LaunchLint
MCPFree toolsAcademyPricing
DEENESFRITCreate account / Login

Legal

Privacy policy

What personal data LaunchLint processes, why it is needed, and the rights available to you.

Effective date: 2026-07-24

ImprintPrivacyTermsWithdraw a contractCancel contracts here
01

Controller

LaunchLintRene DresselIm Höfchen 2, 53809 Ruppichteroth, Deutschlandsupport@launchlint.app
02

Sources and required information

We receive data from you, connected Google and GitHub services, and Link or Stripe for payments. Required fields are marked. Without account and contract data we cannot provide an account or paid plan; project and store data are needed only when you use the related review.

03

Account, sign-in, and connections

Email accounts involve name, email, verification status, password hash, sessions, and security events. Google or GitHub sign-in supplies the authorized account ID, email, verification status, name, and optional profile image. We do not request Gmail, Drive, contact, or calendar access.

For the GitHub App we process installations, account names, selected repositories, and read-only permissions. Tokens and sessions are protected server-side and removed when revoked or the account is deleted, unless retention is required.

04

App projects, reviews, and connector

Reviews process selected repository or ZIP files, paths, dependencies, configuration, evidence, results, and manual task status. Code is never installed, built, or executed, and secret-like values are masked.

The connector processes OAuth clients and scopes, connection times, a pseudonymous workspace identifier, prepared file lists, confirmed uploads, and tool-call records. Upload requires confirmation. Package ecosystem, name, and version may be sent to the public OSV API for vulnerability checks, but source code is not.

LaunchLint currently uses no external AI model to generate review findings and does not provide project files for AI training.

05

Store information and sharing

Store text, privacy and support URLs, review credentials, screenshots, and submission data are stored and reviewed when provided. Expiring share links store a hashed token, expiry, locale, last access, and optional agency branding.

06

Payments, subscriptions, and refunds

For Managed Payments, Link is merchant of record. Link and Stripe independently process payment method, billing address, tax, and transaction data and send receipts. LaunchLint stores customer, Checkout, Payment Intent and Subscription references, plan, status, period, limits, refund requests, and webhook events, but no full card or bank data.

For purchases not covered by Managed Payments, the roles shown at Checkout apply. Contract and payment records are processed for performance and statutory tax and evidence duties.

07

Communications and legal declarations

We process support messages and technical details you submit. Resend sends verification, password reset, security, contract, withdrawal, and cancellation messages.

Withdrawal and cancellation records include name, email, contract reference, declaration content, date and time, confirmation status, and handling status so we can act and prove receipt.

08

Usage, security, and local storage

For authentication and security, we process hashed IP-derived request identifiers, timestamps, errors, and access logs. Non-reversible HMAC markers derived from verified email, OAuth or GitHub account, and project limit repeated free use.

Essential session cookies are used. A random journey ID is stored in sessionStorage; internal events may include locale, source category, device type, plan, and account ID when signed in. LaunchLint creates no personalized advertising profiles and uses no advertising cookies.

Public information, tool, and Academy pages embed StartupBar for mutual referrals between software startups. Loading the widget connects your browser to startupbar.co and necessarily transmits connection data such as IP address, browser characteristics, and referrer. StartupBar measures anonymous impressions and clicks and states that its isolated widget sets no visitor cookies. The widget is not loaded in account, dashboard, upload, payment, or legal areas.

09

Purposes and legal bases

  • GDPR Art. 6(1)(b): account, contract, reviews, connector, support, and contract management.
  • Art. 6(1)(c): tax, commercial, evidence, and consumer-law duties.
  • Art. 6(1)(f): security, abuse prevention, troubleshooting, internal product and reach measurement, mutual startup referrals, and legal defense.
  • Art. 6(1)(a): only where optional consent is expressly requested.
10

Recipients

  • Hetzner Online GmbH: hosting, database, Redis, and S3-compatible object storage in the EU
  • Google Ireland Limited: user-initiated authentication and provision of basic account profile data
  • GitHub, Inc.: customer-initiated read-only repository access
  • Stripe Payments Europe, Ltd. and Link: Managed Payments, Checkout, subscriptions, taxes, receipts, and payment status
  • Resend, Inc.: transactional email for verification, password reset, withdrawal, and cancellation
  • Open Source Vulnerabilities (OSV): known-vulnerability lookup using package name and version
  • StartupBar (startupbar.co): mutual startup referrals and anonymous impression and click measurement on public pages
11

International transfers

GitHub, Google, Stripe/Link, Resend, and OSV may process data outside the EEA. Where no adequacy decision applies, providers rely in particular on EU Standard Contractual Clauses and supplementary safeguards.

12

Retention

  • Temporary ZIP uploads: normally no later than 24 hours.
  • Technical logs: generally 30 days.
  • Free-use prevention markers: no more than 180 days.
  • Unconfirmed connector uploads and short-lived receipts: until their technical expiry.
  • Account, projects, results, and store data: until account deletion or earlier expiry of purpose.
  • Contract, withdrawal, cancellation, and legal evidence: generally until statutory limitation expires; mandatory longer periods remain.
  • Link/Stripe payment and tax records follow their legal periods. Backups rotate and are used only for recovery.
13

Your rights and authority

Subject to the GDPR, you may request access, correction, deletion, restriction, portability, or object, and withdraw consent prospectively. You may object to legitimate-interest processing for reasons relating to your situation.

Data export and account deletion are available in the dashboard. Contact support@launchlint.app. You may also complain to a competent authority, including the North Rhine-Westphalia data protection authority at poststelle@ldi.nrw.de or www.ldi.nrw.de.

14

Automated decisions

LaunchLint makes no solely automated decision producing legal or similarly significant effects. Scores are technical prioritizations and do not decide a contract or store approval.

15

Security and changes

We use encrypted transport, access controls, server-side keys, read-only repository access, rate limits, separated storage, and no execution of third-party code. No system is absolutely secure.

We update this policy for material processing or legal changes and provide appropriate notice of significant updates.