Glam

PRIVACY POLICY

Last Updated: July 15, 2026

At Glam Labs, Inc. (“Glam Labs”, “us”, we”, or “our”), protecting your privacy and maintaining absolute data transparency is our core priority. We comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and other global privacy standards.

This Privacy Policy explains how we collect, process, secure, and retain your personal information when you access our mobile applications (iOS and Android), desktop applications, websites, and web platforms (collectively, “GLAM” or the “Services”).

1. Definitions of Core Processing Terms

2. Information We Collect and Process

To provide our editing and generative AI services, we collect several categories of information:

2.1 Personal Information Provided Directly by You:

2.2 Processing of Uploaded Photos and Videos:

Most standard image and video editing features are processed directly on your local device. However, utilizing generative AI features (including the AI Avatars feature) requires cloud processing.

3. Apple App Store Privacy Disclosures (Guidelines 5.1.1 & 5.1.2)

To comply with Apple’s developer requirements regarding “Face Data” and user transparency, we establish the following operational rules:

3.1 On-Device Alignment Analysis:

Any facial characteristics, landmark coordinates, or alignment geometry analyzed on your device (collectively, “Face Data”) are processed locally utilizing Apple Vision. This landmark data is processed strictly in volatile system memory, is dropped following alignment, is never serialized, written to disk, or saved, and is never used for user tracking, behavioral profiling, marketing, or biometric identification.

3.2 Data Storage and Recipients:

3.3 Platform-Specific Data Sharing for Refunds:

If you request a refund for an in-app purchase through Apple’s App Store, we may provide Apple with certain consumption metrics. This metadata is shared solely to help Apple make informed refund decisions and includes:

4. Data Retention and Deletion

We maintain the following data retention policy:

Data CategoryRetention PeriodAction Taken upon Account Termination or request
Uploaded Source PhotosIndefiniteRetained securely on DigitalOcean cloud servers to allow personalized model (LoRA) retraining when migrating to improved base model versions.
Personalized AI Model Weights (LoRAs)IndefiniteStored and persisted securely on DigitalOcean to prevent requiring users to re-train from scratch on every generation.
Generated Output Content (Avatars)User-Controlled / IndefiniteMaintained on DigitalOcean Spaces to remain accessible across your devices. Removed only upon administrative backend deletion of file assets.
Account Data & Metadata (MongoDB)Active DurationRetained for the duration of your active account. Deleted within thirty (30) days of account termination.
Support Tickets & Comms1 to 2 YearsAnonymized and retained for support auditing and security verification, then systematically purged.

5. Your Rights and Choices

5.1 Account Deletion and File-Level Erasure Limitations:

CRITICAL LIMITATION DISCLOSURE: When you initiate account deletion, we permanently delete your profile and active records from our production databases, rendering your account inaccessible and removing the association between your identity and your uploaded content from our active systems. Although immediate file level deletion from all cloud storage and backup infrastructure may not be technically feasible, any remaining source photos, personalized model weights (including LoRAs), generated outputs, or encrypted backup copies that temporarily remain within our or our service providers' secure cloud infrastructure are permanently inaccessible, cryptographically orphaned or otherwise disassociated from your account, cannot reasonably be associated with you or used to identify you, and are not used for any business, operational, or AI training purposes following account deletion. Such residual copies are retained solely as part of secure backup or storage processes and are automatically overwritten or permanently destroyed in accordance with our data retention and backup policies. We process account deletion requests in accordance with applicable privacy laws, including the GDPR and the CCPA/CPRA, subject to any applicable legal exceptions.

5.2 Data Portability and Access Requests:

You have the right to request a complete, machine-readable copy of your personal data. To exercise this right, email your request to [email protected]. Following identity verification, our privacy compliance team will deliver your secure data package via electronic mail within forty-five (45) days.

5.3 Community Feed Control:

5.5 Community Feed

GLAM features a voluntary community space where users can share their artistic creations. If you choose to publish your Output Content to the Glam Community Feed, you grant us a non-exclusive, royalty-free, worldwide, transferable, and sub-licensable license to display, store, reproduce, and make such materials available to other users. Other users may use your shared assets as reference or inspiration for their own generations. You can toggle these sharing permissions or delete your public feed posts at any time within your in-app settings.

6. Security Safeguards

We implement robust administrative, physical, and electronic security measures to safeguard your personal data. All database records and stored cloud assets are protected behind a Virtual Private Network (VPN) and encrypted in transit and at rest. Access is strictly limited to authorized personnel subject to binding confidentiality agreements.

7. Global Compliance Addenda

California Privacy Rights (CCPA/CPRA):

We do not sell or “share” (for cross-context behavioral advertising) your personal information. California residents have the right to request disclosures regarding collected data categories, request deletion (subject to the cloud-storage limitations disclosed in Section 5.1), and opt out of any future data sales by contacting [email protected].

United Kingdom & European Union (GDPR):

Our European legal basis for processing is the performance of our contract with you or your explicit, informed consent. You have the right to lodge complaints with your local supervisory authority (e.g., ICO in the UK, Garante in Italy, AEPD in Spain, CNIL in France, BfDI in Germany, or FDPIC in Switzerland).

In compliance with the UK GDPR and EU GDPR, Glam Labs, Inc. has appointed its corporate legal counsel to act as its designated representative:

Canadian (PIPEDA) & Australian (APP) Privacy Laws:

Your data may be transferred to and stored on servers in the United States. By using our Services, you consent to this cross-border transfer. You may contact our designated Privacy Officer at [email protected] with any compliance inquiries.

8. Privacy Policy Updates

We reserve the right to revise this Privacy Policy. Material updates will be communicated to you via email or through prominent notifications within the App prior to the changes taking effect. Continued use of the App following update notifications constitutes your acceptance of the revised policy.

9. Privacy Support Contacts