Privacy Policy

Effective date: July 8, 2026

Last updated: October 8, 2026

If there is any conflict between a translation and the English version, the English version prevails.

1. Who we are

Growfeed ("Growfeed", "we", "us", "our") is an AI social media content generation and scheduling service for businesses and agencies (e-commerce first), operated by VISIONALTECH UK LTD, a private limited company registered in England and Wales under company number 13564223, with registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

For the purposes of the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and applicable data protection law, VISIONALTECH UK LTD is the data controller of the personal data described in this policy.

Contact for privacy matters: [email protected](subject line: "Privacy Request").

2. Scope

This policy explains what personal data we collect when you use Growfeed (the website at growfeed.app, the web application, and related services), why we collect it, the legal bases we rely on, who we share it with, how long we keep it, and the rights you have.

It does not cover third-party websites or services we link to, or the social media platforms you choose to connect (such as Facebook, Instagram, Pinterest, TikTok, WordPress, or Telegram), which are governed by their own privacy policies.

3. The personal data we collect

Information you give us

  • Account data: your name, email address, and password (password hashes are stored by our authentication provider, Supabase Auth).
  • Billing data: your plan, subscription status, and related Stripe customer / subscription identifiers. Card details are collected and processed by Stripe and are never stored on our systems.
  • Store and brand data:your store's web address, business name, logo, brand colours, product catalogue, brand voice answers, target audience, languages, and promotional details you provide. Where this includes personal data, we process it to provide the service.
  • Content you create or approve: captions, images, videos (including Studio projects), schedules, and feedback you submit within the service.
  • Support and communications: the content of messages you send us (including guest name/email on support tickets where provided).

Information we collect automatically

  • Usage data: features used, generation and publishing activity, credit usage, and related application events needed to operate the product.
  • Device and technical data: IP address (including hashed forms used for anonymous rate limiting), browser type, device type, and similar technical identifiers.
  • Cookies and similar technologies: see section 6 and our Cookie Policy.

Information from connected accounts

When you connect a social or publishing account, we receive access tokens (and where applicable refresh tokens), account identifiers, and related metadata needed to publish on your behalf — for example Facebook Page and Instagram Business identifiers, Pinterest boards, TikTok account identifiers, Telegram bot tokens and channel IDs you provide, and WordPress site credentials. We request only the permissions needed to provide the features you use. You can disconnect these accounts at any time.

We do not intentionally collect special category data (such as data revealing health, religion, or political opinions). Please do not submit such data into the service.

4. How and why we use your data, and our legal bases

PurposeLegal basis (UK/EU GDPR)
Create and manage your account; authenticate youPerformance of a contract (Art. 6(1)(b))
Provide the core service: generate, schedule, and publish content (including Studio)Performance of a contract (Art. 6(1)(b))
Process payments and manage subscriptions and creditsPerformance of a contract (Art. 6(1)(b))
Send service and transactional messages (security alerts, in-app digests)Performance of a contract (Art. 6(1)(b))
Provide customer supportPerformance of a contract / legitimate interests (Art. 6(1)(f))
Operate, secure, debug, and improve the serviceLegitimate interests (Art. 6(1)(f)) in running a reliable, secure product
Analytics on our marketing pagesConsent (Art. 6(1)(a)) — via the cookie banner, where required
Marketing communications and retargetingConsent (Art. 6(1)(a))
Comply with legal, tax, and accounting obligationsLegal obligation (Art. 6(1)(c))
Establish, exercise, or defend legal claimsLegitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You can ask us for more detail about that balancing at any time.

Where we rely on consent (for non-essential cookies and marketing), you can withdraw it at any time without affecting processing carried out before withdrawal.

5. AI processing of your content

Growfeed uses artificial intelligence to generate captions, images, and videos and to analyse store information you provide (including during onboarding scans). To do this, the content and brand information you submit is sent to the AI providers listed in section 7 solely to generate output for you or to operate the features you request.

We do not use your content to train our own models. Whether a third-party AI provider uses prompts or outputs to improve their models is governed by that provider's terms; we do not make claims here beyond what those terms state.

6. Cookies and tracking

We use strictly necessary cookies to make the service work (for example, to keep you logged in and to remember your cookie choices). On our marketing pages, analytics and marketing cookies are set only with your consent, managed through our cookie banner.

Full details of cookie categories and named cookies are in our Cookie Policy. You can change or withdraw non-essential choices at any time using the "Cookie settings" control in the footer.

