Legal
Privacy Policy
Last updated: September 10, 2026
This Privacy Policy explains how LaunchSite OS, LLC ("LaunchSite OS," "we," "us," "our"), a Kentucky limited liability company, collects, uses, discloses, and safeguards information when you use our health-coaching platform. We treat the privacy and security of health-related information as foundational to the product, not an afterthought.
At a glance
- Adult wellness coaching. LaunchSite OS provides coaching software. It does not offer a BAA or support HIPAA-regulated workflows, diagnosis, treatment, prescribing, or lab ordering.
- Your coach controls your records. For information a client enters or a coach records in a workspace, the Coach is the decision-maker (controller) and we act as their service provider (processor).
- Client health data stays outside advertising. We never use client health-related information for advertising or to train AI models. Optional Google Ads measurement on selected public marketing and signup pages starts only when you allow it, with ad personalization disabled.
- Every vendor is published. The full list of providers, their roles, and what each one can see is at /privacy/subprocessors - currently 29 providers.
- Access is locked down by design - encryption in transit and at rest, database row-level security, and server-side role checks on every request.
- You have rights to access, correct, export, and delete your information, and to withdraw consent for consumer health data. See Your privacy rights.
1. Who we are and our role
LaunchSite OS provides software for adult wellness and fitness coaches ("Coaches"). We do not offer a Business Associate Agreement (BAA). Use in the capacity of, or on behalf of, a HIPAA covered entity, and any workflow requiring a BAA, is prohibited. Actual activities and relationships determine which laws apply; a policy or checkbox cannot establish an exemption. We treat client information as sensitive consumer health information. Our own data-handling responsibilities remain ours, alongside the Coach's responsibilities. See our Consumer Health Data Privacy Policy for the purposes, sharing, and rights associated with that information.
Our role depends on the information involved:
- Coach account, billing, platform-usage, and optional public-site measurement information - we are the controller (we decide how it is used for the purposes described here). Google acts as a separate controller of the measurement information it receives, as explained in Section 11.
- Client information, leads, and messages inside a Coach's workspace - the Coach is the controller of that information and we act as a service provider / processor on the Coach's behalf, handling it only to deliver the service and on the Coach's documented instructions. Clients and leads should direct requests about their own information to their Coach; we help Coaches fulfil them.
The table in Section 2 marks which role applies to each category.
2. Information we collect
The categories below are the complete set the platform handles. Categories marked optional exist only if you or your coach turn the relevant feature on.
Connected mailbox correspondence · sensitive · optional
- Google/Outlook account identifiers and connection status
- Matched prospect or client email text and subjects, which may include health information supplied by the sender
- Provider message/thread identifiers and authentication, reply-matching and processing results
Controller: the Coach (we process on their behalf) · Sources: A mailbox its owner authorizes through Unipile; People corresponding with that mailbox
Historical chart tables and saved charts · sensitive · optional
- Selected numeric columns, dates, categories, original text, and units from a coach-reviewed CSV
- Historical chart snapshots of selected coaching data with source references
Controller: the Coach (we process on their behalf) · Sources: Previously uploaded and reviewed by the coach for a selected client; Previously generated from authorised coaching records
Optional public AI demonstration · optional
- A visitor’s short fictional meal-planning prompt and generated example
- An opaque network rate-limit key, attempt count and window time
Controller: LaunchSite OS · Sources: An adult visitor who confirms they want to use the public demonstration
Privacy requests, permissions, and review records · sensitive
- Account identifiers, request and review type, jurisdiction, assigned staff, due dates, evidence references and outcomes
- Purpose-specific permission statements and versions, recorded actions, receipt times and withdrawal events
- Coach-provided evidence provenance and asserted historical dates, labelled separately from in-app client confirmations
Controller: LaunchSite OS · Sources: The client, coach, authorized platform staff, and authenticated requests
Account erasure work and completion evidence · sensitive
- Account and subject identifiers, exact private object references, provider references, deletion states, retry attempts and completion or retention evidence
- Minimal deletion tombstones used to prevent restored backups from reactivating erased accounts
Controller: LaunchSite OS · Sources: Authorized deletion requests and the records and storage references held by the service
Signed coach-client agreement evidence · sensitive · optional
- The signed agreement text and resolved fields, signer identifiers, signature, signing time, content hash, amendments and void events
- The coach contracting entity (legal name, registration and tax numbers, address) as it stood when the agreement was sent, frozen into the same content hash
- Legacy signed rows captured at migration time, explicitly distinguished from a document recorded at the original signing
Controller: the Coach (we process on their behalf) · Sources: The coach and client during agreement preparation and signing; Existing signed records captured with their known limitations
Coach agreement acceptance records
- Authenticated account ID and email, typed signer name and title
- Full accepted document versions, acceptance statement, document hashes, server timestamp, IP address and browser user agent
- Historical wellness-attestation hashes and timestamps where full documents were not originally recorded
Controller: LaunchSite OS · Sources: Directly from the coach when accepting platform agreements; Automatically from the authenticated request and published platform documents
Account and profile information
- Name, email address, and password (stored only as a salted hash)
- Optional profile pictures uploaded by a user or their coach
- Coach practice name, brand, logo, and business profile including the postal address used in marketing footers and any separate contracting entity named on client agreements
- Team membership and role (coach, team member, client)
- Coach-saved workspace shortcut names and internal page addresses, private to that coach and retained until unpinned or the account record is deleted
Controller: LaunchSite OS · Sources: Directly from you at signup; Profile pictures uploaded by you or your coach; From the coach or team owner who invited you; From a system the coach connected to their own workspace with a Partner API key; Written by a coach about themselves when they choose to appear in the coach directory
Client wellness and health-related records · sensitive
- Check-ins, symptoms, complaints, and wellness system-status grades
- Weight, body composition, blood glucose, temperature, daily water intake, and similar self-reported measures
- Supplement, peptide, nutrition, and training programming
- Coach-uploaded educational resources and course lessons, including any client wellness information included in a video, PDF, office document or text file
- Menstrual or reproductive information, where a client chooses to provide it as intake
- Coach notes and goals
- System Status coach focus notes, review dates and links to assigned tasks or plans; private anatomy view bookmarks with coach-written annotations and camera settings
- Private conversation follow-up notes written by a coach, with a chosen reminder time and the conversation they refer to
Controller: the Coach (we process on their behalf) · Sources: Directly from the client; Entered or uploaded by the coach on the client’s behalf; Uploaded by the coach as Library resources or Networks course lessons; Sent by a system the coach connected with a Partner API key, or read back out by it
Pre-participation health screening · sensitive · optional
- Answers to the standard PAR-Q+ readiness questions (heart condition, chest pain, dizziness, chronic conditions, prescribed medication, joint or bone problems, and medically supervised activity)
- Whether any answer was "yes", and the date the questions were answered
- The coach’s decision about a flagged screening, the reason they recorded for it, and who made it
Controller: the Coach (we process on their behalf) · Sources: Directly from the client, through the client portal
Lab files and extracted markers · sensitive
- Uploaded lab PDFs and images (for example serum, gut, hormone, or mycotoxin panels)
- Marker names, values, and reference ranges extracted from those files
- Saved chart snapshots containing selected confirmed results, units, report intervals, and source references
- The patient name and testing company printed on the report, and the panel type read from it
Controller: the Coach (we process on their behalf) · Sources: Uploaded by the client or the coach
Progress photos and movement video · sensitive
- Progress and body-composition photos
- Lift and movement video submitted for form review
- Pose landmarks derived from that video to draw form feedback
Controller: the Coach (we process on their behalf) · Sources: Uploaded by the client or the coach
Connected device and wearable metrics · sensitive · optional
- Daily aggregates for steps, sleep duration, resting heart rate, and heart-rate variability
- Recovery, strain, readiness, and similar scores produced by the device maker
Controller: the Coach (we process on their behalf) · Sources: Apple Health, at the client’s direction, after Apple’s own permission prompt; Whoop, Oura, Fitbit, or Ultrahuman, after the client authorises the connection
Messages and conversation content
- In-app messages between a coach and a client
- Coach-private conversation snooze times and client-reply wake times; follow-up notes are never sent to the client and are removed when the coach completes or cancels the follow-up, or the related account or client record is deleted
- Posts, chat, comments and event responses in the partner community — a shared space for referral partners and the LaunchSite team, where everything written is readable by every other partner in the room
- Private photo, document, and video attachments sent in a direct conversation; an uploaded video original is available to the conversation while a compatible copy is prepared
