Privacy Policy
Last updated: September 19, 2026
Grow One works because you trust it with your email, your calendar, your voice, and your notes. This policy explains — plainly — what we collect, why, who processes it, how long we keep it, and how you delete it.
A Spanish translation is available at privacy-es.html. If the two ever differ, this English version controls.
Who we are
Grow One is made by Grow Forward MC LLC, a limited liability company based at 2950 Clay St #201, San Francisco, CA 94115, USA. Grow One is an AI personal assistant iOS app: it helps with email, calendar, tasks, meeting notes, thought capture, and topic digests, with an optional Social Agent for social publishing and insights.
For anything in this policy, contact us at ai@growfmc.com.
What we collect
Everything below is collected only after you grant it — each source is a separate, explicit connection or upload you make in the app.
Account and sign-in
You sign in with Google or with Sign in with Apple (some longer-standing accounts use an email address and password instead). From that sign-in we receive and store your name and email address; Google also passes a link to your profile picture, which our authentication provider, Supabase Auth, keeps. When you later connect Gmail or Google Calendar, the userinfo.email and userinfo.profile scopes give us that same name and email. If you use Apple's "Hide My Email", we only ever see the relay address Apple gives us. During onboarding you answer a few plain questions about yourself or your business (your name, what you do, how you want the assistant to behave); those answers are stored with your account and are the basis of what the assistant knows about you.
Gmail (via Google OAuth)
If you connect Gmail, we request the gmail.modify scope. We use it to read your inbox so the assistant can classify and summarize your email, and to send replies — but only replies you approve. Grow One never auto-sends email unless you explicitly opt in to that behavior. AI-drafted replies are stored in our database, not in your Gmail drafts.
Google Calendar (via Google OAuth)
If you connect Google Calendar, we request calendar.events (read and write events) and calendar.calendarlist.readonly (to list your calendars). Events are created only when you confirm them.
Voice and meeting audio
Voice recordings and meeting audio you capture are transcribed to power notes, tasks, and recall. Meeting audio is stored with its note — deleting the note also deletes its recording.
Voice recognition data (voiceprints)
If you use speaker-labeled meeting notes, Grow One stores short voice reference clips ("voiceprints") of speakers you name — including, optionally, your own voice via "This is me." Because they identify a person by their voice, we treat them as sensitive. They are used for one purpose only: to recognize and label who said what in your future meeting transcripts. They are created only when you name a speaker, stored in a private bucket readable only by our servers (never by any app client), never used for advertising or for identifying anyone outside your own meeting notes, never shared, and never sold. When speaker identification runs on a recording, the reference clips of the speakers you named are sent to OpenAI's transcription API for that recording only, under the same no-training API terms as everything else we send.
Deleting them: you can have the app forget any speaker (which deletes that speaker's voiceprint), and deleting your account permanently removes every voiceprint — the audio files and the database records. You can also email ai@growfmc.com to have them removed.
Photos
Photos you upload — for chat vision, schedule scanning, or the social content library — are processed for the feature you used them in.
Contacts
Contacts you create in the app, or that are derived from your email and meetings, are stored to build your personal contact history.
Thoughts and notes
Ideas and notes you capture are stored so the assistant can recall them when you ask.
What the assistant remembers
To answer you from your own information, the assistant keeps a memory of what you tell it and what you connect: facts you confirm about yourself and the people you mention (for example a partner's name, your kids' school, a client's timeline), summaries of your chats, and short excerpts of your notes, meeting transcripts, Notion pages, and email context. Much of this text is also stored as embeddings — numeric representations that let the assistant find the relevant passage when you ask a question. Memories and facts are visible in the app under Settings, where you can correct or delete them; deleting a note, page, or your account deletes its embeddings with it.
Notion
If you connect Notion, you choose in Notion's own screen which pages to share with Grow One. We read the text of those pages and store it, with embeddings, so the assistant can answer from them; the copy is refreshed about every 30 minutes and removed when you un-share a page, disconnect Notion, or delete your account. With your permission the app also writes to Notion: it saves your meeting notes and trip guides to a page you pick, and creates pages or database rows only when you ask and confirm on screen. It never deletes anything in Notion.
Stripe
If you connect Stripe, you create a restricted API key in your Stripe account and paste it into the app. That key lets us read your customers, invoices, payments, payouts, and disputes, and create customers and invoices when you ask and confirm; it cannot move money. We check for new Stripe events about every 15 minutes and keep a ledger of them so the assistant can tell you who paid, who owes you, and when a payment fails. Your customers' names and emails from Stripe may be used to recognize them in your email and contacts. Disconnecting Stripe deletes the key and the payment history stored with your account.
