Privacy Policy
Effective date: August 5, 2026
Last updated: August 5, 2026
Version 1.0 — August 2026
This Privacy Policy explains how Kommireddy Hemanth Kumar, a sole proprietorship (not a separately registered company) operating under the brand name “Groager” (“Groager”, “we”, “us”), registered at 1-1, Andallamma Thota, Komadavolu Road, Near Arepalli Complex, Eluru, Andhra Pradesh, 534001, India, collects, uses, and protects information in connection with the Groager platform. It applies both to (a) you, if you hold a Groager account, and (b) visitors to websites that use Groager's tracking snippet, where we act as a data processor on behalf of our customer (the website owner). This policy describes what our systems actually collect today, not a generic template — see the sections below for specifics.
1. Information We Collect About You (Account Holders)
1.1 Account & profile data
- Full name and email address, provided at signup;
- Password (stored as a salted hash — we never store or can view your plaintext password), or, if you sign up with Google, your Google account's email/profile info via OAuth (no password stored);
- Organization/workspace name, and your role within it (owner, admin, member, or viewer);
- Content you create in the product: chat conversations with the AI assistant, business goals you define, alert configurations, API keys and webhook endpoints you create, and similar account configuration.
1.2 Billing data
Subscription payments are handled entirely by Paddle.com Market Limited as our payment processor and Merchant of Record. We do not receive or store your full card number or other sensitive payment details — Paddle collects and processes that directly. We receive from Paddle only what is necessary to manage your subscription (e.g. plan, status, and billing email).
1.3 Technical & usage data
When you use the Groager dashboard itself, our servers log standard request metadata (IP address, timestamp, endpoint accessed, response time) for security, rate-limiting, and debugging. If an unhandled error occurs, we log the error type, message, the page/endpoint involved, and — if you were logged in — your user and organization ID, to help us fix bugs. The Groager dashboard itself does not use cookies for authentication; your session is kept in your browser's local storage.
2. Information Collected From Your Website Visitors (If You Use the Tracking Snippet)
If you embed Groager's tracking snippet on your own website, it collects the following about your website's visitors, on your behalf, so we can generate your analytics dashboard:
2.1 Sessions
- A visitor identifier stored in a first-party browser cookie (
niq_vid) on your website's own domain, valid for 365 days, used to recognize returning visitors across sessions; - IP address (used transiently for approximate geolocation — see 2.3 — and abuse/bot filtering);
- Browser user agent, parsed into device type, browser, and operating system;
- Referring URL, and any UTM campaign parameters present in the landing URL;
- Landing page, exit page, session duration, and number of pages viewed;
- Whether the session is flagged as a bounce, a conversion, likely bot traffic, or internal traffic (e.g. from an IP you've allow-listed as your own office/team).
2.2 Events
The snippet can record individual visitor interactions, depending on what your site triggers:
- Page views, scroll depth, and outbound link clicks;
- Clicks on designated call-to-action elements, file downloads, and clicks on
tel:,mailto:, and WhatsApp links; - Form-related events;
- Custom events you define, which may include arbitrary properties you choose to send;
- Screen/viewport dimensions and page responsiveness (Core Web Vitals-style) metrics;
- The visitor's IP address and user agent (same as above), attached to each event for attribution.
2.3 IP-based geolocation
To show country/city/region-level location in your analytics, we send the visitor's IP address to a third-party geolocation lookup service, ip-api.com, which returns an approximate country, city, and region. Results are cached for 24 hours per IP to limit how often this lookup happens. We do not use this for precise (e.g. GPS-level) location.
2.4 Respecting Do Not Track / opt-out
The tracking snippet checks the visitor's browser navigator.doNotTrack signal (and equivalent vendor-prefixed signals) and does not collect data if it is enabled, unless the site owner has explicitly configured the snippet to require separate consent. Bot and known-internal traffic is flagged but is still recorded (marked as such) rather than silently dropped, so it can be excluded from your reports without losing the underlying record.
If you are a visitor to a website that uses Groager's tracking snippet and have questions about that site's data practices, please contact that website directly — they, not Groager, are the data controller for their own visitors and determine how their site uses this data (e.g. what consent notices they show). Groager processes this data as instructed by our customer.
If you are a Groager customer embedding the tracking snippet on your own website, you — not Groager — are solely responsible for obtaining any cookie or tracking consent required from your own visitors under the law that applies to them (for example, ePrivacy/GDPR-influenced consent requirements in the EU/UK, or similar rules elsewhere), for showing any required consent banner, and for your own site's privacy policy disclosing this tracking to your visitors. Groager provides technical support for this (the snippet's data-consent-required flag and consent() API, and respecting Do Not Track by default — see 2.4), but does not, and cannot, assess what consent your specific site and audience legally require — that determination, and the resulting liability if it is wrong, is yours as the site operator. See also our Terms of Service, Section 4, and our Cookie Policy, Section 2.4.
