SALE ENDS SEP 28: UP TO 50% OFF
50% OFF STOREWIDE + EASY RETURNS!
CARBON NEUTRAL SHIPPING

Version: 2.2
Last updated: 10 September 2026
Effective: 10 September 2026
Applies to: the CalmCarry mobile app and the CalmCarry API (together, the “Service”). It does not cover the separate The Glow Company retail website, which has its own privacy policy.


Who we are

The Service is operated by GLOWCO INTERNATIONAL LLC (“CalmCarry”, “we”, “us”, “our”), the entity that publishes CalmCarry on the App Store and operates the CalmCarry API. GLOWCO INTERNATIONAL LLC is the controller (and, for California purposes, the business) responsible for the personal information described in this policy. “The Glow Company” is a retail brand associated with our group; purchases made on that website are governed by that website’s own privacy policy, not this one.

How to reach us about privacy:

  • Email: Admin@glowco.co
  • Post: GLOWCO INTERNATIONAL LLC, 607 Gazetta Way, West Palm Beach, Florida 33413, United States of America

Data Protection Officer. We are not required to appoint a Data Protection Officer under Article 37 of the UK or EU GDPR, and we have not appointed one. Privacy questions can be sent to Admin@glowco.co.

UK and EU users. We are a controller based in the United States. Where the law requires us to designate a representative in the UK or the EU under Article 27 of the UK/EU GDPR, that representative’s name and contact details will be published in this section. In the meantime you can raise any UK or EEA data-protection matter with us directly at Admin@glowco.co, and you always keep the right to complain to your local supervisory authority (see your rights).


The short version

  • We ask for as little as we can, and we use it only to run the app. We never sell your personal information, and we never “share” it for cross-context advertising. We do use a few named service providers, only to operate the Service (see Who we share it with).
  • There are no advertising SDKs and no cross-app or cross-site tracking in this app.
  • We do not use your microphone, record your sleep, track your location, or score your nights.
  • A child profile is different: no information that identifies your child is ever sent to us. What a child profile needs is stored on the device only. See Children.
  • You can export everything we hold about you, or delete your account, from inside the app in a couple of taps. See Your rights.

This summary is for convenience only and does not replace the full policy below.


California notice at collection

For California residents, at or before collection: we collect the categories of identifiers, California customer-records information, commercial information, internet or other electronic network activity, and, in the form of your account log-in credentials, sensitive personal information. We use them only to provide and secure the Service as described below. We do not sell or share personal information, and we do not use sensitive personal information beyond what is needed to provide the Service. Retention is described under How long we keep it and the California section. This notice links to the full policy you are reading.


The information we collect, why, and our legal basis

We collect only the categories below, and only for the purposes shown. For users in the UK/EEA, the “Legal basis” column states the lawful basis under the UK GDPR and EU GDPR. Providing your email address (or, if you use Apple or Google sign-in, the identifier those services release) is necessary to create and operate your account; without it we cannot give you an account. Everything else below is optional, and the core app works without it.

Information you give us when you create an account

What Why Legal basis (UK/EU)
Email address To identify your account, sign you in, and send password resets and verification codes Contract (necessary to provide your account)
Your name (optional) To greet you in the app Legitimate interests (personalising the app); you can leave it blank
A one-way hash of your password So we can check your password without ever storing it Contract; legitimate interests (account security)
Whether your email is verified So your account stays recoverable Legitimate interests (account security)
Your app preferences (for example your chosen bedtime reminder time and saved favourites) So your settings follow you to a new phone Legitimate interests (syncing your settings across your devices)

If you sign in with Apple or Google, we receive the email address and name that provider releases to us. If you use Sign in with Apple’s Hide My Email, we only ever see the relay address. For Sign in with Apple we also store a token used for one purpose only: so that if you delete your account, we can tell Apple to revoke it.

If you subscribe

We store your subscription tier, status, plan, renewal date, and the store’s own reference for the purchase. Your card details never reach us. Payment is handled entirely by Apple or Google under their own privacy policies. Legal basis: contract.

If you register a CalmCarry device

We store the device serial number, an optional nickname you choose, the model, and warranty status; and, if you enter them on the warranty form, the purchase date and the retailer where you bought the device. If you make a warranty claim, we store the details of that claim. Legal basis: contract, and compliance with our legal obligations for warranty and consumer-protection records.

