Skip to main content

LaunchEngine Privacy Policy

Last updated: 28 August 2026

LaunchEngine is a trading name of PowLeads Ltd (company no. 11932107), registered in England and Wales at Axis Building, 142, 9 Whitworth Street West, Manchester, England, M1 5JD.

This policy explains what personal data LaunchEngine collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It covers https://launchengine.app, the LaunchEngine web app, the LaunchEngine Posting Companion browser extension, and the free launch-map tool. It is written to satisfy the UK GDPR, the EU GDPR, the Data Protection Act 2018, and PECR.

The short version. We collect the account details you give us, the product information you type in, and the content the engine drafts for you. We use AI vendors to generate that content, and we never use your content to train our own models. The browser extension posts through your own logged-in browser session — we never see or store your social-media passwords. We do not sell your data. You can export or delete everything at any time by emailing [email protected].

1. Who we are

LaunchEngine is a trading name of PowLeads Ltd, a company registered in England and Wales under number 11932107, with its registered office at Axis Building, 142, 9 Whitworth Street West, Manchester, England, M1 5JD. PowLeads Ltd is the data controller for the personal data described in this policy, except where section 3 says we act as a processor on your behalf.

Data protection contact: [email protected]. We are not required to appoint a Data Protection Officer, and we have not appointed one; that address reaches the person accountable for data protection.

2. What we collect and why

DataWhy we have itLawful basis
Account details — name, email address, and (if you sign in with Google or GitHub) the profile identifier that provider returnsCreating and securing your account, signing you in, sending service noticesPerformance of our contract with you
Launch inputs — your product URL, repository URL, description, the story of why you built it, brand and copy context you enterGenerating your launch map, directory list, posts, comments and video scriptsPerformance of our contract with you
Generated content — drafts, scheduled posts, comments, images, voiceovers and videos the engine produces for youDelivering the service, letting you review and approve before anything is publishedPerformance of our contract with you
Connected-platform data — the handles and account identifiers of social accounts you connect, plus the results of posts made on your behalfPublishing where you ask us to, reporting what was posted and what failedPerformance of our contract with you
Browser-extension activity — see section 4Posting and commenting through your own browser sessionYour consent, given when you install and enable the extension
Billing data — plan, subscription status, invoices, and the last four digits and expiry of your cardTaking payment and meeting UK accounting and tax obligationsContract, and legal obligation for records we must keep
Technical and usage data — IP address, browser and device type, pages viewed, feature usage, error reports, server logsKeeping the service up, diagnosing faults, preventing abuse and fraudOur legitimate interest in a secure, working product
Analytics and advertising data — PostHog product analytics and the Meta advertising pixelUnderstanding which parts of the product are used, and measuring our advertisingYour consent, given through the cookie banner. Nothing in this row loads before you accept.
Support correspondence — emails and in-app messages you send usAnswering you, and keeping a record of what was askedOur legitimate interest in supporting customers

We do not ask for, and do not want, special-category data (health, political opinions, religious beliefs, biometrics, sexual orientation) or criminal-offence data. Please do not put it into launch inputs or chat.

3. When we are a processor for you

Two features make you the controller and us the processor, because the personal data involved is other people’s, and you decide what happens to it:

  • The waitlist widget. If you embed the LaunchEngine waitlist on your own site, the email addresses your visitors submit are yours. We store and display them to you, and do nothing else with them.
  • Directory submissions. When you ask the engine to submit your product to a third-party directory, we send the details you supplied — which may include your name and email — to that directory on your instruction.

In both cases you are responsible for having a lawful basis for that data and for telling those people what you are doing with it. Article 28 terms are available as a signed Data Processing Agreement on request — email [email protected].

4. The Posting Companion browser extension

The LaunchEngine Posting Companion is an optional Chrome extension. It exists so that posts and comments go out through your own logged-in browser session, the way you would post them by hand. This is deliberate: the alternative is handing us your platform passwords, and we do not want them.

What it can technically do

The extension declares broad host access (<all_urls>) because Chrome requires it in order to open and drive a tab on the sites you choose. Its content scripts — the code that actually reads or types on a page automatically — are restricted by the extension manifest to four domains: reddit.com, linkedin.com, facebook.com and instagram.com. The one exception is directory form-filling, described below, which runs only on a directory page you queued and only when you ask for it.

What it actually sends us

  • The text of the post or comment you approved, so we can confirm it was published.
  • The resulting post URL, and success or failure with an error reason.
  • The account handle it posted as, so drafts are attributed correctly.
  • Where a target thread or subreddit is part of your plan, the public URL and title of that thread.

Directory submissions

Separately from the four social domains, the extension can open a directory’s own submission page — any web address, because every directory is a different site — and fill that form with the product details from your profile. It only ever opens a directory you queued in LaunchEngine, it fills the form rather than reading the page for us, and what it sends back is which fields it could and could not map, so the filler learns that directory. It does this on no other kind of page.

What it never does

  • It does not read, collect or transmit your passwords, session cookies or authentication tokens.
  • It does not read your private messages, DMs, notifications or email.
  • It does not publish anything you have not approved in the LaunchEngine app.
  • It does not sell, rent or transfer any of this data to anyone, and it is never used for advertising.

