Glowva
← Back to Glowva

Privacy Policy

Last updated: 2 October 2026

Glowva Ltd ("we", "us", "our") values your privacy and is committed to protecting your personal information. This policy explains what data we collect, why we collect it, and how we keep it safe.

For the purposes of UK GDPR and the EU GDPR, the data controller is Glowva Ltd, a company registered in England and Wales (company number 17114339), with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. You can reach our privacy team at [email protected].

1. Information We Collect

We collect only what's necessary to provide and improve our service:

  • Account information (username, email address, and a securely hashed password — we never store your password in plain text)
  • Date of birth (to confirm you are 16 or over; stored encrypted)
  • If you sign in with Apple or Google: the name and email address they share with us
  • Phone number (only if you choose to add one to your account; stored encrypted and never used for advertising)
  • Profile information (display name, bio, profile picture)
  • Content you create (drops, letters, messages, campfire contributions, and any media you upload)
  • Usage and device information (to keep the app working, secure, and improving, to deliver push notifications, and to recognise your devices so we can tell you about a sign-in from a new one)
  • Your phone's timezone (so the notification that your daily drop has arrived reaches you in your own morning, not in the middle of the night)
  • Location data (only if you choose to share it — used for location-based discovery features)

Your messages and posts belong to you and are never shared or sold.

2. How We Use Your Information

We use your data to help you connect with others, improve the app experience, and keep our community safe from misuse or spam.

If you use Glowva on the web and do not have the app's notifications, we email your verified address when someone is waiting for you — a message, a letter, a reply. These emails never include what anyone wrote, are limited to a few a day, and every one has a link to stop them.

3. Legal Basis for Processing (Where UK/EU GDPR Applies)

Where data protection law requires a lawful basis to process your personal data, we rely on the following:

  • Performance of a contract — to create your account and provide the features you ask for.
  • Legitimate interests — to keep Glowva safe, secure, and working well (including moderation, abuse prevention, and aggregate analytics), balanced against your rights and freedoms.
  • Consent — for optional features you choose to switch on, such as sharing your location or adding a phone number. You can withdraw consent at any time.
  • Legal obligation — where we must process or retain data to comply with the law, including child-safety reporting obligations.

4. Data Security

We encrypt sensitive data at rest using AES-256-GCM — including particularly sensitive fields such as phone numbers — and protect data in transit with TLS. Glowva is not end-to-end encrypted — our automated moderation systems (see Section 5) need to read message content to keep the community safe. You can delete your account anytime, and your personal data will be permanently removed. Messages you have already sent to other people stay in their conversation with your name removed — see Section 9.

5. Content Moderation

To keep Glowva safe, content you post (including drops, letters, messages, and uploaded media) is reviewed by automated systems before or shortly after it appears:

  • Anthropic (text and prompt analysis)
  • Sightengine (image and video moderation)
  • Groq (transcribing voice messages so they can be checked the same way as text; the transcript is not stored)

Anthropic and Sightengine process your content under strict data-handling agreements and do not use it to train their general-purpose models. A small amount of content may also be reviewed by our human moderation team if it is reported, escalated, or flagged for appeal.

6. Data Sharing

We do not and will not sell your personal information. We only share data with:

  • Service providers who help us operate Glowva: Railway (database and server hosting), Cloudflare (file storage and content delivery), Anthropic, Sightengine and Groq (automated moderation), Google Safe Browsing (checking links people post against known malware and phishing sites), Amazon Web Services (email delivery), Zoho (our email inboxes, for messages you send us), Sentry (error reporting from the app and our servers), Expo, Apple and Google (push notifications), and Vercel (website hosting and privacy-friendly, cookieless website analytics)
  • When required by law or legal process
  • With your explicit consent

7. International Data Transfers

Some of our service providers are based outside the UK and the European Economic Area (for example, in the United States). Where we transfer your personal data internationally, we rely on appropriate safeguards — such as the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or an adequacy decision — so that your data remains protected to an equivalent standard.

8. Wellbeing Notice

Glowva is a space for connection and self-expression. It is not a mental health service and is not a substitute for professional support. If you are in crisis or struggling, please reach out to a qualified service in your area (for example, Samaritans in the UK on 116 123, or the 988 Suicide & Crisis Lifeline in the US).

