LaunchEngine Privacy Policy
Last updated: 28 August 2026
LaunchEngine is a trading name of PowLeads Ltd (company no. 11932107), registered in England and Wales at Axis Building, 142, 9 Whitworth Street West, Manchester, England, M1 5JD.
This policy explains what personal data LaunchEngine collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It covers https://launchengine.app, the LaunchEngine web app, the LaunchEngine Posting Companion browser extension, and the free launch-map tool. It is written to satisfy the UK GDPR, the EU GDPR, the Data Protection Act 2018, and PECR.
1. Who we are
LaunchEngine is a trading name of PowLeads Ltd, a company registered in England and Wales under number 11932107, with its registered office at Axis Building, 142, 9 Whitworth Street West, Manchester, England, M1 5JD. PowLeads Ltd is the data controller for the personal data described in this policy, except where section 3 says we act as a processor on your behalf.
Data protection contact: [email protected]. We are not required to appoint a Data Protection Officer, and we have not appointed one; that address reaches the person accountable for data protection.
2. What we collect and why
| Data | Why we have it | Lawful basis |
|---|---|---|
| Account details — name, email address, and (if you sign in with Google or GitHub) the profile identifier that provider returns | Creating and securing your account, signing you in, sending service notices | Performance of our contract with you |
| Launch inputs — your product URL, repository URL, description, the story of why you built it, brand and copy context you enter | Generating your launch map, directory list, posts, comments and video scripts | Performance of our contract with you |
| Generated content — drafts, scheduled posts, comments, images, voiceovers and videos the engine produces for you | Delivering the service, letting you review and approve before anything is published | Performance of our contract with you |
| Connected-platform data — the handles and account identifiers of social accounts you connect, plus the results of posts made on your behalf | Publishing where you ask us to, reporting what was posted and what failed | Performance of our contract with you |
| Browser-extension activity — see section 4 | Posting and commenting through your own browser session | Your consent, given when you install and enable the extension |
| Billing data — plan, subscription status, invoices, and the last four digits and expiry of your card | Taking payment and meeting UK accounting and tax obligations | Contract, and legal obligation for records we must keep |
| Technical and usage data — IP address, browser and device type, pages viewed, feature usage, error reports, server logs | Keeping the service up, diagnosing faults, preventing abuse and fraud | Our legitimate interest in a secure, working product |
| Analytics and advertising data — PostHog product analytics and the Meta advertising pixel | Understanding which parts of the product are used, and measuring our advertising | Your consent, given through the cookie banner. Nothing in this row loads before you accept. |
| Support correspondence — emails and in-app messages you send us | Answering you, and keeping a record of what was asked | Our legitimate interest in supporting customers |
We do not ask for, and do not want, special-category data (health, political opinions, religious beliefs, biometrics, sexual orientation) or criminal-offence data. Please do not put it into launch inputs or chat.
3. When we are a processor for you
Two features make you the controller and us the processor, because the personal data involved is other people’s, and you decide what happens to it:
- The waitlist widget. If you embed the LaunchEngine waitlist on your own site, the email addresses your visitors submit are yours. We store and display them to you, and do nothing else with them.
- Directory submissions. When you ask the engine to submit your product to a third-party directory, we send the details you supplied — which may include your name and email — to that directory on your instruction.
In both cases you are responsible for having a lawful basis for that data and for telling those people what you are doing with it. Article 28 terms are available as a signed Data Processing Agreement on request — email [email protected].
4. The Posting Companion browser extension
The LaunchEngine Posting Companion is an optional Chrome extension. It exists so that posts and comments go out through your own logged-in browser session, the way you would post them by hand. This is deliberate: the alternative is handing us your platform passwords, and we do not want them.
What it can technically do
The extension declares broad host access (<all_urls>) because Chrome requires it in order to open and drive a tab on the sites you choose. Its content scripts — the code that actually reads or types on a page automatically — are restricted by the extension manifest to four domains: reddit.com, linkedin.com, facebook.com and instagram.com. The one exception is directory form-filling, described below, which runs only on a directory page you queued and only when you ask for it.
What it actually sends us
- The text of the post or comment you approved, so we can confirm it was published.
- The resulting post URL, and success or failure with an error reason.
- The account handle it posted as, so drafts are attributed correctly.
- Where a target thread or subreddit is part of your plan, the public URL and title of that thread.
Directory submissions
Separately from the four social domains, the extension can open a directory’s own submission page — any web address, because every directory is a different site — and fill that form with the product details from your profile. It only ever opens a directory you queued in LaunchEngine, it fills the form rather than reading the page for us, and what it sends back is which fields it could and could not map, so the filler learns that directory. It does this on no other kind of page.
What it never does
- It does not read, collect or transmit your passwords, session cookies or authentication tokens.
- It does not read your private messages, DMs, notifications or email.
- It does not publish anything you have not approved in the LaunchEngine app.
- It does not sell, rent or transfer any of this data to anyone, and it is never used for advertising.
This use complies with the Chrome Web Store Limited Use requirements: data the extension handles is used only to provide the posting feature you asked for. You can disable or remove the extension at any time from chrome://extensions; removing it stops all of the above immediately.
