Privacy Policy
Last updated: 4 August 2026
This policy explains what personal data Growvo.AI collects, why we collect it, who we share it with, and the choices you have. It covers our website, the Growvo.AI application, and our API.
1. Who we are
Growvo.AI, a product of Lakhera Global Services, is the controller of the personal data described in this policy. Growvo.AI is an AI-powered SEO and social-growth platform that helps teams create on-brand content, plan and publish it to connected channels, and measure the results.
If you have any question about this policy or about how we handle your data, email us at privacy@growvo.ai.
2. Data we collect
We collect only what we need to run the service. We do not buy personal data from data brokers, and we do not build advertising profiles.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Your name, email address, password hash, profile picture, and workspace membership and role | You, or the identity provider you sign in with |
| Content data | Brand profiles, prompts you submit, generated text and images, drafts, comments, and scheduled posts | You, as you use the product |
| Integration data | Access tokens and account identifiers for the channels you connect, plus the metrics we read back from them | The platform you connect, with your authorisation |
| Billing data | Plan, subscription status, invoices, and billing contact. Card details go directly to Stripe and never reach our servers | You and Stripe |
| Usage and product analytics | First-party events about which features you use, generation counts, and quota consumption | Automatically, as you use the product |
| Technical and security logs | IP address, browser and device metadata, request paths, timestamps, and audit records of sensitive actions | Automatically, for security and debugging |
A field-by-field breakdown, including the purpose and retention of each item, is published separately in our Data Collection Policy.
4. How and why we use your data
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service — creating your account, generating content, publishing to your channels, showing analytics | Performance of a contract |
| Billing, invoicing, and enforcing plan limits | Performance of a contract |
| Security, abuse prevention, rate limiting, and audit logging | Legitimate interests |
| Support and service notifications | Performance of a contract |
| Improving reliability and the product, using aggregated first-party usage data | Legitimate interests |
| Product announcements and marketing email, where you have opted in | Consent — withdrawable at any time |
| Meeting legal, tax, and accounting obligations | Legal obligation |
5. AI processing and model training
To generate content, we send your prompt and the relevant brand context to the AI provider you have selected — for example OpenAI, Anthropic, Google, or Mistral — and return the result to you.
We do not use your content, prompts, brand data, or generated output to train any AI model— not our own, and not a third party's. Your content is processed to answer your request and for no other purpose.
If you bring your own AI provider keys (BYOK), prompts are sent to your own provider accounts under your agreement with that provider, and we act only as the conduit.
Generated output can be inaccurate. You are responsible for reviewing anything you publish.
7. International transfers
Lakhera Global Services operates from India, and several of our subprocessors are located in the United States and the European Union. Where we transfer personal data across borders, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with the technical measures described below.
8. How long we keep data
We keep personal data for as long as your account is active, and then only as long as we need it for the purposes in this policy or to meet a legal obligation. Our standard schedule is:
| Data | Retention |
|---|---|
| Account and workspace data | For the life of the account |
| Content, brands, and generated output | For the life of the account, or until you delete it |
| API request logs | Up to 90 days |
| Product analytics events | Up to 365 days |
| Revoked and expired sessions | Up to 30 days |
| Audit logs of sensitive actions | Retained for security and accountability |
| Billing and invoice records | As required by tax and accounting law |
When you delete your account we erase or irreversibly anonymise your personal data, except where we must keep a record — for example an invoice, or an audit entry showing that the deletion itself took place.
9. How we protect your data
Data is encrypted in transit with TLS. Integration credentials and AI provider keys are encrypted at rest with AES-256-GCM. Passwords are hashed with bcrypt. Access is controlled by role-based permissions, every workspace is isolated from every other, optional two-factor authentication is available, and sensitive actions are written to an immutable audit log.
Our controls are described in more detail on the Security & Trust page. To report a vulnerability, email security@growvo.ai.
11. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, receive a portable copy, object to or restrict processing, and withdraw consent. Indian users have equivalent rights under the Digital Personal Data Protection Act, 2023, including the right to nominate someone to exercise them.
To exercise any right, email privacy@growvo.ai from your account address. We respond within 30 days. Deletion is covered step by step on our Delete Your Data page.
We do not sell or share personal data, so there is nothing to opt out of under the CCPA, and we will never discriminate against you for exercising a privacy right. If you are in the EEA or UK you may also complain to your local supervisory authority.
12. Children
Growvo.AI is a business tool and is not directed at children. You must be at least 18, or the age of majority where you live, to use it. We do not knowingly collect data from children; if you believe a child has given us data, contact us and we will delete it.
13. Changes to this policy
If we make a material change we will update the date at the top of this page and, where the change significantly affects you, notify you by email or in the product before it takes effect.
14. Contact and grievances
For any privacy question, request, or complaint, contact our Grievance Officer at privacy@growvo.ai. For general help, email support@growvo.ai. We aim to acknowledge every privacy request within 72 hours and to resolve it within 30 days.
Related policies
This policy is published in English. Translations are provided for convenience; if they conflict, the English version prevails.
3. Signing in with Facebook or Google
You can create a Growvo.AI account with an email and password, or by signing in with Facebook or Google. Social sign-in is entirely optional — nothing in the product requires it.
Facebook Login
When you choose “Continue with Facebook”, we ask Facebook for two permissions only — public_profile and email. From those we receive:
We use this solely to create your account, sign you in, and show your name and picture in the interface. We do not request access to your friends, posts, pages, photos, or ad accounts. We never post to your Facebook timeline, and we do not read your Facebook content. We do not use Facebook data for advertising or share it with advertisers.
You can disconnect Growvo.AI at any time from your Facebook settings, under Settings & Privacy → Settings → Apps and Websites. To have the data we received deleted, follow our data deletion instructions.
Google Sign-In
When you choose “Continue with Google”, we receive your Google account ID, name, email address, and profile picture, and use them for the same purpose — account creation and authentication. We request no access to your Gmail, Drive, or Contacts for sign-in.
Channels you connect for publishing
Connecting a channel to publish or measure content is a separate, deliberate action you take inside the product, and it is not part of signing in. When you connect a channel we store an encrypted access token and the account or page identifier, and we use them only to perform the actions you ask for — publishing the posts you schedule and reading back the performance metrics we show you. You can disconnect any channel at any time from workspace settings, which revokes and deletes the stored token.