RevenueCat and App Store Connect (your own apps)
If you publish apps and connect RevenueCat, you create a read-only API key in your RevenueCat project and paste it into the app (or, where available, approve a read-only OAuth connection). That key lets us read your app's aggregate charts: revenue, subscribers, trials, churn, new customers, and breakdowns by store, country and plan. It cannot see your app's individual users and cannot change anything. We take one snapshot per day and keep a daily history so the assistant can answer questions, notice a week-over-week shift, and write a weekly read. Optionally you can also connect an App Store Connect API key with the Sales and Reports role; it lets us read your daily download counts, which app versions had activity, and your public App Store reviews — nothing else about your apps or your Apple account. You can add markers (a release, a price change, a campaign) to a timeline so the assistant can compare before and after. Disconnecting deletes the keys, the stored daily history, and the timeline for that app.
Social account data (via Zernio)
If you connect social accounts (Instagram, Facebook, LinkedIn, and others we support) through our publishing partner Zernio, we access your own posts, comments on your posts, and follower statistics, and we publish the posts you approve. We do not read the private messages of those social accounts.
WhatsApp Business inbox (via Zernio)
If you connect a WhatsApp Business number (Creator plan), customer conversations on that number — messages and any media — reach us through Zernio so the assistant can summarize threads and draft replies for you to send. Those conversations belong to you and your customers; we process them only to provide the inbox features, we never send a message you did not approve, and they are deleted when you delete your account. Your WhatsApp app itself is unaffected.
Your website pages (landing pages)
On the Creator plan you can build one-page websites in the app. A page is public on the internet the moment you publish it, at an address you choose under pages.growone.io, and anyone with the link can open it. We store the page itself (its text, design and address), the photos you add to it (in a public storage bucket, so the page can show them), an optional preview image and description for when the link is shared, a count of how many times the page was opened, and your conversation with the website assistant. Every published page carries a small "Made with Grow One · Report" footer so visitors can report abuse.
What the website assistant knows, and does not know. Pages are written and edited by DeepSeek (see the provider table below). To build a page, DeepSeek receives only a short brand guide we assemble from what you have given the app: your or your business's name, whether the account is a business, solo professional or personal account, the business type, brand colors and tone of voice you set (or, from your social strategy if you built one, its brand colors, fonts, visual style, tone of voice, business overview and products and services), the colors, fonts and visual style read from a website you asked us to match (our server fetches only the one page whose address you paste, and keeps a short description of its look), your phone number and website from your profile, product names, descriptions and prices from Stripe if it is connected, confirmed facts about your business, your contact details, your work role and hours and your home city, whether you have a logo, the design instructions we (Grow One) write for the builder, the page being edited (including its logo and photos), and the messages you type in the website assistant. That is the whole list. DeepSeek never receives your email, calendar, meeting notes, contacts, thoughts, chat history with the main assistant, the assistant's memories about you, your uploaded documents, your location, or anything about other people. You can see the exact brand guide the builder gets at any time under My business / About me inside the website workspace.
Visitors to your pages (people who fill in your forms)
If your page has a contact or sign-up form, a visitor's submission is stored for you: the name, email, phone and message they typed, any extra fields the form asked for, the page it came from, the visitor's browser type, and a one-way hash of their IP address that we keep only to stop spam. To filter spam we also check that the email's domain has a real mail server (a DNS lookup of the domain, not of the visitor) and refuse known throwaway-email domains. Submissions appear under Leads or Responses in the app. If you are a business and chose to, they also reach your Sales & Customer Hub — and any team members, Slack channel or push notification you set up for lead alerts — where the assistant may draft a reply for you; a reply to a form submission is never sent automatically. Visitors are not tracked across sites: pages contain no analytics, advertising or tracking scripts. Submissions are deleted when you delete the page or your account. A visitor who wants their submission removed can ask the page owner, or write to us at the address below and we will remove it.
Device and technical data
We keep this deliberately minimal. Grow One contains no third-party analytics, advertising, or tracking SDKs — no ad identifiers, no cross-app tracking, no behavioral profiling. What we do process: a push-notification token so your iPhone can receive the alerts you asked for, and standard server logs (IP address, timestamps, request paths) kept for security and reliability. Crash reports reach us only if you've chosen to share analytics with app developers in your iOS settings — through Apple, not through any SDK we added.
Location (iPhone only)
The first time you open the iPhone app after this feature ships, iOS asks once whether Grow One may use your location. If you allow it, City mode turns on; if you decline, nothing is read or stored and iOS will not ask again. You can change this any time in Settings → Privacy & Data, in one of two modes. City: when you open the app, your iPhone converts its position to a city name using Apple's own geocoder and we store only the city, region and country — never coordinates. Precise: the same, plus your exact coordinates are sent with a chat or search request so "near me" means where you are; those coordinates are used for that one request and are not stored. Turning location off deletes the stored city. Nothing is read in the background, and web browsers never have access to location.
