Launchology

    Privacy Policy

    Last updated: August 2026

    This policy explains what personal data Launchology collects, why, what we do with it, and what rights you have. It applies to our website, our platform and all our services.

    We have tried to make it readable rather than defensive. If anything is unclear, email hello@launchology.co and we will explain.


    1. Who we are

    Launchology Ltd is the data controller for the personal data described in this policy. That means we decide what data is collected and why, and we are accountable for it.

    Controller

    Launchology Ltd

    Registered in

    England and Wales

    Company registration number

    17359147

    Registered office

    71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

    Data protection contact

    hello@launchology.co

    ICO registration reference

    We process personal data in accordance with the UK GDPR (as amended by the Data (Use and Access) Act 2025), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003.


    2. What we collect

    2.1 Information you give us

    Category

    Examples

    Account data

    Name, email address, password (stored hashed, never in plain text).

    Profile data

    Job role, industry, location, company name, stage of business, bio, profile photo.

    Startup data

    Information about your business that you enter to tailor the AI Co-Founder and investor matching — sector, stage, funding target, traction, business model.

    Payment data

    Billing name, billing address, country, and the last four digits and expiry of your card. We never see or store your full card number — see section 6.

    Learning data

    Courses enrolled on, lesson and module progress, quiz and exercise responses, completion records, certificates.

    AI Co-Founder data

    The prompts and questions you submit, and the responses generated.

    Investor Database activity

    Searches you run, records you view, matches generated for you.

    Mentoring data

    Session bookings, notes taken during or after sessions, and recordings where you have agreed to them.

    Community and user content

    Posts, comments, replies, uploaded files.

    Communications

    Emails and messages you send us, and support requests.

    Marketing preferences

    Whether you have subscribed to or opted out of our emails.

    2.2 Information we collect automatically

    • Device and connection data: IP address, browser type and version, operating system, device type, screen size, language and time zone.

    • Usage data: pages viewed, features used, time spent, referring page, clicks, and the dates and times of your visits.

    • Cookies and similar technologies: see our Cookie Policy.

    2.3 Information from other sources

    • Payment and subscription status from Stripe.

    • Email engagement — opens and clicks — from our email provider.

    • Advertising data from Meta and Google where you arrive via one of our ads, subject to your cookie consent.

    • Publicly available business information, such as a company website or a public LinkedIn profile, where relevant to providing our services.

    2.4 Special category data

    We do not ask for, and do not want, special category data — information about health, race or ethnicity, religion, political opinions, trade union membership, sex life or sexual orientation, genetic or biometric data — or information about criminal convictions.

    Please do not enter such information into the AI Co-Founder, community posts or any free-text field. If you do, you are choosing to make it public or to share it with us, and we may delete it.


    3. Why we process your data, and our lawful basis

    Under UK GDPR we must have a lawful basis for everything we do with your data. Here is ours, in full.

    What we do

    Why

    Lawful basis

    Create and administer your account

    To let you use the Platform

    Contract — necessary to provide the service you signed up for

    Deliver courses, the Accelerator, templates and track your progress

    To provide what you paid for

    Contract

    Operate the AI Co-Founder

    To answer your questions and tailor guidance

    Contract

    Provide the Investor Database and smart matching

    To provide what you paid for

    Contract

    Schedule and deliver Accelerator Plus mentoring

    To provide what you paid for

    Contract

    Take payments, issue invoices, manage subscriptions

    To get paid and meet accounting rules

    Contract, and legal obligation for record keeping

    Send service emails (receipts, password resets, changes to terms, session reminders)

    So you can use the service and know what is happening

    Contract

    Provide customer support

    To answer you

    Contract

    Send marketing emails to customers about our own similar services

    To tell you about relevant products

    Legitimate interests, relying on the “soft opt-in” under PECR — you can opt out at any time

    Send marketing emails to people who are not customers

    To tell you about Launchology

    Consent

    Analytics and product improvement

    To understand what works and fix what does not

    Consent where cookies are used; otherwise legitimate interests in improving our service

    Advertising and measuring ad performance

    To reach founders who would benefit, and not waste money

    Consent

    Prevent fraud, abuse, login sharing and content piracy

    To protect the business and paying members

    Legitimate interests in protecting our property and our members

    Keep the Platform secure, back up data, investigate incidents

    To keep your data safe

    Legitimate interests, and legal obligation for security

    Use testimonials, case studies, your name or logo in marketing

    To show what we do

    Consent, withdrawable at any time

    Respond to legal claims, regulators or law enforcement

    To comply and defend ourselves

    Legal obligation, and legitimate interests in establishing or defending legal claims

    Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and concluded it is not. You may ask us for details of that assessment, and you may object — see section 10.

