BACK TO HOME
/ COMPLIANCE

What we audit.

And how we protect the data you trust us with.

IMPORTANT DISCLAIMER

LaunchShield is an automated compliance tool. It does not provide legal advice. All final decisions are at the discretion of Apple / Google review teams. Our assessments are provided “as-is” and do not guarantee App Store / Play Store acceptance.

/ APPLE

App Store Review

All sections of the Apple App Store Review Guidelines (1.x safety, 2.x performance, 3.x business, 4.x design, 5.x legal), Privacy Manifest, Required Reason APIs, Info.plist purpose strings, StoreKit disclosure, ATT compliance, account deletion (5.1.1(v)).

/ GOOGLE

Play Console

Google Play Developer Program Policies: Deceptive Behavior, Restricted Content, Privacy & Deception, Families Policy, Data Safety Form alignment, target SDK compliance, permissions review.

/ COVERAGE AREAS

Every checkpoint we run

01Privacy Manifest & Required Reason APIs
02Info.plist purpose strings (all NS* keys)
03Account creation & deletion (Apple 5.1.1(v))
04Subscription disclosure & auto-renew terms
05User-Generated Content moderation
06Kids category & families policy
07ATT prompt copy & timing (iOS 14.5+)
08Data Safety Form alignment (Play Console)
09Deceptive behavior & spam patterns
10Restricted content categories
11Target SDK compliance
12StoreKit implementation & external links
13Location permission justification
14Health & fitness data disclosures
15AI-generated content labeling
16Crypto & Web3 restrictions
/ SCOPE LIMITS

What LaunchShield does not check

  • Actual app binary or source code (we only audit submitted metadata)
  • Runtime behavior, crashes, or performance
  • Trademark or copyright infringement in your name, icon, or content
  • Financial regulations (SEC, FinCEN, MSB, etc.)
  • Healthcare regulations (HIPAA, HITRUST) beyond store disclosure
  • Local employment, tax, or export-control law
  • Any determination that requires legal judgment (consult an attorney)
/ SECURITY POSTURE

How we protect your data

TLS 1.3 in transit
All API traffic encrypted with modern ciphers.
Zero-Retention buffers
Audit content wiped in try/finally on every request.
AES-256 at rest
MongoDB Atlas encrypted storage for audit summaries.
Rate-limited endpoints
Per-IP throttling to prevent abuse.
/ SUB-PROCESSORS

Third parties we work with

Full disclosure, per GDPR Art. 28 and CPRA § 1798.140.

VendorPurposeRegionDPA
Anthropic, PBCClaude Sonnet 4.5 LLM inferenceUSLink
MongoDB AtlasAudit summary DB (no raw content)US / EULink
Stripe, Inc.Payment processingUSLink
Vercel Inc.Hosting & edge networkGlobalLink

We provide 30 days’ notice on this page of any new sub-processor.

/ REGULATORY ALIGNMENT

Frameworks we align with

GDPR (EU)
Full data subject rights, SCCs for transfers, 30-day DSAR window, 72-hour breach notification.
UK-GDPR + DPA 2018
UK IDTA for cross-border transfers, ICO complaints handling.
CCPA / CPRA (California)
Right to know, delete, correct, opt-out; 45-day response window; no sale/share of data.
EU AI Act (Art. 50)
AI interaction disclosure, no prohibited practices, no high-risk applications.
SOC 2 Type II
In progress — target audit period Q4 2025.
ISO 27001
Aligning controls; certification roadmap 2026.
/ VULNERABILITY DISCLOSURE

Report a security issue

Security researchers: we welcome coordinated disclosure. Please do not access user data beyond what is necessary to demonstrate the issue, and do not publish before we’ve had a reasonable window to remediate (typically 90 days).

  • Contact: security@launchshield.dev
  • PGP: Available on request
  • Response SLA: Acknowledgment within 24h, initial assessment within 5 business days
  • Recognition: Public thanks (unless anonymity requested); no bounty program yet
/ STATUS
All systems operational
Uptime target: 99.5% · Rolling 90-day
99.98%