01Who is responsible for your data
The controller of personal data processed through Growth Plan is Programmable, LLC (company number [COMPANY REGISTRATION NUMBER]), 3607 10th St NW, Washington, DC, United States (“we”, “us”). This policy covers programmable.marketing, the plans and reports it produces, and the emails we send about them.
Contact us about anything in this policy, or to exercise your rights, at [email protected]. We are a small company and have not appointed a data protection officer; that address reaches the people responsible for privacy.
This policy is written to meet the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, and to inform customers in the United States. It applies to buyers and visitors, and to people who are mentioned in public sources that a plan draws on (section 9).
02The short version
- We research companies from public sources. We do not ask for, and do not want, private information about anyone.
- From you we keep an email address (if you give one), payment references from Stripe, a hashed form of your IP address for abuse prevention, and any notes you add to a plan.
- We use no analytics, advertising or tracking cookies and no third-party scripts. See the Cookie Policy.
- Plans are public by default. You can ask us to unpublish or delete one.
- We never sell personal data or share it for advertising.
03What we collect
Information you give us
- The domain you submit, for a preview or a plan. This identifies a company, not you.
- Your email address. Optional when you buy a plan; required when you request a plan while purchases are closed. We store it with the purchase or request and as the plan’s notification address.
- Idea statuses and notes added by whoever holds a plan’s edit link. Notes are free text. They are visible to anyone who can see the plan, so please keep personal or confidential information out of them.
- Messages you send us, for example support, refund or privacy requests, and anything you include in them.
- A Slack webhook address, only if you use “Send to Slack”. We use it once to post the summary and do not store it.
Information created when you use the Service
- Payment records: the Stripe checkout session and customer identifiers, amount, currency, status, dates, and any refund or dispute. Stripe holds your card details and billing address; we never see full card numbers.
- Hashed IP address: to limit abuse we keep a salted SHA-256 hash of your IP address (not the address itself) with free previews and plan requests, and in memory for rate limiting.
- Email delivery records: which emails we sent about a plan, to which address and when, so we never send the same one twice.
- Server and security logs: our web server (Caddy) and Cloudflare record IP addresses, user agents, requested URLs and timestamps. Our application logs may contain the email address and domain linked to a purchase.
- Usage and cost records for each AI call (model, token counts, cost, the domain). These contain no personal data about you.
- The plan edit key stored in your browser’s local storage (see the Cookie Policy).
Information about companies, from public sources
To write a plan we gather public information about the company behind the domain: its website, search results (through our self-hosted SearXNG search and Jina AI), review and directory sites, Reddit, Hacker News and Stack Exchange, GitHub, SEC EDGAR filings, job boards, app stores, public certificate and domain records, and Google’s Chrome UX Report. This information is about businesses, but it can incidentally include personal data, such as a reviewer’s name, a Reddit or GitHub username, a person named in a job post or press article, or a public professional profile that appears in search results. Section 9 explains how we treat that data.
