Privacy Policy
Last updated 2 September 2026
GlowIQ ("we", "us") is a beauty companion app made by Bluestocking Studio. This policy explains what we collect, why, and the control you have. It describes what the app actually does.
The short version
- Your face image never leaves your device. Scans are analyzed on-device; only derived labels and metrics (your color season, undertone, and four numeric skin and eye metrics) are sent to your account. We never receive or transmit photos.
- Keeping a selfie is optional, and it stays on your phone. If you turn on "Keep a selfie for my avatar", one photo is stored in the app's local cache on your device only. It is not uploaded, not included in iCloud backups, and you can remove it any time from Profile → Privacy & data. It is off by default.
- We collect the minimum needed to run your account, personalize recommendations, and manage your subscription.
- We do not sell your data, and we do not use it for cross-app advertising or share it with data brokers.
- You can export or permanently delete everything from Profile → Privacy & data, any time.
What we collect and why
| Data | Why | Stored where |
| Email and name (via Clerk) | Account sign-in and recovery | Clerk; our database stores your email and a user id |
| Derived scan metrics (color season, undertone, radiance, hydration, skin clarity, eye brightness, scan timestamps) | Show your palette and Glow Score, track progress | Our database |
| Recommendation feedback (like, dislike, save, season override) | Personalize recommendations to your taste | Our database |
| Subscription status (via RevenueCat) | Unlock Premium and manage billing | RevenueCat; our database mirrors status |
We do not collect: photos or raw images, facial geometry, precise location, contacts, your advertising identifier (IDFA), or microphone data.
How processing works
Face analysis runs entirely on your device. The result that leaves your device is a small set of labels and numbers, never pixels, embeddings, or facial landmarks. This is enforced in the app's architecture, not just promised: the code path that sends a scan result strips anything that is not one of those labels before it is serialized.
Who we share with (processors)
We use these service providers strictly to operate GlowIQ; they act on our instructions:
- Clerk, authentication (sign-in by email code).
- RevenueCat, subscription management, working with Apple's App Store.
- Render, hosting for our backend and database.
- Sentry, server-side error diagnostics. Request bodies are never attached to error reports.
We do not sell personal data or share it for cross-context behavioral advertising.
Your rights and controls
- Export: Profile → Privacy & data → Download my data returns a full copy of everything on your device and, when you are signed in, everything on our servers.
- Delete: Profile → Privacy & data → Delete my data permanently erases your account with our sign-in provider and all associated data on our servers, then wipes the app on your device. If the server-side deletion cannot be completed, nothing is deleted and the app tells you so.
- Depending on where you live (for example EEA/UK GDPR, California CCPA/CPRA, Singapore PDPA), you may have additional rights to access, correct, or restrict processing. Contact us to exercise them.
Data retention
We keep your data while your account is active. Deleting your account removes it from our live database immediately. Backups of our database are retained for up to 30 days and then purged.
Children
GlowIQ is not directed to children under 13 (or the minimum age in your country). We do not knowingly collect data from them.
Changes
We will update this policy as the app evolves and revise the date above.
Contact
glowiq@bluestocking.studio