Legal

Privacy Policy

What personal data we collect, why, and your rights.

All policies

Effective 17 June 2026 · ForgeAI Studio Ltd (company no. 17175307), West Bromwich, United Kingdom.

1. Controller

ForgeAI Studio Ltd (company no. 17175307), West Bromwich, United Kingdom, is the data controller for personal data processed through GrowthDept. Contact: support@novastacks.co.uk.

2. What we collect

Account data (name, email, authentication identifiers). Business data you provide or we crawl from your public website (offers, audience, brand). Usage data (logs, device/ browser, actions in the app). Content you create in the Service. Data from integrations you connect, within the scopes you grant.

We do not sell your personal data and we do not use it to train third-party models for unrelated purposes.

3. Why we use it (lawful bases)

To provide and secure the Service (performance of contract). To improve and support the Service and prevent abuse (legitimate interests). To send service and, with consent where required, product communications. To comply with legal obligations.

4. AI processing

To generate strategy, content and analysis we send relevant business and content data to our AI model provider(s) acting as our processor under contract. We minimise what is sent and do not include payment card details. See our Responsible AI Policy.

5. Sharing & sub-processors

We share data with vetted sub-processors who help us run the Service (hosting & database, AI model provider, email delivery, and any integration you connect). All are bound by data-protection terms. We may disclose data where required by law.

6. International transfers

Where data is transferred outside the UK/EEA, we rely on appropriate safeguards such as the UK IDTA / EU Standard Contractual Clauses.

7. Retention

We keep personal data for as long as your account is active and as needed to provide the Service, then delete or anonymise it within a reasonable period unless a longer period is required by law.

8. Your rights

You have the right to access, rectify, erase, restrict, port and object to processing of your personal data, and to withdraw consent. To exercise these, email support@novastacks.co.uk. You can also complain to the UK Information Commissioner's Office (ICO).

9. Data from Meta Platforms (Facebook & Instagram)

If you connect a Facebook Page or Instagram account, we access only the data covered by the permissions you approve in Meta's consent flow: your list of Pages, the ability to publish the posts you approve, engagement data on your own posts, and comments on your own posts so we can draft replies for your approval. We use this data solely to provide the Service to you — never for advertising to others, profiling unrelated to your business, or resale. Access tokens are encrypted at rest. Disconnecting the integration in Settings deletes our copies of the associated tokens and stops all access; you can also revoke GrowthDept's access at any time from your Facebook settings. See our Data Deletion page for full removal instructions.

10. Data from Google services

If you connect a Google service, we access only the data covered by the OAuth scopes you approve on Google's consent screen, via Google's official APIs. Google Search Console (read-only): search-performance data for the site you select — queries, pages, clicks, impressions, click-through rate, position and sitemap status — used solely to show you your SEO performance and generate SEO recommendations. Google Analytics (read-only): traffic and conversion reports for the GA4 property you select — users, sessions, events and conversions — used solely to compute your growth metrics, reports and channel attribution. Google Calendar (read-only): we read events and free/busy availability on the calendar you select, to show you meeting metrics and to avoid proposing times when you are busy; we do not create, change or delete anything on your calendar, and we do not read calendar settings or manage your calendars. Gmail (send-only): where you choose Gmail as your sending account, we send only the individual messages you have approved in GrowthDept, from your own address, using Gmail's official API; the scope we request cannot read, search or delete your mail, and we never do so. YouTube (read-only): if you connect YouTube, we read your own channel's video list and its analytics reports to show you how your videos perform; we do not read other people's data and we do not change your channel.

How we store and share it: OAuth tokens are encrypted at rest (AES-256-GCM) with a key held outside our database. Google user data is used only to provide the features above to you; it is never sold, never used for advertising, never used to train generalised AI models, and never transferred to third parties except the sub-processors that host the Service under contract for us. Humans at GrowthDept do not read this data except with your affirmative consent (e.g. a support request), for security purposes, or where required by law. Disconnecting an integration deletes our stored tokens immediately, and you can also revoke GrowthDept's access at any time at https://myaccount.google.com/permissions.

Limited Use disclosure: GrowthDept's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

11. Security & changes

We protect data with the measures described in our Security Policy. We may update this policy; the effective date below reflects the latest version.

Questions about this policy? Email support@novastacks.co.uk.