—Privacy & Data Ethics

Privacy Policy

Last updated October 1, 2026

1. Your accounts stay in your browser

Submission agencies usually ask for your passwords or run your accounts from their own servers. LaunchDistro does neither.

LaunchDistro is an MCP server your own AI app (Claude, Cursor, Codex and others) connects to. It gives your agent the plan and each directory's playbook; your agent fills the forms in your own browser, where you watch and approve every submit. Sign-ins, passwords, cookies and verification codes pass between your browser and the directory only. Nothing is ever submitted from our servers.

2. Information we collect

We collect only what the service needs to work:

  • Account Credentials: Your email address and cryptographically verified session token managed via Better-Auth.
  • AI app connections: For each AI app you connect, a one-way hash (SHA-256) of its access token, the name you give it and when it last called us. We never store the token itself, and we collect no hardware or device identifiers.
  • Submission records: What your agent records through LaunchDistro for each directory: its status, the confirmation and listing URLs, timestamps, the short note your agent writes (what is left to do, or what the directory answered) and the results of our link checks on the public listing. They are shown only to you, in your dashboard.
  • Directory reports: When a directory shows something its playbook did not say (a price, an approval time, a badge rule), your agent may report it to us in the page's own words, with the page's URL. Reports are stored with your account in case we need to ask about one.
  • Directory suggestions: When you recommend a directory we do not list, your agent sends us its site, its name and why you recommend it. We read suggestions grouped by site, without your name, product or account, to decide which directories to check and add. Nothing is submitted there on your behalf.
  • Screenshot Receipts: Screenshots of confirmation pages uploaded by our former local app, before September 27, 2026. Nothing uploads new ones. Those already stored are shown only to you, signed in to your dashboard, and can be deleted at any time.
  • Product Profile: The product facts you save in the dashboard (name, URLs, descriptions, contact email) so the agent can fill directory forms with them.

How we use notes and reports to improve playbooks. We read submission notes and directory reports grouped by directory, to find where a playbook is wrong or out of date (for example, when several agents note that a directory's free listing has no link). They are never shown to other users, and never with your name, product or account. A playbook changes only on what we confirm ourselves, on the directory's own pages or on a real submission; nothing your agent writes is copied into a playbook as it is.

3. Information we never collect or store

To preserve absolute security for your startup, our servers never request, log, or store:

  • Your personal or third-party directory passwords.
  • Browser session cookies, auth tokens, or 2FA recovery secrets.
  • Credit card or payment account numbers (handled entirely by Dodo Payments).
  • Your source code. Your agent reads your repository on your machine; we receive only what it saves to your product profile.

4. Third-party infrastructure and processors

We partner with industry-leading infrastructure providers to operate the service:

  • Dodo Payments: Our Merchant of Record for payments, subscription billing, invoicing, and VAT/sales tax compliance.
  • Cloudflare: DNS routing, edge CDN caching, and DDoS mitigation.
  • Our server: Your account, AI app connections, product profile and submission records are kept in a PostgreSQL database on our own server.
  • Cloudflare R2: Private object storage for screenshot receipts. The storage bucket is not publicly accessible; receipts are served only through your signed-in dashboard.
  • Resend: Sends the account emails (confirming your address, resetting your password). It receives your email address, your first name and the email's content, and keeps your address on our contact list. Product updates are sent only if you ticked “Email me product updates” or turned them on in Settings; every one has an unsubscribe link, and Settings turns them off. Deleting your account removes you from the list.
  • Google (Gemini API): Only if you use “Fill from website” in your product profile, the public text of the page you enter is sent to Gemini to draft your descriptions.
  • Ahrefs Web Analytics: Counts visits to our public pages (the page, the site you came from, your country and type of device) without cookies and without identifying you. It does not run in your dashboard or on the password reset page.
  • Google Analytics: Counts visits to our public pages (the page, the site you came from, your country and type of device). It sets cookies only if you press Accept in the banner; until then it runs with every storage type switched off and stores nothing on your device. We turn off its advertising features. Your choice is kept in this browser only. to withdraw it. It does not run in your dashboard or on the password reset page.
  • Google and GitHub sign-in: Only if you choose to sign in with them; we receive your name, email address and avatar.

5. Data retention and deletion rights

We keep your data, including screenshot receipts, for as long as your account exists, on a free plan or a paid one. Receipts are proof of your submissions, and directories sometimes publish listings months later, so we do not expire them while you still use your account.

  • Delete one receipt: any screenshot can be deleted from the Submissions page of your dashboard. It is removed from storage immediately.
  • Delete your account: from Settings, at any time. This immediately removes your account, AI app connections, product profiles, submission records and notes, directory reports and suggestions, and every screenshot receipt from storage, and cancels your subscription first so you are not charged again.

You can also ask us to do either by emailing contact@launchdistro.com. Listings you already published on third-party directories are controlled by those sites; deleting your LaunchDistro account does not remove them.

6. GDPR & CCPA compliance

Under the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), you have the right to access, export, rectify, or erase your personal data, as well as the right to restrict or object to its processing. We do not sell or monetize personal data under any circumstances.

7. Contact our privacy team

If you have any questions regarding this Privacy Policy or how we handle your data, contact our Data Protection Officer at contact@launchdistro.com.

Your next 10 directory submissions are free.

Add it to Claude or Cursor, describe your product once, and watch the first form fill itself.