Privacy policy
Last updated 1 September 2026
What we hold, why we hold it, who else sees it, and how to get it deleted.
What we collect
Account: your name, email address, hashed password (or your Google account identifier if you sign in with Google), and the workspaces you belong to.
Project data: the sites, listings and repositories you add, everything an audit measures about them, and the findings, opportunities, experiments and reports built from those measurements.
Connected sources: access tokens and API credentials you choose to connect, encrypted at rest with AES-256. They are never displayed back, exported, or included in reports.
Operational records: sign-in times, audit-log entries of who changed what, email delivery records, usage counters, and provider billing events.
Anonymous audits: if you run the free audit from our home page without an account, we store the URL, the findings, a hashed form of your IP address and a random device token — so the same visitor cannot re-run it endlessly. The raw IP is not stored.
What we do not do
We do not sell your data, share it with advertisers, or use it to train third-party models. We do not put tracking pixels in our emails. We do not collect page content, form input or cookies from visitors to sites where you install the fix snippet — it fetches the fixes you approved and applies them, nothing more.
Why we hold it
To run the service you asked for: performing audits, storing their evidence, showing your history, sending the emails you enabled, enforcing plan limits, and taking payment. We keep audit evidence because the product’s value is that a figure can always be traced back to its source.
Who else processes it
Paddle.com Market Ltd — payments and subscriptions as merchant of record; receives your billing details directly, not through us. Resend — transactional email delivery. Google (Search Console, Analytics, PageSpeed Insights), DataForSEO, GitHub and public app-store endpoints — only for the sources you connect. Our servers and database are hosted in the EU.
Access by our staff
Our staff do not browse your reports. Access to the content of your audits — findings, evidence and generated reports — is switched off by default in our own administration tools, which show counts rather than content.
When you ask us for help with something we cannot diagnose from counts alone, a member of our team can grant themselves access to one workspace for up to 24 hours. Doing so requires a written reason, is recorded against that person’s name, and expires by itself. Everything else our staff can see — your plan, your subscription state, how many projects and audits exist — is operational information rather than the content of your work.
Activity records
We keep a record of changes made in your workspace: who made the change, what changed, when, and the IP address and browser it came from. We keep it to answer security questions, to resolve disputes about what happened to an account, and so that a workspace owner can see who on their team changed something.
The record excludes passwords, tokens and integration credentials — those are never written to it. It is append-only: nobody, including us, can edit or delete an entry. We keep it for 24 months, and entries relating to billing or to a suspension for seven years, because those are what a payment dispute or a legal request asks about.
Suspensions and appeals
If we suspend an account, we retain the reason, our notes, any appeal you file and the outcome — after the account closes, and for seven years. We keep it so that a decision can be reviewed, so we can answer a payment provider or regulator who asks about it, and so that the same account is not wrongly re-created. Read the acceptable-use rules in our terms.
How long we keep it
Account and project data: while your account exists, and for 30 days after deletion in backups. Anonymous free-audit records: 90 days. Email delivery logs: 12 months. Billing records: as long as tax law requires, usually 7 years, held largely by Paddle.
Your rights
Email privacy@aigrowthmanager.com to get a copy of your data, correct it, or have it deleted. We answer within 30 days. You can disconnect any integration at any time from the project’s integrations page, which deletes the stored credential immediately. If you are in the UK or EU you may also complain to your data protection authority.
Cookies
We use a session cookie to keep you signed in, a cookie to remember which workspace you are viewing, and — for the free anonymous audit — a device token cookie so one machine cannot run it repeatedly. There are no advertising or analytics cookies on this product.