7. Who we share your data with (sub-processors)

We share personal data with trusted third parties who process it on our behalf, under contract, and only as needed to provide the service. Current processors include:

ProviderPurposeRegion
HetznerApplication hostingGermany
CloudflareDNS, reverse proxy, and CDN{{REGION_CLOUDFLARE}}
SupabaseDatabase, authentication, file storage, and authentication emailsGermany
StripePayment processing and subscription billing{{REGION_STRIPE}}
Trigger.dev CloudBackground job processing (generation, publishing, scheduled tasks){{REGION_TRIGGER_DEV}}
Google (Vertex AI / Gemini)AI text and related generation{{REGION_GOOGLE_VERTEX}}
OpenAIAI image generation, moderation, and Studio speech features{{REGION_OPENAI}}
Atlas CloudAI text, image, and video generation{{REGION_ATLAS_CLOUD}}
DeepSeekAI text generationChina
Black Forest Labs (Flux)AI image generation{{REGION_BFL}}
xAI (Grok)AI image generation{{REGION_XAI}}
AnthropicAI vision / product analysis for Studio workflows{{REGION_ANTHROPIC}}
PexelsStock photo search fallback{{REGION_PEXELS}}
Jina ReaderStore URL content retrieval during onboarding and catalog sync{{REGION_JINA}}
SnapRenderHomepage screenshots for brand colour extraction{{REGION_SNAPRENDER}}
Internal scraper serviceBrand DNA and product catalog scanning{{REGION_SCRAPER_SERVICE}}
Meta PlatformsPublishing to Facebook and Instagram on your instruction{{REGION_META}}
PinterestPublishing Pins on your instruction{{REGION_PINTEREST}}
TikTokPublishing to TikTok on your instruction{{REGION_TIKTOK}}
TelegramPublishing to channels you configure (using credentials you supply){{REGION_TELEGRAM}}
Google (OAuth)Optional sign-in authentication{{REGION_GOOGLE_OAUTH}}
Microsoft Clarity / Google Tag ManagerMarketing-page analytics (consent-based){{REGION_CLARITY}} / {{REGION_GTM}}
UmamiWebsite analytics (and session replay where you consent){{REGION_UMAMI}}

WordPress sites you connect are your own systems (or your clients'); we send content there only on your instruction using credentials you provide.

We may also disclose personal data where required by law, to enforce our terms, or in connection with a merger, acquisition, or sale of assets (in which case we will notify you where required).

We do not sell your personal data.

8. Data from Meta Platforms (Facebook & Instagram)

We access Facebook and Instagram data only after you grant permission through Meta's OAuth flow.

Permissions (by purpose):

  • Publish to your Facebook Page — so we can create posts and Reels you schedule or approve.
  • Read Page engagement — so we can show performance metrics in Growfeed.
  • Publish to Instagram — so we can publish captions, images, and Reels to your Instagram Business account.
  • Read Instagram insights — so we can show Instagram analytics.
  • List Pages you manage — so you can choose which Page / Instagram account to connect.

What we store and how we use it:

  • Facebook Page IDs, Instagram Business account identifiers, and OAuth access tokens (and related metadata such as the Meta user id used for data-deletion mapping). Tokens are stored in our database and access is restricted to the application.
  • Published content references and engagement metrics needed to display analytics.
  • Data is accessed only to provide Growfeed features you request.

How to revoke:

  • In Growfeed: Channels → Disconnect Facebook / Instagram.
  • On Facebook: Settings → Apps and Websites → remove Growfeed. This triggers our Meta data deletion callback (see our Data Deletion page).

Meta privacy policy: facebook.com/policy.

9. Data from Pinterest

We access Pinterest data only after you grant permission. Connecting Pinterest is optional and used to publish Pins and read board / Pin information on your behalf.

Permissions (by purpose):

  • Read your account — identify the connected Pinterest account in Channels.
  • Read boards — let you choose which board Pins are published to.
  • Create boards — only when you ask to create a board from inside the product.
  • Read and write Pins — publish Pins you approve and show related metrics.

What we store:

  • Pinterest account identifiers and display information.
  • Boards you choose to publish to.
  • OAuth access and refresh tokens, stored in our database with access restricted to the application.
  • Pins Growfeed has published on your behalf and public metrics we retrieve.

How to revoke:

  • In Growfeed: Channels → Pinterest → Disconnect.
  • On Pinterest: Settings → Apps and websites → remove Growfeed.

10. Data from TikTok

We access TikTok data only after you grant permission. Connecting TikTok is optional and used to publish content on your behalf.

Permissions (by purpose):

  • Basic profile information — identify the connected TikTok account.
  • Publish video — upload and publish content you approve.

What we store:

  • TikTok account identifier and display information.
  • OAuth access and refresh tokens, stored in our database with access restricted to the application.
  • Posts Growfeed has published on your behalf.