- Group space conversations between a coach and the clients they added to that space
- Posts published to a community — by the coach, and by clients in a channel the coach has opened to everyone — and the comments written underneath them, visible to every other client in that community
- The whole message history between a client and their coach, when a team admin or the coach transfers that client to another coach on the same team — the receiving coach can read it, and each message still shows who wrote it
- Posts, chat, comments and event responses in a community that a coach has invited another coach into — that guest coach reads everything written in the room, including messages from clients who are not theirs, and is shown to everyone in the room as a guest; they cannot see any client’s plans, check-ins, notes, labs or health records
- WhatsApp and Instagram conversations connected to the coach’s paid Pro CRM workspace; these channels are separate from private coaching messages
- For enabled CRM messaging workflows: provider account, conversation, sender and message identifiers; inbound text and timestamps; the CRM contact and lead link; workflow enrollment, reply waits, handoff tasks and confirmed or uncertain send outcomes
- Website chat-widget conversations with a visitor, coach and optionally the coach-selected AI agent; a random visitor credential is stored in the browser session and only its hash is stored on the server, with access expiring after 30 days
- Google/Outlook mailbox connection identity and address, synchronization cursor and status, matched CRM email sender/recipient details, subject and plain-text body, provider message and thread identifiers, authentication results, reply matching and automation outcomes; raw attachments and unmatched message bodies are discarded by the importer
- Coach-selected mailbox Reply-To routing; imported sender verification is unavailable and synchronized mail does not authorize reply workflows or AI actions; disconnect stops collection and is confirmed separately with the mailbox provider
- Consent state and opt-out history for each email address, plus withdrawals already recorded against a messaging channel we have since retired, which are retained rather than erased
Controller: the Coach (we process on their behalf) · Sources: Sent by you; Received from the person you are talking to; Delivery receipts from the platform the message went through
Voice input, call recordings, transcripts, and synthetic voice · sensitive · optional
- Recordings and transcripts of consults and coaching calls the coach chooses to capture
- Derived call metrics about the coach’s own delivery (talk ratio, questions asked, whether a next step was set)
- Audio generated from a configured synthetic voice
- Microphone audio captured while a coach uses a voice feature — the Cowork consoles, voice check-in, and dictation — and sent for transcription
- A short segment recorded while the assistant is speaking, if the coach has turned on “Talk to interrupt”, so that a sentence spoken over the assistant is not lost
Controller: the Coach (we process on their behalf) · Sources: Uploaded or captured by the coach; Meeting platform transcripts the coach imports; The coach’s microphone during a voice session they started
Prospect, lead, and CRM contact information
- Name, email, phone, company, and stage for people in a coach’s pipeline
- Form submissions, booking requests, business-card scans, and QR-code captures
- UTM campaign, medium, content, and term recorded when a lead arrives from a link
- Notes, tasks, deals, estimates, and activity history the coach records
Controller: the Coach (we process on their behalf) · Sources: The person, when they complete a public form, book a call, or scan a card; The coach, when they add or import a contact
LaunchSite OS business contacts and activity
- Contact names, email addresses, phone numbers and companies
- Platform sales opportunities, notes, tasks, communications and connection records
- The platform owner who created or changed a shared business record
Controller: LaunchSite OS · Sources: People contacting LaunchSite OS; Authorized LaunchSite OS business owners adding or importing records
Subscription and payment information
- Plan, subscription status, invoices, and billing email
- For the separate Pro CRM add-on: payment-processor subscription and price identifiers, subscription status, paid-through date, cancellation setting and synchronization time; access follows the governing team owner and also requires the coaching subscription
- Limited card metadata (brand, last four digits, expiry) returned by the payment processor
- For a managed coach app purchase: the selected setup offer, a secret token for its permanent payment link, payment-link status, and processor session, customer, and subscription identifiers
- For coaches who sell through the platform: payout account status and marketplace transaction records
- For a call booked on a coach’s public booking page: the amount, currency, whether it was paid, and the processor’s session identifiers, linked to the appointment it paid for
- For referral partners: the PayPal address you give us to be paid at; the code attribution; commission entries calculated from each collected subscription payment after discounts and excluding tax; refund reversals; and the record of payments we have made to you
Controller: LaunchSite OS · Sources: You, at checkout; Our payment processor; A referral partner, when they enter the PayPal address they want to be paid at; Platform administrators, when they record a missed partner-code attribution for an existing coach, with an audit record of the assignment; A visitor to a coach’s public booking page, when that page charges for the call
Campaign and engagement records
- Connected business locations, Facebook Pages, Instagram business accounts and advertising account identifiers, names, timezone and currency
- Encrypted marketing-provider authorization tokens, granted permissions, account selection and connection status
- Which campaign emails and messages were sent to whom, and when
- Frozen email content, sender and recipient details, experiment variant, sending attempt and provider message identifiers
- A random first-party funnel visitor cookie, per-experiment hashed visitor identifier, assigned variant, entry date and verified lead-capture outcome; no IP address or browser fingerprint is stored in experiment records
- Delivery, open, click, bounce, complaint, and unsubscribe event identifiers and timestamps reported by the sending provider; campaign events do not store raw clicked URLs, IP addresses or user agents
- Public Google and Facebook reviews: author display name, rating or recommendation, written feedback, provider identifiers and dates
- Coach-authored public review replies, publication attempts and provider-confirmed outcomes
- Recipients, request content, delivery outcomes, cooldowns and coach-selected first-attendance or first-payment rules for review-request emails
- Which public reviews a coach selected for an embeddable widget, and its revocable public link
- Daily campaign spend, impressions, clicks, currency, timezone and import coverage from selected Google Ads and Meta Ads accounts
- Coach-selected campaign tag mappings and reconciliation of CRM acquisitions against recorded paid ledger entries
- Selected Google or Meta lead-form identifiers, submission dates and campaign identifiers, import outcomes and references to the created or matched CRM contact
- Standard name and email fields copied from a selected provider form into a CRM contact; phone fields and custom answers are discarded rather than saved by the importer
- Meta form responses can contain additional answers in transit; the importer does not retain the raw provider response
- An email-permission hold for newly imported contacts and the workspace owner’s dated evidence of permission when they clear that hold
- The reviewed manual workflow explicitly selected to follow up with an eligible ad lead, its deduplicated enrollment and subsequent draft-review outcomes
- Versioned lifecycle package and portable setup installation receipts, selected dependency mappings and references to copied configuration assets; portable exports exclude contact and member records, credentials, payment history and outbound approvals
- Social post drafts, captions, links, selected business accounts, scheduled release times, immutable public media copies, provider post identifiers and observed likes and comments
- Which members a coach put on a retention list, the stated reason, and whether a staff member contacted or skipped them
- A staff member’s own note about a contact attempt, and the date it was made
- Whether a member agreed to marketing on a given channel, when, what wording they were shown, and whether they later withdrew it
- A member’s unsubscribe token, so a one-click unsubscribe works without them signing in
Controller: the Coach (we process on their behalf) · Sources: Generated when the coach sends a campaign; Returned by Google or Meta after the coach authorizes a marketing connection; Reported back by the email provider; Recorded by a staff member working a LaunchPoint retention list; Captured from the member themselves — at the desk, on a form, or by their own unsubscribe
AI prompts, outputs, and workspace memory · sensitive
- The workspace content sent to an AI provider to produce a requested output
- Drafts, summaries, and suggestions the AI returns
- Saved AI memories and embeddings derived from workspace content
- A per-coach record of AI usage and cost against the monthly credit limit
- Operational records of each AI run — which feature ran, which model, how long it took, how many tokens it used, which tools ran, whether retrieval found anything, and whether the coach approved the result. These records contain no prompt, reply, or document text
- OAuth connection, tool-call, change, and usage records for an external AI client the coach connects through MCP
- Selected chart measurements, dates, original units, source references and rendered images returned to an external AI client for a coach-requested MCP chart
- Historical chart requests and source revisions in previously saved conversations
Controller: the Coach (we process on their behalf) · Sources: Generated when a coach or client uses an AI-assisted feature; Received from an external AI client the coach authorises to use LaunchSite tools; Generated when a client asks their coach’s assistant a question
Community moderation reports and flags · sensitive
- A report one member makes about another member’s post or comment, including the reason they chose and anything they wrote
- An automatic flag raised by reading a member-written post or comment — the reason, a confidence score, and one sentence describing the concern
