Privacy Policy

Last updated 9 September 2026

GrowthX AI SEO (“GrowthX”, “we”) is a search-engine-optimisation workspace. Customers connect the websites and marketing accounts they own or manage, and we analyse that data to report on technical health, search visibility and local presence, and to recommend changes. This policy explains what we hold, why, who else sees it, and how to get it removed.

Information you give us

When you register we store your name, email address and a hashed password. We use these to authenticate you, to scope your data to your organisation, and to contact you about the service.

Websites you ask us to analyse

When you add a site, we fetch its pages the way a search engine would and store what we retrieve: URLs, page titles, meta descriptions, headings, body text, response codes, response times and detected technical issues. We only crawl domains a customer has entered into the product.

Google account data

Connecting a Google service is optional and always initiated by you. Each connector requests the narrowest scope that lets it read what the product displays:

  • Google Search Console — webmasters.readonly. Read-only. We read your property list and search performance data.
  • Google Analytics 4 — analytics.readonly. Read-only. We read your property list and traffic reports.
  • Google Business Profile — business.manage. Google publishes no read-only scope for Business Profile, so this scope also permits writing. We use it to read your business information, categories, services, hours, reviews, photos, posts and performance metrics. We only write back to your profile when you explicitly approve a specific proposed change; we never modify a profile automatically.

We store the resulting data so the dashboard can display it without re-querying Google on every page view, and we refresh it on a schedule while the connection is active.

GrowthX's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How connection credentials are protected

OAuth access and refresh tokens are encrypted with AES-256-GCM before they are written to our database, using a key held only in the server environment. Tokens are never displayed in the product, never written to logs, and never sent to any third party other than Google itself when refreshing a session.

Automated analysis and AI providers

Recommendations in the product are generated by large language models. To produce them we send the relevant business content — for example a business profile's description, categories and services, or a page's text — to one of the model providers we use: Sarvam, Mammouth, Google Gemini, OpenAI, Anthropic or Groq. Which provider handles a given request depends on availability and the task.

We do not send your OAuth tokens, passwords or account credentials to these providers, and we do not permit them to use your content to train generalised AI models. If you would rather your Google data were never processed this way, do not connect a Google account — the crawl-based features work without one.

Who else sees your data

We do not sell your data or share it for advertising. Beyond the AI providers described above, your data is processed by the infrastructure we run on — our application hosting, managed Postgres database and Redis queue — and by the APIs you have chosen to connect. We disclose data if legally compelled to.

Retention, revoking access and deletion

Disconnecting a Google service from the integrations screen revokes our access with Google and deletes the stored tokens for that connection. You can also revoke access directly at your Google account permissions page.

Data we previously synced remains until you delete the associated project or ask us to remove it. Deleting a project removes its crawl data, synced Google data and generated recommendations. To delete your account and everything under it, contact us and we will action it.

Changes to this policy

If we change how we handle your data we will update this page and the date at the top. If a change materially affects data already collected, we will contact account holders directly.

Contact

Questions about this policy, or a request to access or delete your data, can be sent to the address on our website. We aim to respond within 30 days.