Glossly
Pobierz
Ten dokument jest dostępny tylko po angielsku. Reszta serwisu jest przetłumaczona, ta strona jeszcze nie.

Privacy policy

Last updated: 29 July 2026

This policy explains what personal data we process when you use the Glossly mobile app and the glossly.app website, why we process it, who else sees it, and what you can ask us to do with it.

It is written to describe what the app actually does. Where a section says data stays on your phone, or that we never see it, that is a statement about how the app is built, not a promise about intentions.

1. Who is responsible for your data

The controller of your personal data is LimitWaste Sp. z o.o., ul. Wspólna 19/72, 25-003 Kielce, Poland, registered in the National Court Register (KRS) under number 0000803658, NIP 5272905462, REGON 384349430.

For anything concerning this policy or your data, write to contact@glossly.app. We have not appointed a Data Protection Officer; messages sent to that address reach the people who can act on them.

2. Using Glossly without an account

Glossly does not ask you to register before you can use it. The first time you save something worth keeping — finishing onboarding, saving your first routine — the app creates an anonymous account for you in the background. It has no email address and no name attached to it; it is an identifier that lets your data belong to someone.

An anonymous account is tied to that installation. If you clear the app's data, reinstall or switch phones without registering first, the session is lost and so is access to everything stored under it. Registering later attaches an email address (or a Google or Apple identity) to the same account, which is why nothing has to be migrated and nothing is lost.

An anonymous account that was created but never used — no routine, no photos, nothing saved — is deleted after 30 days. An anonymous account that holds something is kept for 12 months from your last activity, and deleted with everything under it after that.

3. What we process, and on what legal basis

Below is everything the app stores about you, grouped by what it is for. Unless stated otherwise, the legal basis is Article 6(1)(b) GDPR — processing necessary to provide the service you asked for.

Account and sign-in

  • Your account identifier — a UUID. It is shown in your profile and can be copied; quoting it in a support message is how we find your account without asking for anything else.
  • If you register: your email address and password. The password is stored as a hash by our authentication provider and is never visible to us.
  • If you sign in with Google or Apple: the identifier that provider returns, plus the email address and name they pass on. We do not receive your password or the rest of your profile, and we do not post anything anywhere.
  • The date the account was created and the date of the last sign-in.

Your hair profile and routine

  • A display name and, optionally, a profile picture.
  • Declared hair characteristics: type, condition and porosity.
  • Your care routine: the treatments you defined, which days they fall on, a weekly or fortnightly cycle, the growing-out mode, notes, and reminder settings.
  • Which treatments you ticked off and when — this is what the weekly summary, the streak, the points and the badges are calculated from.
  • Care programmes you started and your progress through them.

Your shelf and ingredient scans

  • Products you added to your shelf: name, brand, category and your own read of the protein/emollient/humectant balance.
  • Ingredient lists you paste into the scanner, kept verbatim together with the product name you gave, so an old scan can be re-run against a larger ingredient catalogue without you retyping it.
  • If you photograph an ingredient panel instead of typing it, that photograph is sent to Google's Gemini API to be transcribed into text, and the text comes back for you to check and correct. The photograph itself is not stored — neither by us nor, under the terms of the paid tier we use, for Google's own purposes.

Progress photos and measurements

  • Photos you take or pick from your gallery, along with the date and any note you add. They are stored in a private bucket that is not publicly readable; the app opens them through links that expire after one hour.
  • Hair length measurements and the length goal you set.

Photo analysis (optional, premium)

  • When you ask for a reading of a specific photo, that photo is sent to Google's Gemini API together with the instructions for the model, and what the model returns — a short description, up to four observations, up to three suggestions — is stored next to that photo, with the language and the model version.
  • This never happens on its own. It runs per photo, when you ask for it, and no more than 12 times a day per account.
  • Deleting the photo deletes the reading with it.

A reading of a photograph of your hair and scalp may touch on things close to health — dryness, breakage, the condition of your scalp. We therefore treat this feature as processing that requires your explicit consent under Article 9(2)(a) GDPR, given by requesting the analysis, and you can stop using the feature at any time without affecting anything else in the app. The instructions the model is given forbid it from diagnosing a medical condition or recommending treatment; if something looks like it needs attention, the answer will say only that it is worth showing to a specialist in person.

Subscription

  • The purchase itself is handled by Google Play or the App Store. We never see your card details, your billing address or your full payment history.
  • To know whether your subscription is active, we use RevenueCat, which receives your Glossly account identifier and the purchase data the store reports (product, status, renewal and expiry dates).

Reminders

  • Reminders are scheduled by your phone, locally. There are no push tokens, no notification server, and nothing about your routine leaves the device in order to remind you of it. Your time zone is read on the device so a reminder fires at the hour you set.

How the app is used

  • We measure how the app is used with Amplitude and with our own OpenPanel instance: which screens you open and which features you use — a routine saved, a treatment ticked off, an analysis requested — together with the app version, device model, operating system version and language. Both receive the same events. Events are tied to a random installation identifier and, once you are signed in, to your Glossly account identifier.
  • What we do not send there: your photos, your notes, the names of your treatments, your measurements, your email address. The events say that something happened, not what it was about.
  • Legal basis: our legitimate interest in knowing which parts of the app are worth keeping (Article 6(1)(f) GDPR). You can object to it — write to contact@glossly.app.