- Whether a coach dismissed the flag, hid the content, or restricted an ability, and when
Controller: the Coach (we process on their behalf) · Sources: Submitted by a community member using the report control; Generated by automatically reading posts and comments that members write in a community
Participation and activity records in a group space
- Which steps of a coach’s Start-here sequence a member has marked done, and when
- When a member was last active in the app, shown to their coach as a quiet-member reading
- Counts of a member’s posts and comments in one space, used to rank that space’s leaderboard
- How many days after joining a space a post becomes visible to that member
Controller: the Coach (we process on their behalf) · Sources: Directly from the member as they use the space; Automatically, as you use the platform
Public AI demo requests · sensitive
- The sentence a visitor types into the assistant demo on our marketing site — typically a calorie or macro target, a diet, an allergy or a food they avoid
- The one-day meal plan the assistant returns to them
- A one-way hash of the visitor’s IP address, with a count and a timestamp, used to hold each network to three free builds a day
Controller: LaunchSite OS · Sources: Typed by a visitor into the demo on our public marketing site, with no account and no sign-in
Usage, device, and diagnostic data
- Log data, IP address, browser and device type, and actions taken in the app
- Error reports, scrubbed of request bodies, cookies, and personal data
- Push notification tokens for the web and mobile apps
- Audit records of privileged actions inside a workspace
- MCP connection activity, tool name, affected record identifiers, change state, timing, outcome, and usage units without raw prompts or complete tool results
Controller: LaunchSite OS · Sources: Automatically, as you use the platform
Optional public-site advertising measurement · optional
- Your allow-or-decline measurement choice and when you made it, stored in your browser
- After you allow measurement: advertising click and cookie identifiers, the selected public page path, and browser, device, and network information including the IP address Google receives with a request
- A confirmed new coach signup or first paid platform subscription, with a receipt identifier to avoid duplicate counting and, for a paid subscription, its amount and currency
- No names, email addresses, form contents, client records, health information, private workspace paths, URL query strings, or page referrers are included in our measurement events
Controller: LaunchSite OS · Sources: Your browser choice; Consented visits to selected public marketing and signup pages on launchsite-os.com; Confirmed platform signup and payment results
Workforce and employment records (LaunchPoint ERP) · optional
- Employee name, preferred name, work email, phone, employment type, and hire and end dates
- Assigned work sites, shifts, clock-in and clock-out records, and approved hours
- Pay rates and labor cost, visible only to those the account owner has granted access
- Job title, department, reporting line, team membership, and a written description of the role
- A sign-in account for an employee, where the account owner chooses to issue one
Controller: the Coach (we process on their behalf) · Sources: Entered by the account owner or an authorised administrator; Recorded by the employee at a time-clock device
Building access records (LaunchPoint ERP) · optional
- A door credential — a fob or card serial, a phone token, or a door PIN, each stored only as a one-way hash
- Which door was used, at which site, and the exact time it was used
- Whether entry was allowed or refused, and the reason it was refused
- Attempts by a credential that is not recognised, recorded without a name because there is none
- Whether anybody was rostered on at the time
Controller: the Coach (we process on their behalf) · Sources: Issued by the account owner or an authorised administrator; Recorded by a door reader when a credential is presented
Children and collection records (LaunchPoint ERP) · sensitive · optional
- A child’s name and date of birth, held so the room’s supervision ratio can be computed
- Which member is the child’s guardian
- The adults that guardian has authorised to collect the child, with a relationship and phone number
- Each check-in and check-out: the time, who handed the child over, and who collected them
- A written reason where a child was released to somebody not on the authorised list
Controller: the Coach (we process on their behalf) · Sources: Entered by the account owner or their staff from what the guardian tells them at the desk
Bank statement records (LaunchPoint ERP) · optional
- A name for a bank account, the bank it is held at, and the last four digits of its number — never the full number
- Imported statement lines: the date, the amount, and the description the bank wrote, which often names the counterparty
- Which line was matched to which bill, expense or ledger entry, by whom, and when
- Which months the account owner has closed, and when a closed month was reopened
Controller: the Coach (we process on their behalf) · Sources: A statement file the account owner exports from their own bank and imports themselves
Business identity for a white-label app listing · sensitive · optional
- The coach’s registered legal entity name, business address, business phone and business email
- Their Employer Identification Number (EIN), and their D-U-N-S number where they already have one
- The name and title of the person with authority to sign for the business
- The store listing they write, their brand colours, and the logo and store artwork they upload
- Their answers to the intake’s yes/no permissions, their typed electronic signature, the time it was signed, and which version of the wording they signed
- Business paperwork they choose to attach, such as an LLC or incorporation certificate
- A government photo ID, ONLY where a store or Dun & Bradstreet specifically asks for one — never requested by default, and optional in the form
- The App Store Connect issuer ID, key ID and private .p8 API key used to provision the coach organization’s app; the private key is stored in Azure Key Vault, while the application database keeps only its opaque versioned vault reference
Controller: the Coach (we process on their behalf) · Sources: Entered by the coach themselves, through a single-use intake link we send them; Provided once by a platform administrator after the coach organization grants the named App Store Connect access needed to manage its app
Paired browser extensions · optional
- A pairing code, stored only as a SHA-256 hash and valid for five minutes and one use
- A per-browser access token, stored only as a SHA-256 hash — the readable value exists once, in the browser that paired, and is never recoverable afterwards
- A label the extension reports so you can tell your browsers apart, such as “Chrome on Windows”
- When each browser was paired, when it last called us, and when it was revoked
Controller: LaunchSite OS · Sources: Created by you when you generate a pairing code in Settings; Reported by the extension itself when it pairs
Pages and optional screen images Co-Work uses · sensitive · optional
- Your spoken or typed instruction for the browser session
- A text description of visible page controls, their labels and field values
- When you enable screen sharing: still images of the connected tab’s visible viewport, which may include client health information or imagery
- The page address and the sites allowed for this session
- Session history recording the instruction, step kinds, element references and outcomes
Controller: LaunchSite OS · Sources: The browser tab you connect to Co-Work, only while your session is running; LaunchSite and at most one additional site you explicitly allow for that session; Screen images require the extension’s screen-sharing choice and browser permission; password, payment, one-time-code and marked private controls, and opaque frames, are masked
Records brought across from a coach’s previous platform · sensitive · optional
- Client names, email addresses, phone numbers and status, as the previous platform recorded them
- Programme, workout and exercise names and their contents
- Whatever else that platform returned alongside those records — the capture is stored exactly as it arrived, unedited
- Where a coach opens their check-in or progress history on the old platform, whatever that page returned about their clients — which can include weights, measurements and notes about symptoms or wellbeing
- NEVER an image. Only responses the platform sends as JSON are read, so progress photos are not captured, not transmitted and not stored
Controller: the Coach (we process on their behalf) · Sources: Read from the coach’s own account on their previous platform, by the LaunchSite Sync browser extension, using the session already open in that browser; No password or credential for that platform is ever sent to LaunchSite, and LaunchSite never contacts that platform itself
We do not buy personal information from data brokers. Where information reaches us from a device or an outside service - Apple Health, a wearable, a connected calendar or inbox, a payment processor - it does so because you authorised that connection, and you can disconnect it.
California statutory categories
For California residents, the categories above map to the statutory categories in the CCPA/CPRA as follows. The purposes and recipients are described in Sections 4 and 8. We do not sell information for money or send client health information for advertising. Optional public-site measurement sends identifiers, internet activity, and limited commercial information to Google only after you allow it; you can decline or withdraw this choice as described in Section 11.
- Identifiers (name, email, phone, IP address, account identifiers) - collected as: Connected mailbox correspondence; Privacy requests, permissions, and review records; Account erasure work and completion evidence; Signed coach-client agreement evidence; Coach agreement acceptance records; Account and profile information; Messages and conversation content; Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity; Subscription and payment information; Campaign and engagement records; Community moderation reports and flags; Participation and activity records in a group space; Public AI demo requests; Usage, device, and diagnostic data; Optional public-site advertising measurement; Workforce and employment records (LaunchPoint ERP); Building access records (LaunchPoint ERP); Children and collection records (LaunchPoint ERP); Bank statement records (LaunchPoint ERP); Business identity for a white-label app listing; Paired browser extensions; Records brought across from a coach’s previous platform.
