Trust
Security
Last updated: October 7, 2026
This page summarizes, in plain language, how GrowthAI protects your account and the data in your workspace. It's meant to give you a clear picture of our practices — not to serve as a certification or compliance claim.
Account protection
- Password storage — we never store your password in plain text. It's run through a salted, one-way cryptographic hashing function before it's saved, so even we can't read it back.
- Optional two-factor authentication — you can turn on authenticator-app-based two-factor authentication from your Account settings for an extra layer of protection beyond your password.
- Session handling — signing in issues a session credential that's stored in hashed form, expires automatically, and can be revoked by signing out. We never ask for your password over email or chat.
- Email verification and password reset — account recovery flows use single-use, time-limited codes sent to your registered email address.
Data isolation
Every organization has its own private workspace. Leads, notes, tasks, pipeline activity, and company profile information are scoped to your organization and are not visible to other GrowthAI customers. Within an organization, administrators control what teammates can see and do through role-based permissions.
Encryption in transit
Connections to GrowthAI are encrypted using HTTPS/TLS, so data moving between your browser and our servers is protected from interception.
Payments
Subscription payments are handled entirely by our payment processor (Stripe). GrowthAI never receives or stores your full card number.
Third-party service providers
Optional features — like lead search, email verification, contact enrichment, and transactional email delivery — are powered by vetted third-party providers. These providers only receive the specific information needed to perform that function (for example, an email address to check deliverability) and are not permitted to use it for their own purposes. You can see which optional features are configured for your account from within the Service.
Access controls
Access to production systems and customer data is limited to the people who need it to operate and support the Service. We apply the principle of least privilege to internal access.
Reporting a security issue
If you believe you've found a security vulnerability in GrowthAI, please tell us before disclosing it publicly so we can investigate and fix it. Email support@growthai.rinmac.com with as much detail as you can — steps to reproduce, affected URLs, and potential impact — and we'll respond as quickly as we can. Please don't access, modify, or delete data that isn't yours while investigating an issue.
Your part in keeping your account secure
- Use a strong, unique password for your GrowthAI account and turn on two-factor authentication;
- Don't share your login credentials, and remove teammates from your organization promptly when they leave;
- Review the data you import or paste into GrowthAI before you add it, especially if it came from an external source;
- Contact us right away if you notice unexpected activity on your account.
Questions
For anything else about how we protect your data, email support@growthai.rinmac.com. For how we collect and use data, see our Privacy Notice.