GrowthOS

Privacy Policy

What GrowthOS collects, why, who helps us run it, and what you can ask us to do about it — written to be read rather than skimmed past.

Last updated 4 October 2026

1. Who we are

GrowthOS is an operating system for marketing and growth agencies. When an agency uses it, two different kinds of information are held here, and we are responsible for them in different ways:

  • Information about the people who use GrowthOS — an agency’s own team. For this, we decide what is collected and why (in data-protection terms, we are the “controller”).
  • Information an agency keeps about its own clients — contacts, proposals, contracts, tasks, files and notes. The agency decides what goes in and what it is for, and we hold and process it on the agency’s instructions (we are its “processor”). If you are an agency’s client, that agency is the first place to ask about your information.

2. What we collect

Your account

For example

Your name, work email address, role, profile photo, and your display preferences

Where it comes from

You, or the admin who added you

Your agency

For example

Its name, website, logo, services, postal address and sending domain

Where it comes from

You, and a one-off read of your public website when you sign up

Your clients

For example

Client names and websites; contact names, email addresses and phone numbers; deal values; proposals, contracts, call notes, tasks, files and knowledge-base entries

Where it comes from

Your team, the files you upload, the accounts you connect, and public websites you ask us to read

Emails sent through GrowthOS

For example

The messages, your clients’ replies, and whether each one was delivered, bounced or opened — with the mail app, device and approximate location our email provider reports for an open

Where it comes from

Our email provider

Sign-in and security

For example

Sign-in codes (stored only as a scrambled one-way hash), the IP address and browser that started each session, and a log of important actions

Where it comes from

Your browser, as you use the service

AI usage

For example

Which feature ran, on which model, how much text it used and what it cost

Where it comes from

Recorded every time a feature uses AI

Voice typing

For example

A recording of what you say, sent to be turned into text and then thrown away — the recording is never stored

Where it comes from

Only when you press Speak beside a text box

Bug reports

For example

A screenshot of the page, your note, your browser and screen size, and the page address

Where it comes from

Only when you choose to send one from the Feedback tab

We do not collect payment card details — there is no billing in GrowthOS yet.

3. How we use it

  • To run the service: showing your agency’s information to the people in your agency allowed to see it, writing documents, sending the emails you ask us to send, and running your delivery board.
  • To keep it secure: sign-in codes, limits on repeated attempts, and the log of important actions.
  • To keep you informed: sign-in codes, notifications, and replies from your clients. These are part of the service, not marketing.
  • To tell account holders about new features in an occasional product update. Every issue has an unsubscribe link, and unsubscribing never affects the service.
  • To help you when you ask us for support.

We do not sell personal information, we do not share it with anyone for advertising, and GrowthOS contains no advertising or analytics trackers.

If you are in the UK or the European Economic Area: we rely on our contract with your agency to provide the service, on our legitimate interest in keeping it secure and telling account holders what has changed, and on your consent where we ask for it — such as browser notifications.

4. AI features

Some features send text to an AI model to write or summarise something — a proposal, a follow-up email, a task draft. Each one sends only what that feature needs, together with the parts of a client’s knowledge base your agency has switched on.

If your agency has connected its own AI account (Anthropic, OpenAI, OpenRouter or Google Gemini), requests go to that provider under your agency’s own agreement with it. Otherwise they go to Anthropic under ours.

We never use your information to train AI models, and Anthropic does not train its models on what is sent through its commercial service. When your agency uses its own AI account, that provider’s terms decide what happens to what it receives — check them, particularly on a free plan.

5. Who else handles your information

We use these providers to run GrowthOS. Each receives only what it needs to do its job.

