Privacy Policy
Last updated: January 2026
Gleamy helps event hosts, planners, photographers, and teams collect guest photos and videos in one event photo gallery, keep memories organized, and help guests find the photos they appear in with AI Face Find. We are committed to protecting your privacy and handling personal data transparently, securely, and in accordance with applicable data protection laws, including the GDPR in the EU/EEA and KVKK in Turkey.


1. Data controller
In this Privacy Policy, "Gleamy", "we", "us", and "our" refer to the data controller responsible for processing your personal data.
- Brand
- Gleamy
- Contact
- hello@gleamy.ai
For detailed legal identity, address, tax, and contact information about the service provider, please refer to our Terms & Conditions.
2. About this policy
This Privacy Policy explains how we collect, use, share, store, and protect personal information when you visit gleamy.ai" target="_blank" rel="noopener noreferrer" class="text-secondary dark:text-accent">https://gleamy.ai (the "Site") or use the Gleamy platform, including when you register, create an event, upload or view event content, use AI Face Find, leave guestbook messages, contact us, or purchase an event plan. This Policy should be read together with our Terms & Conditions, Refund Policy, Distance Selling Contract, and any consent or notice shown inside the Service.
3. Information we collect
When you visit the Site or use the Service, we may collect information you provide directly and information collected automatically from your device and usage. Automatically collected information may include browser type, IP address, time zone, cookie identifiers, pages viewed, actions taken, and technical performance data. We refer to this as "Device Information."
- Account and contact information – Information such as your name, email address, account details, support messages, and communication preferences.
- Event information – Information needed to create and manage event photo galleries, such as event name, date, cover image, access settings, gallery links, QR code usage, and plan-related settings.
- Event content – Photos, videos, guestbook messages, and related metadata uploaded or submitted by event hosts, guests, photographers, or other authorized users.
- Face recognition and selfie data – Where AI Face Find or Private gallery features are used, selfies, photos, videos, and face-matching data derived from them may be processed to help guests find the photos they appear in or to personalize gallery visibility. Where required by applicable law, this processing may require explicit consent or another valid legal basis.
- Cookies and similar technologies – Small data files and similar technologies stored on your device to help the Site work properly, remember preferences, understand usage, and improve performance. You can manage cookies in your browser settings.
- Log files and analytics data – Records of site and platform activity that may include IP address, browser type, referring/exit pages, timestamps, feature usage, and performance information.
When you purchase or attempt to purchase an event plan through the Site, we collect information needed to process the transaction and provide access, such as your name, email address, billing details, selected plan, payment status, and payment-related information handled securely by payment providers.
4. How we use information
We use account, order, and event information to:
- Process purchases and payments, and issue invoices or transaction records where applicable
- Create, authenticate, and manage your Gleamy account
- Create and manage event photo galleries, QR codes, gallery links, access settings, and plan features
- Provide core features such as guest uploads, gallery browsing, sharing, downloads, digital guestbook, AI Face Find, and Private gallery access
- Communicate with you about your account, event galleries, purchases, support requests, security alerts, and important updates
- Detect, prevent, and address fraud, abuse, unauthorized access, and security issues
- Comply with legal, tax, accounting, consumer protection, and data protection obligations
We use Device Information to:
- Operate, improve, and optimize the Site and platform experience
- Understand feature usage and performance to improve reliability
- Help protect Gleamy and its users against suspicious activity
- Measure the effectiveness of product improvements and user experience changes
5. How we share information
We share personal information only when needed to operate Gleamy securely, provide the Service, comply with legal obligations, or protect users. This may include sharing data with:
- Payment processors that securely handle transactions and payment verification.
- Cloud, storage, and infrastructure providers that host the platform and store event content securely.
- Analytics, logging, and monitoring providers that help us understand performance, detect errors, and improve the Service.
- Communication and support providers that help us send important emails, respond to support requests, and provide service updates.
- Legal, regulatory, tax, accounting, or security advisors where necessary to comply with legal obligations or protect our rights and users.
6. Your rights
Depending on your location, you may have rights regarding your personal information, such as the right to access, correct, delete, restrict processing, request portability, object to certain processing, or withdraw consent where processing is based on consent. To exercise these rights, contact us at hello@gleamy.ai or use the contact form in the Contact section on the gleamy.ai homepage.
- Access, correction, or update of your personal information
- Deletion requests, subject to legal, contractual, security, and technical requirements
- Objection to or restriction of certain types of processing
- Withdrawal of consent where processing is based on consent, including where applicable for AI Face Find or face-matching features
- Data portability where applicable
- Complaint to a competent data protection authority where applicable
7. Legal basis for processing
We process personal data based on one or more of the following legal grounds: (a) performance of a contract — to provide the Service you have purchased or requested; (b) legitimate interests — to operate, improve, secure, and prevent misuse of the platform; (c) legal obligations — to comply with applicable laws, tax, accounting, consumer protection, and regulatory requirements; (d) consent or explicit consent — where required for specific activities, such as certain cookies, marketing communications, or face recognition / AI Face Find features.
