Privacy policy
Glorious measures skin and records what you do to it. That makes most of what it holds health data, so this policy is specific about what is collected, what never leaves your phone, and how to delete all of it.
Draft of 22 Sep 2026.
Who we are
The controller of your data is [company name — placeholder], [registered address — placeholder], company number [company number — placeholder], registered with the Information Commissioner's Office under [ICO registration number — placeholder].
Data protection contact: [privacy@ — placeholder address]. Whether a Data Protection Officer is required, and who it is, is [to be decided — placeholder].
This policy covers the Glorious app and this website.
What is collected
- Skin readings
- Eight indicators, an overall score, the zone they were read from, and the date and time of the reading. These come from the device, not from anything you type.
- Face captures
- The photograph taken while a reading is captured. Captures stay on your phone unless you turn on backup, which is not offered yet.
- Diagnoses you record
- A condition a clinician has given you, if you choose to enter it, and who told you. The app never adds a diagnosis of its own.
- What you do
- Your routines and steps, the runs you complete, the products on your shelf, treatments, and the time budget you chose.
- Voice, as text
- During a routine you can speak instead of tapping. Your phone turns the audio into text; the text, plus which step you are on, is sent to be interpreted. The audio itself never leaves the phone.
- Shelf photos
- When you ask the app to read your bathroom shelf, that one photo is sent, read, and discarded in the same request. It is not stored, and nothing reaches your shelf until you confirm it.
- Consents
- What you agreed to, and when. Kept so both of us can see what the basis for holding your data actually was.
- Account
- Your email address, and the identifier Apple or Google gives us if you sign in that way. Sign in with Apple can hide your address, and that works here.
- Technical information
- Crash and error reports, with no readings or captures attached. Whether any usage analytics are collected at all is [to be decided — placeholder]; the intention is none.
- This website
- Nothing. No cookies, no analytics, no fonts or scripts loaded from anyone else. Your Supabase account details are never handled by this site.
Why we are allowed to hold it
Skin readings tied to you, and any diagnosis you record, are special category data about health under Article 9 of the UK GDPR. The lawful basis for processing them is your explicit consent (Article 9(2)(a), with Article 6(1)(a)). You give it in the app, separately from agreeing to the terms, and each use is asked for on its own: holding your readings, sending routine speech to be interpreted, reading a shelf photo, and joining cohort comparisons.
Your email address is processed to give you an account and sign you in, which is what performing our contract with you requires (Article 6(1)(b)). Crash reports are kept under legitimate interests (Article 6(1)(f)), to keep the app working.
You can withdraw any consent at any time, in the app. Withdrawal stops that processing from then on; it does not make what was already done unlawful. Withdrawing consent to hold readings means there is nothing left to show you, so the app will offer to delete them.
What stays on your phone
- Face captures. They stay on the phone unless you turn on backup. Backup is not available yet; when it is, it will be off until you switch it on, and this policy will be updated before it ships.
- Voice audio. Speech is turned into text on the device by the phone's own recogniser. Only the text is sent.
- Your working copy. The app keeps its own copy of your data on the phone so a routine runs with no signal. That copy is inside the app's private storage and is removed when you delete the app or delete everything.
Where it is stored
Structured data — readings, routines, runs, shelf, treatments, recorded diagnoses and consents — is stored in a Postgres database run by Supabase in London, United Kingdom. Every table has row-level security, so a signed-in person can only read and write rows that are their own.
Sign-in emails are sent from [email provider — placeholder: Resend or Postmark], with UK or EU hosting to be confirmed before launch.
Model calls that interpret routine speech or read a shelf photo are made to Anthropic. The processing region is [to be confirmed — placeholder]. If that is outside the UK or EU, the transfer will be covered by the UK International Data Transfer Addendum before any real user's data goes near it.
Who else processes it
These are processors: they act on our instructions, under a data processing agreement, and not for their own purposes.
- Supabase
- The database and sign-in. Holds your readings, routines, shelf, consents and account. Hosted in London.
- Anthropic
- The model calls. Two of them: turning the text of what you said into one routine action, and reading the products in a shelf photo. Nothing else is sent, and no face capture is ever sent.
- [email provider — placeholder]
- Transactional email only: your sign-in link, and account notices.
- Cloudflare
- Serves this website. It does not receive your account data.
- Apple and Google
- Distribute the app, and provide sign-in if you choose theirs. Their own privacy terms apply to that part.
Your data is never sold, never shared with advertisers, and never handed to a brand. If a product is ever placed by a brand that paid for placement, the payment buys the tagged slot, not your data.
The data processing agreements with the processors above are [not yet signed — placeholder].
Models, and what is never sent to one
- A face capture is never sent to a model.
- Nothing you give the app is used to train a model, ours or anyone else's. Model calls are made under terms that exclude training on our inputs and outputs.
- A shelf photo is read in the request and not written down anywhere.
- Voice audio never leaves the phone; only the text does.
- A model never produces a diagnosis, and the app never presents one.
Deleting everything
Settings, then Delete everything. One tap, one confirmation, no email to anyone. It deletes:
- every reading, and the score history built from them;
- your routines, runs and completed steps;
- your shelf, treatments and recorded diagnoses;
- your consent records;
- your account and its sign-in record, so the email address is no longer known to us;
- the copy held on the phone, including face captures.
The deletion is a real deletion, not a flag. Encrypted database backups still hold the rows until they age out, within [backup retention — placeholder], and they are never used to restore a deleted account.
How long it is kept
- Readings and what you recorded: for as long as your account exists. They are the point of the app — a trend needs its history — so nothing is deleted on a timer.
- Crash and error reports: [log retention — placeholder].
- After you delete everything: nothing, except any record we are required by law to keep, which is [to be confirmed — placeholder].
- If an account is unused for [dormancy period — placeholder], we will write to you before deleting anything.
Cohort comparisons
The app can show how a choice worked out for other people. That needs a separate consent, it is off unless you turn it on, and it can be turned back off.
Comparisons are of choices, not of people: a group is defined by what was applied, never by who applied it. Nothing is reported unless the group is large enough to hide any individual in it, and a comparison always shows the outcome that went badly as well as the one that went well. You are never identified, and no comparison is ever shown to anyone with your name on it.
Your rights
Under UK GDPR you can ask us to:
- give you a copy of what we hold about you, and tell you what we do with it;
- correct anything that is wrong;
- delete it — which you can also do yourself, in the app;
- stop or restrict a particular use;
- give you your data in a portable form, or send it to someone else;
- withdraw a consent, at any time.
Write to [privacy@ — placeholder address]. You will get an answer within one month. There is no charge.
If you are not satisfied, you can complain to the Information Commissioner's Office, the UK's data protection regulator: ico.org.uk/make-a-complaint, helpline 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. You can complain to them directly; you do not have to come to us first.
Children
Glorious is not for children. The minimum age is [minimum age — placeholder], and age is [how age is checked — placeholder].
Not medical advice
The app measures skin and describes what changed. It does not diagnose, it is not a medical device, and nothing it says replaces a clinician. A diagnosis you record is the clinician's, and the app keeps it attributed to them.
Changes to this policy
This draft is dated 22 Sep 2026. A change that affects what is collected or who processes it will be shown in the app before it takes effect, and a change to the basis for holding health data will be asked for again rather than assumed.