Last updated: July 19, 2026
GrowthAtlas ("we", "us", or "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
1. Information We Collect
Account information: When you register, we collect your name, email address, and password (stored as a secure hash).
Usage data: We collect information about how you interact with the Service, including pages visited, features used, AI generation counts, and crawl activity.
Website data you provide: When you import website pages or competitor data, that information is stored to provide the Service to you.
Connected Google services (optional): If you choose to connect Google Search Console or Google Analytics 4, we store:
- An encrypted OAuth refresh token (we never receive or store your Google password)
- Your Google account email address, if returned during authorisation
- Property or site identifiers (e.g. GA4 property ID, Search Console site URL)
- Aggregated performance data imported from your connected account, such as search queries, impressions, clicks, rankings, page paths, sessions, active users, page views, and engagement metrics
We import only data needed to display SEO and traffic insights in your workspace. We do not access Google Ads, modify your Analytics configuration, or export individual end-user identifiers from Google.
Social Hub / Instagram (optional): If you connect an Instagram professional account through Meta (Instagram Login), we store:
- An encrypted OAuth access token (never exposed to the browser or frontend)
- Instagram professional account identifiers, usernames, display names, and profile picture URLs returned during connection (no Facebook Page required)
- Publishing metadata (scheduled posts, captions, hashtags, destination status) and aggregated insights metrics for your connected accounts
- Competitor intelligence: competitor usernames you enter manually for tracking. We do not scrape Instagram, do not use Meta Business Discovery in this release, and do not import competitor media as reusable assets.
- Media you upload to the Social Studio (images/videos stored privately for publishing)
- Rights declarations you submit before any imported asset may be used (immutable audit record of the declaration text you agreed to)
We do not sell Platform Data, use it for advertising, or share it with third parties except as needed to operate the Service (see Section 3).
Payment information: We do not currently store payment card details directly. Billing is handled by a PCI-compliant third-party processor (Paddle).
Communications: If you contact us via the contact form or email, we retain those communications to respond to your enquiry.
2. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Service
- Display Search Console and Analytics insights in your project dashboard
- Run scheduled synchronisation to keep connected Google data up to date
- Publish, schedule, and analyse social content on your connected Instagram accounts
- Provide competitor tracking for usernames you enter manually (no scraping; no Business Discovery sync in this release)
- Generate AI-assisted captions and content ideas (prompts may include post captions and project context; we do not send OAuth tokens or unnecessary personal data)
- Support content strategy features (e.g. topic suggestions based on search performance, where enabled)
- Enforce plan limits and usage quotas
- Send transactional emails (account verification, password reset, connection health alerts)
- Respond to your support enquiries
- Monitor for abuse or unauthorised usage
We do not sell your personal data to third parties. We do not use your connected Google Analytics or Instagram data for our own marketing or advertising analytics.
3. Data Sharing
We share limited data with:
- Meta (Facebook/Instagram) — when you connect Instagram or publish content, we call Meta APIs using your authorisation. Data is used only to provide Social Hub features to your account and is subject to Meta's Platform Terms and Privacy Policy.
- OpenAI — content generation prompts are sent to the OpenAI API. We do not send personally identifiable information or OAuth tokens in prompts. Review OpenAI's privacy policy.
- Google — when you connect Search Console or Analytics, we call Google APIs using your authorisation. Data is used only to provide the Service to your account and is subject to Google's Privacy Policy. We do not share your Google data with other customers or third-party advertisers.
- Paddle — payment and subscription data for billing. See Paddle's privacy policy.
- Hosting providers — our infrastructure providers process data as data processors under our instructions.
4. Data Retention and Deletion
We retain your account data for as long as your account is active. If you close your account, we will delete your data within 90 days, except where we are required to retain it for legal compliance.
Google integrations: If you disconnect Google Search Console or Google Analytics in the app, we delete the connection and remove associated imported metrics. OAuth tokens for disconnected integrations are deleted.
Social Hub / Instagram:
- Platform Data obtained through your connection is deleted or anonymized when you disconnect in GrowthAtlas, when Meta notifies us of deauthorization, or when you submit a verified data-deletion request through Facebook's Apps and Websites settings.
- Private media you uploaded is deleted when you remove it, when a project is purged, or when your account is closed.
- We retain minimal publish-attempt audit metadata (timestamps, success/failure status) with platform payloads scrubbed, where needed for billing disputes or operational integrity.
- Competitor intelligence uses public data only; we do not store competitor media files. Competitor import as a reusable Studio asset is disabled and not available without separate Meta permission.
- Retention generally follows Meta's guidance to delete Platform Data when no longer necessary for the stated purpose; absent a documented legitimate-purpose exception, retention should not exceed 120 days after the data is no longer needed.
Requesting deletion of Instagram/Facebook data: You may disconnect Instagram in your project settings at any time. You may also request deletion via Facebook → Settings → Apps and Websites → remove GrowthAtlas → Send Request. Our data-deletion callback initiates cleanup automatically; you will receive a confirmation code and status URL. You may also contact us.
5. Security
We implement appropriate technical and organisational measures to protect your data, including encryption of OAuth tokens at rest (Google and Meta), HTTPS-only access to the platform, project-scoped data isolation, and server-side authorization for all social actions.
6. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal data. You can disconnect Google and Instagram integrations at any time from your project settings. To exercise other rights, please contact us.
7. Cookies
We use essential cookies for session management and CSRF protection. Our public marketing website may use optional analytics cookies with your consent — see our Cookie Policy for details. Connecting Google Analytics or Instagram inside the GrowthAtlas app uses provider APIs server-side; it does not set provider analytics cookies in your browser for those features.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.
9. Contact Us
If you have questions about this Privacy Policy or your personal data, please contact us.