LaunchValid

Privacy Policy

Last updated: July 25, 2026

Effective date: June 30, 2026

What changed: We explained how we process data that founders collect from leads, app visitors, and program applicants; corrected our Google Drive and Google Sheets disclosure and added a Google limited use statement; and described programs and pooled credits, data rooms and share links, and live working sessions.


1. Introduction

AmpFi App LLC, a Wyoming limited liability company, doing business as LaunchValid (“LaunchValid,” “we,” “us,” or “our”), respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you use the LaunchValid website and services at launchvalid.com, our applications, and the founder subdomains we host on launchvalid.app (together, the “Service”).

By using the Service, you acknowledge this Privacy Policy and our Terms of Service.

Contact: hello@launchvalid.com


2. Information we collect

2.1 Information you provide

  • Account data: name, email address, Google account identifier (sub), and profile photo from Google OAuth (sign-up and sign-in).
  • Project and research content: business ideas, project titles, research documents, imports (PDF, Word, text, markdown), comments, notebook messages, pinned insights, project intake answers, and Concept Studio artifacts.
  • Published assets and their settings: pitch decks, data rooms and the documents you place in them, hosted validation pages, and built apps you generate, along with their share links, viewer allow lists, expiry settings, and view analytics.
  • Team and collaboration: invitee emails, roles (owner, editor, viewer, chat-only), and source-access settings you configure. On a Business account team, we also store your team roster (member emails, whether each member may create projects, and their status), an optional company email domain you allow for sharing, and, for each team-funded project, its title and credit usage attributed to your account so the account owner can see team spending.
  • Marketplace data: seller profile (bio, categories, portfolio), bids, task statements of work, deliverables, validation notes, and messages related to tasks.
  • Ratings and reports: star ratings and written reviews you leave for a counterparty after an engagement, and Trust & Safety reports you file (category, description, and the item reported). Ratings and reviews you leave about a seller are shown publicly on that seller’s profile (attributed by first name); reports are used internally for review and are not published.
  • Billing data: subscription tier and payment status via Stripe (we do not store full payment card numbers).
  • Onboarding survey: optional answers you give during sign-up: how you heard about us, what problem you are trying to solve, what you hope to do, and optional details about yourself (such as your role, experience, and, if you choose to share it, gender). These are voluntary and used to improve the product; you can skip them.
  • Support and communications: emails and messages you send to us.

2.2 Information collected automatically

  • Usage data: pages viewed, features used, clicks, timestamps, referring URLs, device type, browser, and approximate location derived from IP address.
  • Log and diagnostic data: error logs, performance metrics, and security events.
  • Cookies and similar technologies: session cookies, authentication tokens, and analytics identifiers (see Section 9).

2.3 Information from third parties

  • Stripe: payment confirmation, Connect account status for sellers, payout metadata.
  • Google: OAuth sign-in (openid, email, profile) and Google Drive access with the drive.file scope. This scope reaches only files this app creates in your own Drive. We use it two ways: to export your research to a Google Doc, and to run the Google Sheets that store data for your hosted pages and built apps. For those Sheets we create the file, then read, append, update, and delete rows in it as your pages and apps operate. We never see or list the rest of your Drive. Refresh tokens are stored encrypted on our servers.
  • Sellers and founders: deliverables, validation status, and marketplace transaction data exchanged through the Service.

Google limited use. LaunchValid's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Data we receive through Google APIs is used only to provide and improve the features described above. We do not use it for advertising, we do not sell it, and we do not use it to train generalized or foundation AI models.


3. How we use information

We use information to:

  • Provide, maintain, and improve the Service.
  • Run AI features (research generation, notebook chat, research sync, Concept Studio, comment-driven updates) using your project content according to your settings and team permissions.
  • Process subscriptions, credit metering, boost purchases, and marketplace payments.
  • Send transactional emails (account, billing, task updates, research ready notifications).
  • Send marketing emails where permitted (you may opt out).
  • Enforce Terms, prevent fraud, and protect security.
  • Comply with law and respond to lawful requests.
  • Analyze aggregated or de-identified usage to improve the product.

We do not sell your personal information.


4. AI processing disclosure

LaunchValid uses third-party AI services to process your project content and generate outputs. We do not disclose specific model or vendor names in the product.