3. Optional Third-Party Integrations You Connect
3.1 Google Search Console
If you choose to connect a website to Google Search Console, we request read-only access via Google OAuth and store your connection's access/refresh tokens (encrypted at rest) plus the Search Console performance data you've authorized us to read (queries, clicks, impressions, click-through rate, and average position for your site). You can disconnect this at any time from your dashboard, which revokes our access.
3.2 “Sign in with Google”
If you sign in using Google, we receive your name, email address, and Google account ID via standard OpenID Connect scopes (openid, email, profile) — we do not request access to your Gmail, Drive, or other Google data through this login flow.
3.3 Other integrations
Additional optional integrations may be added to the platform over time; each will only access the specific data needed for that integration, and will be described here and/or at the point you connect it.
4. How We Use Information
- To provide, operate, and maintain the Service (e.g. generating your analytics dashboard, running SEO audits, powering the AI assistant);
- To send transactional emails: account verification, password reset, team invitations, and alerts you've configured (e.g. a website's Core Web Vitals crossing a threshold);
- To detect, investigate, and prevent fraud, abuse, and security incidents;
- To provide customer support and respond to your requests;
- To improve the Service, including debugging errors (see 1.3);
- To comply with legal obligations.
We do not sell your personal data, or your website visitors' data, to third parties.
5. Data Controller vs. Data Processor
- For your account data (Section 1) — Groager is the data controller: we determine why and how that data is processed (running your account, billing, support, product improvement).
- For your website visitors' data collected via the tracking snippet (Section 2) — Groager is the data processor, and you (our customer, the website owner) are the data controller. We process that data only as needed to provide your analytics dashboard, per your instructions (embedding the snippet, configuring what it tracks) — we do not decide independently what to do with your visitors' data beyond that.
6. GDPR Legal Basis for Processing
Where the EU/UK GDPR applies, here is the legal basis we rely on for each real category of data described above:
| Data category | Legal basis | Why |
|---|---|---|
| Account & profile data (1.1) | Contract | Necessary to create and operate your account and provide the Service you signed up for. |
| Billing data (1.2) | Contract / Legal obligation | Necessary to process your subscription payment and to meet tax/accounting record-keeping requirements. |
| Dashboard technical & error logs (1.3) | Legitimate interest | Necessary to keep the Service secure, debug errors, and prevent abuse — a proportionate interest balanced against minimal impact on you. |
| Website visitor analytics — sessions/events (2.1–2.2) | Legitimate interest of our customer (you), or Consent where you configure the snippet to require it | You, as data controller for your own visitors, determine and are responsible for the correct basis for your site and audience — see Section 2 and our Cookie Policy. |
| IP-based geolocation (2.3) | Same basis as sessions/events above | Part of the same analytics processing, on your instructions as controller. |
| Google Search Console / Google Sign-In data (3.1–3.2) | Consent | You explicitly connect these integrations via OAuth; the connection is opt-in and revocable at any time. |
| AI assistant chat content (Section 7) | Contract | Processing your prompt/data to generate the AI response is necessary to provide the feature you invoked. |
Where you (or your visitors) have a choice, you may withdraw consent at any time — see Section 12 (Your Rights) below.
7. AI Processing
The AI assistant and AI-generated explanations are powered by Anthropic's Claude API — the commercial API product, not the consumer Claude.ai chat product. When you use these features, relevant structured data already in your dashboard (e.g. your analytics figures, audit findings, or the text of your question) is sent to Anthropic to generate a response. Per our product design, the AI is used only to explain and summarize evidence already computed by our backend — it is not given blanket access to your full account.
On AI training: by default, Anthropic does not use data submitted through its commercial API (which is what Groager uses) to train its models. We have not enabled, and our codebase contains no configuration for, any Anthropic feedback, telemetry-sharing, or model-improvement opt-in program that would change this — Groager sends requests to the standard Claude API and nothing more. See Anthropic's Privacy Policy and commercial API terms for Anthropic's own, authoritative statement of this policy, which governs their handling of API data independent of anything stated here.
9. Third-Party Sub-Processors
We share data with the following categories of third-party service providers, only as needed to run the Service:
- Paddle.com Market Limited — payment processing, billing, tax compliance (Merchant of Record for subscriptions);
- Google LLC — OAuth sign-in and, if you connect it, Search Console API access;
- Anthropic PBC — AI processing for the AI assistant and AI-generated explanations (see Section 7);
- ip-api.com — IP-to-location lookups for visitor geolocation in analytics (see 2.3);
- Our email delivery provider (currently Google/Gmail SMTP) — for sending transactional emails;
- Our cloud infrastructure and database backup storage providers, currently including Backblaze B2 for encrypted off-site database backups, and our virtual private server hosting provider for the servers the Service runs on.
We do not have a Content Delivery Network (CDN) in front of the Service at this time; requests are served directly from our servers.
10. Data Retention
- Account data is retained for as long as your account is active, and for a limited period afterward to allow for reactivation or legally required record-keeping, after which it is deleted or anonymized upon request.
