Privacy policy

Last updated 2026-09-29

Who we are

Golméa is a skincare and beauty app operated from Sweden. We decide how and why your data is used, which under the GDPR makes us the data controller.

You can reach us at support@golmea.app about anything in this policy, including a request to see or delete your data.

The short version

You can use Golméa without creating an account. If you do link an Apple ID, it exists so your data survives a lost phone — not so we can identify you elsewhere.

We do not sell your data. We do not share it with advertisers. We have no advertising in the app.

The sensitive things you tell us — your cycle, whether you are pregnant, your allergies, your photos — are used to make the advice specific to you, and for nothing else.

What we collect

Your profile: first name, skin type, skin concerns, allergies, climate, hair type and condition, makeup preferences, and optionally your menstrual cycle length, the start of your last period, pregnancy status and due or delivery date.

What you scan and save: products you scan, the analysis we generate, your shelf, your routine, which steps you complete or skip each day, your streaks, saved looks and colour palettes, and your conversations with the Skin Agent.

Photographs: if you use Morning Mirror, it takes three photos of your face — from the front, the left and the right. Only the front photo is stored, so your skin can be compared over time, and it is kept in a private store that only your account can read.

Technical data: app version, device type, crash reports, and anonymous usage events such as which screens are opened.

Your plan and how much of it you have used: which subscription tier you are on, any credits you have bought, and a count of how many times you have used each feature this month. We keep the counts to apply the monthly allowances — they reset each month and are not used to profile you.

Approximate location, only if you allow it, and only to fetch the UV index and weather for your area. We store the coordinates on your device, not the address, and we do not track your movement.

Health data, and why we ask for explicit consent

Your cycle, pregnancy status, allergies and skin concerns are health data under Article 9 of the GDPR. So are the photographs of your face, in the sense that they reveal information about your skin.

European law treats this category as prohibited to process unless you give explicit consent. That is why these fields are optional and asked for separately: you can use Golméa fully without telling us any of them, and the app will simply give less specific advice.

You can withdraw that consent at any time by clearing those fields in your profile, or by deleting your account, which removes everything.

We use this data to personalise recommendations — flagging an ingredient against your allergy, adjusting advice for your cycle phase, or excluding ingredients that are not considered safe in pregnancy. We do not use it to advertise to you, and we never share it with insurers, employers or data brokers.

Artificial intelligence, and what it sees

Golméa uses Claude, an AI model made by Anthropic, to analyse products against your profile. When you scan something, we send Anthropic the product details and the relevant parts of your profile — for example your skin type, concerns and allergies — so the answer is about you rather than generic.

We never send your name, email address, Apple ID or photographs to Anthropic for product analysis. Morning Mirror is the exception: analysing your skin requires sending all three of its photos. Of the three, we keep only the front photo, as described above.

Anthropic processes this on our behalf and does not use it to train its models.

We keep a record of these AI interactions — the information we sent and the answer that came back — to measure quality and to improve the advice over time. This record is tied to your account and is deleted when you delete your account.

Who else processes your data

Supabase stores your account, your data and your photos, hosted in the EU (Stockholm).

Anthropic provides the AI analysis described above, in the United States. Transfers outside the EU are covered by the European Commission's standard contractual clauses.

PostHog provides anonymous product analytics, hosted in the EU. Sentry receives crash reports, hosted in Germany.

Apple handles Sign in with Apple. If you choose Hide My Email, we never see your real address.

When you scan a barcode we look it up with INCI API and Open Beauty Facts. Only the barcode is sent. Nothing about you goes with it.

Expo hosts the app updates. When Golméa starts it asks Expo's servers whether a newer version of the app is available, which tells them your device type, app version and a random installation identifier. It carries nothing about you or your skin.

If you email us, the message is delivered through Cloudflare and kept in a Google Gmail mailbox. Our website, golmea.app, is served by Cloudflare, which sees your IP address as any web host does. The website sets no cookies and runs no analytics.

How long we keep it

Your data stays until you delete it. Deleting your account removes your profile, scans, analyses, routine, completions, conversations, saved looks, palettes and photographs, immediately and permanently.

Daily routine completions older than 90 days are removed from your phone automatically. Copies kept on our servers may be retained longer.

Anonymous accounts that are never used again may be deleted after a period of inactivity.

Your rights

Under the GDPR you can ask for a copy of your data, correct it, delete it, restrict or object to how it is used, and take it elsewhere in a machine-readable form.

Two of these are built into the app. Settings → Export my data produces a file containing everything we hold, from both our servers and your phone. Settings → Delete account erases it.

For anything else, write to support@golmea.app. If you believe we have handled your data badly you can complain to the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority.

Children

Golméa is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us information, write to us and we will delete it.

Security

Data is encrypted in transit and at rest. Access is restricted per account at the database level, so one account cannot read another's data. Photographs are stored privately and are only reachable through a short-lived link generated for you.

No system is perfect. If a breach ever affects your data, we will tell you and the relevant authority as the law requires.

Changes

If we change this policy in a way that materially affects you, we will tell you in the app before it takes effect. The date at the top shows the current version.