Test environment
AutoGrow

AutoGrow Privacy Notice

Last updated: 2026-09-16 Version: 2.0.2

This Privacy Notice explains how CipherPlay, Inc. ("CipherPlay", "we", "us", "our") collects, uses, shares and protects personal data in connection with AutoGrow: the desktop application (the "App"), the website at useautogrow.com and its web workspace (the "Site"), the research service, and related support (together, the "Services"). It supplements the AutoGrow Terms of Service at useautogrow.com/tos, and terms defined there mean the same here.

AutoGrow is not offered to people or organizations in the European Economic Area, the United Kingdom or Switzerland, and we block sign-up and purchase from those countries.

It covers two groups of people: customers (people who use AutoGrow), and people who are not customers whose professional information passes through the Services, for example because a customer viewed their LinkedIn profile or ordered research that includes them.

At a glance


1. Who We Are

CipherPlay, Inc. is a Delaware corporation with its principal office at 1717 East Cary Street, Richmond, VA 23223, USA. It operates AutoGrow.

Our roles.

2. Information We Collect About Customers

Account information. Your email address, name if you give it, plan, subscription status, sign-in and session records (including the device name your computer reports, such as its hostname), and records of your acceptance of our Terms and your Share & Unlock choice. Those records include the date and time, the version in force, your IP address, user agent and app version.

Billing information. Plan, billing period, payment status, and purchase and credit history. Stripe processes card payments; we do not receive or store full card numbers. To prevent trial abuse, we store a one-way hash of the card fingerprint Stripe provides.

Your workspace (cloud sync). The App syncs your local database and configuration to your account: your persona, target-audience profiles, message templates, goals, settings, uploaded documents, lists, campaigns, drafts, and the records the App keeps about people (see Section 3).

Usage and device data. App version and platform; feature, automation and workflow events (what ran, when, how long, and whether it succeeded); errors, retries and deviations; AI usage metrics (model, token counts and cost, but not prompt content); status heartbeats such as whether the browser is running and which step is active; and IP addresses in some server records, such as feedback tickets.

Website analytics. On the Site we record page views and interactions with named controls (for example, which button was clicked, never what you typed), broad acquisition-source categories, entry-page categories, and bounded public campaign labels from tagged links (source, medium, campaign name, campaign ID and link placement). We also record confirmed account milestones such as verified signup, research submission and delivery, and payment success or failure. These records are linked to your account if you are signed in and to a random device identifier. Campaign labels may be retained with the account to understand subsequent outcomes. Your account email and plan identify your profile in our private, self-hosted OpenPanel analytics. Research contents, form values, full referrer URLs, full query strings and search-keyword parameters are not sent. We do not send IP addresses to it, and we do not use third-party advertising or tracking cookies. See Section 10.

Communications and support. Emails and messages you send us, feedback and bug reports (with IP address, user agent and app version), and records of support sessions. A bug report may include recent logs, the current assistant chat, recent actions and results, profile data scraped during the session, a screenshot of the automated browser, and app state. Secrets such as cookies and tokens are redacted. Bug reports are designed to exclude private message bodies, and screenshots are omitted when the session handled private conversations. You can limit bug reports to a short summary in Config.

Voice input. If you use the microphone, your recording is sent to an AI provider to be transcribed. The text appears in your input box for you to review before sending.

Live view during support. When our staff start a support view, the App streams images of its automated browser window to our servers for that session. The App shows a banner while this is happening. Frames are relayed to the viewer and held in memory only; they are not saved to a database. Pending approval cards and drafts in your App may also be visible to support staff.

Referrals and invitations. If you use a referral link, we record the referral, and a short hash of the visitor's IP address and user agent for click counting. If you share a research brief or invite someone, we store the email addresses you enter. If someone requests a sign-in link without an account, we keep that email so we can follow up about AutoGrow.

Your LinkedIn session. The login session the App creates with LinkedIn, including its cookies, is stored only on your device, encrypted at rest, and is never sent to our servers.

3. Information About People Who Are Not Customers

In customers' workspaces. When a customer uses the App, it can record professional information about other people: names, profile URLs, headlines, job titles, employers, locations, public profile contents, public posts and notifications, AI-generated notes and fit scores, and the customer's interactions with them. It also stores any contact lists or CRM exports the customer imports. We hold this as the customer's processor.

In the Community Profile Pool. If a customer has chosen Share & Unlock, copies of the public professional profiles their App scans are added to the Pool. We control the Pool. See Section 7.

