Privacy Policy

Last updated: February 18, 2026

GrowthMastery.ai ("we," "us," or "our") is operated by Joe McVeen. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at growthmastery.ai (the "Service"). By using the Service, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

1.1 Information You Provide

  • Account information: name, email address, and password when you create an account.
  • Payment information: billing details processed securely through Stripe. We do not store your full credit card number on our servers.
  • Business information: company name, website, industry, and other details you provide to build funnels and marketing materials.
  • Communications: messages, feedback, and support requests you send to us.

1.2 Information from Third-Party Integrations

When you connect third-party accounts to GrowthMastery.ai, we may receive information from those services as described below.

1.3 Automatically Collected Information

  • Usage data: pages visited, features used, timestamps, and interaction patterns.
  • Device information: browser type, operating system, IP address, and device identifiers.
  • Cookies and similar technologies: we use cookies and local storage to maintain your session, remember preferences, and analyze usage. See Section 5 for details.

2. Meta (Facebook & Instagram) Data

When you connect your Meta (Facebook/Instagram) account to GrowthMastery.ai, we request access to the following data through the Meta API:

  • Facebook Ad Account data: ad campaigns, ad sets, ads, spend, performance metrics, and audience insights associated with your connected ad accounts.
  • Facebook Page data: page information, posts, engagement metrics, and page insights for pages you manage.
  • Instagram Account data: profile information, media, follower counts, engagement metrics, and Instagram Insights for connected professional or business accounts.

2.1 How We Use Meta Data

  • To display your ad performance and analytics within the GrowthMastery.ai dashboard.
  • To provide AI-powered insights and recommendations to optimize your ad campaigns.
  • To help you build and manage marketing funnels connected to your Meta advertising.

We do not sell your Meta data to third parties. We do not use your Meta data for purposes unrelated to the services you have requested.

2.2 Revoking Meta Access

You can revoke GrowthMastery.ai's access to your Meta data at any time by:

Upon revocation, we will stop accessing new data from Meta and delete cached Meta data within 30 days, unless retention is required by law.

3. How We Use Your Information

  • To provide, maintain, and improve the Service.
  • To process transactions and send billing-related communications via Stripe.
  • To generate AI-powered content, recommendations, and analytics using Google Gemini AI. Your inputs may be sent to Google's API for processing; we do not use your data to train third-party AI models.
  • To send transactional emails (account verification, password resets, notifications) via Postmark.
  • To respond to your inquiries and provide customer support.
  • To detect, prevent, and address technical issues and security threats.
  • To comply with legal obligations.

4. Third-Party Service Providers

We use the following third-party services to operate the platform:

  • Supabase: database hosting and user authentication. Data is stored securely on Supabase's infrastructure.
  • Stripe: payment processing. Stripe collects and processes your payment information under their own Privacy Policy.
  • Meta (Facebook/Instagram): advertising data integration as described in Section 2.
  • Google Gemini AI: AI-powered content generation and analysis.
  • Cloudflare: DNS, CDN, and security services. Cloudflare may process request metadata (IP addresses, headers) for security and performance.
  • Postmark: transactional email delivery.
  • Vercel: application hosting and deployment.

5. Cookies and Tracking

We use the following types of cookies:

  • Essential cookies: required for authentication and core functionality (session tokens, CSRF protection).
  • Preference cookies: remember your settings and preferences.
  • Analytics cookies: help us understand how visitors interact with the Service so we can improve it.

You can control cookies through your browser settings. Disabling essential cookies may prevent you from using the Service.

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, legal compliance).

Cached data from third-party integrations (such as Meta) is retained only while your integration is active and is deleted within 30 days of disconnection.

7. Data Security

We implement industry-standard security measures including encryption in transit (TLS), encrypted data at rest, secure authentication, and regular security reviews. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

8. Your Rights

8.1 General Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data.
  • Object to or restrict processing of your data.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time where processing is based on consent.

8.2 GDPR (European Economic Area)

If you are in the EEA, our legal bases for processing your data include: performance of a contract (providing the Service), legitimate interests (improving and securing the Service), and consent (where applicable). You have the right to lodge a complaint with your local data protection authority.

8.3 CCPA (California)

If you are a California resident, you have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell your personal information. To exercise your rights, contact us at the email below.

9. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at: