LaunchPilot Privacy Policy
This Privacy Policy explains how LaunchX GmbH ("we", "us", "operator") processes personal data when you use LaunchPilot ("the Service"), available at launch-pilot.launch-x.de. We process personal data as a controller within the meaning of Art. 4 (7) of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").
1. Operator
LaunchX GmbH
Lärchenstraße 12, 84032 Landshut
Email: info@launch-x.de
For data protection inquiries please use the email address above. Full company details are listed in our Imprint.
2. What data we collect
- Account credentials. Your email address and a hashed (one-way salted) representation of your password. We never store passwords in clear text.
- OAuth tokens for connected platforms (TikTok, Meta/Instagram, LinkedIn, YouTube, Threads, X). Tokens are stored encrypted at rest using a server-side symmetric key.
- Post content drafted by you. Text, images, videos, hashtags and scheduling metadata you create or upload in the composer.
- Usage logs. Authentication events, publishing events and error logs (technical metadata such as timestamps, IP addresses and request identifiers). Used for security monitoring and debugging.
- Billing data (only if you have a paid plan): invoice address, VAT ID where applicable, and transaction metadata required by German tax law.
3. How we use it (purposes and legal bases)
- To provide the scheduling and publishing service — performance of the contract you concluded with us (Art. 6 (1) (b) GDPR).
- To call platform APIs on your behalf when you publish — performance of the contract (Art. 6 (1) (b) GDPR).
- To send transactional emails (account confirmation, password reset, publishing failure notifications) — performance of the contract (Art. 6 (1) (b) GDPR).
- To keep security and error logs — our legitimate interest in operating a secure, debuggable service (Art. 6 (1) (f) GDPR).
- To meet statutory record-keeping obligations for invoices and accounting documents — compliance with a legal obligation (Art. 6 (1) (c) GDPR in conjunction with § 257 HGB and § 147 AO).
We do not use your data for advertising. We do not sell data to third parties. We do not profile users for any commercial purpose.
4. Per-platform data flow when you publish
When you connect a social platform to the Service, you authorise us via OAuth to act on your behalf on that platform. When you instruct the Service to publish a post, we communicate with that platform's official API to deliver the content you authored. The platform's own privacy policy applies to your data once it is received by the platform. The platform acts as an independent controller for the data it receives from you, not as our processor.
TikTok (Content Posting API)
When you publish to TikTok via LaunchPilot, we use TikTok's Content Posting API. We host your video on our server at launch-pilot.launch-x.de, and we transmit to TikTok a request that contains the URL of the video, your caption, hashtags, your selected privacy setting (e.g. public, friends, only me), and your interaction preferences (allow comments / duet / stitch). TikTok then pulls the video file from our server directly (TikTok's "PULL_FROM_URL" mechanism). The URL is served from a verified domain that we have registered with TikTok for this purpose. Once TikTok has received your content, TikTok's own privacy policy applies, available at https://www.tiktok.com/legal/page/eea/privacy-policy/en.
Meta (Instagram, Threads)
When you publish to Instagram or Threads via LaunchPilot, we transmit your post content (text, image or video, caption, scheduling metadata) to Meta's Graph API. From the moment Meta receives the data, Meta's privacy policy applies, available at https://privacycenter.instagram.com/policy. Note that Meta operates from servers outside the European Economic Area; transfers occur under the EU-U.S. Data Privacy Framework and Meta's standard contractual clauses.
When you publish to LinkedIn via LaunchPilot, we transmit your post content (text, image or video, caption, scheduling metadata) to LinkedIn's Marketing API. From the moment LinkedIn receives the data, LinkedIn's privacy policy applies, available at https://www.linkedin.com/legal/privacy-policy. LinkedIn is a U.S. entity; transfers occur under the EU-U.S. Data Privacy Framework.
YouTube
When you publish to YouTube via LaunchPilot, we transmit your video, title, description, tags, privacy setting and scheduling metadata to YouTube's Data API. From the moment YouTube receives the data, Google's privacy policy applies, available at https://policies.google.com/privacy. Google is a U.S. entity; transfers occur under the EU-U.S. Data Privacy Framework.
X (Twitter)
When you publish to X via LaunchPilot, we transmit your post content (text, media, scheduling metadata) to X's API. From the moment X receives the data, X's privacy policy applies, available at https://x.com/en/privacy.