    Where we rely on consent, you may withdraw it at any time. Withdrawing consent does not affect processing carried out before you withdrew it.


    4. The AI Co-Founder — how your data is handled

    Because this is the part people most often ask about, we set it out separately.

    How a request travels. When you use the AI Co-Founder, your prompt and relevant context from your startup profile are sent from our platform to the Lovable AI Gateway, which forwards the request to the AI model best suited to the task and returns the response to us. Lovable acts as our processor; the model providers act as sub-processors.

    Which models we use. We currently use models from OpenAI and Google, selected automatically depending on the task — a large model for conversation and guidance, smaller and faster models for tasks such as tidying up a profile field or interpreting an investor search. Both are reached through the Lovable AI Gateway rather than directly.

    Your prompts are not used to train AI models. Our agreement with Lovable expressly prohibits the use of customer personal data for training, retraining or fine-tuning AI models, and that obligation carries down to the model providers they route to.

    How long anything is kept. We retain your conversation history on our own systems so you can refer back to it and so the tool can maintain context — you can delete individual conversations from within the tool, and everything is deleted with your account. Our AI providers hold prompts and responses only transiently, for the period needed to generate a response and to monitor for misuse, after which they are deleted.

    Where it is processed. Primarily in the United States. See section 7 for the safeguards that apply.

    Please do not enter other people’s personal data, confidential information belonging to someone else, payment details, or login credentials.

    If we change provider, we will update this policy before the change takes effect.

    The AI Co-Founder does not make any decision about you that produces a legal or similarly significant effect. See section 12.


    5. Who we share your data with

    We do not sell your personal data. We never have and we will not.

    We share data with the service providers below, each of which processes it on our instructions under a written contract that meets UK GDPR requirements.

    Provider

    What they do

    Where data is processed

    Vercel

    Hosting and content delivery for launchology.co — every page request passes through it

    EEA and USA

    Supabase

    Database, user authentication, file storage and the serverless functions behind the platform

    EEA and USA

    Lovable

    Development and build platform, the AI gateway described in section 4, and delivery of transactional emails such as sign-up confirmations and password resets

    EEA and USA

    OpenAI

    AI model provider for the AI Co-Founder — reached as a sub-processor through Lovable

    USA

    Google

    AI model provider (Gemini) for the AI Co-Founder and investor search — reached as a sub-processor through Lovable

    EEA and USA

    Stripe

    Payment processing, subscription billing, invoicing

    UK, EEA and USA

    Loops

    Marketing and lifecycle emails, and email engagement tracking

    USA

    Calendly

    Booking Accelerator Plus mentoring sessions

    USA

    Google (Google Meet)

    Delivering Accelerator Plus mentoring sessions

    EEA and USA

    Google (Google Analytics 4)

    Website and product analytics

    EEA and USA

    Meta Platforms (Meta Pixel)

    Advertising measurement and audience building

    EEA and USA

    We review this list when we change providers. If we add a new provider that receives your personal data, we will update this policy in line with section 15.

    We may also disclose personal data:

    • to our professional advisers — accountants, lawyers, insurers — where necessary and under a duty of confidence;

    • to law enforcement, regulators or courts where we are legally required to, or to establish or defend legal claims;

    • to a buyer or successor if we sell or restructure the business, in which case we will tell you and this policy will continue to apply until replaced.

    Guest contributors and mentors may see your name, profile and questions where you interact with them. They are bound by confidentiality.

    Community areas: anything you post is visible to other members of that community. Please treat it as public.


    6. Payment data

    Card payments are processed by Stripe, a PCI-DSS Level 1 certified payment processor. Your card details are submitted directly to Stripe and never pass through or get stored on our systems. We receive only the information needed to identify a payment: your billing details, the card type, the last four digits, the expiry date, and whether the payment succeeded.

    Stripe processes your data as an independent controller for its own fraud-prevention and regulatory purposes. See stripe.com/privacy.


    7. International transfers

    Some of our providers are based outside the UK, principally in the United States. Where personal data is transferred outside the UK, we make sure one of the following applies:

    • the country has UK adequacy status (this covers the EEA, and the USA where the provider is certified under the UK Extension to the EU–US Data Privacy Framework);

    • the transfer is covered by the UK International Data Transfer Agreement (IDTA), or the International Data Transfer Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment;

    • another lawful safeguard under Chapter V of the UK GDPR applies.

    The providers to whom we currently transfer personal data outside the UK are Vercel, Supabase, Lovable, OpenAI, Google, Stripe, Loops, Calendly and Meta, as set out in section 5.

    You can ask us for a copy of the safeguards in place for any specific transfer by emailing hello@launchology.co.


