Privacy Policy
Effective October 7, 2026
Groa (groa.im, "Groa", "we") takes your personal information seriously. This policy explains what we process, why, and when we delete it.
1. Information we process
Groa processes only the information it needs to run the service. Here is exactly what we store.
| Category | Items |
|---|---|
| Your account | Email address or user ID, password (stored only as a one-way bcrypt hash), sign-up time, admin flag |
| Connected Naver accounts | Naver ID, password and login session cookies (stored encrypted), profile nickname, the label you give the account, connection status, whether the account is identity-verified, last login time |
| Connected Tistory accounts | Account ID, password and login session data (stored encrypted) |
| Writing and publishing data | Schedule settings (account, cafe or board, keywords, interval), generated titles, bodies and images, images you upload, published post URLs and results |
| Activity records | Logs of automated actions such as neighbor management and comments (target blog and post identifiers, result, time), and blog performance metrics such as views |
| API usage | API keys (we keep only a hash and a short identifying prefix, never the key itself), posts created through the API, request processing records |
| Access logs | IP address, time, request method and path, response code (query strings such as search terms are not logged) |
Sign-up asks only for an email address (or a user ID) and a password. We do not collect names, phone numbers or national ID numbers.
2. Why we use it
- To identify you and keep you signed in
- To draft, schedule and publish posts and manage neighbors and cafes on the Naver and Tistory accounts you connect
- To show you publishing results and performance
- To authenticate API keys, apply rate limits and prevent duplicate posts
- To investigate errors, prevent abuse and respond to security incidents
We never use personal information for advertising and never sell it.
3. How Naver account credentials are stored
- Passwords and login session cookies of connected Naver accounts are encrypted on our server with symmetric encryption (Fernet) and are never returned in the app or in any API response.
- They are decrypted only to carry out an action you asked for on Naver, such as signing in, publishing a post, listing cafes or managing neighbors.
- When you remove a connected account, its password, session cookies and scheduled jobs are deleted with it.
4. Data sent to AI providers
Drafting, review and image features send data to these AI providers.
| Provider | Data sent | Purpose |
|---|---|---|
| OpenAI (GPT models) | Keywords, topics and reference material, draft titles and bodies, posts under review, and captcha images shown during Naver sign-in | Drafting, quality review, captcha recognition |
| xAI (Grok) | Image descriptions, topic search terms | In-post image generation, research on current topics |
We never send your email address, your Groa password, or Naver passwords and session cookies to AI providers. Posts submitted through the API are published as written and are not rewritten by AI.
Only when you turn on the related feature, search terms are also sent to the YouTube Data API (video search) and the Coupang Partners API (product links). This website loads its web font from the jsDelivr CDN.
5. Retention and deletion
- Account and service data: kept until you close your account. Closing it deletes connected accounts, scheduled jobs, publishing history, images, API keys and activity records along with it.
- Removing a connected account: its password, session cookies and scheduled jobs are deleted immediately. Records of posts already published (title, body, URL and which ID published them) stay in your history until you close your account. We will delete them on request.
- Access logs: server logs rotate by size, so the oldest entries are removed automatically.
- Sign-in: sign-in tokens live in your browser. Access tokens expire after 60 minutes and refresh tokens after 14 days. Changing your password invalidates every token issued before.
If a law requires us to keep certain records, we keep them separately and only for the required period.
6. Sharing
We do not sell or give your personal information to third parties. The AI calls in section 4 and the Naver or Tistory publishing you instruct happen only as far as needed to provide the service. Requests made under applicable law are the only exception.
7. Your rights and deletion requests
- You can delete connected Naver and Tistory accounts, scheduled jobs, uploaded images and API keys yourself in the app.
- To access, correct or delete your data, stop processing, or close your account, email admin@groa.im from the address you signed up with. We verify the request and handle it without delay, within 10 days at the latest.
8. Security
- All traffic is encrypted with HTTPS.
- Groa passwords are stored as bcrypt hashes; connected account passwords and sessions are stored encrypted; API keys are stored only as hashes.
- Sign-in and API calls are rate-limited to block brute-force attempts.
- The database is not reachable from the internet.
9. Cookies and browser storage
Groa uses no advertising or analytics cookies and no third-party tracking scripts. To keep you signed in, a sign-in token is kept in your browser's local storage and is removed when you log out.
10. Children
Groa is not intended for children under 14 and does not accept sign-ups from them.
11. Contact
For privacy questions, complaints or requests, contact our privacy officer at admin@groa.im.
12. Changes to this policy
We post changes on this page at least 7 days before they take effect, or 30 days before for changes that materially affect your rights.
Effective date: October 7, 2026