Home

Privacy Policy

Last updated: August 28, 2026

What we collect

  • Account info: name, email, and authentication data when you sign up.
  • Billing info:handled entirely by Creem, our merchant of record — we receive confirmation of your subscription status but never your card details.
  • API keys: if you use BYOK tools, your third-party API keys are encrypted (AES-256-GCM) and stored to let you run tools without re-entering them each time.
  • Usage data: which tools you run and when, so you can see your run history.
  • Run artifacts: outputs generated by tools you run, retained for 30 days.
  • Credit records: if you buy credits, we keep your balance and a line for every credit that moves \u2014 when, which app, which provider and model, and what it cost. Deliberately not the content: the ledger records that a call happened and what it was billed at, never what you sent or what came back.

How we use it

  • To provide and operate the platform (running tools, managing your membership).
  • To communicate with you about your account, billing, or changes to our service.

Who we share it with (sub-processors)

  • Creem— payment processing and billing (Creem is merchant of record)
  • Supabase— database and authentication
  • Vercel— application hosting
  • Cloudflare R2— file/artifact storage
  • Resend— transactional email delivery
  • AI providers you connect— only when you run a tool using your own key; we don’t share your key or data with providers you haven’t connected
  • OpenAI and ElevenLabs — only when you run on credits. See below.

We do not sell your data.

AI providers, and what changes on credits

When you run on your own key, the request goes to a provider you chose, on your account, under your agreement with them. We store your key encrypted and never see the plaintext; what that provider does with your data is between you and them.

When you run on credits, the request is made on our provider accounts instead. Those providers become our sub-processors for that call, and whatever you send \u2014 your prompt, and any file or URL the tool passes on \u2014 is processed by them under their own terms and their own retention policies, which we do not control. Today those providers are OpenAI (text) and ElevenLabs (speech). If that list changes, this page changes with it.

Which mode you are in is never a surprise: it is shown before you run anything, and on your credits page.

Data retention

  • Run artifacts: 30 days, then automatically deleted.
  • Account data: retained while your account is active, and for 30 days after cancellation/deletion, then removed.
  • API keys: deleted immediately if you remove them from your account or delete your account.
  • Credit records: kept for as long as the account exists, and deleted with it. They are append-only while it does \u2014 an entry is never edited or removed, because it is the only thing that can answer “where did my credit go”.

Your rights

You can request a copy of your data, ask us to correct it, or ask us to delete your account and associated data by contacting support@buildnlaunchai.com.

International users

If you’re outside Bangladesh, your data may be processed by our sub-processors in other countries (e.g., US-based Supabase/Vercel infrastructure). By using Build & Launch AI, you consent to this transfer.

Changes to this policy

We’ll update this page and notify you of material changes via email or a site notice.

Contact

Privacy questions? support@buildnlaunchai.com