Privacy Policy
This Privacy Policy explains how One Dollar Code, Inc. ("Growwly", "we", "us", or "our"), the operator of growwly.co, collects, uses, discloses, and protects information when you use our website, web application, free tools, browser extension, and related services (collectively, the "Service").
By using the Service, you agree to the collection and use of information as described in this Privacy Policy.
1. Information We Collect
1.1 Information You Provide Directly
- Account information: name, email address, password (hashed), and profile details when you register.
- Communications: messages you send us via email, support chat, or feedback forms.
- Payment information: when you subscribe to a paid plan, payment card details are collected and processed directly by Stripe. Growwly does not store your full card number, CVV, or bank credentials on our servers.
1.2 Information from Google/YouTube (via OAuth)
When you connect your YouTube channel to Growwly, we access data through the YouTube Data API and related Google APIs, which may include:
- Channel metadata (channel name, ID, description, thumbnail, subscriber count)
- Video-level metadata and statistics (titles, descriptions, tags, views, likes, comments, publish dates)
- YouTube Analytics data (where explicitly authorized), such as watch time, traffic sources, RPM/CPM estimates, and audience retention
- Basic Google account identifiers required to authenticate the connection
We only request the minimum scopes necessary to provide the Service, and you can review and revoke these permissions at any time via your Google Account permissions page.
Google API Limited Use Disclosure: Growwly's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use YouTube API data to serve advertisements, and we do not sell YouTube API data to third parties, data brokers, or ad networks.
1.3 Information from the Browser Extension
If you install our optional Chrome/Edge extension, it may collect:
- Publicly rendered YouTube page data (e.g.,
ytInitialData, InnerTube continuation tokens) while you actively browse YouTube pages with the extension enabled - Public comment content on channels you audit: when you run a channel audit, the extension reads the top comments on that channel's most-viewed videos, including the comment text and the commenter's public display name. These are people other than you, and their display names are personal data, so we name them here rather than folding them into "public page data". They are used only to analyse how an audience responds to a channel, are never used to build a profile of an individual commenter, are never sold or shared with data brokers or ad networks, and are deleted on the schedule in Section 5.
- Basic technical identifiers (browser type, extension version) needed for compatibility and debugging
- Crash reports: the surface that failed, an error message and a short stack trace, plus the extension version. These are sent without an account identifier and contain no page content.
Requests made using your YouTube session. To fill in information YouTube does not put on the page, the extension makes its own requests to YouTube from your browser, using your existing YouTube session, in two situations: while you scroll a feed (to identify the uploader of cards you are shown, at roughly one request every few seconds), and while a channel audit is running (about 150 paced requests over 8–10 minutes, which you start deliberately). No such request is ever made when Capture is switched off in the extension's settings.
This data is tagged in our systems as source: extension to distinguish it from official API-sourced data, and is used solely to supplement channel/video analytics shown to you or aggregated (in de-identified form) for platform-wide benchmarking features such as Playbooks. The extension does not access your browsing history outside of YouTube, your passwords, or non-YouTube page content.
All of the above can be turned off at any time with the Capture switch in the extension's settings, which stops collection and stops the requests described above.
1.4 Information Collected Automatically
- Usage data: pages visited, features used, click patterns, session duration.
- Device/log data: IP address, browser type, operating system, referring URLs, timestamps.
- Cookies and similar technologies: used for authentication, preferences, and analytics (see Section 7).
2. How We Use Your Information
We use collected information to:
- Provide, operate, and maintain the Service, including channel audits, RPM estimates, competitive analysis, and Playbooks.
- Authenticate your account and maintain your OAuth connection to YouTube.
- Process payments and manage subscriptions via Stripe.
- Generate aggregated, de-identified insights and benchmarks (e.g., niche-level trends) that do not identify any individual channel unless explicitly featured with consent.
- Send transactional emails (billing receipts, account notices) and, where you've opted in, marketing communications.
- Improve and troubleshoot the Service, including through analytics on feature usage.
- Detect, prevent, and address fraud, abuse, or violations of our Terms of Service.
