Legal
Privacy Policy
A plain-language summary of the data GRC Launchpad collects, the third parties that receive it, and the choices you have. We try to keep this readable end-to-end; the legal commitments are in the sections that follow.
1. What this policy covers
This policy describes how GRC Launchpad (“we”, “us”) collects, uses, and shares information when you sign up, browse the catalog, work through labs, or upgrade to Pro. It applies to this site and to any account you create on it. Third-party sites we link to (an employer, a job board, a certification body) have their own policies and are not covered here.
2. Information we collect
We collect the minimum needed to run the service and we tell you when we collect it. Concretely:
- Account information. Your email address, the display name you choose, and a hashed password (we never store passwords in plain text). Account creation is required minimum password length is 8 characters. Reset emails link to a one-time URL that expires in 60 minutes.
- Session data. When you sign in we issue a signed session cookie. The cookie holds a token; it does not hold your password, your email, or your payment information.
- Payment information. If you upgrade to Pro or join a Team plan, checkout is handled by Stripe under a hosted Stripe Connect session managed by the platform. We never see or store your card number, expiration, or CVC. Stripe receives the limited payment information needed to process your charge and acts as a payment subprocessor on our behalf.
- Usage information. Your progress through the roadmap, which labs you have started, your answers to lab prompts, and workbench artifacts you save. On Pro, the lab answers and workbench prose you submit for AI rubric review are sent to the AI service for grading.
- Telemetry. Standard request metadata (IP address, user-agent string, referring page) is logged for security and abuse prevention. We do not set advertising or cross-site tracking cookies.
3. How we use your information
We use what we collect for a small, defined set of purposes:
- Authenticating your account and keeping it secure.
- Processing billing for Pro and Team plans and sending the receipts that follow.
- Sending transactional email only: signup confirmation, password reset, receipts, and important service announcements. We do not send marketing email from this domain.
- Tracking your progress through the roadmap and the labs.
- Detecting and preventing abuse (rate limiting, scraping, attempted unauthorized access).
- On Pro, grading the lab answers and workbench artifacts you submit through the AI-rubric review feature and the company generator.
4. Where your data is stored
Account records, billing records, and progress records are stored in a managed PostgreSQL database provisioned by the platform. Auth cookies are signed and stored client-side; the server keeps only a session identifier and the minimum data needed to validate it. The AI-grading service stores submitted text only long enough to produce the rubric output; we do not commit your submitted prose to a long-lived training pool.
5. Subprocessors
We share the minimum data needed with a small set of named subprocessors:
- Stripe. Payments for Pro and Team plans via a hosted Stripe Connect session managed by the platform. Stripe receives your billing details at checkout; we never see full card data.
- Transactional email proxy.Outbound transactional mail (signup, password reset, receipts) sent through the platform’s authenticated email proxy at
POLSIA_EMAIL_PROXY_URL. The proxy accepts outbound mail only; it does not accept attachments, cc/bcc, or a custom From address. - Managed PostgreSQL. Account, billing, and progress records, operated by the platform.
- AI grading service. On Pro, the lab answers and workbench prose you submit for AI rubric review are sent to the AI service for grading; it returns scores, strengths, and gaps, and does not retain your submissions long-term.
6. Cookies and sessions
We use one category of cookie: a signed session cookie so you stay signed in between page loads. We do not use advertising cookies, third-party analytics cookies, or cross-site-tracking cookies. Disabling session cookies in your browser will sign you out, which is the intended behavior.
7. Data retention and deletion
We keep your account while it is active. If you request account deletion we delete your account record, your progress record, your billing linkage, and any lab prose saved server-side within 30 days. Backups roll off on the platform’s normal cycle. Anonymized aggregate counts (for example, total labs completed across all users) are not tied back to your account and may persist.
8. AI features on Pro
Pro subscribers get up to 200 AI rubric reviews per month and access to the AI company generator. When you submit a lab answer or a workbench artifact for review, the text is sent to the AI service for grading; the service returns scores, a strengths list, and a gaps list, and it does not retain your submission. AI output is advisory; it is not a certification, a hiring decision, or a guarantee of job readiness.
9. Your rights
You can ask us to:
- Provide a copy of the personal data we hold for your account.
- Correct inaccurate account information.
- Delete your account and the data tied to it.
- Stop processing your data for a specific purpose where applicable.
To exercise any of these, email grc-launchpad@polsia.app. We respond within 30 days. Stripe-controlled billing records follow Stripe’s own retention rules and are exported to you via Stripe when you request them.
10. Changes to this policy
We update this page when our practices change. The “Last updated” line at the top reflects the most recent revision; for material changes we also surface a notice on the dashboard after you sign in.
11. Contact
Questions, requests, or complaints: grc-launchpad@polsia.app.