Privacy Policy
Last updated: August 26, 2026
1. Who we are
Grovik is operated by Holm Marketing, a sole proprietorship registered in Denmark (CVR 45285014), based in Gråsten, Denmark ("we", "us"). We are the data controller for the personal data described below. For any privacy question, contact support@grovik.ai.
2. What we collect
- Account data: name, email, password (hashed), company name.
- Billing data: handled by our payment processor (Stripe) - we receive limited metadata, not full card numbers.
- Site and content data: your website URL, brand tone and audience settings, connected platform credentials, generated articles and images.
- Usage data: pages visited, features used, device and browser information, IP address.
- Cookies: see Section 6.
3. How we use it
We use your data to provide and improve the Service (create your account, run keyword research, generate and publish content, provide support), to process billing, to keep the Service secure, and to communicate with you about your account. Providing the Service and handling billing rest on our contract with you; security and product improvement rest on our legitimate interest, which you can object to at any time.
Everything in Section 6 marked "your choice" rests on your consent, and on nothing else. Where we describe hashing data before sending it, that is a security measure — it is not what makes the sharing lawful, and it does not happen without your consent.
4. Who we share it with
We share data with service providers who help us run Grovik, including: cloud hosting, our database provider, our payment processor (Stripe), our authentication provider (Clerk), our AI providers (used to generate content on your behalf), and keyword/search-data providers. These providers are bound by data processing agreements. We do not sell your personal data.
If — and only if — you have consented to the corresponding purpose, we also share measurement data with Google (Google Analytics, linked to Google Ads) and Meta (the Meta pixel and the Conversions API). Section 6 sets out exactly what each of them receives. For the marketing purpose, Meta acts as an independent controller of the data it receives, not only as our processor.
5. International transfers
Some of our service providers are located outside the EU/EEA, including in the United States. Where this is the case, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
6. Cookies and measurement
Nothing that measures you runs until you say it can. When you first visit, we ask, and until you answer we load no analytics or advertising scripts and set no cookies for either purpose. You can change or withdraw your answer at any time using the Cookies link in the footer of every page; withdrawing a purpose deletes the cookies it set.
Strictly necessary (no consent asked, and none needed)
These make the site work and are not used for measurement: your sign-in session (set by our authentication provider, Clerk), and a short-lived cookie that remembers a sign-up you have already started so it survives the trip through the sign-up screen. They carry no advertising identifier.
Analytics (your choice)
If you agree, we load Google Analytics 4 (Google Ireland Limited), which sets the _ga and _ga_* cookies to recognise your browser across pages. We use it to see which pages people use, how many free audits get run, and how many visitors go on to a subscription. The events we record are page views, a completed free audit, and a purchase.
We also send completed purchases to Google Analytics from our own servers, using the Measurement Protocol, when Stripe confirms a payment. This is how a purchase gets counted even if you close the tab on Stripe's payment page. It carries the amount paid, the plan, and the Analytics identifier from the _ga cookie — no name, email or address — and it is only sent for accounts that agreed to analytics.
We link Google Analytics to Google Ads so that these four events can be reported as conversions there. We do not run any Google Ads tag on this site and we do not store Google click identifiers.
Marketing (your choice)
If you agree, we load the Meta pixel (Meta Platforms Ireland Limited), which sets the _fbp cookie to recognise your browser and, if you arrived from a Meta ad, the _fbc cookie recording that click. We use it to tell which ads bring people to Grovik. The events we record are page views, a completed free audit, and a purchase.
We also send completed purchases to Meta from our own servers, using Meta's Conversions API, so a purchase confirmed by Stripe after you have left the site is still counted. These server-side events carry more than the browser ones do, and it is worth being specific about what:
- your email address, name, and any billing city, postal code and country Stripe holds — each hashed (SHA-256) before it leaves us, so Meta receives a scrambled value it can compare against its own records but cannot read back;
- an account identifier of ours;
- the
_fbp/_fbcvalues from your browser, and the IP address and browser user-agent recorded when you signed up; - the amount paid, the plan and the billing period.
We store the _fbp, _fbc, IP address and user-agent on your account record for this purpose, and only if you agreed to marketing. If you did not, none of it is stored and no server-side event is sent.
Where the answer is kept
Your choice is stored in a first-party cookie (grovik_consent) for 12 months, together with the date you gave it, after which we ask again. If you create an account, the same answer is recorded on your account — that is what our servers check before sending any of the events described above, since a payment confirmation arriving weeks later has no cookie to read.
We also keep a record of the choice itself, so we can show what was agreed to and when. Each record holds the date, which purposes were allowed or refused, which version of this wording you were answering, and a random id that links your first answer to any later change — including a withdrawal. It contains no IP address, no name, no email and no account id. Records are kept for 24 months: 12 while the consent is valid, and 12 more so the answer that was in force can still be produced.
7. Cookie declaration
Every cookie this site can set. The strictly necessary ones are set regardless of your choice, because the site does not work without them; the rest are set only after you allow that purpose, and deleted if you withdraw it.
| Cookie | Set by | Purpose | Expires | What it does |
|---|---|---|---|---|
__session | Clerk (our sign-in provider) | Strictly necessary | Session | Keeps you signed in as you move between pages. Deleted when you sign out. |
__client_uat | Clerk (our sign-in provider) | Strictly necessary | 1 year | Records that a sign-in session exists, so pages know whether to show you the dashboard or the sign-in screen. |
grovik_consent | Grovik | Strictly necessary | 12 months | Your answer to this banner — which purposes you allowed, when you answered, and a random id that links that answer to any later change you make. Without it we would have to ask on every page. |
grovik_pending_plan | Grovik | Strictly necessary | 1 hour | Remembers that you started a sign-up, so the trip through the sign-up screen does not lose it. Cleared as soon as the sign-up finishes. |
gsc_oauth | Grovik | Strictly necessary | 10 minutes | A one-time security token used while connecting your Google Search Console account, to verify the reply really came from Google. Only set if you start that connection. |
_ga | Google Analytics | Analytics | 2 years | Tells one browser apart from another so visits can be counted without counting the same person twice. |
_ga_* | Google Analytics | Analytics | 2 years | Keeps the state of your current visit for our specific Analytics property (the suffix is the property id). Works together with the cookie above. |
_fbp | Meta (Facebook) | Marketing | 3 months | Identifies your browser to Meta so we can see which of our ads lead to sign-ups. |
_fbc | Meta (Facebook) | Marketing | 3 months | Records that you arrived here by clicking one of our Meta ads, and which one. Only set if you actually came from such a click. |
Beyond these, no third-party script runs on this site. The fonts are served from our own domain, so no request leaves your browser for a font provider.
8. Data retention
We keep account data for as long as your account is active, plus a reasonable period after closure. Billing records are kept as required by Danish accounting law. After that, data is deleted or anonymized.
9. Your rights
Under GDPR, you have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise these rights, email support@grovik.ai. You can also lodge a complaint with the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk).
10. Security
We use encryption in transit and at rest, access controls, and other reasonable technical measures to protect your data. No method of transmission is 100% secure.
11. Children
The Service is not directed at children under 16, and we do not knowingly collect data from them.
12. AI processing
Grovik uses AI to research keywords and generate content. Your content is not used to train third-party AI models. AI providers process your data under confidentiality and data processing agreements.
13. Changes
We may update this Privacy Policy. Material changes will be notified by email before taking effect.
14. Contact
Holm Marketing Gråsten, Denmark Email: support@grovik.ai