Information we collect automatically while you use the app

What Why Legal basis (UK/EU) How long
Which sessions you played and when (tied to your account) So your progress, recents and streaks work Legitimate interests (making your progress, recents and streaks work); you can object using the Settings control below Deleted after 400 days
Pseudonymous app-usage events, keyed to a random per-install identifier and never to your name, email or account To understand, in aggregate, which parts of the app help Legitimate interests (understanding aggregate usage); with an opt-out in Settings Deleted after 400 days
Saved sound mixes So you can reload a mix you built Contract Until you delete it or your account
A push token, if you turn on reminders To deliver the reminders you asked for Consent (you enable notifications) Until you turn reminders off or delete your account
Basic technical data needed to serve a request (for example your IP address at the moment of a request) To keep the Service secure and available and to prevent abuse and automated attacks Legitimate interests (security and abuse-prevention) Used only in the moment to serve and secure the request; not written to our database. Any IP addresses that appear do so transiently in our hosting provider’s operational logs, under that provider’s own retention

You can turn off both the account-linked session records and the pseudonymous usage events at any time: Settings, then “Usage & activity data”. Turning it off stops the sending immediately and discards anything still queued on your device. Where we rely on legitimate interests, you have the right to object; where we rely on consent, you can withdraw it at any time, without affecting processing already carried out.

Is play history “health” data? We do not treat which sessions you played as health data: we do not diagnose you, score your sleep, or infer any health condition from it. It exists only to power your own progress, recents and streaks, and you can switch it off.

What we do NOT collect

No microphone access and no audio recording. No sleep tracking, snore detection or sleep score. No location. No contacts, calendar or photos. No advertising identifier and no cross-app tracking. No health-app data. No biometric data: Face ID or Touch ID is used only to unlock the parent gate, and that check happens on your device through Apple, so we never receive your face or fingerprint. For California purposes, we do not collect protected-classification characteristics, biometric information, precise geolocation, sensory (audio or visual) data, professional or employment information, education information, or inferences drawn to create a profile.

No crash or diagnostic reports. Crash-reporting code is present in the app but ships switched off, with no destination configured, so no crash or error data leaves your phone in this release. If we ever enable it, we will update this policy first.


Children’s privacy (COPPA)

CalmCarry is bought and set up by adults, and accounts are intended for adults. Inside an adult account there is an optional, parent-gated Kids Mode intended for a child to use under a parent’s supervision. Because we collect no personal information from a child, the notice-and-consent obligations of the U.S. Children’s Online Privacy Protection Act (COPPA) are not triggered; we explain our practices here voluntarily so parents know exactly how it works.

No information that identifies a child is ever transmitted to us. When a parent creates a child profile, the only child-specific information involved is a first name the parent types, together with that profile’s settings, and the CalmCarry app keeps them on the device only. They are not sent to us or to any third party, so we do not receive, store, see, or produce them. While a child profile is active, the app sends no analytics events, no session records, no push tokens, and no crash reports, shows no advertising, and offers nothing social or interactive with other people.

Because no child-identifying information is collected or transmitted, no “collection” or “disclosure” of a child’s personal information, as defined by 16 CFR § 312.2, takes place, and none of our service providers ever receives child information.

Parental controls and rights. Kids Mode sits behind a parent gate that a child cannot pass. At any time a parent can review what a child profile contains (the on-device first name and settings), change it, remove it, or refuse to permit any further collection or use of the child’s information. Removing the child profile or deleting the app erases the on-device first name. Because we hold nothing about your child on our servers, there is nothing for us to send you, correct, or delete on request; if you have any question about your child’s information, email us at Admin@glowco.co and we will help.

If a child uses a standard account. CalmCarry accounts are for adults. If we learn that we have collected personal information from a child under 13 through a standard account, we will delete that information promptly. You can notify us at Admin@glowco.co.

If we ever change what Kids Mode does so that any child information would be collected or transmitted, we will not do it quietly: we will update this policy, show you the change in the app before it takes effect, and, where the law requires it, obtain verifiable parental consent before collecting anything new.


How we use your information

We use the information above only to: create and run your account; deliver the sessions, mixes, timers and reminders you ask for; process and maintain your subscription; register your device and handle warranty; keep the Service secure, prevent abuse, and debug problems; understand, in aggregate, which parts of the app help; comply with our legal obligations; and communicate with you about your account and about material changes to this policy. We do not use your information for advertising, and we do not make decisions that produce legal or similarly significant effects about you by solely automated means.


