Privacy
launchpat is made by Setpat Technologies, Unipessoal Lda (Portugal). Questions and requests: hello@setpat.com.
Last updated 2026-09-12.
What information we collect
This section summarises what user information launchpat accesses, collects, stores and otherwise uses, including API Data relating to users. Each item is described in more detail in the section named after it below.
- Account information: your email address, a password held by Supabase Auth (we never see or store it), and the products, settings and content you create in the app.
- Billing information: your Stripe customer and subscription identifiers, your plan and usage counters. Card details go directly to Stripe and never reach our servers.
- Personal access tokens: stored as SHA-256 hashes only.
- Connected social accounts: where you connect one (for example X), the OAuth tokens for that connection, encrypted at rest.
- Support correspondence: your messages, your address and our replies.
- Public content we process for your products: public posts, product facts and platform metadata gathered from the sources you configure.
- YouTube API Data: for videos and channels relevant to your product: the video id, title, a short description excerpt, channel name, publish date and public engagement counts at fetch time. Where a channel is one of your product's own sources we also keep a channel snapshot: the channel handle and id, its subscriber and video counts, and the titles and view counts of its recent uploads. This is public data retrieved with a server-side API key. We never request, receive or store Google account credentials or OAuth tokens, so we hold no Authorized Data and no per-user YouTube account access.
- Usage and device information: entries we keep in your browser's local and session storage, product-analytics events, the user-agent string recorded when you click a link in a product email, and server logs. See Cookies and device storage.
Your account
To operate your account we process your email address and a password (handled by Supabase Auth; we never see or store your password itself), plus the products, settings and content you create in the app. Sign-in state is kept in your browser's local storage. Legal basis: contract performance (GDPR Art. 6(1)(b)). Your data is stored with Supabase in the EU, on servers we operate in the EU (Germany/Finland). To have your account and its data deleted, write to hello@setpat.com; see Deleting your data and revoking access below.
Connected social accounts
If you connect a social account (for example X) so launchpat can publish replies you approve or read your own post metrics, we store the OAuth tokens for that connection encrypted at rest. Tokens are used only to act on your explicit instructions (nothing is ever posted without your approval), and disconnecting the account invalidates them. Legal basis: contract performance (Art. 6(1)(b)).
Billing
Payments are processed by Stripe; your card details go directly to Stripe and never touch our servers. We store only your Stripe customer and subscription identifiers, your plan, and usage counters needed to meter the service. Invoices and VAT handling follow EU rules. Legal basis: contract performance (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for accounting records.
Transactional email
Service email (signup confirmations, daily product emails, billing and support replies) is delivered via Resend as our email processor. We do not send marketing email without a separate opt-in.
Support
When you email support, we store your message, address and our replies to resolve your request, and may use AI models to classify and route the message. Support history follows our general log-retention posture. Legal basis: contract performance (Art. 6(1)(b)).
API keys
Personal access tokens you create are stored as SHA-256 hashes only. The token itself is shown once and cannot be recovered by us. Revoke any token at any time in the app.
Session recording
With your consent, we record your session (clicks and navigation) using PostHog, with data stored in the EU, to find bugs and improve the product. Your typing and personal information are masked. We do not record the admin console.
Consent is optional: declining does not affect your access to the product. You can withdraw consent at any time from Account settings → Session recording. Recording stops immediately when you withdraw.
- Controller: Launchpat
- Processor: PostHog (EU region)
- Purpose: debugging and product improvement
- Legal basis: consent (GDPR Art. 6(1)(a))
- Your rights: withdraw consent, access, erasure: contact hello@setpat.com
The daily product email
Each product you add can send you a daily product email: a summary of that product's signals, drafts and results, delivered to your account's email address. It is part of the service you signed up for.
When you click a link in one of these emails, we record the click (which kind of link, when, for which product, and your browser's user-agent string) to learn which parts of the email are useful. We use no open-tracking pixels. Click records are deleted after 90 days.
- Controller: Launchpat (Setpat Technologies, Unipessoal Lda.)
