1. Who we are and when this policy applies
GrowthScout provides website analysis, search intelligence, content planning, AI-assisted content creation, media management, and publishing tools. GrowthScout is established and operated in Bristol, United Kingdom. The UK General Data Protection Regulation, Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, and Privacy and Electronic Communications Regulations are our primary privacy framework.
GrowthScout is the controller of personal data used to operate our website, accounts, billing, communications, security, and business. Where we handle personal data contained in customer content or a connected service solely on a customer's instructions, GrowthScout acts as that customer's processor and the customer remains responsible for its own lawful collection and use of that data. If GrowthScout uses personal data for a separate purpose that we determine, such as protecting or improving our own service, we act as controller for that separate use. That separate role does not make customer content handled solely as a processor available for unrelated reuse.
This policy applies when you visit growthscout.io, create or use an account, join an organisation, connect another service, communicate with us, or otherwise use GrowthScout from any country. Mandatory laws where you live may give you additional rights, which we honour when they apply to our processing. This policy does not govern websites, services, or publishing destinations controlled by other organisations.
2. Personal data we collect
Depending on how you use GrowthScout, we collect and process the following categories:
- Account and identity data: your name, email address, password hash, avatar, verification and last-login state, Google account identifier and profile details when you use Google sign-in, organisation membership and role, invitations, and selected account settings.
- Website and business data: website addresses, business descriptions, audiences, markets, competitors, sitemap data, and the public pages and resources GrowthScout retrieves from websites you ask us to analyse.
- Customer content: prompts, instructions, keywords, content plans, articles, conversations, generated outputs, uploaded images and media, comments, and other material you submit or create.
- Connected-service data: Google Search Console properties and search-performance data, publishing settings, WordPress or webhook destination details, and credentials or tokens needed to operate integrations you enable.
- Billing data: billing contact details, Stripe customer and subscription references, plan, payment status, invoice and transaction values, and tax-related information. Stripe collects complete payment-card details on its own hosted pages.
- Technical and security data: IP address, user agent, browser, operating system, device description, session and authentication activity, request and response metadata, error and diagnostic information, and security events.
- Communications: messages and information you provide when you request help, respond to an invitation, exercise a privacy right, or otherwise contact us.
Where the data comes from
We receive data directly from you and other members of your organisation; automatically from your browser and use of the service; from services you connect, such as Google Search Console and Stripe; from customers that invite you or provide content; and from public sources such as websites, sitemaps, and public search data.
Please avoid submitting special-category or highly sensitive personal data unless it is genuinely necessary, lawful, and covered by your agreement with GrowthScout.
3. How we use personal data and our UK lawful bases
The lawful bases below describe our processing under UK data-protection law. Where another law applies, we also comply with any additional legal-ground, consent, or notice requirements it imposes.
We use personal data for the following purposes and UK lawful bases:
- Provide the service
- To create accounts, analyse websites, run requested AI workflows, manage content and media, connect integrations, publish content, and provide support. Where you contract with us personally, we rely on that contract or steps you ask us to take before entering it. For authorised users acting for a customer organisation, we rely on our and the organisation's legitimate interests in providing and administering the requested business service.
- Manage billing and records
- To administer trials, subscriptions, credits, invoices, payments, refunds, and accounting. We rely on a contract with you where you are the contracting customer; otherwise, on legitimate interests in administering the customer organisation's account; and, where applicable, on legal obligations.
- Protect and improve GrowthScout
- To authenticate users, prevent fraud and abuse, investigate errors, monitor reliability, understand feature performance, and improve the service using relevant account, technical, security, usage, diagnostic, and operational records. We rely on our legitimate interests in operating a secure, dependable, and useful business service, balanced against your rights.
- Communicate with you
- To send authentication, invitation, billing, security, service, and support messages. We rely on a contract with you where the message is necessary to perform it, and otherwise on our legitimate interest in administering the service. Where consent is legally required for an optional communication, we will ask for it.
- Meet legal requirements
- To keep required records, respond to lawful requests, establish or defend legal claims, and enforce our agreements. We rely on legal obligations and legitimate interests in protecting our rights.
You need to provide the account, website, and billing information required for the features you choose. Without it, we may be unable to create an account, provide that feature, or enter or perform a contract with you or your organisation.
4. AI-assisted processing and automated decisions
GrowthScout uses AI models to analyse website material, suggest keywords and plans, generate or edit content and images, and support agent workflows. The prompts sent to a model can include your instructions, website content, business context, and earlier workflow outputs. GrowthScout normally stores the messages, provider request and response, model, token usage, cost, errors, and timing with the related workspace so the feature can operate and its history, reliability, and cost can be reviewed.
