GLOUP/Legal documents

Privacy
notice

In force from 25 September 2026Version 5

This is a translation provided for convenience. The Italian version is the reference text.

In short

Your face photos, scores, the products on your shelf and your diary answers are processed and stored solely on your device: they are not sent to any server, are not accessible to the controller and are not used to train models. You are not asked to create an account, there is no advertising and no profiling of any kind takes place. The only information that leaves the device relates to managing your subscription and looking up a product by its barcode: this is described in Article 4.

1Data controller#

The data controller is GLOUP, which may be contacted at privacy@gloup.beauty. GLOUP is developed and operated by Riccardo Sasso, a natural person, who is the controller of the processing within the meaning of Article 4 GDPR.

No Data Protection Officer has been designated, since none of the conditions laid down in Article 37 of Regulation (EU) 2016/679 (“GDPR”) applies.

2Scope#

This notice is provided pursuant to Articles 13 and 14 GDPR and applies to anyone who uses the GLOUP application, wherever it is used. The controller applies the GDPR standard to all users; any rights conferred by other national legislation remain unaffected and are in addition to those listed here.

3Data processed on the device#

The data listed in the table below are generated and stored solely in the memory of the user’s device. The controller has no access to them and does not hold them in any form.

DataPurposeLocationRetention
Face photosCalculation of skin parameters by areaOn the device onlyUntil deleted by the user
Scores by areaShowing progress over timeOn the device onlyUntil deleted by the user
Products ownedBuilding the routine and flagging incompatibilitiesOn the device onlyUntil deleted by the user
Diary answersIdentifying weekly correlationsOn the device onlyUntil deleted by the user
Name and agePersonalisation and comparison by age groupOn the device onlyUntil deleted by the user

Photos are processed entirely on the device. The application does not perform facial recognition and does not generate biometric templates capable of uniquely identifying a natural person: images are used solely to measure optical parameters of the skin surface. Those parameters describe the appearance of a surface, not the user’s state of health: they are not used to detect or monitor any medical condition and do not constitute data concerning health within the meaning of Article 4(15) GDPR. The controller nevertheless handles them with the care owed to sensitive data: every scan is initiated by the user after authorising access to the camera, and consent may be withdrawn at any time by ceasing to carry out scans and deleting photos and scores from the Profile section of the application, or by revoking camera access in the system settings. No data capable of revealing a person’s state of health is disclosed to third parties.

The application does not process email addresses, telephone numbers, contacts, geolocation data, the device’s advertising identifier or browsing history. No third-party analytics, crash-reporting or advertising measurement tools are integrated into the application.

Face data

This section gives a complete description of the face-related data processed by the application.

Face data (English)

This section fully describes the face-related data the app processes.

  • Face photo. When the user starts a scan, the app takes one photo with the front camera. The photo is saved in the app's private storage on the device, so the user can compare their own photos over time.
  • Framing frames. While the user frames their face, the app reads low-resolution frames about every 0.7 seconds, only to find the position and size of the face and guide the framing. Each frame is deleted right after it is read and is never kept.
  • Face landmarks. To locate the areas to observe (forehead, cheeks, nose, chin, under-eye), Apple's Vision framework computes on the device the face rectangle and two-dimensional landmark points (eyes, eyebrows, nose, mouth, face contour). These points are used only during the analysis and are not stored.
  • Data stored with each scan. Optical measurements per area (colour, lightness, shine, texture, pores and spots per unit of area), photo quality, the share of the photo taken up by the face, the distance in pixels between the eyes and the head tilt angles. The latter are used only to make measurements taken at different distances and angles comparable. None of this data can identify a person.
  • What the app does not do. It does not use the TrueDepth camera, ARKit or depth data. It performs no face recognition or face authentication and creates no faceprints or biometric templates. It does not send face data to any server, to the developer or to any third party (including Apple and RevenueCat), and does not use it for advertising, marketing, profiling, sale or model training.
  • Retention and deletion. Face data stays on the device until the user deletes it. "Cancella tutti i miei dati" (Delete all my data) in the Profile section deletes the saved photos and measurements immediately; temporary copies created by the camera while shooting remain in the app's cache, which the system clears automatically. Uninstalling the app deletes everything. Face photos are excluded from device backups (iCloud or computer). Like all app data, the measurements may be included in a backup the user has turned on, which Apple manages under the user's control; the developer has no access to it. The file the user can export with "Scarica i miei dati" (Download my data) contains the measurements but not the photos, and is shared only where the user chooses.

Deletion

The user may delete the data from the Profile section of the application or by uninstalling the application: in either case the data are removed from the device and no copy remains with the controller, which has never had them at its disposal.

