Questions about anything here: security@growthxai.com
What data we process
- Lead data you import or that we collect for you: names, job titles, companies, profile URLs, email addresses and the custom fields you add.
- Messages sent and received through your LinkedIn accounts and mailboxes, and each lead's timeline.
- LinkedIn session data for each connected account, so it can send without anyone sharing a password.
- Mailbox connections: OAuth tokens for Gmail and Outlook, or the IMAP/SMTP details you enter for other mailboxes.
- Usage data: planned and executed actions, and an audit log of changes in your workspace.
Who controls it
You are the controller of your workspace data; we process it on your behalf to run your outreach. Our data processing agreement sets out the terms, and the privacy policy covers the data we hold about you as a customer.
The DPA is published in full and applies automatically under our Terms. Need a countersigned copy for your records? Email privacy@growthxai.com.
Where it lives
Your workspace data is stored in a Supabase database, and the product's back-end functions run on Supabase too.
Your workspace data is hosted in the United States / Europe. The app and its back-end functions run in the same region as your data.
Sub-processors
The companies that process workspace data for us, and why.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, storage and back-end functions | All workspace data |
| Stripe | Payments and billing | Billing contact and payment details |
| Resend | The product's own emails to you and your team (not your outreach) | Recipient email address, message content |
| Google (Gemini) | AI reply tagging, drafts, AI lines and routing, with our key | The lead and message text the AI step needs |
| Proxy providers | A dedicated proxy in the account owner's country for each LinkedIn sender | LinkedIn traffic for that sender |
| Your own AI provider Early access | Only if you add your own Gemini, Anthropic or OpenAI key. That provider then handles your AI requests under your own account with them. | The lead and message text the AI step needs |
Each provider processes data in the United States / Europe, except the proxy for a LinkedIn sender, which sits in that sender's own country. Notice periods and your right to object to a new sub-processor are in section 7 of the DPA.
Each LinkedIn account connects through its own proxy in the owner's country. Mailboxes connect directly and don't use a proxy. Proxy FAQ
Who can see what
- Data is separated by workspace, and inside a workspace by client, with row-level security in the database.
- Four roles: Owner, Manager, Member and Client viewer. Members can be limited to certain clients; client viewers see only their own client, read-only unless given can reply. The same rules apply in the app, on the server and in the Claude connector.
- Claude works with exactly the role and client scope of the person who connected it. It can't see or do anything that person couldn't.
- API keys Early access act as the member who created them, never as Owner, and can be limited to certain clients. If that person leaves or loses a role, the key loses the same rights at once.
- Exports and changes are recorded in the workspace audit log, which Owners and Managers can read and export.
Passwords and credentials
- Nobody shares a LinkedIn password, with us or with an agency. The account owner logs in through a hosted page, on their own device.
- The optional Chrome extension keeps a session connected from the owner's own browser. It never sees the password, its pairing token works for one account only, and stored cookies are encrypted.
- Disabling an account with Purge stored secrets ticked removes its stored session data.
- Gmail and Outlook connect through OAuth, so we never see those passwords.
- API keys are shown once and stored only as a hash. Your own AI key is tested, then kept write-only: we show a hint, never the key.
Retention and deletion
- Nothing is deleted when a trial ends or a payment fails. LinkedIn accounts pause until it's resolved, then pick up where they left off.
- Blocking or unsubscribing a lead never deletes them: the lead, their timeline and the conversation stay.
- Owners and Managers can export leads, messages, actions and the audit log as CSV at any time.
When you close your workspace, or we terminate it:
- The workspace stays readable for 30 days so you can export your data.
- Account data and workspace data are then deleted from our live systems within 90 days.
- Backup copies are removed in the ordinary course of backup rotation, within a further 35 days.
- Invoices, payment records and records needed to establish or defend legal claims are kept for as long as the law requires.
The full retention schedule, purpose by purpose, is in the Privacy Policy (sections 4 and 8) and the Terms of Service.
To ask for your workspace data to be deleted, email security@growthxai.com.
Encryption
- The app and the API are served over HTTPS.
- LinkedIn session cookies are encrypted before they're stored.
Details of encryption at rest across our hosting providers are being confirmed and will be listed here.
Certifications
Not yetWe don't have SOC 2 or ISO 27001 certification. We'd rather tell you that plainly than imply otherwise. If your security review needs answers beyond this page, send us your questionnaire.
Report a vulnerability
If you think you've found a security problem, email security@growthxai.com with the details and steps to reproduce it. Please don't access other people's data or disrupt the service while testing.
Our contact details are also published at /.well-known/security.txt.