  • What is processed: Research sections, imports, comments, notebook messages, selected sources, and concept-generation inputs derived from your project. AI also helps produce and update the other things you create: pitch decks and data room documents, hosted validation pages and built apps, and, for programs, application screening across cohorts, pooled-credit research, and live working sessions.
  • Purpose: To generate and update research, answer questions with citations, produce concept and fundraising assets, build validation pages and apps, score and summarize program applications, and incorporate your feedback.
  • Human review: LaunchValid staff may access content only when necessary for support, abuse investigation, dispute resolution, or legal compliance, not for routine review of your research.
  • Training: We do not use your private project content to train public foundation models. Our AI providers’ terms govern their handling of API data.
  • Outputs: AI outputs may contain errors. See the Terms of Service disclaimers; outputs are not professional advice.

5. How we share information

We share information only as follows:

RecipientPurpose
Service providersHosting (e.g. Vercel), database, email (AWS SES), file storage (AWS S3), analytics (e.g. PostHog), AI APIs, payments (Stripe), under contracts requiring appropriate safeguards
Other users you authorizeTeam members, collaborators, and marketplace counterparties according to your roles, publishes, and assignments. On a Business account team, the account owner can see the title and credit usage of projects paid from the shared pool, and can see a project's research only if the member who created it shares it
Programs you joinWhen you take part in a program such as an accelerator, its people can see your participation and the research funded from the program's shared credit pool, each according to their role. A program admin runs the program. Reviewers and monitors can see the materials for the founders they oversee, and a monitor may read research sections across a cohort but not your private notebook. In a live working session you have agreed to, the program host and any monitors watching can see that session's thread in real time. See Section 6
Data room, page, and app viewersPeople you invite to a data room through a share link can see the documents you include. Visitors to your hosted pages and users of your built apps interact with what you publish. We record limited viewer and visitor information as described in Section 6
Legal and safetyWhen required by law, subpoena, or to protect rights, safety, and integrity of the Service
Business transfersIn connection with merger, acquisition, financing, or sale of assets (including entity rename or reformation), with notice where required

We do not share your full private research with marketplace sellers except what you publish in task scope or messages.


6. Data we process for founders (leads, app visitors, and applicants)

Some features let a founder collect information from other people: visitors to a hosted validation page, users of an app the founder builds, or applicants to a program the founder runs. When this happens, the founder is the controller of that information and LaunchValid is a processor acting on the founder's behalf. The founder decides what to collect and why. We process it to run the feature. This is separate from the information we collect about our own account holders, which the rest of this policy covers.

6.1 Hosted page leads

When a visitor submits the form on a founder's hosted validation page, we capture the email address, an optional name, and the other answers the form asks for, along with basic source information such as campaign tags and the referring page. We store a one-way hash of the visitor's IP address and browser for spam and rate limiting; we do not store the raw IP address. A copy may be mirrored to a Google Sheet in the founder's own Google Drive. We also keep bucketed, aggregated traffic counts (views, approximate unique visitors, and conversions by source) so the founder can measure demand. The founder owns and manages these leads.

6.2 App visitors

An app a founder builds with LaunchValid stores its data in a Google Sheet in the founder's own Google Drive. When a member of the public uses the app, the entries they submit are written to that Sheet. LaunchValid keeps only a count of submissions for abuse and traffic limits. The actual entries live in the founder's Sheet, which the founder controls.

6.3 Program applicants

When someone applies to a program running on LaunchValid, we collect the applicant's name and email, their company and one-line description, the people they name as founders or teammates, and their free-text answers. We store a salted hash of the submitter's IP address for anti-abuse, never the raw IP. Applications may be scored with AI to help the program review them. The program is the controller of applicant information, and LaunchValid processes it for the program.

6.4 Viewer information in data rooms and share links

When a founder shares a data room through a share link, we record the email a viewer enters to open it, a one-way hash of their IP address (never the raw IP), a shortened browser string, and view counts and timestamps, so the founder can see who opened the room. The founder controls who is invited and can set a link to expire or revoke it at any time.

6.5 Retention and your rights for this data

We keep this information for as long as the founder or program keeps it in their account, and we delete or return it when they delete it or close their account, subject to short-lived backups that roll off on the schedule in Section 7. If you submitted your details to a founder's page, app, or program and want to access, correct, or delete them, contact that founder or program first, since they control the data. You can also reach us at hello@launchvalid.com and we will help route your request and support the founder in honoring it.


