Effective date: July 20, 2026 · Last updated: July 20, 2026
This Privacy Policy describes how Gloss ("Gloss," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the Gloss mobile application (the "App") and any related services (together, the "Service"). By using the Service, you agree to the practices described in this Policy. If you do not agree, please do not use the Service. Your use of the Service is also governed by our Terms of Use.
| Category | Examples | Required? |
|---|---|---|
| Account information | Email address and password, or an identifier provided by Apple or Google if you sign in with those services. First-time use may create an anonymous account containing no personal information at all. | Optional — the App works anonymously until you choose to create an account |
| Skin profile | Your answers to onboarding questions: how your skin feels, your main concern, your current routine, SPF habits, makeup habits, your first name (if provided), and reminder preferences | Yes, to personalize the Service |
| Scan photos | The selfie you take or select for each skin scan | Yes, to perform a scan — see Section 2 for how these are handled |
| Communications | Emails you send to our support address and the information you choose to include in them | Optional |
| Category | Examples |
|---|---|
| Scan results | Your daily glow score, the four metric scores (hydration, clarity, texture, radiance), short AI-written observations and tips, and the date of each scan |
| Routine activity | Which routine steps you check off, stored on your device |
| Usage counts | The number of analysis requests made per day per account, and coarse network information (IP address) used solely to enforce fair-use limits and prevent abuse |
| Device data | Basic technical information sent automatically by your device when it communicates with our servers (e.g., IP address, request timestamps) |
Subscriptions are processed by Apple through your App Store account. We receive subscription status information (for example: an anonymized identifier, which plan is active, when it renews or expires) via our subscription-management provider, RevenueCat. We never receive or store your payment card details, billing address, or Apple ID password.
This is the part of the Service people ask about most, so we want to be precise:
What we collect. The only face data the Service collects is the ordinary photograph (a standard JPEG image) that you choose to capture or select for a skin scan, and which may show your face. We do not create, derive, generate, or store a faceprint, face template, face geometry, face signature, face embedding, or any other biometric identifier. The Service performs no facial recognition, no facial identification, no face matching, no face tracking, no emotion or demographic inference, and no age estimation. It does not use the TrueDepth camera, ARKit face tracking, Vision face-landmark APIs, or any comparable face-detection framework. The photograph is never used to identify you, to distinguish you from any other person, or to link you to any other record.
How it is used. The photograph is used for one purpose only: to generate a cosmetic appearance score (hydration, clarity, texture, radiance), two short cosmetic observations, and a skincare tip. It is not used for advertising, profiling, marketing, research, product development, or model training, and it is never sold or rented.
How it is shared. The photograph is transmitted over TLS to our processing server and passed to a single third-party AI provider, Anthropic, PBC (United States), which analyzes it and returns the scores. Anthropic is the only third party that receives it. We share it with no one else, and we do not sell or disclose it to data brokers, advertisers, or any other party except where required by law.
Where it is stored, and for how long. The photograph is not stored. It exists only in memory for the duration of a single analysis request — typically a few seconds — and is discarded when that request completes. It is never written to our database, our object storage, or our logs. Under Anthropic's commercial API terms, API inputs and outputs are not retained for training and are not used to train Anthropic's models. Our retention period for face data is therefore zero: no photograph is retained beyond the lifetime of the request that carried it. A reduced-size copy of your own scan may remain on your own device so you can view your personal timeline; that copy never leaves your device and is deleted when you delete the App or use "Delete account & data".
Your permission. Nothing is transmitted until you have given explicit, informed permission in the App. Before your first scan, the App shows a dedicated consent screen naming Anthropic, PBC, itemizing every field that will be sent and every field that will not, and describing retention. You must tap "I agree" for any photo to be transmitted. If you decline, the App remains fully usable and your scores are calculated on your device with nothing sent at all. You may withdraw permission at any time under Settings → How Gloss works → "Send my scans to Anthropic's AI"; withdrawing takes effect immediately for all future scans.
We use the information described above to:
We do not use your information for third-party advertising, and we do not build advertising profiles about you.
Skin scans are analyzed by an artificial-intelligence vision model operated by Anthropic, PBC. Your photo and relevant, pseudonymous parts of your skin profile are submitted to Anthropic's API for the sole purpose of generating your scores and observations, subject to Anthropic's commercial API terms, under which API inputs and outputs are not used to train Anthropic's models without customer opt-in. AI outputs are estimates generated by a statistical model: they can be imperfect, may vary between scans, and are provided for general informational and cosmetic-tracking purposes only (see Section 13).
Anthropic is the only third-party AI provider used by the Service. The exact fields sent on each scan — and the fields that are never sent, including your name, email address, account identifier, device identifier, location, and any advertising identifier — are listed inside the app under Settings → How Gloss works → “AI & your data — what’s sent, and to whom”, so you can review them at any time without leaving the app.