9. Data Retention

We retain your data as follows:

  • Active accounts: data retained while your account is active
  • Deleted accounts: your profile, your posts, your Glow Drops, the letters you wrote and your account details are permanently removed within 30 days. A small number of things outlive that, and every one of them is listed below. We would rather set them out than tell you “everything” and be wrong.
  • Messages you sent to others: kept in the recipient’s conversation after you close your account, with your name and profile removed so they are no longer attributed to you. A conversation is a shared record, and deleting your account should not erase someone else’s copy of what was said to them — particularly where they may need it to report or prove harassment. Once nobody is left in a conversation, it is deleted in full.
  • Letters you received: a letter belongs to the person who wrote it as much as to the person who read it, so it stays in their record of what they sent, with your name and profile removed. Letters you wrote yourself are deleted with your account.
  • Moderation records: where something you wrote or uploaded was blocked, we keep the decision and a short extract of the content for up to 12 months, so that the decision can be explained, reviewed and appealed. Anything attached to an appeal is kept for as long as that appeal exists.
  • Reports: a report someone makes about content stays in the moderation queue even if the person who made it later closes their account — otherwise closing an account would erase complaints about other people. The report no longer says who made it. So that a moderator can see what was actually reported, we save a copy of the reported text with the report — including private messages and letters, which we can otherwise not show them. That copy is cleared once the report is closed and up to 180 days old; the report itself stays. Anything attached to an appeal is kept for as long as that appeal exists.
  • Child sexual abuse material: where our systems match content against known illegal material, the record and the file are kept indefinitely. We are required by law to preserve and report these, and that obligation does not end when an account is closed.
  • Permanently banned accounts: if an account is permanently banned and then deleted, we keep a one-way scrambled version of the email address. It is enough to stop the ban being undone by signing up again, and not enough to identify anyone or to recover the address from it.
  • Download records: which files you opened and when, kept for up to 90 days and deleted with your account. We do not record IP addresses or device details against them.
  • Glow Drops: expire and are deleted automatically, within 24 hours at most
  • Kindness messages: fade and are deleted automatically after 7 days — unless the person who received it chooses to keep it, in which case it stays until they let it go
  • Campfire Rooms: close 24–48 hours after they open. The room and everything written in it are deleted 7 days after it closes — the week is only there so that anything reported can still be reviewed. We keep a count of how many campfires you joined, for your yearly review, and nothing else
  • Verification tokens (for example, email confirmation links): expire automatically shortly after they are issued

10. Your Rights

You can access, update, or delete your data whenever you wish. You also have the right to:

  • Access your personal data
  • Request data portability
  • Request data deletion
  • Restrict data processing
  • Object to processing based on legitimate interests
  • Withdraw consent for optional features at any time

Contact us if you need help exercising these rights. You also have the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office).

11. Children's Privacy

Glowva is intended for people aged 16 and over. We do not knowingly collect personal information from anyone under 16. If we learn that we have collected data from someone under 16, we will delete it promptly. If you believe a child under 16 has provided us with personal data, please contact [email protected].

12. Cookies & Analytics

We use essential cookies for:

  • Authentication (session cookies)

We do not use advertising or cross-site tracking cookies. We use a privacy-friendly, cookieless analytics service (Vercel Analytics) that measures aggregate page traffic without setting cookies or identifying you individually. The essential cookies above are required for the app to function and do not require consent. For the same essential purposes, the website also keeps a few items in your browser's local storage: your signed-in profile (never your password or sign-in token), a random device identifier used only for new-device sign-in alerts, and preferences such as your theme and which chats you have hidden.

13. Exercising Your Privacy Rights

To exercise your privacy rights:

  • Access and update your data: Go to Settings → Account & Profile
  • Export your data: Go to Settings → Account & Profile, then download your data
  • Delete your account: Go to Settings → Account & Profile, then delete your account

All privacy rights can be exercised directly through the app, or by contacting us.

14. California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information we collect, use, and share
  • Right to delete your personal information
  • Right to opt-out of sale (we do not sell your data)
  • Right to non-discrimination for exercising your privacy rights

You can exercise these rights using the methods described in Section 13 above.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app or by email. Continued use of Glowva after an update means you accept the revised policy.

16. Contact Us

For privacy questions or data requests, contact us: