PRIVACY POLICY
At Glam Labs, Inc. (“Glam Labs”, “us”, we”, or “our”), protecting your privacy and maintaining absolute data transparency is our core priority. We comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and other global privacy standards.
This Privacy Policy explains how we collect, process, secure, and retain your personal information when you access our mobile applications (iOS and Android), desktop applications, websites, and web platforms (collectively, “GLAM” or the “Services”).
This Privacy Policy (“Policy”) governs the use of GLAM, the Website and your use of any of our Services provided through the same. When using or accessing the Website and the Services, you agree to be bound by the terms of this Privacy Policy and our Terms of Use, available at https://getglam.app/terms/. This policy may refer to users as “you” or “user”. If you do not agree to the terms within this Privacy Policy and the corresponding Terms of Use, do not access or use GLAM, the Website or the Services.
Please read this Privacy Policy carefully to understand our policies and practices regarding your personal information and how we will treat it. If you do not agree with the terms of this Privacy Policy, please do not use GLAM or our Website and Services. By accessing or using the Website, the App and Services, you agree to this privacy policy. This Policy may change from time to time (see Changes to Our Privacy Policy). Your continued use of the Website, the App and the Services after we make changes is deemed to be acceptance of those changes, so please check the policy periodically for updates.
1. Definitions of Core Processing Terms
- “App” refers to the GLAM mobile application or the desktop application version of GLAM.
- “Biometric Identification” refers to the automated recognition of individuals based on measurable physical or behavioral characteristics, such as fingerprints, facial features, iris patterns, or voice, that are unique to each person.
- “Face Data” refers to any facial landmarks, coordinates, or mathematical representations of facial geometry extracted from your uploaded photos. Initial face detection is executed locally on your device via Apple Vision strictly in volatile system memory. It is dropped after successful processing, is never serialized, is not written to persistent disk storage, and is not transmitted to our servers. We retain only a non-biometric indicator that a face is present and an associated photo identifier.
- “Glam Community Feed” means the voluntary, user-facing, interactive community space and discovery showcase operated within the App where Users can voluntarily publish, share, and display their generated Output Content, along with any associated text prompts, style settings, or filter configurations, to other Users of the Services.
- “Input Content” refers to the photos, videos, prompts, configurations, and metadata you upload to the App.
- “Metadata” includes technical file characteristics (such as dimensions, file format, device details, and upload timestamps) generated during processing.
- “Output Content” (or “Generated Content”) refers to the final artistic avatars, edited files, or video assets returned to you.
- “Prompts” refers to the text descriptions or artistic style instructions you submit to steer the generative AI models.
- “Services” means the content and features accessible or usable by you when you utilize GLAM as well as those features and functions that we provide and make available to you through GLAM while you are a GLAM User.
- “Users” refers to any person accessing or utilizing GLAM or the App.
- “Website” refers to the following url: https://getglam.app/
2. Information We Collect and Process
To provide our editing and generative AI services, we collect several categories of information:
2.1 How we collect your personal information
Glam Labs collects personal information from you upon your registration for our Services and upon your log-in to or accessing of GLAM, our Website or Services. We collect any additional information about you when you interact with us electronically or in person, when you access GLAM, or our Website and when we provide our Services to you.
It may not be readily apparent to you when such data is being collected. For instance, when you visit our Website or download or use GLAM, your IP address is collected so that we know where to send information you are requesting. An IP address is a number that is used by computers on the network to identify your computer every time you log on to the Internet.
2.2 Why we collect your personal information
We process your personal information because we have a contractual obligation with you. When you create an account to use GLAM (required for any paid subscriptions), or our Website and Services, and agree to our Terms of Service, a contract is formed between you and us. In order to carry out our contractual obligations we need to process the information you provide, which also includes personal information. Even if there is no direct contractual obligation between us, we may process your information based on your explicit consent you have provided (to us or a third-party data controller) for the processing of that information.
2.3 How we use your personal information
We will use the personal information collected from you:
- to administer your account with us and provide you with our Services;
- to respond to your inquiries and deliver reminder e-mails to you;
- to provide you with information regarding updates and changes to GLAM, our Website, our Terms of Service or any Services we offer or provide through it;
- to improve our products and Services;
- to provide personalized experience for you upon use of our Services.