Google API Services — Limited Use disclosure
Grow One's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, for data obtained through Google APIs:
- We do not use it for advertising.
- We do not sell it.
- No humans read it, except with your explicit consent, for security purposes, or to comply with applicable law.
AI providers that process your data
To generate features, relevant content is sent over encrypted connections to the AI providers below, which process it solely to deliver the feature you used. We use their commercial APIs. Per their API terms, Google, OpenAI, Anthropic and DeepSeek each state that data submitted through their APIs is not used to train their models; we rely on those contractual commitments and do not grant any provider permission to train on your data. Their processing is governed by their own terms and privacy policies, linked below.
Meeting recordings and transcripts are never used to train AI models — not by us, and not by our providers. Audio is sent for transcription and the resulting transcript is sent for summarizing, both on paid commercial API tiers whose terms exclude training on submitted content. We do not use your recordings, transcripts, notes, or email to train any model of our own, and we have no model of our own to train.
| Provider | What it processes for you | Their policy |
|---|---|---|
| Google Gemini | Chat, email classification, summaries, image understanding and generation | Privacy policy |
| OpenAI | Voice transcription, voice sessions and dictation; meeting-recording transcription and speaker identification (which sends the short voiceprint reference clips for that recording); embeddings; note organization | Privacy policy |
| Anthropic | Email reply drafting; social strategy and content; live meeting summaries; extracting facts and memories from your conversations; the assistant's daily suggestions and interview questions; chat titles | Privacy policy |
| DeepSeek | Website builder only — writing and editing your landing pages from the brand guide and your instructions in the website assistant (see "Your website pages" above for the exact list of what it receives and never receives) | Privacy policy |
| Exa | Web search queries derived from your requests (search only — Exa is not a model-training provider for us) | Privacy policy |
Some features have alternate providers wired in that are not enabled today (Groq for speech-to-text, Deepgram for read-aloud, Perplexity and Tavily for web search, Moonshot's Kimi as an alternate chat model). If we ever switch one on, we add it to this table before it processes any of your data.
The current list, with a link to each provider's own privacy policy, is also shown inside the app under Settings.
Data about other people
Some of what you connect or create contains information about people who are not Grow One users: the people you email, the people in a meeting you record, your customers on WhatsApp or in Stripe, people you mention in notes and memories, and the visitors who fill in a form on your page. For that data you decide what to connect, record and keep; Grow One processes it only on your instructions to run the features you use, never for advertising, profiling or sale, and it is deleted with your account. If you are one of those people and want something removed, tell the Grow One user you dealt with, or write to us at the address below and we will help.
Service providers (infrastructure)
We rely on a small set of infrastructure providers to run the service:
| Provider | Role |
|---|---|
| Supabase | Database, authentication, and file storage |
| Vercel | Hosting and compute |
| Zernio | Social publishing and public-content insights |
| Apple | Push notifications |
| Google Fonts | Font files for the app's interface and for published pages; Google receives the device's IP address when a font loads |
| Slack | Only if you connect a Slack webhook |
| Resend | Transactional email |
Each provider is engaged only to perform its role for us. Zernio processes your social account connections and your public social content to publish and report on your behalf; its processing is governed by its own terms and privacy policy (at zernio.com), and we do not grant it permission to use your data for anything beyond providing that service.
What we never do
- We never sell your personal data.
- We never show third-party advertising.
- We never share your data with data brokers.
- We never use your data to train AI models, and we don't grant our AI providers permission to either.
- We never make automated decisions about you with legal or similarly significant effects. The assistant sorts, drafts, suggests and — only in the autonomy modes you switch on — acts on routine tasks such as replying to an email or publishing a post, and you can turn every mode off.
How we protect it
Data moves over encrypted connections (TLS) and is stored encrypted at rest by our infrastructure providers. Database access is scoped to your account with row-level security, and the most sensitive stores — voiceprints and captured thoughts — are additionally restricted so only our servers can read them, never any app client directly. Provider credentials and API keys are held server-side only. No system is perfectly secure, which is why we also make the commitment below.
If there's a data breach
If a security breach affects your personal information, we will notify you promptly — without undue delay, and within the timelines applicable law requires — and tell you what happened, what data was involved, and what we're doing about it.
How long we keep things
- Email: full bodies of email alerts are deleted after 90 days; remaining stored email content is deleted after 1 year. Summaries are kept for your own contact history, so the assistant still remembers who you've talked to.
- Social library photos: published photos are removed from our storage 10 days after publishing.
- Meeting audio: kept with its note; deleting the note deletes the recording.
- Recording consent records: kept for 3 years, then deleted automatically. These record that you were shown our recording notice, and what you told us about each recording (whether it was just you, or a conversation you confirmed you had informed). They never contain any audio, transcript, note content, or the names of anyone in the conversation.
