Privacy Policy

Last updated: 31 July 2026

This Privacy Policy explains how Growth OS (“Growth OS”, “we”, “us”, or “our”), available at https://usegrowth-os.xyz, collects, uses, stores, shares, and deletes personal data when you use our website and application.

Growth OS is an AI-assisted creator operating system that helps users research trends, generate short-form content, manage media assets, analyse competitors, and publish to connected social platforms (including TikTok) with the user’s explicit authorisation.

By creating an account or using Growth OS, you acknowledge this Policy. If you do not agree, do not use the service. This Policy is intended to meet common expectations for apps that integrate TikTok Login Kit and the Content Posting API. It is not a substitute for independent legal advice.

1. Who we are (data controller)

For personal data processed through Growth OS, the controller is the operator of the Growth OS service at https://usegrowth-os.xyz.

If you need a postal address for a formal rights request or regulator correspondence, email edwardsjonny547@gmail.com and we will provide the registered contact details for the operating entity.

2. Scope

This Policy applies to:

  • Visitors to our marketing site
  • Users who create Growth OS accounts
  • Users who connect TikTok or other third-party accounts via OAuth
  • Content, media, and analytics processed inside a user’s workspace

3. Personal data we collect

3.1 Account and authentication data

When you sign up or sign in (via Supabase Auth), we process:

  • Email address
  • Display name (if provided)
  • Authentication identifiers / user IDs issued by our auth provider
  • Session cookies and related security tokens

Passwords are handled by Supabase Auth and are not stored in our application database in plain text. We do not receive your social network passwords through TikTok OAuth.

3.2 Workspace and product usage data

  • Projects, drafts, captions, hooks, schedules, and generation history
  • Uploaded media (images/videos), library assets, and Image Packs
  • Product usage events (for example: feature opens, generation counts, publish attempts, error logs) to operate and improve reliability
  • Workspace preferences (for example: active project)

3.3 TikTok OAuth and Content Posting data

If you choose to connect TikTok, we process data necessary to authenticate you and to provide analytics sync and publishing features you request. Depending on the scopes you approve, this may include:

  • Profile identifiers: TikTok open_id, username / display name, avatar URL, and related basic profile fields granted under user.info.basic
  • OAuth credentials: access token, refresh token, token expiry, and granted scope list
  • Publishing metadata: captions/titles you submit, privacy level you select, brand-content toggles, publish job IDs, status responses, and error codes from TikTok’s APIs
  • Media for publishing: slide images or other media you ask us to publish; we host them on infrastructure you control/verify (for example our app domain / storage) so TikTok can pull them via HTTPS
  • Public analytics (where synced): publicly available post metrics you ask us to import for your connected accounts (for example views, likes, comments), shown only inside your workspace

We only request TikTok scopes required for the features you use. Current Login Kit / Content Posting scopes used by Growth OS include:

  • user.info.basic — to identify the connected TikTok creator account and display profile information in Connected Accounts
  • video.publish — to publish content (including photo carousels) directly to TikTok via the Content Posting API after you confirm privacy and consent in-product
  • video.upload — only if enabled for upload-to-inbox / draft upload flows; if this scope is not used in your workspace configuration, it will not be requested

TikTok processing is also governed by TikTok’s Privacy Policy and TikTok Developer Terms of Service. You can revoke Growth OS’s access at any time in TikTok’s app permissions settings and by disconnecting the account in Growth OS.

3.4 Competitor and public research data

When you add competitors or run research features, we may collect publicly available information (for example public profile metadata, public post captions/thumbnails, website metadata, app store listing information). This is processed to provide competitive intelligence inside your workspace and is not sold as a data product.

3.5 AI processing data

To generate copy, briefings, opportunities, and chat answers, we may send prompts and relevant project context to AI providers you configure (for example Groq or OpenAI). Do not submit special-category or sensitive personal data you are not authorised to process.

3.6 Payment data (when billing is enabled)

If paid plans are enabled, payment card details are processed by Stripe (or a similar payment processor). We do not store full card numbers on our servers.