- Personal information in customer records (Cal. Civ. Code § 1798.80(e)) - collected as: Connected mailbox correspondence; Historical chart tables and saved charts; Signed coach-client agreement evidence; Account and profile information; Client wellness and health-related records; Pre-participation health screening; Lab files and extracted markers; Connected device and wearable metrics; Messages and conversation content; AI prompts, outputs, and workspace memory; Workforce and employment records (LaunchPoint ERP); Children and collection records (LaunchPoint ERP); Records brought across from a coach’s previous platform.
- Characteristics of protected classifications - collected as: Children and collection records (LaunchPoint ERP).
- Commercial information (products or services purchased or considered) - collected as: Coach agreement acceptance records; Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity; Subscription and payment information; Optional public-site advertising measurement; Bank statement records (LaunchPoint ERP); Business identity for a white-label app listing.
- Biometric information - collected as: Voice input, call recordings, transcripts, and synthetic voice.
- Internet or other electronic network activity - collected as: Connected mailbox correspondence; Optional public AI demonstration; Coach agreement acceptance records; Messages and conversation content; Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity; Campaign and engagement records; Participation and activity records in a group space; Public AI demo requests; Usage, device, and diagnostic data; Optional public-site advertising measurement; Paired browser extensions; Pages and optional screen images Co-Work uses.
- Geolocation data - collected as: Building access records (LaunchPoint ERP).
- Audio, electronic, visual, or similar information - collected as: Progress photos and movement video; Voice input, call recordings, transcripts, and synthetic voice; Pages and optional screen images Co-Work uses.
- Professional or employment-related information - collected as: Account and profile information; Workforce and employment records (LaunchPoint ERP).
- Inferences drawn from the above - collected as: Optional public AI demonstration; Client wellness and health-related records; Prospect, lead, and CRM contact information; AI prompts, outputs, and workspace memory; Community moderation reports and flags.
- Sensitive personal information (including health information) - collected as: Connected mailbox correspondence; Historical chart tables and saved charts; Privacy requests, permissions, and review records; Account erasure work and completion evidence; Signed coach-client agreement evidence; Client wellness and health-related records; Pre-participation health screening; Lab files and extracted markers; Progress photos and movement video; Connected device and wearable metrics; Voice input, call recordings, transcripts, and synthetic voice; AI prompts, outputs, and workspace memory; Community moderation reports and flags; Public AI demo requests; Children and collection records (LaunchPoint ERP); Pages and optional screen images Co-Work uses; Records brought across from a coach’s previous platform.
Statutory categories not listed - notably precise geolocation - are not collected.
3. Information we deliberately do not collect
- We do not store full payment card numbers; the payment processor handles them.
- We do not place advertising tags in coach or client workspaces or on coach-owned sites. We do not send names, email addresses, form contents, or client health-related information through our optional public-site measurement tag.
- We do not collect precise geolocation.
- We do not collect raw continuous sensor streams from wearables - only the daily aggregates and scores needed for coaching trends.
4. How we use information, and our legal basis
We use each category only for the purposes listed for it. Where the GDPR or UK GDPR applies to you, the legal basis is stated alongside.
Connected mailbox correspondence
- Show matched correspondence on the existing CRM lead timeline for coach review
- Honor opt-out requests; synchronized mail does not trigger reply workflows or assigned AI agents without a supported trusted sender-verification source
Legal basis: Processed on the coach’s documented instructions; the coach determines the applicable basis and any additional condition required for sensitive correspondence.
Historical chart tables and saved charts
- Retain existing client records from the retired Charts workspace; its imports, saved snapshots, sharing and access remain unavailable. Current MCP chart rendering uses the original coaching records, not these historical chart stores
Legal basis: Art. 6(1)(b) with Art. 9(2)(a) explicit consent obtained by the Coach where the selected data concerns health
Optional public AI demonstration
- Generate the requested fictional example with the disclosed AI provider
- Limit abuse of the free demonstration
Legal basis: The visitor’s requested demonstration and legitimate interests in preventing abuse
Privacy requests, permissions, and review records
- Handle privacy rights and eligibility reviews
- Preserve accurate evidence without inventing past permissions
- Apply documented processing restrictions and track unresolved requests
Legal basis: Applicable legal obligations and legitimate interests in handling rights and security requests; permission evidence records the asserted basis rather than creating one
Account erasure work and completion evidence
- Remove active account data and files reliably
- Track provider work, shared records, backups, versions and retained exceptions separately
- Retry incomplete work and prevent reintroduction after restoration
Legal basis: Applicable deletion obligations and legitimate interests in completing and documenting requested erasure
Signed coach-client agreement evidence
- Give coach and client the same finalized agreement
- Prevent later edits from changing signed evidence
- Record amendment, void and reviewed erasure decisions
Legal basis: Performance of the coaching agreement and applicable recordkeeping or dispute purposes; any health content requires an applicable special-category condition
Coach agreement acceptance records
- Record which platform agreements a coach accepted
- Provide copies and investigate agreement disputes
Legal basis: Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interests in keeping evidence of agreements and resolving disputes.
Account and profile information
- Create and secure your account
- Authenticate you and enforce role-based access
- Send service, security, and account notices
- Display a participant’s name and existing profile picture alongside their score in the Performance League, subject to their League participation setting and the viewer’s access to the same coach roster or community
- Show a coach to other coaches in the coach directory, but only if that coach has switched their listing on — their name, photo, headline, region and specialities, and never their clients, roster size, revenue or plan
Legal basis: Art. 6(1)(b) performance of a contract; Art. 6(1)(f) legitimate interests in securing the service
Client wellness and health-related records
- Operate the coaching workspace and the client portal
- Produce coaching outputs: grades, programs, summaries, reminders, progress tracking
- Provide coach-selected learning materials to authorized viewers and record lesson completion
- Enable coach-to-client communication
- Keep coach-only records of who created or last updated assigned plans and who requested lab analysis
- Support Shared coaching: a client’s primary coach or an authorized team admin selects teammates, their responsibilities and client-specific permissions; the platform synchronizes a group conversation containing the client and selected coaches. Removing a collaborator ends that shared-coaching grant and group access, while independent team permissions and retained records remain in place
- Answer the client’s own questions about their plan and their own records, where their coach has enabled the assistant
Legal basis: Art. 6(1)(b) performance of the coaching contract, with Art. 9(2)(a) explicit consent for health data obtained by the Coach as controller
Pre-participation health screening
- Establish whether a client should speak to a doctor before starting physical activity
- Require a coach to review a flagged answer before that client books a class themselves
- Give the business a record of who has been screened and who has not
Legal basis: Art. 6(1)(b) performance of the coaching contract, with Art. 9(2)(a) explicit consent for health data obtained by the Coach as controller
Lab files and extracted markers
- Extract report text, confidence, and table or row locations so a coach can verify marker facts against the uploaded source
- Produce lab summaries and overlays for coaching
- Track markers over time
- File an uploaded report against the right client and panel type
Legal basis: Art. 6(1)(b) with Art. 9(2)(a) explicit consent obtained by the Coach
Progress photos and movement video
- Visual progress tracking
- Coach form review and feedback
Legal basis: Art. 6(1)(b) with Art. 9(2)(a) explicit consent obtained by the Coach
Connected device and wearable metrics
- Show source-labeled trends to the client and their coach
- Inform coaching decisions
- Answer the client’s own questions when their coach has given them an AI assistant: their recent readings are included in the request sent to the AI provider so the answer reflects the week they actually had
Legal basis: Art. 6(1)(a) consent, with Art. 9(2)(a) explicit consent for health data
Messages and conversation content
- Deliver the message and show the conversation
- Run coach-configured CRM replies on the chosen connected account, match replies to the same conversation, prevent duplicate processing, and pause automated replies for human handoff or opt-out; when the coach explicitly enables it, an unmatched inbound sender creates a CRM contact and lead
- Show a community post and its comments — whoever wrote them — to the other members of that community, including any coach the room’s owner has invited into it
- Prove consent and honour unsubscribe and quiet-hours rules
- Detect and prevent abuse of the messaging channels
Legal basis: Art. 6(1)(b) performance of a contract; Art. 6(1)(c) legal obligation for consent and opt-out records
Voice input, call recordings, transcripts, and synthetic voice
- Help the coach review and improve their own calls
- Produce audio playback of written content
- Turn what the coach said into the text of their request
Legal basis: Art. 6(1)(a) consent of every party to the call, obtained by the Coach; Art. 6(1)(f) legitimate interests in the coach’s own performance review
Prospect, lead, and CRM contact information
