← Back to login

Privacy Policy

Last updated: August 10, 2026

This policy explains how AppLaunchFlow collects, uses, shares, and protects information when you use the service, including its AI connectors.

1. Information we process

We process account details, billing and subscription status, project metadata, prompts and instructions, uploaded screenshots and media, generated creative content, product usage and diagnostic data, and support communications. When you connect an AI client, we also process the connector client identifier, approved permissions, token hashes, expiry times, and recent token-use timestamps. We do not store plaintext connector access or refresh tokens.

2. How we use information

We use information to authenticate you, provide and secure AppLaunchFlow, generate and edit content you request, process payments, prevent abuse, troubleshoot errors, provide support, and improve service reliability. We do not sell personal information or use private project content for unrelated advertising.

3. AI connectors

If you authorize ChatGPT, Codex, or another compatible MCP client, that client can invoke the permissions displayed on the consent screen and receive the project data needed to complete your request. When you also approve the identity and email permissions, the client can receive your AppLaunchFlow account identifier, email address, and whether that email is verified so workspace administrators can apply domain-based access controls. The client provider processes data under its own terms and privacy policy. Only connect clients you trust, review their actions, and disconnect them when access is no longer needed.

4. Service providers and transfers

We use vetted providers for hosting, databases, authentication, payment processing, email, analytics, error monitoring, and AI generation. They process data on our behalf under contractual safeguards. Depending on the provider and feature, data may be processed outside your country; we use legally recognized transfer safeguards where required.

5. Retention and security

We retain account and project data while your account is active and as needed for the service, legal obligations, dispute resolution, and security. OAuth authorization codes expire after ten minutes, access tokens after one hour, and refresh tokens after thirty days unless revoked earlier. We use encryption in transit, access controls, hashed connector tokens, rotating refresh tokens, and logging designed to avoid secrets. No system can guarantee absolute security.

6. Your choices and rights

You can edit or delete project content, disconnect AI connectors to revoke their tokens, and contact us to request access, correction, deletion, restriction, portability, or objection where applicable. You may also have the right to complain to your local data-protection authority. Some information may be retained where legally required.

7. Cookies and analytics

We use necessary cookies for sign-in, security, and core service functionality. We may use analytics to understand product usage and diagnose performance. Where law requires it, non-essential technologies are subject to the choices presented to you.

8. Changes and contact

We may update this policy as the service changes. We will update the date below and provide additional notice when required. Questions or privacy requests can be sent to support@applaunchflow.com.