GLOWMAIT
AboutGlowmaitsJoin the waitlist

YOUR DATA

Privacy Policy

Last updated: August 28, 2026

This Policy explains what Glowmait processes when you visit the website, create a Beauty Profile, use cosmetic research features, join the waitlist or send feedback.

ON THIS PAGE

ControllerAI researchWaitlistProvidersRetentionYour rights
01

Controller

The controller responsible for processing personal data on this website is Michelle Kossenko, trading as AICADEMIC, Pfortenstraße 11, 65604 Elz, Germany. Email: info@aicademic.de.

02

Website delivery and security

When you open Glowmait, our hosting provider may process your IP address, request time, requested page, browser and device information, referrer and technical log data. This is required to deliver and secure the website, diagnose errors and prevent abuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and efficient operation of the service.

03

AI-assisted Beauty Profile and cosmetic research

When you build a Beauty Profile or use another cosmetic research feature, we process the cosmetic category, characteristics, preferences and lifestyle choices you select, plus any optional cosmetic detail you enter. This information is sent to the OpenAI API to generate the requested AI-assisted analysis and perform current web research. The legal basis is Article 6(1)(b) GDPR because the processing is necessary to provide the feature you requested.

Cosmetic and anonymous information only. Do not enter names, addresses, contact details, diagnoses, symptoms, medications, pregnancy information, health records, allergies or other sensitive personal data. Glowmait is designed for cosmetic appearance, feel, routine and product-performance questions only. Obvious health-related information, direct identifiers, links, social handles and instruction-injection attempts are rejected before research where our filters detect them.

Glowmait does not use Beauty Profile or cosmetic research inputs to create advertising profiles and does not intentionally save the complete research input or generated result in its own database. API requests are sent with response storage disabled. OpenAI states that API data is not used to train its models by default. Depending on the applicable API data controls, OpenAI may retain customer content in abuse-monitoring logs for a limited period, generally up to 30 days, unless stronger controls such as Zero Data Retention apply.

Generated results may be incomplete, outdated or inaccurate. The interface identifies the research as AI-assisted and provides source links so important product information can be checked against the underlying public sources.

04

Free-profile limit and abuse prevention

During the current free preview, we use pseudonymous technical records to enforce the Beauty Profile limit and reduce automated abuse. The server creates one-way HMAC identifiers from technical request information such as the requesting IP address and browser user-agent. The original IP address is not stored in the Glowmait database for this quota purpose.

The current Beauty Profile allowance is evaluated against successful Beauty Profile builds from the preceding 24 hours. Separate short-window rate-limit markers are used to restrict repeated or parallel research requests and protect the service from automated misuse. Legacy research tools may use separate quota namespaces. These technical records are not used for advertising or cross-site tracking and are subject to rolling cleanup; quota and abuse-prevention records are currently removed when older than 365 days. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are fair access, cost control and protection against misuse.

05

Waitlist and product updates

If you voluntarily join the waitlist, we process your email address, optional first name, source, consent version and consent time to manage the waitlist and send the early-access, launch and feature emails described next to the form. The legal basis is your consent under Article 6(1)(a) GDPR. You can withdraw consent at any time with effect for the future by emailing info@aicademic.de or by using the unsubscribe option included in future marketing emails. Withdrawal does not affect processing carried out before withdrawal.

Waitlist registration is voluntary and is not required to create a free Beauty Profile.

06

Result feedback and contact

If a result-feedback feature is offered, we may record a coarse helpful/not-helpful rating and a predefined reason. Structured analytics events do not include your Beauty Profile selections, optional cosmetic detail, generated result or email address.

If an optional free-text feedback field is offered, please do not include names, contact details, health information or other sensitive personal information. Client-side checks may provide immediate feedback and the server validates submitted free text again before storage.

The legal basis for result feedback is Article 6(1)(f) GDPR. Our legitimate interest is improving the usefulness, reliability and clarity of Glowmait. If you contact us by email, we process your contact details and message to answer your request.

07

Privacy-friendly validation analytics

We use Vercel Web Analytics and a limited first-party validation funnel to understand aggregated page usage and whether the free preview is useful. The custom funnel stores only allowlisted event names, the page path and a small set of non-content properties such as the selected Beauty Profile category, step number, number of selected options, technical error category and campaign UTM parameters that are present in the page URL. We do not send Beauty Profile free text, complete selections, email addresses, generated results or complete research inputs to analytics.

