THAT GLOWING GIRL
Your privacy
Effective date: October 10, 2026.
Operator: WIDGET WORKS LLP. Contact: aaryan@widgetworks.in.
That Glowing Girl provides personal rituals, private journaling, affirmations and optional AI reflections. It is a wellness app and does not provide medical advice, diagnosis or treatment.
Your private space
Your profile, journal, moods, intentions, signature and photos are saved in the app's local storage. Journal storage uses SQLCipher encryption and its key is held by the operating system's secure credential storage. The app does not upload your journal or photos as an account backup. Android app data is excluded from automatic cloud backup and device transfer. Your device's own iOS backup and recovery settings may apply separately.
Camera access supports a live mirror and photos you choose to take. The app does not record mirror video or microphone audio. Photo library access lets you choose images for your own space. Notification permission is optional and supports reminders you configure.
An export or share action sends only the content you choose to the destination you select. That destination's privacy practices then apply. Avoid sharing content you want to keep private.
Optional AI reflections
Before a reflection is sent, the app asks for your consent. Only the writing and reflection context selected for that request are transmitted through our protected Firebase backend to OpenRouter and a permitted Google model provider. Photos and signatures are not included. Requests require a verified membership and an attested app, and are subject to usage limits.
The backend does not persist reflection writing or generated answers in its database or application logs. Provider routing requires zero data retention and prohibits provider data collection. Reflections returned to you are stored locally. You can use journaling without requesting AI, and can withdraw reflection consent in Privacy settings.
Identity and subscriptions
Firebase creates a pseudonymous service identity. If you choose to create an account or sign in, Firebase Authentication also processes your email address and authentication credentials to reconnect your membership. Account sign-in does not sync journals, photos or your personal plan. You can delete your sign-in account from Account & sign in in the app. Firebase and RevenueCat retain that identifier, subscription status, transaction references and usage allowance records needed to provide paid access, restore purchases, prevent fraud and enforce usage limits. Apple or Google processes payments; the app does not receive your payment card details.
Membership is required for the main app. The U.S. prices are $5 per week or $40 per year, with no free trial. The store displays the actual localized price and taxes before confirmation. Subscriptions renew automatically until canceled through the relevant store account. Local app erasure does not cancel a subscription.
Optional app update notifications
If you enable App updates, we store this device’s push token and a random installation identifier linked to its Firebase service identity to send optional notifications through Apple Push Notification service or Firebase Cloud Messaging. Notifications contain general app content only, never your private writing. Turn App updates off to unregister the device. Inactive registrations expire after 30 days. Local data erasure requests unregistering; if offline, the app retries when connected. Existing local reminders remain separate.
Analytics and error reporting
PostHog receives pseudonymous onboarding step and action events, checkout outcomes and selected app interaction events. Events are configured to exclude entered names, birthdays, private writing, moods, signatures, photos, journal content and AI content. We disable IP geolocation and do not use analytics for advertising or cross-app tracking.
For a randomly sampled half of onboarding runs, PostHog may record masked onboarding screens to help us improve the experience. Recording is limited to eligible onboarding and paywall screens, stops outside that flow or while the app is in the background, and excludes private input and personalized preview screens. Entered text and images are masked; console logs, network payloads and touch coordinates are disabled. Onboarding recordings can be turned off in the app’s Privacy controls. Replay Vision is not enabled. Recordings are retained for 30 days under the current project configuration.
Sentry receives scrubbed error reports, code locations, app/build details and safe navigation context so we can diagnose failures. Sentry session replay, screenshots, view hierarchies and network breadcrumbs are disabled. Error messages and event fields are filtered to avoid private content. Diagnostic reports are retained according to the service’s configured retention period and removed when no longer needed for troubleshooting. You can contact us with a deletion request.
Retention, controls and requests
You can export your local data or erase it in the app's Privacy settings, including when your membership is locked. Erasure removes local content and resets local analytics state. It does not cancel store subscriptions or automatically erase transaction, fraud-prevention, quota or legally required service records. Contact aaryan@widgetworks.in for access or deletion requests concerning connected services.
Providers process data in their supported service regions, which may be outside your country. We do not sell personal data. We use these service providers only to operate, secure and improve the app. Applicable privacy rights depend on your location. The app is designed for personal wellness and is not directed to children.
We will update this policy when practices change and show its effective date. Material changes requiring new consent will be presented in the app as appropriate.
This website
This website does not add analytics, advertising pixels, account registration or forms. Fonts and images are served with the site. Our hosting infrastructure processes request information, such as IP address, requested URL, browser information and request time, to deliver and secure the website. If you email us, we use your message and contact details to respond and resolve your request. Please do not send private journal content or payment details.