Policy

Privacy Policy

Last updated · 5 July 2026

This policy explains what LaunchLock collects, why, and how it is handled. The short version: we collect what is needed to run scans, deliver reports, operate monitoring, and bill subscriptions — and we do not sell your data.

On this page

01What we collect

We collect and store the following categories of data:

  • Account data: email address and authentication identifiers, managed through Supabase Auth.
  • Scan data: target URLs you submit, scan events, findings, evidence excerpts, coverage metadata, generated reports, and fix prompts.
  • Monitoring and threat data: uptime check results, incident history, and, when you install the telemetry snippet, request metadata used for threat classification. IP addresses in threat events are hashed when provided.
  • Billing data: subscription plan, Stripe customer and subscription identifiers, and invoice status. Card details are processed and stored by Stripe, never by LaunchLock.
  • Technical data: standard server logs (IP address, user agent, timestamps) used for security, rate limiting, and abuse prevention.

02How we use it

We use this data to run scans you request, generate and store reports, operate monitoring and alerting, enforce plan limits and abuse controls, process payments, provide support, and improve scanner accuracy. We do not sell personal data and we do not use your scan results for advertising.

03Secrets found during scans

When scanners detect exposed credentials or API keys, reports describe the type and location of the exposure. Where the source platform supports redaction (for example GitHub secret scanning), we request redacted values and do not intentionally persist full secret literals.

04Third-party processors

We rely on a small set of processors to run the service:

  • Stripe — payment processing and billing portal.
  • Supabase — authentication and account identity.
  • Vercel — frontend hosting.
  • Infrastructure providers for our scanning and database servers.
  • Optional external scanner services (for example SSL Labs or urlscan.io) receive the target URL only when those integrations are explicitly enabled for a scan.

05Retention

Scan reports and account data are retained while your account is active so you can review history and trends. You can request deletion of your account and associated scan data at any time by contacting us; we delete or anonymize the data within 30 days except where retention is required for legal or security reasons.

06Security

API key secrets are stored hashed and shown only once at creation. Provider credentials you save are encrypted at rest. Access to production systems is restricted and audited. No system is perfectly secure, so we also minimize what we store in the first place.

07Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Contact us to exercise these rights and we will respond within the timelines required by applicable law (including GDPR and similar regulations).

08Changes and contact

We will announce material changes to this policy on the site or by email before they take effect.

Privacy questions and requests: support@launchlock.dev.