AXIS Launch List your app

Privacy Policy

Effective 13 September 2026. This policy covers jonathanarvay.com, where AXIS Launch runs, the AXIS Launch daily newsletter, and every form on the site. AXIS Launch is a Trust Fabric product, built and run by Jonathan Arvay. Questions and requests about your data go through the privacy request form.

1. The short version

2. What we collect, why, and where it lives

2.1 The AXIS Launch daily

When you subscribe we store your email address; whether you have confirmed, unsubscribed or neither, and the dates of each; and a short label for where you signed up, such as linkedin, feed or prompt. Every subscriber gets a share code, and if you signed up through someone's share link we record their code against yours. When you click the confirmation link we record a consent entry: your address, the time, and a keyed hash of your IP address that cannot be turned back into the address. For each issue we record whether it was sent to you and the email provider's message reference.

Why: to send the newsletter you asked for, to prove you asked for it, to stop at once when you unsubscribe, and to know which channels bring readers. Where: our database on Cloudflare; emails are delivered by Resend.

If you tick the box to get the daily on another Trust Fabric product's signup form, that product sends us your address and its own name as the label, and the same confirmation email goes out before anything else.

2.2 Downloads

When you ask for a download on a page under /get/, we store your address, which download you asked for, where you came from, whether you ticked the box for the daily, and when you confirmed. The link arrives by email. Clicking it confirms the address and records a consent entry, as above. Asking for a download does not subscribe you to the daily unless you tick that separate box.

Why: to deliver what you asked for and to prove you asked. Where: our database on Cloudflare; emails by Resend.

2.3 Analytics

Each page sends a short note to our own server when it loads, and when you use a share link, follow a link to another site, or see, close or use the signup box. The note holds the page's path without its query string; the site that sent you, as a host name only; campaign tags in the link, such as utm_source; a label for what happened, such as a share network, the name of the site you followed a link to, or which version of the signup box you saw; your country as reported by Cloudflare; and whether you are on a phone, a tablet or a computer.

To count visitors per day without identifying anyone, we store a value calculated from your IP address and browser details with a key that changes every day and is never saved. The same visitor gets an unrelated value the next day. We never store the IP address or the browser details themselves.

No note is sent if your browser sends Global Privacy Control or Do Not Track, if it identifies itself as an automated client, or if you turn analytics off under Privacy choices at the foot of every page.

Why: to understand, in aggregate, which pages and channels are useful. Where: our database on Cloudflare.

2.4 App submissions

The listing form collects the app's name, tagline, description, category, address and the maker's story. That text can mention a person if it is written that way. A listing sent in as a GitHub issue records the issue number, which links to the public GitHub account that opened it.

Why: to review submissions and publish approved listings. Where: our database on Cloudflare; approved listings become public pages.

2.5 Verification badges

To award a verification badge we look at evidence, such as a code repository, a revenue dashboard shared with us, or an identity document shown to us. We do not keep copies of identity documents or financial statements, and we never show them to anyone else. We record the badge, the date, how it was checked, and at most a reference to where the evidence lives. The badge and its date appear on the listing.

2.6 Requests you send us

The privacy request form and the takedown request form store your address, what you are asking for, and your message or evidence link. The PAID form stores your address, the listing and your note.

Why: to answer you. Where: our database on Cloudflare, visible only in the admin console.

2.7 Security and abuse prevention

Every public form limits how often one connection can send it. To do that we store a keyed hash of the IP address for an hour-long window. Cloudflare, which hosts the site, processes your IP address and request details to deliver pages and protect the site, under its own privacy policy; we do not receive or keep those logs.

2.8 Your browser, and Privacy choices

2.9 What is not open yet

Member accounts, auctions, bids, and the non-disclosure agreements that come with diligence are not open, and we collect nothing for them. This policy will describe that data before any of them opens.

3. What we publish

Listings describe apps. Features describe apps and the people building them, from public sources cited on each page, such as a company's own site, press coverage and public code repositories. Listing pages show a screenshot of each app's public homepage, or the preview image its site publishes for link sharing, credited with the address and the date. Illustrations on the site are generated with Google's Gemini image model from written descriptions, are captioned as generated, and never depict a real person or product.

If something we published names you and is wrong, or you want a personal detail removed, use the request form.

4. Who processes data for us

Service What it does What it receives
Cloudflare Hosts the site and runs our code, database, file storage and backups Everything we store, and your IP address while delivering pages
Resend Delivers our emails Your email address and the email's contents
GitHub Hosts our code and receives listing submissions sent as issues Whatever you put in a GitHub issue
Google (Gemini API) Generates illustrations Written descriptions of pictures only, never personal data
IndexNow (Bing and other search engines) Hears when our pages change Page addresses only
LinkedIn, Bluesky, X, Threads Carry our public posts, when we turn posting on The public post only, never subscriber data

We share personal data with anyone else only when the law requires it, or with a buyer of the site, who would be bound by this policy.

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as the California Consumer Privacy Act defines those terms.

5. Legal bases

Where the law asks for a legal basis: consent for the newsletter and downloads, which you can withdraw at any time; legitimate interests for aggregate analytics without identifiers, abuse prevention, backups, reviewing submissions and awarding badges, answering requests, and keeping unsubscribed addresses so we never email them again; and legal obligation where a record must be kept.

6. How long we keep it

Data Kept for
A subscription you have not confirmed 30 days
Your subscription While you are subscribed. After you unsubscribe, the address stays marked unsubscribed so it is never emailed again, until you ask us to delete it
Per-issue delivery records 400 days
A download request you have not confirmed 30 days
A confirmed download request 2 years, unless you are also a subscriber
Consent entries While a subscription or download record holds your address, including an unsubscribed one; after that, until 3 years from the consent
Raw analytics entries 30 days; the daily totals built from them hold no visitor values
Rate-limit records 2 days
Rejected app submissions 12 months after review
Published listings and their verification records As long as the directory runs; personal details are removed on request
Takedown and privacy requests The requester's address is removed 12 months after the request is closed
PAID form entries 2 years
Our record of data requests we handled (a keyed hash and counts) 3 years
Backups 90 days, so a deletion reaches every backup within 90 days

7. Your rights

You can ask to see the personal data we hold about you, to correct it, to delete it, to receive a copy, to object to a use of it, or to withdraw a consent. Use the privacy request form. We reply to the address you give, to confirm the request came from its owner, before we export or delete anything, and we answer within 30 days. If we decline any part, we say why, and you can reply to ask us to look again.

You can unsubscribe from the daily at any time with the link in every issue; it takes effect at once. We honor Global Privacy Control as an opt-out. We will not treat you differently for using any of these rights. If you are in the EU or the UK, you can also complain to your data protection authority.

8. Security

Confirmation, download and unsubscribe links are signed so they cannot be forged. IP addresses are stored only as hashes, keyed with a secret since 12 September 2026. The admin console needs a signed session, and we collect as little as each purpose needs. No system is perfectly secure; if a breach affects your data, we will tell you as the law requires.

9. Children

The site is for adults. Our Terms require users to be at least 18, the site is not directed to children, and we do not knowingly collect their data. If you believe a child has given us personal data, use the request form and we will delete it.

10. International users

The site is run from the United States, and data is processed there and wherever Cloudflare operates.

11. Changes

When this policy changes, the effective date at the top changes with it. A material change is announced on the site and in the daily before it takes effect.