5. Recipients
The social platforms listed above are recipients of personal data when you instruct us to publish on your behalf. They are not processors within the meaning of Art. 28 GDPR; they act as independent controllers for the data they receive.
In addition we use the following processors to operate the Service:
- Hetzner Online GmbH, Gunzenhausen, Germany — server hosting (data centre in Germany). Order processing agreement in place pursuant to Art. 28 GDPR.
- Cloudflare, Inc., San Francisco, USA — DNS, edge caching, DDoS protection for our domain. Transfer covered by the EU-U.S. Data Privacy Framework and standard contractual clauses.
- Transactional email provider our transactional email provider (see Imprint for current operator); see processor list available on request.
6. Data retention
Different categories of data are retained for different periods, reflecting their purpose and applicable statutory obligations:
- Account data (email, hashed password, profile settings): retained until you delete your account. Deletion within 30 days of an account-deletion request, except where statutory retention applies.
- Posts and uploaded media: retained for 90 days after publication, or until you delete your account, whichever comes first.
- Failed-post logs (debug records of publishing attempts that did not succeed): 30 days.
- OAuth tokens for connected platforms: stored encrypted at rest; deleted immediately when you disconnect a platform, when the token is invalidated by the platform, or upon account deletion.
- Authentication and security logs: 90 days, after which they are deleted or irreversibly anonymised.
- Invoices, accounting records and transaction data: 10 years pursuant to § 257 (4) HGB and § 147 (3) AO (statutory record-keeping under German commercial and tax law). During this period processing is restricted to fulfilling these legal obligations.
7. International data transfers
Our infrastructure is hosted in Germany. When you publish to a non-EEA platform (e.g. TikTok, Meta, LinkedIn, YouTube, X), personal data is transferred outside the EEA at your instruction and to your chosen recipient. Such transfers rely on either the EU-U.S. Data Privacy Framework, the platform's standard contractual clauses, or your explicit consent given by connecting the platform (Art. 49 (1) (a) GDPR). You can withdraw consent at any time by disconnecting the platform in your account settings; this stops future transfers but does not affect transfers already made.
8. Your rights under GDPR
You have the following rights regarding your personal data. To exercise any of these rights, contact us at info@launch-x.de. We respond within one month (Art. 12 (3) GDPR).
- Right of access (Art. 15 GDPR). You can ask us to confirm whether we process your data and to receive a copy of it.
- Right to rectification (Art. 16 GDPR). You can ask us to correct inaccurate data or complete incomplete data about you. Most account fields you can also edit yourself in your profile settings.
- Right to erasure (Art. 17 GDPR). You can ask us to delete your data when it is no longer needed, when you withdraw consent, or when processing is unlawful. Statutory retention periods (see § 6) may delay deletion of specific records.
- Right to restriction (Art. 18 GDPR). You can ask us to limit processing while a dispute is being resolved — for example while we verify a correction request.
- Right to data portability (Art. 20 GDPR). You can request an export of the data you have given us, in a structured, commonly used, machine-readable format. We provide a JSON export on request.
- Right to object (Art. 21 GDPR). You can object to processing based on our legitimate interest (Art. 6 (1) (f) GDPR), in which case we stop unless we can demonstrate overriding legitimate grounds.
- Right to withdraw consent (Art. 7 (3) GDPR). Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
9. Cookies
We use strictly functional cookies only. Specifically, we set a session cookie when you log in so that you remain authenticated across requests. We do not use tracking cookies, analytics cookies, advertising cookies or third-party cookies. Because we use only strictly necessary cookies, no cookie consent banner is required under § 25 (2) Nr. 2 TTDSG.
10. Security
We host on infrastructure inside Germany. Connections to the Service are encrypted via HTTPS (TLS). OAuth tokens for connected platforms are encrypted at rest using a symmetric key controlled by us. Passwords are stored as salted hashes only and cannot be recovered in clear text. Access to production systems is restricted to authorised personnel with multi-factor authentication.
11. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority for our company is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
https://www.lda.bayern.de
You also have the right to complain to the supervisory authority in your EU member state of residence.
12. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in our service or in applicable law. Material changes will be communicated to registered users by email at least 30 days in advance. The current version is always available at this URL.