๐Ÿ”’ Privacy Protected

Privacy Policy

Last updated: June 6, 2026  ยท  Effective: June 6, 2026  ยท  Version: 2.0

๐Ÿ— Plain-Language Summary (TL;DR)

๐Ÿ”’

No selling. Your child's data is never sold, rented, or traded to anyone. Ever.

๐Ÿ—„

Self-hosted. Data lives in an encrypted, private database. Not shared with ad networks.

๐Ÿ—‘

Delete anytime. One click to export or permanently delete all your data.

๐Ÿ“Š

Optional research. Anonymous aggregated data for research only with your explicit consent.

1 Who We Are

GrowChart ("we", "us", "our") is a child growth tracking platform operated by Fayez Ahmed, a sole proprietor based in Bangladesh. Our service is available globally at www.growchart.app and www.growchart.app.

For the purposes of the General Data Protection Regulation (GDPR), we act as the Data Controller for personal data collected through GrowChart. For users in the European Economic Area, we comply with GDPR. For users in California, we comply with CCPA. For users globally, we apply the highest applicable standard.

Contact: For any privacy matter, email [email protected]. We respond within 72 hours.

2 Data We Collect

2.1 Account Data

2.2 Child Health Data (Sensitive)

This is the most sensitive category. You provide this voluntarily to use the core service:

โš  Medical note: GrowChart is not a medical device. Growth data you enter is used only to compute WHO/CDC standard scores for educational purposes. We do not transmit clinical health data to any electronic health record (EHR) system unless you explicitly configure an integration.

2.3 Technical Data

2.4 Data We Do NOT Collect

3 How We Use Your Data

PurposeData UsedLegal Basis (GDPR)
Providing the growth tracking serviceAccount + child health dataContract performance (Art. 6(1)(b))
Computing WHO/CDC z-scores and percentilesChild age, sex, measurementsContract performance (Art. 6(1)(b))
Generating PDF growth reportsAll child data for selected childContract performance (Art. 6(1)(b))
Sending transactional emails (alerts, invitations)Email addressLegitimate interest (Art. 6(1)(f))
Processing subscription paymentsEmail, subscription statusContract performance (Art. 6(1)(b))
Anonymous research dataset (opt-in only)Age in months, sex, measurements (de-identified)Explicit consent (Art. 6(1)(a))
AI Growth Advisor (Premium)Child's measurements, z-scores, feeding/sleep logsContract performance + consent
Security and fraud preventionIP address, usage patternsLegitimate interest (Art. 6(1)(f))
Legal complianceAccount dataLegal obligation (Art. 6(1)(c))

AI Advisor: When you use the AI Growth Advisor (Premium feature), your child's growth context (age, measurements, z-scores, feeding summary) is sent to an AI API for response generation. No raw photos are sent. You can disable the AI Advisor at any time in Settings โ†’ AI Features.

4 Data Storage and Security

4.1 Where Data Is Stored

Your data is stored in a self-hosted, private PostgreSQL database on secured infrastructure. Database files are encrypted at rest using AES-256. All data in transit is protected by TLS 1.3.

4.2 Security Measures

4.3 Data Retention

Data CategoryRetention Period
Active account data (children, measurements, logs)Until you delete your account
Deleted account dataPermanently purged within 30 days of deletion request
Backup copiesOverwritten within 30 days
IP address logs7 days
Anonymised research data (if consented)Indefinite (cannot be re-linked to you)
Payment records7 years (legal requirement)

5 Who We Share Data With

We do not sell your data. We share data with the following trusted processors, under contractual data processing agreements, only to the extent necessary to provide the service:

ProcessorPurposeData SharedPrivacy Policy
LemonSqueezy / PaddlePayment processingEmail, subscription planTheir respective policies
ResendTransactional email deliveryEmail address, email contentresend.com/privacy
Anthropic / Google (AI providers)AI Growth Advisor responses (Premium only)Child growth context (no PII, no photos)Respective privacy policies
Backblaze B2Encrypted file storageEncrypted files onlybackblaze.com/privacy

We may disclose data if required by law (e.g. a court order or regulatory requirement) in the jurisdiction where we operate. We will notify you of any such disclosure unless legally prohibited from doing so.

6 Cookies and Local Storage

What we use

TypeName / KeyPurposeDuration
Session Cookiesb-auth-tokenAuthentication โ€” keeps you logged inSession / 7 days
LocalStoragetheme, language, unitWeight, unitHeightYour app preferencesUntil cleared
IndexedDBofflineQueueOffline measurement queue (PWA)Until synced

We use zero advertising cookies and zero cross-site tracking cookies. No third-party analytics scripts run on our app pages.

Public marketing pages (www.growchart.app) may display Google AdSense banners in the future. These are limited to public calculator pages and are never shown inside the authenticated app.

7 Children's Privacy (COPPA / PDPA)

GrowChart is operated by adults โ€” parents, guardians, and healthcare professionals โ€” on behalf of children. We do not knowingly collect data directly from children under the age of 13.

If you believe a child under 13 has created an account directly, contact us at [email protected] and we will delete the account immediately.

8 Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

๐Ÿ‘

Access

Request a copy of all data we hold about you.

โœ๏ธ

Rectification

Correct inaccurate or incomplete data at any time in-app.

๐Ÿ—‘

Erasure

Delete your account and all associated data permanently.

๐Ÿ“ฆ

Portability

Export all your data as JSON or CSV at any time.

๐Ÿšซ

Object

Opt out of processing for research or legitimate interest purposes.

โธ

Restriction

Request that we pause processing your data while a dispute is resolved.

To exercise any of these rights, email [email protected] or use the in-app Data & Privacy settings. We will respond within 30 days. EU/UK residents may also lodge a complaint with their national supervisory authority.

9 International Data Transfers

GrowChart is operated from Bangladesh. If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data transfer restrictions, please note:

10 Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or for legal compliance. When we make material changes, we will:

Your continued use of GrowChart after the effective date of an updated policy constitutes acceptance of the new terms.

Questions about your privacy?

We take privacy seriously. Reach out and we will respond within 72 hours.