    8. How long we keep your data

    Data

    Retention period

    Account, profile and startup data

    For as long as your account is open, then 24 months after closure — so you can return without losing your progress

    Learning progress and certificates

    As above; certificates retained 6 years so we can re-issue them

    AI Co-Founder conversation history

    For as long as your account is open, or until you delete a conversation; then deleted with your account

    AI Co-Founder prompts held by our AI providers

    Held transiently to generate the response and monitor misuse, then deleted by them

    Mentoring bookings, notes and recordings

    Booking records 12 months; notes and recordings 12 months after the session

    Community posts

    Until you delete them or your account closes; we may retain anonymised copies where a thread would otherwise become unreadable

    Payment, invoice and tax records

    6 years from the end of the relevant financial year — required by HMRC and the Companies Act 2006

    Marketing contact data and consent records

    Until you unsubscribe, then 24 months on a suppression list so we do not accidentally contact you again

    Support correspondence

    24 months

    Website analytics data

    14 months

    Security and access logs

    12 months

    Records relating to a legal claim or dispute

    Until the matter is resolved and any limitation period has expired

    At the end of these periods we delete the data or irreversibly anonymise it. Anonymised, aggregated statistics — which cannot identify you — may be kept indefinitely.

    You can ask us to delete your data sooner — see section 10.


    9. How we keep your data safe

    We use appropriate technical and organisational measures, including:

    • encryption in transit (TLS) and at rest;

    • passwords stored using industry-standard one-way hashing;

    • access to personal data restricted to those who need it, on a least-privilege basis;

    • multi-factor authentication on our administrative systems;

    • regular backups, and reputable infrastructure providers with recognised security certifications;

    • reviewing supplier security before we engage them.

    No system is completely secure and we cannot guarantee absolute security. Please use a strong, unique password and do not share your login.

    If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it. Where the risk to you is high, we will tell you without undue delay.


    10. Your rights

    Under UK data protection law you have the right to:

    Right

    What it means

    Be informed

    Know how we use your data — this policy

    Access

    Get a copy of the personal data we hold about you

    Rectification

    Have inaccurate data corrected or incomplete data completed

    Erasure

    Have your data deleted, where there is no overriding reason for us to keep it

    Restriction

    Have us pause processing while a dispute about accuracy or legitimacy is resolved

    Portability

    Receive data you gave us in a structured, machine-readable format, or have it sent to another provider

    Object

    Object to processing based on legitimate interests. You can object to direct marketing at any time and we must stop

    Withdraw consent

    Withdraw consent at any time where we rely on it

    Not be subject to automated decision-making

    See section 12

    To exercise any of these, email hello@launchology.co. Putting “Data request” in the subject line helps us route it quickly, but we will act on any request however it reaches us.

    We will respond within one month. We may extend this by up to two further months for complex requests, and we will tell you if we need to. We may ask you to verify your identity. There is no charge unless a request is manifestly unfounded or excessive.

    You can also manage a lot of this yourself: update your profile in Account Settings, unsubscribe using the link in any marketing email, and change cookie preferences from the cookie banner link in our footer.


    11. Complaints

    If you are unhappy with how we have handled your personal data, please tell us first at hello@launchology.co with “Data complaint” in the subject line. We will acknowledge within 5 working days and respond substantively within 30 days.

    You also have the right to complain directly to the UK supervisory authority:

    Information Commissioner’s Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Helpline: 0303 123 1113 ico.org.uk/make-a-complaint

    We would rather have the chance to put it right first, but you do not have to come to us before going to the ICO.


    12. Automated decision-making and profiling

    We use automated processing in two places:

    • Investor smart matching, which ranks investors against your startup profile;

    • AI Co-Founder responses, generated from your prompts and profile.

    Both are suggestions and information only. Neither makes a decision that produces a legal effect or similarly significantly affects you, and a human is always the decision-maker — you. We do not use automated decision-making for credit, employment, pricing or eligibility.

    We do not carry out behavioural profiling for advertising beyond the standard advertising cookies described in our Cookie Policy, which run only with your consent.


    13. Children

    Our services are for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has given us personal data, email hello@launchology.co and we will delete it.


    14. Third-party sites

    Our website and Content link to third-party sites and tools. This policy does not cover them. Please read their privacy policies before giving them your data.


    15. Changes to this policy

    We may update this policy. The “Last updated” date at the top always shows the current version.

    If we make a material change — for example a new purpose for processing, a new category of recipient, or a change to your rights — we will tell you by email or in-app notice at least 30 days before it takes effect, and where the change requires your consent we will ask for it.


    16. Contact

    For anything relating to privacy or your data:

    Launchology Ltd 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom Registered in England and Wales, company number 17359147 hello@launchology.co