Privacy Policy
What we hold, where it lives, and how to get it back.
Last updated: October 9, 2026
The short version
- We never sell your data, never show ads, and never use your records to train models.
- Only you, and teammates you invite, can see your account. Isolation is enforced by the database itself, not by the interface.
- Your data is stored in the United States on Google Cloud infrastructure.
- You can export or delete everything at any time, from inside the app.
This summary is for orientation only. The numbered sections below are the operative policy.
01 Who is responsible
GrowthSeeded is operated by an individual sole proprietor based in Dhaka, Bangladesh ("we", "us"). For your own account information, we are the data controller.
For information you record about other people, the roles are reversed. See Section 3, which is the most important section of this policy for most users.
Questions, requests, or complaints: support@growthseeded.com.
02 What we collect
Deliberately little. There are three categories:
- Account information. The email address you sign up with. Your password is handled entirely by Firebase Authentication and is never visible to us in any form.
- Content you enter. Everything you type into the app: names, companies, profile URLs, email addresses, phone numbers, notes, sequence progress, and dates. We do not generate, enrich, purchase, or supplement any of it.
- Basic operational data. Sign-in timestamps and standard technical information any web service receives, used to keep the service running and secure.
There is no analytics tracking, no advertising pixel, and no third-party session recording in the application. We do not build a behavioral profile of how you use it.
03 Data about other people
GrowthSeeded exists to record information about people you want to stay in contact with. Where data protection law applies to that information, you are its controller and we act as your processor, handling it only on your instructions and only to provide the service to you.
In practice this means:
- You decide who to record and what to record about them
- You are responsible for having a lawful basis to do so
- If one of those people asks you about their data, that request goes to you, and we will help you answer it
We never contact anyone you record. The application has no outbound sending capability of any kind, so nobody in your records will ever receive a message from us.
The Opted Out status exists specifically so that a request never to be contacted again can be recorded permanently and honored, including a warning if that person is ever re-added.
04 Why we process it
To provide the service you signed up for, and nothing beyond that: authenticating you, storing and syncing your records, calculating what is due, and processing payment if you subscribe.
Where GDPR or UK GDPR applies, our lawful bases are performance of a contract (providing the app you have signed up for), legal obligation (tax and accounting records for payments), and legitimate interests (keeping the service secure and preventing abuse).
05 What we never do
Stated plainly because these are the questions people actually have:
- We do not sell, rent, or trade your data to anyone, ever
- We do not use your data or your records to train machine learning models
- We do not serve advertising, and the product carries none
- We do not share your data with other users, in any aggregated or anonymized form
- We do not connect to LinkedIn or any other platform, so nothing is sent to or retrieved from them
06 Who can see your data
You, and anyone you invite to your team. A teammate sees the same records you do until you remove them. Every account is isolated at the database level by security rules tied to the account identifier Firebase itself assigns, which cannot be forged from browser code. A signed-in user can reach only their own account, or one they were invited to, and nothing else. Everything outside those paths is denied by default.
We do not routinely access the contents of individual accounts. Access happens only where necessary to maintain the service, investigate a fault, or respond to a support request you have initiated, and no more of it than the situation requires.
The app includes a security self-test in its Privacy and Security panel that attempts a real database read while signed out and reports whether the database refused. It verifies the actual protection rather than asking you to trust a description of it.
07 Service providers
We use a small number of third parties to run the service. Each receives only what it needs to do its job.
- Google Cloud / Firebase: Authentication, database, hosting, server functions. Receives: Your account email and all content you enter
- Paddle.com Market Ltd: Payment processing as Merchant of Record. Receives: Billing details and email, only if you subscribe. We never see or store your card details.
- Google Fonts: Typefaces used in the interface. Receives: Your IP address, as with any loaded web resource
- Cloudflare (cdnjs): Spreadsheet library used for backup and restore. Receives: Your IP address when the library loads
- Brevo: Account emails (such as verification and team invites) and product updates, which you can unsubscribe from at any time. Receives: Your email address and name
- Cloudflare: Hosting for growthseeded.com and cookie-free visit counts. Receives: Your IP address when you visit
None of these providers is permitted to use your data for their own purposes. If this list changes materially, this page is updated.
08 Where it's stored
Your data is stored on Google Cloud infrastructure in a United States multi-region configuration, spread across several data centres for redundancy.
If you are in the European Union, the United Kingdom, or elsewhere outside the United States, this means your data is transferred to and processed in the United States. Google Cloud provides Standard Contractual Clauses for such transfers, which is the mechanism relied on here.
09 How long we keep it
For as long as your account exists. Deleting an individual record removes it immediately from your account.
Two things persist deliberately after a deletion, and it is worth knowing about them:
- A removal registry retains a minimal trace of deleted records, enough to warn you if you later re-add someone you previously removed or who opted out. It holds the most recent 500 entries and not the full original record.
- Payment and invoice records held by Paddle are retained as long as tax and accounting law requires, independently of your account.
Requesting account deletion removes your account document and all associated records, including the removal registry. This cannot be undone, so export a backup first if you want one.
10 Your rights
Most of these you can exercise yourself, immediately, without asking:
- Access and portability. The built-in backup exports every record and its full history to a spreadsheet, at any time.
- Correction. Every field is editable in the app, including completion dates.
- Deletion. Delete individual records in the app, or email us for full account deletion.
If you are in the European Union or the United Kingdom, you also have the right to object to or restrict processing, to withdraw consent where processing relies on it, and to lodge a complaint with your local data protection authority. You do not need to contact us first, though we would rather you did so we can fix it.
Requests to support@growthseeded.com are answered within 30 days, usually much sooner. We do not charge for them.
11 Cookies and local storage
The app uses authentication tokens from Firebase to keep you signed in between visits. That is a functional necessity, not tracking, and there is no way to use an account without it.
There are no advertising cookies, no analytics cookies, and no third-party tracking cookies in the application.
Campaign pages (such as Build Your 30) may load LinkedIn or Meta ad measurement only after you agree to it on that page. The rest of growthseeded.com sets no cookies.
12 Security
Passwords are managed by Firebase Authentication and are never stored by us or visible to us. Data is encrypted in transit and at rest by Google Cloud. Account isolation is enforced by database rules rather than by application code, which means a bug in the interface cannot expose one account's data to another.
Billing fields such as your plan and lead cap are readable but not writable by the browser; only a server-side function that verifies a signed payment notification can change them.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority as the law requires.
13 Children
GrowthSeeded is not directed at children and is not intended for anyone under 18. We do not knowingly collect data from anyone under that age. If you believe a child has created an account, contact us and it will be removed.
14 Changes
The current version always appears on this page with its date at the top. For material changes we will give notice by email or in the app before they take effect.
Want something explained, exported, or deleted?
Privacy requests go to the same inbox as everything else and are handled properly. No form to fill in, no identity-verification maze beyond confirming you control the account.