Data Collection Policy
Last updated: 4 August 2026
A field-by-field record of every category of data Growvo.AI collects, why we collect it, who it is shared with, and how long we keep it.
1. What this document is
Our Privacy Policy explains our commitments in narrative form. This page is the detailed companion to it: a field-by-field record of what we actually collect, why, who it goes to, and when it is deleted. It is written for anyone doing a vendor review, a data-protection assessment, or a platform app review.
If this page and the Privacy Policy ever appear to conflict, treat the Privacy Policy as authoritative and tell us so we can fix the discrepancy.
2. Our collection principles
- Minimisation. We ask for the narrowest set of fields and the narrowest platform permissions that make a feature work.
- Purpose limitation. Data collected to run the Service is not repurposed for advertising or model training.
- No data brokers. We do not buy, rent, or enrich personal data from third-party data providers.
- No sale, no sharing for ads. We do not sell personal data and do not share it for cross-context behavioural advertising.
- Tenant isolation. Every record we store belongs to a workspace, and queries are scoped to that workspace.
3. Account and identity data
| Field | Why we need it | Retention |
|---|---|---|
| Name | To address you and attribute activity inside a workspace | Life of the account |
| Email address | Your login identifier, plus transactional email — verification, password reset, billing, and security notices | Life of the account |
| Password hash (bcrypt) | To authenticate you. We never store or can read your password itself | Life of the account |
| Profile picture URL | Shown in the interface. Taken from your identity provider if you used social sign-in | Life of the account |
| Workspace membership and role | To decide what you are permitted to see and do | Life of the account |
| Two-factor secret, if you enable 2FA | To verify your authentication codes. Encrypted at rest | Until you disable 2FA |
5. Data from channels you connect
Connecting a channel for publishing or analytics is a separate action from signing in, and each connection is per-workspace and revocable.
| Data | Why we need it | Retention |
|---|---|---|
| Access and refresh tokens | To perform the actions you asked for on that platform. Encrypted at rest with AES-256-GCM | Until you disconnect, then revoked and deleted |
| Account, page, or profile identifiers | To know which destination to publish to | Until you disconnect |
| Performance metrics we read back | To show you the analytics you asked for | Until you disconnect or delete the workspace |
We request the narrowest publishing scopes each platform offers for the features you use, and we do not read your inbox, private messages, or contacts unless a feature you explicitly enable requires it.
6. Content you create
| Data | Why we need it | Retention |
|---|---|---|
| Brand profiles — identity, strategy, voice | To condition AI generation so output is on-brand | Until you delete it, or the account closes |
| Prompts you submit | To generate what you asked for, and to show your history | Until you delete it, or the account closes |
| Generated text and images | To populate your content library | Until you delete it, or the account closes |
| Scheduled posts and calendar entries | To publish at the time you chose | Until you delete it, or the account closes |
| Comments and collaboration activity | To support review workflows inside a workspace | Until you delete it, or the account closes |
| Uploaded media | To attach to the content you publish | Until you delete it, or the account closes |
Prompts and brand context are sent to the AI provider you selected in order to produce output. They are not used to train any model — ours or a third party’s. With bring-your-own-key, they go to your own provider account under your agreement with that provider.
7. Billing data
| Data | Why we need it | Retention |
|---|---|---|
| Plan, subscription status, billing period | To grant the right entitlements and enforce usage limits | Life of the account |
| Invoices and payment history | Billing records and dispute handling | As required by tax and accounting law |
| Card details | Not collected by us. Card data goes directly to Stripe; we receive only a token, the card brand, and the last four digits | Held by Stripe |
8. Usage, technical, and security data
| Data | Why we need it | Retention |
|---|---|---|
| Product analytics events | First-party measurement of which features are used, so we can prioritise work. Not shared with advertisers | Up to 365 days |
| API request logs — path, status, timestamp, IP | Debugging, abuse detection, and rate limiting | Up to 90 days |
| Generation and quota counters | To enforce your plan allowance accurately | Life of the account |
| Session records | To let you see and revoke your active sessions | Revoked sessions kept up to 30 days |
| Audit log of sensitive actions | Accountability for billing, permission, and integration changes. Immutable, and credentials are scrubbed before writing | Retained for security and accountability |
| Error diagnostics | To find and fix crashes | Per our error-monitoring provider’s retention |
Our logger redacts secrets and tokens, and we log entity identifiers rather than payload contents.
10. What we deliberately do not collect
- Card numbers, CVVs, or bank credentials — these go straight to Stripe.
- Your password in readable form.
- Government identifiers, biometrics, health data, or precise geolocation.
- Special-category data as defined by the GDPR. Please do not upload it.
- Third-party advertising or tracking identifiers.
- Data about children — the Service is for business use by adults.
12. Getting a copy, or getting it deleted
Email privacy@growvo.ai from your account address to request a machine-readable export or a deletion. We acknowledge within 72 hours and complete within 30 days. Step-by-step deletion guidance, including for data received via Facebook Login, is on our Delete Your Data page.
Related policies
This policy is published in English. Translations are provided for convenience; if they conflict, the English version prevails.
4. Data received from identity providers
Social sign-in is optional. When you use it, this is the entire set of fields we receive — we request nothing else, and we never ask for permission to read or post your content.
We do not request access to your friends, followers, posts, photos, pages, ad accounts, Gmail, Drive, or Contacts in order to sign you in. We do not post anything on your behalf as part of sign-in.
To remove this data, follow our data deletion instructions.