GrowSocialelion (“we”, “us”) is an open-source social-growth agent operated by Ellelion LLC. This policy explains what we collect, why, and the control you keep over your data. If you self-host GrowSocialelion, you are the operator of your own instance and this policy describes the managed service we run at growsocialelion.com.
What we collect
- Account details. Your email address and authentication identifiers when you create an account.
- Connected social accounts. When you connect a network over OAuth, we store the access tokens that network issues us, scoped to the permissions you grant, and revocable by you at any time from the network or from your dashboard. Networks with no OAuth flow use an app-specific password instead, which we exchange for a session and do not store; revoking it stays in your hands, in that network's own settings.
- Content and activity. Drafts the agent produces, posts and replies you publish through us, and the research signals the agent gathers about your niche.
- Operational logs. An audit record of actions the agent takes on your behalf, plus standard technical logs needed to run and secure the service.
- Posts you ask the product to analyze. When you submit or select an X post through an official API-backed product surface, we receive its text, public author information, and URL so the AI can draft relevant work. The browser companion itself does not read that data from x.com.
How we use it
- To research your niche and draft, schedule, and publish content you approve or delegate.
- To run the auto-research loop on the cadence and autonomy setting you choose.
- To provide the audit log, support, and account security.
We do not sell your personal data, and we do not use the content of your connected accounts to train foundation models.
Platform data
Data we access from a connected network is used only to deliver the features you enabled for that network. We request the minimum scopes or credentials each feature needs, retain platform data only as long as your account is connected, and delete stored tokens, credentials, and private-key envelopes when you disconnect a network or close your account. Some network credentials cannot themselves be revoked: a Nostr private key is the identity. For current envelope-backed connections, disconnecting deletes the wrapping key and makes our ciphertext unreadable, but it cannot invalidate a copy held elsewhere. A legacy plaintext Nostr connection may also remain in an old Eve snapshot until the operator audits or removes those snapshots. Your use of each network also remains governed by that network's own terms and policies.
The browser companion
The current Chrome manifest does not request access to x.com and does not load an X content script. X page reading, injected controls, composer prefill, and automated website clicks are disabled under X's April 2026 Automation Rules.
- It does not read X pages. Public X data used by the product comes through official API endpoints and the scopes granted to the connected account.
- It does not inspect your signed-in X session.Account identity is bound through the product's OAuth connection instead of DOM inspection.
- It does not add controls or fill forms on X. Manual handoff may show or copy reviewed text, but you perform every website input and click yourself.
- Archived code is not active behavior. The repository retains the former X content script as implementation history, but the shipped manifest deliberately does not load it. Restoring it requires written permission from X and a privacy-policy update.
- It stores no credentials of any kind. No passwords, no tokens, no keys live in the companion. It does not rely on or inspect your X browser session.
Posts by people who are not our users are processed only to draft the reply you asked for, are never sold, never used to train foundation models, and never used to build profiles of their authors. Dismissing a draft in your Inbox retires it but keeps the record, because the audit log has to stay complete; deleting your account deletes the underlying data. If you are the author of a post that was processed this way and you want it erased, email us and we will erase it.
Sharing
We share data only with infrastructure providers that help us run the service (for example hosting and AI model providers), under contracts that restrict them to that purpose, and when required by law. We never post to your accounts except as you direct or delegate.
Your controls
- Disconnect any network at any time to remove our stored access token or credential envelope. Where the network supports revocation, we request it; Nostr identities cannot be revoked.
- Export or delete your account data on request.
- Self-host the open-source agent if you prefer to keep all data on your own infrastructure.
Your rights (US & California)
Ellelion LLC is based in Wyoming, United States, and your data is processed in the US. You can request access to, correction of, or deletion of your personal data at any time by emailing us. California residents have the right under the CCPA to know what personal information we hold, to request its deletion, and to opt out of its sale. Because we do not sell personal data, there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
Data retention
We keep account data while your account is open and delete it, along with stored network tokens, credentials, and private-key envelopes, when you close your account or disconnect a network, except records we are required to keep for legal or security reasons. You can request deletion sooner.
Changes to this policy
We will update this policy as the service changes and reflect the date above. Material changes will be communicated through the service.
Contact
Questions or requests: [email protected]. Ellelion LLC, Wyoming, USA.