Overview
HerGlow is operated by Maxim Bordon. HerGlow does not have a user account or authentication system. The app does not use advertising, tracking, IDFA, third-party analytics, cookies, or crash-reporting SDKs.
HerGlow does not sell personal information and does not use personal data for targeted advertising or cross-app tracking.
Information users provide
You may choose to provide selfies, profile information, goals, progress details, consent choices, and app history while using HerGlow. Because HerGlow does not use accounts, this information is not tied to a HerGlow login.
The app uses your camera and photo library only when you choose to take, upload, or save images. Permission prompts are controlled by iOS, and you can change permissions in your device settings.
Face Data and AI Image Processing
HerGlow processes face data only when you voluntarily use a feature that requires a selfie. This includes selfies you capture or select, the visible facial image contained in the selfie, Face Scan appearance analysis and results, Best Self edited or generated images, and temporary on-device face validation performed by Apple Vision.
Face Scan appearance analysis may include skin, symmetry, eyes, cheekbones, jawline, lips, glow, overall, potential, percentile, strengths, weaknesses, recommendations, and similar appearance-related results.
What HerGlow does not do: HerGlow does not perform facial recognition, identify or authenticate your identity, create a biometric identifier or persistent face template, or match or compare your face against a face database.
How collection and transmission work: You choose whether to capture or select an image. Before HerGlow sends a selfie for AI photo processing, you must provide explicit in-app permission. If you decline that permission, the image is not uploaded and is not sent to OpenAI.
When you grant permission for AI photo processing, the selfie is resized and sent over encrypted HTTPS through HerGlow's backend, hosted by Vercel, to OpenAI, HerGlow's third-party AI provider. Face Scan uses the selfie only to provide the appearance analysis you request. Best Self uses the selfie only to create the edited glow-up image you request.
HerGlow does not use face data for advertising, cross-app tracking, identification, authentication, sale, or data-broker sharing. HerGlow does not intentionally send OpenAI your name, email, app cookies, or device identifiers with image-processing requests.
Provider handling: OpenAI processes selfies, generated images, AI responses, and instructions for Face Scan and Best Self. Vercel hosts the backend through which requests pass. RevenueCat handles subscription and purchase status but does not receive selfies. Upstash Redis receives only limited security, rate-limit, idempotency, and purchase-ledger metadata and does not receive selfies. Apple handles App Store purchases and device camera and photo-library permissions.
Service providers are required by applicable contracts and law to protect information and process it only for the services they provide, providing the same or equivalent protection described in this policy.
Retention: HerGlow's backend processes selfies, generated images, and AI responses temporarily in memory and does not intentionally persist them after the request completes. Selfies, generated images, appearance scores, prompts, and AI responses are not intentionally written to HerGlow production logs.
OpenAI's standard API abuse-monitoring logs may retain API inputs and outputs for up to 30 days, unless longer retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Data submitted through the OpenAI API is not used to train or improve OpenAI models unless the API account explicitly opts into data sharing.
Vercel may retain ordinary infrastructure metadata, including IP address, route, request time, status, region, and request ID, under its policies, but HerGlow does not intentionally place selfie content in its application logs. Locally stored images and results remain on your device until you delete them through Delete All Data, delete the app, or device or backup behavior removes them.
Consent withdrawal and deletion: You may decline AI processing. You can withdraw locally saved consent and delete locally stored HerGlow information through Delete All Data. After consent is withdrawn, no new selfie is transmitted unless you grant permission again. Data already processed by service providers may remain subject to their retention periods. For privacy questions or deletion requests, contact support.herglow@gmail.com.
Information stored on-device
Selfies, scan results, generated images, profile information, goals, progress, consent status, and history may be stored locally on your device. This local storage helps the app show your history and keep your preferences available without a HerGlow account.
Purchases and RevenueCat
HerGlow uses RevenueCat to manage purchases and subscription access. RevenueCat may process anonymous purchase identifiers, offerings, transaction status, subscription status, and entitlements.
Before paid server features run, HerGlow's backend sends your anonymous RevenueCat App User ID to RevenueCat to verify that the premium entitlement is active. This identifier is supplied by the app and is used as practical access control, not as cryptographic proof of device identity.