04Why we use it, and our lawful bases
Under the GDPR and UK GDPR we must have a lawful basis for each use of personal data. Ours are:
- Producing and delivering the plan you asked for, including the plan-started, plan-ready and plan-failed emails and your edit linkData:Domain, email, edit key, plan notesLawful basis:Contract (Art. 6(1)(b)): needed to provide what you bought or requested
- Taking payment, issuing refunds, handling disputesData:Payment records, emailLawful basis:Contract; legal obligation for records we must keep
- Follow-up emails: 48-hour reminder, day 2, 5 and 10 follow-ups, weekly check-insData:Email, plan progressLawful basis:Legitimate interests in helping customers get value from what they bought. Every email has a one-click opt-out; where local law requires consent for such emails we rely on the customer relationship exemption or ask first
- Researching companies from public sources to write plansData:Public information, which may incidentally include personal data of third partiesLawful basis:Legitimate interests (see the balancing note below)
- Preventing abuse, rate limiting, security, fraud preventionData:Hashed IP, server logsLawful basis:Legitimate interests in keeping the Service safe and available
- Answering your messages and requestsData:Your messages, emailLawful basis:Legitimate interests; contract where it concerns a purchase
- Keeping tax and accounting records; responding to lawful requestsData:Payment recordsLawful basis:Legal obligation (Art. 6(1)(c))
- Optional analytics or marketing cookies (none today)Data:Device identifiersLawful basis:Consent (Art. 6(1)(a)), asked for first, withdrawable at any time
Balancing note: researching companies from public sources
Our interest, and our customers’, is to understand a company’s market position from what that company and the public have chosen to publish. We have weighed that interest against the interests of people who might be mentioned in those sources and concluded it is not overridden by them, because:
- we target companies, not individuals: we never search for a person by name, and we do not build profiles of individuals;
- we only use information that is already public, mostly published by the company itself or posted publicly by the person (for example a public review);
- personal data appears only incidentally, and plans use it for business analysis such as summarising what reviewers say about a product, not to make decisions about anyone;
- we do not look for special category data or use the Service to infer sensitive characteristics, and a published plan shows our analysis with short cited excerpts, not the full raw pages collected for it;
- anyone can object and ask for removal, and we act on it quickly (section 9).
You can ask us for more detail about this assessment at [email protected]. We do not use personal data for automated decisions that have legal or similarly significant effects on anyone (section 11).
05Who we share it with
We use the service providers below. Those acting as our processors may use the data only to provide their service to us, under a data processing agreement. We never sell personal data and never share it for advertising.
- Hetzner OnlineWhat they do:Hosts our servers and databaseLocation:Helsinki, Finland (EU)
- CloudflareWhat they do:DNS, content delivery, proxy and security filtering; sees IP addresses and requestsLocation:Global network; US company
- StripeWhat they do:Payments. Through Stripe Managed Payments, Stripe acts as merchant of record and reseller for the sale and handles tax; for that it is an independent controller under its own privacy policyLocation:United States and EU
- AnthropicWhat they do:AI processing of research material to write plans and previewsLocation:United States
- OpenAIWhat they do:AI processing, used as a secondary providerLocation:United States
- Zoho (Zoho Mail)What they do:Sends our emails and hosts our support inboxLocation:Zoho data centre for our account
- Jina AIWhat they do:Web search and page reading for research (receives queries and URLs about companies, not your details)Location:Provider cloud
- Google (Chrome UX Report API)What they do:Public website performance data (receives the domain only)Location:United States
- GitHub (API)What they do:Public repository data (receives a company or organisation name only)Location:United States
Public sources we query. When researching a company, our servers send its name or domain as a search or lookup to public services such as search engines (through our self-hosted SearXNG instance), Reddit, Hacker News, Stack Exchange, SEC EDGAR, app stores, certificate transparency and domain registration lookups and the Internet Archive. No information about you is sent to them.
Optional integrations. The software can also use Groq (AI processing, US), Resend (email delivery, US), Apify (web scraping) and Apollo.io (business contact and company data, US). We do not rely on them for the core Service; if we switch any of them on, we will list it in the table above before doing so.
Others. Anyone with a plan’s link can see a public plan (section 8). We may disclose data to professional advisers, to a buyer of our business (under confidentiality), or where the law requires it, for example to a court or tax authority.
06International transfers
Our servers and database are in the EU (Finland). Some providers above are based in, or process data in, the United States or other countries outside the EU and UK. When personal data leaves the EU or UK we rely on one of these safeguards:
- where the provider participates in the EU-US Data Privacy Framework (and its UK Extension), that framework and the related adequacy decisions;
- otherwise, the European Commission’s Standard Contractual Clauses (with the UK Addendum for UK data) in the provider’s data processing terms, together with any supplementary measures needed;
- an adequacy decision for the destination country, where one exists.
You can ask us for a copy of the relevant safeguards at [email protected].
