Privacy Policy
This policy explains what information GroGoliath collects, how we use and share it, and the choices and rights you have. We keep it plain-spoken on purpose - being honest by default is one of our principles.
GroGoliath, Inc. ("GroGoliath," "we," "us," or "our") makes programmatic SEO software that generates and publishes pages to the websites our customers connect. This Privacy Policy describes how we handle personal information across our website, web application, and related services (together, the "Services").
It applies to visitors of grogoliath.com, people who sign up for and use the app, and those who contact us. It does not cover the third-party platforms you choose to connect - such as your CMS, hosting, or analytics tools - which are governed by their own privacy policies.
Where GroGoliath decides how and why personal data is processed, we act as a data controller. When we generate and publish pages using the content and instructions you provide, we act as a data processor on your behalf, under our customer agreement.
We collect information in three ways: what you give us, what comes from the services you connect, and what we gather automatically as you use the Services.
Information you provide
Account details — your name, work email, password, and company name when you register.
Billing information — plan, billing address, and transaction records. Card details are processed directly by our payment provider; we don't store full card numbers.
Content & instructions — the prompts, keywords, locations, brand settings, and other inputs you use to generate pages.
Communications — messages, form submissions, and support requests you send us.
Information from services you connect
To publish pages for you, you authorize GroGoliath to connect to your CMS, hosting, or analytics accounts. When you do, we receive and store access tokens and the site data needed to create and publish pages - such as existing page structure, templates, and metadata. We use these only to deliver the Services you've requested.
Information collected automatically
Usage data — pages generated, features used, and actions taken in the app.
Device & log data — IP address, browser and device type, operating system, and timestamps.
Cookies & similar technologies — identifiers used to keep you signed in and to understand how the Services are used (see Cookies & tracking).
We use the information described above to:
Provide, operate, and maintain the Services — including generating and publishing pages to your connected sites.
Create and secure your account, authenticate you, and prevent fraud or abuse.
Process payments and manage your subscription.
Screen generated pages against quality and policy checks before they publish.
Respond to your requests and provide customer support.
Understand usage and improve the performance, reliability, and features of the Services.
Send service and transactional messages, and — with your consent where required — product updates and insights.
Comply with legal obligations and enforce our terms.
We do not use your private content to train shared or third-party AI models.
If you are in the European Economic Area or the United Kingdom, we process personal data under one or more of these legal bases:
Contract — to provide the Services you've signed up for.
Legitimate interests — to secure, maintain, and improve the Services, provided your rights don't override those interests.
Consent — for non-essential cookies and optional marketing messages; you can withdraw it at any time.
Legal obligation — where we're required to process data to comply with the law.
We do not sell your personal information. We share it only in these limited situations:
Service providers (subprocessors) — trusted vendors who help us run the Services, such as cloud hosting, AI model providers, analytics, payment processing, and email delivery. They may process data only on our instructions.
At your direction — with the platforms you connect, in order to publish the pages you create.
Legal reasons — when required to comply with the law, respond to lawful requests, or protect the rights, safety, and security of GroGoliath, our users, or the public.
Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy.
We keep personal information for as long as your account is active or as needed to provide the Services. After that, we retain and use it only as necessary to comply with legal obligations, resolve disputes, and enforce our agreements. When data is no longer needed, we delete or anonymize it.
We protect your information with technical and organizational safeguards, including encryption in transit and at rest, access controls, and regular security reviews. Access tokens for your connected sites are encrypted and used only to publish on your behalf.
No method of transmission or storage is completely secure, so we can't guarantee absolute security. If we become aware of a breach affecting your personal data, we'll notify you and the relevant authorities as required by law.
We operate globally, so your information may be processed in countries other than your own, including the United States. When we transfer personal data across borders, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses — to protect it in line with applicable law.
Depending on where you live, you may have the right to:
Access a copy of the personal data we hold about you.
Correct information that is inaccurate or incomplete.
Delete your personal data, subject to legal exceptions.
Port your data to another service in a portable format.
Object to or restrict certain processing, and withdraw consent where processing is based on it.
If you're a California resident, you have similar rights under the CCPA/CPRA, including the right to know, delete, and opt out of the "sale" or "sharing" of personal information. We do not sell personal information, and we won't discriminate against you for exercising your rights.
To make a request, email support@grogoliath.com. We'll verify your request and respond within the timeframe required by law.
The Services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we'll delete it.
The Services integrate with third-party platforms you choose to connect and may link to external sites. We don't control those services, and their handling of your information is governed by their own privacy policies. We encourage you to review them.
We may update this Privacy Policy from time to time. When we do, we'll revise the "Last updated" date above and, for material changes, provide additional notice such as an email or an in-app message. Your continued use of the Services after an update means you accept the revised policy.
