Legal
Privacy notice
How AppLauncher handles personal data. Last updated 21 September 2026.
Who we are
AppLauncher is the curated app launch directory at applauncher.dev. For the purposes of the UK GDPR and the EU GDPR we are the controller of the personal data described below. The legal entity and its registered address are being finalized and will be named here before paid submissions open. Until then, reach us through the contact form, which is monitored by the same people who run the directory.
What we collect, and why
When you submit an app
We collect the submitter email address, the maker name, any social handles and short bio you choose to add, and everything about the app itself: name, tagline, descriptions, URL, platforms, store links, install command, repository, screenshots, features and the rest. We use it to review the submission, publish the listing and contact you about it. Your email address is not published. The maker name, handles and bio are published on the listing, because that is what you are adding them for.
We also generate a magic-link token tied to your email. It verifies the address, submits the listing and then serves as your permanent edit link. Anyone holding that link can edit your listing, so treat it like a password. Pages reached through it are never indexed.
When you join a waitlist
We store the email address, which page it came from, an optional app URL and note, and a truncated one-way hash of your IP address. We use it for one thing: telling you when submissions or a tool open. There is no drip sequence, and every message carries an unsubscribe link.
When you send us a message
The contact form stores your name, email address, the subject you picked, your message, a truncated one-way hash of your IP address and your browser user agent string. We use it to answer you and to keep a record of the exchange. We do not add you to any mailing list.
When you vote, comment or click out
Vote integrity needs some way to tell one visitor from a thousand. When voting ships we will use a first-party cookie holding a random identifier, a truncated hash of your IP address and a coarse browser signature, all strictly for rate limiting and fraud detection. Outbound clicks through our redirect are counted in aggregate against the listing. We do not build a profile of you across sites and we do not sell any of it.
When you pay
Payments run through Stripe. Your card details are entered on Stripe's infrastructure and we never see or store them. We store the Stripe payment reference, the tier, the amount, the currency, the status and any refund, so we can honor the refund rule and give you an invoice. Stripe processes the payment as an independent controller under its own privacy policy.
Server logs and analytics
The site runs on Cloudflare. Requests generate short-lived edge logs containing an IP address, a user agent and a URL, which exist for security and debugging. For traffic measurement we use Cloudflare Web Analytics, which sets no cookies, does not fingerprint visitors and reports only aggregate counts. There is no Google Analytics, no advertising pixel and no third-party tracker anywhere on this site.
Our badge crawler
A dofollow link can be earned by placing our badge on your own site. To check that, a crawler requests the public pages of listed sites, identifies itself as AppLauncherBot with a link to this notice, respects robots.txt and stores only what it needs: the URL checked, the time, whether a badge link was found and whether it was followed. It does not read anything behind a login and does not collect personal data from your pages. If your badge disappears, the automated email that follows goes to your submitter address.
Legal bases
- Contract. Reviewing, publishing and supporting a listing you submitted, and processing a payment you made.
- Legitimate interests. Keeping the directory free of spam and vote manipulation, verifying badges, securing the service, and measuring aggregate traffic. We have balanced these against your rights and kept the data minimal, hashed and short-lived where we can.
- Consent. Waitlist emails and the newsletter. You can withdraw it from any message or by asking us.
- Legal obligation. Keeping payment and tax records for as long as the law requires.
Who else processes your data
- Cloudflare. Hosting, the database, file storage, the CDN, security and cookieless analytics.
- Stripe. Payment processing for paid tiers, including refunds and invoices.
- An email provider. Transactional email such as magic links, review decisions and waitlist announcements. The provider is being selected and will be named here before it is used.
That is the whole list. We do not sell personal data, we do not share it for cross-context behavioral advertising, and we do not hand it to anyone else except where the law requires it.
International transfers
Our providers operate globally, so data may be processed outside the UK and the European Economic Area. Where that happens we rely on the providers' standard contractual clauses and equivalent safeguards. Cloudflare serves requests from the edge location nearest the visitor, and the database is a single region we will name here once the production account is provisioned.
How long we keep things
- Published listings. Indefinitely, because the point of the listing is that it lasts. You can ask us to unlist it at any time.
- Submissions that were rejected or abandoned. Personal fields are deleted 90 days after the decision. Unverified drafts are purged after 7 days.
- Waitlist addresses. Until you unsubscribe, or 24 months after the last time you heard from us, whichever comes first.
- Contact messages. 24 months after the thread is closed.
- Payment records. As long as tax and accounting law requires, typically six to seven years.
- Edge logs. Days, not months, and controlled by Cloudflare's own retention.
- Hashed IP values. 12 months.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to receive it in a portable format. You can withdraw consent for email at any time. You also have the right to complain to your data protection authority, which in the UK is the Information Commissioner's Office.
Use the contact form and pick "Privacy or legal". We answer within 30 days and usually much faster. We may ask you to confirm control of the email address on the record before acting on a request, because that address is the only identity this site has.
Security
Everything is served over HTTPS. Data lives in Cloudflare's managed database and object storage with access limited to the people who run the directory. IP addresses are hashed with a one-way function before storage and truncated, so the original address cannot be recovered from our records. We do not store passwords, because there are no accounts.
Children
This site is for people building and evaluating software and is not directed at children. Do not submit an app or a message if you are under 16.
Changes
When this notice changes materially we will update the date at the top and, where the change affects how we use data you already gave us, tell the people it affects by email. Older versions are available on request.