AI output can be incomplete or incorrect. GrowthScout's AI features assist content and search work; they do not make decisions about people that produce legal or similarly significant effects. Customers choose whether automatic publishing is enabled and remain responsible for monitoring, checking, correcting, or removing outputs. When Auto publish is on, content may be published before anyone reviews it.
AI conversations, messages, and provider request and response records do not currently have an automated expiry. They can remain after a related user or website record is deleted with that association removed. We assess validated erasure requests and delete or anonymise these records where applicable law requires it, subject to lawful billing, security, audit, and legal-record needs.
6. International transfers
If you use GrowthScout from outside the United Kingdom, your data is transferred to and processed in the UK. Some providers also process data in other countries, including the United States, where data-protection laws may differ from those where you live.
For a restricted transfer from the UK, we use the safeguard applicable to the recipient: UK adequacy regulations where they cover that recipient, or approved contractual safeguards such as the UK International Data Transfer Agreement or the UK Addendum to EU Standard Contractual Clauses, together with a transfer-risk assessment and relevant security measures. Where the EU GDPR applies, transfers use an EU adequacy decision or another EU GDPR transfer mechanism as required. Contact us to request information about or a copy of the safeguard relevant to your data.
7. How long we keep personal data
We use the following periods or criteria:
- Account, organisation, website, customer-content, and integration records are normally kept while the related account or workspace is active. There is currently no automatic post-closure expiry for complete account records, so complete account-erasure requests are handled manually. Website deletion removes website-owned records, but AI conversations, messages, and provider request and response records presently have no automated expiry and may remain with their account or website association removed. We assess validated requests and delete or anonymise data where applicable law requires it, subject to lawful billing, security, audit, and legal-record needs.
- Billing, transaction, tax, and accounting records are kept for the period required by applicable financial and tax law and to resolve payment disputes.
- Bearer authentication sessions are valid for up to 30 days by default unless revoked or replaced. Password-reset links expire after 1 hour, organisation-invitation proofs after 14 days, and Google Search Console connection state after 10 minutes. Expired and revoked records may be retained as needed for security and audit purposes.
- Temporary resumable media uploads expire after 24 hours. The temporary file bytes for successfully completed and failed uploads are removed promptly; their short-lived ownership, status, and error records remain until expiry cleanup.
- Current production database backups are retained for 7 days locally and 90 days in private cloud backup storage. Database binary logs are retained for 7 days. Completed media is mirrored daily, and deleted local media is removed from the mirror on the next successful sync. Data deleted from active systems may remain in a rotating backup for up to 90 days.
- Security, diagnostic, and support records are kept for as long as reasonably needed to investigate the event, protect the service, meet legal requirements, and establish or defend claims.
When deciding a period, we consider the data's amount and sensitivity, the purpose, security and legal risks, contractual commitments, and applicable limitation or record-keeping requirements.
8. Cookies and browser storage
GrowthScout uses cookies and similar browser storage to provide requested features, remember choices, and protect the service. Some storage is strictly necessary for authentication or security; other storage remembers preferences you choose. This includes:
- a bearer authentication token stored until the browser session ends, or in local storage until you sign out or clear it when you choose “Remember me” or “Keep me signed in”; the corresponding server session is valid for up to 30 days by default;
- local-storage values that remember the last sign-in provider and theme and navigation preferences until you change the preference or clear the storage; and session-storage values, including an invited email address and a public-article sharing capability, that normally last until the related flow completes or the browser tab or session ends;
- a 10-minute secure cookie used to protect Google Search Console connection callbacks and a secure organisation-invitation cookie lasting up to 14 days; and
- security technologies set by Google when you choose Google authentication, with durations controlled and described by Google.
GrowthScout's application code does not currently set advertising or behavioural analytics cookies. It loads fonts from Google, so Google receives ordinary request information such as your IP address, browser, and the page making the request. Articles can also include YouTube videos or remotely hosted images; loading them connects your browser to the relevant provider, which may use its own cookies or similar technologies. This does not exclude necessary service logs or aggregate infrastructure data. GrowthScout does not place its own advertising tags or use these embeds for GrowthScout targeted advertising.
You can change theme and navigation preferences in GrowthScout, clear GrowthScout storage through your browser, and avoid persistent sign-in storage by turning off “Remember me”. We use preference storage without consent where a legal exemption for a requested appearance or service preference applies. Blocking storage required for authentication or security may prevent parts of the service from working.
