Privacy Policy
Effective date: July 8, 2026
Last updated: October 8, 2026
If there is any conflict between a translation and the English version, the English version prevails.
1. Who we are
Growfeed ("Growfeed", "we", "us", "our") is an AI social media content generation and scheduling service for businesses and agencies (e-commerce first), operated by VISIONALTECH UK LTD, a private limited company registered in England and Wales under company number 13564223, with registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
For the purposes of the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and applicable data protection law, VISIONALTECH UK LTD is the data controller of the personal data described in this policy.
Contact for privacy matters: [email protected](subject line: "Privacy Request").
2. Scope
This policy explains what personal data we collect when you use Growfeed (the website at growfeed.app, the web application, and related services), why we collect it, the legal bases we rely on, who we share it with, how long we keep it, and the rights you have.
It does not cover third-party websites or services we link to, or the social media platforms you choose to connect (such as Facebook, Instagram, Pinterest, TikTok, WordPress, or Telegram), which are governed by their own privacy policies.
3. The personal data we collect
Information you give us
- Account data: your name, email address, and password (password hashes are stored by our authentication provider, Supabase Auth).
- Billing data: your plan, subscription status, and related Stripe customer / subscription identifiers. Card details are collected and processed by Stripe and are never stored on our systems.
- Store and brand data:your store's web address, business name, logo, brand colours, product catalogue, brand voice answers, target audience, languages, and promotional details you provide. Where this includes personal data, we process it to provide the service.
- Content you create or approve: captions, images, videos (including Studio projects), schedules, and feedback you submit within the service.
- Support and communications: the content of messages you send us (including guest name/email on support tickets where provided).
Information we collect automatically
- Usage data: features used, generation and publishing activity, credit usage, and related application events needed to operate the product.
- Device and technical data: IP address (including hashed forms used for anonymous rate limiting), browser type, device type, and similar technical identifiers.
- Cookies and similar technologies: see section 6 and our Cookie Policy.
Information from connected accounts
When you connect a social or publishing account, we receive access tokens (and where applicable refresh tokens), account identifiers, and related metadata needed to publish on your behalf — for example Facebook Page and Instagram Business identifiers, Pinterest boards, TikTok account identifiers, Telegram bot tokens and channel IDs you provide, and WordPress site credentials. We request only the permissions needed to provide the features you use. You can disconnect these accounts at any time.
We do not intentionally collect special category data (such as data revealing health, religion, or political opinions). Please do not submit such data into the service.
4. How and why we use your data, and our legal bases
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Create and manage your account; authenticate you | Performance of a contract (Art. 6(1)(b)) |
| Provide the core service: generate, schedule, and publish content (including Studio) | Performance of a contract (Art. 6(1)(b)) |
| Process payments and manage subscriptions and credits | Performance of a contract (Art. 6(1)(b)) |
| Send service and transactional messages (security alerts, in-app digests) | Performance of a contract (Art. 6(1)(b)) |
| Provide customer support | Performance of a contract / legitimate interests (Art. 6(1)(f)) |
| Operate, secure, debug, and improve the service | Legitimate interests (Art. 6(1)(f)) in running a reliable, secure product |
| Analytics on our marketing pages | Consent (Art. 6(1)(a)) — via the cookie banner, where required |
| Marketing communications and retargeting | Consent (Art. 6(1)(a)) |
| Comply with legal, tax, and accounting obligations | Legal obligation (Art. 6(1)(c)) |
| Establish, exercise, or defend legal claims | Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You can ask us for more detail about that balancing at any time.
Where we rely on consent (for non-essential cookies and marketing), you can withdraw it at any time without affecting processing carried out before withdrawal.
5. AI processing of your content
Growfeed uses artificial intelligence to generate captions, images, and videos and to analyse store information you provide (including during onboarding scans). To do this, the content and brand information you submit is sent to the AI providers listed in section 7 solely to generate output for you or to operate the features you request.
We do not use your content to train our own models. Whether a third-party AI provider uses prompts or outputs to improve their models is governed by that provider's terms; we do not make claims here beyond what those terms state.