How to revoke:

  • In Growfeed: Channels → TikTok → Disconnect.
  • On TikTok: remove Growfeed from your connected apps.

11. Telegram, WordPress & other channels

  • Telegram: you supply a bot token and channel identifier. We store those credentials in our database (access restricted to the application) to publish messages and media you schedule.
  • WordPress: you connect a site with an application password or plugin credentials. We store those credentials in our database (access restricted to the application) to create or update posts on your instruction.
  • WooCommerce keys (where you enable attribution features): store API keys you provide are stored in our database with access restricted to the application.

12. Google API Data — Limited Use Disclosure

  • Growfeed uses Google Gemini / Vertex AI and optional Google OAuth sign-in.
  • Use of Google user data obtained via Google APIs complies with the Google API Services User Data Policy, including Limited Use requirements, where applicable.
  • Google API data is used only to provide the features you use (sign-in and AI generation).
  • We do not use Google API data for advertising.
  • We do not sell Google API data. We disclose it only to provide the service (including to sub-processors listed above) or as legally required.

13. International data transfers

We are established in the United Kingdom. Our application hosting (Hetzner) and primary database (Supabase) are in Germany. Some processors are located outside the UK and the European Economic Area (EEA).

In particular, content you submit for AI generation may be processed by providers outside the UK/EEA, including DeepSeek (China) and US-based AI providers such as OpenAI, Google (Vertex AI / Gemini), xAI, Anthropic, and Atlas Cloud (and other processors whose regions are marked as placeholders in section 7 until verified).

Where we transfer personal data outside the UK or the EEA, we rely on: {{TRANSFER_SAFEGUARDS}}

You can request more information about the safeguards applied to a given transfer by contacting [email protected].

14. How long we keep your data

We keep personal data only as long as necessary for the purposes described:

  • Account and store data: for the life of your account, then deleted or anonymised within {{ACCOUNT_RETENTION_AFTER_CLOSURE}} of account closure, unless we must keep it longer for legal reasons.
  • Billing and transaction records: retained for {{BILLING_RETENTION_PERIOD}} as required for tax and accounting compliance.
  • Support communications: up to {{SUPPORT_RETENTION_PERIOD}} after resolution.
  • Marketing-consent and cookie records: {{COOKIE_CONSENT_EVIDENCE_RETENTION}}.
  • Connected-account tokens:until you disconnect the account or your account is deleted; Meta-connected Facebook/Instagram tokens are also removed when Meta's data-deletion callback runs.

15. Your rights

Under UK and EU data protection law, you have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate or incomplete data;
  • eraseyour data ("right to be forgotten"), in certain circumstances;
  • restrict or object to our processing, in certain circumstances;
  • data portability — receive your data in a structured, commonly used, machine-readable format;
  • withdraw consent at any time, where we rely on consent;
  • not be subject to solely automated decisions producing legal or similarly significant effects (our content generation does not make legal or similarly significant decisions about you).

To exercise any of these rights, contact us at [email protected]with subject "Data Rights Request". We will respond within one month, as required by law.

Complaints.If you are unhappy with how we handle your data, you can complain to a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO), www.ico.org.uk. If you are in the EEA, you may complain to your local data protection authority. We would appreciate the chance to address your concerns first.

16. Data deletion

You can request deletion of your personal data as follows:

  • By email to [email protected]with subject "Data Deletion Request". We handle confirmed requests within 30 days. Billing records required by law are retained for {{BILLING_RETENTION_PERIOD}}.
  • For Facebook / Instagram connection data removed via Meta: see our Data Deletionpage. Meta's callback deletes matching Facebook and Instagram connection data automatically and provides a confirmation code / status URL.
  • In-app Settings → Delete Account currently routes you to Support so our team can process the request; it does not erase your account automatically.

Backup copies may remain for up to {{BACKUP_FINAL_DELETION_PERIOD}} before final deletion where technically applicable.

17. Data security

We take appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS), hashed authentication passwords via our auth provider, access controls that restrict database credentials and tokens to the application, and use of reputable infrastructure providers. OAuth tokens and site credentials are stored in our database; access is restricted to the application. No system is completely secure, so we cannot guarantee absolute security. Where legally required, we will notify you and the relevant authority of a personal data breach.

18. Children

Growfeed is a business service and is not intended for anyone under the age of 18. We do not knowingly collect data from children. If you believe a minor has provided us with personal data, contact us at [email protected] and we will delete it.

19. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you by email or in-app notice. Your continued use of the service after changes take effect constitutes acceptance of the updated policy.

20. Contact

VISIONALTECH UK LTD
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

Privacy contact: [email protected]

Support: [email protected]

Website: growfeed.app