- Processor: Resend (email delivery)
- Purpose: delivering the daily product email; improving it via click measurement
- Legal basis: contract performance (GDPR Art. 6(1)(b))
- Opt out: every email carries an unsubscribe link (one-click in supporting mail clients) and a per-product toggle in the app; unsubscribing takes effect before the next send
Public product facts
To ground drafts, daily emails and strategy on accurate information, we collect and cache publicly available facts about the products you add: your public website content, your public store and channel listings (for example Steam, the App Store, YouTube). When two products point at the same public website or channel, we compute this snapshot once and share the cached copy between them, so it stays fresher and we scrape the public web less.
These cached facts describe the product's public presence, never you: no private account data, no personal information beyond what the public page itself shows. They are used only to generate your launch content and intelligence, never for advertising or profiling.
- Purpose: product intelligence (grounding your tasks, drafts, daily emails and strategy)
- Legal basis: legitimate interest (GDPR Art. 6(1)(f)): processing information the product's own public pages already publish
- Your rights: object, access, erasure: contact hello@setpat.com. Deleting a product removes its private brain data; cached facts about a public website or channel persist only while some product still references it.
Public social content we process
launchpat helps product makers find public conversations where their product might genuinely help. To do that, we process a limited amount of publicly posted content from platforms such as Reddit, X, Bluesky, Hacker News, YouTube, Steam, GitHub and public app-store reviews: the post's title or a short excerpt, the posting account's public username, a link to the original post, when it was posted, and public engagement counts. We only access content that is publicly visible without logging in.
What we never do: we do not access private or protected content or direct messages; we do not build profiles of people; we do not link identities across platforms; we do not collect contact details, follower lists or friend graphs; we do not sell or export this data; and no reply is ever sent automatically; any response a launchpat customer sends is written or approved by a human and posted under that customer's own account on the platform itself.
- Purpose: surfacing public conversations to the one customer whose product they may concern
- Legal basis: legitimate interest (GDPR Art. 6(1)(f)): assessment documented and reviewed
- Retention: the full technical copy of a post is deleted after 90 days; the short display record after at most 400 days. Posts deleted on their platform stop displaying when we detect that (we re-check periodically).
- Processors: platform-official APIs (e.g. YouTube Data API, Bluesky), xAI (X search), Apify (collection infrastructure for public Reddit listings), Supabase (EU database hosting), and AI model providers used only to judge relevance; we record which provider fetched every stored post.
- Your rights: if a public post of yours appears in launchpat and you object (Art. 21) or want it removed (Art. 17), email hello@setpat.com with a link to the post; we remove its content from our systems for all customers.
YouTube API Services
launchpat's YouTube features use YouTube API Services. By using them you also agree to the YouTube Terms of Service; Google's handling of data is described in the Google Privacy Policy.
What we store from YouTube: the video id, title, a short description excerpt, channel name, publish date and public engagement counts (views, likes, comments) at fetch time. Where a channel is one of your product's own sources we also keep a channel snapshot: its handle and id, subscriber and video counts, and the titles and view counts of recent uploads. Everything we hold from the YouTube Data API is deleted or refreshed within 30 days, as the YouTube API Services Developer Policies require for data retrieved without a Google account authorisation: a video item is re-fetched from YouTube before it is 30 days old and its stored title, description excerpt, channel name, publish date and engagement counts are replaced with the current values; a video YouTube no longer returns is deleted in full, and so is any item we could not refresh within 30 days. Other platforms keep their 90-day and 400-day windows. A channel snapshot is replaced by a fresh one on a recurring sweep and removed outright if it has not been refreshed within 30 days, and YouTube entries in your brief archive are refreshed the same way and removed when the video is no longer available or could not be refreshed within 30 days. We never download, re-host or re-publish video or audio content; every card links out to youtube.com.
Our YouTube integration is server-side and reads only public data: we do not ask for, receive or store Google account credentials or OAuth tokens, so there is no per-user YouTube account access to revoke. A customer can remove a connected channel from their product's sources at any time, which stops its fetches; stored YouTube data is deleted on request via hello@setpat.com (see "Your rights").
Community intelligence (opt-in)
Optionally, each of your products can contribute anonymized learnings to community intelligence: aggregated playbooks about what works in a niche (for example "indie roguelikes"), shared with other makers building similar products. This is off by default and controlled per product from the Product brain card.
Before anything is shared, contributions pass a sanitization step that strips product names, links and any identifying details, and an aggregate is only published when at least three different accounts contribute to it; your individual data is never exposed. Turning the toggle off, or deleting the product, removes your contribution from the next daily rebuild of the aggregates.
