Privacy Policy
Last updated: 2026-05-31
Who we are
GrowOrPay is a personal-commitment app: you set a daily deadline, and if you miss it you pay yourself a small penalty. The service is operated by GrowOrPay (operated by Antonio Ridiche, Bucharest, Romania; contact: support@groworpay.com).
For privacy questions, write to support@groworpay.com. We read every email.
What data we collect
Account data: your email address and a Firebase user ID (UID). That's the minimum needed to sign you in and keep your settings tied to you.
Commitment data: your daily deadline time, your timezone, your chosen currency, and the fee amount you committed. We need these to run the deadline check and to charge you the right amount in the right currency.
Financial data: a Stripe customer ID and a record of charges made (date, amount, success/failure). We do not store card numbers or CVCs — Stripe holds those on their infrastructure and we only see a token.
Usage data: device push tokens (so reminders can reach you when the app is closed), and your IP address at sign-in for one-off geolocation-based currency detection. We don't keep a long IP history.
Why we collect it
To operate the service. Concretely: to charge you when you miss a deadline, to send the reminder and confirmation notifications you signed up for, and to detect and prevent abuse (duplicate accounts, payment-method fraud).
We do not sell your data, and we do not use it for advertising or profiling. There is no behavioural ad layer on this site or in the app.
Who we share data with
We use a small set of named processors, and only the data each one needs:
Stripe (US, with EU Standard Contractual Clauses) — payments. They see your name, email, card details, and charge history.
Firebase / Google Cloud (US, with EU Standard Contractual Clauses) — hosting, authentication, and the database. They see your account data and commitment records.
Resend (US, with EU Standard Contractual Clauses) — transactional email (magic-link sign-in, charge confirmations, refund notices). They see your email address and the message body. Brevo (EU) is retained as a fallback provider that we can switch back to without redeploying.
Sentry (US, with EU Standard Contractual Clauses / Data Processing Agreement) — crash and error reporting from the app and server. They see error messages, stack traces, your Firebase user ID (or a hash of it), and request metadata; we strip emails and card data before sending.
ipapi.co — geolocation for first-run currency detection. They see your IP address at the moment of sign-in and return a country code.
We do not share data with anyone else. We do not have analytics, ad, or tracking SDKs.
Your rights
If you are in the EU, UK, or California, you have the right to access, correct, delete, and export your data. We extend these rights to everyone regardless of where you live.
You can delete your account from Settings → Delete account in the app. Your profile, settings, behavioural data, and support history are erased immediately and irreversibly. Past charge and tip records are kept for the 7-year legal retention period described below, but with your personal identifiers stripped (see "Data retention"). You can also download a JSON export of everything we hold on you from the same screen via the "Download My Data" button.
For anything you can't do in-app — for example a correction request — email support@groworpay.com and we'll handle it within 30 days.
Cookies
The web app uses a Firebase Auth session cookie to keep you signed in. That's it. No marketing cookies, no analytics cookies, no third-party trackers on this site or in the app.
The marketing site (groworpay.com) sets no cookies at all.
Data retention
Account and commitment data (profile, settings, daily check-ins, contests, support tickets): kept until you delete your account, then erased immediately.
Charge and tip records: kept for 7 years after the transaction date to comply with tax and accounting law (EU VAT, Romanian Fiscal Code, equivalent regimes). We can't shorten this even on request — it's a legal obligation under Art. 6(1)(c) GDPR. When you delete your account, these financial records are moved to a separate archive with your personal identifiers stripped out: your email and display name are removed, and your Firebase user ID is replaced with a one-way pseudonymous hash so the records remain auditable for tax authorities but are no longer linkable back to you. Card details themselves live with Stripe and are erased there per the deletion of your Stripe customer.
Children
GrowOrPay is for adults only. You must be 18 or older to use the service. We do not knowingly collect data from anyone under 18, in line with COPPA and equivalent regulations. If you believe a child has signed up, email support@groworpay.com and we'll delete the account.
Changes to this policy
If we make a material change to how we handle your data, we'll email every active user before the change takes effect. Cosmetic edits (typos, clearer wording) won't trigger an email but the "Last updated" date at the top of this page will always reflect the latest revision.
Contact
Privacy questions, data requests, or anything that doesn't fit a form: support@groworpay.com. A real person reads the inbox.