Groowth

Privacy policy

How FIGUE handles personal data in Groowth: what is collected, why, for how long, and what you can ask for.

Last updated August 2026

Who is responsible

The controller is FIGUE, Société par actions simplifiée (SAS), RCS Mulhouse 911 453 835, registered office 57 rue Victor Schoelcher, 68200 Mulhouse, France. Every request about this policy goes to hello@figue.io.

What we collect from you

Your account (name, email address, and the avatar you choose to upload), the workspace you create, the members you invite, the public profiles you choose to track, and the folders, goals and reports you build around them. Billing data (company name, address, payment method) is collected and held by our payment provider, not by us: we store an identifier and the state of the subscription.

What we read from a tracked profile

Only what any visitor to that profile can see: the display name, the avatar, the follower count, and the published posts with their public like, comment and view counts. Groowth never logs in to any network on your behalf, and never asks for a password or an admin access.

What we never collect

Reach, impressions, private messages and any other metric that requires being logged in to the account. They are not accessible, they are not in our data model, and no screen in Groowth shows them. If a tool promises them without a network login, be sceptical.

Why we process it

Running the service you subscribed to, and performing the contract that binds us: creating your workspace, reading the profiles you added, counting your posts, sending the transactional emails the product needs. Our legitimate interest covers keeping the service secure and measuring its audience. Prospecting emails, if any, rely on your consent and every one of them carries an unsubscribe link.

The people behind the tracked profiles

A tracked profile is public data, collected in the legitimate interest of the workspace that follows it and of the service that consolidates it. It is read once per day, never enriched with anything private, and a profile that goes private or disappears stops being read. Anyone can ask for a profile to stop being tracked by writing to us.

Shared, not duplicated

Public profile data is collected by external providers and shared across the product: two workspaces tracking the same public profile read the same rows and trigger a single read per day. That is what keeps the free audit free, and what keeps a network from being read twice for the same thing.

The free audit

The free audit reads a public profile you point us at. It stores that public profile in the same shared layer and starts no daily tracking: nothing recurring happens until someone adds the account to a workspace.

How long we keep it

Account and workspace data is kept for as long as the workspace exists, then deleted when you delete it. Measurement history is kept for the retention the plan announces. The raw payloads returned by the collection providers are purged after 90 days, minus the last one per account and per read kind, which is kept so a collection failure can be diagnosed. Billing records are kept for the duration the law imposes on accounting documents.

Who else processes it

Groowth relies on the providers below, each bound by a data processing agreement and each acting on our instructions only. Some are established outside the European Union; those transfers rely on the European Commission's standard contractual clauses.

Vercel
Application hosting
PlanetScale
Database
Apify
Collection of public profile data
Upstash
Background jobs and scheduling
DigitalOcean Spaces
Avatars, logos and generated reports
Resend
Transactional email
Stripe
Payments and invoicing
Sentry
Error monitoring
Datafast
Audience analytics

Your rights

Access, rectification, erasure, portability, restriction, and objection to a processing based on legitimate interest. Write to us and we answer within one month. You may also lodge a complaint with the CNIL, the French supervisory authority.

Cookies

Groowth sets the cookies its own authentication needs to keep you signed in, and nothing else: no advertising cookie and no cookie-based tracker. Audience measurement on the public site is cookieless and does not profile visitors, and error monitoring records technical diagnostics, never browsing behaviour.

Where a signup came from

When you create an account from a link on one of our public pages, that page is recorded once against the new account, so we know which article brings people in. It is a single page address, carried in the link you followed rather than in a cookie, and it is never collected from anyone who does not sign up. It is not linked to the cookieless audience measurement above, which stays unable to identify anybody.

Access and deletion

Deleting a workspace removes its organisation, folders, tracked accounts, goals and reports. For anything else (a copy of your data, a profile to stop tracking, a question about this page), write to hello@figue.io.

Questions about this page: hello@figue.io