Legal

Privacy Policy

Last updated: July 12, 2026

This Privacy Policy explains how SocialGrovv Ltd (“SocialGrovv”, “we”, “us” or “our”) collects, uses, shares, and protects personal data when you visit our website or use our dashboard and related services (the “Service”). It applies to visitors, account holders, and anyone who interacts with us. By using the Service you acknowledge this Policy. For our contractual terms, see our Terms of Service.

1. Who We Are

SocialGrovv Ltd (company number 17316340), a private limited company incorporated in England and Wales, United Kingdom, is the data controller responsible for the personal data described in this Policy. The UK Information Commissioner’s Office (“ICO”) is our lead supervisory authority. For all privacy questions, requests, and complaints, contact [email protected].

2. Information We Collect

2.1 Account & identity data

  • Name, email address, password (stored as a salted hash by Supabase Auth), timezone, and brand profile preferences.
  • Business/brand profile details you provide (brand voice, niche, target audience, logo).

2.2 Connected social platform data

When you connect an Instagram, Facebook, TikTok, or YouTube account, we receive and store, via that platform’s official API:

  • OAuth access & refresh tokens (encrypted at rest with AES-256-GCM), the scopes you granted, and account-level metadata (username, page/channel ID, profile picture).
  • Publishing-related data: posts you schedule or publish through SocialGrovv, and basic post-status information returned by the platform.
  • For YouTube specifically, the Service uses YouTube API Services. Your use of those features is also subject to the YouTube Terms of Service and the Google Privacy Policy. You can revoke SocialGrovv’s access to your Google data at any time at myaccount.google.com/permissions.

2.3 Content & generated media

Text, images, videos, voice audio, captions, and hashtags you upload, schedule, or generate through the platform. Raw uploads and AI-generated media are stored in our Cloudflare R2 object storage, organized in per-user folders.

2.4 AI generation data

Prompts, reference images, and generation settings you submit to our AI Studio, and the resulting outputs, are stored so you can access your generation history. See Section 5 for how this data is shared with AI providers.

2.5 Billing data

Plan, subscription status, and credit-transaction history. Payments are processed by our billing partner, Polar; SocialGrovv does not receive or store your full card number — only a customer/subscription reference and plan information needed to manage your account.

2.6 Usage & device data

Login times, IP address, browser/device information, and application logs used to operate, secure, and troubleshoot the Service.

2.7 Communications

Support requests, feedback, feature requests, and votes/comments you submit through our in-app feedback board.

3. How We Use Your Information & Legal Basis

As a UK company, our primary framework is the UK GDPR and the Data Protection Act 2018. Where the EU GDPR also applies to you, the legal basis below applies equally under that framework. We use the data we collect to:

  • Provide the Service — authenticate you, run AI generations, build plans, and publish scheduled posts to your connected platforms. (Performance of contract.)
  • Bill and collect payment via Polar, manage subscriptions and credits. (Performance of contract; legal obligation.)
  • Secure the Service — detect and prevent abuse, fraud, and unauthorized access; enforce our Terms. (Legitimate interest; legal obligation.)
  • Operate, maintain, and improve the Service, including debugging and performance monitoring. (Legitimate interest.)
  • Communicate with you — service notices, post-failure alerts, and, where you have opted in, product updates. (Performance of contract; consent.)
  • Comply with law and respond to lawful requests. (Legal obligation.)

We do not use Your Content, connected-platform data, or AI generation prompts to serve you advertising, and we do not sell personal data.

4. Third-Party Platform Integrations

SocialGrovv integrates with Facebook, Instagram, TikTok, and YouTube via their official APIs to automate content distribution, and uses a self-hosted publishing bridge to deliver approved posts. When you connect an account, you agree to the API terms and privacy policies of that platform. We store the OAuth access tokens those platforms provide solely to publish content on your behalf, and keep them securely encrypted. We never sell tokens or personal data to advertisers or unrelated third parties.

