Legal

Privacy Policy

Effective and last updated: July 21, 2026

This Privacy Policy explains how Toadstool Labs LLC, an Oregon limited liability company ("Toadstool," "we," "us," or "our"), collects, uses, discloses, and otherwise processes personal data through Growth Chicken and the websites, applications, APIs, communications, and related services that link to this policy (collectively, the "Service").

The Service is designed for businesses and adults in the United States. If you use the Service for an organization, that organization may separately control information it submits. This policy does not govern an organization's own privacy practices or third-party services that have their own policies.

Questions and privacy requests may be sent to [email protected].

1. Personal data we collect

Depending on how you interact with the Service, we may collect the following categories of personal data:

  • Account and contact data. Email address, username, account identifiers, organization information, account status, preferences, and authentication or API credentials.
  • Customer Content. Prompts, project descriptions, brand information, logos, fonts, images, video, audio, audience descriptions, creative directions, ads, generated output, campaign data, performance observations, tags, external platform identifiers, URLs you ask us to analyze, and other material you submit or generate.
  • Transaction data. Products or subscriptions purchased, token balances and usage, payment status, billing history, and related transaction identifiers. Our payment processor, rather than Toadstool, receives and processes full payment card details.
  • Communications. Contact requests, support messages, product feedback, survey responses, and related correspondence.
  • Device, network, and usage data. Internet Protocol address, browser and device type, operating system, referring and exit pages, timestamps, pages or features used, request and error logs, session information, cookie or similar identifiers, and interactions with emails or the Service.
  • Advertising and attribution data. Advertising click identifiers, campaign parameters, referring source, Meta browser and click identifiers, conversion events, and related measurement information.
  • Inferences. Information we derive from the categories above, such as likely interests, brand characteristics, product preferences, fraud or security signals, and feature recommendations.

We collect this data directly from you, automatically from your browser or device, from your organization and its users, from public webpages you direct us to access, and from providers such as payment, advertising, authentication, and analytics services.

2. Sensitive data

The Service is not designed to collect government identifiers, financial account credentials, precise geolocation, biometric identifiers used to identify a person, health information, or other sensitive personal data. Do not submit sensitive personal data unless we specifically request it and provide any notice or consent required by law. Customer Content may incidentally contain sensitive data that you choose to provide. You are responsible for having a lawful basis and all required permissions for that submission.

We do not sell precise geolocation data.

3. How we use personal data

We may use personal data to:

  • provide, operate, maintain, personalize, and improve the Service;
  • create accounts, authenticate users, secure API access, and manage organizations;
  • process Customer Content, generate creative material, import assets from requested webpages, store files, render deliverables, and fulfill other instructions;
  • process purchases, subscriptions, token usage, refunds, taxes, and transaction records;
  • send authentication links, service messages, account notices, requested marketing communications, and ad-health or performance alerts;
  • respond to support requests, feedback, and other communications;
  • measure performance, understand use, debug errors, research features, and develop or improve the Service;
  • attribute advertising, measure conversions, and market the Service;
  • detect, investigate, and prevent fraud, abuse, security incidents, policy violations, and unlawful activity;
  • enforce our agreements, protect rights and safety, comply with law, and establish or defend legal claims; and
  • create aggregated or deidentified information that we may use and disclose for any lawful purpose. We will not attempt to reidentify data that applicable law requires us to maintain as deidentified.

4. How we disclose personal data

We may disclose personal data to the following categories of recipients:

  • Service providers. Hosting, cloud infrastructure and storage, content delivery, database, security, authentication, email, customer support, payment, rendering, monitoring, and professional-service providers. These may include Railway, Cloudflare, Stripe, Sentry, and RewindRewind.
  • AI and media providers. Providers that process prompts, text, images, video, audio, and related Customer Content to deliver requested features. These may include OpenAI, xAI or Grok, and Suno or their infrastructure providers.
  • Advertising and measurement partners. Meta and other partners that help attribute visits, measure conversions, deliver or evaluate advertising, and understand campaign performance.
  • Your organization and collaborators. Other authorized users, account administrators, and people with whom you direct us to share data or deliver output.
  • Authorities and other parties for legal reasons. Courts, regulators, law enforcement, opposing parties, advisors, and others when we believe disclosure is necessary to comply with law, protect rights or safety, investigate misuse, or enforce agreements.
  • Business transaction recipients. Actual or prospective buyers, investors, lenders, advisors, and other participants in a financing, merger, acquisition, reorganization, sale of assets, bankruptcy, or similar transaction, subject to appropriate confidentiality protections where required.
  • At your direction or with your consent. Any other recipient you authorize.

