Privacy Policy

Last updated: September 3, 2026

Effective date of this version: September 3, 2026 (originally effective June 30, 2026)

What changed: We added the social posting feature to this policy. Section 2.1 now lists the social accounts you connect, the posts you schedule (including your original words when a caption had to be shortened to fit a platform), the engagement numbers we save for published posts, and the dates you choose to mark with a greeting post. Section 2.3 covers what our publishing provider sends back to us, Section 5 names Post for Me as the provider that delivers your posts to the platforms you connect, and Section 7 notes that deleting your account also removes your social connections held at that provider. Earlier, we corrected what we keep when somebody uses a founder's app: this section said we keep "only a count of submissions", and we in fact keep one record per submission carrying hashed sender details, a duplicate-detection value, a spam score and the delivery result. The contents of the entry are still not kept. We also named Sentry as the provider that receives our error reports, and we added a row to Section 5 setting out exactly what an error report contains and what it deliberately leaves out: no request contents, no research, nothing a visitor typed into a page or app, no email address, no sign-in details, and no cookies or headers. Previously we described the anonymous pre-account intake path for one-time purchases in Section 2.4, including the optional team members you can list before you create an account (name, role, LinkedIn URL, and an optional one-line experience note). We added a legitimate-interest assessment for that team member information in Section 2.5, along with a note on the record we keep when a founder lists a teammate, and a page at launchvalid.com/privacy/team-member-opt-out, described in Section 8.5, where a teammate can remove themselves without signing in. Section 7 now states plainly how long we hold an unclaimed anonymous intake, what happens when the claim link expires, and the project-lifetime retention of a project's design lock. Earlier updates named Google Ads and our advertising platforms (Meta, LinkedIn, and Reddit) as advertising and conversion-measurement providers in Section 5, disclosed Google Ads Enhanced Conversions in Section 9, named the other providers that help us run the Service (Cloudflare Turnstile, browser push, Trustpilot, and web search), and described programs and pooled credits, data rooms and share links, and live working sessions.


1. Introduction

AmpFi App LLC, a Wyoming limited liability company, doing business as LaunchValid (“LaunchValid,” “we,” “us,” or “our”), respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you use the LaunchValid website and services at launchvalid.com, our applications, and the founder subdomains we host on vld.vc (together, the “Service”).

By using the Service, you acknowledge this Privacy Policy and our Terms of Service.

Contact: hello@launchvalid.com


2. Information we collect

2.1 Information you provide

  • Account data: your name and email address. If you sign in with Google, we also receive your Google account identifier (sub) and profile photo. If you sign in with an emailed sign-in link, we collect only your email address, and we record that it was verified when you open the link.
  • Project and research content: business ideas, project titles, research documents, imports (PDF, Word, text, markdown), comments, notebook messages, pinned insights, project intake answers, and Concept Studio artifacts.
  • Published assets and their settings: pitch decks, data rooms and the documents you place in them, hosted validation pages, and built apps you generate, along with their share links, viewer allow lists, expiry settings, and view analytics.
  • Team and collaboration: invitee emails, roles (owner, editor, viewer, chat-only), and source-access settings you configure. On a Business account team, we also store your team roster (member emails, whether each member may create projects, and their status), an optional company email domain you allow for sharing, and, for each team-funded project, its title and credit usage attributed to your account so the account owner can see team spending.
  • Connected social accounts: when you connect a social account so we can publish for you, we store the platform and the account handle and username our publishing provider reports for it. The sign-in to the platform happens at the provider; we never see or store a social account password.
  • Scheduled posts: the text and images of each post you schedule, when it is set to go out, which of your accounts it goes to, and what happened to it. When a caption has to be shortened to fit a platform's limit, we keep your original words alongside the shorter version that was posted.
  • Engagement snapshots: for posts we published, we save the engagement numbers the platforms report (such as likes, comments, and shares) at a few points in a post's life, so you can see how it performed over time.
  • Marked dates: dates you choose to have a project mark with a greeting post, such as a new year, a launch anniversary, or a holiday you observe. A date like this can reveal something personal about you, for example a religious observance. You enter these yourself, we never guess them, we use them only to plan and write the greeting posts you asked for, and you can edit or remove them at any time.
  • Marketplace data: seller profile (bio, categories, portfolio), bids, task statements of work, deliverables, validation notes, and messages related to tasks.
  • Ratings and reports: star ratings and written reviews you leave for a counterparty after an engagement, and Trust & Safety reports you file (category, description, and the item reported). Ratings and reviews you leave about a seller are shown publicly on that seller’s profile (attributed by first name); reports are used internally for review and are not published.
  • Billing data: subscription tier and payment status via Stripe (we do not store full payment card numbers).
  • Onboarding survey: optional answers you give during sign-up: how you heard about us, what problem you are trying to solve, what you hope to do, and optional details about yourself (such as your role, experience, and, if you choose to share it, gender). These are voluntary and used to improve the product; you can skip them.
  • About you: an optional note you can write in Account settings describing your background, such as your industry, experience, or how you are working on your idea. It is used to write your research and documents for you, it is never shown on anything you publish, and it is never used to decide what you may buy or access. You can edit or delete it at any time in Account settings by clearing the box and saving, and deleting your account removes it along with everything else.
  • Support and communications: emails and messages you send to us.