Diagnostics and feedback

  • In release builds, crashes and errors are reported to our own error-tracking instance: the error and its stack trace, app version, device model, operating system version and your account identifier. Legal basis: our legitimate interest in a working app (Article 6(1)(f) GDPR).
  • If you send feedback from inside the app, the message goes to Wiredash together with what you chose to attach (a screenshot you drew on, optionally your email address) and basic technical metadata. Legal basis: your request (Article 6(1)(b) and (f) GDPR).
  • If you rate the app, that happens inside the store's own dialog and we receive nothing beyond what the store publishes.

The website

  • glossly.app runs on the same self-hosted OpenPanel instance the app reports to. It records page views, clicks on the store badges and outgoing links, the referring page, and technical data every server receives: IP address, user agent, language and screen size.
  • It sets no cookies and stores no identifier in your browser. Visits are grouped into a session by our own server, on the basis of that technical data. The requests go to our own domain rather than to a third-party analytics vendor, and there is no advertising or cross-site tracking on the site. Legal basis: our legitimate interest in knowing whether the page works (Article 6(1)(f) GDPR).

4. What we do not do

  • We do not sell personal data and do not share it for anyone else's marketing.
  • The app contains no advertising or ad-tracking SDK.
  • We do not read your location, contacts, calendar or microphone. The app asks for camera and photo library access only so you can add a progress photo, and for notification permission only to show reminders.
  • We make no automated decisions that produce legal effects for you. The photo analysis produces a description for you to read; nothing in the app acts on it by itself.

5. Who else processes your data

We use the following providers. Each processes data on our instructions, under a data processing agreement.

  • Supabase — database, file storage, authentication and server functions. This is where your account and everything under it lives. Hosting region: eu-north-1 (Stockholm, EU).
  • Google (Gemini API) — receives a photo only when you ask for one to be read: a progress photo you want analysed, or a photograph of an ingredient panel you want transcribed. We use the paid tier, under which Google does not use submitted content or the responses to improve its products; prompts and responses are logged briefly for abuse prevention only.
  • Google, Apple — only if you choose to sign in with them, and only to confirm who you are.
  • Google Play and Apple App Store — distribution and payments. They are separate controllers of the payment data they hold about you.
  • RevenueCat — subscription status, as described above.
  • Amplitude — how the app is used. The project runs in Amplitude's EU region, so the events are stored in the European Union.
  • OpenPanel — the same events, on an instance we run ourselves on a server in the European Union. It is not a third-party analytics vendor: the data goes to our own machine, and the only other company involved is the provider hosting it.
  • Wiredash — feedback you send from inside the app.
  • Our own error-tracking instance — crash reports.
  • Vercel — hosting of glossly.app.

6. Transfers outside the European Economic Area

Your account, your photos and everything stored under them sit in the European Union: our database and file storage run in the eu-north-1 region (Stockholm), and usage events are stored in Amplitude's EU region. Some of our providers are nonetheless established in the United States (Google, RevenueCat, Amplitude, Vercel) and their staff may reach the data in the course of support and maintenance. Where data is transferred outside the EEA, it happens on the basis of the European Commission's Standard Contractual Clauses, or another mechanism permitted by Chapter V of the GDPR. You can ask us for details of the safeguards that apply to a specific transfer.

7. How long we keep it

  • Account data and everything stored under it: until you delete the account.
  • Anonymous accounts: 30 days if nothing was ever saved under them, otherwise 12 months from the last activity.
  • Deletion takes effect at once — the account, the rows and the photo files are removed immediately, and we cannot restore them afterwards. Where our hosting provider holds routine backups of the database, they are overwritten on that provider's own cycle; we do not use them to bring a deleted account back.
  • Crash reports: 90 days.
  • Usage events: 24 months, in Amplitude and on our own OpenPanel instance alike.
  • Feedback messages: 12 months from the conversation ending.
  • Records we are required by law to keep — accounting records for a purchase in particular — for the period the relevant regulations set, currently five years from the end of the accounting year. They are not linked to your routine or your photos.

8. Deleting your account

You can delete your account from inside the app, in your profile. The deletion removes your photos from storage first and then the account itself, and everything stored under it goes with it — routine, completions, shelf, scans, measurements, analyses, points. What is kept on the device is erased as well. It cannot be undone and we cannot restore it afterwards.

If you cannot reach the app, you can also request deletion by email; the procedure is described on the account deletion page.

Deleting the account does not cancel a subscription. Only Google Play or the App Store can end it — cancel it there first.

9. Your rights

Under the GDPR you have the right to:

  • access your data and receive a copy of it;
  • have inaccurate data corrected;
  • have your data erased;
  • have processing restricted;
  • receive your data in a machine-readable format and have it transferred;
  • object to processing based on our legitimate interest;
  • withdraw consent at any time, where processing is based on consent — this does not affect what was done before you withdrew it.

Write to contact@glossly.app from the address linked to your account, or quote your account identifier from the profile screen. We answer without undue delay and no later than one month from receiving the request.

You also have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.

10. Children

Glossly is not directed at children. If you are under 16, do not use the app without the consent of a parent or guardian. If we learn that we hold data of a child under 16 without such consent, we delete it.

11. Security

Every table in our database has row-level security enabled: a query can only ever return rows belonging to the account making it. Progress photos sit in a private bucket, reachable only through links that expire after an hour and are issued to their owner. All traffic runs over TLS. Keys that could bypass any of this exist only on the server and are never shipped inside the app.

No system is perfect. If you believe your account has been accessed by someone else, write to contact@glossly.app.

12. Changes to this policy

If we change how we process data, we update this page and the date at the top. For changes that materially affect you, we will say so in the app before they take effect.