7. Who we share your data with (sub-processors)
We share personal data with trusted third parties who process it on our behalf, under contract, and only as needed to provide the service. Current processors include:
| Provider | Purpose | Region |
|---|---|---|
| Hetzner | Application hosting | Germany |
| Cloudflare | DNS, reverse proxy, and CDN | {{REGION_CLOUDFLARE}} |
| Supabase | Database, authentication, file storage, and authentication emails | Germany |
| Stripe | Payment processing and subscription billing | {{REGION_STRIPE}} |
| Trigger.dev Cloud | Background job processing (generation, publishing, scheduled tasks) | {{REGION_TRIGGER_DEV}} |
| Google (Vertex AI / Gemini) | AI text and related generation | {{REGION_GOOGLE_VERTEX}} |
| OpenAI | AI image generation, moderation, and Studio speech features | {{REGION_OPENAI}} |
| Atlas Cloud | AI text, image, and video generation | {{REGION_ATLAS_CLOUD}} |
| DeepSeek | AI text generation | China |
| Black Forest Labs (Flux) | AI image generation | {{REGION_BFL}} |
| xAI (Grok) | AI image generation | {{REGION_XAI}} |
| Anthropic | AI vision / product analysis for Studio workflows | {{REGION_ANTHROPIC}} |
| Pexels | Stock photo search fallback | {{REGION_PEXELS}} |
| Jina Reader | Store URL content retrieval during onboarding and catalog sync | {{REGION_JINA}} |
| SnapRender | Homepage screenshots for brand colour extraction | {{REGION_SNAPRENDER}} |
| Internal scraper service | Brand DNA and product catalog scanning | {{REGION_SCRAPER_SERVICE}} |
| Meta Platforms | Publishing to Facebook and Instagram on your instruction | {{REGION_META}} |
| Publishing Pins on your instruction | {{REGION_PINTEREST}} | |
| TikTok | Publishing to TikTok on your instruction | {{REGION_TIKTOK}} |
| Telegram | Publishing to channels you configure (using credentials you supply) | {{REGION_TELEGRAM}} |
| Google (OAuth) | Optional sign-in authentication | {{REGION_GOOGLE_OAUTH}} |
| Microsoft Clarity / Google Tag Manager | Marketing-page analytics (consent-based) | {{REGION_CLARITY}} / {{REGION_GTM}} |
| Umami | Website analytics (and session replay where you consent) | {{REGION_UMAMI}} |
WordPress sites you connect are your own systems (or your clients'); we send content there only on your instruction using credentials you provide.
We may also disclose personal data where required by law, to enforce our terms, or in connection with a merger, acquisition, or sale of assets (in which case we will notify you where required).
We do not sell your personal data.
8. Data from Meta Platforms (Facebook & Instagram)
We access Facebook and Instagram data only after you grant permission through Meta's OAuth flow.
Permissions (by purpose):
- Publish to your Facebook Page — so we can create posts and Reels you schedule or approve.
- Read Page engagement — so we can show performance metrics in Growfeed.
- Publish to Instagram — so we can publish captions, images, and Reels to your Instagram Business account.
- Read Instagram insights — so we can show Instagram analytics.
- List Pages you manage — so you can choose which Page / Instagram account to connect.
What we store and how we use it:
- Facebook Page IDs, Instagram Business account identifiers, and OAuth access tokens (and related metadata such as the Meta user id used for data-deletion mapping). Tokens are stored in our database and access is restricted to the application.
- Published content references and engagement metrics needed to display analytics.
- Data is accessed only to provide Growfeed features you request.
How to revoke:
- In Growfeed: Channels → Disconnect Facebook / Instagram.
- On Facebook: Settings → Apps and Websites → remove Growfeed. This triggers our Meta data deletion callback (see our Data Deletion page).
Meta privacy policy: facebook.com/policy.
9. Data from Pinterest
We access Pinterest data only after you grant permission. Connecting Pinterest is optional and used to publish Pins and read board / Pin information on your behalf.
Permissions (by purpose):
- Read your account — identify the connected Pinterest account in Channels.
- Read boards — let you choose which board Pins are published to.
- Create boards — only when you ask to create a board from inside the product.
- Read and write Pins — publish Pins you approve and show related metrics.
What we store:
- Pinterest account identifiers and display information.
- Boards you choose to publish to.
- OAuth access and refresh tokens, stored in our database with access restricted to the application.
- Pins Growfeed has published on your behalf and public metrics we retrieve.
How to revoke:
- In Growfeed: Channels → Pinterest → Disconnect.
- On Pinterest: Settings → Apps and websites → remove Growfeed.
10. Data from TikTok
We access TikTok data only after you grant permission. Connecting TikTok is optional and used to publish content on your behalf.
Permissions (by purpose):
- Basic profile information — identify the connected TikTok account.
- Publish video — upload and publish content you approve.
What we store:
- TikTok account identifier and display information.
- OAuth access and refresh tokens, stored in our database with access restricted to the application.
- Posts Growfeed has published on your behalf.
