launchpat.

Privacy

launchpat is made by Setpat Technologies, Unipessoal Lda (Portugal). Questions and requests: hello@setpat.com.

Last updated 2026-09-12.

What information we collect

This section summarises what user information launchpat accesses, collects, stores and otherwise uses, including API Data relating to users. Each item is described in more detail in the section named after it below.

Your account

To operate your account we process your email address and a password (handled by Supabase Auth; we never see or store your password itself), plus the products, settings and content you create in the app. Sign-in state is kept in your browser's local storage. Legal basis: contract performance (GDPR Art. 6(1)(b)). Your data is stored with Supabase in the EU, on servers we operate in the EU (Germany/Finland). To have your account and its data deleted, write to hello@setpat.com; see Deleting your data and revoking access below.

Connected social accounts

If you connect a social account (for example X) so launchpat can publish replies you approve or read your own post metrics, we store the OAuth tokens for that connection encrypted at rest. Tokens are used only to act on your explicit instructions (nothing is ever posted without your approval), and disconnecting the account invalidates them. Legal basis: contract performance (Art. 6(1)(b)).

Billing

Payments are processed by Stripe; your card details go directly to Stripe and never touch our servers. We store only your Stripe customer and subscription identifiers, your plan, and usage counters needed to meter the service. Invoices and VAT handling follow EU rules. Legal basis: contract performance (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for accounting records.

Transactional email

Service email (signup confirmations, daily product emails, billing and support replies) is delivered via Resend as our email processor. We do not send marketing email without a separate opt-in.

Support

When you email support, we store your message, address and our replies to resolve your request, and may use AI models to classify and route the message. Support history follows our general log-retention posture. Legal basis: contract performance (Art. 6(1)(b)).

API keys

Personal access tokens you create are stored as SHA-256 hashes only. The token itself is shown once and cannot be recovered by us. Revoke any token at any time in the app.

Session recording

With your consent, we record your session (clicks and navigation) using PostHog, with data stored in the EU, to find bugs and improve the product. Your typing and personal information are masked. We do not record the admin console.

Consent is optional: declining does not affect your access to the product. You can withdraw consent at any time from Account settings → Session recording. Recording stops immediately when you withdraw.

The daily product email

Each product you add can send you a daily product email: a summary of that product's signals, drafts and results, delivered to your account's email address. It is part of the service you signed up for.

When you click a link in one of these emails, we record the click (which kind of link, when, for which product, and your browser's user-agent string) to learn which parts of the email are useful. We use no open-tracking pixels. Click records are deleted after 90 days.

Public product facts

To ground drafts, daily emails and strategy on accurate information, we collect and cache publicly available facts about the products you add: your public website content, your public store and channel listings (for example Steam, the App Store, YouTube). When two products point at the same public website or channel, we compute this snapshot once and share the cached copy between them, so it stays fresher and we scrape the public web less.

These cached facts describe the product's public presence, never you: no private account data, no personal information beyond what the public page itself shows. They are used only to generate your launch content and intelligence, never for advertising or profiling.

Public social content we process

launchpat helps product makers find public conversations where their product might genuinely help. To do that, we process a limited amount of publicly posted content from platforms such as Reddit, X, Bluesky, Hacker News, YouTube, Steam, GitHub and public app-store reviews: the post's title or a short excerpt, the posting account's public username, a link to the original post, when it was posted, and public engagement counts. We only access content that is publicly visible without logging in.

What we never do: we do not access private or protected content or direct messages; we do not build profiles of people; we do not link identities across platforms; we do not collect contact details, follower lists or friend graphs; we do not sell or export this data; and no reply is ever sent automatically; any response a launchpat customer sends is written or approved by a human and posted under that customer's own account on the platform itself.

YouTube API Services

launchpat's YouTube features use YouTube API Services. By using them you also agree to the YouTube Terms of Service; Google's handling of data is described in the Google Privacy Policy.

