Privacy Policy
Effective: July 21, 2026 (draft) · Growth Force, a SignalApps company
This policy explains how SignalApps (“we”) handles personal data in connection with Growth Force (the “Service”). We handle two categories of data differently: account data about the people who use the Service, and workspace content — including third-party personal data that our customers upload or source, for which the customer is the controller and we act as processor on their instructions.
1.What we collect
- Account data: name, work email, workspace/agency membership, authentication data.
- Workspace content: company/prospect records, contact details, notes and knowledge you add to the Company Brain, and messages drafted or approved in the Service.
- Connected-account data: data you authorize us to read from services you connect (e.g. Slack, GitHub, Google, HubSpot, email/enrichment providers). OAuth tokens are stored encrypted.
- Usage & device data:log data, IP address, and product-analytics events (see “Cookies & analytics”).
2.How we use it
To provide, secure, and improve the Service: authenticating you, running the AI employees you configure, drafting and (only with your approval) sending outbound, generating reports, preventing abuse, and providing support. We do not sell personal data, and we do not use your workspace content to train our own or third-party AI models.
3.AI processing
To generate drafts and analysis, relevant inputs are sent to our AI model provider (Anthropic). We send only what is needed for the task. We rely on the provider’s enterprise terms, under which inputs and outputs are not used to train their models. AI output is generated for your review and is not a source of truth.
4.Subprocessors
We share data with vendors who process it on our behalf to run the Service, under contract:
- Anthropic — AI model inference.
- Supabase — database, authentication, storage.
- Vercel — application hosting.
- Email & enrichment providers (e.g. Resend/Smartlead, Hunter/Apollo) — only when you connect them and for the sends/lookups you initiate.
- Sentry — error monitoring; PostHog — product analytics.
A current subprocessor list is available on request; we give notice of material changes.
5.Security
Every tenant table enforces row-level security scoped to the workspace/agency, so one customer cannot read another’s data. Connector tokens are encrypted at rest. Access to production is restricted and audited. No system is perfectly secure, but we design for tenant isolation as a first-class property.
6.Retention
We retain account and workspace data while your account is active. After termination we make data available for export for a reasonable period and then delete or anonymize it, except where longer retention is required by law. You can delete most workspace content in-product at any time.
7.Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, or to object to certain processing. For account data, contact us below. For personal data held as workspace content, direct requests to the customer that controls that workspace; we assist our customers in responding.
8.Cookies & analytics
We use strictly-necessary cookies for authentication and, where enabled, PostHog for product analytics (autocaptured interactions and pageviews). Analytics is off unless configured, and person profiles are created only for signed-in users. [Cookie banner / consent to be finalized with counsel per region.]
9.International & changes
Data may be processed in the United States and other countries where our subprocessors operate, under appropriate safeguards. We may update this policy on notice; the “effective” date reflects the latest version. Questions or requests: bizprogo@gmail.com.