- Run the coach’s pipeline
- Attribute which campaign produced a lead
- Follow up with the person
Legal basis: Art. 6(1)(f) legitimate interests of the Coach in managing their own business enquiries; Art. 6(1)(a) consent where required for electronic marketing
LaunchSite OS business contacts and activity
- Manage LaunchSite OS business enquiries and follow-up in a shared CRM
- Keep business records available to the three authorized business owners and separate from their coaching records
Legal basis: Art. 6(1)(f) legitimate interests in managing business enquiries; Art. 6(1)(a) consent where required for electronic marketing
Subscription and payment information
- Take payment and manage subscriptions
- Collect managed coach app setup fees and maintain the related monthly subscription
- Pay out marketplace sellers
- Pay referral partners the commission they have earned, which means transmitting the PayPal address they gave us to PayPal in order to send that payment
- Let a coach charge for a consultation booked on their own booking page, and show them which bookings are paid
- Meet tax and accounting obligations
Legal basis: Art. 6(1)(b) performance of a contract; Art. 6(1)(c) legal obligation for tax and accounting records
Campaign and engagement records
- Show the coach whether a campaign delivered
- Connect the business locations and marketing accounts the coach selects for their workspace
- Let the coach read business reviews and publish explicitly authorized replies to Google or Facebook
- Send eligible contacts and members a request for honest feedback, when the coach queues one or enables a future-event rule
- Publish the coach’s selected public reviews in a clearly labelled widget until the coach revokes it
- Compare observed email engagement between randomly assigned campaign variants
- Keep a returning browser on its assigned funnel variant and compare observed visitor-to-enquiry conversion between those variants
- Report provider spend alongside mapped CRM leads and recorded collection, keeping currencies separate and identifying incomplete data
- Import enquiries from the selected provider forms, preserve existing contact preferences, prevent duplicate imports and record the owner’s review before email follow-up
- Publish coach-approved social content at the selected time and reconcile provider-confirmed publishing outcomes
- Suppress future sends to people who unsubscribed or complained
- Let a coach see who has already been contacted, so the same member is not approached twice
- Report how many contacted members returned to a class
Legal basis: Art. 6(1)(f) legitimate interests in measuring delivery; Art. 6(1)(c) legal obligation for suppression records
AI prompts, outputs, and workspace memory
- Produce the output that was requested
- Render a requested chart from authorized coaching records with bundled Flint and Vega software, without sending chart data to Microsoft or a separate chart service
- Keep AI features grounded in the coach’s own workspace
- Answer a client’s own questions from the material their coach published, and from the parts of their own record they can already see in their portal
- Reconcile stored memories when newer information contradicts them
- Meter usage
- Monitor whether AI features are working correctly — speed, failures, and whether answers were grounded in the coach’s own material
- Let a coach use their own AI client to read eligible workspace data and make changes to it. A change takes effect as soon as the coach allows the action in that AI client — LaunchSite does not ask for a separate confirmation, and records every change in the coach’s activity history
- Read posts and comments written in a community to flag ones a coach may need to look at
Legal basis: Art. 6(1)(b) performance of a contract, inheriting the Art. 9 condition of the underlying record
Community moderation reports and flags
- Show a community’s coaches what may need their attention, so a room stays usable
- Let a coach see repeated incidents involving one member as a pattern rather than in isolation
- Record what a coach decided about a report
Legal basis: Art. 6(1)(f) legitimate interests in keeping a shared space safe, inheriting the Art. 9 condition of the underlying post
Participation and activity records in a group space
- Show a member where to start in a space
- Let a coach see who has disengaged, by name, so they can reach out
- Rank a space’s leaderboard among the members of that space only
- Release a coach’s material at the pace they set, counted from when each member joined
Legal basis: Art. 6(1)(b) performance of the coaching contract, and Art. 6(1)(f) legitimate interests in a group space that works
Public AI demo requests
- Build the day of meals that was asked for and show it back
- Limit each network to three free builds a day, so the demo cannot be used to run up AI costs
Legal basis: Art. 6(1)(f) legitimate interests in demonstrating the product and protecting it from abuse, with Art. 9(2)(e) where a visitor chooses to make health details about themselves public by typing them into a demo on an open web page
Usage, device, and diagnostic data
- Keep the service secure and reliable
- Diagnose faults
- Deliver notifications you asked for
- Investigate abuse
Legal basis: Art. 6(1)(f) legitimate interests in the security, integrity, and reliability of the service
Optional public-site advertising measurement
- Remember and honour your measurement choice
- Understand whether our advertisements lead to visits, coach signups, and paid subscriptions
- Avoid counting the same confirmed conversion more than once
Legal basis: Art. 6(1)(a) consent for optional measurement; Art. 6(1)(f) legitimate interests in remembering and honouring your privacy choice
Workforce and employment records (LaunchPoint ERP)
- Operate the employer’s rota, timesheet, and labor-cost reporting
- Show the organization’s structure — who works where and who reports to whom
- Authenticate an employee and decide which parts of the organization they may read
- Keep an audit record of changes to employment, access, and approved hours
Legal basis: Art. 6(1)(b) performance of the employment relationship and Art. 6(1)(f) legitimate interests of the employer in operating and staffing the business, in each case with the employer as controller
Building access records (LaunchPoint ERP)
- Decide whether a member or employee may enter the building at that moment
- Answer who was in the building after an incident, an injury, or a theft
- Show the account owner which entries happened while nobody was on shift
Legal basis: Art. 6(1)(b) performance of the membership or employment relationship for entry itself, and Art. 6(1)(f) legitimate interests of the operator in the security of their premises and the safety of the people in them, with the operator as controller
Children and collection records (LaunchPoint ERP)
- Make sure a child is only released to an adult their guardian authorised
- Keep the room within its staff-to-child supervision ratio
- Answer who had a child, and when, after an incident or a dispute
Legal basis: Art. 6(1)(f) legitimate interests of the operator and, decisively, of the child in being released only to an authorised adult — an interest that a child cannot assert for themselves, which is why the guardian supplies the record and the operator is controller. Art. 6(1)(c) legal obligation where local childcare regulation requires an attendance and collection register. No Art. 9 processing: no health data about a child is collected.
Bank statement records (LaunchPoint ERP)
- Check the business’s own books against its bank statement
- Show what moved on the bank with no record behind it, and what was recorded and never settled
- Produce a general journal and trial balance the account owner can give to their accountant
Legal basis: Art. 6(1)(f) legitimate interests of the business in keeping accurate books, and Art. 6(1)(c) legal obligation where accounting and tax law requires records to be reconciled and retained, with the account owner as controller
Business identity for a white-label app listing
- Request a D-U-N-S number on the business’s behalf from Dun & Bradstreet, where they do not already have one
- Enrol the business in the Apple Developer Program and publish their branded app under their own account, as Apple’s guideline 4.2.6 requires
- Publish their Google Play listing and build their app with their own branding
- Create and reconcile the Expo project, Apple bundle identifier, app capabilities, build credentials and store connection through supported provider APIs
Legal basis: Art. 6(1)(b) performance of the contract to build and publish the coach’s branded app, since Apple and Google will not issue a developer account or accept a listing without this information. The electronic signature and the permissions recorded alongside it are also relied on under Art. 6(1)(f) legitimate interests in being able to evidence what the business authorised
Paired browser extensions
- Let an extension you installed reach your own LaunchSite account without holding your password
- Show you every browser that can currently reach your account, so you can revoke one you do not recognise
- Tell you when each browser was last active, so the revoke list means something
Legal basis: Art. 6(1)(b) performance of a contract, since the pairing is what makes an extension you chose to install able to work with your account; Art. 6(1)(f) legitimate interests in securing accounts, for the activity and revocation record
Pages and optional screen images Co-Work uses
- Understand the visible page and choose the next step toward your request
- Describe proposed browser actions and their observed outcomes
- Show you the session’s progress and outcome
Legal basis: Art. 6(1)(b) performance of a contract; where visible content includes health data, processed on the coach’s instructions under the applicable health-data consent basis
Records brought across from a coach’s previous platform
- Show the coach what was found so they can decide what to import
- Create the clients, contacts and programmes the coach chooses to bring across
- Let an import that mapped a field wrongly be explained and corrected afterwards
Legal basis: Art. 6(1)(b) performance of the contract with the coach, who is moving their own business records into the service; Art. 6(1)(f) legitimate interests of the coach and their clients in continuity of coaching when a coach changes platform. Where a capture includes health-related information about a client, the coach relies on Art. 9(2)(a) explicit consent obtained by them as the controller of that record, on the same basis as the wellness records they already hold in LaunchSite
Across all categories we also use information to secure the platform, prevent and investigate abuse, meet our legal obligations, and enforce our terms.