The personal-data categories disclosed may include identifiers, contact and account data, Customer Content, commercial and transaction information, internet or network activity, advertising data, inferences, and communications. We disclose each category only as reasonably relevant to the recipient's role or as otherwise described in this policy.

5. Advertising, cookies, and privacy choices

We and our providers use cookies, local storage, pixels, and similar technologies for authentication, security, preferences, service operation, error monitoring, advertising attribution, and measurement. Meta may receive identifiers, device or browser information, page activity, and conversion data and may combine that information with data from other sources under its own privacy policy.

We do not sell personal data for money. Some U.S. state laws may define disclosures to advertising partners as a "sale," "sharing," or processing for targeted advertising even when no money changes hands. In the preceding 12 months, we may have shared identifiers, commercial information, and internet or network activity with advertising and measurement partners for these purposes.

You may opt out of these disclosures by enabling Global Privacy Control in a supported browser or by emailing [email protected]. The Service treats a Global Privacy Control signal as an opt-out from Meta advertising measurement for that browser. We do not respond to other "Do Not Track" signals. To opt out of nonessential cookies already stored in your browser, you may also clear or block them through browser settings, though parts of the Service may not function correctly.

We do not knowingly sell or share the personal data of anyone under 16.

6. Data retention

We retain personal data for as long as reasonably necessary for the purposes described in this policy, including while your account is active, to provide the Service, maintain transaction and security records, resolve disputes, enforce agreements, comply with legal obligations, and protect the Service. Retention periods depend on the type and sensitivity of data, the context in which it was collected, operational needs, and legal requirements.

When data is no longer required, we may delete, aggregate, or deidentify it. Deletion from active systems may not immediately remove data from backups, security records, legal archives, or systems where continued retention is required or permitted by law. We may retain deidentified information indefinitely.

7. Security

We use administrative, technical, and organizational safeguards designed to protect personal data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding sign-in links, API tokens, devices, and account access and for promptly notifying us of suspected unauthorized use.

8. Your privacy rights

Depending on where you live and subject to legal exceptions, you may have the right to confirm whether we process your personal data; access it; obtain a portable copy; correct inaccuracies; delete it; obtain a list of specific third parties that received personal data; withdraw consent; and opt out of sale, targeted advertising, or profiling that produces legal or similarly significant effects. We do not use personal data to make decisions that produce legal or similarly significant effects.

Submit a request to [email protected] and describe the right you wish to exercise. We may verify your identity and authority using information associated with your account. An authorized agent may submit an opt-out request for you and, where required by law, other requests with proof of authorization. A parent or legal guardian may submit a request for a child.

We will respond within the period required by applicable law, generally 45 days for covered Oregon requests, with an extension where permitted. We will not discriminate against you for exercising a privacy right. If we deny your request, you may appeal by replying to our decision or emailing us with the subject "Privacy appeal." We will provide a written appeal decision and, where required, information about how to contact the appropriate regulator.

Oregon residents may learn more or submit a complaint through the Oregon Department of Justice privacy portal.

9. Children

The Service is not directed to children and may be used only by people who are at least 18 years old. We do not knowingly collect personal data directly from children under 13. If you believe a child has provided personal data, contact us so we can investigate and take appropriate action.

10. International use

Toadstool is based in Oregon, and the Service is operated in the United States. If you access the Service from another country, your personal data may be transferred to, stored in, and processed in the United States and other countries where our providers operate. Those countries may have privacy laws different from those where you live. We use legally recognized safeguards when required.

11. Third-party services

The Service may link to, integrate with, or receive data from third-party services. Their privacy practices are governed by their own notices, not this policy. Review those notices before providing personal data or connecting an account.

12. Changes to this policy

We may update this policy to reflect changes in the Service, our practices, or law. We will post the updated version here and change the date above. If required by law, we will provide additional notice or obtain consent before a material change takes effect.

13. Contact us

Toadstool Labs LLC
Oregon, United States
[email protected]