How to revoke:
- In Growfeed: Channels → TikTok → Disconnect.
- On TikTok: remove Growfeed from your connected apps.
11. Telegram, WordPress & other channels
- Telegram: you supply a bot token and channel identifier. We store those credentials in our database (access restricted to the application) to publish messages and media you schedule.
- WordPress: you connect a site with an application password or plugin credentials. We store those credentials in our database (access restricted to the application) to create or update posts on your instruction.
- WooCommerce keys (where you enable attribution features): store API keys you provide are stored in our database with access restricted to the application.
12. Google API Data — Limited Use Disclosure
- Growfeed uses Google Gemini / Vertex AI and optional Google OAuth sign-in.
- Use of Google user data obtained via Google APIs complies with the Google API Services User Data Policy, including Limited Use requirements, where applicable.
- Google API data is used only to provide the features you use (sign-in and AI generation).
- We do not use Google API data for advertising.
- We do not sell Google API data. We disclose it only to provide the service (including to sub-processors listed above) or as legally required.
13. International data transfers
We are established in the United Kingdom. Our application hosting (Hetzner) and primary database (Supabase) are in Germany. Some processors are located outside the UK and the European Economic Area (EEA).
In particular, content you submit for AI generation may be processed by providers outside the UK/EEA, including DeepSeek (China) and US-based AI providers such as OpenAI, Google (Vertex AI / Gemini), xAI, Anthropic, and Atlas Cloud (and other processors whose regions are marked as placeholders in section 7 until verified).
Where we transfer personal data outside the UK or the EEA, we rely on: {{TRANSFER_SAFEGUARDS}}
You can request more information about the safeguards applied to a given transfer by contacting [email protected].
14. How long we keep your data
We keep personal data only as long as necessary for the purposes described:
- Account and store data: for the life of your account, then deleted or anonymised within {{ACCOUNT_RETENTION_AFTER_CLOSURE}} of account closure, unless we must keep it longer for legal reasons.
- Billing and transaction records: retained for {{BILLING_RETENTION_PERIOD}} as required for tax and accounting compliance.
- Support communications: up to {{SUPPORT_RETENTION_PERIOD}} after resolution.
- Marketing-consent and cookie records: {{COOKIE_CONSENT_EVIDENCE_RETENTION}}.
- Connected-account tokens:until you disconnect the account or your account is deleted; Meta-connected Facebook/Instagram tokens are also removed when Meta's data-deletion callback runs.
15. Your rights
Under UK and EU data protection law, you have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- eraseyour data ("right to be forgotten"), in certain circumstances;
- restrict or object to our processing, in certain circumstances;
- data portability — receive your data in a structured, commonly used, machine-readable format;
- withdraw consent at any time, where we rely on consent;
- not be subject to solely automated decisions producing legal or similarly significant effects (our content generation does not make legal or similarly significant decisions about you).
To exercise any of these rights, contact us at [email protected]with subject "Data Rights Request". We will respond within one month, as required by law.
Complaints.If you are unhappy with how we handle your data, you can complain to a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO), www.ico.org.uk. If you are in the EEA, you may complain to your local data protection authority. We would appreciate the chance to address your concerns first.
16. Data deletion
You can request deletion of your personal data as follows:
- By email to [email protected]with subject "Data Deletion Request". We handle confirmed requests within 30 days. Billing records required by law are retained for {{BILLING_RETENTION_PERIOD}}.
- For Facebook / Instagram connection data removed via Meta: see our Data Deletionpage. Meta's callback deletes matching Facebook and Instagram connection data automatically and provides a confirmation code / status URL.
- In-app Settings → Delete Account currently routes you to Support so our team can process the request; it does not erase your account automatically.
Backup copies may remain for up to {{BACKUP_FINAL_DELETION_PERIOD}} before final deletion where technically applicable.
17. Data security
We take appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS), hashed authentication passwords via our auth provider, access controls that restrict database credentials and tokens to the application, and use of reputable infrastructure providers. OAuth tokens and site credentials are stored in our database; access is restricted to the application. No system is completely secure, so we cannot guarantee absolute security. Where legally required, we will notify you and the relevant authority of a personal data breach.
18. Children
Growfeed is a business service and is not intended for anyone under the age of 18. We do not knowingly collect data from children. If you believe a minor has provided us with personal data, contact us at [email protected] and we will delete it.
19. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you by email or in-app notice. Your continued use of the service after changes take effect constitutes acceptance of the updated policy.
20. Contact
VISIONALTECH UK LTD
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Privacy contact: [email protected]
Support: [email protected]
Website: growfeed.app