02privacy policy

Privacy Notice

How GlowFeed collects, uses, shares, protects, retains, and deletes personal data, including profile, training, media, social, and safety information.

Version
beta-2026-08-27
Effective
27 August 2026
Language
English
Status
Current
01

Controller and contact

The controller for personal data processed through the GlowFeed beta is Robin Olsson, operator of GlowFeed in Sweden.

Privacy and data requests
support@glowfeed.app
Service
GlowFeed mobile app and related web services
Primary establishment
Sweden

GlowFeed has not appointed a data protection officer. Privacy questions and rights requests are handled through the contact above.

02

Scope

This Notice applies when you create or use a GlowFeed account, complete onboarding, log workouts, upload media, publish or interact with content, contact support, use safety tools, or visit this Legal Center. It does not govern an independent service that provides its own notice.

The beta is intended only for adults aged 18 or older. GlowFeed is not an electronic health-record service and should not be used to store diagnoses, treatment plans, medical records, or emergency information.

03

Personal data we process

  • Account and authentication: email address, account identifier, confirmation and recovery status, authentication events, and security metadata.
  • Profile and onboarding: username, display name, biography, profile image, declared age or age-gate result, training interests, unit preferences, privacy choices, reminder choices, and policy receipts.
  • Training activity: routines, exercises, sets, repetitions, load, duration, notes, history, and progress calculations you choose to record.
  • Content and media: captions, posts, photos, video, audio contained in a recording, thumbnails, upload metadata, content status, and technical media properties.
  • Social activity: follows, likes or respect actions, saves, comments, profile views or discovery queries where implemented, blocks, hides, and other interactions.
  • Safety and support: reports, report details, reported content, moderation decisions, appeals, account-deletion requests, support correspondence, and evidence needed to investigate an issue.
  • Device and service data: app version, operating system, coarse network information, IP address in infrastructure logs, request identifiers, timestamps, errors, rate-limit signals, and security events.

GlowFeed does not intentionally request continuous precise location, address-book access, payment-card data, or advertising identifiers in the current beta. Media and text you choose to publish may nevertheless reveal location, health, or other sensitive information. Review content before sharing it.

04

Where data comes from

Most data comes directly from you through account, onboarding, training, publishing, privacy, reporting, and support actions. We also generate service records when the app communicates with the backend. Other users may provide data about you when they interact with your content, follow you, mention you, or submit a report.

Camera, photo-library, microphone, and notification access is controlled by your device. GlowFeed requests a system permission only when a related feature needs it. Denying an optional permission should not authorize unrelated collection.

05

Purposes and lawful bases

PurposeTypical dataPrimary basis
Create, authenticate, and secure an accountEmail, identifiers, authentication and security eventsContract; legitimate interests in security and abuse prevention
Provide profiles, feed, social, training, media, and preference featuresProfile, workouts, content, interactions, settingsContract and actions you request
Publish content to the audience you selectPosts, media, profile identity, engagementContract and your deliberate publishing instruction
Keep the community safe and enforce rulesReports, content, accounts, technical and case recordsLegitimate interests; legal obligations where applicable
Send confirmation, recovery, security, policy, and service messagesEmail, account state, delivery metadataContract; legal obligation; legitimate interests
Operate, debug, and protect the betaRequest, device, error, performance, and security dataLegitimate interests in reliability, fraud prevention, and network security
Comply with law and establish or defend claimsRelevant account, transaction, safety, and correspondence recordsLegal obligation; legitimate interests

Where we rely on legitimate interests, we consider the necessity of the processing and its impact on users. You may object as described below. Marketing messages, if introduced, will use consent or another basis permitted by law and will include an opt-out.

06

Fitness and potentially sensitive data

Workout records are provided by you to use a fitness logging service. Depending on context and detail, fitness content can reveal information about health and may qualify as special-category personal data under European law. GlowFeed does not ask you to upload clinical records or use fitness entries for diagnosis.

If a feature requires processing that legally needs explicit consent, GlowFeed must request that consent clearly and separately where required. You may decline or withdraw consent without changing the lawfulness of earlier processing. Withdrawal can limit or disable the affected feature. Until such a feature presents an appropriate consent control, do not enter medical diagnoses, treatment details, disability records, genetic data, or other clinical information.

GlowFeed does not use facial recognition, biometric identification, or automated health diagnosis in the current beta.

