Privacy Policy
Effective 8 September 2026 · LX Launch, Lda.
This policy explains what personal data LX Launch, Lda. collects when you use elessar, why, who sees it, how long we keep it, and the rights you have over it. It is written to be read, not skimmed, and it describes what the software actually does.
1. Who we are
elessar is operated by LX Launch, Lda. ("LX Launch", "we", "us"), a company incorporated in Portugal. Our registered office is RUA NOVA TIL, 17A, 9050-052, FUNCHAL. Company registration number 518742024. For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, we are the controller of the personal data described in sections 3 to 5 below.
Questions, requests and complaints about personal data go to privacy@lxlaunch.com. We answer within one month, as the law requires, and tell you if we need longer for a complex request.
This policy covers the website at https://elessar.lxlaunch.com and the elessar service (together, the "Service"). It does not cover websites you connect to the Service (for example, your own WordPress site) or the third-party pages you ask us to read; those have their own policies.
2. Two roles: controller and processor
The Service has two kinds of personal data in it, and the law treats them differently.
- Data about you and your account (your email address, your sign-in method, your billing status, the technical data of your visits). For this we are the controller: we decide why and how it is processed, and this policy explains it.
- Data inside the material you give us to work with: the web pages you save as sources, the text of your own website, the posts you paste in, the brand profile you write, and the articles the Service drafts from them. That material can contain personal data about other people (an author's name in an article, a quote, a customer named in a case study). For that data you are the controller and we act as your processor, on your instructions, under the data processing terms in section 12 of the Terms and Conditions. We do not use it for any purpose of our own.
3. What we collect about you
| Data | Where it comes from | Why we have it |
|---|---|---|
| Email address, and a password (stored only as a hash by our identity provider) | You, at sign-up | To create your account, sign you in, and send you sign-in links and confirmation emails |
| Google account name, email address and profile picture | Google, if you choose "Continue with Google" | To create and sign in to your account without a password |
| The date and version of your acceptance of the Terms | Recorded when you tick the box | Evidence of the contract between us |
| Organisation name and your role in it; the names and emails of teammates you invite | You | So an organisation can have more than one member |
| Plan, credit balance, the Stripe customer and subscription identifiers | Created when you upgrade | Billing. Your card details go to Stripe directly and never reach our systems |
| IP address, browser and device type, the pages and API calls you make, and when | Your browser, automatically | Security, abuse prevention, and diagnosing faults (server logs) |
| Your correspondence with us | You, when you email us | To answer you |
4. What we process on your behalf
These are the working materials of the Service. We process them only to provide the Service to you, as described here and in the Terms.
- Sources: the links you save. We fetch each page, keep a copy of the raw response for a limited time (section 8), and extract the readable text, which we split into passages and index so the Service can cite it.
- Your website: when you give us your website address during onboarding, you authorise us to read that one domain, including pages its robots rules would otherwise exclude, to build your brand profile and save its pages as sources. We never crawl any other domain on that basis, and we never read LinkedIn or X on your behalf.
- Competitors and trends: if you name competitor websites we read their publicly available pages, respecting their robots rules. For trend monitoring we read public RSS and Atom feeds you or we select.
- Posts you paste: up to five of your own social posts, used only to learn your writing voice.
- Brand profile: the tone, audience and preferences you enter or approve.
- Drafts, articles, social posts and images the Service generates for you, and the plan of what to write next.
- Publishing credentials: if you connect a WordPress site, the application password you provide is encrypted (AES-256-GCM) before it is stored, and is decrypted only to publish a draft when you ask.
5. How we use artificial intelligence
The Service writes with large language models run by third parties. To draft an article we send the relevant passages from your chosen sources, your brand profile and the draft itself to those providers; to index sources we send passages to an embeddings provider; to make a feature image we send a short description to an image provider. The current providers are listed in section 6.
We use these providers under their business terms, which state that data sent through their APIs is not used to train their models. We do not train models of our own on your data.
The Service does not make decisions about you that have legal or similarly significant effects (GDPR Article 22). Drafts are never published automatically: every article, post and export happens because a person in your organisation chose it.
6. Who we share data with
We do not sell personal data, and we do not share it with advertisers. We use the following service providers (sub-processors) to run the Service. Each is bound by contract to process data only on our instructions.
| Provider | What for | Where |
|---|---|---|
| Microsoft Azure | Hosting the application and its server logs | United Kingdom (UK South) |
| Supabase | Database, authentication, transactional sign-in emails, and file storage for fetched pages and generated images | European Union (AWS, Ireland) |
| Anthropic | Language models that draft and check the writing | United States |
| OpenAI | Embeddings that index your sources for citation | United States |
| Image generation (Imagen), and sign-in if you choose Google | United States | |
| Stripe | Payments, invoices and subscription management | United States / Ireland |
| Cloudflare | Domain name resolution for the website | Global |
| GitHub | Source code and deployment; holds no customer data | United States |
We also share data when you instruct us to (publishing a draft to your WordPress site sends it there), and where the law requires it: to comply with a legal obligation, a court order or a lawful request from a public authority, or to protect the rights, property or safety of LX Launch, our customers or others.
