Access Glow is an authentication service. We handle data only to the extent necessary to make authentication work. We do not sell data, do not use it for advertising, and do not share it with third parties except where strictly required to operate the service.
This policy applies to data collected through the Access Glow website (auralogin.com), the Access Glow dashboard (app.auralogin.com), the Access Glow mobile app, and the Access Glow WordPress plugin.
1. Who we are
Access Glow is developed and operated as an independent product. For any data-related enquiries, contact us at [email protected].
2. What data we collect
Account data
When you create an Access Glow account in the mobile app, we collect:
- Name — used to personalise the app and transactional emails.
- Email address — used as your account identifier and to send essential transactional messages (account creation confirmation, password reset codes).
- Password — stored as a one-way hash using bcrypt. We cannot recover your password and do not store it in plaintext.
Site and device data
When you register a WordPress site and enrol a device, we store:
- Site name and URL — to identify the site within your account.
- Site token and site secret — cryptographic identifiers used to authenticate API requests from the WordPress plugin. The secret is stored hashed.
- Device token — a unique, randomly generated token assigned to your enrolled device for each site. It is stored on your device and matched server-side during login. It is not a password and cannot be used to derive one.
Authentication session data
When a login attempt begins, a short-lived session record is created on the server containing the session token, the site it belongs to, and its expiry time. This record is deleted when the session is resolved (approved, denied, or expired).
Transactional email data
We use Brevo to send transactional emails (welcome message, password reset codes). Your email address is transmitted to Brevo solely for this purpose. Brevo is bound by its own data processing agreement and GDPR compliance obligations.
What we do not collect
- We do not collect biometric data. Biometric authentication (fingerprint, face) is handled entirely by your device's operating system and never leaves your phone.
- We do not use tracking cookies, analytics scripts, or advertising pixels on this website or in the app.
- We do not collect usage analytics, crash reports sent to third parties, or behavioural data.
- We do not collect any data from your WordPress site's content, users, or database beyond what is described above.
3. How we use your data
- To provide the authentication service. This is the sole primary purpose. Your account data, device tokens, and site credentials exist to make passwordless login work.
- To send essential transactional emails. Account confirmation and password reset. We do not send marketing emails.
- To operate and secure the service. Server-side logging (errors, anomalies) is used to maintain reliability. Logs do not contain personal data beyond IP addresses, which are not linked to accounts.
We do not use your data to train machine learning models, build profiles, or share with advertisers.
4. Data retention
- Account data is retained for as long as your account exists. Deleting your account removes all associated account data, site records, and device tokens from our servers.
- Login session data is deleted automatically when the session expires or is resolved — typically within seconds to minutes.
- Transactional email logs may be retained by Brevo in accordance with their own data retention policy.
- Server error logs are retained for up to 30 days and then discarded.
5. Your rights
Depending on your jurisdiction (including under the GDPR for users in the European Union), you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and all associated data.
- Restrict or object to processing in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
You may also delete your account directly from the Access Glow mobile app under Settings → Delete Account.
6. Data transfers
Access Glow servers are hosted in the European Union. Transactional emails are processed by Brevo, which operates under GDPR-compliant data processing agreements. We do not transfer personal data to countries without adequate data protection frameworks.
7. Children's privacy
Access Glow is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected such data, contact us and we will delete it promptly.
8. Changes to this policy
If we make material changes to this policy, we will update the date at the top of this page. Continued use of the service after changes are posted constitutes acceptance of the updated policy.
9. Contact
Questions about this policy or how we handle your data:
[email protected]