Additionally, we may use anonymized information we have collected from you to enable us to display advertisements to our advertisers’ target audiences. Even though we do not disclose your personal information for these purposes without your consent, if you click on or otherwise interact with an advertisement, the advertiser may assume that you meet its target criteria.
- Disclosure of personal information
We will not disclose your personal information to any third party and we do not share, sell, rent, or trade your personal information with third parties for their commercial purposes, however, we reserve the right to disclose information about you to third parties for assistance in improving the Glam Labs products and Services. Additionally, we may disclose personal and non-personally identifiable information with third parties service providers, engaged by us to provide technical support, hosting Services, testing, network security or statistical Services, any such disclosure will be subject to confidentiality obligations.
Glam Labs may also disclose information about you to third parties where we have a good faith belief that such disclosure is necessary in order to: (i) protect, enforce, or defend the legal rights, privacy, safety, or property of Glam Labs, our affiliates or their employees, agents and contractors (including enforcement of our agreements and our terms of use); (ii) protect the safety, privacy, and security of users of the Glam Labs employees, owners, or members of the public; (iii) protect against fraud or for risk management purposes; (iv) comply with the law or legal process; or (v) respond to requests from public and government authorities.
Glam Labs may use a third-party payment processor, such as Stripe, Plaid or other credit card provider platforms for payment transactions. Wherever you designate a payment source for transaction processing with us through any platform, you are responsible for visiting, understanding and abiding by all terms of such platforms and such payment sources.
When you choose to use the AI Avatars feature, you provide your gender identification, which is used to retrain the separate copy of the Stable Diffusion model to generate Avatars based on your particular photos. It is our contractual obligation to ensure that we provide you with the requested service. This data is deleted immediately after the Avatars are successfully generated.
2.2 Personal Information Provided Directly by You:
- Contact information, such as your email address and IP address.
- Profile information, including your name, profile picture, or login metadata from third-party social media integrations.
- Demographic characteristics, specifically your gender selection. Note: Your gender selection is processed solely to guide the generative AI model in rendering conventionally matching artistic styles (e.g., more masculine or feminine avatars) and is retained by default as part of our platform’s data retention policy.
- Your profile picture or Avatar.
- Your First and Last Name
2.3 Other information that may be linked to personal information
- Content you post publicly or privately on your glam labs account;
- Searches completed through the website;
- Preference settings;
- Stored information or files created or stored on website or through the services;
- Any emails you send to Glam Labs;
- Times of access to website;
- Websites that referred to Glam Labs;
- Your operating system type.
2.4 Right to access and control your data
We provide you with many choices about the collection, use and sharing of your data, from deleting or correcting data you include in your profile and controlling the visibility of your posts and communication controls. We will provide you with access to your personal information that we store and allow you to:
- Delete your data — you can request that we erase or delete all or some of your personal data (e. g., if it is no longer necessary to provide Services to you);
- Change or correct your data — you have the option to edit some of your personal data through your account. You can also ask us to change, update or fix your data in certain cases, particularly if it’s inaccurate;
- Object to, or limit or restrict, use of data — you can ask us to stop using all or some of your personal data (e. g., if we have no legal right to keep using it) or to limit our use of it (e. g., if your personal data is inaccurate or unlawfully held);
- Right to access and/or take your data — you can ask us for a copy of your personal data and can ask for a copy of personal data you provided in machine readable form.
- We provide our California consumers with detailed information about the categories of personal information you have collected in the past 12 months.
You may send us an e-mail at [email protected] to request any or all of the above.
2.5 Cookies and Tracking Technologies
We collect information about you using “cookies.” Cookies are small data files stored on your hard drive by a Website. The cookies that we use are for authentication purposes (to facilitate your log-in) and session cookies (to recognize your preferences while navigating through the Website).
Usually the information that we collect automatically through cookies is statistical data and cannot be used to identify you as an individual. It helps us to improve our App(s), Website and Services and to deliver a better and more personalized service. Additionally, there might be third party cookies used on our Website by third party advertisers, those cookies are not related to your profile, they cannot identify who you are and therefore are not linked to your personal data. When you first visit our Website, we ask you whether you wish us to use cookies. If you choose not to accept them, we shall not use them for your visit except to record that you have not consented to their use for any other purpose. If you choose not to use cookies or you prevent their use through your browser settings, you will not be able to use all the functionality of our Website or Services.
