Legal
Privacy
YOUGTM only asks for what it needs to build your growth plan. This page explains exactly what that is.
Last updated July 2026
What we collect
- Account details — your email address and the sign-in method you chose.
- Business profile — the website URL you paste, your description, goals, budget, timeline and any competitors you add.
- Public page content — when you paste a URL we fetch that page's publicly available content to understand your business.
- Workspace activity — which steps you start, ship or skip, the results you log, and notes you write.
- Sidekick conversations — the messages you send to the growth sidekick and its replies.
- Uploads — any report or file you choose to upload for analysis.
- Billing details — if you subscribe, our payment provider handles your card and sends us the subscription status, the last four digits and billing country. We never see or store full card numbers.
What we do with it
Your data is used to generate and continuously re-rank your growth plan, to give the sidekick context about your business, and to keep your workspace available between sessions. We also look at aggregate, non-identifying usage to work out which parts of the product are useful.
We do not sell your data, and we do not use it for advertising.
AI processing of the URLs you submit
When you submit a website address — yours, a competitor's, or one used for a public teardown — we fetch that page's publicly available content and send extracts of it, along with the business details in your profile, to our AI model provider so the consultant can work out what you sell, who you sell to and what to recommend. The same applies to messages and files you send in the chat.
Model providers process this on our instructions to return an answer. We use providers that do not train their models on data sent through our account. Because the output is generated, it can be wrong — treat it as a recommendation, not a fact. Don't paste personal data about other people, card numbers or credentials into the chat.
Where it's stored
Workspaces are stored in a managed Postgres database with row-level security, so each account can only read and write its own rows. Access requires an authenticated session.
Who else processes it
- Our hosting and database provider, which runs the application and stores your workspace.
- Our AI model provider, which generates step briefs, sidekick replies and creative drafts from the context you provide.
- Our web-reading provider, which fetches the public content of URLs you submit.
Each of these processes data only to deliver the feature it powers. We don't send your data to anyone else.
Deleting your data
You can delete your workspace at any time from Settings — that removes your profile, steps, results, notes and sidekick history. If you'd like your account removed entirely, email us and we'll take care of it.
Cookies
We use a small number of first-party cookies and local storage entries to keep you signed in and to remember an in-progress onboarding. There are no advertising or cross-site tracking cookies.
Diagnostics and analytics
When something breaks we log the error, the page it happened on, and the account it affected so we can fix it. We also count aggregate events — how far people get through onboarding, which steps get shipped — to improve the product. There are no third-party advertising or cross-site tracking trackers.
Public teardown pages
Our free teardown pages (yougtm.com/try/…) are generated from publicly reachable content at the domain entered, and the result is cached and publicly viewable at that link so it loads instantly for the next visitor. Don't enter a domain you don't want a public page for. If a page concerns your site and you'd like it removed, email us.
Legal bases for processing
Where UK/EU data protection law applies, we process your data to perform our contract with you (running your workspace), on the basis of legitimate interests (securing the service, fixing faults, understanding aggregate usage), to meet legal obligations, and with your consent where consent is required. You can withdraw consent at any time.
Your rights
- Access — get a copy of the personal data we hold about you.
- Correction — have inaccurate details fixed.
- Deletion — have your account and workspace data erased.
- Portability — receive your workspace data in a machine-readable format.
- Objection and restriction — object to, or ask us to limit, certain processing.
- Complaint — raise a concern with your local data protection authority (in the UK, the ICO).
Email us to exercise any of these; we respond within 30 days.
How long we keep it
Workspace data is kept while your account is active and for up to 30 days after deletion in routine backups, after which it ages out. Error logs are kept for up to 90 days. Aggregate, non-identifying usage counts may be kept indefinitely.
International transfers
Our hosting, database, AI and web-reading providers may process data outside your country, including in the United States. Where that happens we rely on appropriate safeguards such as standard contractual clauses.
Security and breaches
Data is encrypted in transit, access is scoped per account with row-level security, and privileged operations are restricted. No system is perfect — if a breach affects your personal data we'll notify you and the relevant regulator as required by law.
Children
YOUGTM is a business tool and isn't intended for anyone under 16. We don't knowingly collect data from children; if we learn we have, we delete it.
Changes to this policy
We'll update this page as the product changes and revise the date at the top. Material changes will be flagged in the app or by email before they take effect.
Contact
Questions, requests or corrections: hello@yougtm.com.
Postal address: YOUGTM · 447 Broadway, 2nd FL #793, New York, NY 10013, USA.