4Data disclosed to third parties#

The only disclosures of data to third parties are those set out below, which are strictly necessary for the operation of the respective features.

RecipientDataPurposeLegal basis
Apple · Apple Distribution International Ltd., IrelandTransaction and Apple account dataDistribution of the application and processing of in-app purchases; Apple acts as the sellerArticle 6(1)(b) GDPR: performance of a contract
RevenueCat · RevenueCat, Inc., United StatesAnonymous identifier generated by the service, Apple purchase receipt, subscription status and expiry date, device model and application versionVerification and management of the subscription, restoring purchases on a new deviceArticle 6(1)(b) GDPR: performance of a contract
Google (the controller’s spreadsheet) · Google Ireland Limited, IrelandBrand, name and category of a product missing from the catalogue and added manually by the user, with the date and time it was entered; any photo of the product remains on the device and is not sentUpdating the application’s catalogue with the products requestedArticle 6(1)(f) GDPR: the controller’s legitimate interest in completing the catalogue; no data relating to the user
Open Beauty Facts · Association Open Food Facts, FranceSolely the scanned barcodeRetrieving the details of a product missing from the application’s catalogueArticle 6(1)(b) GDPR: performance of a contract, at the user’s request

RevenueCat, Inc. acts as a processor within the meaning of Article 28 GDPR. The identifier it generates is a random code, not linked to the user’s name, email address or any other identifying data, and does not allow the data stored on the device to be traced.

The Open Beauty Facts database is queried only when the user scans the barcode of a product that is not in the application’s catalogue. Only the barcode is transmitted, together with a technical identifier of the application required by the service’s terms of use; no data relating to the user is transmitted.

5Transfers to third countries#

The processing carried out by RevenueCat, Inc. involves a transfer of data to the United States of America. The transfer is covered by the standard contractual clauses adopted by the European Commission by Implementing Decision (EU) 2021/914, supplemented by the additional measures provided for in the data processing agreement entered into with the provider. The data subject may request a copy of the safeguards adopted by writing to the address given in Article 1. Reports of products missing from the catalogue are received by Google Ireland Limited within the European Union; any further processing by the Google group in the United States is covered by the EU-U.S. Data Privacy Framework, in which Google LLC participates, and by the same standard contractual clauses.

6Email communications#

Where the user writes to the controller of their own accord, including to be notified when the application becomes available, the email address and the content of the message are processed solely in order to respond to the request and, where relevant, to send the communication requested.

The legal basis is the data subject’s consent, given by sending the message (Article 6(1)(a) GDPR). Consent may be withdrawn at any time by writing to the address given in Article 1, whereupon the address will be deleted from the controller’s lists. Addresses are not passed on to third parties or used for purposes other than those set out here.

Providing the data needed to use the application is optional; if the data are not provided, the corresponding features cannot be used.

8Retention periods#

9Rights of the data subject#

The data subject may at any time exercise the rights provided for in Articles 15 to 22 GDPR: access, rectification, erasure, restriction of processing, data portability and objection, as well as withdrawal of consent without affecting the lawfulness of processing based on consent given before its withdrawal.

Requests should be sent to privacy@gloup.beauty and will be answered within thirty days, which may be extended by a further two months in the cases provided for in Article 12(3) GDPR, in which event the data subject will be informed.

As regards the data stored on the device, the data subject exercises these rights directly and in full through the features of the application, since the controller does not hold those data.

A data subject who considers that the processing does not comply with the law has the right to lodge a complaint with the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Roma, garante@gpdp.it), or with the supervisory authority of the Member State of habitual residence, and to bring proceedings before the courts.

10Minors#

The application is not intended for persons under the age of 14 (16 in States that set that threshold under Article 8 GDPR) and does not encourage its use by them. The controller does not knowingly process data relating to minors below that age; should it become aware of such processing, it will delete without delay any data that may be in its possession.

11No profiling or automated decision-making#

The controller does not profile users and does not take decisions based solely on automated processing which produce legal effects concerning, or similarly significantly affect, the data subject within the meaning of Article 22 GDPR. The processing performed by the application is descriptive and informative in nature, takes place on the device and is not used to evaluate any aspect of the person other than the skin parameters observed.

12Security measures#

Data stored on the device benefit from the protection measures of the operating system, including storage encryption and the isolation of the application’s private storage area. Access to the camera is subject to the user’s express authorisation, which may be revoked at any time in the system settings. The communications referred to in Article 4 take place over a channel encrypted in transit.

13Changes#

Material changes to this notice are notified to the user within the application, before they take effect. The effective date and version number are always shown at the top of the document.

© 2026 GLOUP · privacy@gloup.beauty