2.6 Security of your personal information
Glam Labs is committed to ensuring that the information you provide to us is secure from accidental loss and from unauthorized access, use, alteration and disclosure. We have implemented suitable physical, electronic and managerial procedures to safeguard and secure information and protect it from misuse, interference, loss and unauthorized access, modification and disclosure.
- All information you provide to us is stored, if at all, on a secure database behind a Virtual Private Network;
- We restrict access to personal information to employees, contractors and agents who need to know that information in order to operate, develop or improve our Services. These individuals are bound by confidentiality obligations and may be subject to discipline, including termination, if they fail to meet these obligations;
- We back up all client data in multiple data centers enabling speedy recovery in case of a disaster;
- Whenever possible we will make sure we pseudonymise all personal or related data.
The safety and security of your information also depends on you. Where we have given you a password for access to certain parts of our App, Website or Services, you are responsible for keeping this password confidential. We ask you not to share your password with anyone. We urge you to be careful about giving out information in public areas of the Website or our Apps or platforms that support or make them available or usable, including chats or message boards. The information you share in public areas may be viewed by any user of the Website or our Apps or Services.
2.7 Commercial and non-commercial communication
By providing information to the Website or through our App(s) or Services, such as signing up for a newsletter or an account, you have agreed to receive e-mail communication from us. However, you may unsubscribe from certain communications by notifying Glam Labs that you no longer wish to receive solicitations or commercial information. Glam Labs will remove you from the database, where you have the right to request this under the Privacy Policy, Terms of Use, or applicable law, or where Glam Labs voluntarily decides to grant the request.
2.8 Processing of Uploaded Photos and Videos:
Most standard image and video editing features are processed directly on your local device. However, utilizing generative AI features (including the AI Avatars feature) requires cloud processing.
- The AI Pipeline & Storage Infrastructure: To generate personalized avatars, you are required to upload between 10 and 20 photos. These photos are processed within containerized private cloud instances hosted on GPU nodes provided by RunPod (whose Terms of Service are available at https://www.runpod.io/legal/terms-of-service and whose Privacy Policy is available at: https://www.runpod.io/legal/privacy-policy ) and Fal AI (whose Terms of Service are available at https://www.fal.ai/legal/terms-of-service and whose Privacy Policy is available at: https://www.fal.ai/legal/privacy-policy ).
- Our core storage systems, general server infrastructure, and persistent user databases are hosted on DigitalOcean Spaces (S3) in the United States (whose policies are available at: https://www.digitalocean.com/legal/terms-of-service-agreement and https://www.digitalocean.com/legal/privacy-policy ).
- Personalized Face-Based Models: A personalized neural network model utilizing low rank adaptation (a “LoRA”) is trained using your uploaded photos to personalize the network. Both the uploaded source photos and the persistent personalized model weights are retained on our DigitalOcean cloud servers by default. This allows continuous platform utilization and model retraining when migrating to new base model versions without requiring you to manually re-upload photos.
- Explicit Biometric Disclosure: Because the platform generates and stores a persistent mathematical representation of your face (the model weights) to generate your custom avatars, this constitutes persistent facial data storage under applicable laws (such as BIPA, CCPA, and GDPR). By uploading your photos and utilizing the AI Avatar generator, you explicitly consent to the persistent storage of this face-based model on our DigitalOcean cloud servers.
3. Apple App Store Privacy Disclosures (Guidelines 5.1.1 & 5.1.2)
To comply with Apple’s developer requirements regarding “Face Data” and user transparency, we adhere to and require compliance with the following operational rules:
3.1 On-Device Alignment Analysis:
Any facial characteristics, landmark coordinates, or alignment geometry analyzed on your device (collectively, “Face Data”) are processed locally utilizing Apple Vision. This landmark data is processed strictly in volatile system memory, is dropped following alignment, is never serialized, written to disk, or saved, and is never used for User tracking, behavioral profiling, marketing, or Biometric Identification.
3.2 Data Storage and Recipients:
- Infrastructure Hosts: All cloud-based GPU compute processing occurs on secure containerized instances hosted by our compute partners, RunPod (runpod.io) and Fal AI (fal.ai), located in the United States. File storage, photos, and personalized models are stored on DigitalOcean Spaces.
- No Third-Party AI Data Transfer: We do not share, sell, or rent your information, photos, videos, or Face Data with external consumer AI networks (such as OpenAI or Midjourney). All processing occurs within secure containerized environments managed by Glam Labs under strict confidentiality agreements. No user data is ever utilized for third-party model training.
- Zero Commercial Trading: We never sell, rent, or trade your information, photos, videos, Face Data, or generated Output Content with third parties for their commercial purposes.
3.3 Platform-Specific Data Sharing for Refunds:
If you request a refund for an in-app purchase through Apple’s App Store, we may provide Apple with certain consumption metrics. This metadata is shared solely to help Apple make informed refund decisions and includes:
- Time elapsed since app installation and total active usage time.
- Anonymous account identifiers.
- Whether the purchased subscription, in-app Coins, or features were consumed.
- Whether a free trial was utilized and historical refund records.
4. Data Retention and Deletion
We maintain the following treatments with respect to our data retention policy:
| Data Category | Retention Period | Action Taken upon Account Termination or request |
|---|---|---|
| Uploaded Source Photos | Indefinite | Retained securely on DigitalOcean cloud servers to allow personalized model retraining when migrating to improved base model versions. |
| Personalized AI Model Weights | Indefinite | Stored and persisted securely on DigitalOcean to prevent requiring users to re-train from scratch on every generation. |
| Generated Output Content (Avatars) | User-Controlled / Indefinite | Maintained on DigitalOcean Spaces to remain accessible across your devices. Removed only upon administrative backend deletion of file assets. |
| Account Data & Metadata (MongoDB) | Active Duration | Retained for the duration of your active account. Deleted within thirty (30) days of account termination. |
| Support Tickets & Comms | 1 to 2 Years | Anonymized and retained for support auditing and security verification, then systematically purged. |
5. Your Rights and Choices
5.1 Account Deletion and File-Level Erasure Limitations:
- Account Deletion: You can initiate an account deletion directly within the App’s settings menu (for iOS users) or by emailing [email protected] (for Android, Web, and Desktop users).
CRITICAL LIMITATION DISCLOSURE: When you initiate account deletion, we permanently delete your profile and active records from our production databases, rendering your account inaccessible and removing the association between your identity and your uploaded content from our active systems. Although immediate file level deletion from all cloud storage and backup infrastructure may not be technically feasible, any remaining source photos, personalized model weights, generated outputs, or encrypted backup copies that temporarily remain within our or our service providers' secure cloud infrastructure are permanently inaccessible, cryptographically orphaned or otherwise disassociated from your account, cannot reasonably be associated with you or used to identify you, and are not used for any business, operational, or AI training purposes following account deletion. Such residual copies are retained solely as part of secure backup or storage processes and are automatically overwritten or permanently destroyed in accordance with our data retention and backup policies. We process account deletion requests in accordance with applicable privacy laws, including the GDPR and the CCPA/CPRA, subject to any applicable legal exceptions.
5.2 Data Portability and Access Requests:
You have the right to request a complete, machine-readable copy of your personal data. To exercise this right, email your request to [email protected]. Following identity verification, our privacy compliance team will deliver your secure data package via electronic mail within forty-five (45) days.
5.3 Community Feed Control:
GLAM features a voluntary community space where users can share their artistic creations. If you choose to publish your Output Content to the Glam Community Feed, you grant us a non-exclusive, royalty-free, worldwide, transferable, and sub-licensable license to display, store, reproduce, and make such materials available to other users. Other users may use your shared assets as reference or inspiration for their own generations. You can toggle these sharing permissions or delete your public feed posts at any time within your in-app settings.
