Legal

Privacy Policy

Last updated: 1 January 2025 · Effective from: 1 January 2025

Your privacy matters to us. This policy explains what data we collect, why we collect it, how long we keep it, and what rights you have over it. We comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, and applicable consumer data protection laws.

1. Who We Are

The Glowup HQ (“we”, “us”, “our”) is the data controller for personal data collected through this website and app. For data requests, contact us at privacy@theglowuphq.com.

2. What Data We Collect

We collect the following categories of personal data:

  • Account information: name, email address, password (hashed; we never store plaintext passwords)
  • Profile data: age, preferences, goals, cycle tracking data you choose to enter
  • Usage data: which features you use, how often, what content you read
  • Payment data: billing information processed by our payment provider (we do not store card details)
  • Communications: messages you send to our AI coach (used only to generate responses, not shared or sold)
  • Device data: IP address, browser type, device type, for security and analytics
  • Cookies: see our Cookie Policy for full details

We only collect data that is necessary for the purposes described in this policy. We do not collect sensitive data such as health records beyond what you voluntarily enter for personalisation.

3. How We Use Your Data

We use your data to:

  • Provide and personalise our service, including cycle-synced recommendations and AI coaching
  • Process your subscription and manage your account
  • Send transactional emails (receipts, password resets); these cannot be opted out of
  • Send marketing emails if you have given explicit consent; you can unsubscribe at any time
  • Improve our platform through aggregated, anonymised analytics
  • Comply with legal obligations
  • Prevent fraud and ensure platform security

We never sell your personal data to third parties. We never use your health or wellness data for advertising profiling.

Our legal basis for processing is: (a) contract performance for account and subscription management; (b) legitimate interests for analytics and security; (c) consent for marketing communications and non-essential cookies.

4. How Long We Keep Your Data

  • Active account data: retained for as long as your account is active
  • Account data after deletion: anonymised within 30 days of deletion request
  • Payment records: retained for 7 years for legal and tax compliance
  • AI chat logs: retained for 90 days for quality and safety monitoring, then deleted
  • Analytics data: aggregated and anonymised, retained indefinitely
  • Marketing consent records: retained for 3 years from last interaction

5. Your Rights Under GDPR

If you are in the EU or UK, you have the following rights regarding your personal data. To exercise any of these rights, email privacy@theglowuphq.com. We will respond within 30 days.

  • Right of access: request a copy of all data we hold about you
  • Right to rectification: correct inaccurate or incomplete data
  • Right to erasure ('right to be forgotten'): request deletion of your data
  • Right to data portability: receive your data in a machine-readable format
  • Right to restrict processing: limit how we use your data
  • Right to object: object to processing based on legitimate interests or for marketing
  • Right not to be subject to automated decision-making with significant effects

You also have the right to lodge a complaint with your national data protection authority (e.g. ICO in the UK, DPA in your EU member state).

6. Cookies

We use cookies to operate the site (necessary), understand usage (analytics), and deliver personalised content (marketing). You can manage your cookie preferences at any time via the cookie banner or our Cookie Policy.

7. Third-Party Services

We use the following third-party services that may process your data:

  • Anthropic: powers our AI wellness coach. Conversations are processed under Anthropic's privacy policy
  • Payment provider (Stripe): processes subscription payments. Card data never touches our servers
  • Analytics provider: anonymised usage analytics only
  • Amazon Associates: affiliate links. Clicking these takes you to Amazon; their privacy policy applies

8. Children's Privacy

Our platform is not intended for users under 13. We do not knowingly collect personal data from children under 13. Users aged 13–15 should have parental or guardian awareness of their use. If you believe we have inadvertently collected data from a child under 13, contact us immediately at privacy@theglowuphq.com and we will delete it promptly.

9. International Data Transfers

Your data may be processed in the United States (by Anthropic and other service providers). We ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission, for any transfers outside the EEA.

10. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes by email or via an in-app notice at least 14 days before the change takes effect. Continued use of the platform after changes constitutes acceptance of the updated policy.

11. Contact Us

For any privacy-related questions or to exercise your rights, contact us at: privacy@theglowuphq.com

We aim to respond to all requests within 5 working days.