Glimpse ("we", "us") is an entertainment app that uses AI to generate readings from selfies. This notice explains what personal data we collect, how we use it, and the choices you have. It applies whether you use Glimpse as a guest or as a registered user.
1. Data we collect
- Account data: email address, display name, avatar URL, password hash (handled by our auth provider), referral code.
- Selfies and derived analysis: photos you upload or capture, the AI-generated reading, scores, age progressions and shareable cards.
- Usage data: scans, comparisons, daily fortunes, streak, XP, plan status, device identifier (guest mode).
- Payment data: subscription status and Stripe customer/subscription IDs. We do not store full card numbers.
- Technical data: IP address and user agent at sign-up and at consent acceptance (for audit only), basic error/diagnostic logs.
2. Why we use it
- To deliver the core service: generate readings, comparisons and daily fortunes.
- To operate accounts, streaks, leaderboards (opt-in only) and referrals.
- To process subscriptions and prevent abuse of free-tier limits.
- To improve quality, debug errors and protect the platform.
- To comply with legal obligations (PDPA, GDPR, tax records).
3. Retention
- Guest scans: automatically deleted after 7 days.
- Account scans & comparisons: kept while your account is active. You may delete individual scans at any time.
- Account data: kept until you delete your account, then removed within 30 days (some records may be retained longer where required by law, e.g. financial records).
- Consent records: kept for the lifetime of the account as a compliance audit trail.
4. Sharing and sub-processors
We do not sell your personal data. We share limited data with vetted sub-processors that help us run the service:
- Lovable Cloud / Supabase — hosting, database, authentication, storage.
- Cloudflare — edge delivery and DDoS protection.
- Google AI / Lovable AI Gateway — selfie analysis (images sent for inference, not used to train third-party models per provider terms).
- Stripe — subscription payments.
- Google OAuth — optional sign-in.
5. Your rights
Under PDPA, GDPR and similar laws you may have the right to access, correct, delete, restrict or port your data, and to withdraw consent at any time. See our PDPA notice and GDPR notice for the specifics and how to exercise them.
6. Security
We use row-level security on user data, encrypted connections (TLS), encrypted storage at rest at our hosting provider, and least-privilege access for our team. No system is perfectly secure — please use a strong, unique password.
7. Children
Glimpse is not directed to children under 13 (or under 16 in the EEA). Do not upload selfies of minors.
8. Contact
Privacy questions, data subject requests, or DPO contact: privacy@glimpze.org.