07How long we keep it
- Plans, their research data, versions, idea statuses and notes, and the plan’s notification emailHow long:Until you ask us to delete them, or 24 months after the plan was last refreshed or updated, whichever is sooner
- Free preview records with hashed IP addressesHow long:30 days (deleted automatically)
- Plan requests (domain, email, hashed IP)How long:12 months (deleted automatically)
- Generation job recordsHow long:90 days after the job finishes (deleted automatically)
- Email delivery recordsHow long:As long as the plan they relate to
- Payment and refund recordsHow long:7 years after the purchase, for tax and accounting. If you ask us to erase your data earlier, we remove your email from them and keep only what the law requires
- Server and security logsHow long:30 days
- In-memory rate-limit countersHow long:Up to one hour; cleared on restart
- Support and privacy correspondenceHow long:3 years after the matter is closed
Stripe keeps its own records of the payment for as long as the law requires it to, under its own privacy policy.
08Public plans
A completed plan is published at /growth-plan/<domain> and can be found by anyone with the link and by search engines; recent plans may appear as examples on our homepage. A plan never shows the buyer’s email address or payment details. It does show idea statuses and notes. If you bought the plan or represent the company it is about, email [email protected] to make it private (it then returns “not found” to everyone, including its PDF, exports and preview image) or to delete it.
09If you are mentioned in a plan
If your name, username, review, post or other information appears in a plan because it was in a public source about a company, you have the same rights as anyone else under this policy, including the right to object and to ask for erasure. Email [email protected] with the plan’s address and what you would like removed. We will:
- remove or anonymise the information in the plan and its stored research, normally within five business days and in any case within one month;
- check any later refresh of that plan for the same information;
- tell you what we did.
We did not collect this information from you directly. The source is the public page it came from, which we can identify for you on request. We cannot remove the information from the original source; for that, please contact the site that published it.
10Your rights
Under the GDPR and UK GDPR you have the right to:
- Access the personal data we hold about you and get a copy;
- Rectification of data that is inaccurate or incomplete;
- Erasure of your data, where there is no overriding reason for us to keep it (such as tax records);
- Restriction of processing while a complaint or correction is being dealt with;
- Portability: receive data you gave us in a structured, machine-readable format (we provide JSON);
- Object to processing based on legitimate interests, including the follow-up emails and research described above, and to direct marketing at any time;
- Withdraw consent at any time, where we rely on consent;
- Complain to a supervisory authority, such as the data protection authority where you live or work (in the UK, the Information Commissioner’s Office at ico.org.uk). We would appreciate the chance to resolve your concern first.
How to exercise them: email [email protected] from the address you used with us, or tell us the plan and purchase involved. We may ask for information to confirm your identity. We respond within one month; if a request is complex we may extend that by up to two further months and will tell you why. We do not charge unless a request is clearly unfounded or excessive.
US residents: depending on your state, you may have similar rights to know, access, correct and delete personal information. Use the same email address. We do not sell or share personal information for cross-context behavioural advertising, and we will not discriminate against you for exercising your rights.
11Automated decision-making
Plans are generated by AI, but they are analyses of companies. We do not make decisions about individuals based solely on automated processing, including profiling, that have legal or similarly significant effects on them. Rate limiting automatically blocks repeated requests from the same hashed IP for a short time; this is a security measure and does not otherwise affect you.
12Children
The Service is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you think a child has given us personal data, contact us and we will delete it.
13How we protect your data
- All traffic is encrypted in transit with HTTPS; Cloudflare filters malicious traffic.
- Servers and the database are hosted in the EU, and access is limited to the people who run the Service.
- We store a salted hash of IP addresses instead of the address itself, and keep card details out of our systems entirely (Stripe handles them).
- A plan’s edit key is delivered in the part of the link that browsers do not send to servers, so it stays out of logs; admin functions require a separate secret.
- The research crawler refuses to fetch private network addresses, and generated reports are escaped and rendered in a sandboxed browser.
- We keep data only as long as section 7 allows and delete it automatically where we can.
14Changes to this policy
We will update this policy when our practices or the law change, and change the “Last updated” date above. If a change materially affects how we use your personal data and we have your email address, we will tell you before it takes effect.
15Contact
Privacy questions and requests: [email protected]. Post: Programmable, LLC, 3607 10th St NW, Washington, DC, United States.