Glim Privacy Policy

Last updated: July 20, 2026

PLEASE READ THIS PRIVACY POLICY CAREFULLY BEFORE USING GLIM.

Glim (“Glim,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, share, store, and retain your personal information when you use our mobile application, website, APIs, and related services collectively, the “Platform”. By accessing or using the Platform, you consent to the practices described in this policy. You must be at least 13 years old to use Glim. If you do not agree, please discontinue use.

1. Definitions

  • “User” means any person who accesses or uses the Platform, including anonymous users who have not created an account.
  • “Simulation” means a photo uploaded or captured by a User to generate an AI try-on preview, such as a hairstyle, hair color, skin, beard, makeup, eyebrow, teeth, lash, lip, or facial structure look.
  • “Generated Look” means the AI-generated try-on image produced from a Simulation, including full “Potential” glow-up previews.
  • “Commitment Plan” means the day-by-day plan a User can start to work toward a Generated Look in real life, including daily tasks, streaks, and before/goal/after photos.
  • “Plan Photos” means the before photo, goal reference photo, and after “reveal” photo a User submits as part of a Commitment Plan.
  • “Device Identifier” means a random identifier generated on your device and stored in your device’s secure hardware-backed storage (iOS Keychain / Android Keystore), used to limit each device to one free AI generation.
  • “Content” means photos, images, text, feedback, screenshots, support messages, or other materials submitted by Users.
  • “Personal Data” means information that identifies or can reasonably identify you.

2. Information We Collect

We collect information in connection with your use of Glim, including:

  • Account Information: An anonymous account identifier created automatically when you first open Glim, and, if you choose to register, your name, email address, username, login method, and account settings.
  • Device Identifier: A random identifier generated on your device and stored in secure hardware-backed storage, sent to our backend with each AI-generation request. Used solely to prevent the same device from repeatedly claiming a free AI-generated look by deleting and reinstalling the app. See “Device Identifiers & Fraud Prevention” below.
  • Simulation Photos: Photos you upload or capture to generate a Generated Look.
  • Generated Looks: The AI-generated try-on images produced from your Simulation photos, along with metadata such as category, selected option, and timestamp.
  • Plan Photos and Progress: Before, goal, and after photos you submit for a Commitment Plan, plus daily task completions, streaks, and plan status.
  • Usage Data: IP address, device type, operating system, app version, session logs, pages viewed, features used, actions taken, crash logs, and performance data.
  • Payment and Subscription Information: Purchase history, subscription status, entitlement status, product ID, renewal status, expiration date, and transaction identifiers processed through app stores and RevenueCat.
  • Support Data: Messages, screenshots, attachments, or details you provide when contacting support.

3. How We Collect Information

We collect information in the following ways:

  • Directly from you: When you open the app, upload or capture a photo for a Simulation or Commitment Plan, register an account, submit support requests, or use app features.
  • Automatically: When you use the Platform, we may collect device, usage, performance, and security information, including your Device Identifier.
  • From service providers: We may receive subscription status, payment entitlement information, authentication information, processing results, or technical logs from providers that help operate Glim.

4. How We Use Your Information

We use your information for purposes including:

PurposeLegal Basis
To generate AI try-on Generated Looks from your Simulation photosConsent / Contractual Necessity
To create, track, and support your Commitment Plans, including daily tasks, streaks, and reveal photosConsent / Contractual Necessity
To save your Generated Looks and plan history in your accountContractual Necessity
To manage your account, login, profile, and app accessContractual Necessity
To process purchases, subscriptions, entitlement status, and generation limitsContractual Necessity
To limit free AI generations to one per device using your Device IdentifierLegitimate Interests / Fraud Prevention
To provide customer support and respond to user requestsContractual Necessity
To improve app performance, reliability, safety, and user experienceLegitimate Interests
To prevent misuse, fraud, abuse, unauthorized access, or security issuesLegitimate Interests / Legal Obligation
To comply with legal obligations, enforce our Terms, and protect our rightsLegal Obligation

5. Photos, Simulations, and Commitment Plans

Glim allows users to upload or capture a photo so the app can generate AI try-on previews of hairstyles, hair color, skin, beard, makeup, eyebrows, teeth, lashes, lips, facial structure, and full “Potential” glow-up previews, and to start a Commitment Plan toward a look they like.

