Privacy Policy
Effective date: August 26, 2026 · Last updated: August 26, 2026
1. Who We Are
Launch at Dawn ("we," "us," "our") operates the AI visibility tracking platform at www.launchatdawn.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
For GDPR purposes, our data controller is Launch at Dawn. For questions about this policy, contact us at privacy@launchatdawn.com.
2. Data We Collect
2.1 Account Data (when you sign up)
- Email address
- Password (stored as a bcrypt hash — we cannot read it)
- Name (if provided via OAuth — Google/GitHub)
- Plan selection (free, starter, pro, growth, agency)
2.2 Business Data (when you add a business)
- Business name, URL, category, city
- Client email (if provided by agency users)
- Country code
- Tracking prompts you create
- Competitor names and URLs
2.3 Analytics Data (generated by our Service)
- AI model responses to your prompts
- Visibility scores, position rankings, sentiment analysis
- Citation data and competitor brand mentions
- Crawler hit logs (bot visits to your website via our integration snippet)
- Cost and token usage per AI model call
2.4 Payment Data (processed by Stripe)
We do not store credit card numbers. Payment is processed by Stripe. We store only your Stripe customer ID and subscription status. See Stripe's Privacy Policy.
2.5 Lead Data (when you use our free tools)
- Email address (from free scan, report request, or contact forms)
- Name and business information (if voluntarily provided)
- Chat transcripts (from our AI agent)
2.6 Integration Credentials
- WordPress Application Passwords (encrypted with AES-256-GCM before storage)
- GitHub/GitLab/Bitbucket access tokens (encrypted with AES-256-GCM)
- Slack webhook URLs
3. How We Use Your Data
- Provide the Service: Run AI visibility scans, track prompts, generate analytics
- Process payments: Manage subscriptions via Stripe
- Send transactional emails: Score alerts, weekly digests, account notifications
- Improve the Service: Aggregate usage patterns (anonymized)
- Customer support: Respond to your inquiries
- Legal compliance: Maintain audit logs, fraud prevention
4. Third-Party Services (Data Processors)
We share data with the following third-party processors solely to provide the Service:
- Supabase — Database, authentication, file storage
- Stripe — Payment processing
- Resend — Transactional email delivery
- Vercel — Hosting and serverless infrastructure
- AI Model Providers — OpenAI, Anthropic, Google (Gemini), Perplexity, Groq, Mistral, DeepSeek, xAI (Grok), OpenRouter. Your prompts and business URLs are sent to these providers to generate AI visibility responses.
- Sanity — Content management (blog posts only — no PII)
5. Your Rights (GDPR)
If you are in the European Economic Area (EEA), you have the following rights:
- Right of Access: Request a copy of all personal data we hold about you
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Portability: Receive your data in a machine-readable format (JSON)
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time (where processing is based on consent)
To exercise any of these rights, use the data export and account deletion tools in your dashboard settings, or email us at privacy@launchatdawn.com.
6. Data Retention
- Account data: Retained while your account is active. Deleted within 30 days of account deletion.
- Analytics data: Retained for the duration of your plan (0–365 days depending on tier).
- Lead data: Retained for 12 months for sales follow-up, then deleted.
- Audit logs: Retained for 24 months for security and compliance.
- Payment records: Retained as required by tax law (7 years in most jurisdictions).
7. Cookies
We use only strictly necessary cookies for authentication (Supabase session cookies). These are HTTP-only, secure, and essential for the Service to function. We do not use advertising or tracking cookies. See our Cookie Policy for full details.
8. Data Security
- All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
- Integration credentials are encrypted with AES-256-GCM before database storage
- Row Level Security (RLS) ensures users can only access their own data
- Admin access is restricted by email allowlist
- Regular security audits and penetration testing
9. International Transfers
Your data may be processed in countries outside the EEA (including the United States) by our third-party processors. We rely on Standard Contractual Clauses (SCCs) and adequacy decisions to ensure adequate protection for international transfers.
10. Children's Privacy
Our Service is not intended for children under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on our Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact Us
For privacy-related inquiries: privacy@launchatdawn.com
For general inquiries: hello@launchatdawn.com