Privacy policy
Last updated 1 September 2026
What we hold, why we hold it, who else sees it, and how to get it deleted.
What we collect
Account: your name, email address, hashed password (or your Google account identifier if you sign in with Google), and the workspaces you belong to.
Project data: the sites, listings and repositories you add, everything an audit measures about them, and the findings, opportunities, experiments and reports built from those measurements.
Connected sources: access tokens and API credentials you choose to connect, encrypted at rest with AES-256. They are never displayed back, exported, or included in reports.
Operational records: sign-in times, audit-log entries of who changed what, email delivery records, usage counters, and provider billing events.
Anonymous audits: if you run the free audit from our home page without an account, we store the URL, the findings, a hashed form of your IP address and a random device token — so the same visitor cannot re-run it endlessly. The raw IP is not stored.
What we do not do
We do not sell your data, share it with advertisers, or use it to train third-party models. We do not put tracking pixels in our emails. We do not collect page content, form input or cookies from visitors to sites where you install the fix snippet — it fetches the fixes you approved and applies them, nothing more.
Why we hold it
To run the service you asked for: performing audits, storing their evidence, showing your history, sending the emails you enabled, enforcing plan limits, and taking payment. We keep audit evidence because the product’s value is that a figure can always be traced back to its source.
Who else processes it
Paddle.com Market Ltd — payments and subscriptions as merchant of record; receives your billing details directly, not through us. Resend — transactional email delivery. Google (Search Console, Analytics, PageSpeed Insights), DataForSEO, GitHub and public app-store endpoints — only for the sources you connect. Our servers and database are hosted in the EU.
How long we keep it
Account and project data: while your account exists, and for 30 days after deletion in backups. Anonymous free-audit records: 90 days. Email delivery logs: 12 months. Billing records: as long as tax law requires, usually 7 years, held largely by Paddle.
Your rights
Email privacy@aigrowthmanager.com to get a copy of your data, correct it, or have it deleted. We answer within 30 days. You can disconnect any integration at any time from the project’s integrations page, which deletes the stored credential immediately. If you are in the UK or EU you may also complain to your data protection authority.
Cookies
We use a session cookie to keep you signed in, a cookie to remember which workspace you are viewing, and — for the free anonymous audit — a device token cookie so one machine cannot run it repeatedly. There are no advertising or analytics cookies on this product.