Privacy Policy
Effective January 1, 2026
Short version
We collect the minimum data needed to run RaiseLaunch Studio. Your dossier, writing samples, and generated content stay in your organization's isolated data scope. We don't sell your data. We don't train shared AI models on it. You can export or delete everything at any time.
What we collect
- Account data: email, name, organization name.
- Content inputs: URLs, uploaded documents (decks, PDFs, financials), writing samples — everything you provide during onboarding and dossier edits.
- Generated content: every artifact, run, and publication we create for you.
- Integration tokens: OAuth access/refresh tokens for Gmail, LinkedIn, X — stored encrypted, used only to publish on your request.
- Billing data: handled by Stripe; we store a customer ID and subscription status, never your card details.
- Usage metadata: which modules ran, token counts, approval/publication events.
How we use it
- To run the Service — generate content, schedule runs, publish to your integrations.
- To bill you ($197/mo via Stripe).
- To send essential transactional emails (welcome, trial-ending, payment issues).
- To debug and improve the Service — aggregated, non-identifying metrics only.
AI providers
We send prompts and content to the following AI providers, each governed by their own privacy policy and data processing addendum:
- Anthropic (Claude) — drafting and synthesis. Data not used to train Anthropic's models.
- OpenAI (gpt-image-1) — cover image generation. API inputs not used for training per OpenAI's API data policy.
- Gamma — investor deck generation from outlines.
- Firecrawl — public URL scraping when you connect your website.
- Unstructured.io — parsing uploaded PDFs/DOCX/PPTX.
We do not operate a shared model that trains on customer content.
Infrastructure sub-processors
- Supabase — database, auth, file storage.
- Vercel — application hosting.
- Inngest — background job execution.
- Stripe — payments.
- Resend — transactional email.
- Sentry — error monitoring (no PII in error payloads).
Data retention & deletion
We retain your data for the life of your account plus 30 days after cancellation, so you have a window to export. After that, we delete everything except what we're legally required to retain (invoices, tax records).
You can delete individual artifacts, schedules, or your entire account from the app. Email privacy@raiselaunch.com for a full export or a hard-delete request.
Your rights (GDPR / CCPA)
You have the right to access, correct, export, and delete your personal data. To exercise any of these rights, email privacy@raiselaunch.com. We'll respond within 30 days.
Security
All data is encrypted in transit (TLS 1.2+) and at rest. OAuth tokens are encrypted at the column level. Row-Level Security ensures one org cannot read another's data. Access to production is limited to named engineers with MFA.
Cookies
We use cookies only for authentication (Supabase session) and Stripe's fraud protection. We do not use advertising cookies or cross-site trackers.
Children
RaiseLaunch Studio is not directed at children under 16 and we don't knowingly collect data from them.
Changes
Material changes to this policy will be announced via email. Continued use after changes means acceptance.
Contact
Questions? privacy@raiselaunch.com