Our custom validation tracking does not write analytics identifiers or campaign attribution into localStorage, sessionStorage or advertising cookies. Campaign parameters are carried in the URL between relevant Glowmait pages when present. Vercel states that Web Analytics is designed without third-party tracking cookies and provides aggregated, privacy-oriented analytics. The legal basis for our limited validation analytics is Article 6(1)(f) GDPR. Our legitimate interests are measuring feature reliability, validating demand and improving usability. If we introduce analytics or marketing technology that requires consent to device storage or access, it will remain disabled until any legally required consent has been obtained.

08

Service providers and international transfers

We currently use the following providers:

  • Vercel Inc., hosting, delivery, security and website analytics.
  • Supabase Inc., database infrastructure for waitlist entries, optional feedback, validation funnel events and pseudonymous quota and abuse-prevention records.
  • OpenAI and applicable affiliates, AI-assisted Beauty Profile and cosmetic research through the OpenAI API.

Providers may act as processors or other recipients depending on the service and configuration. Where GDPR Chapter V applies to a transfer outside the EEA, we rely on an applicable lawful transfer mechanism, such as an adequacy decision or Standard Contractual Clauses, as appropriate to the provider and configuration. Provider region, contractual terms and transfer settings are operational compliance items that we review as the service develops.

09

Retention

  • Beauty Profile quota records: counted only within the rolling 24-hour free-profile window and currently subject to rolling deletion when older than 365 days.
  • Short-window abuse-prevention markers: used only for technical rate limiting and currently subject to the same rolling technical cleanup.
  • Custom funnel events: automatically subject to a 90-day rolling retention period.
  • Optional free-text result feedback: automatically subject to a 90-day rolling retention period where that feature is used.
  • Waitlist data: until consent is withdrawn, the waitlist purpose ends or the data is no longer required, subject to limited evidence and statutory retention requirements.
  • Contact messages: until the request is resolved, plus any period required for legal claims or statutory obligations.
  • Provider logs: according to the provider configuration and applicable security and abuse-prevention retention periods.
10

Cookies and device storage

Glowmait currently does not use advertising cookies and our custom validation analytics does not store analytics identifiers in your browser. A temporary session-storage value may be used only for an explicit owner testing session when an authorised test token is supplied. If non-essential cookies, pixels, browser storage or comparable tracking technologies are introduced, they will remain disabled until any legally required consent has been given.

11

Security and data minimisation

Glowmait applies technical and organisational measures designed to reduce the amount of personal data processed and protect it against misuse and unauthorised access. Connections use HTTPS, service credentials remain server-side, request sizes are limited, same-origin checks are applied to write endpoints, expensive research endpoints are rate-limited, research and feedback free text is validated on the server for direct identifiers, obvious health-related content and instruction-injection attempts, and public analytics events do not contain research input, profile free text or email addresses.

12

Your rights

Subject to the legal requirements, you may request access, correction, deletion, restriction of processing and data portability. You may object to processing based on legitimate interests and withdraw consent at any time with effect for the future.

You may lodge a complaint with a data protection supervisory authority. For a controller based in Elz, the competent authority is generally the Hessian Commissioner for Data Protection and Freedom of Information, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany, datenschutz.hessen.de.

13

Children

Glowmait is not directed to people under 18 and we do not knowingly collect their personal data.

14

AI transparency and automated decisions

Beauty Profile and cosmetic research results are identified as AI-assisted. Their results are generated with AI from the information you provide and public research sources. Glowmait provides cosmetic recommendations but does not make decisions that produce legal or similarly significant effects about you within the meaning of Article 22 GDPR.

Generated result containers may also carry machine-readable HTML metadata identifying them as AI-generated text. This is a supplementary transparency measure and does not replace any further technical marking measures that may be required under applicable AI law or standards.

15

Changes and contact

We update this Policy when providers, features or legal requirements change. To exercise your rights or ask a privacy question, email info@aicademic.de.

GLOWMAIT

Intelligent tools for your most beautiful life.

Explore

About usGlowmaitsWaitlist

Legal

Terms of ServicePrivacy PolicyLegal Notice
© 2026 AICADEMIC. All rights reserved.Made for your glow.