5. AI-Assisted Features

Our AI Studio and plan builder use third-party AI providers — including OpenAI, Anthropic, fal.ai (for image/video generation models), and ElevenLabs (for voice/TTS) — as sub-processors. To generate outputs, we transmit the prompts, reference media, and settings you submit to the relevant provider. We instruct these providers not to use your inputs or outputs to train their models, except where a provider’s default policy requires it; any such exception will be disclosed here. AI outputs are generated probabilistically and may be inaccurate — you remain responsible for reviewing them before publishing.

6. Who We Share Data With

We do not sell personal data. We share data only with:

  • Infrastructure providers — Supabase (authentication and database), Cloudflare (R2 media storage), and our background job/worker service that renders AI images, videos, and audio.
  • AI model providers — OpenAI, Anthropic, fal.ai, and ElevenLabs, as described in Section 5.
  • Billing processor — Polar, to manage subscriptions and payments.
  • Connected social platforms — Meta (Facebook, Instagram), TikTok, and Google (YouTube), when you schedule or publish content or request analytics.
  • Authorities — when legally required (court order, valid law-enforcement request) or necessary to investigate fraud, abuse, or security threats.
  • Successor entities — in the event of a merger, acquisition, or sale of assets, subject to this Policy or notice of a new one.

7. International Data Transfers

SocialGrovv is based in the United Kingdom, and our infrastructure and AI-provider sub-processors may process data in other countries, including the United States and the European Union. Where personal data subject to the UK GDPR is transferred outside the UK, we rely on adequacy regulations, the UK International Data Transfer Addendum (“IDTA”), or the EU Standard Contractual Clauses as incorporated by the IDTA, supplemented by additional technical and organisational safeguards. Where the EU GDPR applies to you, equivalent Standard Contractual Clauses apply to transfers of your data.

8. Data Security

The security of your data is critical to us:

  • All sensitive data — especially OAuth access tokens — is encrypted with AES-256-GCM before being stored in our database.
  • All traffic between your browser and our servers is protected by SSL/TLS.
  • Our database is protected with Supabase Row Level Security (RLS) policies. Only you can access your own rows; server-to-server jobs (webhooks, background workers) use a service-role key that never reaches the browser.
  • Access to production systems and secrets is limited to authorized personnel on a least-privilege basis.

No system is fully secure, and we cannot guarantee absolute security.

9. Data Retention & Deletion

We keep your personal data for as long as you actively use SocialGrovv. If you delete your account or submit a data deletion request (e.g. via the Facebook Data Deletion flow):

  • Personally identifiable information, social media tokens, and generated media are permanently removed from our systems and Cloudflare R2 storage within 30 days.
  • Billing records are retained for as long as required by applicable tax and accounting law.
  • Operational logs are typically retained for up to 12 months for security and troubleshooting purposes.
  • Anonymized, aggregated analytics may be retained for statistical purposes.

10. Your Rights

Under applicable data-protection law — including the UK GDPR and, where relevant, the EU GDPR — you have the right to:

  • Access the personal data we hold about you.
  • Correct incomplete or inaccurate data.
  • Request complete erasure of your data (the right to be forgotten).
  • Object to or restrict certain processing activities.
  • Withdraw consent where processing is based on consent, without affecting processing already carried out.
  • Lodge a complaint with a supervisory authority — the UK Information Commissioner’s Office (ICO) at ico.org.uk, or your local EU data-protection authority if the EU GDPR applies to you.

Most account changes can be made from your dashboard’s profile, billing, or Connections settings. For requests that cannot be handled in-product, email [email protected].

11. Children

The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Cookies

We use cookies for authentication, security, and preferences, as described in our Cookie Policy.

13. Changes to this Policy

We may update this Privacy Policy from time to time. If a change is material, we will provide reasonable notice (for example by email or in-product notice) before it takes effect. The date at the top of this page reflects the last update.

14. Contact

For any privacy-related questions, concerns, or deletion requests, please reach out to us:

Email: [email protected]
We respond to all requests within 48 hours.
SocialGrovv Ltd — registered in England and Wales, company number 17316340.