
Privacy policy
Last updated 28 August 2026
The short version. To use GROW Moment you give us an email address and a payment method. There is no face scan and no camera. After that, the data is what you write: a level and a note each day, and the body figures your protocol is computed from. Your notes and your body data are private by default. Your level and your index are visible to other members by default, and you can turn that off. We do not sell anything to anybody.
The rest of this page is the detail behind that, including the parts that are less comfortable — health data, third-party processors, and where the servers are. If you joined while signup still ran a face check, §2 says what is left of it and how to have it erased.
1Who is responsible for your data
The controller of the personal data described here is Kasparas Maniušis, at Vytauto Žalakevičiaus g. 13-13, LT-10109 Vilnius, Lithuania, operating growmoment.app.
For anything to do with your data, or anything else, write to info@growmoment.app or call +370 628 16971. Data protection contact: info@growmoment.app.
GROW Moment is for adults. You must be 18 or over to hold a membership, and we do not knowingly process the data of anyone younger.
2Your face: we no longer ask for it
There is no face scan. Signing up does not use your camera, and we do not collect, derive or store any biometric data about you. If you are joining now, this clause does not describe anything that will happen to you.
What this used to be
Earlier versions of the service ran a one-time liveness check at signup using Amazon Rekognition Face Liveness, and derived a face template from it so that one person could not hold several memberships. That step has been removed. Nothing in the product performs it any more, and the code that did has been deleted.
What we still hold, and for how long
Members who joined while that step existed have an enrolment record from it. Each one carries a deletion deadline stored on the record itself, and the images are deleted when it passes. We do not create new records, and nothing reads the existing ones to make decisions about you.
Having it removed now
If you were enrolled and want the remaining record erased before its deadline, write to info@growmoment.app and we will remove it. Because nothing depends on it any more, there is no consequence to your membership for asking.
3What else we hold
Your account
- Email address and, if you sign in with a password, a password held in hashed form by Firebase Authentication. We never see the password itself.
- Member number, allocated once and never reused.
- Nickname and avatar. Both are generated for you: the nickname and its meaning, and the avatar image, are produced by a model from a prompt and a style you choose. Your stated gender is used to pick an avatar style and for nothing else.
- “About me”, if you write one. It appears on your public profile and is given to Aris as standing context.
- Your timezone, captured from your browser. It exists so the daily reminder lands at 22:00 where you are rather than at a random hour.
What you log
- Check-ins. One per local day: a level from 0 to 5 and, optionally, a note. The note is private to you. To write his reply, Aris sends it to our AI provider — see Your notes and AI below. His reply is stored so your history can show what he said.
- Stories. If you publish a day, a single headline written by Aris from your note becomes visible to other members. That headline is a synthesis, not your note reproduced. A second, separate choice — made per day — decides whether the note behind the headline travels with it. Unpublishing removes both and leaves no record that a story existed.
- Your protocol base. Sex, birth date, height, weight, how often you train, how the rest of your day moves, your bedtime and how long you intend to sleep. We store what you told us; every target is computed from it on read and none of the computed numbers are stored.
- Your day. The schedule, targets and goals you keep, and which parts of the protocol you ticked off on a given day.
- Forum activity. Posts, comments and votes, under your nickname and visible to other members.
Body and health figures. Your height, weight, date of birth, sleep and training load can amount to data concerning health. We treat them as special-category data and process them on the basis of your explicit consent, given at checkout and again when you set up your base. You can withdraw that consent or delete the base entirely, without giving up the rest of the membership. We do not connect to fitness trackers or wearables and we do not collect step counts or heart-rate data.
Your notes and AI
Your daily note is a free-text field, so what goes in it is entirely yours to decide — and people write about their health, their moods, their treatment and their setbacks. We do not ask for any of that, and no part of the product looks for it. But we do have to say plainly what happens to a note once you save it.
Where it goes. The note is stored in our database in Frankfurt. To write his reply, and to write a story headline if you ask for one, Aris sends the text of that note to OpenAI in the United States. It is sent without your name, your email or your account id — the provider receives the words and nothing that identifies who wrote them. We ask the provider not to store it, and it is not used to train their models. Like any API customer we cannot rule out a short abuse-monitoring window on their side; what we control is that nothing we send links those words to you.
The basis for it. Because a note can contain data concerning health, we treat it as special-category data and rely on the explicit consent you give at checkout, which names your notes and this transfer. You can withdraw that consent at any time; the practical effect is that Aris stops replying, because a reply to a note requires sending the note.
What stays private. Notes are private by default and no other member can read one. Publishing a day as a story is a separate choice you make per day, and it publishes a one-line headline rather than the note; releasing the note behind it is a further, separate choice. Nothing is inherited from one day to the next.
If you would rather Aris never saw a particular day, leave the note empty — the check-in still counts, and your streak is unaffected.
Payment
Payments run through Stripe. We hold a Stripe customer id, a subscription id and status, the price, the amount, the currency, the billing interval, the renewal date and invoice records. We never receive or store your card number.
Collected automatically
- Request data — IP address, user agent, the page requested, and the time — logged by our hosting provider for security and diagnostics.
- Error reports — when something breaks, a stack trace and the account id associated with the failing request go to our monitoring service.
- Page-timing measurements — anonymous loading and responsiveness figures. They carry no identifier and are used to find slow pages.
- Cookies. Only the ones that keep you signed in, carry an in-progress signup, and remember your cookie choice. See the cookie policy.