2.2 Information collected automatically

  • Usage data: pages viewed, features used, clicks, timestamps, referring URLs, device type, browser, and approximate location derived from IP address.
  • Log and diagnostic data: error logs, performance metrics, and security events.
  • Cookies and similar technologies: session cookies, authentication tokens, and analytics identifiers (see Section 9).

2.3 Information from third parties

  • Stripe: payment confirmation, Connect account status for sellers, payout metadata.
  • Google: OAuth sign-in (openid, email, profile) and Google Drive access with the drive.file scope. This scope reaches only files this app creates in your own Drive. We use it two ways: to export your research to a Google Doc, and to run the Google Sheets that store data for your hosted pages and built apps. For those Sheets we create the file, then read, append, update, and delete rows in it as your pages and apps operate. We never see or list the rest of your Drive. Refresh tokens are stored encrypted on our servers.
  • Sellers and founders: deliverables, validation status, and marketplace transaction data exchanged through the Service.
  • Post for Me (our social publishing provider): the account handles and usernames of the social accounts you connect, and the engagement numbers the platforms report for the posts we publish for you.

Google limited use. LaunchValid's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Data we receive through Google APIs is used only to provide and improve the features described above. We do not use it for advertising, we do not sell it, and we do not use it to train generalized or foundation AI models.

2.4 Anonymous pre-account intake for one-time purchases

You can buy a single finished deliverable (for example a Validation Report, Investor Deck, or Brand Kit) before creating an account. On that path we collect only what the deliverable needs, and we keep it under the retention rules in Section 7.

  • Idea and business type: a short description of your idea and, where the deliverable needs it, the business type (SaaS, marketplace, services, physical product, B2B, B2C, or other).
  • Public-facing name and brand color: an optional company or product name shown on the deliverable, and an optional brand color used to style it.
  • Website URL and logo: optional. If you upload a logo we store it in our file storage; if you provide a URL we validate it as a public https address.
  • Team members: an optional list, up to five entries, of the people on your team. For each teammate we store their name, role, LinkedIn URL (or another professional profile link), and an optional one-line experience note. This information appears on the deliverable (for example on a deck slide or in an investor memo) so that investors can see who is building the company.
  • Buyer email: the email address you enter at checkout, used to send the claim link and (once you sign in and claim) tied to your account.

The intake fields are yours to change or clear after you sign in and claim the workspace: open the project settings and edit or remove any field, including team members.

2.5 Legitimate-interest assessment for teammate information

When you list a teammate on the anonymous intake path, you are providing another person's professional information (name, role, LinkedIn URL, and an optional one-line experience note) without our being able to obtain their consent at the moment of collection. For that limited purpose we rely on the legitimate-interest lawful basis under GDPR Article 6(1)(f) (and equivalent provisions in other jurisdictions where recognized), and we have carried out the balancing test the law requires.

  • Purpose. To generate the deliverable you are paying for. Investor decks, memos, and data room documents commonly identify the founding team, and omitting the team would materially reduce the usefulness of the deliverable to its intended reader.
  • Necessity. The minimum fields needed are name, role, LinkedIn URL, and an optional one-line experience note. We do not collect contact details, addresses, salary information, or any sensitive personal information about a teammate.
  • Balancing test. The information we process is limited to what a professional would normally publish on a public professional profile (LinkedIn, a company About page, or a public bio). The reader base is small and known to the buyer (the investors or partners the buyer chooses to share the deliverable with). A teammate can remove themselves at any time using the opt-out route in Section 8.5, and we honor that request without requiring them to sign in.
  • Retention. The information is retained while the project is active on the buyer's account. If the anonymous purchase is never claimed, the intake (including team members) stays with the unclaimed purchase record on the terms described in Section 7, and a teammate can have their details removed at any time using the route in Section 8.5.
  • You are responsible for the input. The buyer represents that each teammate has been (or will be) informed that they were listed for the purpose of this deliverable, that the fields are limited to public professional information, and that a teammate may opt out at any time by contacting the buyer or by using the route in Section 8.5. LaunchValid provides the mechanism; the founder decides whom to list.
  • We keep a record of that responsibility. When a buyer submits teammates, we record the date, the versions of these policies the buyer accepted at that moment, and the IP address the submission came from. We keep that record for as long as the project, so that a teammate who asks can be told when and on what terms their details were entered.

