Privacy Policy
Theo Console, operated by Growth Collective (wearegrowth.co). Last updated: July 9, 2026.
Who we are
Theo Console is a business platform that lets marketing teams operate an AI assistant ("Theo") for advertising operations: drafting ad creative, validating campaigns, and reporting on performance across connected marketing platforms.
Information we collect
- Account information: your name, email address, and role, provided when your organization invites you.
- Connected platform data: when your organization connects an advertising account (for example a Meta ad account), we access campaign structures, ad creative, performance metrics, and account metadata that the platform's API provides under the permissions you grant.
- Content you create: ad drafts, creative assets you upload, and configuration you set.
- Usage records: actions taken in the product (by people and by the AI assistant) are recorded in an audit log for security and accountability.
How we use it
- To provide the product: create and manage ad drafts, validate and (on your explicit instruction) publish campaigns to connected platforms, and report on performance.
- To secure the product: authentication, authorization, audit trails, and abuse prevention.
- We do not sell personal data. We do not use your advertising data to train general-purpose AI models.
Storage and security
Data is stored with vetted cloud infrastructure providers (Supabase, Railway, Vercel). Platform access tokens are encrypted at rest with AES-256-GCM and are never exposed to browsers. Access is scoped per organization (tenant) and enforced at the database layer. Media files live in a private bucket accessible only through short-lived signed URLs.
Data retention and deletion
Your organization's administrators can revoke a connected platform at any time, which deletes its stored credentials immediately. You may request deletion of your data as described at our data deletion page. We honor platform requirements, including Meta's data deletion callback obligations.
Third-party platforms
When you connect a platform (Meta, Google, and others), your use of that platform remains governed by its own terms and privacy policy. We access only the permissions you explicitly grant during the OAuth flow, and you can revoke them at any time from the platform's security settings or from Theo Console.
Contact
Privacy questions: periel@wearegrowth.co