Privacy Policy
Version 1.0 · Effective 26 August 2026
Launch is built local-first. Your alarms, routines and morning history live on your device and are never sent anywhere unless you choose to create an account.
The short version
- We do not sell or share your personal information, and we never have.
- We do not use advertising networks, and we do not track you across other apps or websites.
- We do not ask for your location, contacts, camera, microphone, or health data.
- You can delete your account and everything in it from inside the app at any time.
1. Who we are
Launch App ("Launch", "we", "us") provides the Launch alarm and morning-routine mobile application (the "App"). This policy explains what we do with personal information and applies to everyone who uses the App.
For privacy questions, requests, or complaints, contact us at privacy@launchalarm.app. We are the entity responsible for the personal information described here — the "controller" under UK data protection law, an "APP entity" under Australian law, an "agency" under New Zealand law, an "organization" under Canadian law, and a "business" under United States state privacy laws.
2. What we collect, and when
Stays on your device (we never receive it)
Unless you create an account, everything you do in Launch is stored only on your device: your alarms, wake-up mission settings, routines and their steps, alarm sounds, app preferences, and your morning history (when your alarm rang, when you dismissed it, how many times you snoozed, and which routine steps you completed or skipped).
If you create an account (optional)
An account exists solely so your data can be backed up and synced across your devices. If you create one, we collect and store:
- Account identifiers — your email address, and a user ID we generate. If you sign in with Apple or Google, we receive an identifier and the email address you choose to share (including a private relay address, if you use Apple’s hide-my-email feature).
- Your app data — the alarms, routines and morning history described above, synced to our servers so you can restore them.
If you subscribe
- Subscription status — whether you have an active subscription, which plan, and when it renews or expires. Payment is processed entirely by Apple or Google. We never see or store your card number, billing address, or any payment credential.
Always, in limited form
- Diagnostics — if the App crashes or errors, we receive a technical report (device model, operating system version, app version, and the error). This is configured to exclude personal information, and it is not linked to your identity when you have no account.
- Basic usage events — anonymous counters that tell us whether core flows work, for example that an alarm fired or a morning was completed. These carry no content: no alarm labels, no routine names, no times of day.
Motion sensor
The Shake mission reads your device’s accelerometer while that mission is on screen, purely to count shakes. This data is processed on your device in the moment and is never recorded, stored, or transmitted.
What we never collect
We do not collect location data, contacts, photos, camera or microphone input, biometrics, health or medical records, precise device identifiers for advertising, or the content of any communication.
3. Why we use it, and our legal bases
We use personal information only for these purposes:
- To provide the App — running alarms, missions, routines, and your morning history.
- To back up and sync your data across your devices, if you have an account.
- To provide and validate subscriptions, and to restore purchases you have already made.
- To fix crashes, diagnose faults, and keep alarms reliable.
- To respond to you when you contact support.
- To meet legal obligations and to protect against fraud, abuse, or security incidents.
Legal bases (United Kingdom)
Under the UK GDPR (as amended by the Data (Use and Access) Act 2025) we rely on: performance of a contract (Article 6(1)(b)) to provide the App, your account, and your subscription; our legitimate interests (Article 6(1)(f)) in keeping the App secure, stable and free of abuse, and in understanding whether core features work; your consent (Article 6(1)(a)) where we ask for it, such as device notification permission, which you may withdraw at any time in your device settings; and compliance with legal obligations (Article 6(1)(c)).
Consent and collection notice (Australia, New Zealand, Canada)
We collect personal information directly from you, by lawful and fair means, and only what is reasonably necessary for the functions described above. Where Canadian law requires consent, you give it by creating an account and using the App for these described purposes; you may withdraw it by deleting your account, subject to legal retention requirements. If we ever collect your personal information from a source other than you — which we do not do today — New Zealand’s Information Privacy Principle 3A requires us to notify you, and we would.
No automated decision-making
We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you.
5. Where your information goes
Our service providers may store and process personal information outside your country, including in the United States and the European Union. When that happens, we take reasonable steps to ensure it stays protected to a standard comparable to the law of your home country.
- Australia — before disclosing personal information to an overseas recipient, we take reasonable steps as required by Australian Privacy Principle 8 to ensure the recipient does not breach the Australian Privacy Principles.
- New Zealand — we only disclose personal information overseas where Information Privacy Principle 12 permits, including where the recipient is subject to comparable safeguards.
- United Kingdom — transfers rely on UK adequacy regulations or, where none applies, the International Data Transfer Agreement or the UK Addendum to the European Commission’s standard contractual clauses.
- Canada — while personal information is outside Canada, it may be accessible to the courts, law enforcement and national security authorities of that jurisdiction. We remain accountable for it under PIPEDA.
