Privacy Policy

Effective date: 25 July 2026
Last updated: 2 August 2026
Version: 1.4

1. Introduction

Your privacy matters to us. This Privacy Policy explains how AVENIX LTD (trading as GrowApp; “GrowApp”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal data when you access or use growapp.nowand related services (collectively, the “Service”).

AVENIX LTD is a company registered in the United Kingdom. Our registered office is at 8 Stoney Lane, London SE19 3BD, United Kingdom. We are the data controller for personal data processed through the Service, unless stated otherwise in this policy.

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and, where applicable, the EU GDPR for users in the European Economic Area (EEA).

This Privacy Policy is provided to explain our processing activities and does not mean that all processing is based on your consent. It should be read together with our Terms of Use.

Links on our site may lead to third-party websites (for example, Substack). Those sites have their own privacy policies, which govern your activity after you leave our Service.

2. Personal data we collect

We collect information in the following categories:

  • Information you provide — for example, when you request a sign-in link or contact us.
  • Information collected automatically — for example, when you browse the Service.
  • Information from Substack — subscriber data we import to verify paid access (see Section 2.1).

Account and access data

  • Email address (required to send magic sign-in links and verify subscription access)
  • Magic-link token records (including the token, expiry time and usage status)
  • Session identifiers (hashed session tokens associated with your authenticated visit)

2.1 Data received from Substack

Paid subscriptions are managed on Substack. From time to time our administrators import a Substack subscriber export into our database so we can grant and manage access to GrowApp. This import may occur before you first visit growapp.now, and may be repeated when we refresh subscriber lists.

We import only the fields needed to verify and administer GrowApp access: your email address, subscription status/type, subscription tier (Stripe plan), subscription start date and, where applicable, cancellation or expiry date. We do not import engagement metrics, revenue figures, location data, or other Substack analytics columns. We do not receive your payment card details.

After cancellation or expiry, we retain former subscriber records only for the period described in Section 8, then delete or anonymise them.

2.2 Information provided before you visit GrowApp (Article 14)

Because subscriber data may be obtained from Substack before you first visit growapp.now, we provide privacy information through:

  1. this Privacy Policy;
  2. notices in Substack checkout, welcome emails or newsletter/footer communications where available, stating that subscriber information is shared with AVENIX LTD / GrowApp to administer access; and
  3. the Privacy Policy link on the GrowApp sign-in page.

We aim to ensure that individuals are informed within one month of our obtaining the data, typically via Substack subscription communications and/or when they first interact with GrowApp.

Communications

If you contact us by email, we may retain the content of your message and our response for support and record-keeping purposes.

Log and technical data

When you visit the Service, our servers and infrastructure providers may automatically record standard technical data, including IP address, browser type and version, operating system and device type, pages viewed, referring URL, date and time of access, and error or diagnostic data if something fails.

We use this logging for security and operational purposes under legitimate interests. We do not treat this as a substitute for Google Analytics. Non-essential usage analytics via Google Analytics run only with your consent (see Section 5).

Analytics data

If you accept analytics cookies, Google receives and processes analytics identifiers and usage information in accordance with our configuration and Google's applicable data-processing terms. We configure Google Analytics without advertising personalisation and with IP anonymisation enabled. We do not intentionally enable Google Signals or User-ID for GrowApp. See Section 5 for cookie details and retention.

Payment and billing data

Card payments are processed by Substack and its payment processors under their own terms and privacy notices. AVENIX LTD does not process payment card details on GrowApp.

Cookie consent preference

We store your cookie choice in your browser local storage so we can remember and honour your preference on that browser.

3. Purposes, lawful bases and retention overview

Under the UK GDPR (and, where applicable, the EU GDPR), we process personal data only where we have a valid lawful basis. The following summary maps our main processing activities:

We rely on consent for Google Analytics and other non-essential cookies. We rely on legitimate interests for limited security and operational logging necessary to maintain the Service — not for Google Analytics. You may withdraw consent at any time via Cookie settings in the footer.

4. How we use personal data

We use personal data to:

  • Provide, operate, and maintain the Service
  • Send magic sign-in links and important service/account notices
  • Verify subscription access and enforce content entitlements
  • Respond to support requests
  • Detect, prevent, and address security incidents, fraud, and abuse
  • Comply with legal obligations and enforce our Terms of Use
  • Measure site usage with Google Analytics only where you have given cookie consent

Marketing newsletters and subscription communications are sent and managed through Substack. Substack provides the unsubscribe mechanism included in each marketing email. GrowApp service emails (such as magic links and important account notices) are separate from marketing communications and are not used for advertising.

We do not sell your personal data. We do not use your personal data for automated decision-making that produces legal or similarly significant effects.

5. Cookies and similar technologies

We use cookies and similar technologies in accordance with PECR and the UK GDPR. On your first visit we show a cookie banner so you can accept or reject non-essential cookies with equally available choices. Essential cookies may still be used for sign-in and security. You can change your choice at any time via Cookie settings in the site footer.

The cookie lifetime in your browser is separate from the retention period for event data in our Google Analytics property.

