smartgrowth.
Menu
PRIVACY & YOUR DATA

Understand what you share. And where it goes.

How SmarterGrowth handles your account, project information and connected search performance data.

SmarterGrowth

Petite Rue Des Mielles, St Brelade, Jersey, United Kingdom, GB
Privacy enquiries: privacy@smartergrowth.app

Last updated: 5 October 2026

1. Who is responsible

SmarterGrowth operates the SmartGrowth application and is responsible for the account and service information described in this policy. Contact us at privacy@smartergrowth.app about privacy, access or deletion requests. If your employer or another organisation provides your workspace, that organisation also determines how it uses the project information it supplies to the service.

2. Information the application handles

Data handled by SmartGrowth and its use
InformationHow it is used
Account detailsEmail address, display name, a password hash and security records support account creation, authentication and recovery. Your password is not stored as plain text.
Project and workflow inputsProject name, description, audience, market, public URLs, keywords, research goals, questions, competitors and reported metrics supply analysis context.
Analysis evidence and actionsSampled page content and metadata, findings, source links, provider metrics, AI output, timestamps and action statuses support reports and comparison over time. Public source content may itself contain personal information.
Connection dataGoogle authorisation tokens, token expiry information and the selected Search Console website property allow authorised read-only requests. We do not request or store your Google profile, Google email address, password, email messages, contacts or files through this connection. See the Search Console section below for the statistics we process and retain. Provider credentials configured by an operator enable the chosen services.
Operational and security dataJob status, worker heartbeat, request and error information, verification challenges and network addresses support reliability, abuse prevention and troubleshooting. Log contents and retention depend on hosting configuration.

3. Google Search Console data

Access and purpose

When you choose to connect Google, SmartGrowth requests read-only Search Console access using https://www.googleapis.com/auth/webmasters.readonly. Google handles sign-in and asks for your approval. We read the website properties your account can access so you can select the property for your project. For that property, we request search queries (keywords), page URLs, clicks, impressions, click-through rate and average search position.

We use these statistics and keywords to help you assess your website's search and keyword performance, review the context alongside SmartGrowth's keyword scoring metrics, prioritise improvements and produce your project's reports. The current connector samples up to 500 query/page rows over the last 28 available final-data days, ending three days before the analysis. These samples are not a complete record of website traffic or individual visitors.

What we store

We do not download or retain your Google account profile or content such as Gmail messages, contacts, calendars or Drive files. The Search Console connection is separate from the account details you provide directly to SmartGrowth. To keep your authorised connection working, we store access and refresh tokens, their expiry information and the selected website property against your project. We also temporarily store connection-verification records during the authorisation flow.

The current website audit processes the returned query/page rows during analysis and saves derived performance statistics and a finding describing the sample. It does not save a separate copy of the raw Search Console query/page response. The saved statistics remain in your analysis history and may appear in reports, exports and recommendations.

Sharing and limited use

Search Console information is used to provide your SmartGrowth features. Our hosting and database services process the saved connection and analysis records. If you choose AI analysis or forward an audit to AI, derived search-performance statistics and findings can be included in the request to the configured AI provider to generate recommendations for your project. Requested emailed reports are processed by the email delivery service; creating a GitHub issue sends the action and its attached evidence to your selected repository. Google tokens are not included in those requests, reports, exports or issues.

We do not sell Google API data, use it for advertising, credit assessment or lending, or use it to develop, improve or train general-purpose AI or machine-learning models. AI processing is for your requested recommendations, not model training. Providers receiving Google-derived information must be configured and used consistently with these restrictions. Human access is limited to what you authorise for support, necessary security investigation, legal obligations or other access permitted by Google's policy.

SmartGrowth's use and sharing of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. These restrictions also apply to statistics derived from Google API data.

Protection, retention and your controls

Requests to Google's authorisation and Search Console API endpoints use HTTPS. Saved tokens and statistics are held in SQL, with project ownership checks and credentials hidden from client-facing forms and exports. Database connection security, encryption at rest, backup protection and access permissions depend on the operator's hosting configuration, as explained below.