This use complies with the Chrome Web Store Limited Use requirements: data the extension handles is used only to provide the posting feature you asked for. You can disable or remove the extension at any time from chrome://extensions; removing it stops all of the above immediately.

5. AI generation, and what we do not do with your content

  • We do not train models on your content. We build no models of our own and we do not contribute your data to anyone else’s training set.
  • We only use AI providers on no-training terms. Your launch inputs and drafts are sent to the vendors listed in section 7 under their commercial API terms, which exclude the use of API content for model training. We do not route your content through free or community model tiers that reserve the right to train on prompts.
  • A human — you — approves before publication. The engine drafts; nothing reaches a public platform until you approve it, except where you have explicitly turned on scheduled auto-publishing for a specific channel.
  • AI output can be wrong, and can unintentionally resemble existing text. You are responsible for what you publish. See the Terms for the detail.

6. Public pages you create

Some LaunchEngine outputs are public by design, and you should treat them as published to the open internet:

  • Free launch-map results. The launch map generated by the free tool lives at a shareable link. Anyone with that link can read it, and search engines may index it. Do not put confidential material into the free tool.
  • Directory listings and posts. Anything submitted to a directory or published to a social platform is public, and is governed by that platform’s own privacy policy from the moment it arrives there. We cannot delete it for you once it is published.

7. Who we share data with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We use the following processors, each under a written data-processing agreement:

ProcessorPurposeLocation
ClerkAccounts, sign-in, session managementUnited States
ConvexApplication database and backend functionsEuropean Union (eu-west-1)
RailwayWeb application hostingEuropean Union
HetznerVirtual servers running the engine workersGermany / Finland
CloudflareDNS, CDN, custom-domain routing, DDoS protectionGlobal
StripeSubscription payments and invoicingUnited States / Ireland
PostHogProduct analytics (consent-gated)European Union
Meta PlatformsAdvertising pixel and conversion measurement (consent-gated)United States
ResendTransactional and notification emailUnited States
Anthropic, OpenAI, Google (Gemini), OpenRouterAI generation of launch copy, posts and scriptsUnited States
ElevenLabs, Deepgram, fal.aiVoice synthesis, transcription and video renderingUnited States
Firecrawl, Jina, Serper, Apify, ScrapeCreatorsReading public web pages and public platform dataUnited States / self-hosted (EU)
APIFlashScreenshots of public pages you supplyUnited States
AyrshareOptional API-based publishing to social platformsUnited States

We will also disclose data where the law requires it, to enforce our Terms, to protect our rights or someone’s safety, and to a buyer if the business is sold — in which case you will be told before your data moves and this policy continues to apply until it is replaced.

8. International transfers

Several processors above are in the United States. Where personal data leaves the UK or EEA we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on an adequacy decision where one applies, together with the technical measures in section 10. You can ask us for a copy of the relevant transfer mechanism.

9. How long we keep things

DataRetention
Account and launch dataFor as long as your account is open, then 90 days after you close or delete it
Free launch maps (no account)12 months from generation, or on request, whichever is sooner
Generated drafts and postsWith the account; deleted drafts go within 30 days
Extension posting logs90 days
Server and security logs30 days
Billing and invoice records7 years, as required by UK tax law
Support correspondence2 years from the last message

10. Security

  • All traffic is encrypted in transit with TLS; data at rest is encrypted by our hosting and database providers.
  • Authentication and password storage are handled by Clerk; we never store your password.
  • Card details are handled entirely by Stripe; they never touch our servers.
  • Where you supply your own API keys, they are encrypted at rest before storage.
  • Access to production data is limited to the people who need it and is logged.

No system is perfectly secure. If a breach is likely to result in a risk to your rights we will notify the Information Commissioner’s Office within 72 hours and tell you without undue delay where the risk is high.

11. Your rights

Under UK and EU GDPR you can ask us to:

  • tell you what we hold about you, and give you a copy;
  • correct anything inaccurate;
  • delete your data (“the right to be forgotten”);
  • restrict or object to how we process it, including any processing based on legitimate interests;
  • send you, or another provider, a portable machine-readable export;
  • withdraw consent — for cookies, the extension, or marketing email — at any time, without affecting what was lawful beforehand.

Email [email protected] and say what you want. We reply within one month and it costs nothing. If you are unhappy with our answer you can complain to the Information Commissioner’s Office (or your local EU supervisory authority), though we would rather you gave us the chance to fix it first.

If you are in California, you additionally have the rights to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA, and we will not discriminate against you for exercising any right.

12. Cookies

Strictly necessary cookies — the ones that keep you signed in and remember your cookie choice — are set without consent, as PECR permits. Every other cookie and tracker, including PostHog analytics and the Meta pixel, loads only after you accept them in the banner. You can change your mind at any time from the cookie settings link in the footer. Full detail: Cookie Policy.

13. Children

LaunchEngine is a business tool and is not directed at children. You must be at least 18 to hold an account. If we learn we hold a child’s data we delete it.

14. Changes to this policy

If we change this policy materially we will update the date at the top and email account holders at least 14 days before the change takes effect. Continuing to use LaunchEngine after that date means you accept the updated policy; if you do not, close your account and we will delete your data.


LaunchEngine is a trading name of PowLeads Ltd (company no. 11932107), registered in England and Wales at Axis Building, 142, 9 Whitworth Street West, Manchester, England, M1 5JD. Questions about this document: [email protected].