3. How we use information

We use information to:

  • Provide, maintain, and improve the Service.
  • Run AI features (research generation, notebook chat, research sync, Concept Studio, comment-driven updates) using your project content according to your settings and team permissions.
  • Process subscriptions, credit metering, boost purchases, and marketplace payments.
  • Publish the posts you schedule to the social accounts you connect.
  • Send transactional emails (account, billing, task updates, research ready notifications).
  • Send marketing emails where permitted (you may opt out).
  • Enforce Terms, prevent fraud, and protect security.
  • Comply with law and respond to lawful requests.
  • Analyze aggregated or de-identified usage to improve the product.

We do not sell your personal information.


4. AI processing disclosure

LaunchValid uses third-party AI services to process your project content and generate outputs. We do not disclose specific model or vendor names in the product.

  • What is processed: Research sections, imports, comments, notebook messages, selected sources, and concept-generation inputs derived from your project. AI also helps produce and update the other things you create: pitch decks and data room documents, hosted validation pages and built apps, social posts and the pictures on them, and, for programs, application screening across cohorts, pooled-credit research, and live working sessions.
  • Purpose: To generate and update research, answer questions with citations, produce concept and fundraising assets, build validation pages and apps, score and summarize program applications, and incorporate your feedback.
  • Human review: LaunchValid staff may access content only when necessary for support, abuse investigation, dispute resolution, or legal compliance, not for routine review of your research.
  • Training: We do not use your private project content to train public foundation models. Our AI providers’ terms govern their handling of API data.
  • Outputs: AI outputs may contain errors. See the Terms of Service disclaimers; outputs are not professional advice.

5. How we share information

We share information only as follows:

RecipientPurpose
Service providersWe use vetted providers, under contracts requiring appropriate safeguards, to run the Service: AWS Amplify (frontend hosting) and other cloud hosting; MongoDB Atlas (database); AWS SES (email); AWS S3 (file storage); Cloudflare Turnstile (bot protection on public forms, which checks whether a request is automated); Stripe (payments); analytics (e.g. PostHog and Google Analytics); advertising and conversion measurement (Google Ads, and the Meta, LinkedIn, and Reddit advertising platforms, used to measure and improve our ads, loaded per your cookie choice as described in Section 9); a web push delivery service for browser notifications you opt into; Trustpilot (collecting and displaying customer reviews, if you choose to leave one); Sentry (error reporting, so we find out when something breaks); web search and content-extraction services used to gather sources for your research; and third-party AI APIs. Consistent with Section 4, we do not name specific AI model vendors.
Error reportsWhen something goes wrong on our servers we send a report to Sentry so we can fix it. We deliberately keep these reports thin. They carry the address of the page or request that failed, the method, an internal request reference, and your account identifier. They do not carry the contents of your request, your research, anything a visitor typed into your page or app, your email address, your sign-in details, or the contents of any cookie or header. Where an email address appears inside an error message itself, we remove it before the report is sent.
Social publishing (Post for Me)When you schedule posts to your connected social accounts, we share with Post for Me, the provider that delivers them to the platforms: an identifier for your account with us, the text and media of each post, and which of your connected accounts it goes to. The provider holds the connection to your social accounts and sends back to us the account handles and usernames you connected and the engagement numbers for published posts. We share this only to publish the posts you schedule. Disconnecting an account removes the connection at the provider, and so does deleting your LaunchValid account.
Introduction addressesWhen an approved introduction partner meets someone in person and records their email address, we store that address for up to 90 days with the partner's name, send the person one note saying who asked to introduce them, and delete the record when it lapses unclaimed. Signing up with that address credits the partner; ignoring the note is a complete answer.
Other users you authorizeTeam members, collaborators, and marketplace counterparties according to your roles, publishes, and assignments. On a Business account team, the account owner can see the title and credit usage of projects paid from the shared pool, and can see a project's research only if the member who created it shares it
Programs you joinWhen you take part in a program such as an accelerator, its people can see your participation and the research funded from the program's shared credit pool, each according to their role. A program admin runs the program. Reviewers and monitors can see the materials for the founders they oversee, and a monitor may read research sections across a cohort but not your private notebook. In a live working session you have agreed to, the program admin and any monitors watching can see that session's thread in real time. See Section 6
Data room, page, and app viewersPeople you invite to a data room through a share link can see the documents you include. Visitors to your hosted pages and users of your built apps interact with what you publish. We record limited viewer and visitor information as described in Section 6
Legal and safetyWhen required by law, subpoena, or to protect rights, safety, and integrity of the Service
Business transfersIn connection with merger, acquisition, financing, or sale of assets (including entity rename or reformation), with notice where required

We do not share your full private research with marketplace sellers except what you publish in task scope or messages.