6. Children’s online privacy protection act
The Glam Labs Website, App(s) and Services are directed to persons over the age of 13. Glam Labs does not knowingly collect information from children under 13 years of age or have any reasonable grounds for believing that persons under the age of 13 are accessing the Website, or our Services or App(s). If Glam Labs discovers any inadvertently collected Personal Information of a person under the age of 13, that information will be swiftly deleted from its’ records. If you believe that Glam Labs may have any information from a person under age 13, please contact Glam Labs at: [email protected]
7. Global Compliance Addenda
California Privacy Rights (CCPA/CPRA):
We do not sell or “share” (for cross-context behavioral advertising) your personal information. California residents have the right to request disclosures regarding collected data categories, request deletion (subject to the cloud-storage limitations disclosed in Section 5.1), and opt out of any future data sales by contacting [email protected]. You can learn more about your rights in this regard by reviewing California Business and Professions Code §§ 22575-22579.
Privacy notice for California residents under the California Consumer Privacy Act
This Privacy Notice for California residents supplements the information contained in our Privacy Policy above and applies solely to all visitors, users, and others who reside in the State of California. We adopt this notice to comply with the California Consumer Privacy Act of 2018 (CCPA) and the California Privacy Rights Act (CPRA) and any terms defined in the CCPA have the same meaning when used in this notice.
A. Categories of Information We Collect
Our Website, App(s) and Services collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or device (“personal information”). In particular, our Website, Services and App(s) have collected the following categories of personal information from its consumers within the last twelve (12) months:
1). Identifiers, such as: names, e-mail addresses, Internet Protocol addresses, or other similar identifiers.
Collected: YES
2) Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) such as: a name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories.
Collected: YES
3) Protected classification characteristics under California or federal law such as: Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).
Collected: NO
4) Commercial information obtained, purchased or considered, such as records of personal property, records of products or Services purchased or other purchasing or use histories or tendencies
Collected: YES
5) Biometric information
Collected: NO
6) Activity information relating to internet or other electronic networks such as browsing or searching history, or interaction with a Website, ad, or app
Collected: YES
7) Geolocation information
Collected: NO
8) Audio, visual, thermal, electronic, olfactory or other similar information
Collected: YES
9) Information related to employment or other professional standings
Collected: NO
10) Information related to education
Collected: NO
11) Any inferences drawn using any of the above information in order to profile a consumer and reflect the consumer’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities and aptitudes.
Collected: NO
B. Under this Privacy Policy, personal information does not include:
- Publicly available information from government records.
- De-identified or aggregated consumer information.
- Information excluded from the CCPA’s scope and covered by certain sector-specific privacy laws, including but not limited to Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data; the Fair Credit Reporting Act (FRCA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver’s Privacy Protection Act of 1994.
C. We obtain the categories of personal information listed above from the following categories of sources:
- Directly from you. For example, from forms you complete on our Website or through our App(s) or Services.
- Indirectly from you. For example, from observing your actions on our Website or through the use of our App(s) or Services or interactions with our advertisers.
- From social media websites that you use to log in or subscribe to our Website, App(s), or Services.
D. Use of Personal Information
We may use, or disclose the personal information we collect for one or more of the following business purposes:
- To fulfill or meet the reason you provided the information. For example, if you share your name and contact information to request a price quote or ask a question about our products or Services, we will use that personal information to respond to your inquiry. If you provide your personal information to purchase a product or service, we will use that information to process your payment and facilitate delivery. We may also save your information to facilitate new product or Service orders.
- To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses.
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
- As described to you when collecting your personal information or as otherwise set forth in the CCPA.
- We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
E. Sharing Personal Information
We may disclose your personal information to a third party for a business purpose. When we disclose personal information for a business purpose, we enter into a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.
We may share your personal information with the following categories of third parties:
- Payment processors (e. g. Paypal, Stripe, App Store, etc.) for purposes of payment
- Google Analytics for Website metrics and Amplitude for App metrics
- Hosting such as Amazon Web Services.
However, we don’t explicitly share any information with web service providers.
F. Your Rights and Choices
The CCPA provides California residents with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.
1) Access to Specific Information and Data Portability Rights. You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months. Once we receive and confirm your verifiable consumer request, we will disclose to you:
- The categories of personal information we collected about you.
- The categories of sources for the personal information we collected about you.
- Our business or commercial purpose for collecting or selling that personal information.
- The categories of third parties with whom we share that personal information.
- The specific pieces of personal information we collected about you (also called a data portability request).
