Privacy Policy
This policy explains how Grow or Die handles account, analytics, payment, identity, and AI-usage data used to calculate product unit economics.
1. Scope and who we are
This Privacy Policy applies to the Grow or Die website, applications, and related AI product analytics and unit-economics services (the “Service”). “Grow or Die,” “we,” “us,” and “our” refer to the operator of the Service. By using the Service, you acknowledge the practices described here.
The Service is designed for business and professional use. If you use it for an organization, that organization may control the website data and workspaces you submit, while we process that information to provide the Service.
2. Information we collect
Account information
When you continue with Google, we receive the basic profile information you approve, such as your name, email address, profile image, and a Google account identifier. We do not receive or store your Google password.
Grow or Die website analytics
We use Google Analytics on the Grow or Die website and application to understand visits and the setup-to-subscription journey. Google Analytics receives page paths without query parameters, referral information, basic browser and device information, approximate location derived by Google, and events describing steps such as starting setup or opening checkout. We do not send your submitted website, email address, payment identifiers, API keys, or connected product data in these events.
Website and workspace information
We collect the domain you submit and the configuration needed to keep analytics, billing, and AI-usage facts scoped to that product. A paid account has one replaceable website slot. Removing a website deletes its connected-source records, write credentials, identity links, and retained product events, while account and subscription records may remain.
Connected-service data
If you connect Google Analytics 4 (“GA4”), Google Search Console (“GSC”), PostHog, Stripe, Lemon Squeezy, or another service, we receive only the data covered by the permissions or credential you provide. This may include visitor and session aggregates, acquisition and geographic dimensions, product events, payment and refund records, limited payer identifiers, and verified-property information. GA4 or PostHog supplies visitor evidence; GSC is optional search acquisition evidence. Connected-service authorization is separate from Google sign-in and can be revoked.
AI-usage and identity data
Our JavaScript/TypeScript and Python server-side SDKs may receive provider and model names, input, cached-input, cache-read, cache-write, output, and reasoning token counts, request outcome, latency, retry and stream status, fixed SDK provenance, and the account, user, visitor, session, feature, prompt-version, or billing identifiers you explicitly supply. Automatic OpenAI and Anthropic wrappers do not send prompts, generated responses, or your provider API key. Stable opaque IDs must be used instead of email addresses.
First-party attribution data
If a customer installs the Grow or Die browser tracker on its product, the tracker creates opaque visitor and 30-minute session identifiers in local storage and may send page origin and path without its query string or fragment, page title, referring origin, allowlisted first and current campaign parameters, language, time zone, viewport, and detected browser, operating-system, and device category. Public tracker events cannot create financial identity links. A customer may send the opaque visitor ID to its own backend and use the private server SDK to link it to an internal account, user, or payment-provider customer ID. The tracker does not infer country, region, or city from an IP address.
Service, device, and communications data
We may collect IP address, browser and device type, request timestamps, pages viewed, referring URLs, error and security logs, and actions taken in the Service. We also collect information you send when you request support or otherwise contact us.
Billing data
If paid billing is enabled, our payment provider processes your payment method. We may receive transaction status, plan, amount, billing contact, and limited payment identifiers, but we do not store full payment-card numbers.
3. How we use information
We use information to:
- authenticate users and maintain accounts and sessions;
- combine observed visitor, payment, and AI-usage facts;
- apply versioned model prices on our server and calculate revenue, AI variable cost, and contribution metrics;
- attribute those metrics to customers, features, models, prompts, acquisition sources, devices, and geography when identity coverage supports the join;
- link application account or user IDs with visitor, Stripe, Lemon Squeezy, or PostHog identifiers that you submit through the identity API;
- identify data-quality gaps and evidence-backed profit actions;
- measure product performance and improve the user-facing Service;
- provide support, prevent abuse, and protect the Service;
- administer subscriptions and communicate operational updates; and
- comply with law and enforce our agreements.
We do not sell personal information. We do not use Google user data for targeted advertising, credit decisions, or to train generalized or non-personalized artificial-intelligence or machine-learning models.
4. Google user data and Limited Use
Grow or Die’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy , including the Limited Use requirements.
We use Google account profile data only to authenticate you and operate your account. If you explicitly connect GA4, GSC, or another Google service, we use that data only for prominent user-facing features you requested, such as calculating GA4 visitor and acquisition metrics or showing GSC acquisition reports for your product.
We do not transfer Google user data except as needed to provide or improve those user-facing features with your consent, for security, to comply with law, or as otherwise permitted by Google’s policy. Humans do not read Google user data unless you give affirmative permission for specific support, access is necessary for security or legal reasons, or the data is aggregated and handled in accordance with applicable law.
You can revoke Grow or Die’s Google access at any time from your Google Account connections . Revocation stops future access but does not automatically delete information already required for your account or legal records. You can request deletion as described below.
5. AI model telemetry
Grow or Die records the usage facts your server sends after OpenAI or Anthropic calls; it does not proxy those calls. Automatic wrappers observe normal responses, final streamed usage where available, provider failures, timeouts, cancellations, cache usage, latency, and partial or unknown interrupted-stream states. They do not receive or transmit your provider API keys, prompts, or generated output. Model prices are applied by Grow or Die on the server so the SDK does not calculate or transmit monetary values.
The SDK identity method may send opaque application account, user, and visitor IDs together with payer or analytics identifiers to join revenue and AI cost. It rejects email addresses. Usage telemetry delivery is best effort, while identity submission is reliable by default unless the customer explicitly selects best-effort mode.
Google account identity data and Google-derived GA4 or GSC data are not used to train generalized or non-personalized AI or machine-learning models. Do not include prompt text, response text, secrets, health data, payment-card data, or other sensitive information in SDK metadata or identifiers.
8. Retention and deletion
We retain information only as long as reasonably necessary to provide the Service, maintain security, resolve disputes, and meet legal, tax, or accounting duties. OAuth authorization state is short-lived. Session records expire, and connected-service access ends when you disconnect or revoke it. Accepted product events are retained for up to three years under the current paid plan unless deleted earlier with their website or account, subject to backup and legal-record exceptions. Some backup or legal records may remain for a limited period after deletion.
To request account deletion, deletion of Google-derived data, or a copy of your information, email privacy@grow-or-die.com from the email address associated with your account. We may verify your identity before completing the request.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including encrypted network transport, restricted production credentials, least-privilege service access, and secure session cookies. No system is completely secure, so we cannot guarantee absolute security.
10. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or obtain a portable copy of personal information, and to withdraw consent. You may also have the right to complain to a data-protection authority. We do not discriminate against users for exercising applicable privacy rights.
You may disconnect Google through your Google Account, stop submitting a website, or contact us to exercise a right. We will respond within the period required by applicable law.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided information, contact us so we can take appropriate action.
12. Changes to this policy
We may update this policy as the Service or law changes. We will post the revised version here, update the effective date, and provide additional notice when required. Material changes to Google-data use will not apply retroactively without any consent required by law or Google policy.
13. Contact
Questions, privacy requests, and complaints can be sent to privacy@grow-or-die.com.