Privacy Policy for Glowiszyn UG Applications

Last updated: 2026, September 12

This Privacy Policy applies to all mobile applications (collectively referred to as "Applications" or "Apps" and individually as "Application") and related services provided by Glowiszyn UG (haftungsbeschränkt).

This Privacy Policy describes Our policies and procedures on the collection, use, and disclosure of Your information when You use our Services and tells You about Your privacy rights and how the law protects You. By downloading, installing, or using any of our Applications, You agree to the collection and use of information in accordance with this Privacy Policy.

Scope and Applicability (Umbrella Policy)

This is an "umbrella" Privacy Policy that governs all mobile applications, games, websites, and related services that are published now or at any time in the future by Glowiszyn UG (haftungsbeschränkt), regardless of the platform on which they are distributed (including, without limitation, the Apple App Store and the Google Play Store). Every application released by Us is automatically covered by this Privacy Policy unless that particular application provides its own separate privacy policy that expressly supersedes this one.

Any specific applications named in this document (for example, FaceWAT) are listed only as illustrative examples. The fact that an application is not named in this document does not exclude it from the scope of this Privacy Policy.

Different applications collect different data. This Privacy Policy describes the full range of data that Our applications may collect. It does not mean that every application collects every category of data described here. The data actually processed depends on the features of each individual application:

  • Some applications operate entirely offline and store all of Your data locally on Your device only. These applications do not transmit any personal data to Us or to any third party.
  • Other applications may collect some or all of the categories of data described below in order to provide their features (for example, advertising-supported or cloud-connected apps).

The specific data practices of each individual application are disclosed in that application's store listing — for example, the App Privacy details on the Apple App Store and the Data safety section on Google Play. Where those app-specific disclosures differ from this general Policy, the app-specific disclosures describe what that particular application actually does.

Interpretation and Definitions

Interpretation

The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

  • Account means a unique account created for You to access our Service or parts of our Service.
  • Affiliate means an entity that controls, is controlled by, or is under common control with a party.
  • Application refers to any software program provided by the Company and downloaded by You on any electronic device, including any and all current and future titles released by Us (for example, FaceWAT, and other titles released by Us).
  • Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to Glowiszyn UG (haftungsbeschränkt), Mellinghofer Str. 10, 45143 Essen, Germany.
  • Country refers to: Nordrhein-Westfalen, Germany.
  • Device means any device that can access the Service such as a computer, a cellphone, or a digital tablet.
  • Personal Data is any information that relates to an identified or identifiable individual.
  • Service refers to the Application, the Website, or both.
  • Service Provider means any natural or legal person who processes the data on behalf of the Company.
  • Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself.

Collecting and Using Your Personal Data

Types of Data Collected

1. Usage Data & Device Information

Usage Data is collected automatically when using the Service. This allows us to ensure the technical functionality of our Apps.

This data may include information such as:

  • Your Device's Internet Protocol address (e.g. IP address)
  • Device type, model, and manufacturer
  • Operating system version
  • Unique device identifiers (e.g., Advertising ID)
  • Diagnostic data (crash logs, performance data)
  • Time and date of Your visit and time spent on the Service

2. Information Collected while Using the Applications

Depending on the specific functionality of the Application You are using, We may request access to or collect certain information from Your Device to provide features (e.g., photo editing, location tagging, audio processing). This includes, but is not limited to:

  • Camera and Photo Library: To take photos or select images for processing, editing, or uploading within the App.
  • Location Information: We may collect approximate location data (e.g., via IP address) for analytics, advertising, and localization purposes. We generally do not track precise GPS coordinates unless explicitly required for a specific App feature.
  • Microphone: If an App involves audio recording or voice commands.
  • Storage: To save generated content or cache data.

We use this information to provide features of Our Service, to improve and customize Our Service. The information may be processed on Your device or uploaded to the Company's servers and/or a Service Provider's server (e.g., for cloud processing or backup).