- If we sold or disclosed your personal information for a business purpose, two separate lists disclosing: (i) sales, identifying the personal information categories that each category of recipient purchased; and (ii) disclosures for a business purpose, identifying the personal information categories that each category of recipient obtained.
2) Deletion Request Rights. You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.
- We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:
- Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Debug products to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).
Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent.
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
3) Exercising Access, Data Portability, and Deletion Rights. To exercise the access, data portability, and deletion rights described above, you need to submit a verifiable consumer request to us by sending us a message to our customer service at [email protected] Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child.
You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative.
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
- We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
4) Response Timing and Format. We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time, we will inform you of the reason and extension period in writing. We will deliver our written response by mail or electronically, at your option. Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance, specifically by electronic mail communication.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
G. Personal Information Sales Opt-Out and Opt-In Rights
If you are 16 years of age or older, you have the right to direct us to not sell your personal information at any time (the “right to opt-out”). We do not sell the personal information of consumers we actually know are less than 16 years of age, unless we receive affirmative authorization (the “right to opt-in”) from either the consumer who is between 13 and 16 years of age, or the parent or guardian of a consumer less than 13 years of age. Consumers who opt-in to personal information sales may opt-out of future sales at any time. To exercise the right to opt-out, you (or your authorized representative) may submit a request to us at: [email protected]
Once you make an opt-out request, we will wait at least twelve (12) months before asking you to reauthorize personal information sales. However, you may change your mind and opt back into personal information sales at any time by visiting our Website and sending us a message. We will only use personal information provided in an opt-out request to review and comply with the request. Notwithstanding any other provision of this section, GLAM is not intended for use by persons under the age of 13.
H. Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
- Deny you goods or Services.
- Charge you different prices or rates for goods or Services, including through granting discounts or other benefits, or imposing penalties.
- Provide you a different level or quality of goods or Services.
- Suggest that you may receive a different price or rate for goods or Services or a different level or quality of goods or Services.
However, we may offer you certain financial incentives permitted by the CCPA that can result in different prices, rates, or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your personal information’s value and contain written terms that describe the program’s material aspects. Participation in a financial incentive program requires your prior opt in consent, which you may revoke at any time.
United Kingdom & European Union (GDPR):
Our European legal basis for processing is the performance of our contract with you or your explicit, informed consent. You have the right to lodge complaints with your local supervisory authority (e.g., ICO in the UK, Garante in Italy, AEPD in Spain, CNIL in France, BfDI in Germany, or FDPIC in Switzerland).
In compliance with the UK GDPR and EU GDPR, Glam Labs, Inc. has appointed its corporate legal counsel to act as its designated representative:
- Designated Legal Representative & GDPR Agent: Sutter Law, P.C.
- Address: 51 Moraga Way, Suite 2, Orinda, CA 94563
- Inquiries Contact: https://sutterlegal.com/contact/ or [email protected]
Canadian (PIPEDA) & Australian (APP) Privacy Laws:
Your data may be transferred to and stored on servers in the United States. By using our Services, you consent to this cross-border transfer. You may contact our designated Privacy Officer at [email protected] with any compliance inquiries.
8. Privacy Policy Updates
We reserve the right to revise this Privacy Policy. Material updates will be communicated to you via email or through prominent notifications within the App prior to the changes taking effect. Continued use of the App following update notifications constitutes your acceptance of the revised policy.
9. Privacy Support Contacts
- Corporate Address: Glam Labs, Inc., 769 Monterey Blvd., Suite #5A, San Francisco, CA 94127
- General Privacy Inquiries: [email protected]
- Designated Privacy Officer: [email protected]
10. AI Support Providers
The following is the current list of Glam’s key AI support providers with whom your content (including text, photos, and videos) may be shared to generate the content you request. Each provider processes data under contractual obligations to protect it, and each provider’s own Terms of Service and Privacy Policy are linked below.
| Provider | Purpose | Country of Processing | Terms of Service | Privacy Policy |
|---|---|---|---|---|
| RunPod | AI compute (avatar generation) | United States | Terms | Privacy Policy |
| Fal AI | AI compute (avatar generation) | United States | Terms | Privacy Policy |
| DigitalOcean | Cloud storage and hosting | United States | Terms | Privacy Policy |