- Voiceprints: kept until you have the app forget the speaker, or until you delete your account.
- Chats, memories, and facts: kept until you delete them in the app or delete your account.
- Notion index: refreshed on each sync; a page's copy is removed when you un-share it, disconnect Notion, or delete your account.
- Stripe: the key and the payment ledger are deleted when you disconnect Stripe or delete your account.
- RevenueCat and App Store Connect: the keys, the daily metrics history and the timeline are deleted when you disconnect that app or delete your account.
- WhatsApp conversations: kept while the number is connected; deleted when you delete your account.
- Website pages, photos and form submissions: kept until you delete the page or your account. Deleting a page removes its form submissions and the photos uploaded for it (a photo still used by another of your pages stays). A deleted or unpublished page stops being served within about a minute. The website assistant's working copies of a page are kept with your account and deleted with it.
- Server and security logs: our hosting provider's request logs are held briefly for reliability; our own security log (IP address, browser type, request path, event) is kept for 90 days and then deleted automatically.
- Connections: you can disconnect Google, Notion, Stripe, WhatsApp, or social accounts at any time; disconnecting removes the stored credential. The authorization itself also stays listed in your Google, Notion or Stripe account until you remove it there.
- Account deletion: immediate. Deleting your account in the app removes your data, storage files, and social account connections through a verified deletion pipeline. One narrow exception: the recording consent records described above are kept for the remainder of their 3-year window, because they are the record of what you told us about recordings you made, and we may need them to establish or defend a legal claim. Both the GDPR (Art. 17(3)(e)) and the CCPA (§ 1798.105(d)) permit retaining data for that purpose. They hold no conversation content — only that a notice was shown and what you asserted — and they are deleted automatically when the window closes. Two things that hold no personal data also remain: an anonymous monthly total of AI usage that cannot be linked back to you, and a bare deletion record (an internal id and a timestamp). Our social publishing partner Zernio is told to disconnect your accounts; it keeps its own records under its policy.
Your rights (including California)
You can exercise these directly, self-serve, in the app:
- Access: your data is visible to you inside the app — your email summaries, notes, contacts, and settings.
- Deletion: delete your account in the app and everything is removed, immediately and completely — except the narrow recording-consent exception and the short-lived server logs described above.
California residents have these rights under the CCPA/CPRA, including the right to know, delete, correct, and not be discriminated against for exercising them. We do not sell or share personal information as those terms are defined in the CCPA. For any request you can't complete in the app, email ai@growfmc.com.
How to exercise your rights
- In the app: your data is visible on each screen, every connection (Gmail, Calendar, social) can be disconnected in Settings, and account deletion in Settings removes everything immediately.
- By email: send your request to ai@growfmc.com from the email address on your account — that's how we verify it's really you. We respond within the timelines applicable law sets (generally 45 days under the CCPA and one month under the GDPR). California residents may use an authorized agent with written proof of authorization.
California "Shine the Light"
We do not disclose personal information to third parties for their own direct marketing purposes (Cal. Civ. Code § 1798.83), so there is nothing to opt out of — but you're welcome to ask at ai@growfmc.com.
Do Not Track and Global Privacy Control
We don't track you across other sites or apps, show ads, or sell or share personal information — so there is nothing for a "Do Not Track" or Global Privacy Control signal to turn off. This website sets no tracking cookies (only a theme preference stored on your own device).
International users and data transfers
Grow One is operated from the United States, and your data is processed and stored in the US. If you use Grow One from outside the US, you understand that your data is transferred to and processed in the US, where privacy laws may differ from those of your country. For users in the EEA, UK, and Switzerland, where the law requires a transfer mechanism we rely on recognized safeguards such as the European Commission's Standard Contractual Clauses and, where a provider participates, the EU–US Data Privacy Framework.
Legal bases (EEA/UK users)
Where GDPR-style laws apply, we process your data on these legal bases: performance of a contract (running the assistant you signed up for), consent (every data source — Gmail, Calendar, voice, photos, social — is a separate opt-in connection you can withdraw at any time), legitimate interests (securing and improving the service), and legal obligation (where law requires retention or disclosure). You also have the rights to access, rectification, erasure, restriction, objection, and portability, and may lodge a complaint with your local supervisory authority.
Children
Grow One is not directed at children under 13, and we do not knowingly collect personal information from children under 13.
Changes to this policy
If we change this policy, we'll announce it in the app and on this site — and for material changes, we'll tell you before they take effect and refresh your consent where the law requires it. The "Last updated" date at the top always reflects the current version.
Contact
Questions about privacy at Grow One:
ai@growfmc.com
Grow Forward MC LLC · 2950 Clay St #201, San Francisco, CA 94115, USA
See also our Terms of Service.