Glowfolio

Glowfolio Privacy Policy

Effective 23 August 2026

Glowfolio is operated by Anna Katrina Marie Oli. This policy explains how the Glowfolio iOS app and related services collect, use, store, share and delete personal information.

Minimum age

Glowfolio accounts are for users aged 16 and older. A user must confirm they are at least 16 before account creation. If local law requires a higher age to consent independently, that higher age applies. Glowfolio does not currently provide a parental-consent flow for users below the applicable minimum age.

Information we collect

Depending on the features you use, Glowfolio may collect:

  • name, email address, account/user ID and authentication records;
  • Terms/Privacy acceptance or acknowledgement timestamps and versions;
  • optional age range and beauty-profile information;
  • product collection details, ratings, notes, usage inputs and routines;
  • optional product photos;
  • routine completion and product-usage activity; and
  • optional health-related information such as allergies, period, mood, skin condition and breakout observations, but only after separate explicit health-data consent.

Passwords are stored as one-way hashes. Password-reset codes are stored hashed and expire after 15 minutes. Launch 1 does not enable skin-journal photo upload.

Health-data consent

Health and wellbeing information is optional. Before Glowfolio stores covered health/journal information, the app presents a separate notice and asks for explicit consent. This consent is not bundled with the Terms of Use. You may refuse it and continue using non-health features.

You may withdraw consent in Settings → Privacy & Data. Withdrawal stops future covered health-data processing and deletes stored Glow Journal entries and allergy information covered by that consent, while preserving your account, collection and rituals.

How we use information

Glowfolio uses information to:

  • create, authenticate and secure accounts;
  • save and synchronize your content;
  • provide collection, ritual, journal, trend and reminder features;
  • calculate product status, usage estimates and restock timing;
  • personalize in-app presentation and bundled Glow Tips;
  • send requested password-reset emails; and
  • operate, maintain and protect the service.

Launch 1 does not use Glowfolio data for third-party advertising, targeted advertising, cross-app tracking or sale to data brokers.

Service providers

  • Railway — API application hosting.
  • Supabase — production database and configured file storage.
  • Resend — transactional password-reset email delivery.

These providers process information on Glowfolio's behalf as needed to provide the relevant service. Glowfolio may also disclose information where required by law or reasonably necessary to protect users, rights or service security.

International processing

Infrastructure providers may process or store information in countries different from where you live. Where applicable law requires safeguards for international transfers, Glowfolio will use a legally permitted transfer mechanism or safeguard appropriate to the processing.

Retention and deletion

Account and user-created data is retained while the account remains active and as reasonably necessary to provide the service or meet legal/security requirements. Permanent account deletion is available at Settings → Delete My Glowfolio.

The active service deletes the account and associated application records, revokes authentication tokens and removes stored product-photo files, profile-avatar files and legacy journal-photo files where present, subject to limited lawful/provider backup and operational retention.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, port or object to processing, withdraw consent or make a privacy complaint/appeal. You can edit supported information in-app, manage iOS permissions, withdraw health consent, and delete your account.

For additional requests, email contact@glowfolioapp.com.

Regional rights

Where applicable, Glowfolio recognizes mandatory rights under privacy laws including the GDPR/EEA, UK data-protection law, UAE privacy law, the Philippine Data Privacy Act, Canadian privacy laws, the Australian Privacy Act/APPs, New Zealand privacy law and applicable U.S. state privacy laws. Local mandatory rights prevail where they provide additional protection.

Apple Health / HealthKit

Glowfolio Launch 1 does not access Apple Health/HealthKit. Health-related information described here is information users directly enter into Glowfolio after the applicable consent flow.

Security

Glowfolio uses HTTPS/TLS, server-side password hashing, hashed reset codes, authentication tokens, rate limiting and account-scoped access controls. No internet service can guarantee absolute security.

Changes

Glowfolio may update this policy when features, providers, laws or data practices change. Where renewed consent is legally required for a material change, Glowfolio will obtain it before relying on the new processing.

Contact

Email: contact@glowfolioapp.com

Consumer health data: Consumer Health Data Privacy Policy