← Back to home
Trust & security

How we handle your data.

This page is maintained by the Growthme team to answer common security and privacy questions about the product. It reflects controls that are currently in place; it is not an independent certification or audit.

Seller & data controller

Growthme is operated by Katheryn Samuelson ("we", "us"), the seller of the product and the data controller for personal data processed through Growthme. You can contact us at hello@growthme.ai.

Access & authentication

Accounts are protected with email and password sign-in, with optional Google sign-in. Sessions are managed by our authentication provider and stored in your browser.

Each user can only access their own workspace data; row-level authorization is enforced server-side on every read and write.

Platform & hosting

Growthme runs on managed cloud infrastructure that provides hosting, a managed Postgres database, file storage, and serverless functions. Data is encrypted in transit (TLS) and at rest by the platform provider.

The capabilities described here are factual statements about how the product operates — this page is not an independent certification or audit.

Data we collect & why

We collect: (a) account data (name, email, login credentials); (b) product inputs (company profile, goals, audience, website, prompts); (c) generated outputs we produce on your behalf; (d) usage and telemetry (device, browser, IP address, in-app events); and (e) support communications you send us.

We use this data to provide and secure the service, prevent fraud and abuse, improve the product, and respond to support requests. We do not sell your data.

Legal bases (where GDPR/UK GDPR applies): performance of our contract with you (providing the product you signed up for); our legitimate interests (security, fraud prevention, product improvement); your consent where required (e.g. optional analytics cookies); and compliance with legal obligations (tax, accounting).

Email & communications

Transactional and account emails (sign-in confirmations, password resets, product notifications) are sent from our verified email domain. We do not send marketing email from this product.

Every product email contains an unsubscribe link, and unsubscribed and bounced addresses are suppressed automatically.

Cookies & analytics

We use first-party cookies and local storage to keep you signed in and to remember in-app preferences. We may use privacy-friendly product analytics to understand aggregate usage; we do not run third-party advertising trackers inside the product.

Who we share data with

We share personal data only with the following categories of recipients:

  • Paddle.com Market Ltd — our Merchant of Record for all sales. Paddle processes payments, manages subscriptions, handles tax compliance, and issues invoices. See Paddle's privacy policy.
  • Infrastructure and service providers — hosting, managed database, email delivery, and AI model providers acting as our processors under contract, used only to deliver the features you request.
  • Professional advisers — legal and accounting, when necessary.
  • Authorities — where required to comply with applicable law or valid legal process.
Retention

We retain personal data only as long as needed for the purposes described above:

  • Account data: for the life of your account, then deleted within 90 days of account closure.
  • Product inputs and outputs: until you delete them or close your account; backups purge within 30 days.
  • Billing records: retained by Paddle and by us for up to 7 years to meet tax and accounting obligations.
  • Support communications: up to 2 years after the last interaction.
  • Server and security logs: up to 12 months.
Your rights

Subject to applicable law (including GDPR/UK GDPR and the CCPA), you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data ("right to be forgotten");
  • Restrict or object to certain processing;
  • Portability — receive your data in a machine-readable format;
  • Withdraw consent at any time where processing is based on consent;
  • Lodge a complaint with your local data protection supervisory authority.

To exercise any of these rights, or to request account deletion or a copy of your data, email hello@growthme.ai. We aim to respond within 30 days.

Security contact

Found a security issue? Please report it privately to security@growthme.ai. We'll acknowledge your report and keep you updated on remediation.

Last updated August 2026. Growthme is the responsible party for the content on this page.