- Comply with legal obligations.
We do not sell your personal information to third parties.
3. Legal Basis for Processing (EEA/UK Users)
Where applicable data protection law (such as the GDPR) requires it, we rely on the following legal bases:
- Contractual necessity — to provide the Service you've signed up for.
- Consent — for OAuth data access, extension data collection, and marketing communications.
- Legitimate interests — for product improvement, security, and fraud prevention, balanced against your rights.
- Legal obligation — for tax, accounting, and compliance requirements.
4. How We Share Information
We share information only as necessary, with:
- Service providers / sub-processors:
- Cloudflare (hosting, Workers, D1 database, Queues, CDN)
- Supabase (database and authentication infrastructure)
- Stripe (payment processing)
- Google/YouTube APIs (to retrieve authorized channel data)
- Cloudflare AI Gateway / Anthropic (to power AI-generated insights, summaries, and Playbooks; data sent for processing is not used by Anthropic to train models under our commercial terms)
- Legal and safety purposes: to comply with law, respond to lawful requests, or protect the rights, property, or safety of Growwly, our users, or the public.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
We do not permit third parties to use YouTube API data for purposes outside providing you the Service, consistent with Google's API Services User Data Policy.
5. Data Retention
We retain personal information for as long as your account is active or as needed to provide the Service. Specifically:
- Account data: retained until you delete your account, plus a limited grace period for backups.
- YouTube channel/video snapshot data: retained on a decaying schedule (higher frequency for recent data, aggregated/reduced granularity over time) to support historical trend analysis.
- Payment records: retained as required for tax and accounting compliance (typically 7 years or as required by law).
- Extension-sourced data: retained under the same schedule as API-sourced data, tagged by source.
- Comment text and commenter display names: retained for 12 months from collection and then deleted. Aggregate results derived from them (for example, the themes an audience raises about a channel) may be retained after the underlying comments are deleted, because they identify no individual.
- Crash reports: retained for 90 days.
Upon account deletion, we will delete or anonymize personal data within 30 days, except where retention is required by law.
6. Data Security
We implement industry-standard technical and organizational measures to protect your information, including:
- Encryption in transit (TLS) for all data transmission.
- OAuth tokens and sensitive credentials stored using strong encryption at rest.
- Access controls limiting internal access to production data on a need-to-know basis.
No method of transmission or storage is 100% secure. In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by applicable law.
7. Cookies and Tracking Technologies
We use cookies and similar technologies for:
- Essential functions: authentication, session management, security.
- Preferences: remembering your settings.
- Analytics: understanding how users interact with the Service (e.g., via privacy-conscious analytics tools).
You can control cookies through your browser settings. Disabling essential cookies may impair core functionality of the Service.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate or incomplete data.
- Deletion — request deletion of your personal data ("right to be forgotten").
- Portability — request your data in a structured, machine-readable format.
- Objection/Restriction — object to or request restriction of certain processing.
- Withdraw consent — for OAuth access or marketing communications, at any time.
- Non-discrimination (California residents under CCPA/CPRA) — we will not discriminate against you for exercising your privacy rights.
To exercise these rights, contact us at privacy@growwly.co. We will respond within the timeframe required by applicable law (e.g., 30 days under GDPR, 45 days under CCPA).
9. Children's Privacy
The Service is not directed to individuals under 18 years of age, and we do not knowingly collect personal information from children. If we become aware that we have collected data from a child without appropriate consent, we will delete it promptly.
10. International Data Transfers
Growwly operates using global infrastructure providers (e.g., Cloudflare), which may process and store data in countries other than your own. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) for cross-border transfers of personal data from the EEA/UK.
11. Third-Party Links
The Service may contain links to third-party websites or services (including YouTube itself). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies separately.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notice at least 14 days before taking effect. The "Last Updated" date at the top of this page reflects the most recent revision.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, contact us at:
One Dollar Code, Inc. Website: https://growwly.co Email: privacy@growwly.co Address: 8 The Green, #12820, Dover, DE 19901, US