- Analytics data (sessions/events collected via the tracking snippet) is retained indefinitely by default — stated plainly rather than as “a limited period”: there is currently no automated purge or time-based deletion job for this data. It remains available for as long as the associated website stays connected to an account, so historical reporting works, and is deleted only when you request it (see Section 12) or when your account itself is deleted. If you need bounded retention (e.g. to auto-delete analytics data older than N months), that is not yet a feature of the product — contact us to discuss it.
- Database backups are retained for 30 days on our servers and up to 90 days in off-site backup storage, after which they are permanently deleted, independent of when the underlying live data was deleted.
- Error logs are retained as needed for debugging and are not kept indefinitely.
See also our Terms of Service, Section 16.1, for how this applies specifically after account termination or downgrade.
11. Security
We use the following real, currently-implemented measures to protect data — we describe only what is actually in place, not aspirational security posture:
- Encryption in transit: all traffic to and from the Service is served over TLS/HTTPS.
- Password hashing: account passwords are stored as salted bcrypt hashes — we never store or can view your plaintext password.
- Role-based access control: access within a workspace is governed by real role checks (owner/admin/member/viewer) enforced on the backend, not just hidden in the UI.
- Plan-based access control: access to paid features is enforced server-side based on your subscription plan, not just hidden in the UI.
- Rate limiting: sensitive endpoints (login, signup, password reset, and the public tracking endpoints) are rate-limited to reduce abuse.
- Automated backups: daily encrypted database backups, retained per Section 10 above, with off-site replication to Backblaze B2.
- Audit logging: security-relevant account and billing actions are recorded in an internal audit log.
We do not currently hold SOC 2, ISO 27001, or similar third-party security certifications — we are a small operation and have not pursued formal certification. If a certification becomes a real requirement for our customers, we will evaluate it at that time rather than claim one we don't have. No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal data, we will notify you as required by applicable law.
12. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, or to object to or restrict certain processing. To exercise any of these rights — for your account data, or on behalf of your website if you're requesting deletion of visitor analytics data you collected — contact us at groagerai@gmail.com. We currently process deletion and access requests manually (there is no self-service “delete my data” button yet); we aim to respond within a reasonable time and in any event within the timeframe required by applicable law.
Data portability: on request, we will provide your account and analytics data in a structured, commonly-used, machine-readable format (e.g. CSV/JSON export of your analytics and audit data) so you can transfer it elsewhere.
Data Processing Agreement (DPA): if your organization requires a signed DPA to use Groager (for example, to satisfy your own GDPR compliance obligations as a controller), one is available on request — email groagerai@gmail.com. We do not yet have a standing, pre-drafted DPA published on this site; this is a known gap we intend to close as enterprise demand for it grows, not a promise that a document already exists today.
If you are located in the European Economic Area, United Kingdom, or a jurisdiction with a similar data protection authority, you also have the right to lodge a complaint with your local supervisory authority.
13. No Automated Decision-Making With Legal Effect
We do not use your personal data for fully automated decision-making that produces legal effects concerning you or similarly significantly affects you (e.g. automated decisions about eligibility, pricing, or access to the Service made without human involvement). AI-generated explanations and scores in the product (Section 7) are informational — they summarize evidence for you to review and act on; they do not automatically grant, deny, or change your access to anything. Where a plan/entitlement decision does gate your access to a feature, it is a deterministic rule (your subscription plan) applied by our backend, not an AI or profiling-based decision.
14. Cookies Summary
- The Groager dashboard itself (app.groager.com) does not set authentication cookies — your session token is kept in your browser's local storage, not a cookie.
- The tracking snippet, when embedded on a customer's website, sets first-party cookies (
niq_vid,niq_sid,niq_sst, andniq_optoutif you opt out) on that website's own domain, described in Section 2.1. - For the full real cookie inventory (names, durations, flags actually set), see our Cookie Policy.
15. International Data Transfers
We are based in India; some of our sub-processors (Section 9) are based outside India, meaning your data may be transferred to and processed in other countries. Where required by applicable law, we rely on appropriate safeguards (such as those sub-processors' own standard contractual clauses or equivalent mechanisms) for such transfers.
16. Business Transfers
If Groager is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or substantially all of its assets, your data may be transferred as part of that transaction. If this happens, we will require the receiving party to honor the commitments made in this Privacy Policy, and will notify you (e.g. via email or an in-app notice) of any such change in ownership or in how your data is handled.
17. Government & Legal Disclosure
We may disclose your information if required to do so by law, regulation, legal process (e.g. a court order or subpoena), or a valid governmental request, or where we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to an emergency. Where legally permitted, we will make reasonable efforts to notify you before disclosing your data in response to such a request.
18. Children's Privacy
The Service is not directed to individuals under 18, and we do not knowingly collect account data from them. If you believe a child has provided us with personal data, contact us at groagerai@gmail.com and we will take appropriate action.
19. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notice before they take effect.
20. Contact
Questions about this Privacy Policy, or requests relating to your data, can be sent to groagerai@gmail.com. We currently use this single address for all inquiries; a dedicated privacy@groager.com address is a planned future improvement once we have email hosting set up for our own domain, not yet in place today.
Related Policies
This document should be read together with our other policies:
