Privacy Policy
Last updated 26 July 2026
1. Scope
This policy explains what LaunchStudio collects when you use the application, why we collect it, who else sees it, and what you can ask us to do with it. It covers the LaunchStudio application — not the websites that users build and publish with it, which are controlled by the users who published them.
2. What we collect
- Account details. Your email address, a one-way hash of your password (we never store the password itself), an optional display name, your plan tier, and when the account was created.
- What you create. Project names, the prompts you write, the code the Service generates, your edits, your chat history and your version history. This is the substance of the Service and we store it so your work is there when you come back.
- Usage records. How many generations you run and how many tokens they consume, so we can enforce rate limits and understand cost.
- Technical logs. Server logs recording the time, IP address, endpoint, response status and a request identifier for requests to the Service, kept for security, debugging and abuse prevention.
3. What we do not do
- We do not sell your personal data, and we do not share it for advertising.
- We do not run advertising networks, third-party analytics or tracking cookies on the application.
- We do not use your projects to train AI models.
- We keep you signed in with a token stored in your browser’s local storage, not a tracking cookie — which is why you are not asked to dismiss a cookie banner.
4. Why we use it
To provide the Service you asked for (generating, storing, previewing and publishing your projects); to keep your account secure and prevent abuse; to fix faults; and to comply with legal obligations. Where the law requires a lawful basis, ours is performance of our contract with you, and our legitimate interest in keeping the Service secure and working.
5. AI processing — read this one
To generate or edit code we send your prompt, along with the relevant files from the project you are working on, to Microsoft Azure OpenAI Service, which runs the model and returns the result. That processing happens on Microsoft infrastructure under Microsoft’s terms.
Because of this, do not put passwords, API keys, personal data about other people, or anything confidential into prompts or project files. Treat everything in a project as material that leaves our servers to be processed.
6. Who else processes your data
- Microsoft Azure OpenAI Service — code generation, as described above.
- Our hosting provider — the servers and managed infrastructure the Service runs on.
- Error monitoring — where enabled, a diagnostics provider receives technical details of failures (error type, stack trace, request identifier) so we can fix them.
These providers act on our instructions and may process data outside your country. We rely on the transfer safeguards their contracts provide.
7. How long we keep it
- Account details and projects: for as long as your account exists.
- Database backups: kept on a rolling 14-day window, then automatically deleted — so deleted content can persist in backups for up to 14 days.
- Server logs: a short operational retention window, then rotated away.
8. Your rights
Depending on where you live you may have the right to access, correct, export, restrict or delete your personal data, and to object to processing. You can exercise all of these by emailing support@bota.uz. We will respond within 30 days.
Exporting your data.Settings → Your data downloads a JSON file containing your account record, your projects, their version history and your chat transcripts. Project file contents are exported separately as a ZIP archive from each project's workspace.
Deleting your account. Settings → Delete account removes your account, every project, all version history and any published site immediately. Backups still hold that content for up to 14 days, as described above, before they rotate away.
9. Security
Passwords are stored only as bcrypt hashes. Traffic is encrypted with TLS. The database is not reachable from the public internet. Authentication and generation endpoints are rate limited. Sites published by users are served from a separate domain so that generated code can never read your session in the application.
No service can promise perfect security. If we discover a breach affecting your personal data we will notify you and any regulator as the law requires.
10. Children
The Service is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes and contact
We will update this page when our practices change and revise the date at the top; material changes will be notified through the Service or by email. For anything privacy-related, or to make a request under section 8, contact support@bota.uz. See also our Terms of Service.