4What we do with it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Running the check-in, the protocol, the feed and the forum | Performance of the contract — Article 6(1)(b) |
| Historical: verifying a joining member was a real person and not already a member. No longer carried out; the enrolments it produced are held under the consent given at the time, until the deletion deadline on each record | Explicit consent — Articles 6(1)(a) and 9(2)(a) |
| Your protocol base — body and health figures — and the targets computed from it | Explicit consent — Article 9(2)(a) |
| Sending your daily note to our AI provider so Aris can reply | Explicit consent — Article 9(2)(a), and Article 6(1)(b) for the reply itself |
| Taking payment and keeping invoices | Contract, and legal obligation for accounting records |
| The daily reminder and the streak email | Contract; you can switch the reminder off at any time |
| Security, abuse prevention, and keeping the service up | Legitimate interests — Article 6(1)(f) |
| Answering a legal request or a tax audit | Legal obligation — Article 6(1)(c) |
There is no advertising, no profiling for advertising, and no sale of personal data. No third-party advertising or cross-site tracking network is loaded by this product.
5What other members can see
The defaults are these, and every one of them is yours to change:
- Shown by default: your nickname, your avatar, your member number, your daily level, and your index.
- Hidden by default: your notes, and your base — body composition, sleep and training load.
- Only ever shown by a deliberate act: a story headline, and separately the note behind it. Both are decided per day.
- Leaving entirely: one switch removes you from the feed and from search.
Anything you post in the forum is visible to other members under your nickname. Treat it as published.
6Who processes it for us
The following processors act on our instructions under written agreements meeting Article 28 GDPR. Where a transfer outside the EEA is involved, it is covered by the European Commission’s Standard Contractual Clauses together with encryption in transit and at rest.
| Processor | What it does | What it sees | Where |
|---|---|---|---|
| Amazon Web Services | Storage of the face images produced by the liveness check that used to run at signup. No new images are created — the check has been removed from the product | For members who joined while the check existed: the reference and audit images it produced, and a numeric face template. Nothing is captured now | European Union — Frankfurt (AWS eu-central-1) |
| Shared face register | Historical. This product no longer enrols or matches faces — the check was removed. Templates enrolled while it ran remain in a register that is shared with sibling products rather than copied per product, which is why the entry stays until they are erased | For members enrolled while the check ran: the numeric face template derived from it. Not the images — those stay in this product’s own storage. Nothing new is enrolled. | European Union — Frankfurt (AWS eu-central-1), processed under a Joint Controller Agreement (Art. 26 GDPR) |
| Neon | Managed PostgreSQL — the application database | Everything the product stores: account, check-ins, notes, protocol, forum posts, billing references | European Union — Frankfurt (AWS eu-central-1) |
| Google (Firebase Authentication) | Sign-in, password handling and email verification | Email address, password (hashed by Firebase — never seen by us), sign-in metadata | Google infrastructure, subject to Google’s regional terms |
| Stripe | Payment processing and subscription management | Name and email you give at checkout, card details (handled entirely by Stripe), billing country, invoices | Ireland and the United States |
| OpenAI | Generating the coach reply, the story headline, your nickname and your avatar | The content of the note you are sending, the context Aris is given with it, and your avatar prompt — unaccompanied by your name, email or account id | United States |
| Cloudflare (R2) | Object storage for avatar and profile images | Your avatar image and its style asset | Cloudflare’s network |
| Vercel | Hosting, edge routing and Speed Insights | Request metadata — IP address, user agent, the URL requested, and anonymous page-timing measurements | Global edge network |
| Amazon Web Services (Amazon SES) | Sending the reminder, streak, verification and billing emails | Your email address and the content of the message sent to you | European Union — Frankfurt (AWS eu-central-1) |
Beyond these, we disclose personal data only where the law requires it, to establish or defend a legal claim, or — with notice to you — if the service is transferred to another owner.
7How long we keep things
- Your account and everything in it — for as long as the membership exists. Deleting your account deletes the profile, the check-ins, the notes, the protocol and the forum content attached to it.
- Liveness images and face templates — historical only; nothing new is created. Each existing enrolment is held until the deletion deadline on its own record. See §2.
- A minimal archive of deleted accounts — after deletion we keep a small record: the email address, the member number and the payment references. It exists to answer a chargeback and satisfy a tax audit. Nothing you wrote is in it.
- Invoices and payment records — for the period accounting law requires, 10 years (or as mandated by applicable statutory accounting and tax laws).
- Error reports and request logs — a rolling window measured in weeks, not years.
- Abandoned signups — a signup you never finished leaves no account and no charge, only a short-lived session record which expires on its own.
Deletions propagate to encrypted backups as those backups roll over, within 30 days.
8Your rights
Under the GDPR you can ask us to:
- give you a copy of your data, in a portable format;
- correct anything wrong;
- delete your account and its contents;
- restrict or object to a particular use;
- withdraw a consent — health data, or the reminder email — at any time.
Write to info@growmoment.app. We answer within one month. If you think we have handled your data badly, you can complain to a supervisory authority; ours is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), Lithuania, and you may also complain to the authority where you live.
9Security
Everything travels over HTTPS. The session cookie is host-scoped, signed, HTTP-only and not readable by scripts. Access to production data is limited to the people who need it. Backups are encrypted. API routes are closed by default at the edge and opened only where a route is deliberately public.
None of that makes a system unbreakable, and we will not pretend otherwise. If a breach affects your data we will act under Articles 33 and 34 — notifying the supervisory authority within 72 hours and telling you directly where the risk to you is high.
10Changes
If this policy changes materially we will update the date at the top and tell you directly before the change takes effect. A change that widens what we do with data you have already given us will ask for your consent rather than assume it.