Privacy Policy

Effective October 7, 2026

Groa (groa.im, "Groa", "we") takes your personal information seriously. This policy explains what we process, why, and when we delete it.

1. Information we process

Groa processes only the information it needs to run the service. Here is exactly what we store.

CategoryItems
Your accountEmail address or user ID, password (stored only as a one-way bcrypt hash), sign-up time, admin flag
Connected Naver accountsNaver ID, password and login session cookies (stored encrypted), profile nickname, the label you give the account, connection status, whether the account is identity-verified, last login time
Connected Tistory accountsAccount ID, password and login session data (stored encrypted)
Writing and publishing dataSchedule settings (account, cafe or board, keywords, interval), generated titles, bodies and images, images you upload, published post URLs and results
Activity recordsLogs of automated actions such as neighbor management and comments (target blog and post identifiers, result, time), and blog performance metrics such as views
API usageAPI keys (we keep only a hash and a short identifying prefix, never the key itself), posts created through the API, request processing records
Access logsIP address, time, request method and path, response code (query strings such as search terms are not logged)

Sign-up asks only for an email address (or a user ID) and a password. We do not collect names, phone numbers or national ID numbers.

2. Why we use it

We never use personal information for advertising and never sell it.

3. How Naver account credentials are stored

4. Data sent to AI providers

Drafting, review and image features send data to these AI providers.

ProviderData sentPurpose
OpenAI (GPT models)Keywords, topics and reference material, draft titles and bodies, posts under review, and captcha images shown during Naver sign-inDrafting, quality review, captcha recognition
xAI (Grok)Image descriptions, topic search termsIn-post image generation, research on current topics

We never send your email address, your Groa password, or Naver passwords and session cookies to AI providers. Posts submitted through the API are published as written and are not rewritten by AI.

Only when you turn on the related feature, search terms are also sent to the YouTube Data API (video search) and the Coupang Partners API (product links). This website loads its web font from the jsDelivr CDN.

5. Retention and deletion

If a law requires us to keep certain records, we keep them separately and only for the required period.

6. Sharing

We do not sell or give your personal information to third parties. The AI calls in section 4 and the Naver or Tistory publishing you instruct happen only as far as needed to provide the service. Requests made under applicable law are the only exception.

7. Your rights and deletion requests

8. Security

9. Cookies and browser storage

Groa uses no advertising or analytics cookies and no third-party tracking scripts. To keep you signed in, a sign-in token is kept in your browser's local storage and is removed when you log out.

10. Children

Groa is not intended for children under 14 and does not accept sign-ups from them.

11. Contact

For privacy questions, complaints or requests, contact our privacy officer at admin@groa.im.

12. Changes to this policy

We post changes on this page at least 7 days before they take effect, or 30 days before for changes that materially affect your rights.

Effective date: October 7, 2026

Read the Terms of Service