Legal
Privacy Policy
Last updated: June 7, 2026
What is LaunchProofer?
LaunchProofer is an external security and launch-readiness scanner for web applications. You give us a URL; we fetch publicly accessible resources from that URL (the page HTML, linked JavaScript bundles, HTTP headers, and select URL paths) and report on security issues and launch gaps — exposed secrets, misconfigured headers, missing privacy policies, and similar.
We do not access your source code, your hosting provider's dashboard, or any private systems. Everything we check is what any visitor to your URL can already see.
Information we collect
Account email
When you create an account, we store the email address you register with. This is used to identify your account and send authentication emails.
Scanned URLs and results
When you submit a URL for scanning, we store that URL and the findings produced by the scan. This forms your scan history so you can review results after the fact and track improvements over time.
Optional Supabase credentials
The RLS (Row Level Security) check optionally accepts your Supabase project URL and anon key. These are the same credentials visible in your Supabase dashboard under “Project Settings → API → anon public” — they are designed to be used in browser code and are not secret.
We use these only to run the RLS check during that single scan. They are not stored in our database beyond the duration of the request.
Session cookies
We use cookies to keep you logged in between visits. These are essential authentication cookies managed by Supabase Auth. We do not use tracking, advertising, or analytics cookies.
How we use it
- —Run the security and launch-readiness scan you requested.
- —Save your scan results to your account history so you can review them later.
- —Authenticate you when you log in and maintain your session.
- —Send transactional emails — account confirmation, magic links, and similar — via our email provider.
We do not sell your data. We do not use your scan results to train AI models. We do not send marketing emails unless you explicitly opt in.
Third-party processors
We use these services to operate LaunchProofer. Each processes your data only as needed to provide their service to us.
Stores your account, scan history, and session tokens. Hosted on AWS infrastructure.
Serves the LaunchProofer application and API. Scan requests are processed on Vercel serverless functions.
Sends authentication and account emails on our behalf.
Processes subscription payments if a paid plan is active on your account. We do not store card details — Stripe handles all payment data.
Data retention
Scan results are retained indefinitely while your account is active so you can refer back to your history. Your account email and session data are retained as long as you have an account.
If you want your account and all associated scan data deleted, email us at privacy@launchproofer.com. We will delete your data within 30 days.
Cookies
We use only essential session cookies required for login and authentication. These cookies are set by Supabase Auth and are necessary for the service to function. We do not use any third-party tracking, advertising, or analytics cookies.
You can delete these cookies at any time in your browser settings, which will log you out of LaunchProofer.
Your rights
Depending on where you live, you may have rights regarding your personal data — including the right to access a copy of it, correct inaccuracies, or request deletion. We honour these requests regardless of your location.
To exercise any of these rights, email us at privacy@launchproofer.com from the address associated with your account. We will respond within 30 days.
Contact
Questions about this policy or how we handle your data:
privacy@launchproofer.com