07

Recipients and service providers

We disclose personal data only as needed for the purposes above:

  • Other GlowFeed users: profile and content made visible under your selected audience and privacy settings.
  • Supabase: database, authentication, storage, server functions, and associated infrastructure for the app.
  • Resend: delivery and related metadata for transactional account, security, and service email.
  • Cloudflare: DNS, delivery, and network security for GlowFeed web properties, including this Legal Center.
  • Apple and device-platform services: app distribution, operating-system permissions, and platform functions you choose to use under their own terms.
  • Professional advisers and authorities: only where reasonably necessary to obtain advice, protect rights or safety, respond to lawful process, or comply with law.

Processors are permitted to use data only to provide contracted services and must protect it appropriately. GlowFeed does not sell personal data, share it for cross-context behavioral advertising, or run third-party advertising in the current beta.

08

Visibility and your choices

Your settings and publishing choices determine who can see supported profile and post fields. Public or shared content can be viewed, captured, or reshared by recipients outside GlowFeed's control. Avoid publishing information you do not want the selected audience to retain.

You can manage supported privacy, block, hide, notification, and account controls in the app. Device permissions can be changed in operating-system settings. Withdrawing a permission does not delete information already uploaded; delete the content or account, or contact us, if deletion is required.

09

International data transfers

Some providers or support operations may process data outside Sweden or the European Economic Area. Where European transfer restrictions apply, GlowFeed uses a lawful mechanism appropriate to the recipient and transfer, such as an adequacy decision, the European Commission's Standard Contractual Clauses, and supplementary technical or organizational safeguards.

You may ask for information about the applicable safeguard by emailing support@glowfeed.app. Commercially sensitive or security information may be summarized rather than disclosed in full.

10

Retention and deletion

GlowFeed keeps personal data only while it is needed for the purpose collected, the account remains active, or a justified legal, safety, fraud-prevention, dispute, or backup requirement applies. Retention is determined by data type, user choice, account state, sensitivity, operational need, limitation periods, and legal obligations.

  • Profile, training, social, preference, and published-content records normally remain while the account or relevant content is active.
  • Unfinished uploads and operational artifacts are removed or expire when no longer needed for completion, recovery, or abuse prevention.
  • Authentication, security, and infrastructure logs are retained for bounded periods needed to protect and troubleshoot the Service.
  • Moderation and appeal records may be retained after content removal where necessary for safety, repeat-abuse prevention, legal claims, or legal obligations.
  • After deletion from active systems, residual encrypted backup copies expire through provider backup cycles and are not restored for ordinary product use.

The Account Deletion Guide explains how to initiate full account deletion. We will provide more specific retention information for a particular request where required and available.

11

Your privacy rights

Depending on applicable law, you may have the right to access personal data, correct inaccurate data, request deletion, restrict processing, object to processing based on legitimate interests, receive certain data in a portable format, and withdraw consent. You also have the right not to be subject to a solely automated decision that produces legal or similarly significant effects where the legal conditions apply.

Send a request from the email linked to your account to support@glowfeed.app. We may verify identity and clarify scope. We respond without undue delay and within the period required by applicable law. Exercising a right is normally free, although manifestly unfounded or excessive requests may be handled as the law allows.

You may complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or to another competent supervisory authority. Please contact us first if you would like us to investigate directly.

12

Security

GlowFeed uses access controls, authenticated requests, row-level authorization, encrypted HTTPS transport, private media access patterns, rate limits, account isolation, and service-provider safeguards designed to protect personal data. Access is limited according to role and operational need.

No online service can guarantee absolute security. Use a unique password, protect your email and device, keep the app current, and report suspected compromise promptly. We will assess and notify affected people and authorities of a personal-data breach where required.

13

Analytics, cookies, and automated decisions

The current owner beta does not enable third-party advertising analytics, cross-app tracking, targeted advertising, or a third-party crash-reporting provider. Operational backend logs and bounded diagnostic events may still be processed for reliability and security.

This Legal Center does not set optional cookies, use local storage, load third-party fonts, or run client-side analytics. Cloudflare may process ordinary request and security logs to deliver and protect the site.

Automated validation, ranking, rate-limit, and safety signals may assist service operation. GlowFeed does not currently make solely automated decisions that produce legal or similarly significant effects. A human review path is available for eligible moderation appeals.

14

Age limits

The beta is not directed to people under 18. If we learn that an ineligible minor created a beta account, we may restrict the account and delete data after taking reasonable steps to verify the situation and preserve any record legally required for safety.

15

Changes and questions

Material changes receive a new version and effective date. Where required, GlowFeed will provide notice and request renewed acceptance or consent before the changed processing begins.

Questions, concerns, and privacy requests can be sent to support@glowfeed.app.

End of documentAsk a question