Privacy
WE COLLECT ALMOST NOTHING, AND SAY SO IN PUBLIC
This notice explains what launchduels (Secure Success Launch LLC, 306 W Redwood St, Ste 201, Baltimore, MD 21201, United States) collects and why. Short version: the Board runs on first-party data - no ad trackers, no profiling, no data sales, ever. One temporary third-party diagnostic runs during the launch period, disclosed below to the byte and deleted when the board stabilizes.
WHAT WE COLLECT
Account email - for founders who sign in by magic link; also the login identity itself.
Listing content - startup name, tagline, optional domain, and pilot terms you submit; this is public by design.
Claim content - your name, email, optional website, and the one line describing where you’d run the pilot; delivered to the founder, stored so they can answer and so the Rules (R-10/13) can be enforced.
Cohort joiner data - on the indie board, if you join a founding cohort: your email is stored only as a SHA-256 hash (the Board never keeps the address itself), with an optional display name and one-time verification codes that expire within a day. This is what lets the founder prove the cohort is real.
Founder integration keys - if you connect your own Stripe or other provider account so the machine can verify your revenue, the restricted key is stored encrypted and can be removed from your console at any time; the machine reads metrics only - it never transacts, and never sees amounts.
Spectator emails - if you subscribe for the weekly digest or a seat-watch alert, your email and the interests you picked. One click in any email removes you entirely - the row is deleted, not muted.
Commerce and operator messages - if you send a sponsor inquiry, a concierge request, or a message through the feedback form, we store the email you gave with it (your reply address, optional on the feedback form) and what you wrote, so a human can answer you.
Hashed device identifiers - to enforce one-vote-per-person (R-07) and count the funnel. Device ids are random values in a first-party cookie, stored in our database only as SHA-256 hashes. We cannot reverse them, and we don’t fingerprint anything else.
Operational records - the audit trail. Every seat change is recorded with the rule that caused it. This is the Board’s public trust ledger and it is kept indefinitely, in minimized form (actor type, action, rule, subject reference).
WHAT WE DON’T DO
No advertising scripts. No profiling. No selling or renting data. We use Sentry to monitor for software errors - it receives technical failure data (stack traces, request metadata) with emails scrubbed, never browsing behavior, and never used for advertising.
Temporary launch diagnostics. During the launch evaluation period we also run PostHog - server-side event mirroring plus anonymous session playback in your browser - so issues get fixed from evidence. It asks first: the consent banner offers the choice, nothing loads from PostHog until you accept, and decline is honored permanently - no script, no cookie, no event leaves your browser, and the server-side mirror skips declined visitors entirely. If you accept, it sees event names, a hashed device id, board context, and a masked recording of what the page did: everything you type is masked, and the tool is never identified to any account - no email, no user id. No advertising, no profiling, no data sales. When the board stabilizes the tool is removed - one configuration key is unset and nothing loads from it again: no script, no cookie, no data.
RETENTION & DELETION
Forever means the record, not the person (R-51). The wall is forever (R-14), so what an erasure removes is your identifying details - never the historical fact. A graduated listing keeps its name, dates, and outcome; a founder who requests erasure has contact and account data removed while the anonymized listing stands. A cohort’s historical size is frozen at graduation and never recomputed, so removing a member years later cannot falsify a graduated record. A member of a cohort whose outcome is not yet decided may have identity fields removed at once, but the roster row stands until the contest resolves.
Enforcement records are the exception. Flags, benches, and ban history (R-12, R-17) are retained while the Board relies on them, under the legal-claims basis; erasure of an enforcement record is a human decision, made and answered in writing, never automatic.
Claimant data is retained while the related listing is active plus a reasonable enforcement window; you may request deletion of your claim data at any time. The audit trail preserves the fact that a seat event occurred (rule and reference, not your content) and identifies actors only by hash. Founder account data can be deleted when no active listing exists. Alumni listings persist by design (R-14); a listed founder may request removal of contact details from the public page.
Requests go to privacy@launchduels.com and are answered within 30 days. Every granted erasure is logged in the audit trail as a privacy event citing R-51.
COOKIES
Three first-party cookies only: a session cookie (sign-in), a device cookie (vote deduplication, R-07), and an analytics cookie (hashed, for /pulse counts). The session and device cookies are strictly necessary - the machine cannot run without them - so they are set without asking, like every strictly-necessary cookie everywhere. The launch-diagnostics cookie is the exception: the consent banner asks, and the answer binds the code. Nothing loads from PostHog until you accept; decline means no script, no cookie, and no server-side mirroring - ever. The choice is stored in your browser (localStorage, not a cookie) and you can review or change it at any time below. When the launch period ends, the tool and its cookie are removed together.
YOUR RIGHTS
Access, correction, deletion, and objection - email privacy@launchduels.com. Weekly digest emails include a one-click unsubscribe. Depending on your jurisdiction (e.g., EU/UK GDPR, California CPRA) you may have additional rights; we honor them all.
INTERNATIONAL & CHILDREN
Data is processed by our service providers - Vercel (hosting), Neon (database), Upstash (rate limiting), Resend (email delivery), Stripe (payments), Sentry (error monitoring), and the launch-diagnostics tool disclosed above - some of which may be outside your country. Each receives only what its function requires. The Board is not directed at children under 16, and we don’t knowingly collect their data.
Last updated: 2026-09-27.