GlowTheory

Security & Privacy Posture

Last reviewed: 20 April 2026 · Owner: GlowTheory (EquationX) · Contact: hello@glowtheory.app

This document describes how GlowTheory handles user data, where it lives, how it is protected, and where the company is on the path to formal certifications. It is intentionally concrete. Anything written here is implemented today unless explicitly marked as planned.

1. What data we collect

CategoryDataPurpose
AccountEmail, display name, Firebase Auth uid, provider, email-verification status, sign-in timestampsAuthentication, sessions
Skin intakeDeclared skin type, concerns, experience level, skincare philosophy, age range, pregnancy flag, budgetPersonalised routine
BiometricSelfie image (device-captured), derived 468-point facial landmark geometry via MediaPipe, zone-level observations via Google Gemini VisionSkin scan, zone analysis, progress tracking
Routine & shelfAI-generated routine, user-owned products, shopping list, user editsRoutine delivery, expiry reminders, shelf matching
UsageScan count, rescan timestamps, check-in streak, last-active timestampStreaks, progress, admin metrics
CommunicationsEmail send history, delivery receipts, push token, notification preferencesTransactional + opt-in notifications

We do not collect precise geolocation, contacts, phone numbers, payment info (the app is free today), social-graph data, or browsing history outside the app.

2. Where data lives

All user data is stored in Google Cloud Platform, in the Firebase project glow-theory-2eded (US multi-region, ready to deploy to europe-west1 before EU launch). Infrastructure lives in the adjacent equationx project.

Selfie images are not stored long-term. They transit to our Vision service in memory, are analysed, and discarded after the response returns. Only derived metrics — skin-type label, concern tags, health score, zone observations — are persisted.

3. Encryption

4. Authentication and access control

User

Admin

Service-to-service

Sensitive paths proxy through Next.js API routes on glowtheory.app (Firebase session verified) before reaching internal microservices. Microservice URLs are not exposed to the browser. Public API surfaces on our vision and routine services are being locked to authenticated callers in an in-progress security pass; per-user rate limits and Cloud Monitoring alerts on Gemini spend are already in place as interim mitigations.

5. Biometric data handling

GlowTheory's skin scan processes facial landmark geometry, classified as biometric data under Illinois BIPA, Texas CUBI, Washington HB 1493, CCPA/CPRA (sensitive personal information), and GDPR Art. 9 (special category data).

6. Data retention and deletion

7. Vendors (sub-processors)

VendorPurposeRegion
Google Cloud / FirebaseHosting, Auth, Firestore, Cloud Run, Cloud Build, Secret Manager, Logging, Gemini inferenceUS (EU planned)
ResendTransactional email deliveryUS / EU
ExpoPush notification deliveryUS
GitHubSource code hosting, CI triggersUS

We do not resell data to any third party.

8. Incident response

9. Application security

9b. Training-data storage (opt-in only)

Users can optionally help us train and improve GlowTheory's own skin analysis models. If — and only if — a user affirmatively opts in (unticked by default at signup, revokable any time from their profile), the confirmed selfie from each scan is stored alongside the skin-type and concerns they confirmed.

10. Our framing — cosmetic skincare, not medical advice

GlowTheory is a cosmetic skincare app. We do not diagnose medical conditions, we do not prescribe treatments, and we are not a substitute for a dermatologist, esthetician, or physician.

11. Compliance posture

RegulationStatus
GDPR (EU)Architectural readiness in place (consent, portability, erasure, sub-processor list). Full compliance locked in before EU launch.
BIPA (Illinois)Explicit biometric consent and deletion implemented. BIPA counsel review scheduled before opening Illinois.
CCPA / CPRA (California)Sensitive-data consent surfaces and opt-out paths implemented. We do not sell data.
SOC 2 Type IPlanned. Target: 6 months post-seed funding. Expected engagement: Vanta or Drata + third-party auditor.
SOC 2 Type IIPlanned. Target: 24 months after Type I. Controls are being designed to be SOC 2 compatible from day one.
HIPAANot in scope — direct-to-consumer. A future clinic-facing product would add BAAs and HIPAA controls in that product only.

Questions

Security or privacy questions can be sent to hello@glowtheory.app. We respond to privacy requests within 30 days and to security disclosures within 5 business days.

See also: Privacy Policy · Terms of Service

Follow · tipsInstagram