If you are located in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases:
We share information only with the service providers ("processors") that make the Service work, and only what each needs:
| Provider | Role | What they process |
|---|---|---|
| Supabase, Inc. | Authentication, database, and server-function hosting | Account identifiers, skin profile, scan scores, usage counts; photos pass through our server function during analysis only |
| Anthropic, PBC | AI analysis of scans | Scan photo and pseudonymous scoring context, for the duration of each analysis request |
| RevenueCat, Inc. | Subscription management | Anonymized user identifier and subscription status |
| Apple Inc. | Payment processing, app distribution | Your purchase, handled under Apple's own terms and privacy policy |
| GitHub, Inc. | Hosting of this policy page | Standard web-server logs when you view this page |
In addition, we may disclose information: (a) to comply with applicable law, regulation, legal process, or governmental request; (b) to enforce our Terms of Use, including investigation of potential violations; (c) to detect, prevent, or otherwise address fraud, abuse, security, or technical issues; (d) to protect the rights, property, or safety of Gloss, our users, or the public; and (e) in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, in which case the successor will be bound by this Policy or will notify you of changes. We do not sell your personal information to anyone, and we do not share it for cross-context behavioral advertising.
Each provider above acts as our processor under a written agreement that requires it to protect your information to a standard at least equal to the protections described in this Policy, to process it only on our documented instructions and only for the purpose shown, to impose confidentiality obligations on its personnel, to maintain appropriate technical and organisational security measures, and to delete or return the data when the service ends. We confirm that every third party with which the App shares personal data, including our AI provider Anthropic, PBC, provides the same or equal protection of user data as stated in this Policy and as required by Apple's Developer Program License Agreement. None of these providers is permitted to sell your information, to use it for their own advertising, or to use scan photos or results to train AI models.
When you delete your account (Settings → "Delete account & data"), your account, profile, scan history, and usage records are permanently deleted from our production systems, and data stored on your device is cleared. Residual copies may persist for a limited time in encrypted backups before being purged in the ordinary course.
We take reasonable technical and organizational measures to protect your information, including: encryption of data in transit (TLS) for all communication between the App and our servers; encryption at rest for our database; row-level access controls so each account can only ever read its own data; server-side (not client-side) enforcement of access and usage rules; and secret credentials stored in a managed secrets system rather than in the App. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security; you use the Service at your own risk to the extent permitted by law. If we learn of a breach affecting your personal information, we will notify you as required by applicable law.
We will respond to verifiable requests within the timeframes required by applicable law. We may need to verify your identity (for example, by confirming control of the email on the account) before acting on a request.
If you are a California resident, the California Consumer Privacy Act as amended (CCPA/CPRA) gives you specific rights. In the preceding 12 months we have collected the categories of personal information described in Section 1: identifiers (email, account IDs), and inferences/characteristics you provide about your skin (your profile and scores). We collect them for the purposes in Section 3, from you directly and from your device, and disclose them only to the service providers in Section 6.
To exercise these rights, contact us at the address in Section 16. An authorized agent may submit a request on your behalf with proof of authorization.
Our service providers operate primarily in the United States. If you use the Service from outside the U.S., your information will be transferred to, stored, and processed in the United States and possibly other countries where our providers operate, which may have data-protection laws different from those in your jurisdiction. Where required, transfers are protected by appropriate safeguards such as standard contractual clauses implemented by our providers.
Gloss is a general-audience service intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete it promptly. If you believe a child under 13 has provided personal information through the Service, please contact us at the address in Section 16 so we can take appropriate action. Users under 18 should use the Service only with the involvement and consent of a parent or guardian.
Gloss is a cosmetic and wellness tracking tool. Scores, observations, tips, and routines generated by the Service are for general informational purposes only. They are not medical advice, diagnosis, or treatment; the Service does not detect, diagnose, or treat any medical or dermatological condition; and nothing in the Service creates a doctor–patient relationship. Always consult a qualified healthcare professional (such as a dermatologist) about any skin condition or concern. See our Terms of Use for the full disclaimer.
The Service may contain links to third-party websites or services (for example, Apple's subscription-management page or this hosted policy). We are not responsible for the privacy practices of third parties, and this Policy does not apply to them. We encourage you to review the privacy policies of any third-party service you interact with.
We may update this Policy from time to time as the Service evolves or as legal requirements change. When we do, we will update the "Last updated" date at the top of this page, and for material changes we will provide additional prominent notice (for example, in the App). Your continued use of the Service after a change becomes effective constitutes acceptance of the updated Policy. We encourage you to review this page periodically.
For privacy questions, data requests, or complaints:
Gloss — Privacy
Email: glossaiskn@gmail.com
Please include "Privacy request" in the subject line so we can route it quickly.