What we collect: For Simulations, we collect the photo you submit and generate a Generated Look from it, along with metadata such as category, selected option, and timestamp. For Commitment Plans, we collect the before photo, goal reference photo, and after reveal photo you submit, along with your daily task completions and streak history.

How we use this data: We use submitted photos and related outputs only to provide Glim’s core app functionality, including generating try-on previews, running your Commitment Plans, and saving your Generated Looks and plan history in your account.

What is sent for AI processing: When you submit a photo for a Simulation, Glim sends the photo and related selections (such as the category or look you chose) to our AI processing provider so it can generate your Generated Look. Original Simulation photos are sent for processing but are not separately retained by Glim after your Generated Look is produced. Plan Photos you submit for a Commitment Plan are stored by Glim as described in “Storage” below.

Who receives Simulation photos: Glim uses Google’s Gemini API to process submitted photos and generate AI try-on Generated Looks.

User permission before third-party AI processing: Glim asks for your permission before sending your photo to third-party AI providers. If you do not consent, you should not submit a photo for a Simulation or Commitment Plan.

Glim does not use your photos to identify you, authenticate you, verify your identity, track you across apps or websites, build advertising profiles, or sell your data. Glim is not a face recognition or biometric identification service.

Storage: Generated Looks and Plan Photos are stored using our cloud storage and database provider (Supabase) so you can access your generation history and Commitment Plans. Access is restricted to your account and authorized service operations required to provide the app.

Retention: Generated Looks, Plan Photos, and related plan data are retained while your account is active or while needed to provide your generation history and Commitment Plans, unless you delete your account or request deletion earlier. When a deletion request is processed, associated Generated Looks and Plan Photos are deleted from active storage, including the underlying image files, unless limited retention is required for legal, security, fraud prevention, or operational reasons. See “Account and Data Deletion” below for the specific data categories deleted and one narrow exception involving Device Identifiers.

6. Third-Party AI Services

Glim uses a third-party AI service provider to generate try-on Generated Looks from your submitted photos.

Google (Gemini API): Glim sends submitted Simulation photos and related selections to Google’s Gemini API to generate your AI try-on Generated Look. Google’s handling of this data is also subject to Google’s own terms and privacy practices.

Glim requires user permission before sending photos to third-party AI providers for processing. This Privacy Policy is not the only notice provided; Glim also provides an in-app disclosure before AI processing begins.

7. Device Identifiers & Fraud Prevention

Glim generates a random Device Identifier on your device the first time you use the app and stores it in your device’s secure hardware-backed storage (iOS Keychain / Android Keystore), rather than in regular app storage, so it survives an app delete and reinstall. This identifier is sent to our backend with each AI-generation request.

Why we collect it: Glim offers one free AI-generated look before a subscription is required. The Device Identifier lets us recognize that a device has already claimed its free generation, even if the app is deleted, reinstalled, or used with a new anonymous account, so that the free-generation limit cannot be repeatedly reset.

How it is stored: Your Device Identifier, together with a record of which account used it and when, is stored in a dedicated table in our database. It is linked to your account while your account exists.

What we don’t do with it: Your Device Identifier is never shared with third parties, including RevenueCat, Google, or Apple — it exists only in Glim’s own backend. It is not used for cross-app or cross-website tracking, advertising, or any purpose other than free-generation fraud prevention, and it is never combined with data from other apps or websites.

Retention after account deletion: Unlike most of your data, your Device Identifier record is retained after you delete your account, but the link to your (former) account is removed at that time. We retain it in this unlinked form only to prevent that same device from claiming another free generation under a new account. See “Account and Data Deletion” below for full details.

8. Cookies & Tracking Technologies

We and our service providers may use cookies, analytics identifiers, device identifiers, and similar technologies to support app functionality, measure performance, prevent fraud, maintain security, and improve the Platform. This is separate from the dedicated Device Identifier described above, which is used only for free-generation fraud prevention.

