1. Controller and contact
glowTFup is provided by etHack Kordian Goldman, NIP 5213849822 (“glowTFup”, “we”, “us”). For personal information that we actually receive, etHack Kordian Goldman is the data controller. Privacy questions and data protection requests may be sent to kordian11111@icloud.com. We have not appointed a Data Protection Officer because our present processing activities do not require one.
2. Facial information processed only on your device
When you choose to perform a scan, the app processes:
- front-camera RGB images and raw TrueDepth depth maps;
- camera calibration information and timestamps;
- facial landmarks, head-pose guidance and derived facial measurements;
- measurement uncertainty, deterministic scores and saved reports;
- manual landmark corrections you make inside the app.
This information may qualify as personal or biometric-related information depending on applicable law. It is used only to provide the measurement, review, report and progress features you request. glowTFup does not use facial information to establish or verify anyone's identity.
3. Facial information is not collected by us
The information listed above remains inside the app's protected storage on your iPhone. We do not receive it, upload it to a server, use it for identity recognition, sell it, share it with advertisers, or use it for marketing or data mining. The app contains no third-party advertising or analytics SDK.
4. Information we may actually receive
We may process the following limited information outside the app:
- Support correspondence: your email address, message, attachments and any device or diagnostic details you choose to provide. Please do not email facial images, depth files or biometric reports.
- Legal and business correspondence: information needed to respond to a request, comply with law or establish, exercise or defend a legal claim.
- Website technical data: GitHub may process IP addresses, request logs, device/browser information and security data when it serves this website. We do not add analytics, advertising cookies or tracking scripts to these pages.
- App Store information: Apple processes purchases and may make subscription entitlement and transaction status available to the app. We do not operate a server that stores your purchase history or payment details.
5. Purposes and legal bases under the GDPR
Where the GDPR applies, we rely on the following legal bases:
- Article 6(1)(b) — contract and pre-contractual steps: responding to requests needed to provide or support glowTFup.
- Article 6(1)(f) — legitimate interests: answering general support and privacy enquiries, protecting the app and website, preventing abuse, and establishing, exercising or defending legal claims. These interests are limited by your rights and reasonable privacy expectations.
- Article 6(1)(c) — legal obligation: retaining or disclosing information where applicable law requires it.
Providing information in a support email is voluntary. If you do not provide enough information to understand the issue, we may be unable to answer or resolve it. Camera access is controlled through iOS permission and is required only to perform a scan.
6. Camera permission
iOS asks for your permission before glowTFup accesses the TrueDepth camera. You may revoke permission at any time in iOS Settings. Without camera access, scanning cannot work, but you may still access information that does not require a new scan.
7. Retention
Saved reports and their reference images are stored locally in the app container. Biometric report files are excluded from iCloud backup and use iOS file protection. You can delete individual reports in the app. Deleting the app removes its remaining locally stored information from the device, subject to normal iOS device-backup behavior controlled by Apple.
Support correspondence is normally deleted or anonymised within 24 months after the enquiry is closed. We may retain particular correspondence longer only when reasonably necessary to comply with law or establish, exercise or defend a legal claim, for the applicable statutory period. GitHub and Apple determine retention periods for information they process under their own policies.
8. Recipients and international transfers
Limited information may be handled by:
- Apple, including iCloud Mail and App Store/StoreKit services, for support email delivery and subscription processing;
- GitHub, Inc. and its affiliates, which host these public legal pages;
- professional advisers or public authorities, only where reasonably necessary or legally required.
Apple and GitHub may process information outside the European Economic Area. Where GDPR transfer rules apply, such transfers are handled using an applicable adequacy decision, the EU–US Data Privacy Framework where available, Standard Contractual Clauses, or another lawful safeguard. Details are available in Apple's Privacy Policy and GitHub's Privacy Statement.
9. Purchases and Apple services
Subscriptions are purchased and managed through Apple's App Store and StoreKit. We receive only the entitlement state needed to unlock subscribed features; we do not receive your payment-card details. Apple's handling of App Store data is governed by Apple's App Store & Privacy information and its privacy policy.
10. Your GDPR rights
Because we do not receive or maintain your facial data, we generally cannot access, export or delete it remotely. You control it on your device through the app's delete controls and by deleting the app.
For personal information we actually hold, you may have the right to request access, rectification, erasure, restriction of processing, data portability, or to object to processing based on legitimate interests. These rights may be limited where an exemption applies. You also have the right to lodge a complaint with a supervisory authority. In Poland, the competent authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), available at uodo.gov.pl.
To exercise a right, email kordian11111@icloud.com. We may need to verify that the request relates to you. We normally respond within one month as required by the GDPR.
11. Automated processing and scores
glowTFup calculates measurements and transparent deterministic heuristic scores locally on your device. These outputs do not produce legal effects or similarly significant effects and are not used by us to make decisions about you. We do not perform advertising profiles or identity recognition.
12. Children
glowTFup is not directed to children and is not offered as a children's app. We do not knowingly collect personal information from children.
13. Security and limitations
We use iOS platform protections and keep measurement data on-device to reduce exposure. No storage system can be guaranteed completely secure. Protect your iPhone with a passcode and keep iOS updated.
14. Changes
We may update this policy when the app or legal requirements change. The effective date above identifies the current version. Material changes will be reflected in the app or on this page as appropriate.
15. Contact
etHack Kordian Goldman · NIP 5213849822
kordian11111@icloud.com