What we store from YouTube: the video id, title, a short description excerpt, channel name, publish date and public engagement counts (views, likes, comments) at fetch time. Where a channel is one of your product's own sources we also keep a channel snapshot: its handle and id, subscriber and video counts, and the titles and view counts of recent uploads. Everything we hold from the YouTube Data API is deleted or refreshed within 30 days, as the YouTube API Services Developer Policies require for data retrieved without a Google account authorisation: a video item is re-fetched from YouTube before it is 30 days old and its stored title, description excerpt, channel name, publish date and engagement counts are replaced with the current values; a video YouTube no longer returns is deleted in full, and so is any item we could not refresh within 30 days. Other platforms keep their 90-day and 400-day windows. A channel snapshot is replaced by a fresh one on a recurring sweep and removed outright if it has not been refreshed within 30 days, and YouTube entries in your brief archive are refreshed the same way and removed when the video is no longer available or could not be refreshed within 30 days. We never download, re-host or re-publish video or audio content; every card links out to youtube.com.

Our YouTube integration is server-side and reads only public data: we do not ask for, receive or store Google account credentials or OAuth tokens, so there is no per-user YouTube account access to revoke. A customer can remove a connected channel from their product's sources at any time, which stops its fetches; stored YouTube data is deleted on request via hello@setpat.com (see "Your rights").

Community intelligence (opt-in)

Optionally, each of your products can contribute anonymized learnings to community intelligence: aggregated playbooks about what works in a niche (for example "indie roguelikes"), shared with other makers building similar products. This is off by default and controlled per product from the Product brain card.

Before anything is shared, contributions pass a sanitization step that strips product names, links and any identifying details, and an aggregate is only published when at least three different accounts contribute to it; your individual data is never exposed. Turning the toggle off, or deleting the product, removes your contribution from the next daily rebuild of the aggregates.

How we use and share your information

We use the information above to operate your account, to gather and score signals for your products, to generate drafts, strategy and product emails, to meter and bill the service, to answer support requests, to keep the service secure and prevent abuse, and to fix bugs and improve the product. We do not sell personal information, and we do not use it for advertising, ad targeting or building advertising profiles.

Internal parties. Setpat Technologies, Unipessoal Lda personnel access your information only where it is necessary to operate, support or secure the service.

External parties. We share information with the following categories of service providers, who process it on our instructions:

We also disclose information where the law requires it, and to professional advisers where necessary to meet our accounting and tax obligations.

Cookies and device storage

We use no advertising cookies and no cross-site tracking cookies, and we set no cookies from our own JavaScript. We do store and read information on your device, and some of our providers do so as well.

You can clear this storage at any time in your browser, refuse or withdraw consent for session recording in Account settings, and control cookies through your browser settings.

Deleting your data and revoking access

Deleting stored data. To have your account deleted, write to hello@setpat.com from the address the account uses. We remove your products and their data, including any YouTube API Data held for them, without undue delay and in any event within 30 days. YouTube API Data is deleted within seven calendar days of receiving the request, as the YouTube API Services Terms require. You can also ask us to delete specific data at any time at the same address. You can remove a product yourself in the app at any time: Move to trash keeps it recoverable for 30 days, and Permanently delete erases it and its data. Beyond that, data expires on its own: the full technical copy of a platform item after 90 days and its short display record after 400 days; YouTube data is deleted in full after 30 days (see YouTube API Services). Email click records are deleted after 90 days.

Stopping collection. Removing a channel or account from a product's sources stops the scheduled fetches for it; if that channel is also the product's primary URL, change or remove the URL as well, since a product is always monitored at its primary URL. Disconnecting a connected social account disables launchpat's use of it and we ask the provider to revoke the stored token.

Revoking access to your Google account. launchpat reads only public YouTube data, using a server-side API key, and never requests, receives or stores Google account credentials or OAuth tokens, so launchpat holds no authorization against your Google account. You can review and revoke any third party's access to your Google account at any time on the Google security settings page at https://myaccount.google.com/connections?filters=3,4&hl=en. To have YouTube data we have already stored deleted, write to hello@setpat.com. Deleting the copy we hold does not delete anything from YouTube itself. To remove a video, a comment or a channel from YouTube you must delete it on YouTube, signed in to the Google account that owns it; the YouTube Help Centre explains how.

Your rights

Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent: write to hello@setpat.com. You can also complain to a supervisory authority; ours is the CNPD (Portugal).