  • Essential Technologies: Required for login, account management, security, subscriptions, and core features.
  • Analytics Technologies: Help us understand app usage, reliability, crashes, and performance.
  • Preference Technologies: Remember settings, account state, and app preferences.

9. Sharing of Information

We may share information in the following circumstances:

  • Service Providers: Providers that support hosting, authentication, storage, database operations, analytics, crash reporting, payments, subscriptions, customer support, and AI image generation.
  • Third-Party AI Providers: Google’s Gemini API processes submitted Simulation photos as needed to generate Generated Looks.
  • Payment Providers: App stores and RevenueCat, used to process purchases, manage subscriptions, and confirm entitlement status.
  • Legal Requirements: Where necessary to comply with laws, court orders, government requests, legal process, or to enforce our Terms.
  • Safety and Security: Where necessary to detect, prevent, or respond to fraud, abuse, security incidents, unauthorized access, or technical issues.
  • Business Transfers: In connection with a merger, acquisition, financing, restructuring, bankruptcy, or sale of assets.

We do not sell your photos, Generated Looks, Plan Photos, Device Identifier, or other Personal Data to advertisers. Your Device Identifier is never shared with any third party, including our AI, payment, or platform providers.

10. Third-Party Services & SDKs

Glim uses third-party service providers to operate the Platform, including providers for authentication, cloud database, storage, payments, subscription management, analytics, crash reporting, and AI image generation.

These providers may process Personal Data, photos, Generated Looks, Plan Photos, device data, usage data, or payment-related data only as needed to provide their services to Glim and support the app’s functionality.

  • Supabase: Used for authentication (including anonymous accounts), database, cloud storage, signed URLs, and storing account-related app data, Generated Looks, Plan Photos, and Device Identifier records.
  • RevenueCat: Used to manage subscriptions, purchases, products, entitlement status, renewal status, and generation usage limits. RevenueCat does not receive your Device Identifier.
  • Google (Gemini API): Used to process submitted Simulation photos and generate AI try-on Generated Looks. Google does not receive your Device Identifier.
  • Apple: Used for app distribution, in-app purchases, sign-in, device services, and platform functionality where applicable. Apple does not receive your Device Identifier.
  • Google: Used for sign-in, platform services, app distribution, or related functionality where applicable.

We require our service providers to process information only as needed to provide services to Glim and to apply appropriate privacy, security, and confidentiality protections.

11. Data Security

We use administrative, technical, and organizational safeguards to protect your information, including access controls, authenticated account access, secure service providers, and cloud storage protections. However, no system is completely secure, and you use the Platform at your own risk.

12. Data Retention

We retain your information only as long as necessary to provide the Platform, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud, maintain security, and improve our services.

  • Account data: Retained until account deletion plus a reasonable processing period, unless longer retention is required for legal, security, fraud prevention, or operational reasons. If you use Glim without registering an account, your anonymous account data is retained on the same basis until you request deletion.
  • Generated Looks and Plan Photos: Retained while your account is active or while needed to provide your generation history and Commitment Plans, unless you delete your account or request deletion earlier.
  • Commitment Plan progress: Task completions, streaks, and plan status are retained while your account remains active unless you delete your account or request deletion.
  • Device Identifier: Retained indefinitely, including after your account is deleted, but unlinked from your account at that time. See “Account and Data Deletion” below.
  • Usage, analytics, and crash data: Retained as needed to improve reliability, maintain security, prevent abuse, and understand app performance. Some information may be retained in aggregated or anonymized form.
  • Payment and subscription records: Retained as required by app stores, RevenueCat, tax, accounting, fraud prevention, or legal obligations.
  • Support data: Retained as needed to respond to your request, keep support records, prevent abuse, and improve the service.

13. Children’s Privacy

Glim is not intended for individuals under 13 years of age, and we do not knowingly collect Personal Data from anyone under 13. If you believe we have collected data from someone under 13, please contact us and we will take appropriate steps to delete it.

14. International Data Transfers

Your information may be stored and processed in Australia, the United States, or other countries where Glim or our service providers operate. These countries may have data protection laws different from those in your country of residence. When we transfer information internationally, we rely on appropriate safeguards where required by applicable law.

