Data Collection Policy

Last updated: 4 August 2026

A field-by-field record of every category of data Growvo.AI collects, why we collect it, who it is shared with, and how long we keep it.

1. What this document is

Our Privacy Policy explains our commitments in narrative form. This page is the detailed companion to it: a field-by-field record of what we actually collect, why, who it goes to, and when it is deleted. It is written for anyone doing a vendor review, a data-protection assessment, or a platform app review.

If this page and the Privacy Policy ever appear to conflict, treat the Privacy Policy as authoritative and tell us so we can fix the discrepancy.

2. Our collection principles

  • Minimisation. We ask for the narrowest set of fields and the narrowest platform permissions that make a feature work.
  • Purpose limitation. Data collected to run the Service is not repurposed for advertising or model training.
  • No data brokers. We do not buy, rent, or enrich personal data from third-party data providers.
  • No sale, no sharing for ads. We do not sell personal data and do not share it for cross-context behavioural advertising.
  • Tenant isolation. Every record we store belongs to a workspace, and queries are scoped to that workspace.

3. Account and identity data

FieldWhy we need itRetention
NameTo address you and attribute activity inside a workspaceLife of the account
Email addressYour login identifier, plus transactional email — verification, password reset, billing, and security noticesLife of the account
Password hash (bcrypt)To authenticate you. We never store or can read your password itselfLife of the account
Profile picture URLShown in the interface. Taken from your identity provider if you used social sign-inLife of the account
Workspace membership and roleTo decide what you are permitted to see and doLife of the account
Two-factor secret, if you enable 2FATo verify your authentication codes. Encrypted at restUntil you disable 2FA

4. Data received from identity providers

Social sign-in is optional. When you use it, this is the entire set of fields we receive — we request nothing else, and we never ask for permission to read or post your content.

ProviderPermissions requestedFields receivedUsed for
Facebook Loginpublic_profile, emailApp-scoped user ID, name, email address, profile picture URLAccount creation and authentication only
Google Sign-Inopenid, profile, emailGoogle account ID, name, email address, profile picture URLAccount creation and authentication only

We do not request access to your friends, followers, posts, photos, pages, ad accounts, Gmail, Drive, or Contacts in order to sign you in. We do not post anything on your behalf as part of sign-in.

To remove this data, follow our data deletion instructions.

5. Data from channels you connect

Connecting a channel for publishing or analytics is a separate action from signing in, and each connection is per-workspace and revocable.

DataWhy we need itRetention
Access and refresh tokensTo perform the actions you asked for on that platform. Encrypted at rest with AES-256-GCMUntil you disconnect, then revoked and deleted
Account, page, or profile identifiersTo know which destination to publish toUntil you disconnect
Performance metrics we read backTo show you the analytics you asked forUntil you disconnect or delete the workspace

We request the narrowest publishing scopes each platform offers for the features you use, and we do not read your inbox, private messages, or contacts unless a feature you explicitly enable requires it.

6. Content you create

DataWhy we need itRetention
Brand profiles — identity, strategy, voiceTo condition AI generation so output is on-brandUntil you delete it, or the account closes
Prompts you submitTo generate what you asked for, and to show your historyUntil you delete it, or the account closes
Generated text and imagesTo populate your content libraryUntil you delete it, or the account closes
Scheduled posts and calendar entriesTo publish at the time you choseUntil you delete it, or the account closes
Comments and collaboration activityTo support review workflows inside a workspaceUntil you delete it, or the account closes
Uploaded mediaTo attach to the content you publishUntil you delete it, or the account closes

Prompts and brand context are sent to the AI provider you selected in order to produce output. They are not used to train any model — ours or a third party’s. With bring-your-own-key, they go to your own provider account under your agreement with that provider.

7. Billing data

DataWhy we need itRetention
Plan, subscription status, billing periodTo grant the right entitlements and enforce usage limitsLife of the account
Invoices and payment historyBilling records and dispute handlingAs required by tax and accounting law
Card detailsNot collected by us. Card data goes directly to Stripe; we receive only a token, the card brand, and the last four digitsHeld by Stripe

8. Usage, technical, and security data

DataWhy we need itRetention
Product analytics eventsFirst-party measurement of which features are used, so we can prioritise work. Not shared with advertisersUp to 365 days
API request logs — path, status, timestamp, IPDebugging, abuse detection, and rate limitingUp to 90 days
Generation and quota countersTo enforce your plan allowance accuratelyLife of the account
Session recordsTo let you see and revoke your active sessionsRevoked sessions kept up to 30 days
Audit log of sensitive actionsAccountability for billing, permission, and integration changes. Immutable, and credentials are scrubbed before writingRetained for security and accountability
Error diagnosticsTo find and fix crashesPer our error-monitoring provider’s retention

Our logger redacts secrets and tokens, and we log entity identifiers rather than payload contents.

9. Cookies and browser storage

We set six first-party cookies — four strictly necessary for sign-in security, two for your language and currency preference — plus a few interface-state keys in browser storage. We run no advertising or third-party tracking cookies. Each one is itemised in our Cookie Policy.

10. What we deliberately do not collect

  • Card numbers, CVVs, or bank credentials — these go straight to Stripe.
  • Your password in readable form.
  • Government identifiers, biometrics, health data, or precise geolocation.
  • Special-category data as defined by the GDPR. Please do not upload it.
  • Third-party advertising or tracking identifiers.
  • Data about children — the Service is for business use by adults.

11. Who we share data with

Only with the subprocessors that operate the platform on our behalf, with the channels you publish to at your instruction, with other members of your workspace according to their role, and where legally compelled. Every subprocessor, what it processes, and where it is located is listed on our Subprocessors page.

12. Getting a copy, or getting it deleted

Email privacy@growvo.ai from your account address to request a machine-readable export or a deletion. We acknowledge within 72 hours and complete within 30 days. Step-by-step deletion guidance, including for data received via Facebook Login, is on our Delete Your Data page.

This policy is published in English. Translations are provided for convenience; if they conflict, the English version prevails.