5. AI generation, and what we do not do with your content
- We do not train models on your content. We build no models of our own and we do not contribute your data to anyone else’s training set.
- We only use AI providers on no-training terms. Your launch inputs and drafts are sent to the vendors listed in section 7 under their commercial API terms, which exclude the use of API content for model training. We do not route your content through free or community model tiers that reserve the right to train on prompts.
- A human — you — approves before publication. The engine drafts; nothing reaches a public platform until you approve it, except where you have explicitly turned on scheduled auto-publishing for a specific channel.
- AI output can be wrong, and can unintentionally resemble existing text. You are responsible for what you publish. See the Terms for the detail.
6. Public pages you create
Some LaunchEngine outputs are public by design, and you should treat them as published to the open internet:
- Free launch-map results. The launch map generated by the free tool lives at a shareable link. Anyone with that link can read it, and search engines may index it. Do not put confidential material into the free tool.
- Directory listings and posts. Anything submitted to a directory or published to a social platform is public, and is governed by that platform’s own privacy policy from the moment it arrives there. We cannot delete it for you once it is published.
7. Who we share data with
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We use the following processors, each under a written data-processing agreement:
| Processor | Purpose | Location |
|---|---|---|
| Clerk | Accounts, sign-in, session management | United States |
| Convex | Application database and backend functions | European Union (eu-west-1) |
| Railway | Web application hosting | European Union |
| Hetzner | Virtual servers running the engine workers | Germany / Finland |
| Cloudflare | DNS, CDN, custom-domain routing, DDoS protection | Global |
| Stripe | Subscription payments and invoicing | United States / Ireland |
| PostHog | Product analytics (consent-gated) | European Union |
| Meta Platforms | Advertising pixel and conversion measurement (consent-gated) | United States |
| Resend | Transactional and notification email | United States |
| Anthropic, OpenAI, Google (Gemini), OpenRouter | AI generation of launch copy, posts and scripts | United States |
| ElevenLabs, Deepgram, fal.ai | Voice synthesis, transcription and video rendering | United States |
| Firecrawl, Jina, Serper, Apify, ScrapeCreators | Reading public web pages and public platform data | United States / self-hosted (EU) |
| APIFlash | Screenshots of public pages you supply | United States |
| Ayrshare | Optional API-based publishing to social platforms | United States |
We will also disclose data where the law requires it, to enforce our Terms, to protect our rights or someone’s safety, and to a buyer if the business is sold — in which case you will be told before your data moves and this policy continues to apply until it is replaced.
8. International transfers
Several processors above are in the United States. Where personal data leaves the UK or EEA we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on an adequacy decision where one applies, together with the technical measures in section 10. You can ask us for a copy of the relevant transfer mechanism.
9. How long we keep things
| Data | Retention |
|---|---|
| Account and launch data | For as long as your account is open, then 90 days after you close or delete it |
| Free launch maps (no account) | 12 months from generation, or on request, whichever is sooner |
| Generated drafts and posts | With the account; deleted drafts go within 30 days |
| Extension posting logs | 90 days |
| Server and security logs | 30 days |
| Billing and invoice records | 7 years, as required by UK tax law |
| Support correspondence | 2 years from the last message |
10. Security
- All traffic is encrypted in transit with TLS; data at rest is encrypted by our hosting and database providers.
- Authentication and password storage are handled by Clerk; we never store your password.
- Card details are handled entirely by Stripe; they never touch our servers.
- Where you supply your own API keys, they are encrypted at rest before storage.
- Access to production data is limited to the people who need it and is logged.
No system is perfectly secure. If a breach is likely to result in a risk to your rights we will notify the Information Commissioner’s Office within 72 hours and tell you without undue delay where the risk is high.
11. Your rights
Under UK and EU GDPR you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything inaccurate;
- delete your data (“the right to be forgotten”);
- restrict or object to how we process it, including any processing based on legitimate interests;
- send you, or another provider, a portable machine-readable export;
- withdraw consent — for cookies, the extension, or marketing email — at any time, without affecting what was lawful beforehand.
Email [email protected] and say what you want. We reply within one month and it costs nothing. If you are unhappy with our answer you can complain to the Information Commissioner’s Office (or your local EU supervisory authority), though we would rather you gave us the chance to fix it first.
If you are in California, you additionally have the rights to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA, and we will not discriminate against you for exercising any right.
12. Cookies
Strictly necessary cookies — the ones that keep you signed in and remember your cookie choice — are set without consent, as PECR permits. Every other cookie and tracker, including PostHog analytics and the Meta pixel, loads only after you accept them in the banner. You can change your mind at any time from the cookie settings link in the footer. Full detail: Cookie Policy.
13. Children
LaunchEngine is a business tool and is not directed at children. You must be at least 18 to hold an account. If we learn we hold a child’s data we delete it.
14. Changes to this policy
If we change this policy materially we will update the date at the top and email account holders at least 14 days before the change takes effect. Continuing to use LaunchEngine after that date means you accept the updated policy; if you do not, close your account and we will delete your data.
LaunchEngine is a trading name of PowLeads Ltd (company no. 11932107), registered in England and Wales at Axis Building, 142, 9 Whitworth Street West, Manchester, England, M1 5JD. Questions about this document: [email protected].