Use of Your Personal Data

The Company may use Personal Data for the following broad purposes:

  • To provide and maintain our Service: Including monitoring the usage of our Service and ensuring technical stability.
  • To manage Your Account: To manage Your registration as a user of the Service.
  • For the performance of a contract: The development, compliance, and undertaking of the purchase contract for products or services You have purchased.
  • To contact You: regarding updates, security alerts, and support.
  • For Advertising and Marketing: To show You advertisements (including personalized ads) that support our free Apps, and to inform You about other goods, services, and events We offer.
  • For Business Transfers: We may use Your information to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets.
  • For Data Analytics: To analyze usage trends, determine the effectiveness of our promotional campaigns, and to evaluate and improve our Service, products, services, marketing, and your experience.

Sharing of Your Personal Data

We may share Your personal information in the following situations:

  • With Service Providers: To monitor and analyze the use of our Service, to display advertisements to You, to support and maintain our Service (e.g., Cloud hosting, AI processing).
  • With Business Partners: We may share Your information with Our business partners to offer You certain products, services, or promotions.
  • With Affiliates: We may share Your information with Our affiliates, in which case we will require those affiliates to honor this Privacy Policy.
  • For Legal Reasons: Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities.

Third-Party Services and Advertising

Our Applications are often provided as "Freemium" services supported by advertising. We work with third-party service providers to display ads and analyze user behavior. These third parties may access your data (such as Advertising ID and IP address).

Key partners we work with include, but are not limited to:

  • Google Play Services
  • Google AdMob & AdSense: For displaying advertisements.
  • Google Analytics for Firebase: For user analytics.
  • Firebase Crashlytics: For crash reporting and stability.

Which of these services are present depends on the individual application. Several of our apps contain no advertising, tracking or analytics SDKs at all; where that is the case, the app-specific section below says so explicitly. Where advertising is displayed, the advertising SDK may process your device's advertising ID (Google Advertising ID or Apple IDFA) together with your IP address.

In the European Economic Area and the United Kingdom, our apps that show personalised advertising ask for your consent before any ads are loaded, using Google's Consent Management Platform (UMP); on iOS Apple's App Tracking Transparency dialog applies in addition. You can change that choice later in the app's settings, and you can reset or limit the advertising ID in your device settings. Without consent, only non-personalised advertising is shown.

We advise You to review the Privacy Policies of these third-party services. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Physical Print Orders (PopArt Studio)

If you order a physical print (poster, canvas or acrylic glass) of your artwork through the "PopArt Studio" app, we additionally process the following data solely to fulfil that order, on the legal basis of contract performance (Art. 6(1)(b) GDPR) and our legal retention obligations (Art. 6(1)(c) GDPR):

  • The image you created (for printing),
  • Delivery and billing details (name, address, country),
  • Contact details (email for the order confirmation, optionally phone),
  • Order and payment data.

For this purpose your data is shared with the following processors/recipients:

  • Gelato (Gelato ASA, Oslo, Norway, and its worldwide print partners) — printing and shipping; receives the image and the delivery address. As Gelato produces locally around the world, a transfer to third countries may occur, safeguarded by EU Standard Contractual Clauses.
  • Stripe (Stripe Payments Europe, Ltd., Ireland) — payment processing; you enter your payment details directly with Stripe.
  • Our own server (api.popart.glowiszyn.com, operated by Glowiszyn UG) — receives the order and stores the image temporarily so Gelato can retrieve it.

The image editing itself happens locally on your device; the image is only transmitted when you actively place a print order. The uploaded image is automatically deleted from our server after the order is processed, and at the latest after 72 hours. Order and invoice data are retained for the statutory retention periods (generally 6–10 years).

Health & Fitness Data (Live Deficit)

The application Live Deficit can, at Your explicit request, read active energy burned (calories) from the health platform on Your device — Health Connect on Android and Apple HealthKit ("Apple Health") on iOS. This is used solely to import Your active energy into the app's daily calorie-deficit calculation, so that You do not have to enter workouts manually.

  • Read-only, single data type: We only read the "active energy burned" (kcal) value. We do not read any other health or fitness data, and We never write any data back to Health Connect or Apple Health.
  • Only on Your explicit action: No health data is accessed until You actively choose "Connect Health" in the app and grant permission in the system dialog.
  • Processed and stored locally only: The imported values are stored and processed exclusively on Your device. This health data is never transmitted to Our servers, never stored in any cloud, never shared with any third party, and never used for advertising or analytics.
  • Revocable at any time: You can withdraw access at any time in Your Health Connect or Apple Health settings, and You can delete the imported entries within the app.

