Legal
Privacy Policy
Effective date: May 29, 2026
1. Who we are
GrowBien LLC (“GrowBien,” “we,” “us”) operates growbien.com and the GrowBien platform — an AI-powered marketing system for physician-led wellness and aesthetics practices. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.
Questions? Email us at [email protected].
2. Information we collect
Information you provide directly
- Name, email address, and practice website submitted through our intake or booking forms
- Practice type, location, and contact details provided during onboarding
- Communications you send us via email or in-platform messaging
Information collected automatically
- Browser type, device type, IP address, and referring URL when you visit growbien.com
- Pages visited and actions taken on the GrowBien platform (via Google Analytics 4)
- Cookie identifiers used to maintain your session and measure site performance
Third-party data connected by clients
Clients who connect their Google Analytics, Google Search Console, Google Business Profile, or Google Ads accounts grant GrowBien read and limited write access to those services for the purpose of generating marketing content and reports. This data is used solely to deliver the services described in your subscription plan. See below for how we share and disclose this data and how we protect it.
How we share and disclose Google user data
When you connect a Google service (Google Business Profile or Google Ads), GrowBien accesses only the data covered by the specific permissions you grant, and uses it solely to deliver the features described in your subscription plan. We disclose this Google user data only as follows:
- Google. Data is retrieved from, and (for Google Business Profile review replies you approve) written back to, Google’s own APIs using the access you granted. Review replies are posted only to your own Google Business Profile.
- Google Cloud / Firebase. Your connected-account authorization tokens and the metrics we retrieve are stored on Google Cloud infrastructure (Firebase / Firestore), which hosts the GrowBien platform.
We do not sell Google user data, and we do not use it for advertising. We do not transfer your raw Google account data (such as your Google Ads campaign details or your authorization tokens) to our AI or automation subprocessors. Our content-generation services (Anthropic’s Claude API and n8n) receive only the content topics and briefs needed to produce marketing drafts; they are not given access to your connected Google accounts. Aggregate performance figures we derive from your data (for example, total ad spend and total conversions for a period) are used to generate your reports and recommendations within your own portal.
We may disclose data if required by law or to protect the security and integrity of our systems. GrowBien’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we protect your data
We apply the following safeguards to the data connected to your account, including Google user data:
- Encryption in transit. All data exchanged between your browser, GrowBien’s servers, and third-party APIs is encrypted using HTTPS/TLS.
- Encryption at rest for credentials. The authorization tokens that let GrowBien access your connected Google services are encrypted before storage using AES-256-GCM, with a unique initialization vector generated for each token and an authentication tag verified on every decryption. Tokens are never stored in plain text.
- Restricted access. Connected-account credentials are stored in a database collection that is accessible only to GrowBien’s server-side systems. Client-side and browser access to these records is denied by our database security rules; the credentials are never exposed to the browser.
- Revoking access. You can disconnect any Google service at any time from Settings → Integrations, which deletes GrowBien’s stored copy of your authorization token so GrowBien can no longer access that service. You may also revoke GrowBien’s access directly from your Google Account at https://myaccount.google.com/permissions.
3. How we use your information
- To operate and deliver the GrowBien platform and services you subscribe to
- To generate marketing content, reports, and recommendations for your practice
- To communicate with you about your account, service updates, and support requests
- To send the GrowBien Brief newsletter (only with your consent; unsubscribe anytime)
- To analyze aggregate usage patterns and improve the platform
- To comply with applicable law and protect the security of our systems
We do not sell your personal information to third parties. We do not use your data for advertising on behalf of other businesses.
4. Third-party services
GrowBien uses the following third-party services to operate the platform. Each is governed by its own privacy policy.
| Service | Purpose |
|---|---|
| Google Analytics 4 | Website and platform usage analytics |
| Google Ads / Search Console / GBP | Client marketing channel management (client-connected) |
| Anthropic Claude API | AI-generated content drafts and marketing recommendations |
| n8n | Automated AI agent workflows that generate content on your behalf |
| Firebase / Google Cloud | Platform hosting, database, and authentication |
| Amazon S3 | Storage for AI-generated images (blog hero images) |
| Webflow | Blog publishing destination for approved content |
| Airtable | Internal client operations and content calendar management |
| Tally.so | Lead capture and booking forms on growbien.com |
| Brevo (formerly Sendinblue) | Transactional email and lead nurture sequences |
| Calendly | Discovery call scheduling |
5. HIPAA awareness
GrowBien is a marketing platform, not a healthcare provider or covered entity under HIPAA. We are designed to be HIPAA-aware in the following ways:
- We do not collect, store, or process Protected Health Information (PHI) — patient names, diagnoses, treatment records, or insurance information
- Our AI content generation workflows are designed to operate without patient-identifiable data
- Clients are responsible for ensuring their own HIPAA compliance and should not share PHI with GrowBien systems or personnel
For more on how we handle data ownership, see our article Who really owns your marketing accounts.
6. Data retention
We retain your account information for as long as your subscription is active and for up to 12 months afterward for billing and compliance purposes. Marketing content, analytics snapshots, and reports generated for your practice are retained in your client portal during your subscription and remain accessible for 90 days after cancellation, after which they may be deleted.
You may request deletion of your data at any time by emailing [email protected].
7. Cookies
growbien.com uses cookies for session management, analytics (Google Analytics 4), and form functionality (Tally). You may disable cookies in your browser settings, though some platform features may not function correctly without them.
8. Your rights
Depending on where you are located, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Request deletion of your data
- Opt out of marketing communications at any time
- Withdraw consent for data processing where consent is the legal basis
To exercise any of these rights, contact us at [email protected].
9. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. Material changes will be communicated to active subscribers via email.
Questions? [email protected]
View Terms of Service →