Privacy, as the product is actually built
The shortest honest description is this: your computer does the work it can do, GrowLeafy collects what it needs to prove identity and entitlement, and your private business data is not part of that by default.
Local processing comes first
Deterministic work happens on the customer's computer. Files are read, transformed and written locally by the engine running on your machine, and that work does not need to leave the device to be done correctly.
Sending a document across a network is a decision, not a default. Where a task can be completed locally, the local path is the one that runs.
Minimum collection
GrowLeafy collects what it needs to operate the service: the identity that signs you in, the entitlement records that prove what your account owns, the device registrations that let you revoke a machine, and the payment records that prove a payment happened.
Identity and entitlement are the load-bearing ones. The rest exists so that questions about your account can be answered from records instead of guesses.
Cloud controls, and when remote reasoning is used
Some work cannot be done locally: it needs a large model running on servers rather than on your desktop. When a task takes that path, it is governed by cloud controls on your account - what may be sent, for which purpose, under your entitlement and under the policy in force for that device.
Remote reasoning is therefore a bounded, controlled path for the tasks that genuinely need it, not a background habit. If a task does not need the cloud, the cloud is not involved.
Enterprise isolation
Enterprise deployments are separated from ordinary consumer use. An organisation's data, identities and entitlements are kept within that organisation's scope, so one customer's work is not mixed into another's.
Enterprise arrangements are handled by agreement, and the specific terms are set out in that agreement rather than on this page.
The experience-sharing control
Experience sharing is opt-in only. Nothing is contributed unless you turn it on, and you can turn it off again at any time - it is revocable, not a decision you make once and regret later.
What leaves your machine under that control is a sanitised, generalised signature of an experience: the shape of a task and its outcome, stripped of specifics. It is never a file, never a path, never a name and never your business content.
You can see everything you have contributed, export it, and delete it. A control you cannot inspect is not a control, so contribution is visible and removable by the person who contributed it.
Retention
Records are kept for as long as they are needed for the purpose they exist for. Entitlement, payment and audit records are kept while your account exists, because they are the evidence that answers "what does this account own" and "what happened to this order" - deleting them would make those questions unanswerable.
A detailed retention schedule with fixed periods is not published on this page. If you need the retention position for a specific record before you rely on it, ask GrowLeafy support rather than assuming a period.
The customer data boundary
The boundary is the part of this page that matters most, so it is stated on its own.
How identity, entitlement and device trust are built is described on the security page. What you may rely on from GrowLeafy, and what you may not, is in the service terms.