Because health and fitness data is a special category of personal data, We process it only on the basis of Your explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR), which You give by connecting Health in the app and which You may withdraw at any time with effect for the future. Live Deficit's use of Health Connect data adheres to the Google Play Health Connect permissions policy, including the requirements that Health Connect data is not used for advertising and is not shared.

Flea Market Finder – Nearby Search and Submitted Markets

The application Flea Market Finder shows flea markets and similar events nearby. It needs no user account and contains no advertising and no analytics or tracking SDK.

  • Nearby search: If You allow location access, the app requests Your location at coarse accuracy and sends it with the search radius and period to Our server flohmarkt.glowiszyn.com, which replies with matching listings and does not store the request. No device identifier is sent. Without access You search by place name or postcode. Legal basis: providing the requested feature (Art. 6(1)(b) GDPR).
  • Abuse protection: To limit request floods We store, per request, a keyed hash of the IP address – never the address itself – and delete these entries after 7 days at the latest (Art. 6(1)(f) GDPR).
  • Submitted markets and corrections: When You submit a market or report a correction, We store what You entered plus that hashed IP value. A submitted market is published with its market details (name, place, times, organiser) after editorial review (Art. 6(1)(f) GDPR).
  • Optional contact email: You may give an email address for questions about Your submission. It is never published, never sent to the app and never used for advertising. Legal basis: Your consent (Art. 6(1)(a) GDPR), which You can withdraw at any time by writing to hello@glowiszyn.com.
  • Stored locally: Saved markets, reminders, filters, language, the last location used and the last search results (for offline viewing) stay on Your device and are not transmitted. Reminders are scheduled locally without a push service.

Finance Tracker – Local Data, Remote Configuration and Feedback

The application Finance Tracker (bundle ID com.glowiszyn.financetracker) is a household budget book. Everything You enter – entries with amount, category, note, date and payment method, as well as budgets, recurring entries and savings goals – is stored exclusively on Your device. There is no user account, no cloud synchronisation and no transfer of these contents to Us. A backup file is created only when You export one Yourself. The app contains no tracking, analytics or advertising SDKs and collects no advertising IDs.

  • Remote configuration at start: On every start the app fetches a small configuration file from our server (api.financetracker.glowiszyn.com), so that We can change details such as the store address or a notice text without publishing a new version of the app. No data You entered and no device identifier is transmitted. As with any server request, our server processes the technically unavoidable access data (IP address, time, requested address, user agent); the section on server log files applies. The legal basis is our legitimate interest in operating and maintaining the app (Art. 6(1)(f) GDPR). Without a network connection the app continues to work unchanged with its built-in defaults.
  • Voluntary feedback: Only when You send feedback from within the app do We transmit the text You typed, the app version, the platform and the selected language to the same server. No device identifiers and no entry contents are transmitted. The legal basis is Your consent given by sending (Art. 6(1)(a) GDPR) or our legitimate interest in improving the app (Art. 6(1)(f) GDPR).
  • Purchases and subscriptions: The optional Pro features are handled entirely through the Apple App Store or Google Play; We receive no payment data, only the confirmation that a purchase or subscription exists.
  • Web version: At financetracker.glowiszyn.com/app We offer a preview version in the browser. Everything entered there stays in Your browser's storage only; no contents are transmitted to Us. Moving the data into the app happens through a backup file You export Yourself.

Mein Pferd – Local Data, Optional Cloud Backup and Sharing

The application Mein Pferd (bundle ID com.glowiszyn.pferd) helps You manage horses. The data You enter – such as a horse's master data, health, care and feeding records, appointments and deadlines, photos and notes – is stored exclusively on Your device and does not leave it unless You use one of the optional functions described below. The app contains no tracking, analytics or advertising SDKs and collects no advertising ID.