Household and caregivers

CalmCarry lets one subscription cover a household. If you invite another adult as a caregiver (or accept an invite) using a one-time code, the linked adults in your household can see the household’s profiles and registered devices and can share the subscription. The invite is a code, so we do not collect the other person’s email to set it up. Removing the link, from either side, stops that shared access.


Who we share it with

We do not sell your personal information, and we do not “share” it for cross-context behavioural advertising (as those terms are used under U.S. state privacy laws). We disclose personal information only in the limited ways below.

Service providers (processors) process data on our documented instructions, under contract, only to run the Service, and are each contractually required to protect your information to at least the standard described in this policy and to use it only to provide services to us:

Provider What it handles Where
Vercel Inc. Hosts and runs the CalmCarry API United States
Neon Inc. The database that stores the account information described above United States (AWS US East region)
Resend (Resend, Inc.) Sends transactional email only (password reset and verification codes) United States

Independent third parties. Apple and Google act as independent controllers, not our processors, when they authenticate your sign-in and process App Store or Google Play payments; their handling of that data is governed by their own privacy policies, which we do not control. These disclosures are limited to what is necessary for sign-in and payment and do not constitute a sale or share of personal information.

We may also disclose personal information: to comply with law, legal process, or a lawful government request; to enforce our terms or protect the rights, safety, and property of our users, the public, or us; and in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honour this policy or give you notice and choice as the law requires.

None of these providers ever receives a child’s personal information, because no child-identifying data is transmitted from the device at all.


International data transfers

We are based in the United States, and our API (Vercel) and database (Neon, AWS US East) are in the United States. If you use the Service from outside the United States, your information is transferred to and processed in the United States.

For users in the UK and the EEA, where we transfer personal information to the United States we rely on the European Commission’s Standard Contractual Clauses and, for the UK, the UK International Data Transfer Addendum, together with additional safeguards as appropriate. You can ask us for more information about these transfer mechanisms using the contact details above.


How long we keep it

  • Session records and pseudonymous usage events: 400 days, then deleted automatically by a daily job. We keep them that long so month-to-month and seasonal patterns remain meaningful, and no longer.
  • Account information (including saved mixes and any push token): kept while your account exists, and erased when you delete it or when you turn the relevant feature off.
  • Security and operational logs (which may include IP addresses): not stored in our own database; any such logs are held only transiently by our hosting provider for security and abuse-prevention.
  • Subscription records: the underlying purchase is recorded by Apple or Google, not by us, and kept under their policies; we keep only the minimal status described above, for as long as your account exists.
  • Warranty and device records: kept for as long as needed to honour the warranty and to meet our legal and accounting obligations.
  • A child’s first name: never sent to us, so never retained by us; removed from the device when the profile or the app is deleted.

Your rights

Wherever you live, you can use the following controls inside the app:

  • Access / get a copy of your data. Settings, then “Export my data” hands you everything tied to your account, ready to save or send on.
  • Delete your account and data. Settings, then “Delete account”. Deleting your account erases your account information from our systems. A limited set of records may be retained where the law allows or requires it, for example warranty and consumer-protection records and tax and accounting records, and your store purchase history remains with Apple or Google under their policies. Everything else is deleted or de-identified. Deleting your account does not cancel a subscription: cancel that in your Apple or Google account settings.
  • Correct your details by editing them in the app, or by emailing us.
  • Turn off usage measurement. Settings, then “Usage & activity data”.

You may also make any of these requests, or ask a question, by emailing Admin@glowco.co. You may use an authorized agent to submit a request on your behalf; we will ask for proof of the agent’s authorization and may verify your identity directly. We will verify your request against your account, respond within the time the applicable law requires (for California and several other states, within 45 days, extendable once by a further 45 days with notice to you), and will not discriminate against you for exercising your rights. If we ever need to deny a request, we will tell you why, and you may appeal by replying to our decision or emailing Admin@glowco.co.

UK and EEA (UK GDPR / EU GDPR)

In addition to the above, you have the right to: access; rectification; erasure; restriction of processing; data portability; and to object to processing based on our legitimate interests. Where we rely on consent, you may withdraw it at any time. Our legal bases are stated in the tables above. You also have the right to lodge a complaint with your supervisory authority, for example the Information Commissioner’s Office (ICO) in the UK, or your national data protection authority in the EEA. We would appreciate the chance to address your concern first. See also the note for UK and EU users under Who we are regarding our representative.