6. Data we process for founders (leads, app visitors, and applicants)

Some features let a founder collect information from other people: visitors to a hosted validation page, users of an app the founder builds, or applicants to a program the founder runs. When this happens, the founder is the controller of that information and LaunchValid is a processor acting on the founder's behalf. The founder decides what to collect and why. We process it to run the feature. This is separate from the information we collect about our own account holders, which the rest of this policy covers.

6.1 Hosted page leads

When a visitor submits the form on a founder's hosted validation page, we capture the email address, an optional name, and the other answers the form asks for, along with basic source information such as campaign tags and the referring page. We store a one-way hash of the visitor's IP address and browser for spam and rate limiting; we do not store the raw IP address. A copy may be mirrored to a Google Sheet in the founder's own Google Drive. We also keep bucketed, aggregated traffic counts (views, approximate unique visitors, and conversions by source) so the founder can measure demand. The founder owns and manages these leads.

6.2 App visitors

An app a founder builds with LaunchValid stores its data in a Google Sheet in the founder's own Google Drive. When a member of the public uses the app, the entries they submit are written to that Sheet, which the founder controls. We do not keep a copy of what was submitted. We do keep one record per submission so we can stop abuse and apply traffic limits, and that record holds which app and table it went to, a one-way hash of the sender's IP address and browser, a short value used to spot the same submission arriving twice, a spam score, and whether the write to the Sheet succeeded. It never contains the contents of the entry.

6.3 Program applicants

When someone applies to a program running on LaunchValid, we collect the applicant's name and email, their company and one-line description, the people they name as founders or teammates, and their free-text answers. We store a salted hash of the submitter's IP address for anti-abuse, never the raw IP. Applications may be scored with AI to help the program review them. The program is the controller of applicant information, and LaunchValid processes it for the program.

6.4 Viewer information in data rooms and share links

When a founder shares a data room through a share link, we record the email a viewer enters to open it, a one-way hash of their IP address (never the raw IP), a shortened browser string, and view counts and timestamps, so the founder can see who opened the room. The founder controls who is invited and can set a link to expire or revoke it at any time.

6.5 Retention and your rights for this data

We keep this information for as long as the founder or program keeps it in their account, and we delete or return it when they delete it or close their account, subject to short-lived backups that roll off on the schedule in Section 7. If you submitted your details to a founder's page, app, or program and want to access, correct, or delete them, contact that founder or program first, since they control the data. You can also reach us at hello@launchvalid.com and we will help route your request and support the founder in honoring it.


7. Data retention

We retain information while your account is active and as needed to provide the Service, resolve disputes, enforce agreements, and comply with legal obligations.

  • Account deletion: You may request account deletion; we will delete or anonymize personal data within 30 days except where retention is required (billing records, dispute logs, legal holds). Deleting your account also removes any social account connections you made, including the connection held at our publishing provider.
  • Project content: Deleted with account or per your deletion request, subject to backups that roll off on a schedule (typically 30 to 90 days).
  • Billing records: Retained as required for tax and accounting (often 7 years).
  • Unclaimed anonymous intake (one-time purchases): When a buyer pays without signing in, we hold the intake fields (idea, business type, brand information, team members, and any uploaded logo) against a claim token so the buyer can attach the workspace to their account. The claim link works for 30 days from the purchase. After that the link stops working and nobody can open the workspace with it, but we keep the intake and the document it produced, because the purchase was paid for and never collected and the buyer may still write to us for it or dispute the charge with their bank. We do not erase it on a timer. If you want it gone sooner, email hello@launchvalid.com from the address you paid with and we will delete it, and a teammate listed on an unclaimed intake can have their own details removed at any time using the route in Section 8.5. The accounting and payment record needed for tax and refund handling is retained under our billing retention rule above.
  • Project design lock: A project's design lock (brand color palette, typography choices, and design mood carried across the project's deliverables) is retained for the lifetime of the project so that later regenerations continue to match. It is deleted when the project is deleted or when you reset the lock from the project settings.

