In short
- There are no accounts. We never collect your name, email address or phone number. Your data is tied to one installation of the app, not to you as a person.
- Face photos are uploaded to our server and passed to an AI model provider to produce the analysis you asked for. We do not build biometric templates and we do not use them to recognise anyone.
- We do not sell data and we run no advertising or marketing profiling.
- You can erase everything with one button in the app: Settings → Delete all data.
- We never see your card details. Payments are handled entirely by the App Store and Google Play.
- Data reaches the United States — our infrastructure and AI providers are based there. We rely on Standard Contractual Clauses.
1. Who is responsible for your data
The controller of personal data processed in connection with the Glooup app, within the meaning of Article 4(7) GDPR, is:
Registered details
- Name
- Antoni Ciechanowicz DGC E-COM
- Legal form
- Sole proprietorship registered in the Polish CEIDG business register
- Address
- ul. Bosmańska 32 lok. 19, 81-116 Gdynia, Poland
- Tax ID (NIP)
- 9581754483
- Data protection contact
- dgcecomapps@gmail.com
We have not appointed a Data Protection Officer, as none of the conditions in Article 37(1) GDPR apply. For every question about personal data, write to the address above — it is the only support channel we operate.
We are established in the European Union, so this policy is written around the GDPR. If you use Glooup from outside the EEA, the same standard applies to you: we do not operate a lower tier of protection by region.
2. Glooup has no user accounts
The app requires no registration, no sign-in and no email address. On first launch Glooup generates two random values on your device: a device identifier and a device token. The token is held in your phone's secure system storage (Keychain on iOS, Keystore on Android). Our server stores only its SHA-256 hash — we never hold the token itself.
That pair acts as the key to your data: whoever presents the token sees the scans belonging to that installation. Two consequences follow:
- We do not know who you are. We hold nothing that would link an installation to a named person, beyond what you type into the app yourself.
- Uninstalling the app or losing your phone means losing access to that installation's scan history. We have no technical way to restore it on a new device. Your subscription can be restored through the store, because Apple or Google runs it.
In the sense of Article 11 GDPR, we therefore process data that in most cases does not allow us to identify the data subject on our own. That affects how your rights work in practice — see section 9.
3. What data we process
The scope depends on which features you use. These are the only categories we process:
a) Onboarding answers — given voluntarily, and every question can be skipped: age (between 16 and 80), gender, your goals, the skin concerns you select (for example acne, redness, dryness, sensitive skin) and product preferences (for example fragrance-free, vegan, hypoallergenic). These answers are included in the prompts sent to the AI model so the advice fits you.
b) Photos and analysis results — the photo you take or pick from your library, plus the result: the seasonal colour palette assigned to you and a confidence value, a 0–100 score with per-trait scores and tips, the generated "after" image for the makeup guide, the how-to steps, a headline and description, and a note comparing the scan to your previous one. See section 4.
c) In-app activity — your scan history, the daily ritual (which tips were shown and read on a given day, in your phone's local date), your streak counter, and your chosen interface language.
d) Subscription data — whether a subscription is active and on which tier (plus or pro), the user identifier assigned by our subscription provider, and a timestamp of the last event that changed that status. We never receive or store card numbers or any payment details — these are handled exclusively by Apple and Google.
e) Push notification token — if you allow notifications, we store the token issued by the notification service so we can tell you when your analysis is done. It is overwritten on each launch and deleted as soon as the service reports it is no longer valid.
f) Diagnostic and security data — crash and error reports (device type and model, OS version, app version, stack trace, the sequence of events leading to the error). Before a report leaves your device it passes through a scrubber that removes the device token and other values matching sensitive patterns.
g) Usage counters — how many scans a device started on a given day, its lifetime scan count, and which scan types have already used their free allowance. These counters contain no photos and no results. They exist so limits cannot be reset by deleting your own scans, which is why they are the one piece of device-side data that survives "Delete all data".
h) Technical logs — server logs generated automatically when handling requests, needed to keep the service running and to detect abuse.
Glooup does not collect: your name, email address, phone number, postal address, contact list, precise GPS location, health-app data, or advertising identifiers. We use no ad networks and perform no cross-app tracking.
4. Face photos — exactly what happens
This is the most sensitive category in the app, so here is the full path:
- You take a photo with the camera or choose one from your library — only after granting the relevant permission in your phone's settings.
- The file is uploaded to our storage at our backend provider and saved alongside the scan record.
- To run the analysis we generate a signed, time-limited URL to that file and pass it to the platform that runs the AI models. The model fetches the photo from that URL, analyses it and returns a text result — plus, for the makeup guide, a generated image.
- The generated "after" image is stored next to the input photo so you can return to it.
- Both remain in your scan history until you delete them.
We do not use your photos to train AI models. We do not publish them, do not share them with other users, and pass them to no one outside the providers listed in section 6.