Railway

What it does for us

Runs the application and its background worker

What it receives

Everything, as it passes through our servers

Neon

What it does for us

Our database

What it receives

Everything stored in GrowthOS

Cloudflare (R2)

What it does for us

Stores files

What it receives

Files you upload, and documents GrowthOS creates

Postmark

What it does for us

Sends email and receives your clients’ replies

What it receives

Email addresses, message contents, and delivery, bounce and open reports

Anthropic

What it does for us

AI for the credit included with every workspace

What it receives

The text a feature sends to be written or summarised

OpenAI, OpenRouter, Google

What it does for us

AI — only if your agency connects its own account with one of them

What it receives

The text a feature sends, under your agency’s agreement with that provider

Groq (OpenAI as the back-up)

What it does for us

Turns speech into text for voice typing — only when you press Speak

What it receives

The recording of what you said, once. We never store it

Pipedream

What it does for us

Connects the accounts your agency links — Google Analytics, Google Search Console, HubSpot, Brevo and DataForSEO

What it receives

The connection to that account, and the data GrowthOS reads from it

OneSignal

What it does for us

Browser notifications — only once you turn them on in Settings → Profile

What it receives

Your GrowthOS user id, your browser’s subscription and details, and the title of each notification sent to you

Ybug

What it does for us

Bug reports — it loads only when you open the Feedback tab

What it receives

What you choose to send: a screenshot, your note, browser details and the page address

Some of these providers are based in, or process information in, the United States. Where the law requires a safeguard for that transfer, we rely on the provider’s standard data-protection terms.

6. Emails sent for agencies

Proposals, follow-ups and contracts are sent from the agency’s own email address, on its instructions, to its own clients. Every sales email carries the agency’s postal address and a link to stop further follow-ups, and a reply from the client stops them automatically.

So an agency can tell whether its email arrived, our email provider reports when a message is delivered, bounces or is opened. For an open it also reports the mail app, the kind of device and an approximate location (city and country), which we keep with the message. An agency can switch open tracking off for all its emails, and then no tracking image is added at all. An “open” is only an estimate — some mail apps load pictures automatically and others block them. The same reports are kept for our own product updates.

7. Cookies and browser storage

GrowthOS sets only the cookies it needs to work. None of them is used for advertising or analytics.

gos_session

What it is for

Keeps you signed in

How long it lasts

30 days, or until you sign out

gos_challenge

What it is for

Makes a sign-in code work only in the browser that asked for it

How long it lasts

15 minutes

gos_ai_oauth

What it is for

Holds your place while you connect a Claude subscription

How long it lasts

10 minutes

gos_superadmin

What it is for

Signs GrowthOS’s own staff into the admin console

How long it lasts

8 hours

Your browser also remembers your theme, accent colour and text size, on your device only. If you turn on browser notifications, the notification service keeps its own small record in your browser; until then it is never loaded. The Feedback tab loads nothing at all until you press it.

8. How long we keep it

  • Your account and your agency’s information: for as long as your agency uses GrowthOS. When an agency asks us to delete its workspace, every record belonging to it is deleted at once, together with its files. That cannot be undone.
  • Sign-in codes expire after 10 minutes, and a signed-in session after 30 days.
  • An unsubscribe, or a client’s request to stop follow-ups, is kept for as long as we hold the address it applies to — that record is how we keep honouring it.
  • Backups held by our database provider expire on that provider’s own schedule.

9. Your rights

You can ask us for a copy of your information, to correct it, to delete it, to send it to you in a portable form, or to stop using it for a purpose you object to. If you are in California, you also have the right to know what we collect and not to be treated differently for using these rights — and we do not sell or share personal information as California defines those words.

Most of your own details can be changed in Settings. For anything else, use the Feedback tab on the right-hand edge of any GrowthOS page. We answer within one month.

If you are an agency’s client, contact the agency first — it decides what is held about you, and we will help it answer.

If you are in the UK or the EEA and are not happy with our answer, you can complain to your data-protection authority — in the UK, the Information Commissioner’s Office.

10. How we keep it safe

Every agency’s information is kept apart from every other agency’s. Connections are encrypted. There are no passwords to steal: sign-in codes and session tokens are stored only as one-way hashes, and AI account keys your agency connects are encrypted and are never shown again in full.

11. Children

GrowthOS is a tool for businesses. It is not meant for anyone under 18, an account can only be opened with a work email address, and we do not knowingly collect information about children. If you believe a child’s information has been put into GrowthOS, use the Feedback tab on the right-hand edge of any GrowthOS page and we will delete it.

12. Changes to this policy

If we change this policy in a way that matters, we will tell account holders by email or in the app before the change takes effect. The date at the top of this page always shows the current version.

13. Contact

To ask about anything on this page, use the Feedback tab on the right-hand edge of any GrowthOS page.