Privacy Policy
Last updated: 26 July 2026
Who we are
LaunchCanvas is an implementation tracking product for SaaS teams. This policy is published by LaunchCanvas, and covers two things: the data this marketing site collects when you join the waitlist, and the data the LaunchCanvas application handles when you use it — including data from a Google account you choose to connect.
If you have a question about anything here, or you want your data removed, write to privacy@launchcanvas.io and a person will answer.
Joining the waitlist
The waitlist form on this site asks for one thing: your email address. It is stored in our database, and we use it for one thing: to contact you about the launch of LaunchCanvas. We do not send unrelated marketing, and we do not sell, rent, or share the list with anyone else.
To be taken off the waitlist, write to privacy@launchcanvas.io and we will delete your address from the database. You do not need to give a reason.
Using the LaunchCanvas application
When you create an account in the application, we store the details needed to run it: your email address, your name if you give one, your authentication credentials, and the workspaces, projects, stages, items, comments, meetings and activity records you create in the product.
We use this to operate the service for you — to sign you in, to show you your workspaces, and to keep your work available between sessions. We do not sell it, and we do not use it for advertising.
Connecting a Google account
LaunchCanvas can keep a workspace's data in a Google Sheets spreadsheet you own, rather than in our database. This is optional. It only happens if you choose to connect a Google account and set a workspace to Sheets storage.
When you connect a Google account, we ask Google for one scope: https://www.googleapis.com/auth/spreadsheets
That scope lets the application read and write spreadsheets in your Google account. You choose the spreadsheet: you give us its link when you set the workspace up, and we set up the tabs and header rows the workspace needs inside the spreadsheet you gave us. From then on we read and write the rows in it as you work — projects, stages, items, comments, members, activity and meeting records.
The feature cannot work without it. When a workspace is set to Sheets storage, the spreadsheet is not a copy or an export — it is the workspace's storage. Reading it is how the application shows you your board, and writing to it is how your changes are saved. Without spreadsheet access there is nothing for the workspace to read from or write to.
Where your spreadsheet data lives
In the spreadsheet, in your own Google account. When a workspace uses Sheets storage, the project, stage, item, comment, member, activity and meeting records are read from and written to your spreadsheet directly from your browser. The contents of your spreadsheet are not copied into our database and are not stored on our servers.
If you disconnect Google Sheets, or stop using LaunchCanvas entirely, the spreadsheet and everything in it stays with you.
What we store because of the connection
One thing: a key that lets the application reconnect to your spreadsheet. When you approve the connection, Google gives us this key — a refresh token — and we store it on our server, so that the connection lasts and you are not asked to approve it again every time you come back.
The key works only for the scope above, and only on your behalf, so the only thing it reaches is the spreadsheet your workspace uses. It is not shared with anyone.
What we never do with Google user data
LaunchCanvas's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- we do not sell Google user data, to anyone, ever;
- we do not use Google user data for advertising of any kind;
- we do not use Google user data to train, fine-tune, or improve machine learning or AI models, ours or anyone else's;
- we do not let humans read your Google user data, except where you have explicitly asked us to (for example, if you ask us to look into a problem), where it is necessary for security purposes or to comply with the law, or where the data has been aggregated and anonymised.
Who else processes your data
These are the main third parties involved, and what each one handles:
- Google — holds your Google account and the spreadsheets that back Sheets-storage workspaces, and issues the key that lets the application reach them.
- Supabase — our database and authentication provider. Stores waitlist email addresses, account records, workspace records, and the stored Google key.
- Vercel — our hosting provider. Serves this site and the application, and processes the requests that pass through them.
We do not use analytics, advertising, or tracking services on this site, and it sets no tracking cookies.
How long we keep things
- Waitlist email addresses — until launch, or until you ask to be removed, whichever comes first.
- Account and workspace records — until you delete your account, after which they are deleted.
- The stored Google key — cleared the moment you disconnect Google Sheets in the application. If you revoke access from your Google account instead, it is cleared automatically the next time the application tries to use it. Either way it is not retained, and deleting your account deletes it along with everything else.
- Your spreadsheets — we never had them, so there is nothing for us to keep. They stay in your Google account for as long as you keep them there.
Revoking our access to your Google account
There are two routes. Either one ends our access immediately, and neither of them needs you to contact us.
- Disconnect inside LaunchCanvas. Disconnect Google Sheets from your workspace settings in the application. The stored key is cleared there and then. The application can no longer reach your spreadsheets, and any workspace using Sheets storage stops loading until you reconnect.
- Revoke from your Google account. Go to your Google account permissions and remove LaunchCanvas's access. Google invalidates the key straight away, so our access ends at that moment, whatever we do. The next time the application tries to use it the attempt is rejected, and the stored key is cleared automatically at that point.
Either way, the spreadsheet itself is untouched — it is yours, and revoking access only stops us reaching it.
Deleting your data
Write to privacy@launchcanvas.io from the address on your account, and say what you want deleted. We will act on it and confirm when it is done.
On a full deletion request we delete:
- your account and authentication record;
- your workspaces and everything stored in our database for them — projects, stages, items, comments, members, activity and meeting records;
- the stored Google key;
- your email address from the waitlist, if it is still on it.
What we cannot delete is anything in your own Google account, because we do not control it — your spreadsheets remain yours to keep or delete.
Changes to this policy
If what we do with your data changes, we will update this page and change the date at the top. The current version always lives at this address. If a change is significant and we have your email address, we will tell you.
Contact
Questions about this policy, help revoking access, or a deletion request: privacy@launchcanvas.io.