Effective 2 August 2026 · Updated 26 September 2026 · Growfis
Growfis connects the tools your store already uses — Shopify, Meta Ads, Shiprocket, Google Analytics 4, Google Search Console and Google Ads — behind one AI assistant. This policy describes what we access, why, and what control you keep.
Account data: your name and email from Google sign-in, and your workspace membership. Store connections: OAuth tokens and API credentials for the services you explicitly connect. Credentials are encrypted at rest (AES-256-GCM) and are never shown back in plain text. Operational data: the store data those services return (orders, products, ad performance, shipping status, analytics) is read through official APIs to answer your questions and run the workflows you configure. Activity records: tool calls, workflow runs and approvals are logged so every change the agent makes is auditable by you.
Solely to operate the product for your store: answering questions from live data, executing the actions you approve, running scheduled workflows, and showing dashboards. We do not sell your data, use it for advertising, or train AI models on it.
To answer questions about orders and to arrange shipping, returns and exchanges, Growfis reads personal data belonging to yourcustomers from the services you connect — typically a customer’s name, email address, phone number, shipping address and order history. That data is read through official APIs at the moment it is needed and shown only to you and your workspace members. We do not build a separate customer database, never sell it, never use it for advertising, and never use it to train AI models. Where a customer’s details form part of a question you asked or a record of an action taken on your behalf, they can persist inside saved chat history, the agent’s memory, workflow run records and the activity log — and are removed when those records are deleted. For this data you are the controller and Growfis acts as a processor on your instructions.
Conversations and the data needed to answer them are processed by Anthropic’s Claude models — via your own Claude plan (the Growfis connector in the Claude app, or the Claude Code plugin) or via API for hosted features like scheduled digests. Anthropic’s commercial terms apply to that processing; Anthropic does not train on API data by default.
If you connect Meta Ads, we access your ad account through Meta’s Marketing API — campaign, ad set, ad and insights data (spend, reach, ROAS and similar performance metrics), and, when you ask the agent to, we create or update campaigns, ad sets, ads and creatives in your account. Platform Data is used only to provide these features to you.
Customer audiences. If you ask the agent to build a customer-list audience, identifiers from your store — customer email addresses, phone numbers and names — are normalized and hashed with SHA-256 on our servers before they are sent, so Meta receives irreversible hashes and never the raw values. Two identifiers that Meta forbids hashing (an external ID you supply, and a mobile advertiser ID) are sent as given. These uploads happen only when you explicitly request them, only into audiences in your own ad account, and the data is used for no other purpose. You can delete an audience at any time from Meta Ads Manager or by asking the agent, which removes the uploaded identifiers from Meta.
Platform Data is never sold, shared with third parties, or used for our own advertising or model training. It is processed transiently to answer your requests; ad-account credentials are stored encrypted and are deleted when you disconnect Meta from Settings or request account deletion (completed within 30 days). To revoke access at any time, disconnect in Settings or remove the app from your Meta Business integrations.
Google sign-in provides your email and profile name for authentication. If you connect GA4 or Search Console, we access those properties read-only to answer analytics questions and show your traffic, funnel and search dashboards. If you connect Google Ads, we use the one Google Ads account you choose to answer your questions about your advertising — reading campaigns, ad groups, keywords, search terms and products with their spend, clicks and conversions — and, only when you ask, to create campaigns, pause or delete them, add keywords or change budgets for you. New campaigns are always created paused, and nothing starts spending or has its budget raised until you approve it in Growfis. Growfis’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never used for advertising, and never transferred to third parties except as needed to provide the features you requested. We do not use Google user data to develop, improve, or train generalized or non-personalized AI and/or ML models. It is shown only to you and processed transiently to answer your requests. You can revoke access anytime from Settings or from your Google account permissions; disconnecting deletes the stored Google OAuth tokens, and any cached analytics data is removed within 30 days.
We apply the following protection mechanisms to all sensitive data, including Google user data, OAuth tokens and connected-service credentials:
Data goes only to the infrastructure that runs the product: AWS (hosting, in ap-south-1), Neon (database), Anthropic (AI processing), and the services you connected acting on your instructions. No other third parties.
If one of your customers asks to see or delete the personal data held about them, or you receive such a request through your store, email support@growfis.com and we will locate and action it across chat history, agent memory, workflow records and audit logs. We complete these requests within 30 days, and confirm back to you what was found and removed.
Connections are revocable anytime from Settings, which invalidates the stored credentials and stops all further access to that service immediately. Operational data is kept only while it is useful to you, and every store of it is bounded and reachable: the agent’s memory is capped per store and can be viewed, edited or deleted from the Memory page at any time; chat history can be cleared per conversation from the app; returns, workflow and activity records are retained as your operating history until you delete them or close your account. We do not retain operational data after an account is closed. Email support@growfis.com to have your account and all associated data deleted; we complete deletion within 30 days.
Questions about this policy: support@growfis.com. We’ll update this page if practices change, with the effective date above.