Optional cloud backup and device synchronisation. If You enable the cloud backup, a pseudonymous account is created automatically on our server (api.pferd.glowiszyn.com). No name, email address or password is required – the account is identified solely by a randomly generated access token stored on Your device. Your app data is transmitted over an encrypted connection (HTTPS) and stored there so that You can restore it and synchronise it between Your own devices.

Optional sharing. You can generate a sharing code or link to grant another person (for example a stable owner, co-rider or veterinarian) read or write access to the shared data. Access is granted solely through that code; we do not collect the recipient's email address. Shares can be revoked at any time in the app.

The legal basis is the performance of the user agreement and the provision of the functions You expressly requested (Art. 6(1)(b) GDPR). Operation runs on our own server; backup and sharing data is not passed on to third parties, apart from our technical hosting provider. You can disable the cloud backup at any time and delete the account together with the stored data, which is then removed from our server.

Print orders. If You order a physical print product with a photo of Your horse, we additionally process the image You selected, Your delivery and billing details, Your email address and the order and payment data. The recipients and retention periods are the same as described under “Physical Print Orders” above: the image is passed to our print partner Gelato, payment is handled by Stripe, and the uploaded image is deleted from our server after the order has been processed, at the latest after 72 hours.

In-app purchases / subscriptions. Optional subscriptions can be purchased in the app. Payment and contract handling take place entirely through the Apple App Store or Google Play; we receive no payment data, only the confirmation that a purchase or subscription exists.

Affiliate Programmes

Some of our websites finance themselves through affiliate programmes – in particular the Amazon partner programme. We place links to third-party offers; if You follow such a link and make a purchase, the provider may set a cookie or a comparable identifier in order to attribute the sale to us. We ourselves receive only aggregated settlement figures and cannot identify individual purchasers. The legal basis is our legitimate interest in financing our offering (Art. 6(1)(f) GDPR), and, where the provider requires consent for cookies, Your consent (Art. 6(1)(a) GDPR). Prices shown for such products may be out of date; see the price disclaimer in our imprint.

TimeRoutine – Local Data, Reminders and Advertising

The application TimeRoutine (bundle ID app.timeroutine) helps You structure daily routines. Your routines, tasks, timer settings and preferences are stored exclusively on Your device. There is no user account, no cloud synchronisation and no transfer of these contents to us – the app has no server of its own. A backup file is created only when You export one Yourself.

Reminders. Reminders are scheduled and displayed locally by Your device. We operate no push service for this app, and no notification is routed through our servers.

Advertising. The free version displays advertising via Google AdMob; the section “Third-Party Services and Advertising” above applies, including the processing of Your advertising ID. The consent dialogue described there (Google UMP, and App Tracking Transparency on iOS) is included from app version 2.1.0 onwards; from that version on You can also reopen it at any time via “Ad Privacy Options” in the app settings. The Pro purchase removes the advertising.

Purchases. Pro is handled entirely through the Apple App Store or Google Play; we receive no payment data, only the confirmation that a purchase exists.

Newsletter and Product Updates

On our websites and in our Applications we offer the option to subscribe to a free email newsletter informing You about news, new features and the release of the products You subscribed to, as well as occasional updates about our other apps and offerings. You can unsubscribe at any time. The newsletter is operated by Us on our own system at newsletter.glowiszyn.com, running on the same server in Germany as our other services. No external email service provider is involved and Your data is not shared with any third party.

Double Opt-In and Proof of Consent

Sign-up uses the double opt-in procedure: after submitting the form You receive an email asking You to confirm by clicking a confirmation link. You are only added to the list after that confirmation, so nobody can subscribe someone else's address. If You do not confirm within 30 days, We delete Your data completely and without further notice; the confirmation link itself expires after seven days.

As proof of consent We record the time of sign-up and of confirmation, the IP address used, Your browser identification (user agent), the page You signed up on, and the exact wording and version of the consent text. Later changes to Your preferences and Your unsubscription are recorded as well.

Data We Collect

Only Your email address is required. In addition We store the language of the emails (German or English), derived from the page You sign up on, and the service through which You signed up. You can change the language at any time yourself (see below).

