Legal
Privacy
DealLaunch AI is a private system of record for your deal workflow. This page explains, in plain terms, what we collect and how we handle it.
What we collect
Account details you provide when you request access or sign in: your name, email, company and role.
The project data you enter: deals, firms, contacts, notes, documents (or links to them), outreach drafts and activity.
Basic technical data needed to run the service (authentication sessions and error diagnostics).
How we use it
To provide your private workspace - storing and displaying the deals, contacts and documents you create.
To draft and research on your request. When you use an AI feature, the relevant project context is sent to our AI provider (Anthropic) to produce a draft or research suggestion. AI output is unverified and is never sent or acted on without your review.
We do not sell, rent or share your contact lists, and we do not use your private deal data to build a shared investor marketplace.
One thing is shared between accounts, and only this: the email FORMAT a company uses - its domain and the shape of its addresses, such as "first.last" - read from public web pages during a search. It contains no names, no email addresses, no contacts and nothing from your workspace, and your own contact list is never a source for it. It exists so that a fact about a public company, once researched, does not have to be researched again.
Where your data lives
Data is stored in Supabase (PostgreSQL) with row-level security so each account only sees its own records. Outreach mailbox credentials are encrypted at rest and decrypted only on the server to send on your instruction.
Documents you upload are held in a private storage bucket and served through short-lived signed links.
Subprocessors we rely on include Supabase (database, auth, storage), Anthropic (AI drafting/research), Vercel (hosting) and your own connected email provider (Microsoft 365 / Google / SMTP) for sending.
How we protect your data
In transit: everything moves over HTTPS with TLS. The app, the API and the database are reachable no other way.
At rest: the database and the document store are encrypted at rest by our infrastructure provider (Supabase, AES-256), hosted in the EU (Frankfurt).
Credentials get a second layer on top of that. Mailbox passwords and OAuth refresh tokens - including any Google refresh token - are encrypted by the application with AES-256-GCM before they are written, under a key held only in server environment configuration and never in the database. A copy of the database alone does not yield a usable credential.
Access: every table is protected by row-level security, so an account reaches only its own rows and the projects explicitly shared with it. Mailbox credentials are stricter still - they are personal to the user who connected them and are readable by nobody else, including the owner of the workspace and including us. They are decrypted on our server only at the moment you send, and never reach a browser.
Least privilege: we request the narrowest scope that does the job. For Gmail that is send-only; we request no scope that can read, search, list, download or modify your mail.
Retention and deletion: disconnecting a mailbox deletes its stored credential immediately. Deleting your account removes your workspace data. We keep no copy of your mail.
People: no member of our staff reads Google user data. Access to production systems is limited to the accounts that need it and is protected by two-factor authentication.
If we ever discover a breach affecting your data, we will tell you and the relevant supervisory authority without undue delay, as required by the GDPR.
Google user data
If you connect a Gmail account, DealLaunch AI requests one scope: https://www.googleapis.com/auth/gmail.send. It permits sending only. It gives no ability to read, search, list, download or modify any message in your mailbox, and we request no other Google scope.
We use it for one purpose: to send the outreach messages you have reviewed and chosen to send, from your own address, to the counterparties you entered on your own mandate. We never send on our own behalf and we never message anyone you have not added yourself.
We store only a refresh token, held so that sending continues to work between sessions. It is encrypted by the application with AES-256-GCM under a key that lives only in server configuration, decrypted on our server at the moment you send, and never exposed to the browser. Disconnecting the mailbox in the app deletes it immediately. See How we protect your data above for the mechanisms in full.
DealLaunch AI use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as necessary to provide or improve this feature, to comply with applicable law, or as part of a merger or acquisition. We do not use Google user data for advertising, and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.
Google user data is never sent to our AI provider. Message drafting happens from the project data you entered in DealLaunch AI, before anything reaches your mailbox.
Outreach and email
When you connect a mailbox, messages are sent from your own account and only for emails you have approved. If you place approved messages in the scheduled queue, they may continue to go out on a daily schedule - even while the app is closed - until the queue empties or you cancel it.
You are responsible for ensuring your outreach complies with applicable anti-spam and data-protection rules.
Your choices
You can edit or delete records in your workspace at any time. To export or permanently delete your account data, contact us at hello@deallaunch.ai.
This summary reflects current practice and will evolve as the product matures; it is not a substitute for legal advice. Questions: hello@deallaunch.ai.