Glowy legal
Privacy Policy
Glowy asks for photographs of your face. This page says exactly what happens to them — where they are stored, which companies see them, and how to get rid of them.
Effective 28 August 2026 · Glowy is owned and operated by One Man Holdings LLC · glowy.pics@gmail.com
1.Who we are
Glowy is owned and operated by One Man Holdings LLC (“we”, “us”). We are the controller of the personal data described here. For anything in this policy — including a request to see or delete your data — write to glowy.pics@gmail.com.
2.What we collect
Account information
Your email address, and a password that is stored only as a cryptographic hash by our authentication provider — we never see or store the password itself. If you sign in with Google instead, we receive your name, email address and Google account identifier.
Photographs
- Selfies. The 3–15 photographs of your face that every generated photo is built from.
- Reference images. The pictures you upload to show the style, pose or setting you want.
- Generated photos. The results the service produces for you.
Photographs of a face are biometric-adjacent personal data in several jurisdictions, and we treat all three categories as sensitive regardless of what any particular law calls them.
Billing
Your subscription status, plan, billing dates, and a record of every credit added to or spent from your balance. Payments are handled by Stripe on Stripe’s own pages: card numbers never reach our servers and we never store them. We hold only the customer identifier Stripe gives us.
Usage
A log of events — account created, photo requested, photo completed or failed, subscription started — with timestamps and the cost each generation incurred. We use this to run the service, to find faults, and to understand whether the business works. It is not sold, and it is not used to build a profile of you for advertising.
Reports
If you report one of your own generated photos, we keep the report, the reason you chose, and any note you add.
3.How your photographs are used
In plain English
Your selfies are used to make photos of you, and for nothing else. We do not train models on them, we do not show them to anyone else, and we do not use them in marketing.
When you ask for a photo, two things happen. First, your reference image is sent to Anthropic’s Claude, which writes a description of the look in it. Then that description and up to 2 of your selfies are sent to our image provider, which produces the finished photograph. Both steps are set out in the table below.
We do not use your photographs to train any model of our own, and we do not sell or rent them to anybody.
4.Who else sees your data
We use the following companies to run the service. Each one only receives what it needs for the step it performs, and each has its own privacy terms which govern what it does with that data.
Supabase
Database, authentication and file storage
Your email address, your account record, and every photo you upload or generate. Data is held in the ap-south-1 region (Mumbai, India).
Anthropic
Reading your reference image
The reference image you upload — the picture of the look you want. It is sent to Claude so the service can write a description of that look. Your selfies are never sent here.
apimart.ai (Seedream)
Generating the finished photo
Up to two of your selfies together with the written description. This is the step that produces your photo, and it is the only place your selfies are sent outside our storage.
Stripe
Payments
Your email address and payment details, which you enter on Stripe’s own pages. Card numbers never reach Glowy’s servers.
Optional sign-in
Only if you choose to sign in with Google: your name, email address and Google account identifier. Nothing is sent to Google if you sign in with an email and password.
We may also disclose data where we are legally required to, or where it is necessary to investigate abuse, fraud, or a credible threat to someone’s safety. We will tell you when we are permitted to.
We do not sell your personal data, and we do not share it with advertisers or data brokers.
5.Where your data is stored
Your account record and every photograph are stored in the ap-south-1 region (Mumbai, India). Our other providers process data in the regions their own terms describe, which may include the United States and the European Union. If you are in a jurisdiction that restricts international transfers, using Glowy involves your data crossing borders, and you should not use the service if that is not acceptable to you.
6.How long we keep it, and how to delete it
We keep your photographs for as long as your account exists, because the whole point of a selfie set is that it is uploaded once and reused. You are in control of removing them:
- Selfie sets and reference images can be deleted at any time from the Uploads page in your account. Deletion removes the files immediately and permanently; there is no undo and no recycle bin.
- Generated photos and your whole account cannot yet be deleted from inside the app. Email glowy.pics@gmail.com and we will delete them. We are building the self-serve version of this.
When you delete a set or ask us to delete your account, we remove the files. We keep a minimal billing and transaction record where we are required to for tax and accounting purposes, and we keep the record that a moderation decision was made — but not the content it was made about.
Links to your photographs are private and expire after 60 minutes. Nothing you upload is ever publicly readable.
7.Your rights
Depending on where you live, you may have the right to access the data we hold about you, to correct it, to delete it, to receive a copy in a portable form, to object to or restrict how we use it, and to withdraw consent. You also have the right to complain to your local data protection authority.
To exercise any of these, email glowy.pics@gmail.com. We will respond within 30 days. We may ask you to confirm you control the account before acting on a request — the alternative is handing someone else’s photographs to whoever asks for them.
8.Security
Photographs are stored in a private bucket that is not publicly readable. Access is enforced at the database level per account, so one user’s session cannot read another user’s files. Traffic is encrypted in transit. Links to your images are signed and short-lived rather than permanent.
No system is perfectly secure, and we will not claim otherwise. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority where the law requires it.
9.Children
Glowy is for adults. You must be 18 or older to use it. We do not knowingly collect data from anyone under 18, and we do not permit photographs of minors to be uploaded for any reason. If you believe a child has used the service or that a child’s photograph has been uploaded, email glowy.pics@gmail.com and we will delete the account and its contents.
10.Cookies
We use cookies only to keep you signed in and to keep the sign-in process secure. We do not use advertising cookies, and we do not run third-party analytics or tracking scripts on the site.
11.Changes to this policy
If we change this policy in a way that materially affects how your data is handled, we will update the effective date at the top and notify account holders by email before the change takes effect.
12.Contact
One Man Holdings LLC, operator of Glowy — glowy.pics@gmail.com. See also our Terms & Conditions and Refunds & Cancellation policy.