Security & data
Security & Data
Here’s where your data is stored, what we access, and what we don’t keep. We cover what we do today separately from the principles we’re building the product on.
Last updated: September 24, 2026
At a glance
Early-access applications are stored in a database in Frankfurt (EU). Advertising and measurement tools run only if you consent. The product is being built with read-only Search Console access, data in the EU, mandatory two-step verification for owners and admins, and only summarized data sent to AI.
1. What data do we process today?
Growado has not launched yet. Today we process data in two places: the website and the early-access list.
- Website: our hosting provider’s server logs (IP address, browser information, time of visit). Analytics and marketing cookies load only if you consent.
- Early-access form: full name, work email, role, company, team size, and, if you share it, your biggest challenge in organic growth; also the campaign that brought you to the site and your cookie choice.
- Confirmation email: one email confirming we received your application.
For full details, see the Privacy Policy and the KVKK Information Notice.
2. Where is your data stored?
- Early-access applications: in a Supabase database in the Frankfurt (Germany, EU) region.
- Website: hosted on Vercel.
- Confirmation emails: sent through Resend.
- Ad measurement: sent to Google (GA4, Google Ads) and Meta only if you consent.
The applications table can’t be accessed from the browser; only the site’s server can write to it.
3. What principles is the product built on?
These are the design principles for the product we’re building. When the product launches, we’ll update this page to match the actual implementation.
- Google Search Console: we ask for read-only access and use data only from the property you choose. You can disconnect at any time.
- Website crawling: crawls only public pages on your project’s domain, respects robots.txt, and is limited by a page budget per project.
- Data location: product data is stored in a database in Frankfurt (EU).
- Access keys: connection keys are encrypted in the application and can be rotated.
- Account security: two-step verification is available to everyone and is required for Owner and Admin roles.
- Separation: each organization’s data is kept apart from the others, and automated tests check this.
- AI: only summarized or aggregated data is sent to the AI provider.
- Export and deletion: you can export your data and ask us to delete it; deletion also covers connections and stored files.
- Access logging: access to production data is limited to named people and logged.
4. What we don’t do
- We don’t sell your data.
- We don’t use your Search Console data for advertising, and we follow Google’s user data policy (Limited Use).
- We don’t ask for health data or other special categories of personal data; uploading such data is against our terms of use.
- We don’t present certifications we don’t have.
5. Certifications and compliance
We don’t hold SOC 2 or ISO 27001 certification today. We are building the controls these standards require (access management, change management, logging, and backups with a restore test) from the first version of the product. An audit will start when customers need it.
We meet our obligations as a data controller under KVKK (Turkish data protection law). Visitors in the EU/EEA can find their GDPR rights in the Privacy Policy.
6. Service providers
- Today (website and early access): Vercel (hosting), Supabase (database, Frankfurt), Resend (email), and Google and Meta (ad measurement, only with consent).
- Added with the product: Clerk (authentication), Cloudflare (scheduled jobs), Bunny (file storage, EU), Sentry (error monitoring), PostHog (product analytics in the EU region), and Anthropic (AI).
We will publish the current list before the product launches.
7. Reporting a vulnerability
If you believe you’ve found a security vulnerability, please email the address below. We will confirm we received your report and keep you informed. Please give us time to fix the issue and do not access other users’ data.
Address
Antalya Teknokenti Arge 2 Binası No 3A/106 Konyaaltı, Antalya
Other legal documents
Before you use Growado, we recommend reading these too.
Start making better content decisions.
We respect your privacy. Join the early-access list and be one of the first teams to try Growado.
Get early access- Free early access
- Sign up with your work email
- Priority access at launch