Effective 25 August 2026 · Last updated 25 August 2026
This policy explains what GlowUps does with your personal data. The short version: we collect what a forum needs to run, we publish what you choose to publish, and we do not sell anything about you. The section on photographs is the one worth reading closely, because a before-and-after photo of a medical procedure is health data.
1. Who we are
glowups.net (“GlowUps”, “we”, “us”) is an independently operated online community and is the controller of the personal data described here. We apply the standards of the General Data Protection Regulation to everyone who uses the site, wherever they are.
Data protection contact: [email protected]
2. What we collect
2.1 What you give us
- Account data: username, email address, a hashed password (we never store the password itself), your confirmation that you are 18 or over, and your registration date.
- Profile data: anything you choose to add, such as avatar, location, signature, about text and links.
- Content: your threads, posts, photographs, reactions, and any attachments.
- Private conversations: messages you send other members through the site. These are private from other members but are stored on our server and are visible to administrators where necessary for moderation or legal reasons.
- Correspondence: reports you file, and emails you send us.
2.2 What we collect automatically
- IP address, recorded on registration, login, and with each post, for spam and ban-evasion detection.
- Technical data: browser and version, operating system, screen size, language, referring page, and the pages you view with their timestamps.
- Cookies and local storage: see our Cookie Notice.
2.3 What we get from others
- Anti-spam and anti-abuse services, which return a risk score for an email address or IP address at registration.
- Our CAPTCHA provider, which tells us whether a submission looks automated.
- Our email delivery provider, which tells us whether a message was delivered or bounced.
3. Photographs, and why they are treated differently
A before-and-after photograph of a rhinoplasty, a bimax, a hair transplant or a body recomposition can reveal information about your health and about medical treatment you have had. Under Article 9 of the GDPR that is special category data and gets extra protection.
- We do not require you to post photographs. Choosing to upload one is entirely voluntary.
- Where you upload a photograph to a public area of GlowUps, you are deliberately making that information public. We rely on Article 9(2)(e) (data manifestly made public by the data subject) and, where it is needed, on your explicit consent, which you give by choosing to publish it. You can withdraw that consent at any time by deleting the content or asking us to.
- Photographs you upload are re-encoded and resized by the forum software, which removes most embedded metadata such as GPS coordinates and camera identifiers. Do not rely on that. Check your images before uploading if location or device data matters to you.
- Never upload a photograph of another person's face or body without their permission. If you do, you become responsible for that person's data as well as your own, and we will remove the image on request.
4. Why we use your data, and our legal basis
- Running the site: creating your account, displaying your posts, delivering notifications you have asked for. Legal basis: performance of our contract with you.
- Publishing your content: showing what you post to other members and to the public. Legal basis: contract; for health data, Article 9(2)(e) and your explicit consent.
- Safety, moderation and abuse prevention: spam filtering, detecting ban evasion, investigating reports, keeping moderation records. Legal basis: our legitimate interest in running a safe community.
- Security and diagnostics: server logs, error logs, rate limiting. Legal basis: legitimate interests.
- Service emails: password resets, alerts you have subscribed to, important notices about the site. Legal basis: contract.
- Any marketing email: only if you have opted in. Legal basis: consent, which you can withdraw at any time.
- Complying with the law: responding to lawful requests, keeping records we are required to keep. Legal basis: legal obligation.
5. Cookies
We use cookies that are necessary for the site to work: a session cookie, a “stay logged in” cookie if you choose it, a CSRF token, and small preference cookies that remember things like your light or dark theme and whether you have collapsed the gallery. We do not use advertising or cross-site tracking cookies. Details are in the Cookie Notice.
6. Who we share data with
We do not sell personal data and we do not share it for anyone else's marketing. We share it with:
- Our hosting and infrastructure providers, who store the site and its database on our behalf.
- Our content delivery and security provider, which sits in front of the site and sees request data including your IP address.
- Our email delivery provider, for the emails the site sends you.
- Anti-spam and CAPTCHA providers, at registration and on some submissions.
- Law enforcement, regulators or others, where we are legally required to, or where it is necessary to establish, exercise or defend legal claims, or to protect someone's vital interests.
- A buyer or successor, if the site is ever transferred, subject to this policy.
And, of course, with the public: everything you post in a public area of the forum.
7. International transfers
Our providers process data in several countries, including the United States. Whenever personal data crosses a border we rely on an adequacy decision for the destination country, or on approved standard contractual clauses and the transfer addenda that go with them, together with appropriate technical safeguards.
8. How long we keep it
- Account data: for as long as your account is open. If you close it, we delete or anonymise your account record.
- Your posts: posts are part of ongoing conversations, so when an account is closed we usually keep the posts and detach them from your identity rather than deleting threads other members contributed to. If you want specific posts or photographs deleted outright, ask and we will do it.
- Photographs and attachments: deleted from the server when you or we delete them, subject to backup rotation.
- IP addresses attached to posts: retained while the content exists, for abuse investigation.
- Server and security logs: a short rolling period, normally no more than 90 days.
- Moderation and ban records: kept for as long as necessary to enforce bans and to defend against complaints.
- Backups: deleted data can persist in backups for a short period before those are overwritten.
9. Your rights
Under the GDPR, and under comparable data-protection laws elsewhere, you have the right to:
- ask what we hold about you and get a copy (access);
- have inaccurate data corrected (rectification);
- have data deleted (erasure), subject to the retention points above;
- ask us to restrict processing while a dispute is resolved;
- receive your data in a portable format (portability);
- object to processing we carry out on the basis of legitimate interests;
- withdraw consent at any time, where we rely on it.
To exercise any of these, email [email protected]. We respond within one month. We may ask you to confirm you control the account before we act, because these requests are a common route for account takeover.
If you are unhappy with how we handle your data, please tell us first at [email protected] so we can put it right. You also have the right to complain to the data-protection supervisory authority for the country where you live, work, or where you think the problem happened.
10. What we cannot undo
Public posts and photographs are indexed by search engines and can be copied, screenshotted and archived by people we have no relationship with. When you delete something we remove it from GlowUps, and we will ask search engines to drop it from their index, but we cannot reach into caches, archives or someone else's saved copy. Please take that into account before you post a photograph of your face.
11. People under 18
GlowUps is for adults. We do not knowingly collect data from anyone under 18. If we learn that an account belongs to someone under 18 we suspend it and delete the account and its content. If you believe a minor has an account here, tell us at [email protected].
12. Security
The site is served over HTTPS, passwords are stored hashed and salted, administrative access is limited to the people who need it, and we apply software updates as they are released. No system is perfectly secure. Use a password you do not use anywhere else, and enable two-step verification in your account preferences if you want a second layer.
13. Automated processing
We use automated spam and abuse scoring at registration and on some submissions. It can cause a registration or post to be held for manual review. It does not, on its own, produce legal effects concerning you, and a human reviews anything that is held. If an automated check has blocked you in error, email [email protected].
14. Changes to this policy
We may update this policy. The date at the top shows when it last changed. Where a change materially affects how we use your data we will give notice on the site or by email before it takes effect.
15. Contact