8. Your rights and choices

8.1 All users

  • Access and correction: update profile in account settings; contact us for other corrections.
  • Deletion: request deletion via hello@launchvalid.com.
  • Marketing opt-out: unsubscribe link in marketing emails.
  • Cookies: manage browser settings; some features require essential cookies.

8.2 California residents (CCPA/CPRA)

If you are a California resident, you may have the right to:

  • Know categories and specific pieces of personal information collected.
  • Delete personal information (subject to exceptions).
  • Correct inaccurate personal information.
  • Opt out of sale or sharing for cross-context behavioral advertising. We do not sell or share personal information for cross-context behavioral advertising.
  • Limit use of sensitive personal information where applicable.
  • Non-discrimination for exercising privacy rights.

Submit requests: hello@launchvalid.com with subject “Privacy Request.” We will verify your identity before responding.

Authorized agents: May submit requests with proof of authorization.

8.3 Other US state privacy laws

Residents of Colorado, Virginia, Connecticut, Utah, and other states with privacy laws may have similar rights. Contact us at hello@launchvalid.com.

8.4 European Economic Area / UK (if applicable)

If we offer the Service to individuals in the EEA or UK, we will provide lawful bases, international transfer mechanisms, and rights under GDPR as required. At MVP launch we are English-first and USA-focused; contact us before relying on EU-specific features.

8.5 Removing yourself if a founder listed you (no account needed)

If a founder listed you as a teammate on a one-time purchase (see Section 2.4) and you want your details removed, you do not need a LaunchValid account. Go to launchvalid.com/privacy/team-member-opt-out, enter the email address (or LinkedIn URL) the founder used for you, and confirm. The page looks up every project that carries a matching entry, removes your name, role, LinkedIn URL, and one-line experience note from each, and confirms the removal on screen. No sign-in is required. You may also email hello@launchvalid.com with subject "Team-member opt-out" and we will process the same removal by hand.

The opt-out removes your personal information from every project we can find you in. It does not affect any prior copy a founder has already downloaded or shared outside our Service; if you have shared professional information publicly (for example on LinkedIn) it remains public independently of us.


9. Cookies and analytics

We use:

  • Essential cookies: session cookie (httpOnly), session security, load balancing. These are required to run the Service and are always on.
  • Analytics cookies: product analytics (e.g. PostHog) to understand feature usage in aggregated form. Non-essential; loaded only after you consent.
  • Advertising cookies: where enabled, marketing/measurement pixels (e.g. Meta, LinkedIn, Reddit) to measure and improve our advertising. Non-essential; loaded only after you consent.
  • Google Consent Mode signals: our Google measurement tag (Google Analytics and Google Ads) loads on every page, but it reads and writes advertising and analytics cookies only after you consent. Until then it sends cookieless, non-identifying signals (no cookies and nothing that identifies you personally, with IP and page data redacted) that Google uses to estimate overall, aggregated ad and site performance. These signals carry no personal data and cannot identify you.
  • Enhanced Conversions (Google Ads): if you accept marketing cookies and then sign up or make a purchase, a hashed, irreversible version of your email address may be sent to Google to match that action to the ad you clicked. The value is hashed before it is sent, either in your browser, or on our server for a purchase you made before signing in (where your email never reaches the browser). This runs only with your consent, and never if you reject non-essential cookies.

Consent: on your first visit we show a cookie banner. Cookie-setting analytics and advertising tags do not load unless you choose "Accept." If you choose "Reject non-essential," those cookies never run; the Google tag stays in its cookieless, non-identifying mode described above (you can opt out of that too via your browser's Do Not Track / ad settings and Google's own controls). You can change your choice at any time by clearing the lv_cookie_consent cookie in your browser (which re-shows the banner). Essential cookies cannot be disabled without breaking sign-in and core functionality.


10. Security

We use administrative, technical, and organizational measures appropriate to the nature of the data, including encryption in transit (HTTPS), access controls, and vendor security reviews. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

Report security concerns to hello@launchvalid.com.


11. Children

The Service is not directed to children under 18. We do not knowingly collect personal information from children. Contact us if you believe a child has provided data.


12. International users

LaunchValid is operated from the United States. If you access the Service from outside the US, you consent to processing and storage in the US and other countries where our providers operate, which may have different data protection laws.


13. Third-party links

The Service may link to third-party sites (Stripe, Google, seller portfolios). Their privacy practices are governed by their own policies.


14. Changes to this Privacy Policy

We may update this Privacy Policy. We will post the revised version with a new “Last updated” date and provide additional notice for material changes where required.


15. Contact

AmpFi App LLC d/b/a LaunchValid
Privacy inquiries: hello@launchvalid.com
Website: https://launchvalid.com

For Terms of Service, see the Terms of Service.