7. Data retention

We retain information while your account is active and as needed to provide the Service, resolve disputes, enforce agreements, and comply with legal obligations.

  • Account deletion: You may request account deletion; we will delete or anonymize personal data within 30 days except where retention is required (billing records, dispute logs, legal holds).
  • Project content: Deleted with account or per your deletion request, subject to backups that roll off on a schedule (typically 30 to 90 days).
  • Billing records: Retained as required for tax and accounting (often 7 years).

8. Your rights and choices

8.1 All users

  • Access and correction: update profile in account settings; contact us for other corrections.
  • Deletion: request deletion via hello@launchvalid.com.
  • Marketing opt-out: unsubscribe link in marketing emails.
  • Cookies: manage browser settings; some features require essential cookies.

8.2 California residents (CCPA/CPRA)

If you are a California resident, you may have the right to:

  • Know categories and specific pieces of personal information collected.
  • Delete personal information (subject to exceptions).
  • Correct inaccurate personal information.
  • Opt out of sale or sharing for cross-context behavioral advertising. We do not sell or share personal information for cross-context behavioral advertising.
  • Limit use of sensitive personal information where applicable.
  • Non-discrimination for exercising privacy rights.

Submit requests: hello@launchvalid.com with subject “Privacy Request.” We will verify your identity before responding.

Authorized agents: May submit requests with proof of authorization.

8.3 Other US state privacy laws

Residents of Colorado, Virginia, Connecticut, Utah, and other states with privacy laws may have similar rights. Contact us at hello@launchvalid.com.

8.4 European Economic Area / UK (if applicable)

If we offer the Service to individuals in the EEA or UK, we will provide lawful bases, international transfer mechanisms, and rights under GDPR as required. At MVP launch we are English-first and USA-focused; contact us before relying on EU-specific features.


9. Cookies and analytics

We use:

  • Essential cookies: session cookie (httpOnly), session security, load balancing. These are required to run the Service and are always on.
  • Analytics cookies: product analytics (e.g. PostHog) to understand feature usage in aggregated form. Non-essential; loaded only after you consent.
  • Advertising cookies: where enabled, marketing/measurement pixels (e.g. Meta, LinkedIn, Reddit) to measure and improve our advertising. Non-essential; loaded only after you consent.
  • Google Consent Mode signals: our Google measurement tag (Google Analytics and Google Ads) loads on every page, but it reads and writes advertising and analytics cookies only after you consent. Until then it sends cookieless, non-identifying signals (no cookies, no identifiers, IP and page data redacted) that Google uses to estimate overall, aggregated ad and site performance. These signals contain no personal data and cannot identify you.

Consent: on your first visit we show a cookie banner. Cookie-setting analytics and advertising tags do not load unless you choose "Accept." If you choose "Reject non-essential," those cookies never run; the Google tag stays in its cookieless, non-identifying mode described above (you can opt out of that too via your browser's Do Not Track / ad settings and Google's own controls). You can change your choice at any time by clearing the lv_cookie_consent cookie in your browser (which re-shows the banner). Essential cookies cannot be disabled without breaking sign-in and core functionality.


10. Security

We use administrative, technical, and organizational measures appropriate to the nature of the data, including encryption in transit (HTTPS), access controls, and vendor security reviews. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

Report security concerns to hello@launchvalid.com.


11. Children

The Service is not directed to children under 18. We do not knowingly collect personal information from children. Contact us if you believe a child has provided data.


12. International users

LaunchValid is operated from the United States. If you access the Service from outside the US, you consent to processing and storage in the US and other countries where our providers operate, which may have different data protection laws.


13. Third-party links

The Service may link to third-party sites (Stripe, Google, seller portfolios). Their privacy practices are governed by their own policies.


14. Changes to this Privacy Policy

We may update this Privacy Policy. We will post the revised version with a new “Last updated” date and provide additional notice for material changes where required.


15. Contact

AmpFi App LLC d/b/a LaunchValid
Privacy inquiries: hello@launchvalid.com
Website: https://launchvalid.com

For Terms of Service, see the Terms of Service.