GlowNest
Parent controlsSafetyHow safety worksCustomer loginGet started
Privacy policy

Your family's information deserves clear rules.

This notice explains what GlowNest collects, why we use it, how the visual safety systems work, who information may be shared with, and the rights available to parents and children.

Version: 2026-08-31 · Last updated: 31 August 2026

1. Who is responsible for your information?

GlowNest is the controller responsible for the personal information described in this policy when operating the GlowNest service.

Before public launch: the service operator must add its full legal/business address in GLOWNEST_LEGAL_ADDRESS.

Privacy contact: privacy@glownestchat.co.uk

2. Who uses GlowNest?

GlowNest is designed around a parent or responsible adult creating and managing a family account and child profiles. Children use child profiles inside that family-managed environment. Because the service is intended for children, we apply higher privacy and safety protections to child information and provide a shorter privacy notice written for children.

3. Information we may collect

  • Parent account information: name/display name, email address, password hash, account status and verification information.
  • Household information: household name, parent membership, parent roles and parent-security settings.
  • Child profile information: child name, avatar, age band, friend code, chat/call/discoverability settings and hidden/active status.
  • Communication information: chat messages, conversation membership, attachments, voice notes, message delivery/read status, friend requests, friendships and blocks.
  • Call information: call identifiers, participants, call state and technical signalling needed to establish audio/video calls.
  • Device and notification information: device identifiers, platform, push/VoIP notification tokens and active household/child mode.
  • Safety information: Safety Center incident metadata such as child, household, incident type, source, conversation or call identifier, confidence where supplied, timestamps, status and parent resolution notes.
  • Website security information: session identifiers, IP address, browser/user-agent information, audit events, rate-limit information, password-reset and email-verification tokens.

4. How photo and live-video safety analysis uses information

Child photos

Child photo uploads are checked before delivery. The server currently processes the image privately for automated nudity/sensitive-content classification before it can be delivered in a child conversation. Images identified as sensitive are blocked. The current server implementation discards the blocked image after classification and retains incident metadata rather than the blocked image itself.

On supported iOS devices, Apple's Sensitive Content Analysis can also check the prepared child photo on the device. The Apple classification result remains on the device.

Child video calls

GlowNest runs safety checks during child video calls. On iOS, sampled local and remote child video is analysed on-device and the Apple classification result is not sent to GlowNest. On Android, small sampled frames are sent securely to the GlowNest server scanner, processed transiently in memory and not written to disk. A safety detection can end the call and create a Safety Center incident.

Safety systems may produce false positives or false negatives. They are used to reduce risk and support parent involvement, not to make assumptions about a child's character or identity.

5. Why we use personal information and our lawful bases

PurposeTypical informationLawful basis
Provide and secure the parent account and web portalParent account, household, security and device dataPerformance of our contract with the parent/account holder; legitimate interests in account security
Provide child profiles, communication and family controlsChild profile, messages, friendships, call and settings dataLegitimate interests in providing the family-requested service while protecting the interests and rights of child users
Operate photo/video safety systems and Safety CenterVisual media processed for classification, incident metadata, device/call dataLegitimate interests in safeguarding children and preventing harmful use; legal obligation where specific online-safety or reporting law applies
Prevent abuse, fraud and unauthorised accessIP addresses, device data, audit logs, rate limitsLegitimate interests in security and protecting users
Meet legal/regulatory duties and respond to lawful requestsRelevant account, safety, content and audit dataLegal obligation
Send optional marketing or use non-essential tracking in futureOnly information covered by a separate choiceConsent where required. The current website does not use advertising or analytics cookies.

Where information includes special-category personal data, we only process it where a valid additional condition under data-protection law applies. GlowNest does not use the safety classifier to infer unrelated sensitive characteristics about a child.

6. Who we may share information with

We do not sell personal information to advertisers. We may share the minimum information necessary with service providers that help us operate GlowNest, such as:

  • hosting, infrastructure, database and backup providers;
  • Apple for iOS push/VoIP notification delivery and Apple platform services;
  • Google/Firebase for Android push notification delivery;
  • email delivery providers for account verification, password resets and service messages;
  • professional advisers, auditors or security specialists where necessary;
  • law-enforcement, regulators, safeguarding bodies or other authorities where we are legally required or permitted to do so.

Other child users receive only the information needed for the communication features they use, such as a child's display name/avatar, friend information and messages exchanged with them. Blocked sensitive photos are not delivered to the intended recipient.

7. International transfers

Some technology providers may process information outside the United Kingdom. Where UK data-protection law requires safeguards for an international transfer, we use an applicable lawful transfer mechanism, such as UK adequacy regulations or appropriate contractual safeguards.

8. How long we keep information

We keep personal information only for as long as reasonably necessary for the purpose for which it is used, taking account of account status, child safety, dispute handling, security, backup cycles and legal/regulatory requirements.

  • Account, household and child-profile data is generally kept while the relevant account/profile remains active and for a limited period afterwards where needed for security, disputes or legal duties.
  • Messages and delivered media are retained as required to provide conversation history unless deleted under product/account controls or a retention rule.
  • Safety incident metadata may be retained after resolution where necessary for safeguarding, audit, complaints or legal obligations.
  • Website rate-limit records are short-lived and are routinely removed after their security window expires.
  • The website login session cookie normally lasts only for the browser session.

Where law requires a specific retention period for a regulatory or law-enforcement report, that legal retention period overrides our normal deletion schedule.

9. Your rights

Depending on the circumstances, parents and children may have rights to access personal information, correct it, ask for deletion, restrict certain processing, object to processing based on legitimate interests, and receive certain information in a portable format. Where processing is based on consent, consent can be withdrawn.

Your right to object: where we rely on legitimate interests, you can object to that processing. We will consider the objection and whether we have compelling legitimate grounds to continue.

Children have data-protection rights in their own right. A parent can help a child exercise those rights, but the child's interests and maturity must also be considered.

To make a request, email privacy@glownestchat.co.uk. We may need to verify identity and authority before disclosing family information.

10. Complaints

Please contact us first so we can try to resolve a privacy concern. You can also complain to the UK Information Commissioner's Office (ICO), the UK data-protection regulator.

Safety or moderation complaints can be submitted through our safety and complaints form.

11. Security

GlowNest uses measures intended to protect family information, including HTTPS/TLS, server-side authorisation, security headers, restricted internal services, password hashing, server-verified parent PIN access, audit logging and access controls. No online service can guarantee absolute security.

12. Changes to this policy

We may update this policy when GlowNest changes or legal requirements change. Material changes will be brought to users' attention where appropriate. The version date at the top identifies the current notice.

GlowNest

Parent-controlled chat and calls for families.

© 2026 GlowNest. All rights reserved.

SafetySafety & parent controlsReport a safety concernPrivacy for children
LegalPrivacy policyCookie policyTerms of serviceComplaints