California (CCPA / CPRA)

If you are a California resident, you have the right to know, access, correct, and delete the personal information we hold about you, to obtain a portable copy, and to appeal a denial. You also have the right to opt out of the “sale” or “sharing” of personal information and to limit the use of sensitive personal information — but we do not sell or share personal information, and we use sensitive personal information only to provide and secure the Service (a purpose for which no “limit” opt-out is required under 11 CCR § 7027), so there is nothing to opt out of. We will not discriminate against you for exercising any right.

Categories of personal information we have collected in the last 12 months, and disclosed only to the service providers named above for the business purposes described:

  • Identifiers: email address, name, device serial number, and a random per-install identifier.
  • California customer-records information: your account details and warranty/device-registration records.
  • Commercial information: your subscription tier and status.
  • Internet or other electronic network activity: which sessions you played and pseudonymous usage events, if you leave usage measurement on.
  • Sensitive personal information: your account log-in credentials (email together with your password, which we store only as a one-way hash), collected and used solely to authenticate you and secure your account.

We collect these from you directly; from your device as you use the app; and from third parties you choose to use with the Service — namely Apple and Google, who release your email and name when you use Sign in with Apple or Google and provide subscription and purchase references from the App Store or Google Play. We have not sold or shared any category of personal information, and we do not knowingly collect or sell the personal information of consumers under 16. California’s “Shine the Light” law: we do not disclose personal information to third parties for their own direct marketing, so there is nothing to request under it.

Retention by category (California): identifiers, customer-records information, and commercial information are retained for the life of your account and deleted when you delete it; internet or other electronic network activity information (session records and usage events) is retained for 400 days; sensitive personal information (login credentials) is retained for the life of your account; device and warranty records are retained as long as needed to honour the warranty and meet our legal and accounting obligations.

Other U.S. states

If you reside in a U.S. state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana), you have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Because we do not sell your data, serve targeted advertising, or profile you, those opt-outs do not apply to us. To appeal a denied request, reply to our decision or email Admin@glowco.co; we will respond within the time your state’s law requires.

Other regions

Depending on where you live, you may have similar rights under laws such as the UAE Personal Data Protection Law (contactable authority: the UAE Data Office), the Australian Privacy Principles (the OAIC), and Canadian privacy law. Use the contact details above and we will honour the rights that apply to you.


Do Not Track and Global Privacy Control

The app contains no advertising or cross-site tracking, so there is nothing for a “Do Not Track” or Global Privacy Control (GPC) signal to stop. Because we never sell or share personal information, no opt-out signal is required to change how we treat your data.


Automated decision-making

We do not use your personal information to make decisions about you by solely automated means that produce legal or similarly significant effects.


Third-party services and links

Signing in with Apple or Google, and paying through the App Store or Google Play, are governed by those companies’ own privacy policies. Our marketing and support pages, and the purchase of a physical CalmCarry device, take place on the separate The Glow Company website, which has its own privacy policy. We are not responsible for the privacy practices of services we do not operate.


How we protect it

Traffic between the app and our servers is encrypted in transit. Passwords are stored only as one-way hashes. Sign-in tokens are held in your phone’s secure keychain. Changing your password immediately ends every other signed-in session. Administrative access to the database is restricted, and rate limiting protects sign-in and password reset against automated guessing. No service can promise perfect security, but we design so that the most sensitive thing in a family’s account, a child’s information, is never in our systems at all.


Changes to this policy

If we make a material change we will update the “Last updated” and “Effective” dates above and tell you in the app before the change takes effect. Your continued use of the Service after a change becomes effective means you accept the updated policy, except where we are required to obtain your consent.


Contact us

GLOWCO INTERNATIONAL LLC
Admin@glowco.co
607 Gazetta Way, West Palm Beach, Florida 33413, United States of America

Move Forward Every Day

At Glowco, since 2015, our mission has been clear improving lives by helping people unwind, rest deeply, and feel calmer in everyday life.

We’re committed to natural solutions that support balance and well-being.

After more than 10 years of innovation and the trust of thousands of satisfied customers, CalmCarry and our Natural Ingredients Gummies continue to help people relax, recharge, and feel their best naturally.

Join our mailing list to receive Glowco updates, exclusive offers, and early access to new products.

You can unsubscribe at any time.

img