Effective date: August 15, 2026 Last updated: August 1, 2026 Version: 2.2

Growth Leaps ("Needlz", "we", "us") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and protect your information when you use needlz.ai. It applies to all Users regardless of location, with additional rights for individuals in the EEA/UK (including France), Brazil, and California noted below.

Data Controller: Growth Leaps, 3206 Warder St NW, Washington, DC 20010, USA — contact@needlz.ai


1. Data We Collect

1.1 Account Data — Name, email address, company/brand name, role or job title, billing address, and payment method (processed by our payment provider; we never store full card details). If you start a free trial, we record the trial start and end dates.

1.2 Brand & Configuration Data — The brand profile, website, competitors, buyer questions, topics, brand names and aliases, and the markets (countries) you choose to measure. For agency and multi-brand customers, this includes the same information for each brand you manage on behalf of a client.

1.3 Measurement Data — The results of our scans: which AI answers named your brand or a competitor, how warmly, in which position, which sources fed those answers, and the market and date of each scan. This is stored as a history so the Platform can show trends and generate reports.

1.4 Engagement & Outcome Data — The conversations surfaced to you; the AI Suggestions generated; which suggestions you edited, skipped, or marked as posted; and, where you have told us you posted a reply and provided your public handle, publicly available signals about that reply (for example whether it is still visible and its public engagement counts). We use this to report outcomes to you and to improve suggestion quality.

1.5 Brand Voice Data — Where you provide them or mark a reply as posted, samples of your own writing, used to make future suggestions sound like you. You can ask us to delete these samples at any time.

1.6 Technical Data — IP address, browser type and version, device identifiers, operating system, referral URLs, session duration, and log data.

1.7 Communications — Emails, support messages (including WhatsApp support conversations, where you choose to use that channel), and feedback you send us.

1.8 Third-Party Integration Data — If you connect third-party platform accounts (e.g., a Reddit handle), we store the identifiers and tokens needed to perform the functions you request, and nothing more.

1.9 Public Content We Analyse — The Platform analyses publicly available content (for example public Reddit, Quora and X threads, public web pages, and publicly generated AI answers) to surface opportunities and measure visibility. We do not collect private or non-public content from these sources, and we do not attempt to identify the individuals who wrote public posts beyond the public author name shown on the source.

2. How We Use Your Data

  • Provide and operate the Platform, including scans, measurements, suggestions, and reports.
  • Personalise AI Suggestions to your brand voice, at your direction.
  • Measure and report outcomes of replies you have posted.
  • Billing, invoicing, tax compliance, and fraud prevention.
  • Customer support and responding to enquiries.
  • Transactional emails (account notices, scan results, billing receipts) and, with consent, marketing communications.
  • Security monitoring, debugging, abuse prevention, and enforcing our Acceptable Use Policy.
  • Compliance with legal obligations.
  • Aggregated, de-identified analytics to understand usage and improve the product and our models.

We do not sell your personal data. We do not use your confidential brand content, your private data, or your clients' data to train models for the benefit of other customers. Where we improve our systems from usage, we do so using aggregated and de-identified information that does not identify you, your brands, your clients, or any individual.

Purpose GDPR basis LGPD basis
Providing the Platform Art. 6(1)(b) — contract Art. 7(V) — contract performance
Measurement, suggestions, outcome reporting Art. 6(1)(b) — contract Art. 7(V)
Billing, tax & fraud prevention Art. 6(1)(b)/(c)/(f) Art. 7(II)/(V)/(IX)
Marketing communications Art. 6(1)(a) — consent Art. 7(I) — consent
Security & abuse prevention Art. 6(1)(f) — legitimate interests Art. 7(IX) — legitimate interests
Analysis of public content for measurement Art. 6(1)(f) — legitimate interests Art. 7(IX), and Art. 7(IV) for publicly accessible data
Legal compliance Art. 6(1)(c) Art. 7(II)
Product analytics and service improvement (de-identified) Art. 6(1)(f) — legitimate interests Art. 7(IX)

Where we rely on legitimate interests, we have assessed that our interest in operating, securing, and improving the service does not override your rights. You may object at any time (Section 7).

4. Data Sharing

We share data only with:

  • Service providers (sub-processors): cloud hosting and storage (Google Cloud / Firebase), payment processing (Stripe, and any merchant-of-record we appoint for a country), AI model providers used to generate AI Suggestions, search- and answer- measurement providers, email delivery, and analytics — each bound by data processing agreements. The current list is available on request to contact@needlz.ai.
  • Professional advisers — lawyers, accountants, auditors, under confidentiality.
  • Regulators and law enforcement — where required by law or to protect rights and safety.
  • Business transfers — in a merger, acquisition, or asset sale, data may transfer to the successor entity under this policy's protections.