6. How long we keep it
- Device data — kept until you delete it in the App, or until you uninstall the App. Uninstalling removes it from your device.
- Account data — kept while your account exists. When you delete your account we permanently delete your account and all associated data from our live systems, and it is removed from routine backups within 30 days.
- Subscription records — retained for as long as required for tax, accounting and audit obligations, typically up to seven years, in a form limited to what those obligations require.
- Diagnostics — retained for up to 90 days, then deleted.
7. Your rights and choices
Because Launch is local-first, the fastest route to most of these is the App itself: your data is on your device, and Settings → Account → Delete account removes everything we hold. You can also contact us and we will action any request the law gives you.
Everyone
- Access a copy of the personal information we hold about you.
- Correct information that is inaccurate or out of date.
- Delete your account and the data associated with it.
- Ask us questions about how we handle your information, and complain if you are unhappy.
United Kingdom
You also have the rights to restrict or object to processing, to data portability, and to withdraw consent. We will respond within one month, which may pause if we need you to clarify a request. You may complain to the Information Commissioner’s Office (ico.org.uk), though we would appreciate the chance to resolve it first.
Australia
You may request access to and correction of your personal information under the Australian Privacy Principles. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au). We will notify you and the OAIC of any eligible data breach likely to cause you serious harm, as the Notifiable Data Breaches scheme requires.
New Zealand
You have rights of access and correction under the Privacy Act 2020. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner (privacy.org.nz). We will notify the Privacy Commissioner and affected individuals of any privacy breach that has caused or is likely to cause serious harm.
Canada
You may access your personal information and challenge our compliance under PIPEDA, and you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca). If you are in Quebec, you also have rights to the portability of your computerised personal information and to request that we cease disseminating it or de-index it, under Law 25, and you may complain to the Commission d’accès à l’information. Residents of Alberta and British Columbia have equivalent rights under their provincial Personal Information Protection Acts.
United States
Depending on your state — including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, New Hampshire, New Jersey, Iowa, Indiana, Kentucky, Rhode Island, Tennessee, Minnesota, Maryland and Nebraska — you may have rights to know, access, correct, delete, obtain a portable copy of your personal information, and to opt out of sale, sharing, targeted advertising, and certain profiling.
We do not sell or share personal information as those terms are defined in the California Consumer Privacy Act, we do not process it for targeted advertising or profiling, and we do not knowingly process the personal information of anyone under 16 for those purposes. There is therefore nothing to opt out of, and we honour Global Privacy Control signals as a matter of course. We will not discriminate against you for exercising any privacy right. You may use an authorised agent to make a request; we will ask for proof of their authority. Where a request is denied you may appeal by replying to our response, and where your state provides one you may escalate to your Attorney General.
For California residents, the categories in the twelve months before this policy’s date map as follows: identifiers (email, user ID); commercial information (subscription status); internet or other electronic network activity (in-app usage events); and inferences — none, as we draw none. Each is collected for the business purposes in section 3 and disclosed only to the service providers in section 4.
How to make a request
Email privacy@launchalarm.app from the address associated with your account, or use Settings → Account → Delete account in the App. We will verify your request by confirming control of that email address. We do not charge for these requests, and we respond within the period your law requires — one month in the UK, 30 days in Australia and Canada, 20 working days in New Zealand, and 45 days in most United States jurisdictions.
8. How we protect it
We take reasonable technical and organisational measures appropriate to the sensitivity of the information:
- All network traffic is encrypted in transit using TLS.
- Authentication tokens are stored in your device’s hardware-backed secure storage — the iOS Keychain or the Android Keystore — never in ordinary app storage.
- Our database enforces per-user access rules at the database layer, so one account cannot read another’s data even if the application were compromised. These rules are tested adversarially.
- Subscription entitlements are validated server-side and cannot be altered by a client.
- Access to production systems is limited to those who need it.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach occurs that is likely to cause you serious harm, we will notify you and the relevant regulator as the law requires.
9. Children
Launch is not directed to children. We do not knowingly collect personal information from anyone under 13, and we do not knowingly collect it from anyone under 16 without appropriate consent where their local law requires it. If you believe a child has provided us with personal information, contact us and we will delete it promptly. We do not profile children, serve them advertising, or use their data to encourage prolonged use.
10. Changes to this policy
We may update this policy as the App or the law changes. The version and effective date are shown at the top. If a change materially affects how we handle your personal information, we will tell you in the App before it takes effect, and where the law requires it we will ask for your consent. Continuing to use Launch after a change takes effect means you accept the updated policy.
11. Contact us
Privacy questions, requests and complaints: privacy@launchalarm.app. General support: support@launchalarm.app. We aim to acknowledge every privacy enquiry within 5 business days and to resolve it within the statutory period for your country.