On biometric data. Under Article 4(14) GDPR, biometric data becomes a special category only when it is processed for the purpose of uniquely identifying a natural person. Glooup builds no biometric templates, never compares faces between users, and is not used for identification or identity verification. A photo is analysed solely for appearance features, to deliver the feature you requested. Regardless of that classification, we treat face photos as requiring heightened protection and rely on your explicit consent, given by starting a scan.
Skin information. The skin concerns you select and some analysis results may in certain circumstances qualify as health data. We process them solely on the basis of your explicit consent under Article 9(2)(a) GDPR, given when you select those answers or start a scan. You can withdraw that consent at any time — see section 10.
Only upload photos you are entitled to use — your own, or those of people who have agreed to it. If you upload someone else's photo, you are responsible for having a basis to do so.
5. Purposes of processing and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Running a colour analysis, face analysis or makeup guide and delivering the result | Photo, analysis result, device identifier, language | Art. 6(1)(b) GDPR — necessary to perform the contract for supplying digital content. For the face photo and skin information additionally Art. 9(2)(a) GDPR — explicit consent |
| Tailoring advice to you based on your onboarding answers | Age, gender, goals, skin concerns, product preferences | Art. 6(1)(a) GDPR — consent given by voluntarily answering. For skin concerns, Art. 9(2)(a) GDPR |
| Maintaining your scan history, daily ritual and streak | Scan history, ritual activity, streak counters | Art. 6(1)(b) GDPR — performance of the contract |
| Making paid features available to subscribers | Subscription status and tier, subscription provider user id | Art. 6(1)(b) GDPR — performance of the contract |
| Telling you your analysis has finished | Push token, language, scan type | Art. 6(1)(a) GDPR — consent granted in your phone's settings, revocable there at any time |
| Keeping the app running, diagnosing errors, security | Diagnostic data, technical logs | Art. 6(1)(f) GDPR — legitimate interest in a correctly functioning and secure service |
| Enforcing scan limits and preventing cost-generating abuse | Usage counters | Art. 6(1)(f) GDPR — legitimate interest in protecting the service against abuse and uncontrolled cost |
| Handling complaints and data requests, defending against claims | Correspondence and the data needed to handle it | Art. 6(1)(c) GDPR — legal obligation, and Art. 6(1)(f) GDPR — establishing, exercising or defending legal claims |
Providing data is voluntary but necessary for the corresponding feature: without a photo there is no analysis, and without notification consent we cannot tell you it finished.
6. Who processes data for us
We do not sell data and share it with no one for their own marketing. We do rely on providers without which the app could not function. Each is bound by a data processing agreement under Article 28 GDPR.
| Provider | Role | What it receives |
|---|---|---|
| Convex, Inc. (USA) | Application database and file storage | All data described in section 3, including photos and analysis results |
| Replicate, Inc. (USA) | Platform running the AI models that perform the analysis | The photo (fetched from a signed URL) and the prompt, which contains your onboarding answers and context from previous scans |
| RevenueCat, Inc. (USA) | Subscription status handling and verification | Subscription user identifier, purchase and expiry events. No photos, no analysis results |
| Expo (650 Industries, Inc., USA) | Push notification service and app update delivery | Push token and notification content (that a scan has finished). No photos, no analysis results |
| Functional Software, Inc. (Sentry, USA) | Crash and error reporting | Diagnostic data after sensitive values have been scrubbed. No photos |
| Apple Inc. / Google Ireland Limited | App distribution, payment and subscription handling, notification delivery to the device | Transaction and billing data — processed by these companies as independent controllers under their own privacy policies |
The AI models performing the analysis run on Replicate's infrastructure. As at the date of this policy they are the vision-language model openai/gpt-5.6-luna and the image model xai/grok-imagine-image-2. We may switch to comparable models — the recipient category and the scope of data transferred stay the same.
Beyond the above, data may be disclosed to public authorities where required by applicable law, and to legal advisers to the extent needed to establish, exercise or defend legal claims.
7. Transfers outside the European Economic Area
Most of our providers are established in the United States, so your data — including photos — is processed outside the EEA.
Transfers rely on the mechanisms in Chapter V GDPR: Standard Contractual Clauses approved by the European Commission (Implementing Decision 2021/914) concluded with each provider and, for providers certified under the EU–U.S. Data Privacy Framework, also the European Commission adequacy decision of 10 July 2023.
You can request a copy of the safeguards in place by writing to dgcecomapps@gmail.com.
