Privacy Policy for GRLY
Effective date: July 3, 2025 · Last updated: June 24, 2026
The short version
GRLY is a supplement tracker operated by Ourskin, Inc. We collect what we need to run the app — your account details and the wellness/supplement information you choose to track — and your health information is used only with your explicit consent, which you can withdraw at any time. We do not sell your data, we do not use advertising networks or analytics trackers, and we do not track you across other apps or websites. You can access, export, or delete your data by contacting us, and delete your account in the app at any time. The full detail is below.
1. Who We Are & Scope
This Privacy Policy ("Policy") explains how Ourskin, Inc., doing business as "GRLY" ("GRLY", "we", "us", or "our"), collects, uses, shares, and protects your personal information when you use the GRLY mobile app, the website at grlyapp.co, and the GRLY store at grly.co (together, the "Services").
Ourskin, Inc. is the data controller responsible for your personal information. This Policy meets the EU and UK General Data Protection Regulation (GDPR / UK GDPR), the Swiss Federal Act on Data Protection (FADP), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and other applicable laws. Region-specific rights are in Sections 15–17.
Legal entity: Ourskin, Inc., a Delaware corporation
Registered address: 1111B South Governors Ave, Dover, DE 19904, USA
Privacy contact: connect@grlyapp.co
2. Information We Collect
Information you provide
Account information — your name and email address, and (if you register with a password) a securely hashed password. If you sign in with Google or Apple, we receive your name and email from that provider.
Wellness & supplement data (health information) — the supplements you track; dosages, schedules, and reminders; your intake history (taken/skipped, dates, and any notes you add); your onboarding answers (such as age range, goals, and preferences); and streak/progress data. Under GDPR/UK GDPR this is special-category health data, and under the CPRA it is sensitive personal information. We process it only with your explicit consent (Section 5).
Label scans — if you use the camera scanner, a photo of the supplement label is sent to our analysis service to identify the product. The image is not stored on your device and is retained only transiently for the analysis (Section 12).
Communications — anything you send us directly (e.g., support requests).
Information collected automatically
Device & technical data — a per-app device identifier and a push-notification token (used to deliver the reminders you enable), app version, time zone, and basic diagnostic information needed to operate the app.
Information from the store
Order information — if you shop at our store (grly.co) or link your store and app accounts, we may receive order information so we can show your orders and make relevant recommendations. Payments and checkout are handled by Shopify under its own privacy policy; we do not receive full payment card numbers.
What we do not collect: we do not collect your precise location, your contacts, or your photo library; we do not use advertising identifiers (such as Apple's IDFA or Google's GAID); and we do not ask for App Tracking Transparency permission, because we do not track you across other companies' apps or websites.
3. How We Use Your Information & Our Legal Bases
Create and manage your account — using your account data, on the basis of performance of a contract.
Provide the core features (supplement tracking, reminders, label analysis, recommendations) — using your account, wellness/health, and label-scan data, on the basis of your explicit consent (Art. 9(2)(a)) for health data and performance of a contract for other data.
Show your orders and relevant recommendations if you shop or link accounts — using your account and order data, on the basis of performance of a contract and legitimate interests.
Secure the Services, prevent abuse and fraud, debug, and improve the app — using your account and device/technical data, on the basis of legitimate interests.
Communicate with you about your account and notify you of changes — using your account data, on the basis of legitimate interests and legal obligation.
Comply with law and respond to lawful requests — on the basis of legal obligation.
Marketing. We do not currently send marketing emails or push notifications from GRLY. If we introduce them, we will rely on your consent where required and always give you a way to opt out.
4. We Do Not Sell, Share for Advertising, or Track You
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising (as those terms are defined under California law). We do not use third-party advertising networks, do not serve targeted ads based on your health data, and do not track you across other companies' apps or websites. We do not use third-party analytics SDKs in the app, and we honor browser "Do Not Track"/Global Privacy Control signals where required by law.
5. Health Data & Your Explicit Consent
Because GRLY helps you track supplement intake, we process information about your health. The law treats this as a special category requiring a higher standard of protection, and we will not process your health data without your explicit consent.
How we obtain consent. During onboarding, before the health questions, you are shown a dedicated consent screen explaining what health data we process and why. To proceed you must actively tick an unchecked box. We record the fact, time, and policy version of your consent.
Withdrawing consent. You can withdraw at any time in the app (Settings → Health data processing) or by emailing connect@grlyapp.co. When you withdraw, we stop processing your health data: the tracking and reminder features that rely on it are turned off, and label analysis is disabled. Withdrawal does not affect processing carried out before you withdrew. You may also ask us to delete your health data (Section 14).
6. How We Share Information & Our Service Providers
We share information only as needed to run GRLY, with service providers ("processors") who act on our instructions under a data-processing agreement and may use your data only to provide services to us. They are US-based unless noted:
DigitalOcean — cloud hosting and database for the Services.
OpenAI — analyzes the supplement-label image/text you scan to identify the product.
Google; Apple — sign-in, if you choose "Continue with Google/Apple".
Apple Push Notification service — delivers the reminders you enable.
Resend — sends transactional emails (e.g., verification, password reset).
Shopify — runs the GRLY store and processes checkout and orders.
We may also disclose information where required by law or to protect rights and safety, and to a successor entity in the event of a merger, acquisition, or sale of assets (subject to this Policy). These third parties process information under their own privacy policies, which we do not control; we encourage you to review them.
