Privacy Policy
Effective July 19, 2026 · GrowthOS by LaunchLift (operating name; a legal entity will be designated as the service formalizes) · Contact: admin@launchlift.app
1. What we collect
Account data (via Supabase Auth): your email address and password (stored hashed by Supabase — we never see it), or your Google account email and profile name if you sign in with Google, plus account creation and login timestamps.
Campaign data you provide: business goals, product names and descriptions, target metrics, channel selections, and any edits you make to generated plans and todos.
AI-generated data: campaign plans, channel research results, todo lists, copy drafts, generated images, and agent-run metadata (which model ran, token counts, web-search request counts) tied to your account.
Anonymous tool inputs: the free tools on our site (the homepage preview and the Subreddit Finder) work without an account. The product description and goal you type there are sent to our AI providers to generate your result, and are not saved to a profile — there is no account to attach them to.
IP addresses: we record client IP addresses to enforce daily rate limits on the free tools and on password-reset emails. These are stored as daily counters and serve no other purpose.
Page analytics: we use Vercel Web Analytics (Vercel is already a listed subprocessor) to count page visits and referrers. It is cookieless and does not track you across sites. We run no advertising trackers.
We do not collect payment card data. If paid plans go live, billing will be handled by a PCI-compliant payment processor and this policy will be updated first.
2. How we use it
- To generate and store your campaigns, plans, todos, drafts, and images.
- To operate authentication and access control — database row-level security ensures only your authenticated account can read or write your campaigns.
- To show you your own AI usage on the Activity page, and to enforce fair daily usage caps.
- To improve prompt quality and honesty guardrails. Our evaluations run on fixed test fixtures — not on your private campaign content.
3. Who processes it (subprocessors)
Your inputs are sent to the following providers strictly to deliver the service:
- Cloudflare (Workers AI) — runs most of our AI generation (campaign plans, copy drafts, tool suggestions) and image generation. Receives your campaign inputs and generation prompts.
- Anthropic (Claude API) — runs channel research and launch-timing recommendations, including live web search. Receives your campaign goal, product description, and related prompts.
- Supabase — authentication, Postgres database, and file storage. Holds account credentials and all campaign data.
- Resend — delivers our authentication emails (signup confirmation, password reset). Receives your email address.
- Serper and Firecrawl — power our self-hosted channel research when enabled: Serper receives search queries derived from your campaign goal and audience; Firecrawl fetches the public pages those searches surface. Neither receives your account details.
- Vercel — application hosting. Processes standard request data (IP address, request logs) as part of serving the app.
We don't sell your data and don't share it with advertisers. We'll update this list before adding a new subprocessor.
4. Storage, retention & deletion
- Campaign data is retained for as long as your account is active.
- Generated images are served from a public-URL bucket— anyone who has an image's exact link can view it while it exists. Discarding a todo's image output deletes the image, and deleting a campaign deletes all of its images.
- Deleting a campaign removes its goals, channels, plans, todos, and generated images (cascading delete), subject to provider backups that age out on standard rotation.
- You can delete your account any time from Settings → Delete account — this removes your campaigns, generated images, and login. Prefer email? Write admin@launchlift.app and we'll do it for you.
- Rate-limit counters (including IPs) are keyed by day and automatically purged after 7 days.
5. Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. Contact admin@launchlift.app to exercise these rights; we respond within the timeframe applicable law requires.
6. Security
- Access to campaigns is enforced by database-level row-level security — only your authenticated user can read or write your data.
- Credentials are never stored in plaintext (handled by Supabase Auth).
- No system is 100% secure; we can't guarantee absolute security of data transmitted to the service.
7. Children's privacy
GrowthOS is not directed at children under 16, and we don't knowingly collect their data.
8. International transfers
Our subprocessors may process data in the United States or other countries. By using GrowthOS you consent to this transfer, subject to the safeguards those providers maintain.
9. Changes
We'll update this policy as the product evolves — for example when payment processing or product-email notifications go live. Material changes get a new effective date at the top of this page.
See also: Privacy Policy · Terms of Service · Pricing