Google Analytics scripts and analytics cookies are loaded only after you choose “Accept all”. If you choose “Reject non-essential”, we do not load Google Analytics and do not set analytics cookies. We do not send analytics events before consent.

Most browsers also let you block or delete cookies; blocking essential cookies may prevent parts of the Service from working correctly.

6. How we share personal data

We share personal data only as described below:

  • Service providers (processors) who help us run the Service:
    • Database and authentication infrastructure: Supabase
    • Object storage and content delivery: Cloudflare R2
    • Hosting and application infrastructure: DigitalOcean
    • Operational backups: Backblaze B2
    • Transactional email delivery: Zoho Mail
    • Website analytics: Google Analytics (only with your cookie consent)
    These providers may access personal data only to perform services for us and are contractually required to protect it in line with UK GDPR requirements.
  • Substack — subscription billing, payment processing and subscriber management are handled by Substack as an independent controller for payment and newsletter data. We import limited subscriber data as described in Section 2.1 to operate access on GrowApp.
  • Legal and safety disclosures — where required by law, court order, or regulatory request (including UK authorities), or where necessary to protect rights, safety, and security.
  • Business transfers — if we undergo a merger, acquisition, or asset sale, personal data may transfer as part of that transaction, subject to this policy or notice to you.

We do not share personal data with third parties for their independent marketing.

7. International data transfers

We are established in the United Kingdom. Personal data may be processed in countries other than the UK, including outside the UK and EEA (for example, the United States), where our service providers maintain facilities.

Where we transfer personal data from the UK to a country that is not covered by a UK adequacy regulation, we put in place appropriate safeguards required by UK GDPR. These may include the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or other lawful transfer mechanisms.

Where EU GDPR applies to a transfer from the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) or an applicable adequacy decision.

You may contact us to request further information about the safeguards used for a particular transfer.

8. Data retention

We retain personal data only as long as necessary for the purposes described in this policy, unless a longer period is required or permitted by UK law. The overview table in Section 3 sets out our current retention periods. Operational backups may retain deleted data for up to 30–90 days before being overwritten.

When data is no longer needed, we delete it or anonymise it so it can no longer identify you.

9. Security

We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, or alteration, as required under UK GDPR. These include access controls, encrypted connections (HTTPS), and restricted access to production systems.

No method of transmission or storage is completely secure. You are responsible for keeping access to your email account secure, since sign-in links are sent there.

10. Your rights (UK GDPR / GDPR)

Under the UK GDPR (and, where applicable, the EU GDPR), you have the following rights regarding your personal data:

  • Access — request a copy of personal data we hold about you.
  • Rectification — request correction of inaccurate or incomplete data.
  • Erasure — request deletion of your data, subject to legal exceptions.
  • Restriction — request that we limit processing in certain circumstances.
  • Objection — object to processing based on legitimate interests.
  • Data portability — where processing is automated and based on your consent or a contract, you may have the right to receive personal data that you provided to us in a structured, commonly used and machine-readable format and, where technically feasible, to have it transmitted to another controller.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
  • Lodge a complaint — with a supervisory authority (see Contact us).

To exercise these rights, contact us at [email protected]. We will request only information reasonably necessary to verify your identity and protect your personal data. We aim to respond within one month, as required by UK GDPR (extendable in complex cases as permitted by law).

11. Data breaches

If a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner’s Office (ICO)without undue delay and, where feasible, within 72 hours after becoming aware of it. If the breach is likely to result in a high risk to individuals' rights and freedoms, we will also notify affected individuals without undue delay, unless an applicable legal exception applies.

12. Children's privacy

The Service is intended for individuals aged 18 or over. We do not knowingly collect personal data from children under 18. If you believe that a person under 18 has provided us with personal data, please contact us and we will take steps to delete it.

13. Third-party app content and personal data

Screenshots and recordings in our research library are intended to show application interfaces rather than identify individual users. Where reasonably possible, we use demonstration data or remove, blur or anonymise names, account identifiers, profile images, messages and other personal data.

In limited cases, Third-Party App Content may incidentally contain publicly available or demonstration personal information. We process such material only where necessary for the research and commentary purposes of the Service and subject to applicable data-protection and intellectual-property laws.

If you believe that content in the Service contains your personal data and would like us to review or remove it, please contact [email protected] and identify the relevant content.

14. Changes to this policy

We may update this Privacy Policy from time to time. The effective date and version at the top indicate when it was last revised. Material changes will be posted on this page; where required by law, we will provide additional notice (for example, by email to registered users).

15. Contact us

For privacy questions, requests to exercise your rights, or complaints about our data practices, contact:

  • AVENIX LTD (trading as GrowApp)
  • Registration number: 16105497
  • VAT number: Not VAT registered
  • Email: [email protected]
  • Registered office:
    8 Stoney Lane
    London SE19 3BD
    United Kingdom

You have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection: https://ico.org.uk/. You can make a complaint at https://ico.org.uk/make-a-complaint/. If you are in the EEA, you may also contact your local data protection authority.