← Back to Glimsa

Privacy Policy

Last updated: 24 July 2026 · Glimsa is currently in open beta.

The short version

  • Your photos are stored in private storage — not public, not browsable, not indexed.
  • We do not train any AI model on your photos, and we do not sell or share your data.
  • Your photo is sent to our AI provider only to generate the look you asked for.
  • You can delete every photo and result you have ever uploaded, from inside the app, at any time.
  • Glimsa is for adults (18+). Don't upload photos of other people without their consent.

What we collect

The photos you upload, the images we generate from them, your email address (that is the whole account — there is no password), your remaining credit balance, and basic usage records such as which look you applied and whether it succeeded. If you rate a result or send a comment, we store that too.

Why we process your photo

Only to produce the transformation you requested. A facial photo is sensitive personal data, and uploading one is your explicit consent for that single purpose. You can withdraw it at any time by deleting your photos (see below). We never use your images for advertising, and we never use them to train models — ours or anyone else's.

Who else processes your photo

To generate a look we send your image to our AI providers — fal.ai, which runs Google's image models, and Google Gemini, which reads the photo to describe hair and colouring. Your images are also stored with Supabase (database and private storage) and the app is served by Vercel. Sign-in emails are sent through Resend. These providers process data on our behalf; each has its own privacy policy.

How long we keep it

Photos and results are kept while your account exists, so you can revisit your looks. There is no automatic expiry during the beta — instead, deletion is in your hands and takes effect immediately: use “Delete my photos” in the app footer to erase every photo and generated result from storage right away. To delete the account itself, email us and we will remove it within 30 days.

Your rights

You can access, correct, export or delete your data, and withdraw consent at any time. If you are in the EU/UK you have these rights under the GDPR; in Chile, under Law 21.719; in California, under the CCPA. Write to privacy@glimsa.com and we will respond within 30 days.

Security

Data is encrypted in transit and at rest. Storage buckets are private and access is enforced per-user at the database level (row level security), so one account can never read another account's photos.

Age limit and other people's photos

Glimsa is for people aged 18 and over. Do not upload photos of minors. Only upload photos of someone else if they have agreed to it.

About the results

Generated images are illustrative AI simulations. They are a preview, not a promise: a real haircut, colour or treatment may look different. Glimsa does not provide medical or cosmetic advice — for any procedure, talk to a qualified professional.

Contact

Questions or complaints: privacy@glimsa.com. Glimsa is operated by HF Labs. As the product leaves beta this policy will be updated; the date at the top always reflects the current version.