4. How we use personal data

We use personal data to:

  • Create and secure accounts; authenticate sessions
  • Provide workspaces, generation, libraries, scheduling, and publishing
  • Connect TikTok accounts, refresh tokens, and execute publish requests you initiate
  • Show analytics and recommendations inside your workspace
  • Detect abuse, debug failures, and maintain service security
  • Respond to support and privacy requests
  • Comply with law and enforce our Terms of Service

We do not sell personal data. We do not use TikTok user data to serve third-party advertising. We do not use TikTok data outside the Growth OS product experience except as needed to operate the features you requested or as required by law.

5. Legal bases (EEA/UK users)

Where GDPR/UK GDPR applies, we rely on:

  • Contract — to provide the service you signed up for (account, sync, publish)
  • Consent — for OAuth connections and optional processing where consent is required (you can withdraw by disconnecting)
  • Legitimate interests — security, fraud prevention, product reliability analytics (balanced against your rights)
  • Legal obligation — where we must retain or disclose data by law

6. Cookies and similar technologies

We use cookies and local storage for:

  • Authenticated sessions (Supabase Auth)
  • CSRF / OAuth state protection during TikTok connect flows
  • Workspace preferences (for example active project / UI settings)

We do not use third-party advertising cookies to track you across unrelated sites for ad targeting.

7. Sharing and subprocessors

We share personal data only with service providers that help us operate Growth OS, under contractual obligations to protect it:

  • Supabase — authentication and (in production) database / storage
  • Netlify (or similar hosting) — application hosting and edge delivery
  • AI providers (for example Groq, OpenAI) — generation features you use
  • TikTok — when you connect an account or publish; TikTok receives the content and instructions you authorise
  • Stripe — payments when billing is enabled

We may disclose data if required by law, regulation, legal process, or to protect the rights, safety, and security of Growth OS, our users, or the public.

8. International transfers

Our infrastructure and subprocessors may process data in the United Kingdom, European Economic Area, United States, or other locations where those providers operate. Where required, we rely on appropriate transfer mechanisms offered by our providers (for example standard contractual clauses).

9. Retention

  • Account data — kept while your account is active
  • TikTok tokens — kept while the account remains connected; deleted or invalidated when you disconnect or when tokens expire and cannot be refreshed
  • Publish jobs / logs — retained as needed for debugging, abuse prevention, and audit (typically up to 12 months unless a longer period is required)
  • Uploaded media — retained until you delete it or delete your account, subject to backup cycles
  • Security logs — may be retained longer where needed for security and legal compliance

10. Security

We use industry-standard safeguards appropriate to a SaaS product, including encrypted transport (HTTPS), access-controlled databases, and least-privilege service credentials. No method of transmission or storage is 100% secure; you are responsible for protecting your account credentials and for reviewing content before publishing.

11. Your rights and choices

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion or anonymisation
  • Export a copy of your data (portability)
  • Object to or restrict certain processing
  • Withdraw consent where processing is consent-based

In-product controls include:

  • Disconnect TikTok from Connected Accounts
  • Revoke app access in TikTok’s settings
  • Request account deletion by emailing edwardsjonny547@gmail.com

We will respond to verifiable requests within a reasonable period (generally within 30 days where required by law). You may also complain to your local data protection authority.

12. Children

Growth OS is not directed to children under 13 (or under 16 where a higher age is required by local law). We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will delete it.

13. Automated decision-making

Growth OS uses AI to generate suggestions and insights. These outputs are assistive; they do not produce legal or similarly significant decisions about you without human review. You remain responsible for what you publish.

14. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date will change when we do. Material changes will be highlighted on this page or communicated in-product where appropriate. Continued use after an update constitutes acceptance of the revised Policy.

15. Contact

Privacy requests: edwardsjonny547@gmail.com
Legal: edwardsjonny547@gmail.com
Web: https://usegrowth-os.xyz