15. Your Privacy Rights

Depending on your jurisdiction, you may have rights to:

  • Access, correct, update, or delete your Personal Data.
  • Request deletion of your photos, Generated Looks, Plan Photos, and Commitment Plan history.
  • Restrict or object to certain processing.
  • Withdraw consent where processing is based on consent.
  • Request a portable copy of your data.
  • Complain to a privacy regulator or data protection authority where applicable.

To exercise your rights, contact us at support@glimapp.com. We will respond within applicable legal timeframes.

16. Account and Data Deletion

You may request deletion of your account and associated data in-app (Settings → Delete My Data) or by contacting us. For step-by-step instructions, visit our Delete Account page.

When you request deletion, we permanently delete the following from our active systems, in this order: any legacy face-scan diagnostic, metric, or upgrade records; face scan records; your Commitment Plans (including plan tasks and task completions); your Simulator generation history; weekly and free-generation usage records; subscription records; notification preferences and push tokens; RevenueCat event history; your profile; and finally your account itself. This is a full deletion, not a deactivation — once complete, this data cannot be recovered.

One narrow exception: Your Device Identifier record is not deleted. Instead, the link between that record and your account is removed (the account reference is cleared), and the identifier itself is retained. We do this because the sole purpose of the Device Identifier is to prevent someone from deleting their account specifically to reset their free-generation eligibility and claim another free look on the same device. Deleting this record along with the rest of your account data would defeat that protection. Your internal anonymous-tracking record, by contrast, has no such exception and is deleted along with the rest of your account data.

After a deletion request is processed, we also delete associated Generated Looks and Plan Photos from active storage, including the underlying image files, unless limited retention is required for legal, security, fraud prevention, or operational reasons.

17. Your Choices and Consent

You can choose not to submit a photo. If you do not submit a photo or do not provide consent for third-party AI processing, Glim will not be able to generate AI try-on Generated Looks or run a Commitment Plan for that submission.

You may also delete your account, request deletion of your data, contact support, or stop using the Platform at any time.

18. Changes to This Policy

We may update this policy from time to time. We may notify you of material changes by email, in-app notice, or by updating the date at the top of this page. Continued use of Glim means you accept the revised policy.

19. Contact Us

For questions or concerns about this policy, contact us at support@glimapp.com.

Appendix A: Glossary

  • Simulation: A photo uploaded or captured to generate an AI try-on preview.
  • Generated Look: The AI-generated try-on image produced from a Simulation, including full “Potential” glow-up previews.
  • Commitment Plan: A day-by-day plan to work toward a Generated Look, including daily tasks, streaks, and a reveal photo.
  • Plan Photos: The before, goal, and after photos submitted as part of a Commitment Plan.
  • Device Identifier: A random identifier generated on your device and stored in secure hardware-backed storage, used to limit each device to one free AI generation.
  • Third-Party AI Providers: External AI service providers, including Google’s Gemini API, that process submitted photos as needed to provide Glim’s AI image generation features.

Appendix B: Changelog

April 26, 2026: Initial release of Glim Privacy Policy.

May 13, 2026: Added clearer information about Face Data and Photos, AI processing, third-party service providers, storage, sharing, retention, and deletion.

May 15, 2026: Added clearer disclosure of what Face Scan data is sent to third-party AI providers, identified OpenAI and fal.ai/FAL as AI processing providers, clarified user permission before third-party AI processing, and expanded the description of data collection, use, sharing, retention, and deletion.

July 13, 2026: Updated this policy to reflect Glim’s shift from photo scoring/analysis to an AI appearance simulator with Commitment Plans. Replaced Face Scan/Analysis Results terminology with Simulations, Generated Looks, and Plan Photos; replaced OpenAI and fal.ai/FAL with Google’s Gemini API as Glim’s AI processing provider; clarified that anonymous accounts are created automatically before registration; and clarified that deletion removes underlying image files from storage, not only database records.

July 20, 2026: Added disclosure of the Device Identifier collected to limit free AI generations to one per device, including a new “Device Identifiers & Fraud Prevention” section. Replaced the general description of account deletion with a complete, itemized list of what is deleted and disclosed the one exception where a Device Identifier record is retained in unlinked form after account deletion.