Privacy Policy
What GrowthOS collects, why, who helps us run it, and what you can ask us to do about it — written to be read rather than skimmed past.
Last updated 4 October 2026
1. Who we are
GrowthOS is an operating system for marketing and growth agencies. When an agency uses it, two different kinds of information are held here, and we are responsible for them in different ways:
- Information about the people who use GrowthOS — an agency’s own team. For this, we decide what is collected and why (in data-protection terms, we are the “controller”).
- Information an agency keeps about its own clients — contacts, proposals, contracts, tasks, files and notes. The agency decides what goes in and what it is for, and we hold and process it on the agency’s instructions (we are its “processor”). If you are an agency’s client, that agency is the first place to ask about your information.
2. What we collect
Your account
For example
Your name, work email address, role, profile photo, and your display preferences
Where it comes from
You, or the admin who added you
Your agency
For example
Its name, website, logo, services, postal address and sending domain
Where it comes from
You, and a one-off read of your public website when you sign up
Your clients
For example
Client names and websites; contact names, email addresses and phone numbers; deal values; proposals, contracts, call notes, tasks, files and knowledge-base entries
Where it comes from
Your team, the files you upload, the accounts you connect, and public websites you ask us to read
Emails sent through GrowthOS
For example
The messages, your clients’ replies, and whether each one was delivered, bounced or opened — with the mail app, device and approximate location our email provider reports for an open
Where it comes from
Our email provider
Sign-in and security
For example
Sign-in codes (stored only as a scrambled one-way hash), the IP address and browser that started each session, and a log of important actions
Where it comes from
Your browser, as you use the service
AI usage
For example
Which feature ran, on which model, how much text it used and what it cost
Where it comes from
Recorded every time a feature uses AI
Voice typing
For example
A recording of what you say, sent to be turned into text and then thrown away — the recording is never stored
Where it comes from
Only when you press Speak beside a text box
Bug reports
For example
A screenshot of the page, your note, your browser and screen size, and the page address
Where it comes from
Only when you choose to send one from the Feedback tab
| What | For example | Where it comes from |
|---|---|---|
| Your account | Your name, work email address, role, profile photo, and your display preferences | You, or the admin who added you |
| Your agency | Its name, website, logo, services, postal address and sending domain | You, and a one-off read of your public website when you sign up |
| Your clients | Client names and websites; contact names, email addresses and phone numbers; deal values; proposals, contracts, call notes, tasks, files and knowledge-base entries | Your team, the files you upload, the accounts you connect, and public websites you ask us to read |
| Emails sent through GrowthOS | The messages, your clients’ replies, and whether each one was delivered, bounced or opened — with the mail app, device and approximate location our email provider reports for an open | Our email provider |
| Sign-in and security | Sign-in codes (stored only as a scrambled one-way hash), the IP address and browser that started each session, and a log of important actions | Your browser, as you use the service |
| AI usage | Which feature ran, on which model, how much text it used and what it cost | Recorded every time a feature uses AI |
| Voice typing | A recording of what you say, sent to be turned into text and then thrown away — the recording is never stored | Only when you press Speak beside a text box |
| Bug reports | A screenshot of the page, your note, your browser and screen size, and the page address | Only when you choose to send one from the Feedback tab |
We do not collect payment card details — there is no billing in GrowthOS yet.
3. How we use it
- To run the service: showing your agency’s information to the people in your agency allowed to see it, writing documents, sending the emails you ask us to send, and running your delivery board.
- To keep it secure: sign-in codes, limits on repeated attempts, and the log of important actions.
- To keep you informed: sign-in codes, notifications, and replies from your clients. These are part of the service, not marketing.
- To tell account holders about new features in an occasional product update. Every issue has an unsubscribe link, and unsubscribing never affects the service.
- To help you when you ask us for support.
We do not sell personal information, we do not share it with anyone for advertising, and GrowthOS contains no advertising or analytics trackers.
If you are in the UK or the European Economic Area: we rely on our contract with your agency to provide the service, on our legitimate interest in keeping it secure and telling account holders what has changed, and on your consent where we ask for it — such as browser notifications.
4. AI features
Some features send text to an AI model to write or summarise something — a proposal, a follow-up email, a task draft. Each one sends only what that feature needs, together with the parts of a client’s knowledge base your agency has switched on.
If your agency has connected its own AI account (Anthropic, OpenAI, OpenRouter or Google Gemini), requests go to that provider under your agency’s own agreement with it. Otherwise they go to Anthropic under ours.
We never use your information to train AI models, and Anthropic does not train its models on what is sent through its commercial service. When your agency uses its own AI account, that provider’s terms decide what happens to what it receives — check them, particularly on a free plan.
5. Who else handles your information
We use these providers to run GrowthOS. Each receives only what it needs to do its job.