If we sell or transfer the business, personal data may pass to the new owner under the same commitments, and we will tell you first.
7. Legal bases and international transfers
We rely on the following lawful bases under GDPR Article 6(1):
- Performance of a contract (Article 6(1)(b)): everything needed to provide the Service you signed up for: accounts, sources, drafting, publishing, billing.
- Legitimate interests (Article 6(1)(f)): keeping the Service secure and available, preventing abuse, diagnosing faults from logs, and understanding aggregate usage so we can improve it. We have balanced these interests against your rights; you can object (section 9).
- Legal obligation (Article 6(1)(c)): keeping accounting and tax records, and answering lawful requests.
- Consent (Article 6(1)(a)): where we ask for it, for example if we ever send marketing email, which you can withdraw at any time. Reading your own website beyond its robots rules is done on the authorisation you give during onboarding.
Our servers are in the United Kingdom and the European Union. Some providers in section 6 process data in the United States. Those transfers rely on the EU–US Data Privacy Framework and the UK Extension to it where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary safeguards such as encryption in transit and at rest. You can ask us for a copy of the relevant safeguards.
8. How long we keep data
- Your account and everything in it: for as long as your account is open. When you close it (section 9) we delete your organisation's data within 30 days, except as noted below.
- Raw copies of fetched pages: 90 days from fetching, after which they are deleted automatically. The extracted passages and citations remain as long as the source is in your library.
- Server logs: 30 days.
- Billing records: 10 years from the end of the financial year in which they were made, as Portuguese accounting and tax law requires.
- Records of your acceptance of the Terms, and correspondence about legal claims: for the limitation period of the claim they evidence.
- Backups: our database provider keeps backups for a short rolling period; deleted data disappears from them as they rotate.
9. Your rights
Under the GDPR and the UK GDPR you can ask us to:
- Access the personal data we hold about you and receive a copy of it.
- Correct data that is inaccurate or incomplete.
- Delete your data ("right to erasure"). Closing your account does this for everything except the records we must keep by law.
- Restrict processing while a dispute about accuracy or lawfulness is resolved.
- Receive the data you gave us in a portable, machine-readable form, and have it sent to another provider where technically feasible. The Service can export your articles as HTML, Markdown and JSON at any time.
- Object to processing based on legitimate interests, and to any direct marketing.
- Withdraw consent where processing is based on consent, without affecting what was done before you withdrew it.
To exercise a right, email privacy@lxlaunch.com from the address on your account, or tell us how else to verify that it is you. We do not charge for this unless a request is manifestly unfounded or excessive.
You also have the right to complain to a supervisory authority. Ours is the Comissão Nacional de Proteção de Dados (CNPD) in Portugal, www.cnpd.pt. If you are in the United Kingdom you may complain to the Information Commissioner's Office, ico.org.uk; elsewhere in the EU, to the authority where you live or work. We would ask you to contact us first so we can try to put things right.
10. Cookies
The Service sets only cookies that are strictly necessary to operate it. There are no advertising, tracking or analytics cookies, and no consent banner is needed for the cookies below.
| Cookie | Purpose | Lifetime |
|---|---|---|
| sb-…-auth-token (one or more parts) | Your signed-in session, held server-side and unreadable by scripts on the page | Until you sign out, or the session expires |
| elessar_org | Which of your organisations is active | Session |
| elessar_terms | Carries your acceptance of the Terms across the Google sign-up round trip | 15 minutes |
| sb-…-code-verifier | Part of the secure sign-in handshake with Google or a sign-in link | Minutes, until sign-in completes |
11. Security
All traffic to the Service is encrypted in transit (TLS). Data is encrypted at rest by our hosting and database providers. Each organisation's data is isolated from every other by row-level security enforced inside the database, not only by application code. Stored publishing credentials are encrypted with a key that is never written to code or logs. Access to production systems is limited to the people who operate the Service and is authenticated without shared passwords.
No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify the supervisory authority within 72 hours where the law requires it, and notify you without undue delay where the breach is likely to put your rights at high risk.
12. Children
The Service is for businesses and the people who work for them. It is not directed at children, and you must be at least 18 to hold an account. If you believe a child has given us personal data, email us and we will delete it.
13. Changes to this policy
When we change this policy we update the effective date at the top. For changes that materially affect how we use your personal data we will tell you by email or a notice in the Service at least 30 days before they take effect. Earlier versions are available on request.
14. Contact
LX Launch, Lda., Portugal. Email: privacy@lxlaunch.com.