Legal

Privacy Policy

Last updated October 6, 2026

This policy explains what Launch Ready (uselaunchready.com) collects when you use the product at https://uselaunchready.com. It is written in plain language. It is not legal advice.

Who we are

Launch Ready is a pre-launch website QA tool. You paste a URL; we crawl publicly reachable pages (and staging sites you authorize), score launch readiness, and produce a report you can share or download.

The controller of your personal data is Péter Kiss, who operates Launch Ready from Calle Las Huertas 15, 29788 Frigiliana (Málaga), Spain. For anything about your data, write to privacy@uselaunchready.com. Full operator details are in the legal notice.

For personal data inside your workspace — for example teammates' emails or data on the sites you scan — you are the controller and we process it for you under the Data Processing Addendum.

What we collect

  • Account data: email address, optional name, authentication records (password hash or Supabase/Google auth identifiers), and session cookies needed to keep you signed in.
  • Project and scan data: start URLs you submit, optional staging HTTP basic credentials you save (encrypted at rest), expected analytics/pixel settings, crawl snapshots, findings, scores, share tokens, and PDF exports you generate.
  • API keys and AI agents: the name, a short display prefix and a one-way hash of each API key (the key itself is shown once and never stored), when it was last used, and the scans and reads made with it, including through the MCP connector.
  • Free plan site: the registrable domain a Free workspace checks (for example client.com), when it was set and how. It is kept when the project is deleted, so the one-site rule holds.
  • Billing data: Stripe customer and subscription identifiers. Card numbers are processed by Stripe; we do not store full card details.
  • Operational logs: scan progress events, email delivery records, and error logs needed to run and debug the service.
  • Team data (Pro and Agency): invite emails and workspace membership when you use teams.
  • Share reward: if you submit a post to earn a Full Scan Credit, we store the post's address, the platform, the author handle we identify from the post, the result of our automatic checks (whether the post is reachable and public, whether it contains your workspace's link and a disclosure, and when it was posted), our decision and its reason, and who in your workspace submitted it. We use this to review the submission, to grant and, if needed, withdraw the credit, and to keep the same post or social account within the share reward's limits. To check a post we request it from the platform's public interfaces (Bluesky, the Mastodon instance, X, Meta), which see that the post was requested. We keep this data while your workspace exists. If you delete your account or the workspace, we delete the post address and handle and keep only a one-way keyed hash of each, so the same post cannot earn a credit again. Your data export includes your submissions.
  • Analytics data, only if you accept analytics cookies: pages visited, product steps such as signing up or starting a scan, and device and approximate location from Google Analytics. We never send Google your email, your name, or the sites you scan.

Third-party sites we crawl

When you start a scan, we request the URL you provide and linked pages within the crawl limits of your plan. That may include HTML, headers, redirects, and limited rendered content from those sites. We do this only to produce your report. We are not claiming ownership of the sites you scan.

Full page HTML is processed while the scan runs and is not kept. We keep what the report needs: findings with short evidence snippets (such as the tag or header that triggered a rule), page addresses, scores, and a screenshot of the homepage. The API and the MCP connector never return evidence snippets or page HTML.

Do not submit URLs you are not allowed to test. You are responsible for having permission to scan the target (including staging sites protected by credentials you supply).

How we use data

  • Create and secure your account
  • Run scans, store reports, and power share links / PDFs
  • Send transactional email (magic links, password reset, invites, scan complete)
  • Process subscriptions and prevent abuse
  • Improve reliability and fix bugs

We do not sell your personal information.

Where data lives

The web app runs in the European Union: Vercel’s Frankfurt region (fra1). The database and authentication run on Supabase in the EU. Scan results, account records, and share links are stored there.

Some processors below operate globally and may process data outside the EU on our behalf — payments (Stripe), transactional email (Resend), bot protection (Cloudflare), error monitoring (Sentry), and any alert endpoint your workspace configures. Where that involves a transfer out of the EEA, it rests on the processor’s own standard contractual clauses.

Processors we rely on

  • Hosting and edge delivery (currently Vercel for the web app)
  • Postgres and auth (Supabase)
  • Payments (Stripe)
  • Transactional email (Resend, when configured)
  • A long-running scan worker host (Railway, off Vercel) that processes the job queue
  • Bot protection on signup and login (Cloudflare Turnstile, only when it is enabled; it sees the request and a challenge token, not your account data)
  • Error monitoring (Sentry, only when it is enabled; payloads are scrubbed of secrets before they are sent)
  • Alert delivery (Slack, and any webhook endpoint your workspace configures — we post monitoring alerts to the addresses you give us and nowhere else)
  • Analytics (Google Tag Manager and Google Analytics, provided by Google Ireland Limited — only if you accept analytics cookies; Google may process this data in the United States under the EU–US Data Privacy Framework)

Our data processing addendum lists the same set as sub-processors with their roles and locations.

Retention and deletion

Account, project, and scan data are kept while your account is active. You can delete a project or your account from settings; export is available before delete. Share links can expire or be revoked. Backups and logs may retain residual copies for a limited operational period. Invoices and billing records are kept for as long as tax and accounting law requires.

Homepage screenshots are deleted after 30 days, keeping each project's latest one. On the Free plan you can open the last seven days of scans; that is a limit on what you see, not a deletion schedule, and upgrading shows older scans again. A Free workspace's site (see What we collect) stays recorded after its project is deleted; it is removed with the workspace, or on request.

Cookies and similar tech

We use cookies that the product needs to keep you signed in, remember your workspace, and remember your cookie choice. Analytics and marketing cookies are set only if you accept them, and you can change your mind at any time. Reports shared with your clients load no analytics. We do not sell data or use it for third-party ad targeting. The Cookie Policy lists every cookie and how long it lasts.

Your choices

You can update account details, revoke share links, remove staging credentials, export your data, or delete your account from the product.

You also have the right to access, correct, delete, or port your personal data, to restrict or object to how we process it, and to withdraw consent at any time. Write to privacy@uselaunchready.com and we will answer within one month.

If you think we have mishandled your data, you can complain to the Agencia Española de Protección de Datos (AEPD) or to the data protection authority where you live.

Children

Launch Ready is built for business users. It is not directed at children under 16.

Changes

We may update this policy as the product changes. The “Last updated” date at the top will change when we do. Continued use after an update means you accept the revised policy.

Also see our Terms of Service, our Cookie Policy, our Data Processing Addendum, and how the scanner works.