8. How long we keep data
| Data | Retention |
|---|---|
| Photos, generated images and analysis results | Until you delete them in the app. The app does not expire them automatically, so your scan history stays complete — deleting them at any time is in your hands |
| Onboarding answers, ritual history, streak counters | Until you use "Delete all data" |
| Device record and subscription status | For the duration of the subscription and as long afterwards as needed to administer it. This record survives "Delete all data", because removing it would detach your subscription from the device — at that point it holds nothing describing a person |
| Files uploaded but never attached to a scan | Deleted automatically; the cleanup job runs hourly |
| Scans stuck mid-processing | Closed out automatically; the job runs every 10 minutes |
| Subscription events (kept for duplicate detection) | 30 days, then deleted automatically. They contain nothing describing a person |
| Scan usage counters | For as long as the device uses the app. They survive "Delete all data", as limits could otherwise be reset at will. They contain no photos and no results |
| Diagnostic data and technical logs | Per the retention periods applied by those providers, typically up to 90 days |
| Support correspondence and complaints | For as long as needed to handle the matter, then until the limitation period for related claims expires |
Data passed to the AI model provider is subject to that provider's own retention periods, applied to deliver the service and detect misuse.
9. Your rights
Under the GDPR you have the right to:
- access your data and obtain a copy (Art. 15),
- rectification of inaccurate data (Art. 16),
- erasure (Art. 17),
- restriction of processing (Art. 18),
- data portability for data processed on the basis of consent or contract (Art. 20),
- object to processing based on legitimate interests (Art. 21),
- withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand (Art. 7(3)).
How this works without accounts. Because we hold no email address or other identifying data, a request sent from any mailbox does not tell us which data it concerns. Under Articles 11(2) and 12(6) GDPR we may ask for information that would let us identify the data, and where we cannot link it, we may decline the request and tell you why.
The fastest and most reliable route is therefore the in-app controls described in section 10. They give effect to your right of erasure immediately, with no identity check needed. For the other rights, write to dgcecomapps@gmail.com — we respond without undue delay and within one month of receiving the request.
Complaints. If you believe we process your data unlawfully, you may lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland (uodo.gov.pl). If you live elsewhere in the EEA, you may instead approach the supervisory authority of your habitual residence.
10. Deleting your data
Erase everything: open the app, go to Settings and choose Delete all data. This removes every scan together with input photos and generated images, your onboarding answers, and your ritual history and streak counters. It cannot be undone.
What remains afterwards is only: the device record holding your subscription status (so you do not lose access you paid for) and the scan usage counters. Neither contains a photo, an analysis result or an onboarding answer. Deleting your data is not the same as cancelling your subscription — cancel that in your App Store or Google Play settings.
Delete a single scan: select it in your scan history and delete it. Both the photo and the result are removed.
Withdraw system permissions: camera, photo library and notification access can be turned off in your phone's system settings, under Glooup.
Uninstalling the app removes the device token from your phone and cuts off access to that installation's data, but does not by itself erase data held on the server. If you want it erased, use "Delete all data" before uninstalling.
11. Age requirement
Glooup is intended for people aged 16 or over. We do not direct the app at children and do not knowingly collect data from anyone below that age. The threshold matches the age of consent for information society services in Poland under Article 8(1) GDPR as implemented in Polish law.
If we establish that data belonging to someone under 16 has been entered into the app, we will delete it without undue delay. If you are a parent or guardian and believe a child is using the app, write to dgcecomapps@gmail.com and we will help erase the data.
12. Automated processing and the nature of results
Results in Glooup are produced by automated processing using artificial intelligence models. We do not, however, take decisions about you that produce legal effects or similarly significantly affect you within the meaning of Article 22(1) GDPR — a result is informational and inspirational content.
AI models can be wrong, and their assessments are subjective and dependent on photo conditions such as lighting and framing. Glooup is not a medical device and is not intended to diagnose, treat or assess any health condition. For anything concerning your skin and health, consult a doctor, dermatologist or licensed skincare professional.
13. Security
We apply technical and organisational measures appropriate to the risk, in particular:
- encryption in transit (TLS) at every stage of transmission,
- storing the device token only in the phone's secure system storage, and on the server only its SHA-256 hash,
- token-based access control: every request for scan data must present the token bound to that device,
- automatic scrubbing of sensitive values from error reports before they leave the device,
- stripping file URLs from provider error messages before they reach our logs,
- rate limits protecting the service against abuse,
- keeping the set of providers to a minimum and giving each only the data it needs.
No system is completely secure. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you under Article 34 GDPR and the supervisory authority under Article 33 GDPR.
14. This website
This site sets no marketing or analytics cookies of its own, embeds no tracking tools, and collects no personal data from visitors. Our hosting provider generates standard server logs needed to deliver the site securely, processed under Article 6(1)(f) GDPR.
15. Changes to this policy
We may update this policy when the app changes, when the scope of processing or the list of providers changes, or when the law does. The current version is always published on this page with its version number and effective date.
Changes that materially affect how your data is processed will additionally be announced in the app before they take effect. Where a change requires fresh consent, we will ask for it separately.
Questions about this policy go to dgcecomapps@gmail.com. See also our Terms of Use and Support page.