Privacy Policy
Last updated 31 July 2026
Glow50x provides an AI aesthetic simulation platform to clinics. This policy explains what data we handle, who else touches it, where it lives, and how it is deleted. We have written it to describe what the platform actually does today rather than what we would like it to do.
1. Who we are and how responsibility is split
Glow50x is operated by Grow50x.ai, Dubai, United Arab Emirates. Your clinic is the data controller of its patients' personal data. Glow50x processes that data on the clinic's behalf in order to deliver the service. For clinic account data β your business details, user accounts and billing β Glow50x acts as the controller.
2. Data we process
On behalf of clinics (patient data):
- Patient identity and contact details entered by the clinic (name, email, phone, notes).
- Patient photographs uploaded for simulation, including facial and body photography.
- Clinical assessment data generated in the workflow, such as hair-loss staging, donor-area analysis, graft estimates and procedure configurations.
- Generated simulation images, timelines and consultation reports.
- The consent record captured when a patient is created: the consent confirmation, the date, and the attesting clinician's typed signature.
As controller (clinic data): clinic profile and licence details, user accounts and roles, credit balances and transaction logs, billing records, support correspondence and technical logs.
3. Why we process it
Patient data is processed solely to provide the service to your clinic: generating simulations, assessments, timelines and reports, and maintaining your patient records. We do not use patient photographs for advertising, and we do not sell personal data.
4. Subprocessors β who else touches the data
- Google (Google Cloud / Firebase) β application hosting, authentication, database and storage; and AI image processing: patient photographs are transmitted to Google's generative AI service in order to produce the simulation images.
- Stripe β payment processing for clinic billing. Stripe does not receive patient photographs.
We will update this list before adding any further processor that handles patient data.
5. Where data is stored
Platform data is stored on Google Cloud infrastructure located in the United States. Time-limited operational backup copies are maintained for disaster recovery and are subject to the same confidentiality obligations. Clinics in jurisdictions with cross-border transfer requirements β for example the EU/EEA under the GDPR, or TΓΌrkiye under the KVKK β should assess this transfer as part of their own controller obligations. Contact us and we will cooperate with your documentation.
6. Retention and deletion
Patient records, photographs and simulations are retained until the clinic deletes them. Deleting a patient also removes that patient's photographs and simulations from the live database. Cached AI-processing artifacts (such as annotated planning images) are automatically deleted approximately 30 days after creation.
Account deletion (self-service): the clinic owner can permanently delete the clinic account from Settings β Profile β "Delete clinic account". This removes the clinic, every doctor sub-account, and all patient records, photographs, simulations, analyses and cached artifacts. Deletion is immediate and cannot be undone. The same control is available in the Glow50x mobile apps, and clinics may also request deletion via support.
There is currently no automated retention limit for patient records and no self-service bulk export. We state this plainly rather than imply automation that does not exist. If your clinic requires a defined retention schedule, apply it through in-app deletion or contact us.
7. Security
Data is encrypted in transit over HTTPS and encrypted at rest using Google Cloud's platform-managed encryption. Access to patient data is isolated per clinic: a clinic's accounts can only reach that clinic's records. Account credentials are managed by Firebase Authentication. Administrative access is restricted and used for operations and support.
8. Cookies and tracking
The application uses only a functional session and authentication mechanism. We run no advertising trackers and no third-party analytics in the application.
9. Patients' rights
Patients should direct access, correction and deletion requests to their clinic, which controls their records. If a patient contacts us directly we will refer the request to the relevant clinic and cooperate in fulfilling it. Escalations: partner@glow50x.com.
10. AI transparency
Every image generated by the platform carries an embedded notice identifying it as an AI-generated simulation for consultation and visualisation purposes, and printed reports carry a visible simulation disclaimer. Simulations are illustrative; actual results may differ.
11. Changes and contact
We will post updates to this policy here and, for material changes affecting patient data, notify clinics in the application. Contact: partner@glow50x.com β Glow50x, Dubai Internet City, UAE.
This document is published in English; the English text governs. Questions: partner@glow50x.com
Read the Terms of Service