9. Security
We use appropriate technical and organisational measures designed to protect personal data. These include access controls, hashed passwords and session tokens, encryption for stored integration secrets, encrypted transport in production, restricted private storage, rate limits, input and upload validation, and backups. No internet service can guarantee absolute security, so please use a unique password, protect your account, and tell us promptly if you believe it has been compromised.
10. Your privacy rights in the UK and elsewhere
Under UK data-protection law, you may have rights to access your personal data; correct inaccurate data; ask for deletion or restriction; receive certain data in a portable format; object to some processing; and withdraw consent where we rely on it. If another privacy law applies where you live, you may have some or all of these rights, different response periods, or additional rights. These rights are not absolute, and lawful exceptions may apply. You may also update some account and workspace information directly in GrowthScout.
Your right to object
You can object at any time to direct marketing. You can also object to processing based on our legitimate interests because of your particular situation. We will stop unless we have compelling legitimate grounds to continue or need the data for legal claims.
To exercise a right, email [email protected]. Tell us which account and request are involved. We may ask for information needed to verify your identity and authority. You may use an authorised agent where local law allows it. UK requests are normally answered within one month; other requests are answered within the period required by applicable law.
11. Complaints and regulators
To make a data-protection complaint, email [email protected] with “Data protection complaint” in the subject line and explain what happened and the outcome you want. We will acknowledge the complaint within 30 days, investigate it without undue delay, keep you informed where the investigation is ongoing, and tell you the outcome.
You also have the right to complain to the UK Information Commissioner's Office. You can find complaint guidance at ico.org.uk. If another country's privacy law applies, you may also have the right to complain to the privacy or data-protection authority where you live. In the EEA, this includes the authority where you live or work, or where the issue occurred.
12. United States privacy supplement
This section supplements the rest of the policy for residents of California and other United States states. It applies only when the relevant state law covers GrowthScout, the personal information, and your request. For California's online privacy disclosures, section 2 identifies the information categories and sources, section 5 identifies third-party categories, section 10 explains how to review or correct information, section 14 explains policy changes, and the effective date appears above. The tracking disclosures appear below.
The information in section 2 can fall within US state-law categories including identifiers; customer-record and commercial information; internet or electronic-network activity; professional information such as organisation membership and role; visual information in avatars or uploads; and sensitive personal information such as account sign-in credentials, connected-service secrets, and sensitive information a customer chooses to include in content. We use sign-in credentials and connected-service secrets only to provide and secure requested services, not to infer characteristics about a person. We disclose these categories to the recipient categories in section 5 for the purposes described in this policy.
GrowthScout does not sell personal information for money or other valuable consideration and does not share it for cross-context behavioural advertising. We do not use personal information for targeted advertising and therefore do not provide a “Do Not Sell or Share” link.
Where an applicable US state law gives you rights, these may include asking us to know or access, correct, delete, or provide a portable copy of personal information; to opt out of sale, targeted advertising, or certain profiling; to limit certain uses of sensitive personal information; and to appeal a decision about your request. You or an authorised agent can submit a request using the contact details below. We verify requests as reasonably necessary, respond within the period required by the applicable law, and do not discriminate against you for exercising a right. If we deny a request and applicable law gives you an appeal right, reply to our decision or email [email protected] with “Privacy appeal” in the subject line.
GrowthScout does not currently respond differently to legacy browser “Do Not Track” signals because there is no generally accepted standard for them. Where an applicable law requires us to recognise an opt-out preference signal such as Global Privacy Control, we process it as required. Because GrowthScout does not currently conduct covered sale, sharing, or targeted advertising, there is presently no such GrowthScout processing to opt out of. Yes, other parties may collect activity over time and across different websites when a browser automatically loads Google-hosted fonts or when you load Google features, YouTube media, or remotely hosted article images. Their independent collection is governed by their own privacy terms. GrowthScout does not authorise that collection for GrowthScout advertising.
13. Children
GrowthScout is a business service and is not intended for children under 18. We do not intentionally solicit accounts or submissions from children. Like any visitor, a child who accesses the public site may generate IP, user-agent, and request data automatically. If you believe a child has created an account or provided personal data to us, contact us so we can investigate and take appropriate action.
14. Changes to this policy
We review this policy as GrowthScout, its providers, and legal requirements change. We will post the updated version here and change the date at the top. If a change materially affects how we use account data, we will also provide a prominent in-service notice or contact affected account holders where appropriate. We will seek consent before a new use where the law requires it; continued use is not treated as consent where consent is required.
15. Contact us
For privacy questions, rights requests, or information about international-transfer safeguards, contact:
GrowthScout
Bristol, United Kingdom
[email protected]