7. Cookies & Similar Technologies
The GRLY mobile app does not use advertising or third-party analytics cookies. Our website (grlyapp.co) uses only the cookies necessary to make it work and remember your preferences. Our store runs on Shopify, which sets its own cookies needed for shopping, cart, and checkout; those are governed by Shopify's cookie and privacy policies. Where required by law, we will request your consent for any non-essential cookies. You can control cookies through your browser settings.
8. International Data Transfers
We operate from, and process data in, the United States. If you use GRLY from outside the US (including the UK, EU, or Switzerland), your information is transferred to and processed in the US. Where required, we rely on appropriate safeguards for these transfers — such as the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss equivalent — in our agreements with service providers. You can contact us for more information about these safeguards.
9. Automated Decision-Making & Profiling
We do not carry out automated decision-making that produces legal or similarly significant effects on you, and we do not build advertising or behavioral profiles about you. Any recommendations we show (for example, a supplement you already track being available in our store) are based on your own data and do not involve solely-automated decisions about you.
10. How We Protect Your Information
We use technical and organizational measures appropriate to the sensitivity of the data, including:
Encryption in transit — all communication between the app and our servers uses HTTPS/TLS.
Encryption at rest — our managed database and your device's storage are encrypted at rest; authentication tokens are held in the iOS Keychain, and account passwords and password-reset tokens are stored only in hashed form.
Access controls & least privilege — access to personal data is authenticated and limited to what is needed to operate the Services; each account can access only its own data.
Data minimization — we collect only what we need and embed no advertising or third-party analytics trackers.
No method of transmission or storage is completely secure, but we work to protect your information and continually improve our safeguards.
11. Data Breach Notification
We maintain procedures to detect, investigate, and respond to personal-data breaches. If a breach is likely to affect your rights, we will notify the relevant supervisory authority and, where required, affected users without undue delay and within the timeframes required by law (under the GDPR, within 72 hours of becoming aware of a notifiable breach).
12. Data Retention
We keep personal information only as long as needed for the purposes in this Policy, then delete or de-identify it. Indicative periods:
Account & wellness/supplement data — for the life of your account. On account deletion, removed from active systems immediately; residual copies in encrypted backups are overwritten on the normal backup cycle (typically within about a week).
Label-scan images & analysis — retained only transiently to perform the analysis and deleted shortly afterward (target: within 24 hours).
Consent records — for the life of your account plus a limited period afterward, as evidence that consent was given and/or withdrawn.
Support communications — for as long as needed to handle your request and a reasonable period afterward.
Records required by law — as long as required for legal, security, tax, or accounting purposes.
13. Children
GRLY is not directed to children under 13, or under 16 where a higher age of digital consent applies (including parts of the UK and EU). You must be at least 16 years old to use GRLY. We do not knowingly collect personal information from children below the applicable age. If we learn that we have, we will delete it. If you believe a child has provided us information, contact connect@grlyapp.co.
14. Your Privacy Rights
Subject to your location and applicable law, you have the rights below. To exercise any of them, email connect@grlyapp.co; we may need to verify your identity. We respond within the time required by law — generally within one month under the GDPR/UK GDPR (extendable by up to two further months for complex requests, with notice).
Access & portability — request a copy of the personal information we hold about you.
Correction — ask us to correct inaccurate or incomplete information.
Deletion / erasure — delete your account in the app (Menu/Settings → Delete Account), which removes your account and associated data from our active systems, or ask us to delete your information.
Withdraw consent — turn off health-data processing at any time (Section 5).
Restriction & objection — ask us to restrict or object to certain processing.
Manage device permissions — control notifications and camera access in the app or your device settings.
You will not be discriminated against for exercising these rights. If you are unhappy with our response, you may have the right to complain to your data protection authority (Section 16).
15. California Privacy Rights (CCPA/CPRA)
California residents may request to know, access, correct, or delete the personal information we hold, and may use an authorized agent. We do not sell or "share" personal information for cross-context behavioral advertising, so there is no opt-out needed in that respect. We collect the categories in Section 2, for the purposes in Section 3, and disclose to the service providers in Section 6. You have the right not to receive discriminatory treatment for exercising your rights. To make a request, email connect@grlyapp.co.
16. UK, EU & Swiss Users
This section applies if you are in the United Kingdom, European Economic Area, or Switzerland, and supplements the rest of this Policy. The controller is Ourskin, Inc.
Legal bases are in Section 3; we process your health data only on the basis of your explicit consent, which you can withdraw at any time.
Your rights include access, rectification, erasure, restriction, objection, data portability, and withdrawal of consent (Section 14).
Complaints — you may lodge a complaint with your supervisory authority: in the UK, the Information Commissioner's Office (ICO); in the EEA, your national data protection authority; in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).
International transfers — see Section 8.
Our Article 27 representatives:
EU representative: [TO BE APPOINTED]
UK representative: [TO BE APPOINTED]
Until appointed, please direct all requests to connect@grlyapp.co.
17. Users in Other Regions
Wherever you use GRLY, this Policy applies to you, and you may have additional rights under your local privacy law — for example, Australia's Privacy Act and the Australian Privacy Principles, Canada's PIPEDA, or New Zealand's Privacy Act. To exercise any such rights, contact connect@grlyapp.co.
18. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app or by other means. If a change materially affects how we process your health data, we will ask you to review and re-confirm your consent.
19. Contact Us
For any question or request about this Policy or your personal information, contact us at connect@grlyapp.co, or write to Ourskin, Inc., 1111B South Governors Ave, Dover, DE 19904, USA.