Legal Basis

We send the newsletter solely on the basis of Your consent pursuant to Art. 6(1)(a) and Art. 7 GDPR in conjunction with Sec. 7(2) No. 2 of the German Act Against Unfair Competition (UWG). We do not rely on the existing-customer exemption under Sec. 7(3) UWG. Recording the sign-up procedure is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in being able to prove the consent required by law.

No Open or Click Tracking

Our newsletters contain no tracking pixels ("web beacons"), no open tracking and no redirected counting links. We therefore do not learn whether or when You opened an email, nor which links You clicked. No analysis of Your reading behaviour and no profiling takes place.

Preferences and Your Rights

At the end of every email, next to the unsubscribe link, You find a personal link where You can change the language of the emails or unsubscribe, without registering. You can exercise Your right of access to all data stored about Your address including the consent record (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR) and Your other rights at any time by sending an informal email to hello@glowiszyn.com. We handle Your request without undue delay and within one month at the latest.

Unsubscribing and Withdrawal of Consent

You can stop receiving emails and thereby withdraw Your consent with effect for the future at any time – via the unsubscribe link in every email, via the unsubscribe function of Your email client (We support the "List-Unsubscribe" standard including one-click unsubscribe per RFC 8058), or informally by email to hello@glowiszyn.com. The lawfulness of processing carried out before the withdrawal remains unaffected.

Storage Period

We store Your data for as long as Your subscription lasts. After You unsubscribe, the subscription data is deleted automatically after two years at the latest. Proof of Your consent is kept for up to three years after the end of the subscription in order to defend against potential claims (Art. 6(1)(f) GDPR); processing of that data is limited to this purpose. To make sure an unsubscribed address is never contacted again by mistake, We additionally keep a non-reversible checksum (HMAC hash) of the address on a suppression list; the address itself cannot be reconstructed from it. You can trigger immediate and complete erasure yourself at any time (see above) or request it informally from Us.

Protection Against Misuse

To prevent automated sign-ups and the subscription of addresses belonging to other people, the form uses a field invisible to You (a "honeypot"), a minimum dwell time, and a limit on attempts per IP address and per email address. No cookies are set and no external services are involved.

Retention and Deletion

The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. Usage Data is generally retained for a shorter period, except when this data is used to strengthen the security or to improve the functionality of Our Service.

You can request deletion of your data by contacting us or, where applicable, using the delete function within the App.

GDPR (General Data Protection Regulation) Rights

If You are located in the European Economic Area (EEA), You have certain data protection rights. Glowiszyn UG aims to take reasonable steps to allow You to correct, amend, delete, or limit the use of Your Personal Data.

Legal Bases for Processing

Where the GDPR applies, We process Your Personal Data on the following legal bases:

  • Performance of a contract (Art. 6(1)(b) GDPR) — to provide the features You request and to fulfil purchase and print orders.
  • Legitimate interests (Art. 6(1)(f) GDPR) — to ensure the technical stability and security of our Apps, to analyse and improve our Service, and to prevent fraud and abuse.
  • Consent (Art. 6(1)(a) GDPR) — for personalised advertising and any other processing that requires Your consent; You may withdraw Your consent at any time with effect for the future.
  • Legal obligation (Art. 6(1)(c) GDPR) — where We are required to retain data, e.g. for statutory tax and commercial-law retention periods.

You have the right to:

  • Access, update or delete the information We have on You.
  • The right of rectification.
  • The right to object.
  • The right of restriction.
  • The right to data portability.
  • The right to withdraw consent.
  • The right to lodge a complaint with a supervisory authority (Art. 77 GDPR).

Right to Lodge a Complaint

Without prejudice to any other remedy, You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU Member State of Your habitual residence, place of work, or place of the alleged infringement. The authority competent for Us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
https://www.ldi.nrw.de

Children's Privacy

Our Services are not addressed to anyone under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personally identifiable information from anyone under these ages. If We become aware that We have collected Personal Data from a child without verification of parental consent, We take steps to remove that information from Our servers.

Changes to this Privacy Policy

We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page. You are advised to review this Privacy Policy periodically for any changes.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

  • By email: hello@glowiszyn.com
  • By mail: Glowiszyn UG (haftungsbeschränkt), Mellinghofer Str. 10, 45143 Essen, Germany