HerGlow does not intentionally send RevenueCat selfies, profile photos, name, age, or gender. Apple processes App Store purchases under Apple's own privacy policy. HerGlow's backend does not independently verify Apple StoreKit transaction JWS values.
Service providers
HerGlow uses service providers to operate the app and provide the features you request:
- OpenAI processes Face Scan and Best Self image requests, including selfies, instructions, generated images, and AI responses needed to provide the requested feature. OpenAI Privacy Policy
- Vercel hosts the HerGlow backend through which Face Scan, Best Self, purchase-verification, and security requests pass. Vercel Privacy Notice
- Upstash Redis processes limited security, rate-limit, idempotency, and retry metadata for backend abuse and cost protection. Upstash Redis does not receive selfies. Upstash Privacy Policy
- RevenueCat manages purchase status and entitlements. RevenueCat does not receive selfies. RevenueCat Privacy Policy
- Apple provides iOS, camera and photo library permission controls, and App Store purchases. Apple Privacy Policy
These service providers are required by applicable contracts and law to protect information and process it only for the services they provide, providing the same or equivalent protection described in this policy.
Purposes of processing
HerGlow processes information to:
- provide Face Scan and Best Self features you request;
- validate that an image contains a face before processing;
- show locally stored results, history, goals, and progress;
- manage purchases, subscription status, and entitlements;
- operate, secure, debug, and maintain the backend service;
- respond to privacy or support requests.
Data retention
HerGlow's backend processes Face Scan selfies, Best Self selfies, generated images, and AI responses temporarily in memory and does not intentionally persist them after the request completes. API responses use Cache-Control: no-store.
Selfies, generated images, appearance scores, prompts, AI responses, raw provider errors, and image information are not intentionally written to HerGlow production logs.
OpenAI's standard API abuse-monitoring logs may retain API inputs and outputs for up to 30 days, unless longer retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Data submitted through the OpenAI API is not used to train or improve OpenAI models unless the API account explicitly opts into data sharing.
Vercel may retain ordinary infrastructure metadata, including IP address, route, request time, status, region, request ID, and infrastructure logs, under its policies. HerGlow does not intentionally place selfie content in its application logs. Redis-backed records use limited metadata such as hashed RevenueCat App User IDs, idempotency keys, purchase-ledger metadata, counters, and expiration windows. Upstash Redis does not receive selfies.
Information stored locally on your device remains there until you delete it through Delete All Data, delete the app, or it is otherwise removed by device or Apple backup behavior.
Security
HerGlow uses reasonable technical measures designed to limit the information sent to providers and avoid intentional storage of sensitive image-processing data on the backend. However, no app, network, or storage system can be guaranteed to be completely secure.
User choices and deletion
You can choose whether to take or upload images, whether to save generated images, and whether to make purchases. You can also manage camera and photo library permissions in iOS settings.
You may decline AI processing. If you decline the explicit in-app permission for AI photo processing, your selfie is not uploaded and is not sent to OpenAI.
You can withdraw locally saved consent and delete locally stored HerGlow data using Delete All Data in the app. After consent is withdrawn, no new selfie is transmitted unless you grant permission again. Deleting the app also removes its local data, subject to device backups and Apple behavior.
Locally stored data is separate from information that has already been processed by service providers. Provider copies may remain subject to the retention periods described in this policy and in those providers' policies.
For privacy questions or deletion requests, contact support.herglow@gmail.com.
International processing
HerGlow's service providers may process information in different countries or regions. Processing may involve international data transfers through Vercel, OpenAI, Upstash Redis, RevenueCat, and Apple.
Children's privacy
HerGlow is not intended for children under 13. Users under the age of majority should use HerGlow only with permission from a parent or guardian.
If you believe a child has provided information through HerGlow, contact support.herglow@gmail.com.
Changes to this policy
HerGlow may update this Privacy Policy from time to time. If the policy changes, the updated version will be posted on this page with a new effective date.
Contact information
HerGlow is operated by Maxim Bordon. For privacy questions, support, or requests, email support.herglow@gmail.com.