Privacy Policy

Effective 7 October 2026

The short version: we collect what we need to run your account and, later, to bill you. We don’t sell personal data, run advertising trackers, or use your data to train AI models.

1. Who we are

Launchpad is a product of Axonscape, Hyderabad, Telangana, India (“Axonscape”, “we”). We decide how and why your personal data is processed, so under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) we are the Data Fiduciary, and under the EU and UK GDPR the controller. This policy covers the Launchpad website (launchpad.axonscape.com), console (console.launchpad.axonscape.com), command-line tool and MCP server.

Not covered: data inside the apps you build with Launchpad. For your app’s users, you are the Data Fiduciary (or controller) and your own privacy policy applies. Launchpad sets up the services that hold that data in your own Provider accounts; we don’t access it except as needed to carry out what you instruct.

2. What we collect

WhereWhat we collectSource
Website waitlistEmail address; your optional answer about what you’re building; whether you’re open to an interview; sign-up timeYou
Website visitsIP address and browser details, processed by our host to serve and protect the site; bot-check signals from Cloudflare TurnstileYour browser
GitHub sign-inGitHub user id, username and verified email addresses (we keep one as your account email). The GitHub access token is used once at sign-in and never storedGitHub, with your permission
Console sessionsA session cookie; we store only a one-way hash of it, with its expiryYour browser
Provider tokensAccess tokens for your Vercel, Supabase, Resend, Cloudflare, Render and Stripe accountsYou
ProjectsProject names, launchpad.json configuration, resource ids at your Providers, and project secrets (such as database passwords and API keys)You, and created for you at your Providers
ActivityRun history and logs (what was created or changed, with ids and URLs, never secret values); uptime check resultsThe Service
BillingPlan, subscription status, Stripe customer and subscription ids. Card details are collected and held by Stripe, never by usStripe
SupportWhatever you send us by emailYou

We don’t use analytics or advertising cookies.

3. Why we use it, and on what basis

PurposeBasis
Run the Service: sign you in, set up and manage your Provider resources, monitor uptimeData you give us for that purpose (DPDP Act s.7(a)); performing our contract with you (GDPR)
Bill you and keep tax and accounting recordsOur contract with you; legal obligation
Keep the Service secure and prevent abuseData you give us for using the Service; legitimate interests (GDPR)
Contact you about the beta or an interviewYour consent, given on the waitlist form; you can withdraw it at any time
Service messages (security notices, billing, changes to terms)Our contract with you; legitimate interests (GDPR)
Answer support requestsData you give us for that purpose

We don’t send marketing email without your consent, and we don’t make automated decisions about you that have legal or similarly significant effects.

4. How we protect your tokens and secrets

Provider tokens and project secrets work like passwords, so we treat them as sensitive data and apply reasonable security practices to them, as the Information Technology Act, 2000 and its rules require:

  • Encrypted at rest with AES-256-GCM, each value locked to its owner and purpose.
  • Never shown back. The console shows the names of saved tokens and secrets and when they were saved, never their values.
  • Kept out of logs. Run logs and AI-agent (MCP) responses contain names, ids and URLs only.
  • Used only when needed. Our worker decrypts a token only while carrying out a run you started or a check you set up.
  • Removable any time. Delete a token in the console, or revoke it at the Provider, and we can no longer use it.

If you use the command-line tool on your own computer instead of the console, your secrets stay on your computer and aren’t sent to us. We also use HTTPS everywhere and store session cookies only as hashes.

No system is perfectly secure. If a personal data breach affects you, we’ll tell you and the Data Protection Board of India (and any other authority the law requires) without undue delay.

5. Who we share it with

We don’t sell or rent personal data. We share it only with the service providers that run Launchpad for us (our Data Processors), under contracts that limit their use of it to providing their service:

ProcessorWhat it does for us
VercelHosts the website and console
SupabaseHosts our database (tokens and secrets are stored encrypted)
RenderRuns our background worker
StripeTakes payments and manages subscriptions
ResendSends our emails
CloudflareBot protection on the waitlist form
GitHubSign-in

When you connect your own Provider accounts, we send data to them because you’ve instructed us to; they act under their agreement with you. We may also disclose data where the law requires it, to protect rights and safety, or to a buyer as part of a merger or acquisition, which we’d tell you about first.

Transfers outside India. Our processors may store and process data in the United States and other countries. We transfer data only as the DPDP Act permits, and for EU and UK users we rely on Standard Contractual Clauses or an adequacy decision.

6. How long we keep it

DataKept for
Sign-in sessions30 days, or until you sign out
Uptime check results90 days
Provider tokensUntil you delete them or close your account
Projects, secrets and run logsUntil you delete the project (secrets are wiped at once; the project record and its logs are removed 30 days later) or close your account
Account (GitHub id, username, email)Until you close your account
Billing records and invoices8 years, as Indian tax and company law requires
Waitlist entriesUntil you ask us to remove you, or 12 months after Launchpad opens to the public
Support emails2 years after the conversation ends

When you close your account we erase your account data within 30 days, apart from records we must keep by law. Copies in database backups are overwritten in the normal backup cycle.

7. Your rights

Under the DPDP Act you have the right to:

  • get a summary of the personal data we hold about you and how we use it;
  • have it corrected, completed, updated or erased;
  • withdraw consent you gave (for example, to beta emails) as easily as you gave it, without affecting earlier use;
  • have your grievances addressed, and nominate someone to exercise these rights if you die or become unable to.

If you’re in the EU or UK you also have GDPR rights, including portability and the right to object to processing based on legitimate interests. If you’re in California, we don’t sell or share personal information for cross-context behavioural advertising, and we won’t treat you differently for using your rights.

To use any of these rights, email hello@axonscape.com from your account’s email address so we can confirm it’s you. You can also delete your provider tokens and projects yourself in the console at any time.

8. Grievance Officer and complaints

Our Grievance Officer handles privacy questions and complaints: Grievance Officer, Axonscape, Hyderabad, Telangana, India, hello@axonscape.com (subject “Privacy grievance”). We acknowledge within 48 hours and resolve within 30 days.

If you’re not satisfied with our response, you can complain to the Data Protection Board of India, or, in the EU or UK, to your local data protection authority.

9. Cookies

We use only essential cookies: a session cookie that keeps you signed in to the console (30 days), and a short-lived cookie that protects the GitHub sign-in step. Cloudflare Turnstile may set its own cookie to tell people from bots. We use no analytics or advertising cookies, so there’s no cookie banner.

10. Children

Launchpad is for adults. We don’t knowingly collect personal data from anyone under 18; if you think we have, contact us and we’ll delete it.

11. Changes

We’ll post any changes here with a new effective date, and email account holders at least 30 days before material changes take effect. See also our Terms of Service.

Contact

Axonscape, Hyderabad, Telangana, India · hello@axonscape.com