8. International data transfers
We may process or store data in countries outside your jurisdiction, including countries that may have different data protection standards. When we transfer personal data internationally, we use appropriate safeguards required by applicable law, such as standard contractual clauses, equivalent contractual protections, or other lawful transfer mechanisms.
9. Security measures
We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, loss, or destruction. These may include encryption in transit, secure cloud infrastructure, access controls, authentication safeguards, monitoring, logging, and internal procedures. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
10. Data retention
We retain account, transaction, support, and legal records for as long as needed to provide the Service, comply with legal obligations, resolve disputes, prevent abuse, and enforce our agreements. Event media such as photos and videos may be retained according to the selected event plan, gallery access period, storage settings, and deletion requests where applicable. Some data may remain in backups or logs for a limited period before deletion in line with our technical and legal requirements.
11. Event content, face recognition, and biometric data
Event content may include personal data within photos, videos, and guest messages. Features such as AI Face Find and Private gallery access may involve face matching to help guests find photos they appear in or to limit visibility to content they are allowed to access. Depending on the jurisdiction and how the feature is used, face-matching data may be considered biometric data or special category data. Where required by applicable law, we and/or the Event Host must rely on a valid legal basis, provide appropriate notice, and obtain explicit consent before enabling or using these features. Face recognition data is not used for advertising, public surveillance, or cross-event tracking, and is processed only for the event-specific features described in the Service.
12. Event Host and guest responsibilities
Event Hosts decide how their event gallery is used, who is invited, which access setting is selected, and whether features such as AI Face Find or Private gallery access are enabled. Event Hosts are responsible for informing guests, photographers, and other participants about the use of Gleamy at the event and for obtaining any notices, permissions, or consents required by applicable law. Guests should only upload content they have the right to share and should respect the privacy and rights of other people appearing in event content.
13. Minors
Our services are not intended for individuals under 18 to create an account or purchase event plans. Event content may include minors; in such cases, the Event Host is responsible for ensuring appropriate notices, permissions, and compliance with local laws before uploading, sharing, or enabling features that process such content.
14. Cookies and Do Not Track
Some browsers offer a "Do Not Track" signal. We do not currently respond to DNT signals with a uniform change in behavior. You can manage cookies and similar technologies through your browser settings. Where required by law, we may ask for your consent before using non-essential cookies or similar technologies.
15. Complaints
We encourage you to contact us first at hello@gleamy.ai or via the contact form on the gleamy.ai homepage to try to resolve any concerns regarding your data. If you believe your data protection rights have been violated and we have not adequately addressed your concern, you may have the right to lodge a complaint with a competent supervisory authority. In Turkey, you may contact the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu). In the EU/EEA, you may contact your local data protection authority.
16. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in the Service, legal requirements, or business practices. When we make material changes, we will:
- Update the 'Last updated' date at the top of this page
- Notify you via email or through the Service at least 30 days before changes take effect for material changes
- Provide a summary of key changes where practical
Your continued use of the Service after the effective date constitutes acceptance of the updated policy. If you do not agree to the changes, you should stop using the Service before the changes take effect.
17. GDPR and EU/EEA users
The General Data Protection Regulation (GDPR) is an EU privacy law that strengthens the protection of personal data. It has applied since May 25, 2018, and applies to controllers and processors that handle the data of people in the EU/EEA in certain circumstances. We aim to follow GDPR principles by processing personal data lawfully, fairly, transparently, securely, and only for appropriate purposes.
Your rights under GDPR
If you are in the EU/EEA, you may have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete personal data.
- Right to erasure: Request deletion of your personal data in certain circumstances (the "right to be forgotten").
- Right to restrict processing: Request that we limit how we use your data in specific situations.
- Right to object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to data portability: Request your data in a structured, commonly used, machine-readable format.
- Right to withdraw consent: Where processing is based on consent or explicit consent, withdraw it at any time without affecting processing that occurred before withdrawal.
We aim to respond to data rights requests within 30 days, unless a different period applies under applicable law. To exercise any of these rights, contact us at hello@gleamy.ai or use the contact form in the Contact section on the gleamy.ai homepage.
18. Turkey — KVKK
In Turkey, personal data protection is governed by Law No. 6698 on the Protection of Personal Data (KVKK). The identity of the data controller is set out in Section 1 of this Policy. You may submit requests such as access, correction, deletion, objection, restriction, and other rights available under KVKK to us at hello@gleamy.ai or via the contact form on the gleamy.ai homepage. Where event content or AI Face Find involves biometric data, relevant notices and explicit consent processes should be handled separately from general privacy notices where required by KVKK and applicable guidance.
19. Contact information
If you have questions about this Privacy Policy, the Service, or your rights, please contact us:
- Brand: Gleamy
- Email: hello@gleamy.ai
- For detailed legal identity, address, tax, and contact information about the service provider, please refer to our Terms & Conditions.
We aim to respond to inquiries within 5 business days.