- Purpose: product intelligence only; shared learnings are never used for advertising or profiling
- Legal basis: consent (GDPR Art. 6(1)(a)), withdrawable at any time per product
- Your rights: withdraw consent (the toggle), access, erasure: contact hello@setpat.com
How we use and share your information
We use the information above to operate your account, to gather and score signals for your products, to generate drafts, strategy and product emails, to meter and bill the service, to answer support requests, to keep the service secure and prevent abuse, and to fix bugs and improve the product. We do not sell personal information, and we do not use it for advertising, ad targeting or building advertising profiles.
Internal parties. Setpat Technologies, Unipessoal Lda personnel access your information only where it is necessary to operate, support or secure the service.
External parties. We share information with the following categories of service providers, who process it on our instructions:
- Hosting and database: Supabase (EU) and servers we operate in the EU (Germany and Finland).
- Payments: Stripe.
- Email delivery: Resend.
- Product analytics and session recording: PostHog (EU region). Analytics events reach PostHog through a proxy on our own domain; session recording runs only with your consent.
- Network, CDN and bot protection: Cloudflare (including Turnstile on public pages) and jsDelivr for script delivery.
- AI model providers: we send product content and the public content we collect, which can include YouTube video metadata, to AI model providers so it can be scored, summarised and turned into drafts. Providers we use include Anthropic, DeepSeek, xAI and Google.
- Data source APIs and collection providers: the platform APIs you configure as sources, including the YouTube Data API, and collection providers such as Apify and Firecrawl.
We also disclose information where the law requires it, and to professional advisers where necessary to meet our accounting and tax obligations.
Cookies and device storage
We use no advertising cookies and no cross-site tracking cookies, and we set no cookies from our own JavaScript. We do store and read information on your device, and some of our providers do so as well.
- Our own browser storage: in your browser's local and session storage we keep your sign-in state (Supabase Auth), interface preferences such as the theme, collapsed panels, hidden tiles and the product you last opened, one-time flags recording that you have seen a tour or tutorial, and short-lived state for the admin console.
- Cloudflare: places security and bot-management cookies at the network edge, runs Turnstile on our public scan pages, and serves a web-analytics beacon on our public marketing pages.
- PostHog: stores analytics identifiers in local storage on app pages. Autocapture is off; session recording starts only after you grant consent.
- Stripe: if you start a checkout, Stripe stores information on its own pages under its own policy.
You can clear this storage at any time in your browser, refuse or withdraw consent for session recording in Account settings, and control cookies through your browser settings.
Deleting your data and revoking access
Deleting stored data. To have your account deleted, write to hello@setpat.com from the address the account uses. We remove your products and their data, including any YouTube API Data held for them, without undue delay and in any event within 30 days. YouTube API Data is deleted within seven calendar days of receiving the request, as the YouTube API Services Terms require. You can also ask us to delete specific data at any time at the same address. You can remove a product yourself in the app at any time: Move to trash keeps it recoverable for 30 days, and Permanently delete erases it and its data. Beyond that, data expires on its own: the full technical copy of a platform item after 90 days and its short display record after 400 days; YouTube data is deleted in full after 30 days (see YouTube API Services). Email click records are deleted after 90 days.
Stopping collection. Removing a channel or account from a product's sources stops the scheduled fetches for it; if that channel is also the product's primary URL, change or remove the URL as well, since a product is always monitored at its primary URL. Disconnecting a connected social account disables launchpat's use of it and we ask the provider to revoke the stored token.
Revoking access to your Google account. launchpat reads only public YouTube data, using a server-side API key, and never requests, receives or stores Google account credentials or OAuth tokens, so launchpat holds no authorization against your Google account. You can review and revoke any third party's access to your Google account at any time on the Google security settings page at https://myaccount.google.com/connections?filters=3,4&hl=en. To have YouTube data we have already stored deleted, write to hello@setpat.com. Deleting the copy we hold does not delete anything from YouTube itself. To remove a video, a comment or a channel from YouTube you must delete it on YouTube, signed in to the Google account that owns it; the YouTube Help Centre explains how.
Your rights
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent: write to hello@setpat.com. You can also complain to a supervisory authority; ours is the CNPD (Portugal).