What we process, and what we never do with it
Written to be read. If anything here is unclear or looks wrong, write to privacy@growthclan.com and we will fix the wording or the behaviour.
Last updated: 5 August 2026
In short
- We process what you give us and what you connect, to produce your go-to-market work and to measure whether it worked.
- We do not sell your data, we do not use it for advertising, and we do not train models on your content.
- Provider keys are encrypted before they reach the database; only ciphertext is stored.
- Deleting a project deletes its data. Disconnecting an integration deletes its stored credential.
- The cross-project learning layer sees the shape of results, behind anonymisation thresholds — not your code, your customers or your copy.
Who we are
Bladesmith AI is a product of Growthclan Inc., which is the controller for the data described here.
Growthclan Inc.2261 Market Street, San Francisco, CA 94114, United StatesEIN 37-2173633Privacy and data requests: privacy@growthclan.comEverything else: info@growthclan.comFor questions about the product rather than your data, the fastest route is hello@bladesmith.io.
What we process
Your account. Email address and the authentication records that keep you signed in; your plan and, if you pay, the billing records Stripe returns to us. We never see your card number.
Your project. The product URL you paste, what we read from your public site, the answers you give about your positioning and audience, and — if you connect a repository — the contents we read to understand the product and to write changes.
What you connect. Only what the capability needs: funnel and traffic metrics from your analytics, query performance from Search Console, revenue outcomes from Stripe. The full list of what each connection can do, generated from the registry the product itself uses, is on the security page.
What the system produces. Plans, drafts, proposals, approvals, executed actions and the outcomes measured afterwards — plus an append-only record of what ran, when, and on whose approval.
This website. Aggregate page analytics through Vercel, which runs without cookies, used to see which pages are read. We do not run advertising trackers here. The complete cookie list — there are two, both strictly necessary — is in the cookie policy.
Why we process it
To provide the product you asked for: reading your product, producing the plan and the work, executing what you approve, and measuring the result. To keep the service running, secure and billed correctly. And to improve what we recommend — which is the one purpose worth describing precisely, below.
Cross-project learning
Bladesmith gets better by learning which kinds of action move which metrics for which kinds of product. What crosses the boundary between projects is the shape of a result — an action type, a metric, a movement, a coarse description of the kind of product — behind anonymisation thresholds. Your code, your customer data and your copy are not what travels, and nothing that identifies you or your customers is published to another project.
Sub-processors
These services process data on our behalf. The first group is always in the path because the product runs on it; the second only ever sees anything if you connect it.
| Service | What for |
|---|---|
| Supabase | Database, authentication and file storage |
| Vercel | Hosting, plus page analytics for this website |
| Anthropic | The model that drafts and diagnoses. Your content is processed to produce your output |
| Trigger.dev | Running long jobs durably |
| Stripe | Payments, if you are on a paid plan |
Only if you connect it:
- Attio
- Linear
- DataForSEO
- Google Search Console
- Resend
- Instantly
- PostHog
- Google Analytics
- Stripe
- Statsig
- GrowthBook
- fal.ai
- Bannerbear
- Vercel Flags
- Vercel
- App Store Connect
- Google Play
- AppTweak
- iTunes Search
Keeping and deleting
Project data lives as long as the project does. Deleting a project deletes it — the plan, the drafts, the measurements and the stored credentials — rather than archiving or flagging it. Disconnecting an integration deletes the credential we hold for it. Work already merged into your repository or sent from your own provider stays where it is, because it was always yours. Billing records are kept as long as tax and accounting rules require.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, object to a particular use, or ask us to stop entirely. Write to privacy@growthclan.com and we will respond. If you are in the EU or the UK you also have the right to complain to your data protection authority.
Legal basis (GDPR)
If you are in the EU or the UK, we rely on:
- Performance of a contract — providing the product you signed up for — the plan, the execution, the measurement.
- Legitimate interests — keeping the service secure, preventing abuse, and improving what we recommend.
- Consent — where we ask for it specifically, such as connecting a third-party account.
- Legal obligation — tax, accounting and record-keeping.
California rights (CCPA/CPRA)
California residents can ask what personal information we collect, ask us to delete it, and are entitled to non-discrimination for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising. Use the same address as above.
Where the data is
Growthclan Inc. is a company in the United States, and the services listed above process data in the United States and the European Union. Where a transfer out of the EEA or the UK is involved, it is covered by the standard contractual clauses in our agreements with those providers.
Children
The product is for people running a business and is not directed at children. We do not knowingly collect data from anyone under 16; if we learn that we have, we delete it.
How it is protected
Provider keys are encrypted with AES-256-GCM before they reach the database and only ciphertext is stored. Every user-owned table is isolated at the database level by row-level security. Every action that writes to the outside world waits for your approval. The full model, including what we have not done yet, is on the security page.
Changes and governing law
When this notice changes materially we will update the date at the top and, for changes that affect what we do with your data, tell you in the product before they take effect.
This notice is governed by the laws of California, without prejudice to the rights the law of your own country gives you.