Two kinds of people, two different roles
This platform serves businesses, and those businesses serve consumers. LaunchDispute decides how business-account data is handled. For consumer data, the business that enrolled the consumer decides what is collected and why; we process it on that business’s instructions.
If you are a consumer and want your information corrected or deleted, contact the business you signed up with. If you cannot reach them, contact us and we will help.
Information we collect
From business users:
- Name, email address, and password (stored only as a salted hash, never in a recoverable form).
- Company name, branding, and custom domain settings.
- Billing contact and subscription status. Card numbers are entered directly with our payment processor and never reach our systems.
- Usage records: clients enrolled, dispute rounds run, letters generated and mailed.
- Security records: sign-in attempts, IP address, and an append-only audit trail of actions taken in the account.
Consumer information
When a business enrolls a consumer, the platform may hold the consumer’s name, address, date of birth, Social Security number, credit-report contents, dispute history, and correspondence sent on their behalf.
Social Security numbers, dates of birth, and credit-report contents are encrypted individually before they are stored, using a key unique to that business. They are never written to logs. Every read of this information is recorded in the audit trail with the identity of the person who read it.
How we use it
We use the information to:
- Analyze credit reports and draft dispute letters.
- Print, mail, and track correspondence to credit bureaus and furnishers.
- Detect changes between report versions in order to show progress and to justify a charge.
- Operate accounts: authentication, invitations, notifications, and support.
- Bill for the service and detect fraud or abuse.
- Meet record-keeping obligations under the Credit Repair Organizations Act and the Fair Credit Reporting Act.
We do not sell personal information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use consumer credit data to train AI models, and our AI providers are engaged under terms that prohibit them from doing so.
What is sent to AI providers
Analysis and letter drafting are performed by a third-party AI provider. Before anything is sent, direct identifiers are removed: the provider receives the substance of the tradelines being disputed, not the consumer’s Social Security number, date of birth, or full account numbers.
Legal citations in generated letters are drawn from a fixed, vetted list rather than produced by the model, so a model cannot invent a statutory reference.
Who else processes this data
We use the following service providers. This list is maintained alongside the code that integrates them, so it reflects what is actually in use:
| Provider | What they do |
|---|---|
| Cloudflare | Hosting, edge network, application database (D1), document storage (R2), session storage (KV), and background job queues. All application data rests here. |
| Z.ai (GLM) | Default AI provider for credit-report analysis and dispute-letter drafting. Input is stripped of direct identifiers before it is sent. |
| Anthropic | Fallback AI provider used for escalation and when a draft fails the citation gate. Same identifier stripping applies. |
| Lob | Physical mail delivery of dispute letters to credit bureaus and furnishers, including certified mail and delivery tracking. |
| Resend | Transactional email — invitations, progress notifications, and password resets. |
| Stripe | Subscription billing and payment processing for business customers. Card details are entered directly with Stripe and are never transmitted to or stored by us. |
| PayPal | Alternative subscription billing and payment processing for business customers. |
Security
All traffic is encrypted in transit. Sensitive consumer fields are encrypted at rest under a two-tier key scheme: a master key held outside the database wraps a separate key for each business, which in turn encrypts individual fields. A copy of the database alone is not enough to read them.
Passwords are stored as salted PBKDF2 hashes. Sign-in is rate limited by both account and network address. Each business’s data is isolated, and every action that changes data is written to an append-only audit log that cannot be edited or deleted.
No system is perfectly secure. If a breach affects your information, we will notify you and the appropriate authorities as required by law.
How long we keep it
Consumer records are retained for five years after the account is closed, which covers the record-keeping window applicable to credit-repair activity. This period is configurable per deployment but is never set below two years.
When the retention period ends, personal information is destroyed by discarding the encryption key for that business. This is irreversible: the stored data cannot be decrypted afterward by us or by anyone else.
Audit records and billing records are retained for the same period. Because the audit log is append-only, entries within it are never edited or removed.
Your rights
Depending on where you live, you may have the right to know what personal information is held about you, to obtain a copy, to correct it, to delete it, and to not be discriminated against for exercising these rights.
To make a request, email privacy@launchdispute.com. We will verify your identity before acting, and we will respond within the time your jurisdiction requires. Consumers enrolled by a business should contact that business first, since it controls the record.
Some information cannot be deleted on request where we are required to retain it, for example records of disputes already sent and billing records.
Needs counsel: This section states commercial intent only and has not been reviewed by counsel. It is not final contract language.
Cookies
We use a single cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.
Children
This service is not directed to anyone under 18, and we do not knowingly collect information from children.
Changes to this policy
We will post any change here with a new effective date and notify account owners by email before a material change takes effect. This revision is dated July 20, 2026.
Contact
Privacy questions and rights requests: privacy@launchdispute.com.