GrowLove

Privacy Policy

Effective 2026-09-12

This is the plain-English version of what GrowLove does with your data. Short version: we keep what you give us, we don't sell it, we don't run ad trackers inside the app, and we let you delete your account. The marketing site (growlove.app) uses privacy-respecting Google Analytics — details below.

Who we are

GrowLove is a small relationship app for one or two people. It helps you keep a calm daily check-in with yourself or your partner. The company operating GrowLove is the data controller for everything on this page. If you want to reach us about privacy, write hello@growlove.app.

What we collect

We only collect what we need to run the app. That's:

GrowLove does not use advertising SDKs, product analytics tools such as Segment or Mixpanel, product attribution services, or a separate third-party crash-reporting service. Our sign-in and subscription services process technical service metadata; their SDK disclosures include usage or diagnostic data. We do not use those services to track you for advertising, and we do not place advertising cookies anywhere.

Marketing site analytics. Our marketing pages at growlove.app, including the homepage and public FAQ, run Google Analytics 4 with IP anonymisation enabled. It records aggregate visit data — pages viewed, referring source, country, device type, and whether you submitted the waitlist form — so we can tell which channels bring people here. It does not see your email address or any text you type into the waitlist form. Google Analytics cookies are limited to those marketing pages. The Privacy Policy and Terms pages shown inside GrowLove do not load analytics. The app displays its FAQ natively without loading the public FAQ page. If you'd rather not be counted on our marketing pages, most browsers and ad blockers can block Google Analytics with one click.

Where it's stored

Your data lives in an encrypted, managed database operated by a reputable cloud provider in the United States. Credentials and secrets are stored in encrypted secret storage, not in code or in our application logs.

Who has access

Only the GrowLove backend can read or write your data, and only under a least-privilege role limited to what the app actually needs. No third parties have direct database access, and we don't share your data with marketing partners, ad networks, or data brokers. A small number of GrowLove maintainers may access production data when investigating a bug you reported or when responding to a legal request.

How AI is used

AI processing permission is required to complete GrowLove onboarding. Before asking for it, the app explains what is shared with external AI services and links to this policy. We record your choice and the disclosure version. Shared AI processing requires permission from both current partners.

Depending on the feature, we send relevant profile and relationship preferences, locality names, questionnaire answers, reflections, notes, wishes, activity feedback and derived summaries. These can include sensitive relationship information you choose to provide. AI helps suggest activities and daily questions, organise wishes, create summaries and retrieve relevant memories. Photo files and sign-in credentials are not sent to these AI services. Text you write may itself contain identifying details, so avoid including information you do not want processed.

We do not use your content to train our own AI models. External services process requests under their API terms; retention and processing locations depend on the service. We do not promise that all providers retain no data.

You can withdraw permission in Us → Settings → Privacy & consent → AI & your data. This stops new AI requests, including background processing. It cannot recall a request already sent. Your saved content and account controls remain available. If you enable AI again, eligible saved content may be processed; not every previously skipped task is replayed. A material change to this disclosure requires a new choice in the app.

How long we keep it

We keep your saved data while your account is active. When an in-app deletion succeeds, we erase your profile details, answers, private notes, preferences, AI permission records and authored content from the live database, and remove your sign-in identity. This includes your content copied into shared activity history. Joint plans, activity memories and AI memory for your former couples are also removed. Your partner keeps their account and independently authored private content.

Photos become unavailable through the app when their references are removed. Their files enter a durable deletion queue, which our maintenance process drains; failed file deletions are retried. Minimal technical account and pairing markers remain to reject old sessions and keep surviving records consistent. They contain no profile details, answers or photos. Statistics that no longer identify a person may remain.

Encrypted database backups can retain a copy after it is removed from the live app. Our database provider, Neon, documents a 30-day retention period for its encrypted backups. Separately, we schedule automatic deletion of the keys for our temporary encrypted release backups 35 days after creation, making those copies unrecoverable. These backup copies are used for recovery and are not accessible through the app during normal use.

How to delete your account

In-app: open Us → Settings → Account → Delete account. Account settings are also available from the AI permission screen before onboarding. You'll be asked to confirm. Deletion cannot be undone; you can export your data first. If the app reports an error, retry deletion.

By email: write to hello@growlove.app from the email on your account, with the subject line "Delete my account." We aim to confirm within 5 business days.

Your rights

Wherever you live, you can ask us to access, correct, export, or delete your data. If you're in the EU, EEA, UK, or Switzerland, the GDPR gives you formal rights to access, rectification, erasure, restriction, portability, and objection. If you're in California, the CCPA/CPRA gives you the rights to know, delete, correct, and opt out of the sale or sharing of personal information (we do not sell or share personal information, so the opt out doesn't apply in practice).

To exercise any of these rights, write to hello@growlove.app. We'll respond within 30 days. We won't charge you for a reasonable request and we won't ask for more identity proof than we need to confirm the request is yours.

Children

GrowLove is for adults in adult relationships. It's not designed for or directed to children under 16, and we do not knowingly collect data from children. If you believe a child has signed up, write to hello@growlove.app and we'll remove the account.

International transfers

Our backend is hosted in the United States. External AI services and their hosting providers may process data in the United States and other countries, as described in their linked policies. Do not assume that choosing a model restricts processing to the model developer's country. Contact us for information about the safeguards applicable to your data.

Security

Connections between the app and our backend use TLS. Credentials and secrets are kept in encrypted secret storage, never in code. Our backend runs under a least-privilege role limited to what the app actually needs. We don't promise the impossible — no system is perfectly secure — but we don't take shortcuts on the obvious things.

Changes

If we change this policy in a way that affects how we handle your data, we'll update the effective date at the top and email active users before the change takes effect. Cosmetic edits (typos, link fixes) may land without a notice.

Contact

Email: hello@growlove.app
Postal mail: available on request.

← Back to growlove.app