Effective date: June 1, 2025 · Version 1.0 · GDPR / UK-GDPR / CPRA
Your privacy policy text and app description are processed exclusively in volatile server memory (Node.js Buffers) and wiped via a try / finally block the instant your audit completes — whether it succeeds, fails, or times out. Raw user artifacts are never persisted to disk. We do not use your content to train AI models.
LaunchShield (“we,” “us”) is the data controller for personal information processed through this Service. For questions or to exercise your rights:
| Category | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Ephemeral audit content (privacy policy text, app description) | AI compliance analysis | Art. 6(1)(b) contract | Wiped on completion |
| App metadata (name, category, feature checklist, platforms) | Deliver + persist audit summary | Art. 6(1)(b) contract | 24 months |
| Audit result (score, findings, code fixes) | Enable retrieval + sharing | Art. 6(1)(b) contract | 24 months |
| Contact / billing email (only if you purchase) | Receipts, support | Art. 6(1)(b) contract | 7 years (tax) |
| Technical logs (IP address, user-agent, timestamps) | Rate-limiting, security, abuse prevention | Art. 6(1)(f) legitimate interest | 90 days |
| Payment metadata (tokenized card, last-4, country) | Handled by Stripe | Art. 6(1)(b) contract | Per Stripe policy |
We do not knowingly collect biometric data, health data, precise geolocation, or data from children under 16. We do not process “sensitive personal information” under CPRA § 1798.140(ae).
Every audit request is wrapped in a try / finally block. In the finally stage, our wipeBuffers() routine executes buffer.fill(0) to zero-fill every Node.js Buffer holding your submitted content, then dereferences the buffer object. This runs even if the LLM call fails, times out, or throws an unhandled exception. No temporary files are written to disk. No worker queues persist your content between requests.
The Service is an automated decision-making system within the meaning of Art. 22 GDPR. Its output (the Readiness Score and findings list) is generated by Anthropic Claude Sonnet 4.5 based on the app metadata you provide and the current Apple / Google published guidelines.
Logic involved: Your submission is sent to the LLM inside a fixed system prompt that instructs it to enumerate compliance violations, categorize them by severity, and generate structured JSON output. No human reviewer is involved in Scout and Launch tiers. The Insurance tier includes optional human-in-the-loop expert review.
Significance: Our output is informational and does not, on its own, produce legal effects concerning you. You retain full control over whether to act on any finding.
Your rights: You may request (i) human review of any material output, (ii) an explanation of the logic, and (iii) the ability to contest a finding by emailing privacy@launchshield.dev.
We use the following sub-processors. Each is under contract to process personal data only on documented instructions and with appropriate technical and organizational measures.
| Sub-processor | Function | Data types | Location | Transfer mechanism |
|---|---|---|---|---|
| Anthropic, PBC | LLM inference | Prompt (audit content, wiped after request) | US | SCCs (EU) / UK IDTA |
| MongoDB Atlas | Audit summary storage | App metadata, audit result | US / EU | SCCs |
| Stripe, Inc. | Payment processing | Card token, email, country | US | SCCs |
| Vercel Inc. | Hosting, edge network | Request logs, IP | Global | SCCs |
Neither Anthropic nor any other sub-processor uses your content to train models under our agreements.
If you access the Service from outside the United States, your data may be transferred to and processed in the US. For transfers from the EEA / UK / Switzerland, we rely on the EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum. Where applicable, we conduct Transfer Impact Assessments (TIAs) and implement supplementary technical measures (encryption in transit and at rest, access controls).
LaunchShield uses only strictly necessary cookies for session state and CSRF protection. We do not use marketing, advertising, or cross-site tracking cookies. We do not employ third-party analytics on the audit product itself. This means no cookie banner is required under ePrivacy Directive Art. 5(3).
If you are in the EEA, UK, or Switzerland, you have the following rights:
We respond to verified requests within 30 days (extendable by 60 days for complex requests, with notice).
If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (2023 effective):
We respond within 45 days, extendable by 45 days with notice. To submit a verifiable consumer request, email privacy@launchshield.dev. We may need to verify your identity before fulfilling the request.
We implement industry-standard technical and organizational measures:
In the event of a personal data breach that is likely to result in a risk to your rights, we will notify affected users and applicable supervisory authorities within 72 hours of becoming aware, as required by Art. 33 GDPR.
The Service is not directed to children under 16. We do not knowingly collect personal information from children. If we learn we have collected such data, we will delete it promptly.
We may update this Privacy Policy from time to time. Material changes will be posted at the top of this page at least 14 days before taking effect. For substantial changes affecting your rights, we will notify you by email where we have an address on file.
To exercise any right or ask a question: privacy@launchshield.dev. We aim to respond within 5 business days for initial acknowledgment.