Privacy Policy
Last updated 9 August 2026.
Grovvi is operated by Uzair Abdullah, a sole proprietor based in Pakistan, trading as Grovvi, who is the data controller for the data described here. Contact: support@grovvi.net.
What we collect
Account data
Your name, email address, and the organization you belong to. This comes from you at signup and is held by our authentication provider.
Billing data
Paddle, our merchant of record, takes your payment and holds your payment details. We never see or store your card number. We receive and store the fact that a payment succeeded or failed, its amount, and identifiers that link it to your account.
Content you give us
Your company profile, the competitors and websites you name, keywords and topics you enter, and any call or chat transcripts you upload.
Data we fetch for you
Search results, keyword metrics and news items from search data providers, and the public pages of the competitor sites you name, fetched by our crawler. See grovvi-bot.
Usage data
Product events, error reports and server logs, so we can see what broke and what is slow. These include an account identifier, a timestamp and technical details such as browser and IP address.
Why we use it
- To run the service you asked for, which is our contract with you.
- To take payment and meet tax and accounting obligations.
- To keep the service working and secure, and to fix faults, which is our legitimate interest.
- To answer you when you contact support.
We do not sell your data. We do not use your content to train our own models.
Transcripts, and who sees them
This one deserves its own section, because uploaded transcripts are the only data in the product that can belong to someone who never signed up, such as the other voice on a sales call.
Transcript text you upload is sent to DeepSeek, a language model provider based in China, which processes it to extract topics. There is no setting that routes it elsewhere. DeepSeek's own terms govern what they do with data sent to their API, and you should read them if this matters to you. If it is not acceptable for your data, do not use the transcript upload feature. Every other part of Grovvi works without it.
You are responsible for having the right to upload a recording or transcript of a conversation, including any consent the law where you operate requires.
Who else processes your data
We use these providers to run the service. Each one sees only what it needs.
| Provider | What it does | What it sees |
|---|---|---|
| Paddle | Payments, invoicing, tax, merchant of record | Your name, email, billing address, payment details |
| Clerk | Accounts and sign in | Your name, email, session data |
| Neon | The database | Account records and everything you create in the product |
| Cloudflare | Hosting, file storage, embeddings | Requests, uploaded files, cached pages, text sent for embedding |
| Fly.io | Background jobs | Job payloads for work you start |
| DataForSEO | Search results, keyword volume, news | The keywords and domains you research |
| DeepSeek | Language model for most processing, including transcripts | Text you submit, and transcript text |
| Moonshot AI | Language model for competitor page analysis | Public competitor page text |
| Zhipu AI | Language model for quality review of output | Generated output under review |
| PostHog (EU region) | Product analytics | Product events, account identifier, IP address |
| Sentry | Error reporting | Error details and technical context |
| Axiom | Server logs | Request logs and technical context |
| Resend | Email delivery | Your email address and message contents |
| Upstash | Rate limiting | Account identifier and request counts |
| Inngest | Job scheduling | Job metadata |
These providers operate in several countries, including the United States, the European Union and China, so using Grovvi means your data crosses borders. Product analytics are hosted in the European Union. That does not make the rest of the service EU resident, and the table above is the honest answer to a data residency question.
We update this list as the product changes. Material additions are announced before they take effect.
How long we keep it
- Uploaded transcripts: 2 years by default, and your organization can set a shorter period in settings. A daily job deletes them when the period is up.
- Topics, keywords, calendars and other output: kept while your account exists, because it is your work.
- Cached competitor pages: 30 days.
- Account and billing records: kept while the account exists, and afterwards for as long as tax and accounting law requires.
- Logs and error reports: kept for the retention period of the provider that holds them, which is measured in weeks, not years.
When you close your account you can ask us to export your data for 30 days, after which we may delete it.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, or stop a particular use of it. Write to support@grovvi.net and we reply within 30 days. If you are in the European Union or the United Kingdom you also have the right to complain to your data protection authority.
Cookies
The app sets cookies that keep you signed in. These are necessary for it to work. Product analytics use a cookie to recognize a returning browser. This website, at grovvi.net, sets no cookies at all.
Security
Data is encrypted in transit and at rest by our providers. Access to production data is limited to the operator of the service. Connected third party account tokens are encrypted before they are stored. No system is perfectly secure, and we do not claim otherwise.
Children
Grovvi is a business tool and is not for anyone under 18. We do not knowingly collect data from children.
Changes
We update this policy as the product changes. The date at the top shows the last change. Material changes are announced by email or in the app before they take effect.