Railway
What it does for us
Runs the application and its background worker
What it receives
Everything, as it passes through our servers
Neon
What it does for us
Our database
What it receives
Everything stored in GrowthOS
Cloudflare (R2)
What it does for us
Stores files
What it receives
Files you upload, and documents GrowthOS creates
Postmark
What it does for us
Sends email and receives your clients’ replies
What it receives
Email addresses, message contents, and delivery, bounce and open reports
Anthropic
What it does for us
AI for the credit included with every workspace
What it receives
The text a feature sends to be written or summarised
OpenAI, OpenRouter, Google
What it does for us
AI — only if your agency connects its own account with one of them
What it receives
The text a feature sends, under your agency’s agreement with that provider
Groq (OpenAI as the back-up)
What it does for us
Turns speech into text for voice typing — only when you press Speak
What it receives
The recording of what you said, once. We never store it
Pipedream
What it does for us
Connects the accounts your agency links — Google Analytics, Google Search Console, HubSpot, Brevo and DataForSEO
What it receives
The connection to that account, and the data GrowthOS reads from it
OneSignal
What it does for us
Browser notifications — only once you turn them on in Settings → Profile
What it receives
Your GrowthOS user id, your browser’s subscription and details, and the title of each notification sent to you
Ybug
What it does for us
Bug reports — it loads only when you open the Feedback tab
What it receives
What you choose to send: a screenshot, your note, browser details and the page address
| Provider | What it does for us | What it receives |
|---|---|---|
| Railway | Runs the application and its background worker | Everything, as it passes through our servers |
| Neon | Our database | Everything stored in GrowthOS |
| Cloudflare (R2) | Stores files | Files you upload, and documents GrowthOS creates |
| Postmark | Sends email and receives your clients’ replies | Email addresses, message contents, and delivery, bounce and open reports |
| Anthropic | AI for the credit included with every workspace | The text a feature sends to be written or summarised |
| OpenAI, OpenRouter, Google | AI — only if your agency connects its own account with one of them | The text a feature sends, under your agency’s agreement with that provider |
| Groq (OpenAI as the back-up) | Turns speech into text for voice typing — only when you press Speak | The recording of what you said, once. We never store it |
| Pipedream | Connects the accounts your agency links — Google Analytics, Google Search Console, HubSpot, Brevo and DataForSEO | The connection to that account, and the data GrowthOS reads from it |
| OneSignal | Browser notifications — only once you turn them on in Settings → Profile | Your GrowthOS user id, your browser’s subscription and details, and the title of each notification sent to you |
| Ybug | Bug reports — it loads only when you open the Feedback tab | What you choose to send: a screenshot, your note, browser details and the page address |
Some of these providers are based in, or process information in, the United States. Where the law requires a safeguard for that transfer, we rely on the provider’s standard data-protection terms.
6. Emails sent for agencies
Proposals, follow-ups and contracts are sent from the agency’s own email address, on its instructions, to its own clients. Every sales email carries the agency’s postal address and a link to stop further follow-ups, and a reply from the client stops them automatically.
So an agency can tell whether its email arrived, our email provider reports when a message is delivered, bounces or is opened. For an open it also reports the mail app, the kind of device and an approximate location (city and country), which we keep with the message. An agency can switch open tracking off for all its emails, and then no tracking image is added at all. An “open” is only an estimate — some mail apps load pictures automatically and others block them. The same reports are kept for our own product updates.
8. How long we keep it
- Your account and your agency’s information: for as long as your agency uses GrowthOS. When an agency asks us to delete its workspace, every record belonging to it is deleted at once, together with its files. That cannot be undone.
- Sign-in codes expire after 10 minutes, and a signed-in session after 30 days.
- An unsubscribe, or a client’s request to stop follow-ups, is kept for as long as we hold the address it applies to — that record is how we keep honouring it.
- Backups held by our database provider expire on that provider’s own schedule.
9. Your rights
You can ask us for a copy of your information, to correct it, to delete it, to send it to you in a portable form, or to stop using it for a purpose you object to. If you are in California, you also have the right to know what we collect and not to be treated differently for using these rights — and we do not sell or share personal information as California defines those words.
Most of your own details can be changed in Settings. For anything else, use the Feedback tab on the right-hand edge of any GrowthOS page. We answer within one month.
If you are an agency’s client, contact the agency first — it decides what is held about you, and we will help it answer.
If you are in the UK or the EEA and are not happy with our answer, you can complain to your data-protection authority — in the UK, the Information Commissioner’s Office.
10. How we keep it safe
Every agency’s information is kept apart from every other agency’s. Connections are encrypted. There are no passwords to steal: sign-in codes and session tokens are stored only as one-way hashes, and AI account keys your agency connects are encrypted and are never shown again in full.
11. Children
GrowthOS is a tool for businesses. It is not meant for anyone under 18, an account can only be opened with a work email address, and we do not knowingly collect information about children. If you believe a child’s information has been put into GrowthOS, use the Feedback tab on the right-hand edge of any GrowthOS page and we will delete it.
12. Changes to this policy
If we change this policy in a way that matters, we will tell account holders by email or in the app before the change takes effect. The date at the top of this page always shows the current version.
13. Contact
To ask about anything on this page, use the Feedback tab on the right-hand edge of any GrowthOS page.