1. What This Covers
This Privacy Policy explains what data LaunchGuard (“we,” “us”) collects when you use the Service, how we use it, and who we share it with.
2. Data We Collect
- Account data— name and email address, managed via our authentication provider, Clerk. If you sign in with GitHub, we receive an OAuth token scoped to what’s needed to clone your repositories and (only at your explicit request) open pull requests.
- Scan targets and content — the repository URL, website URL, or uploaded archive you submit for scanning, and the source code we clone or extract from it in order to run scanners against it.
- Reports and findings — the output of each scan: scores, findings, AI-generated explanations, and chat messages you send about a report.
- Payment data — handled entirely by Stripe; we do not receive or store your card details, only the resulting transaction record (amount, credits purchased).
- Usage and log data — standard request metadata (IP address, timestamps, endpoints called) for security, rate limiting, and debugging.
3. How We Use It
To operate the Service: to run the scans you request, generate reports and AI explanations, process payments, send you scan-notification emails/webhooks you’ve configured, prevent abuse, and improve the product.
4. Third Parties We Share Data With
We use the following subprocessors, each only for the purpose described:
- Clerk — authentication and account management.
- Stripe — payment processing.
- OpenAI — generates plain-English finding explanations, suggested fixes, and chat responses. Relevant finding/report content is sent to OpenAI’s API for this purpose.
- GitHub — cloning repositories and, at your request, opening fix pull requests, via the OAuth token you grant.
- Vercel — hosting for the web app.
- Railway — hosting for the API and background worker, and the database.
- Cloudflare — storage for uploaded files (R2).
We do not sell your data.
5. Data Retention
We retain scan targets, reports, and findings for as long as your account is active, so you can review scan history and regression trends. To delete your account or data, email us at cole@launchguardian.net; we’ll process the request within 30 days.
6. Security
We use industry-standard measures to protect your data in transit and at rest, including HTTPS, encrypted database connections, and scoped access tokens. No system is perfectly secure, and we can’t guarantee absolute security.
7. Your Rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data. Contact us at cole@launchguardian.net to make a request.
8. Children’s Privacy
The Service is not directed at anyone under 16, and we don’t knowingly collect data from them.
9. Changes to This Policy
We’ll post updates here with a new “Last updated” date.
10. Contact
Questions about this policy? Contact us at cole@launchguardian.net.