Privacy & Data handling

Privacy Policy

Last updated: July 2026

Access Glow is an authentication service. We handle data only to the extent necessary to make authentication work. We do not sell data, do not use it for advertising, and do not share it with third parties except where strictly required to operate the service.

This policy applies to data collected through the Access Glow website (auralogin.com), the Access Glow dashboard (app.auralogin.com), the Access Glow mobile app, and the Access Glow WordPress plugin.

1. Who we are

Access Glow is developed and operated as an independent product. For any data-related enquiries, contact us at [email protected].

2. What data we collect

Account data

When you create an Access Glow account in the mobile app, we collect:

Site and device data

When you register a WordPress site and enrol a device, we store:

Authentication session data

When a login attempt begins, a short-lived session record is created on the server containing the session token, the site it belongs to, and its expiry time. This record is deleted when the session is resolved (approved, denied, or expired).

Transactional email data

We use Brevo to send transactional emails (welcome message, password reset codes). Your email address is transmitted to Brevo solely for this purpose. Brevo is bound by its own data processing agreement and GDPR compliance obligations.

What we do not collect

3. How we use your data

We do not use your data to train machine learning models, build profiles, or share with advertisers.

4. Data retention

5. Your rights

Depending on your jurisdiction (including under the GDPR for users in the European Union), you may have the right to:

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

You may also delete your account directly from the Access Glow mobile app under Settings → Delete Account.

6. Data transfers

Access Glow servers are hosted in the European Union. Transactional emails are processed by Brevo, which operates under GDPR-compliant data processing agreements. We do not transfer personal data to countries without adequate data protection frameworks.

7. Children's privacy

Access Glow is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected such data, contact us and we will delete it promptly.

8. Changes to this policy

If we make material changes to this policy, we will update the date at the top of this page. Continued use of the service after changes are posted constitutes acceptance of the updated policy.

9. Contact

Questions about this policy or how we handle your data:

[email protected]