The live connection record is retained until you disconnect it or delete the project. Disconnecting Google removes the saved tokens and property from the application's live connection table and stops subsequent requests through that connection; it does not remove earlier saved analysis statistics. Our retention period for saved analyses, including derived Search Console statistics, is 30 days from creation. Database backups have a 30-day retention period. You can remove saved project analyses sooner by deleting the project after cancelling any active jobs. Connection-verification records expire after ten minutes and expired records are removed when another Google connection is started.

You can also revoke SmartGrowth's access in your Google account. Revoking access prevents further authorised access but does not automatically delete existing SmartGrowth records. For additional deletion requests, contact the privacy contact identified in this policy. Connecting Search Console is optional; public website checks remain available without it.

4. Purposes and lawful bases

We process account and project information to provide the service you request, including analyses, reports and authorised connections. Where applicable, this processing is necessary to perform our agreement with you. We also process information for our legitimate interests in keeping the service secure, preventing abuse and diagnosing failures, and where needed to meet legal obligations. Where processing relies on consent, you can withdraw that consent.

Required account and workflow fields enable their respective features. Optional connections add evidence and are accessed only after authorisation. You can disconnect Google without losing access to basic public website checks.

5. Providers and disclosures

Depending on configuration and the workflows you run, information is processed by our hosting and database services, email delivery service, Google Search Console, a search provider such as SerpApi, YouTube, public Mastodon instances, app listing services and OpenRouter and its selected model provider (or the locally authenticated OpenCode provider during development testing). Creating a GitHub issue sends its content to your selected repository. Public web requests disclose normal network request information to the destination website.

AI requests may include project context, goals, questions, public page summaries, findings and metrics. Provider handling of non-Google inputs depends on the selected provider and account settings. Google-derived information is subject to the restrictions in section 3, including the prohibition on general-purpose model training. See How we use AI for the request flow.

Account verification is handled by SmartGrowth using a short-lived, one-use arithmetic challenge. The email delivery service handles password recovery and requested PDF growth reports. Service providers may process information in other countries. Contact privacy@smartergrowth.app for the current hosting, recipient and international-transfer arrangements for your workspace.

6. Cookies and browser storage

SmartGrowth uses an essential session cookie named SmartGrowth.Session to authenticate you. The configured session validity is 12 hours with sliding renewal; the Remember me option can make the cookie persistent. ASP.NET antiforgery cookies protect submitted forms. Google authorisation stores a short-lived state and verifier in the application database to validate the connection flow.

The application does not include marketing tracking or third-party analytics scripts. We will update this notice if that changes.

7. Storage, security and retention

Application records are held in our SQL database. Google tokens and provider credentials are stored directly in SQL and rely on database connection security, access controls and the encryption at rest configured for the deployment. Saved credentials are masked in forms and omitted from application JSON exports. ASP.NET Data Protection protects authentication cookies. We restrict access to service records to their intended purpose.

Our retention period for saved analyses is 30 days from creation, and database backups expire after 30 days. Account and project setup information is retained while needed to provide your workspace, subject to deletion requests and applicable legal obligations. Google connection records are retained as explained in section 3. Project deletion removes the live project records; copies already included in backups remain until their backup expires. Reports or issues you send to external services are subject to those services' retention and your control over those copies.

There is no self-service account-wide deletion screen. Contact privacy@smartergrowth.app to request deletion or details of the records we hold about you.

8. Your choices and rights

You can review your inputs, export project reports and manage Google connections from your workspace. Disconnecting Google stops SmartGrowth's use of the saved connection; you can also revoke access in your Google account.

Depending on the applicable law and processing basis, you may have rights to access, correction, erasure, restriction, portability and objection, and to withdraw consent where processing relies on it. Send requests to privacy@smartergrowth.app. We handle requests that are not available through the application, including account-wide deletion and personal-data requests.

If UK data protection law applies, you can raise a complaint with the Information Commissioner's Office. The relevant regulator may differ for another jurisdiction.

9. AI and automated decisions

The current workflows produce research and recommendations for human review. They do not automatically publish website changes or make decisions with legal or similarly significant effects about individuals. AI answer samples and suggested actions may be incorrect and should be checked.

10. Changes and contact

We update this policy when our data practices change and show the revision date above. Before using Google API data for a new purpose or accessing additional data, we will explain the change and obtain any required renewed consent. Privacy enquiries and deletion requests: privacy@smartergrowth.app.

Please avoid submitting sensitive personal information in free-text project fields unless it is necessary for your requested service.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.