We do not share your data with other Needlz customers. Each customer's data is isolated to that customer's account.

5. International Transfers

Our infrastructure is hosted in the United States (US-East region), and some sub-processors operate elsewhere. Where personal data is transferred internationally we rely on appropriate safeguards:

  • EEA / UK: the European Commission's Standard Contractual Clauses (Decision 2021/914) and UK International Data Transfer Addendum, with transfer risk assessments where required.
  • Brazil: the ANPD's standard contractual clauses under Resolution CD/ANPD No. 19/2024, or another lawful transfer mechanism under LGPD Chapter V.

A copy of the relevant safeguards is available on request.

6. Retention

Data Retention
Account & billing records Duration of the account, then as required for tax and accounting law (typically up to 5 years)
Brand configuration & measurement history Duration of the account, so trends and reports remain available; deleted on request or after account closure per below
Engagement, outcome & brand-voice data Duration of the account; brand-voice samples deletable on request at any time
Support communications Up to 3 years from last contact
Technical logs Typically up to 12 months

After account closure we delete or anonymise personal data within a reasonable period (typically up to 3 years for records we must retain), and backup copies are purged on a rolling schedule. You may request earlier deletion (Section 7).

7. Your Rights

EEA / UK (GDPR / UK GDPR): access; rectification; erasure; restriction; portability; objection to legitimate-interest processing and to direct marketing; withdrawal of consent at any time; the right not to be subject to solely automated decisions with legal or similarly significant effects (we do not make such decisions); complaint to your supervisory authority — in France, the CNIL (www.cnil.fr).

Brazil (LGPD): confirmation of processing; access; correction; anonymisation, blocking, or deletion of unnecessary or non-compliant data; portability; deletion of consented data; information on sharing; information about the consequences of refusing consent; revocation of consent; review of automated decisions; petition to the ANPD.

California (CCPA/CPRA): know what personal information is collected, used, shared, or sold; delete; correct; opt out of sale/sharing (we do not sell or share personal information for cross-context behavioural advertising); non-discrimination for exercising rights.

To exercise any right: contact@needlz.ai. We respond within the timeframe required by applicable law (typically 15 days in Brazil, one month in the EEA/UK).

8. Security

We implement appropriate technical and organisational measures: encryption in transit (TLS) and at rest, tenant isolation (each customer's data is accessible only to that customer's account members), least-privilege access controls, server-side enforcement of account boundaries, and regular security review. If a personal data breach affects you, we will notify you and the relevant authority as required by law. No internet transmission method is 100% secure.

9. Cookies

See our Cookie Policy. You can manage preferences via the cookie banner and the Cookie Settings link in the footer. We set no non-essential cookies until you choose, and rejecting is as easy as accepting — a single click on the banner.

10. Agencies and Multi-Brand Customers

If you use the Platform on behalf of clients, you are the controller of your clients' personal data and Needlz acts as your processor under our Data Processing Agreement. You are responsible for having a lawful basis and the authority to submit that data, and for informing your clients as required.

11. Children's Privacy

The Platform is not directed at children under 16, and we do not knowingly collect their data. If we become aware that we have, we will delete it promptly.

12. Changes to This Policy

Material changes will be notified by email or in-app notice at least 14 days before taking effect.

13. Contact

Data Controller: Growth Leaps — 3206 Warder St NW, Washington, DC 20010, USA Privacy enquiries: contact@needlz.ai Data Protection Officer (if appointed): contact@needlz.ai EU/UK representative, if required: contact@needlz.ai Brazil (LGPD) representative, if required: contact@needlz.ai


Version History

Version Date Summary
1.0 July 22, 2026 Initial policy
2.0 August 15, 2026 Global launch update: added measurement history, engagement/outcome and brand-voice data categories; clarified analysis of public content; explicit statement on de-identified service improvement; expanded legal bases; per-category retention table; Brazil transfers under ANPD Resolution 19/2024; CNIL and ANPD named; agency/multi-brand controller-processor section
2.1 July 30, 2026 Reconciled with the Terms & Conditions as the reference generation: the sub-processor list is now provided on request; clarified that a Data Protection Officer and the EU/UK and Brazil representatives are named where appointed or required; internal cross-references now point at published routes
2.2 August 1, 2026 Section 9 now states plainly that no non-essential cookies are set until you choose, and that rejecting takes the same single click as accepting — matching the Cookie Policy