How we protect your data

GrowthHasten reads your website and, if you connect them, your Search Console and Analytics. This page sets out exactly how that access is limited and how the data is kept.

Last updated 9 October 2026

Google access is read-only

  • GrowthHasten asks Google for two data scopes only: webmasters.readonly (Search Console) and analytics.readonly (Google Analytics 4). Neither can change a property, a setting or any data.
  • Signing in with Google requests your name and email only, with no offline access, so no long-lived Google token is kept for sign-in.
  • Every Google connection uses OAuth with PKCE.
  • Access tokens are never stored. They are minted in memory for each sync and discarded.
  • Refresh tokens are encrypted at rest with AES-256-GCM, with a random IV for every value and the authentication tag checked on every read. The key is held outside the database and differs per Google product. If the key is unavailable, the connection is refused rather than stored unencrypted.
  • Disconnecting Search Console or Analytics in Settings deletes the stored token and all data read from that source, in one transaction. You can also remove GrowthHasten's access from your Google Account's third-party connections page at any time.

Accounts and sessions

  • Session tokens are 32 random bytes. The database stores only a SHA-256 hash of each one, so a copy of the database cannot be used to sign in.
  • The session cookie is HTTP-only, sent over HTTPS only, SameSite=Lax, and signed. Sessions expire after 30 days, enforced on the server.
  • Changing your password signs out every other session.
  • Passwords are hashed with scrypt.
  • Sign-in and sign-up are rate-limited per email address and per IP address.

AI assistant (MCP) tokens

  • Assistant tokens are created in the product and stored only as a SHA-256 hash. The full token is shown once.
  • Every assistant tool is read-only and scoped to your own account. Other accounts' websites are invisible to it.
  • You can revoke a token at any time, and it stops working immediately. Calls are rate-limited per token.

Where your data lives

  • The application runs on Vercel, pinned to the Seoul region (icn1).
  • The database is Supabase Postgres in Seoul (ap-northeast-2). Database access from the public API is revoked; the application reaches it from the server only.
  • Website crawling and page rendering run on our own crawler service.
  • All traffic to growthhasten.com and app.growthhasten.com is served over HTTPS.

AI processing

  • Explanations and drafts are written by Google Gemini through its API. It receives the findings and page content needed for the request, and, for some features, figures from your connected Google data.
  • Everything AI writes is labeled as AI-written in the product, and any AI sentence that contains a figure not present in your data is discarded.

Deletion

  • You can delete a website, or your whole account, from Settings. Deleting the account cancels running analyses and removes every website, analysis, connection and token under it.
  • On the Free plan the product keeps your current analysis and the one before it, and prunes older ones automatically. Growth and Scale keep the full history.

Payments

  • Payments are processed by Stripe. Card details are entered on Stripe's own forms and never touch our servers.

Report a vulnerability

If you believe you have found a security problem in growthhasten.com, app.growthhasten.com or the Hasten LinkLens extension, email support@growthhasten.com with “Security report” in the subject. Include the steps to reproduce it. We reply within 1 business day, keep you informed while we fix it, and credit you if you would like.

Please test only against your own account, do not access or change other people's data, avoid anything that degrades the service for others, and give us reasonable time to fix the problem before you disclose it publicly.

How we collect and use personal data is in the privacy policy.