In research deliverables. Our research service collects business information about people and companies from public sources and licensed data providers: names, job titles, employers, business locations, LinkedIn and other public profile URLs, business email addresses and phone numbers (with how each was verified), public web and news mentions, and supporting evidence and source links. See Section 8.

Private messages. Private LinkedIn message bodies from other people are handled only as described in Section 6. They never reach our servers.

4. How We Use Information

We use personal data to:

Automated scoring. AutoGrow scores how well people match a customer's target audience to help the customer prioritize outreach. These scores do not produce legal or similarly significant effects, and we prohibit using AutoGrow for decisions about employment, credit, insurance, housing or education.

5. Legal Bases (GDPR, UK GDPR and Swiss Law)

We do not offer the Services in the EEA, the UK or Switzerland. Those laws can still apply to our processing, for example when a person in those countries has a professional profile in the Community Profile Pool or appears in research. Where they apply, we rely on:

6. AI Providers and Inbox Features

AI providers. To draft, summarize, score, transcribe, research and analyze, the App and our servers send the relevant content to AI models through OpenRouter, which routes requests to model providers such as Anthropic and Google. That content may include personal data, such as a profile the App is reading or a message you are drafting. Providers process it to return a result, under their own terms and privacy practices.

One-time inbox analysis. If you click the inbox Quick Start or expressly ask the assistant to analyze your unread inbox, the App may retrieve unread messages and enough conversation history to judge relevance, spot likely spam or unwanted pitches, understand the relationship, and recommend or draft a reply. That manual request authorizes one pass. Ongoing background analysis and unattended replies require a separate saved inbox policy.

Where private message bodies go. Incoming and historical private message bodies are held transiently on your device. For the AI task you requested, your device sends them directly to the configured third-party AI model provider. They are not routed through AutoGrow's servers. They are not written to the local database, cloud sync, logs, telemetry, audit records or diagnostic bug reports, and the App discards its transient copy when the task ends.

What our servers receive. To enforce your policy, avoid duplicates, coordinate multiple devices, schedule work, and prevent duplicate or ambiguous replies, our servers receive opaque conversation and message identifiers plus derived metadata, such as categories, risk flags, action state, timestamps, limits, counts and outcomes. Derived classifications, inbox state and generated outbound drafts may be retained and synced. A draft is text proposed for you to send, not a stored copy of the sender's message.

Read receipts. Receipt-safe analysis does not intentionally open an unread conversation. If you or the App opens one in LinkedIn's interface, LinkedIn may mark it read and notify the sender. Analyzing, locally ignoring or displaying a triage result does not authorize opening it.

Writing style. The App may keep a non-verbatim description of your writing style, derived from writing you authored: public posts, uploaded files, and your own messages when processed during a task you requested. Other people's messages may be used only as transient context and are never a source of your writing style. There is no separate setting for learning your style from messages. A manual task is explicit each time, and ongoing inbox processing is governed by your inbox policy.

Unattended replies. Unattended replies are off by default. Turning them on requires an explicit, versioned, time-limited inbox policy that sets eligible audiences and categories, confidence thresholds, active hours, review sampling, and daily and per-run limits. That policy may narrow, but never exceed, the active Operating Brief's limit on published text. Full Auto mode, campaign auto-send or campaign membership does not authorize inbox replies. Within a confirmed policy, eligible replies may be sent without per-message review; high-risk, incomplete or ambiguous cases require review. Pause or Off stops further unattended replies immediately. An ambiguous send is never retried automatically.

7. Share & Unlock and the Community Profile Pool

What the Pool is. A shared store of professional-profile information that CipherPlay operates, holding one record per person, so the same public profile does not need to be re-collected for every customer.

How data gets in. Only from customers who chose Share & Unlock. When their App scans a public LinkedIn profile while working for them, a copy is sent to the Pool. The App never scans anyone just to fill the Pool. Customers who choose Keep private, or who have not answered, contribute nothing, and our servers refuse contributions from them.

What a record contains. Name, profile URL, headline, location, current company and school, profile photo link, pronouns, follower and connection counts, "open to" status, the About section, and the experience, education, skills, certifications and other sections of the public profile. It does not include private messages. Some fields, such as connection degree and mutual connections, describe the relationship to the customer whose App captured it.

Contributor records. For each contribution, we record which customer account contributed it, when, and what changed. We use this to maintain data quality, investigate problems, and answer privacy and deletion requests. We do not show other customers who contributed or viewed a record. When a contributor deletes their account, the link to that account is removed and the contributed profile data remains in the Pool.

