GrowthHack Social
← Home

Legal

Privacy Policy

What the service stores, why, who it shares data with and how to delete it. No legal fog: what follows describes what the code actually does.

Updated: 1 August 2026. The service is operated by Nikita Somov (private individual, Dubai, United Arab Emirates), growthhack.social. Questions and requests: support@growthhack.social.

What we store

About your account: email address, whether it has been confirmed, interface language, creation date and a password hash. The password itself is not stored — it cannot be recovered from the hash.

When you sign in with Google: we request only openid email profile and store your Google identifier and email address. We have no access to your mail, files or contacts, and we do not request it.

About your project: name, time zone, publication language, topic, schedule, connected material sources, stop words.

About connected social accounts: username, platform identifier, granted permissions and the access token. The token is stored encrypted (AES-GCM); the encryption key lives in the server configuration rather than in the database and is bound to that specific account row — a stolen database without the server key yields no tokens.

About pipeline activity: collected material, drafts, review results, published posts and their statistics (views, likes, replies), plus records of model-call spending.

Retention periods

Data is deleted automatically, not “as needed”:

  • source material — 90 days;
  • completed pipeline jobs — 30 days;
  • publication statistics snapshots — 400 days;
  • stop-word triggers — 180 days;
  • unused material in the pool — 14 days;
  • model spending records — indefinitely: this is financial accounting, it contains no texts and is not tied to post content.

Who we share data with

We do not sell data and do not pass it to advertisers. Sharing happens only where the service cannot work without it:

  • Threads (Meta) — publishing posts and retrieving their statistics. What goes there is what you approved for publication.
  • Language model providers — the text of the material and the draft is sent for processing to produce a finished post. Your email address and account data are not sent.
  • Google reCAPTCHA — on the sign-in and sign-up pages, to tell a human from a bot. Google receives browser technical data to the extent described in its own policy.
  • Resend — email delivery (address confirmation, password recovery).

Cookies and sessions

There are no advertising or analytics cookies. Only technical ones are used: a session identifier (to keep you signed in) and a request-forgery protection token. Your theme choice and form drafts are stored locally in the browser and never reach the server.

Your rights

Export everything. Project settings include an export: you receive an archive with your material, drafts and publications.

Delete your account. Deletion is available in the “Danger zone” section and requires password confirmation. Along with the account we delete projects, material, drafts, publications and social connections. Deletion cannot be undone.

Disconnect a social account. Disconnecting a Threads account stops publishing and statistics collection immediately.

For questions about data processing write to support@growthhack.social.

Security

The connection to the service runs over HTTPS. Passwords are stored as hashes, social tokens in encrypted form. Administrator access to service areas is protected by a second factor, and all administrator actions are written to a log.

Nobody can guarantee complete security, and we will not pretend that we do. If you have found a vulnerability, write to support@growthhack.social.

Changes to this policy

For material changes we will update the date at the top of the page. If a change affects what data is shared, we will notify you by email.

Privacy Policy Terms of Use

GrowthHack Social
Log in Privacy Terms