

Glow does not sell personal information and does not share it for cross-context behavioural advertising, so there is nothing to opt out of on that front. You will never be treated differently for exercising any of these rights.

To exercise them, email info@glowskin.health from your account address.

If something goes wrong

If your data is ever exposed — taken, sent somewhere it should not have gone, or made visible to someone who should not have seen it — you get an email at your account address without undue delay. It says what happened, what of yours was involved, what is being done about it and what you should do. Where the law requires it the regulator is told as well: in the EU and the UK the data protection authority, within 72 hours of Glow becoming aware; in the United States the Federal Trade Commission, under the rule that covers health apps like this one. This holds whether the cause was somebody breaking in or Glow's own mistake.

When this policy changes

The date at the top changes whenever this page does. If a change is significant, meaning Glow starts collecting a new kind of data or sends your data somewhere new, you get an email at your account address before it takes effect, and a note in the app. Carrying on using Glow after that counts as accepting the new version.

Contact

Mina Khan
Columbia, Maryland, USA
info@glowskin.health