We do not sell or rent personal information for money. Our optional public-site measurement is configured with ad personalization disabled; it is used to measure advertising results, not to build remarketing audiences. We do not use client health-related information for advertising, targeted advertising, or profiling that produces legal or similarly significant effects. We do not use client data to train AI models, and our AI providers are contractually barred from doing so.
5. AI-assisted features
Features such as draft program suggestions, lab-result summaries, message drafts, transcription, and the coach copilot send relevant workspace information to the AI providers listed at /privacy/subprocessorsto produce the requested output. Provider processing and retention depend on the applicable service terms and account settings, including security and abuse monitoring. A public vendor reference is not proof of a particular account's agreement or zero-retention setting.
AI features operate only on your own workspace data. Output is assistive and informational - a drafting aid for the Coach, not medical advice - and the Coach reviews and remains responsible for any decision. Client-authored content is treated as untrusted input when it enters a prompt, and actions that change data run only from an explicit, authorised instruction.
A Coach may separately connect an external AI client through the Model Context Protocol (MCP). That client receives only data the Coach's current role and permissions allow, and each change requires a one-time approval in LaunchSite. The external AI provider is selected by the Coach, not engaged by LaunchSite as our subprocessor. Its own privacy, retention, and model-training terms apply after data is returned to it. Revoking the connection stops future access but does not remove copies the external provider already holds.
6. How we protect information
- Encryption of data in transit (HTTPS/TLS) and at rest at the database and storage layers.
- Database row-level security so a Coach can reach only their own clients, and a client only their own records.
- Server-side enforcement of coach and client roles on every request; authorisation roles are never taken from user-editable data.
- Health files, lab uploads, and progress photos are held in private storage and served only through authenticated, short-lived access - never a public or long-lived URL.
- Hardened HTTP security headers (HSTS, anti-clickjacking, MIME protection).
- Least-privilege, scoped access for automated and AI tooling, and audit records of privileged actions.
No method of transmission or storage is perfectly secure, but we work to protect your information using safeguards appropriate to its sensitivity.
7. Service providers and other recipients
We publish 29 third-party providers, with each provider's purpose, processing region, activation, and categories of data at /privacy/subprocessors. Providers processing coaching records on our behalf may not use client data for their own purposes or to train AI models. The register separately identifies Google Ads as an independent controller for optional public-site measurement; it receives no client records. Connected services and visitor-consented measurement are marked separately.
We maintain that page as the current register rather than a list "available on request." If you are a Coach and want notice of changes to it, email privacy@launchsite-os.com.
8. Sharing and disclosure
We disclose information only:
- to the Coach who owns the client or lead relationship, and to team members that Coach has authorised;
- to subprocessors under contract, as described above;
- to Google Ads for optional public-site measurement after you allow it, limited to the information described in Section 11 and the measurement category in Section 2;
- to a third-party service you connected, to the extent needed to provide that feature - the outbound channels below set out what each one can send;
- to comply with law or valid legal process - we assess each request, require valid process, and will notify the affected user unless legally prohibited;
- to protect the rights, safety, and security of users and the platform, or to investigate abuse; or
- in connection with a merger, acquisition, or sale of assets, in which case we will require the recipient to honour this policy and will notify you of any material change.
We will not otherwise disclose client health-related information without authorisation.
Systems a Coach connects, and what we send them
A Coach can connect their own software - an automation platform, a CRM, or something they run themselves - and have LaunchSite OS send it a message when something happens in their workspace. These connections are off unless a Coach sets one up, the Coach chooses the receiving system and supplies its address, and the Coach can change or remove it at any time. Because we do not choose these destinations, they are not in the subprocessor list; each one is set out here instead.
Social publishing to connected business accounts
Destination: The Facebook Pages and Instagram professional accounts the coach connects and selects for a post. Published posts are visible under those accounts at the provider.
How it is turned on: A coach saves a draft, then explicitly releases it for immediate or scheduled publication to selected enabled accounts. Connecting an account or saving a draft does not release a post.
What can be sent:
- The caption, optional Facebook link, selected marketing images or uploaded Instagram Reel video
- The selected business account identifiers and instructions to prepare and publish the post
- An unguessable public media address so Meta can retrieve the released copy of an image or video
What is never sent through it:
- Private coaching files are not selectable through the social media picker
Content the Coach controls: The coach writes the caption and chooses or uploads the media. We do not inspect their content for personal or health information. The coach controls what becomes public; published copies remain subject to the provider’s controls.
Public replies to business reviews
Destination: The Google Business Profile location or Facebook Page the coach connects and selects. The provider displays the reply publicly against a review or recommendation.
How it is turned on: A coach writes the reply and explicitly chooses to publish it. Imported reviews do not cause an automatic public reply.
What can be sent:
- The coach’s reply text and the provider identifiers for the business, review and existing reply where applicable
What is never sent through it:
- Coaching records are not automatically attached to review replies
Content the Coach controls: Reply text is written by the coach and is not filtered for personal or health information. Coaches choose what they disclose publicly.
Email requests for business reviews
Destination: A lead or member selected by the coach, or a qualifying member after the coach activates a first-attendance or first-payment rule. Delivery uses the coach’s configured email service.
How it is turned on: A coach queues an individual request or explicitly enables a rule for future qualifying events. The delivery worker checks marketing eligibility, opt-out preferences, quiet hours and the request cooldown before sending.
What can be sent:
- Recipient name and email address
- The coach’s review-request subject and message, business review link, business postal address and unsubscribe link
What is never sent through it:
- Attendance details, payment amounts and coaching records are not attached to the request email
Content the Coach controls: The coach controls the email wording. It is not inspected for personal or health information.
Webhook Endpoints (event delivery to a system the coach connected)
Destination: An HTTPS URL the coach enters. The coach selects the receiving system - for example an automation platform such as n8n, Make, Zapier, or GoHighLevel, or software they run themselves - and can change or remove it at any time.
How it is turned on: Off unless a coach creates an endpoint. Each endpoint is created with an explicit choice of what it may carry, and each message is signed with a secret unique to that endpoint so the receiving system can verify it came from us.
What can be sent:
- The event that occurred (for example, a check-in was submitted, or a compliance figure fell below the threshold the coach set) and when it occurred
- The client identifier the event concerns, and the identifier and threshold of the automation that sent it
- A compliance percentage, where the event is about compliance
- The programme phase the client is in or has moved to
- How many days or check-ins have been missed, the date of the last check-in or daily log, and the client’s check-in schedule
- The identifier of the check-in or message the event refers to - the identifier only, never its contents
- The client name, email address, and phone number - only where the coach set that endpoint to include contact details, which exists because most automation platforms match their own contact records on email or phone
What is never sent through it:
- Check-in answers and any free text a client wrote
- Wellness system-status grades
- Lab results and uploaded documents
- Progress photographs and other imagery
- Message content
Workflow Webhook (lead delivery from a CRM workflow step)
Destination: One of the coach’s own registered Webhook Endpoints, named by a step inside one of their CRM workflows. The coach registers the destination, and can change, disable or delete it at any time.
How it is turned on: Off unless a coach registers a Webhook Endpoint and adds a webhook step to a workflow that names it.
What can be sent:
- That a lead reached a given point in the coach’s workflow, which workflow it was, and when
- The lead identifier, its pipeline stage, where it came from, its deal value, and when it was created
- Marketing attribution recorded with the lead (UTM campaign, source, and medium)
- The labels the coach has applied to that lead
- Every custom field the coach has defined on their leads, with its values
- The lead name, email address, and phone number - only where the coach set that endpoint to carry contact details
What is never sent through it:
- Client coaching records - check-ins, wellness grades, labs and imagery belong to a client rather than a lead, and no lead webhook can reach them
- The content of messages sent to or from the lead
Content the Coach controls: Custom lead fields are created and named by the coach, and we do not restrict what goes in them. A coach who records health-related notes in a custom field will send those notes to their chosen destination. Coaches choose what to collect there and where it goes.
9. Data retention
We keep information only as long as it is needed for the purpose it was collected for:
- Connected mailbox correspondence - Matched correspondence remains with the CRM lead until that record is erased. Disconnecting stops collection but preserves CRM history. Unmatched message bodies and attachments are not retained by the importer; minimal deduplication identifiers remain with the mailbox record.
