Last updated: July 2026
AutoData is operated by GrowSight. If you're in the EU, we act as a data processor for the invoices/documents you upload — you (the customer) are the data controller.
| Category | Purpose |
|---|---|
| Account (email, name, password hash) | Authentication and support |
| Documents you upload (PDFs, photos) | To extract structured data for you |
| Extracted data (vendor, date, amount, etc.) | Delivered to you in Excel, Sheets or API |
| Usage logs (login times, API calls) | Security, debugging, billing |
| Payment info | Handled by AppSumo/Stripe — we don't store card numbers |
| Service | Purpose | Data |
|---|---|---|
| Anthropic (Claude API) | AI document extraction | Document content (zero retention) |
| Vercel | Hosting | All app data (SOC 2 Type II) |
| Neon | Database (Postgres) | Account & extracted data (encrypted at rest) |
| Stripe / AppSumo | Payments | Payment info only, not documents |
| Resend / SendGrid | Email delivery | Email address, transactional messages |
Data is stored in AWS US East region (via Vercel and Neon). For customers who need data residency in EU or elsewhere, our on-premise agent lets you keep all documents inside your own network — nothing ever reaches our cloud.
You have the right to:
To exercise any right, email support@growsight.online. We reply within 30 days.
We use only essential cookies (session token, CSRF protection). No advertising or tracking cookies. Analytics is done in aggregate and cannot be used to identify you.
If a data breach affects your account, we'll notify you within 72 hours of discovery, per GDPR requirements.
AutoData is not directed at children under 16. We don't knowingly collect data from anyone under 16.
Material changes will be notified by email at least 30 days before taking effect. The current version is always at this URL.
For any privacy question: support@growsight.online.
AutoData · A GrowSight product · Back to home