Privacy Policy
What we collect, why we collect it, and the guarantees we make about your content. Written to be read rather than skimmed past.
Who we are
Launchifyer is operated by YOUGUIDE INTERNATIONAL BV, a company registered in Belgium with its registered office at Leonardo Da Vincilaan 19, MC Square, 1831 Diegem, Belgium, VAT BE1009005084. We are the controller for the personal data described in this policy. For anything here, write to privacy@launchifyer.com.
Launchifyer is a free beta. It generates marketing copy, articles, images, ad copy and email sequences from a brand kit you define. It does not connect to advertising channels, publish on your behalf, send email on your behalf or measure campaigns, so this policy describes only the data the generators actually involve.
The email sequences the product writes are drafts stored in your account. We hold no contact lists, no recipient addresses and no subscribers, and nothing you generate is ever delivered to anyone by us.
Controller, not processor
We act as controller for everything covered here, including the brand kits and generated assets you create. We are not offering a processor arrangement during the beta and there is no Data Processing Agreement in place yet. If your organisation needs one before you use the product, email us and we will tell you honestly where we have got to rather than send you a document we have not written.
Data we collect
Data you give us
- Account data — your name, email address and a hashed password. We never store the password itself.
- Profile data — optionally your company name and your role, plus whether you opted in to product email. All three are blank unless you fill them in.
- Brand kit and content — the brand name, description, tone and audience you define, and the copy, articles and images you generate from them.
- Connected account data — if you connect a social account, we store an access token for it (encrypted), the account’s id and display name on that platform, and which permissions it granted. We keep this only to act on the account on your behalf, and we delete it when you disconnect the account.
- Enquiry data — if you complete the contact form, the topic, your name, work email, company, team size and message, so that we can read and reply to it.
We do not take payment details. There is nothing to pay during the beta, so no card, billing address or VAT number is ever collected from you.
Data we collect automatically
- Session data — a session token, your IP address and your browser user-agent string, recorded when you sign in so that we can keep you signed in and spot suspicious activity.
- Generation counts — how many pieces of copy, articles and images you have generated this month, because each is capped. This is a count, not a copy of the content.
- Visit analytics (first-party) — if you allow analytics cookies, we record which pages you view and in what order, plus a coarse device type and the two-letter country of your visit. A pseudonymous id links the pages within one visit; from the point you sign in, that visit is linked to your account. We do not store your IP address. These records are kept for 90 days.
- Page analytics (Vercel) — aggregate page views through Vercel Web Analytics, which is cookieless and only runs if you allow analytics in the consent panel.
What we do not do is build advertising profiles, fingerprint your device, or record what you type, click or watch on a page (no session replay). Our visit analytics records page navigation only, never keystrokes or screen recordings. The cookie policy lists every cookie we set and every third party involved.
How we use it, and on what basis
Under the GDPR we rely on one of four legal bases for every processing activity:
- Contract — creating and securing your account, storing your brand kit, generating copy, articles and images, and enforcing the monthly generation caps.
- Legitimate interests — keeping the service available and investigating abuse.
- Consent — product email if you opted in, and analytics cookies — including our first-party visit analytics, which runs only if you allow the analytics category. Withdrawable at any time, without losing access to anything.
- Legal obligation — responding to lawful requests and keeping records we are required by law to keep.
AI processing and model training
This is the section most people are here for, so it is deliberately blunt.
- We do not train models. We have no training pipeline of any kind, so your brand kit, prompts and generated assets cannot end up in one.
- We require zero-retention terms from every inference provider we integrate, meaning prompts and outputs are not kept on their side once the request completes. We are still finalising that provider set, so we state this as the requirement we impose rather than a finished audit of every vendor.
- Your prompts are sent to the model provider to produce the output you asked for. That is the whole purpose of the request, and it is the only reason your content leaves our systems.
- Generated images are stored in our object storage and are private to your account.
We keep a record of which generations you ran so that the monthly caps work. There is no approval workflow, no guardrail engine and no reviewer log, because none of those are built — the person reviewing the output is you.
International transfers
Our providers operate globally and some process data outside the EEA, principally in the United States. Where that happens we rely on the European Commission's Standard Contractual Clauses, and on the UK Addendum for UK transfers.
We are not offering data residency guarantees during the beta. We cannot promise your data stays inside the EEA, and we would rather say so than publish a region we do not control. If EU-only processing is a hard requirement for you, tell us before you sign up.
How long we keep things
- Account, brand kit and generated content — for as long as your account exists.
- Sessions — until the session expires or you sign out, whichever comes first.
- Contact form enquiries — 24 months from the date you send them, unless they become part of a customer relationship.
- Generation counts — kept as a monthly record so the caps can be enforced.
- Visit analytics (first-party) — per-visit page records are deleted automatically 90 days after the visit. Aggregate figures already counted from them may remain. A visit is linked to your account only from the point you sign in, never for earlier anonymous browsing.
- Page analytics (Vercel) — held in aggregate by Vercel Web Analytics and never tied to your account.
When you ask us to delete your account we remove it from live systems within 30 days. Copies may persist a little longer in our providers' routine backups, which are purged on their schedule rather than ours; we are not quoting a backup window we do not set.
Your rights
You have the right to access, correct, delete, port or restrict the processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time.
- Self-service export and deletion are not built yet. Email privacy@launchifyer.com and we will handle it manually, within 30 days.
- You can change your name, company and role, and turn product email on or off, from your account page.
- We will not charge you or degrade your service for making a request.
- If we get it wrong you can complain to your local supervisory authority. Ours is the Belgian Data Protection Authority — the Gegevensbeschermingsautoriteit, also known as the Autorité de protection des données — in Brussels.
California residents additionally have the right to know, delete, correct and opt out of “sharing” as defined by the CPRA. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
How we protect it
What is true today: traffic is served over TLS, passwords are hashed by our authentication library and never stored in readable form, database access is scoped so that every query is filtered to the signed-in account, and generated images are private to the account that made them.
Our broader security posture — encryption key handling, staff access controls and infrastructure hardening — is written up as architectural commitments on the security page rather than claimed here as finished work, because the platform is pre-launch. We hold no third-party security certifications and do not claim any.
If we ever suffer a breach affecting your personal data we will notify you without undue delay, and the supervisory authority within 72 hours of becoming aware, as the GDPR requires.
Children
Launchifyer is a business tool and is not directed at anyone under 16. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.
Changes to this policy
We will post any change here and update the date shown alongside this document. If a change materially affects how we handle your personal data, we will email registered account holders before it takes effect.