- Historical chart tables and saved charts - Any previously saved table columns and chart snapshots remain stored with the client record; the original CSV file was not retained. Retiring the Charts workspace does not delete these records. Deleting the client deletes imported tables and saved charts. These historical records cannot be accessed through the portal or MCP, and retirement cannot recall copies already downloaded. Read-only MCP chart requests do not create new records in these chart stores.
- Optional public AI demonstration - The demo route does not save the prompt or generated example to a workspace. They are processed for the response and remain visible in the visitor’s browser. Rate-limit metadata has a rolling daily window. Provider handling follows the applicable terms and settings; visitors must not enter personal or client health records.
- Privacy requests, permissions, and review records - Restricted operational and permission evidence can remain after account closure while a documented retention or deletion review is pending. It is not a reason to keep the entire health history. There is no automatic claim that all retained evidence has expired.
- Account erasure work and completion evidence - The deletion manifest survives account removal so cleanup can continue. Unverified provider, backup, shared-record and evidence-retention items remain pending review; account removal does not mean all copies have been erased. Minimal completion and suppression evidence is retained for the applicable documented purpose.
- Signed coach-client agreement evidence - Finalized evidence is protected against ordinary editing and deletion. Account closure sends retained agreement evidence for separate retention or erasure review; it is not silently rewritten or treated as permanent authority to retain unrelated records.
- Coach agreement acceptance records - Retained separately from the account, including after account deletion, to evidence the arrangement and address disputes. These records are append-only for application users and administrators; no automatic expiry or deletion schedule is currently implemented. Requests concerning these retained records require a separate review.
- Account and profile information - While the account is active. Account removal starts tracked erasure; provider copies, backups, minimal agreement evidence and applicable tax or legal holds are reviewed separately rather than represented as erased immediately.
- Client wellness and health-related records - While the coach’s workspace holds the record. Coaches may export or delete a client’s records at any time; deleted records are purged from active systems and roll off backups on the backup schedule. Uploaded course documents are held in private file storage. Replacing a document or deleting its lesson removes the lesson reference; those actions do not delete the stored file bytes. Separately, a plan a coach is drafting but has not yet saved is held on that coach’s own device (browser or app storage) so it survives a reload and can be edited by the assistant. It is not transmitted to or stored by us, is discarded automatically after three days, and is erased when a different coach signs in on that device. Because it never reaches our systems, deleting a client’s records in the workspace does not remove a draft already on a coach’s device; it expires on its own.
- Pre-participation health screening - Held while the coach’s workspace holds the client record, so the business can show who was screened before training. Deleting the client deletes their answers. Answers are never copied into the activity log — only whether a screening was flagged — and are never sent to an AI model.
- Lab files and extracted markers - Held in private storage while the workspace holds the record; deleted on client or coach request. Any snapshots from the retired Charts feature remain historical records and are deleted with the client record. They are no longer available through the portal or MCP; copies already downloaded cannot be recalled.
- Progress photos and movement video - Held in private storage while the workspace holds the record; deleted on client or coach request.
- Connected device and wearable metrics - Disconnecting a device stops future sync and removes the imported aggregates from the active workspace. Revoking access at the device maker separately stops new reads.
- Messages and conversation content - Conversations are held while the workspace holds them. A community post and its comments are held while that community exists; deleting the post removes its comments with it, and either the author or a coach in that community can remove a comment. A direct-message video original is made available from private storage after its upload is verified. When a compatible copy passes verification it replaces the active original at the same private message URL; if conversion fails, the original remains available instead. Active message videos are removed after 90 days while the message and caption remain. Storage versioning and recovery controls can retain an overwritten or deleted video version for up to approximately 37 additional days. Opt-out records are kept indefinitely on purpose — an erased opt-out is an opt-out that stops working.
- Voice input, call recordings, transcripts, and synthetic voice - Recordings and transcripts are held while the coach keeps them and are deleted on request. Derived call metrics about the coach are retained without the underlying transcript where the coach deletes it. Microphone audio captured for a voice feature is sent for transcription and is not stored by us afterwards — what is kept is the resulting text, as part of the conversation it belongs to. The segment recorded while the assistant is speaking is discarded in the browser as soon as that reply finishes, and is only ever sent anywhere if the coach actually interrupted; it is never captured at all when “Talk to interrupt” is off.
- Prospect, lead, and CRM contact information - While the coach keeps the record. A person may ask the coach to export or erase their record; erasure keeps only a non-identifying audit entry proving the erasure happened.
- LaunchSite OS business contacts and activity - Held while the business keeps the record. CRM erasure removes identifying contact data and retains a non-identifying audit entry. Switching profiles does not copy or delete records.
- Subscription and payment information - Transaction records are retained for the period tax and accounting law requires, typically seven years.
- Campaign and engagement records - Engagement events roll off with the campaign. Suppression and complaint records are kept indefinitely so they keep working. A member’s consent log (client_marketing_consents) is APPEND-ONLY and kept for the life of the workspace: a withdrawal is a new row rather than a deletion, because “we stopped when they asked” is only provable if the record of them asking survives — and deleting the earlier grant would destroy the evidence that the send before it was lawful. Marketing connection and account metadata, imported ad metrics, campaign mappings and social publishing records remain until the workspace is deleted; disconnecting clears stored provider credentials and disables those accounts. Social media is made available by a token link only after explicit release; published copies held by the social provider follow that provider’s retention and deletion controls. Cached public review content and its reply state expire after 29 days without refresh and are removed by the hourly review sweep; expired content is never displayed. Review-request records remain for the life of the workspace. Disabling a review widget immediately revokes its public link. Lead-form capture identities remain until workspace deletion to prevent duplicate imports. Deleting a contact removes its linked permission evidence and contact reference, so replay does not restore it. Funnel visitor cookies last up to 90 days. Hourly maintenance removes experiment contact links and rotates visitor hashes older than 90 days in bounded batches, retaining anonymous historical conversion counts until the funnel is deleted.
- AI prompts, outputs, and workspace memory - Prompts and outputs are held with the workspace record they belong to. LaunchSite does not use client health information to train models. Provider handling depends on the product, account settings and applicable terms; a registry entry alone does not verify those terms. A saved memory a coach deletes is recoverable for 30 days and is then permanently removed. A memory that newer information replaces is NOT deleted straight away: it is marked superseded, stops being used in any answer, and is kept alongside what replaced it — with a record of why it was replaced — so the change is visible and can be undone. That history is kept for 12 months and then permanently deleted. Deleting a memory removes it; superseding one defers removal. Where a client moves to a different coach, the previous coach’s saved memories about them are deleted outright. When a coach connects an external AI client through MCP, data returned to that client is subject to the selected provider’s own retention, privacy, and model-training terms. Revoking the LaunchSite connection stops future access but cannot delete copies already held by that external provider. Read-only MCP chart rendering does not save a new chart snapshot or imported table in LaunchSite. Chart data, source references and images returned to the external AI client, and any downloaded copies, are subject to that provider’s terms and the recipient’s handling. The operational records of AI runs are kept for as long as the account is open so that changes in AI quality remain measurable over time. They hold no prompt, reply, or document text, and are used only to operate and improve the service.
- Community moderation reports and flags - A flag is held while the community exists and is removed with the post or comment it is about. Repeated incidents are counted over a rolling 90 days. Hiding a post is reversible and is not deletion; the post and its comments remain and can be restored by a coach.
- Participation and activity records in a group space - Step progress lives with the space and is removed with it, or with the step it belongs to. A leaderboard is computed at read time from posts and comments and is never stored. Ranking is governed by the same single opt-in as the Performance League, changed in one place.
- Public AI demo requests - Nothing a visitor types, and nothing the assistant replies, is written to a database. The request and the plan exist only for the length of the request that produced them, and closing the page ends them. What does persist is the counting row: a one-way hash of the IP address, a count, and the time the current 24-hour window opened. It holds no plan text and no request text, the address itself is not recoverable from it, and the count resets once the window lapses. Those rows are not currently on a deletion schedule, so a lapsed row stays until it is reused or removed by hand.
- Usage, device, and diagnostic data - Operational logs are retained on a rolling short-term schedule. Audit records are retained for the life of the workspace.
- Optional public-site advertising measurement - Your browser remembers the measurement choice for up to 180 days. Conversion-counting markers last for the browser tab session. Consented first-party advertising cookies are configured with a maximum lifetime of 90 days. Withdrawing consent stops future measurement and removes the advertising cookies this site can clear; it does not recall information already received by Google or delete cookies on Google domains. Google retains information under its own policies and applicable terms. Account deletion does not automatically remove browser storage or Google-held measurement information.
