Who we are
Launchpad is operated by Galax (“we”, “us”). We are the data controller for the personal data described in this policy. You can reach us about anything in this document at privacy@launchpad.app.
This policy explains what Launchpad collects, why, and what we will never do with it. It follows the structure of our internal security specification, and each section comes with a plain-language summary — if the two ever read differently, tell us, because that is a bug.
Launchpad is operated by Galax (“we”, “us”). We are the data controller for the personal data described in this policy. You can reach us about anything in this document at privacy@launchpad.app.
We collect and store the following categories of data:
We process your data to provide the service (running your sandboxes, storing your projects, streaming agent turns), to bill you (the credit ledger exists so every charge is explainable), to secure the platform (rate limits, abuse detection, content policy enforcement), and to improve the product using aggregated, pseudonymized usage data.
We do not use your content — your prompts, your chat history, your code, your published apps — to train foundation models, and we do not permit our sub-processors to do so under our agreements with them. We do not sell personal data. We do not show advertising.
We use a small number of sub-processors, each bound by a data-processing agreement:
We will notify account holders before adding a sub-processor that handles content.
You can access, export, correct, or erase your data. Export and account deletion are self-service in Settings — the export produces your actual projects as real repositories, because ownership is the product's whole thesis. For anything the UI doesn't cover, email privacy@launchpad.app and we will respond within 30 days. If you are in the EU/EEA, these are your GDPR rights and you also have the right to complain to your supervisory authority.
Data is encrypted in transit and at rest. Secrets you connect — API keys, database credentials — are envelope-encrypted in a vault so that a database dump does not become a credential dump. Sandboxes are isolated per project at the kernel level. The complete isolation model, including what we deliberately cannot read, is documented on our Security page.
If we confirm a personal-data breach that affects you, we will notify affected users and, where required, the relevant supervisory authority within 72 hours of confirmation, with what we know, what we've done, and what you should do.
Launchpad is not directed at children. You must be at least 13 years old to use it (16 where the EU's age of digital consent applies). If we learn we hold data on a child below these ages, we delete it.
When this policy changes materially, account holders get 30 days' notice by email before the change takes effect. Every version of this document is tracked in version control, so you can see exactly what changed between any two dates.