Who can access the Pool. Our authorized staff, to operate and improve the Services. We are rolling out Pool Access for customers who choose Share & Unlock, which lets them use Pool records inside AutoGrow. Pool records are not sold for money, published, or offered to anyone outside AutoGrow.

Changing your choice. You can switch between Share & Unlock and Keep private at any time in Config. Keep private stops future contributions and ends Pool Access. It does not remove earlier contributions; to request removal of a record about a person, see Section 15.

Notice of Financial Incentive. Share & Unlock is a value-for-data program that US state laws, including the California Consumer Privacy Act, may treat as a financial incentive:

8. Research Services

Sources. Publicly available websites, search engines, public registries and filings, news, professional profiles, and data licensed from third-party providers, including email- and phone-verification services. Research is performed by our automated researchers with AI assistance, and may be performed by contractors acting for us.

Who receives it. The customer who ordered the research, the people that customer shares the brief with, and our staff. Once delivered, the customer is responsible for how they use it.

Limits. We do not collect sensitive data for research. Research is not a consumer report and may not be used for employment, credit, insurance, housing or education decisions.

9. How We Disclose Information

We disclose personal data only as follows:

Sale and sharing. We do not sell customers' own personal information for money, and we do not "share" it for cross-context behavioral advertising. Making Pool records available to participating customers in exchange for their contributions may be considered a "sale" of those individuals' information under some US state laws. Anyone may opt out as described in Section 15.

10. Cookies and Similar Technologies

The Site uses:

Stripe sets its own cookies on its checkout pages. Our homepage displays badges hosted by startup directories, which receive your IP address and browser information when the images load.

We do not use advertising cookies. You can block or delete cookies in your browser; signing in requires the session cookie. We do not respond to Do Not Track signals. Because we do not sell or share website data for advertising, Global Privacy Control signals have no additional effect on the Site.

11. International Transfers

CipherPlay is based in the United States. Our servers are hosted in Germany, and some service providers, including AI providers, process data in the United States and other countries. Where the law requires a transfer safeguard for personal data leaving the EEA, UK or Switzerland, we use the European Commission's Standard Contractual Clauses, with the UK Addendum and Swiss amendments where applicable, or another lawful mechanism. You may request more information about these safeguards.

12. Retention

We keep personal data only as long as needed for the purposes in this Notice:

We may keep data longer if the law requires it or to resolve disputes and enforce our agreements.

13. Security

We protect personal data with administrative, technical and physical safeguards, including:

Workspace data synced to our servers is not end-to-end encrypted. No system is perfectly secure. If a breach affects your personal data, we will notify you and the authorities as the law requires.

14. Your Rights

Depending on where you live, you may have the right to:

How to exercise them. Email contact@cipherplay.net from your account email, with the subject "Privacy Request". Many settings, including Share & Unlock, background profile building, requested collection and diagnostic sharing, can be changed directly in Config, and you can delete your account there or on your account page. We may need to verify your identity before acting. An authorized agent may make a request for you with your signed permission. We respond within one month (GDPR/UK GDPR) or 45 days (US state laws), and may extend these periods as the law permits, telling you why.

Appeals. If we decline your request, you can appeal by replying with the subject "Privacy Appeal". We will respond within the time the law requires. If you are unsatisfied, you may contact your state attorney general.

Data in a customer's workspace. If your information is in a customer's workspace, that customer controls it. We will direct your request to them or help them respond.

15. If You Are Not a Customer

If you believe AutoGrow holds your information, for example in the Community Profile Pool or in research, you can ask us to:

Email contact@cipherplay.net with the subject "Privacy Request" and include your LinkedIn profile URL or other details that help us find your record. When we erase a person from the Pool, we also delete the contributor records about them and permanently block their profile from being re-added. Copies already delivered to customers, or held in customers' own workspaces, are controlled by those customers; we will tell you how to reach them where we can.

16. US State Privacy Disclosures

In the last 12 months we collected these categories of personal information, from the sources and for the purposes described above:

We disclose these categories for business purposes to the service providers in Section 9. As explained in Section 9, making professional information available to Share & Unlock members may be considered a "sale" of identifiers and professional information. We have no actual knowledge of selling or sharing personal information of people under 16.

17. Children

The Services are for adults using them professionally. They are not directed to children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact us and we will delete it.

18. Changes to This Notice

We may update this Notice. When we make a material change, including to how Pool data is used or shared, we will update the version and date above and tell you in the Services or by email before the change takes effect. Where the law requires, we will ask for your consent.

19. Contact