Privacy statement
How Growf collects, uses, shares and protects information when you use our platform. Written to be read, not just signed.
Last updated 1 June 2026
1. Introduction
Growf (“Growf”, “we”, “us”) provides an AI operating system for agencies. This Privacy Policy explains what information we collect, why we collect it, how we protect it, and the choices you have. It applies to our website, applications and API (together, the “Services”). For the purposes of the EU General Data Protection Regulation (GDPR), Growf acts as a data controller for account data and as a data processor for the client content you put into the platform.
2. What we collect
We collect information in three ways:
- Information you provide. Account details such as name, work email and workspace name; billing information; and the content you upload, such as briefs, strategies, assets and client context.
- Information from your use. Log data, device and browser information, IP address, and product usage events that help us run and improve the Services.
- Information from integrations. When you connect a third-party tool, we receive the data you authorise that connection to share. Section 5 explains what this means for Google accounts.
3. How we use data
We use information to:
- provide, maintain and secure the Services;
- run the agents and features you ask for, on your instruction;
- process payments and manage your subscription;
- provide support and respond to your requests;
- understand usage so we can improve the product;
- comply with legal obligations and enforce our Terms.
Our legal bases include performance of our contract with you, your consent where required, our legitimate interests in operating the Services, and compliance with the law.
4. AI & your content
Growf uses AI and agents to turn briefs into strategy and content. This is important, so we say it plainly:
- We do not use your private client content to train shared or foundation models.
- We do not use data from your connected accounts, including Google user data, to train generalised or foundation AI or machine-learning models — ours or anyone else’s.
- Content is processed to generate outputs for your workspace only, on your instruction.
- Where we use third-party model providers, they act as our subprocessors under contractual terms that prohibit training on your data.
5. Google user data
When you connect a Google account to Growf, we ask only for the permissions the feature you turned on needs. Google shows you every scope on its consent screen before you approve it.
What we do with Google user data
- We use it only to provide and improve the user-facing features you connected it for.
- We store it encrypted, as described in section 7.
- We delete it when you disconnect the integration, delete the content, or close your workspace. See section 8 for the periods.
- You can withdraw access at any time in Growf, or at myaccount.google.com/permissions.
What we never do
- We do not sell Google user data.
- We do not use it for advertising, ad personalisation, credit checks or lending decisions.
- We do not use it to train generalised or foundation AI or machine-learning models. Where a model provider processes it to produce output for your workspace, that provider acts as our subprocessor under terms that forbid training on your data.
- We do not transfer it to anyone else, except to subprocessors acting on our instruction, where the law requires it, or in a merger or sale of assets we tell you about first.
- Our staff do not read your Google user data, except with your explicit consent, to resolve a security problem, where the law requires it, or where the data is aggregated and anonymised.
Growf’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Sharing & processors
We do not sell your personal data. We share information only with:
- Subprocessors: vetted vendors (hosting, model providers, payments, analytics) who process data on our behalf under data-processing agreements. We keep a current list and share it on request.
- Within your workspace: with the members and roles you grant access to.
- Legal & safety: when the law requires it, or to protect the rights and safety of users and the public.
- Business transfers: in connection with a merger, acquisition or sale of assets, subject to this Policy.
7. How we protect your data
We protect all personal data, and data from connected accounts in particular, with technical and organisational measures:
- Encryption. Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256.
- Key management. Secrets and encryption keys are held in a managed key-management service and rotated on a set schedule.
- Access control. Inside your workspace, roles decide who sees what. Growf staff access to production systems requires multi-factor authentication, follows least privilege, and is logged and reviewed.
- Isolation. Each workspace is logically separated, so one customer cannot reach another customer’s content.
- Infrastructure. We run on EU-based cloud infrastructure with network segmentation, firewalls and private networking, and we apply security patches promptly.
- Secure development. Changes pass review and testing before release through controlled CI/CD workflows.
- Incident response. We maintain an incident-response plan covering detection, containment, eradication and recovery. If an incident affects your data, we notify affected customers without undue delay and in line with our legal obligations.
Sensitive data. We treat data from connected accounts as sensitive. This includes Google user data such as email, calendar and file content. Every control above applies to it, access is limited to the smallest group of staff who need it, and it is held in the EU-based systems described in section 10.
Our full security practices are set out on our Security page.
8. Retention & deletion
We keep personal data only as long as we need it:
| Data | How long we keep it |
|---|---|
| Account and workspace data | While your account is active, then deleted or anonymised within 30 days of closure |
| Client content you upload | While your account is active, then deleted within 30 days of closure |
| Data from connected accounts, including Google user data | Until you disconnect the integration or close your workspace, then deleted within 30 days |
| Log data and product usage events | 12 months |
| Backups | Purged on a rolling cycle within 90 days |
| Billing and accounting records | 7 years, as Dutch tax law requires |
To delete data sooner, disconnect the integration in-product, delete the content, or email support@growf.io. We confirm deletion within 30 days. We keep data beyond these periods only where the law, our accounting duties or an active security investigation require it.
9. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. You can exercise many of these directly in-product, or by contacting us. If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.
10. International transfers
Growf is operated from the European Union and primarily stores data within the EEA. Where data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
11. Changes to this Policy
We may update this Policy from time to time. When changes are material, we’ll notify you through the Services or by email before they take effect. The “last updated” date above always reflects the current version.
12. Contact
Questions about privacy, or want to exercise a right? Email our team at support@growf.io. You can also review our Security practices and Terms of Service.
Want to see how your agency can
think, create and grow in the AI era?
industry trusted.
Growf is backed by
Quantum Leap Capital
"With our investment of one million euros, we are supporting the development of an AI Operating System that will fundamentally transform the agency world. Agencies need structure, scalability, and true adoption of AI, and Growf delivers exactly that."

Mike de Boer
Quantum Leap Capital