- Workforce and employment records (LaunchPoint ERP) - For the life of the employer’s workspace. Employment records are retired rather than deleted — an employee’s status is set to terminated and the record is kept as employment history. An employee sign-in account is deleted when the account owner revokes it, and revoking it also deletes that person’s access grants.
- Building access records (LaunchPoint ERP) - For the life of the operator’s workspace. A revoked credential is deactivated rather than deleted, and door records are kept rather than trimmed, because the question they answer — who was in the building on a given night — is usually asked long afterwards.
- Children and collection records (LaunchPoint ERP) - Collection records are kept for the life of the operator’s workspace rather than trimmed, because the question they answer — who collected this child, on this day — is asked long afterwards and usually only when something has gone wrong. A child who stops attending is deactivated, not deleted, for the same reason; an authorised adult is revoked rather than removed, so who was permitted last March stays answerable.
- Bank statement records (LaunchPoint ERP) - For the life of the account owner’s workspace. Deleting an import removes its lines and their matches; once a month is closed, imports inside it cannot be deleted, because a reconciliation whose evidence can be removed is not one. Accounting records are typically retained for the period tax law requires.
- Business identity for a white-label app listing - For as long as the coach’s branded app is published, because the same details are needed to renew the developer account and to answer store review. Uploaded artwork is kept with the app and copied into its private source repository. App Store Connect API credentials remain versioned in Azure Key Vault while LaunchSite manages the app; rotating the key creates a new vault version, and credential deletion on app withdrawal is not yet automated. A signed agreement is kept for the life of the arrangement and for as long afterwards as it may need to be evidenced. A photo ID, where one was ever required, is deleted once the store or agency that asked for it has completed its verification. The intake record is deleted on request once the app is withdrawn.
- Paired browser extensions - A pairing code is deleted or marked used within five minutes. A token record is kept for as long as the browser stays paired, and a revoked one is KEPT rather than deleted so the revocation stays visible to you — deleting it would make “revoked” and “never paired” look the same, which is the wrong answer after a suspected compromise. All of it is removed when the account is deleted.
- Pages and optional screen images Co-Work uses - Page descriptions and optional viewport images are sent to our AI provider for the current step and are not saved in our database, application logs, or conversation transcript. Provider processing follows the provider’s applicable data terms. The session record keeps your instruction, allowed sites, step kinds, element references and outcomes with your account and is removed when the account is deleted. Site permission ends with the session. This feature does not record video or the desktop outside the connected tab.
- Records brought across from a coach’s previous platform - A capture stays until the coach imports or discards it, and in any case not indefinitely. DISCARDING deletes the captured content immediately, leaving only a record that a capture happened and was refused. A capture you never import is deleted outright 30 days after it was captured. IMPORTING keeps the captured copy so an import that mapped a field wrongly can still be explained, and that copy is erased 90 days after the import — the record that the import happened remains, without the captured content. Everything is also deleted when the coach’s account is deleted. Records the coach chooses to import become ordinary client and contact records and follow the retention for those categories.
Account access ends before all cleanup necessarily finishes. Our erasure workflow records active files and data, retries incomplete work, and tracks provider copies, shared records, retained agreement evidence, versions, and backups separately. A pending review is not completed deletion. Contact us for the status of your request and any applicable retained category, reason, and expiry. Coaches may request export or deletion of the client records they control; signed evidence has a separate review path.
10. Your privacy rights
Depending on where you live, you may have the right to:
- Know what personal information we hold and obtain a copy of it;
- Correct inaccurate information;
- Delete your information;
- Obtain a portable copy of information you provided;
- Limit the use of sensitive personal information;
- Opt out of sale, sharing, or targeted advertising where applicable, and decline or withdraw optional public-site measurement through the choice described in Section 11;
- Withdraw consent for the processing of consumer health-related data;
- Object to processing, or restrict it, where the GDPR applies; and
- Not be discriminated against for exercising any of these rights.
These rights come from laws including the California Consumer Privacy Act (CCPA/CPRA), the Kentucky Consumer Data Protection Act, the Washington My Health My Data Act, other state comprehensive privacy laws, and - where applicable - the EU and UK GDPR.
How to exercise them. If your information sits in a Coach's workspace - as a client or as someone in a Coach's pipeline - contact that Coach first. They control that workspace, they can export or erase your record in the app, and they are who you actually have a relationship with. If you do not know who holds your information, or a Coach does not respond, contact us at privacy@launchsite-os.com and we will help.
Coaches and other account holders may contact us directly at privacy@launchsite-os.com. We verify every request against the information we already hold, and respond within the timeframe applicable law requires (generally 45 days, extendable where the law allows). An authorised agent may submit a request with proof of authority. If we decline a request you may appeal by replying to our decision; we will reconsider and respond as the law requires, and will tell you how to complain to your state Attorney General or supervisory authority.
One deliberate exception: opt-out, unsubscribe, and complaint records are not erased. Deleting the record of an opt-out would cause messaging to that person to resume, which is the opposite of what the request intends. We keep the minimum needed to keep the suppression working.
11. Cookies and tracking
Necessary cookies support authentication, session management, and remembering whether the app is running embedded. These are separate from the optional Google Ads measurement described below.
On selected public marketing and coach signup pages at launchsite-os.com, you can choose whether to allow Google Ads measurement. The Google tag does not load before affirmative consent, when you decline, or when your browser sends Global Privacy Control or Do Not Track. Declining does not prevent using the site or creating an account. The tag does not run inside coach or client workspaces, on coach-owned sites, or in development environments.
If you allow measurement, Google can receive advertising click and cookie identifiers, the selected public page path, and browser, device, and network information, including your IP address. We may report a confirmed new coach signup or first paid platform subscription, using a receipt identifier to prevent duplicate counting and, for a paid subscription, the amount and currency. Our measurement events exclude names, email addresses, form contents, health information, private workspace paths, URL query strings, and page referrers. Ad personalization and enhanced conversions (matching using identity information such as email addresses) are disabled.
Use Cookie preferences below or in the public marketing footer to change or withdraw your choice. The choice is remembered in your browser for up to 180 days; optional first-party advertising cookies are configured to last no more than 90 days. Withdrawing stops future measurement and clears the advertising cookies this site can remove. It does not recall data already sent or remove cookies on Google domains. Browser session markers prevent duplicate conversion counting and end with the tab session.
Google processes the information it receives as an independent controller under its applicable terms. See Google's advertising data-protection terms and how Google uses information from sites using its services, including its own retention and privacy controls. This measurement is separate from any Google calendar or document connection a Coach enables in a workspace.
Where a Coach adds their own tracking to a page they publish through the platform, that is the Coach's decision and their responsibility to disclose.
12. Children
The platform is for adults aged 18 and over. Coaches must not onboard minors, and parental consent does not create an exception to this service restriction. If you believe a minor's information is present, contact privacy@launchsite-os.com. We will review the facts and arrange appropriate restriction and deletion or other handling required by law. We do not sell personal information.
13. International users and transfers
The platform is operated from the United States (Kentucky), and information is processed there. If you access it from outside the United States, your information will be transferred to and processed in the United States, which may not provide the same level of protection as your home country.
If the EU or UK GDPR applies to you: we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) for transfers, together with the technical and organisational measures described in Section 6. Coaches established in the EEA or UK who need a Data Processing Addendum with those clauses can request one at privacy@launchsite-os.com. We have not appointed an Article 27 representative; if you need one in place before using the platform, contact us first.
14. Breach notification
If we discover a breach of security affecting health-related or other personal information, we will notify affected individuals, affected Coaches, and any authorities as required by applicable law - including the U.S. FTC Health Breach Notification Rule, applicable state breach-notification laws (including Kentucky's), and the GDPR's 72-hour rule where it applies - within the timeframes those laws require.
15. Changes to this policy
We may update this policy. Material changes will be posted here with a revised "Last updated" date, and where required by law we will provide additional notice before they take effect. The subprocessor register is updated as vendors change; that page carries its own date.
16. Contact
Privacy requests and questions about this policy: privacy@launchsite-os.com. General support: support@launchsite-os.com. LaunchSite OS, LLC (Kentucky, USA). Our mailing address is available on request.
This document describes our practices and safeguards. LaunchSite supports adult wellness coaching and does not offer a BAA. Coaches must follow the service restrictions and the laws applicable to their activities. These restrictions do not remove LaunchSite's own privacy or security responsibilities.