Privacy Policy

Last updated: 28 September 2026

This policy explains what happens to your information when you use the gloup iPhone app (“gloup”, “the app”) and the website gloupapp.com.

The short version

  • Filters, Adjust and Beautify run on your iPhone. Those photos aren’t uploaded.
  • Your gloup gallery is stored only on your phone.
  • When you use an AI look, the photo you choose is sent to our AI provider (OpenAI) to make the look. We don’t keep it after the result is delivered.
  • There’s no email or password. The app uses an anonymous ID to keep track of your plan.
  • Apple handles payments. We never see your card details.
  • We don’t sell your data and we don’t track you across other apps for advertising.

1. Who we are

The data controller is Fodina, MB, a Lithuanian small partnership (mažoji bendrija), company code 307677239, registered in Lithuania (“we”, “us”). You can reach us about privacy at info@gloupapp.com.

2. What we process and why

Editing: Filters, Adjust and Beautify

All editing happens on your device. To place Beautify tools correctly, the app finds face points (such as the outline of your eyes and lips) on your device. These face points are used only for the edit you’re making, aren’t uploaded, and aren’t used to identify you.

To find face points, the app uses a face-detection model from Google (MediaPipe), which may be downloaded from Google’s servers. That download doesn’t include your photo, but like any internet request it shares your IP address and basic device information with Google.

Your gloup gallery

Photos you edit and save in gloup are kept in the app’s private storage on your device. They aren’t uploaded to us, and they’re removed if you delete the app. When you choose Download or Share, the photo goes to the place you pick (for example your Photos library or another app), and that app’s own terms apply.

AI looks

When you apply an AI look, the photo you selected and the look you chose are sent over an encrypted connection to our AI provider, OpenAI. The provider processes the photo to create your result, and the result is returned to your device. We don’t keep your photo or the result on our servers after it has been delivered to you.

OpenAI processes the photo on our behalf, under its own data processing and retention terms. Under those terms at the time of writing, OpenAI doesn’t use data sent through its API to train its models and may keep it for a limited time (up to 30 days) to detect abuse before deleting it, unless the law requires longer. We don’t use your photos to identify you or to build a face template, and we don’t use them to train any AI.

Legal basis: performing our contract with you, because you asked for the look (GDPR Art. 6(1)(b)).

Anonymous app ID

gloup doesn’t ask for your name, email or a password. When you first open the app, we create a random anonymous ID using Firebase Anonymous Authentication (hosted in the EU). We use it to store your plan, how many glow-ups you’ve used today, and your credit balance.

Legal basis: performing our contract with you (Art. 6(1)(b)).

Purchases

Subscriptions and credit packs are sold and processed by Apple. Apple tells us what you bought and whether a subscription is active or has renewed, along with transaction identifiers. We never receive your card details, name or Apple ID email. Apple processes your payment as an independent controller under its own privacy policy.

Legal basis: performing our contract with you (Art. 6(1)(b)) and keeping accounting records we’re legally required to keep (Art. 6(1)(c)).

Analytics

With your permission, we use Google Analytics for Firebase to understand how the app is used, for example which screens are opened, when the upgrade screen is shown and when a purchase is made. These events are linked to a random app-instance ID, not to your name. In the EU and EEA we only collect analytics if you agree, and you can change your choice at any time in the app’s settings.

Legal basis: your consent (Art. 6(1)(a)).

Crash reports

If the app crashes, Firebase Crashlytics sends us a crash report: the device model, iOS version, app version, a technical description of the crash and a random installation ID. We use this only to find and fix bugs.

Legal basis: our legitimate interest in keeping the app working (Art. 6(1)(f)).

When you contact us

If you email us, we use your email address and what you send us to answer you.

Legal basis: our legitimate interest in answering your questions (Art. 6(1)(f)), or handling your rights request where that applies (Art. 6(1)(c)).

This website

gloupapp.com uses no cookies, analytics or trackers. Like any website, our hosting provider processes basic technical data (such as your IP address and browser type) to deliver pages and keep the site secure.

3. What we don’t do

  • We don’t sell or rent your personal data.
  • We don’t track you across other companies’ apps or websites for advertising, and we don’t use the iOS advertising identifier.
  • We don’t use facial recognition to identify you.
  • We don’t upload your gallery or the photos you edit for free.

4. Who we share data with

We only share data with service providers that help us run gloup:

ProviderWhat forRole
OpenAICreating AI looks from the photo you chooseProcessor
Google (Firebase)Anonymous ID and plan data (EU region), analytics with consent, crash reportsProcessor
Google (MediaPipe)Delivering the on-device face-detection modelService provider; no photos are shared
AppleApp Store, payments, subscriptions and refundsIndependent controller
Our website hostDelivering gloupapp.comProcessor

We may also disclose information if the law requires it, for example to a court or public authority.

5. Transfers outside the EU

Some of our providers, including OpenAI and Google, are based in the United States or may process data there. When data leaves the European Economic Area, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses or the EU–US Data Privacy Framework where the provider is certified. You can ask us for more information about these safeguards.

6. How long we keep data

DataHow long
Photos you edit and your galleryOn your device only, until you delete them or the app
Photos sent for AI looksNot kept by us after the result is delivered; OpenAI may keep them for a limited time under its own terms (see above)
Anonymous ID, plan, daily count and creditsWhile you use the app; deleted on request, or after 24 months without activity
Purchase recordsAs long as accounting law requires (generally up to 10 years in Lithuania)
Analytics eventsUp to 14 months
Crash reportsUp to 90 days
Support emailsUp to 24 months after the conversation ends

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and get a copy;
  • have it corrected if it’s wrong;
  • have it deleted;
  • restrict or object to how we use it;
  • receive it in a portable format;
  • withdraw your consent at any time (this doesn’t affect anything done before).

Deleting your data. Deleting the app removes your gallery and everything stored on your phone. To delete the records linked to your anonymous ID on our servers (plan, daily count and credits), email info@gloupapp.com. Because we don’t know who you are, please include your app ID, shown in the app’s settings, so we can find your records. Deleting these records doesn’t cancel an Apple subscription; cancel that in iPhone Settings.

We’ll answer within one month. You can also complain to the Lithuanian data protection authority, the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt), or to the authority in the EU country where you live.

8. Children

gloup isn’t directed at children under 13, and we don’t knowingly collect data from them. In Lithuania, users under 14 need a parent or guardian to agree to optional analytics on their behalf; other EU countries set their own ages. If you believe a child has given us personal data, contact us and we’ll delete it.

9. Security

We use encrypted connections (TLS) for everything the app sends, keep server data to the minimum we need, and limit who can access it. No system is perfectly secure, but we work to protect your data and will tell you and the authorities about a breach where the law requires.

10. Changes to this policy

If we change this policy, we’ll update the date at the top. If the change is significant, we’ll also let you know in the app.

11. Contact

Fodina, MB, company code 307677239, Lithuania. Email: info@gloupapp.com. See also our Terms of Use.