Last updated 3 August 2026
Thrivine schedules social posts. To do that it holds your account details, the posts you write, and permission to publish to the channels you connect. This page says exactly what that means.
Thrivine is made by Growvine, based in Dhaka, Bangladesh. If you want to ask about anything here, write to hello@growvine.tech and a person will answer.
Your account. Your name, email address, and a hash of your password. We never store the password itself, and cannot read it.
Your work. The posts you write, when they are scheduled, the images and videos you upload, your workspace settings, and who else is in your workspace.
Your connected channels. When you connect a Facebook Page, Instagram account or LinkedIn profile, we store the access token that network gives us, along with the account’s name, handle and follower count. Tokens are encrypted before they touch our database and are never sent to your browser.
Results. After a post publishes we read back its impressions, likes, comments and shares so the analytics page has something in it.
Sessions. When you sign in we record the browser and IP address, so you can tell your own sessions apart from someone else’s.
We use it to run the product: to publish what you scheduled, to show you what happened, and to keep your account secure. That is the whole list.
We do not sell it. We do not use your posts or your audience to train anything. We do not advertise to you or let anyone else advertise to you through us.
The networks you connect. When you publish, the post and its media go to Facebook, Instagram or LinkedIn — that is the point. Their own privacy policies apply once it arrives.
Our infrastructure. Your data sits on servers we rent, in a Postgres database and an object storage bucket. Email — password resets and workspace invitations — is sent through Resend.
Nobody else. We have no analytics trackers, no advertising pixels, and no third-party scripts on the signed-in part of the product.
Files are stored so the networks can fetch them when a post goes out — Instagram in particular will not accept an upload, it fetches the URL itself. That means an uploaded file sits at an address that is not guessable but is not password-protected either. Do not upload anything you would not be willing to publish.
Location data and other metadata in photos is stripped when the file is processed, before it is stored.
For as long as your account is open. Delete a post and it goes straight away; disconnect a channel and its token is destroyed with it. Close your account and everything goes — see below.
Database backups are kept for fourteen days, so deleted data can persist in a backup for up to that long before it ages out.
Close your account. Settings → Account → Close account. It asks for your password, then removes your account, your workspaces, your posts, your uploads and your connected channels. It cannot be undone.
Disconnect a channel. Channels → Disconnect. The stored token is destroyed immediately.
Through Facebook. If you connected through Facebook you can ask for deletion from Facebook’s own settings — Settings & Privacy → Apps and Websites → Thrivine → Remove. We act on that request as soon as it reaches us and give you a page you can check to confirm what was removed.
If any of that does not work, email hello@growvine.tech and we will do it by hand.
Passwords are hashed with argon2id. Access tokens for your social accounts are encrypted with AES-256-GCM before storage. Sessions use short-lived tokens that rotate, and a token that is reused after rotation ends every session on that account — the usual sign that one has been copied.
None of this makes a breach impossible. If one happens and it affects you, we will tell you what we know, when we know it.
Thrivine is a tool for businesses and is not intended for anyone under 16.
If this page changes in a way that affects what we do with your data, we will email you before it takes effect rather than quietly updating the date at the top.