Privacy Policy

Last updated: September 13, 2026

1. Introduction

Diojen Tech FZ-LLC ("Growty," "we," "our," or "us") operates Growty.ai. Growty — a personal LinkedIn engine. It helps you turn your own work into LinkedIn posts written in your words and publishes them to your own LinkedIn profile only after you approve each one. This Privacy Policy explains what we collect, why, who processes it, how long we keep it and how you can exercise your rights.

2. Information We Collect

2.1 Information you give us

  • Account: name, email address and — if you register with a password — a hashed password. Never stored in plain text.
  • Profile and voice: what you tell us during onboarding (your role, experience, topics you care about, how you write) and the voice profile built from it. You review and can edit all of it.
  • CV or LinkedIn profile PDF: if you import one, the file is parsed in memory during the request. Neither the file nor its raw text is stored or logged. Only the structured profile fields you review are saved; we do not extract phone numbers, postal addresses, dates of birth or photos.
  • Content: ideas, drafts and posts you write or generate in Growty.
  • Waitlist: your email address, if you join the waitlist.

2.2 Information from sign-in providers

If you sign in with LinkedIn (or another provider such as Google or GitHub where offered) we receive your name, email address, profile photo and the provider's account identifier. For LinkedIn we also receive a publishing token; see Section 8.

2.3 Information collected automatically

  • Server logs: IP address, browser type, requested pages and timestamps, used for security and debugging.
  • Bot protection: Cloudflare Turnstile runs on our sign-up and sign-in forms and may collect interaction data to verify you are human.
  • Analytics: We currently run no analytics; only strictly necessary session cookies are set.

3. How We Use Your Information

  • To build your voice profile and draft LinkedIn posts that sound like you
  • To validate drafts against our six writing rules before showing them to you
  • To publish a post to your LinkedIn profile when — and only when — you click Publish
  • To keep your account secure, enforce usage limits and prevent abuse
  • To comply with legal obligations

We do not use your data to train AI models, and we do not allow our AI provider to do so (Section 4). We do not post on your behalf on a schedule, read your LinkedIn messages or connections, or collect engagement statistics from LinkedIn.

4. AI Processing

Drafting, voice-profile extraction and rule validation are performed by the OpenAI API, operated by OpenAI, L.L.C. in the United States. What we send: your onboarding answers, the text extracted from a CV or LinkedIn PDF you import, your voice profile and the draft being written or checked.

  • OpenAI does not use data sent through its API to train its models.
  • OpenAI may keep API inputs and outputs for up to 30 days for abuse monitoring, after which they are deleted.
  • We disable OpenAI's response storage on every request and never upload files to OpenAI; documents are converted to text on our own server first.
  • Everything the AI produces is shown to you as a draft. Nothing is published without your click.

5. Who Processes Your Data

We share personal data only with the service providers below, each bound by a data processing agreement, and with authorities when the law requires it. We do not sell personal data.

ProcessorPurposeWhere
OpenAI, L.L.C.AI drafting, voice-profile extraction and validation (API only; no training on your data; storage disabled per request)United States
Our own servers (Coolify-managed PostgreSQL database)Hosting, database and rolling backups, operated by Diojen Tech FZ-LLCOur hosting provider's data centre (region disclosed on request)
Cloudflare, Inc.DNS, TLS termination, proxy and Turnstile bot protectionGlobal edge network
LinkedIn CorporationSign-in identity and publishing to your own profile, only when you click PublishUnited States / Ireland (per LinkedIn's terms)

6. Data Security

  • In transit: all traffic uses HTTPS/TLS.
  • Sign-in tokens: the LinkedIn publishing (access) token and refresh tokens are encrypted at rest in our database.
  • Passwords: stored only as bcrypt hashes.
  • Documents: CV and LinkedIn PDFs are processed in memory and never written to disk or object storage.
  • Abuse controls: rate limiting on sign-in and AI endpoints; Turnstile on public forms.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Data Retention

DataHow long we keep it
Account, profile, voice profile, drafts and postsUntil you ask us to delete your account
Onboarding answers and the profile fields extracted from your CVStored with your profile; removed with your account
CV or LinkedIn PDF file and its raw textNever stored — processed in memory for the duration of the request
LinkedIn publishing tokenUntil you disconnect LinkedIn or delete your account; LinkedIn expires it after at most 60 days regardless
Data sent to OpenAIUp to 30 days on OpenAI's side for abuse monitoring
Database backupsRolling 14-day window; deleted data leaves backups within that time
Application logsSize-rotated on the server and overwritten; not archived
Waitlist emailUntil you ask us to remove it

8. LinkedIn

Growty uses the official LinkedIn API. When you sign in with or connect LinkedIn, LinkedIn sends us your name, profile photo, email address and member ID, plus an access token that lets us publish to your own profile. We store the token encrypted.

  • We publish a post only when you click Publish on that post. There is no scheduled or automatic posting.
  • We do not read your connections, messages, feed or the reactions and comments on your posts.
  • Disconnecting (Connections page) deletes the access token from our database immediately. If LinkedIn is your only sign-in method we keep your member ID so you can still sign in; it goes when your account is deleted.
  • To revoke Growty on LinkedIn's side as well, open LinkedIn Settings & Privacy → Data privacy → Permitted services and remove Growty. Disconnecting is how you withdraw consent; we honour deletion requests for LinkedIn data at [email protected].

9. Your Rights

Depending on where you live, you may have the right to:

  • Access and correct your data — your profile, voice profile and drafts are editable in the app.
  • Delete your account and all associated data — email [email protected] from your account address and we complete the deletion within 30 days.
  • Export your data in a machine-readable format — on request to [email protected], delivered within 30 days.
  • Withdraw consent for LinkedIn access (disconnect) or analytics (cookie settings) at any time.
  • Object to processing, and lodge a complaint with your local data protection authority.

10. International Data Transfers

We are based in the United Arab Emirates. Your data is stored on our hosting infrastructure and processed by OpenAI in the United States, and by the other providers listed in Section 5. Where your local law requires safeguards for such transfers we rely on the Standard Contractual Clauses included in our providers' data processing agreements. We do not currently offer EU-only data residency.

11. Children's Privacy

Growty is not intended for users under 18 years of age. We do not knowingly collect information from children under 18.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

Diojen Tech FZ-LLC
VUPR0809 - Compass building - Al Hulaila
AL Hulaila Industrial Zone-FZ
Ras Al Khaimah, United Arab Emirates

Email: [email protected]