Privacy Policy

Effective date: July 13, 2026 Last updated: July 13, 2026

Ignition is run by ReLo LLC, a Wyoming limited liability company, from the United States. When this policy says "we", it means ReLo LLC. When it says "you", it means whoever is reading it, which might be someone with an Ignition account, someone trying the demo without one, or an investor who opened a founder's dataroom and never signed up for anything.

This is written to be read. Where the law makes us say something in a particular way we have said it, but everywhere else we have tried to tell you plainly what happens to your information. If something here is unclear, ask us and we will fix the wording.


The short version

You describe a startup idea. We send it to an AI model to generate business materials, and we store both your idea and what came back, because that is the product. We take payment through Stripe. If you opt in, we send you a small amount of email triggered by what you do in the product. We do not sell your data and we do not run advertising trackers. We use Google Analytics, but only if you turn on product analytics, and it never loads before you choose.

Two things are worth knowing that you might not expect, and we would rather you heard them here than discovered them later.

If you open a founder's dataroom and give your email, that founder can see which documents you opened and when. That is the point of the feature, from the founder's side. It is described in full below.

If you ask us to erase you, we destroy your email address but keep a one way fingerprint of it, so that we can be certain never to contact you again. That fingerprint cannot be turned back into your address. It is the only thing that survives an erasure.


1. What we collect, and when

If you make an account

Your email address, your first and last name if you give them, and a password, which Supabase stores hashed and which we never see. We record when you accepted the terms, and where you came from if you arrived through a specific campaign or partner.

When you use the product

Everything you type into the intake: what you are building, who it is for, the problem, your inspiration, your project name and stage, and the further detail you add when you sharpen a brief. This is the most personal thing in the product, not because it identifies you, but because it is your idea.

We store what the AI generates from it: the one pager, the pitch deck, the business plan, the competitive analysis, the tokenomics, the litepaper, the landing page, the brand kit, the stress test teardown, and anything else you generate. We keep the full version history so you can revert.

If you record a voice pitch session, we store the debrief of it.

If you upload files, we store the files and their names.

We also log which model ran, how many tokens it used and what it cost us. That is how we know whether the business works.

When you try the demo without an account

We store the idea text you typed, and the drafts we generated from it, so that you can keep them if you decide to make an account. We do not ask for your email, and there is no email wall on the demo.

We also record a one way fingerprint of your IP address and a random browser token, purely to stop one person from running the demo a thousand times. We used to store the raw IP address here. We do not any more: the rate limiter never needed it, so it no longer has it.

When you open a dataroom

This one is about people who are not our users.

A founder can publish a dataroom and share the link. You can read it without giving us anything. You are asked, optionally, for your email and name, and if you give them, we record them, together with when you first and last visited, how many times you came back, and which documents you opened. All of that is shown to the founder whose dataroom it is. That is the feature they are paying for.

If you accept optional cookies, we set a cookie so we recognise you on a return visit and do not ask again. If you decline, we do not set it, and we ask again next time.

We do not record your IP address or your browser's user agent. We used to record both. Nothing ever read them, so we stopped.

If you apply for a grant

Your name, email, LinkedIn, X handle, country, city, and everything you write in the application. We keep applications after a decision so there is a record of the decision.

If you pay us

Stripe handles the payment. We never see or store your card number. We keep your Stripe customer ID and subscription ID so we know what you are entitled to.


2. Email, and the choice you have about it

We send two kinds of email and we treat them differently.

Email you cannot turn off is the email the product owes you: a decision on your grant application, an invite you asked for, a receipt. There is not much of it.

Email you have to opt into is founder guidance, triggered by what you do in the product. A note after your first project, a note before you pitch, a nudge if you have been away. It is not a newsletter and it is not a drip campaign to a list we bought. If you did not tick the box, you do not get it. The box is unticked by default, and an account works perfectly well without it.

Every one of those emails has a one click unsubscribe, and it works immediately. We record when your email is delivered, opened, or clicked, so we know whether the emails are worth sending, and so a bounce or a spam complaint automatically stops us sending you anything else.

We are not sure whether double opt in is legally required for you. We have not implemented it. It is required in some EU member states for marketing email and not in others, and we would rather tell you we are still working out where we land than pretend we have already decided.


3. Cookies

We use very few. The only third party analytics we use is Google Analytics, and it loads only if you turn on product analytics. No advertising pixels, no session recorders, no tag manager, and nothing loads before you choose.

Cookies that are always on, because the product does not work without them:

  • The Supabase login cookie that keeps you signed in.
  • A demo cookie that carries your generated drafts through signup, so you do not lose them.
  • A demo browser token that stops one person from running the demo endlessly.

Cookies that are off until you say yes:

  • Product analytics. This covers the dataroom cookie described above and Google Analytics. Google Analytics loads only if you turn this on, and never before you choose.
  • Marketing attribution. If you arrive from an ad, a cookie remembers which one for about a month, so we know what is worth paying for. It does not follow you to other websites.

Nothing in the second group is set until you affirmatively agree. Closing the banner without choosing means no. You can change your answer at any time from the "Cookie settings" link in the footer, and turning something off deletes the cookies it set.


4. Who else touches your data

These are the companies that process data on our behalf. We have listed what each one actually receives, not a generic description.

WhoWhat they getWhere
SupabaseThe database. Effectively everything described in section 1.United States
VercelHosting. Sees requests as they pass through.United States
AnthropicYour idea text and the prompts built from it, in order to generate the drafts.United States
ReplicateThe text prompt used to generate your brand logo image.United States
StripeYour name, email, and payment details when you pay.United States
ResendYour email address and the content of the emails we send you.United States
PexelsA search term derived from your project, when we look for a stock image. No personal data.United States

We removed OpenAI from this list because a previous version of our terms claimed we used it and we do not. We added Replicate and Pexels because we do use them and had not said so.

We do not sell your personal information, and we do not share it for cross context behavioural advertising. We have never done either.


5. Your idea, and AI training

We do not use your ideas, your prompts, or your generated outputs to train any AI model of our own. We do not have one.

Your inputs pass through Anthropic's commercial API. Under Anthropic's commercial terms, API inputs are not used to train their public models by default. We are relying on their terms here, not on a promise of our own, and we think you should know the difference.


6. Where your data lives

In the United States. Our database, our host, and every company in the table above are US based.

If you are in the EEA or the UK, that means your data is transferred out of your region. Where the law requires a safeguard for that transfer, we rely on the Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum.

We should be straight with you: putting those agreements in place with each provider is work that is in progress, not work that is finished. We are telling you the mechanism we rely on and that we are still completing it, rather than implying a compliance posture we have not reached.


7. Why we are allowed to process any of this

For people in the EEA and the UK, the law wants us to name a legal basis for each thing we do.

  • To run the product for you, including generating and storing your assets, and taking payment: because we have a contract with you and this is us performing it.
  • To send you founder guidance email: because you consented, and only then.
  • To set non essential cookies: because you consented, and only then.
  • To rate limit the demo, prevent abuse, and keep the service secure: because we have a legitimate interest in the product not being destroyed by whoever finds it first.
  • To show a founder who read their dataroom: because we have a legitimate interest in providing the feature the founder is paying for, balanced against the reader being told clearly, before they give their email, what will be visible.
  • To keep an erasure fingerprint after you ask to be erased: because we have a legitimate interest, and arguably a legal obligation, in never contacting someone who told us to stop.
  • To keep billing and tax records: because the law requires it.

8. How long we keep things

While your account is open, we keep your account and your content, because that is the product.

When you ask us to delete your account, we delete it. Not "mark it deleted": we remove your account, your projects, your briefs, your generated assets, your uploaded files, your voice sessions, your email history, your engagement records, and the behavioural events we recorded about you. That happens across every table that holds them.

Two things do not go.

A one way fingerprint of your email address. We keep it, and nothing else about you, so that if you ever end up back on a list from some other direction, we can recognise that you asked to be forgotten and refuse to email you. It cannot be reversed into your address. It exists purely to protect you from us.

Billing records, where tax law requires us to keep them, and the fact that a grant decision was made, with your identifying details stripped out of it.

Something we have not solved yet, and will not pretend otherwise: anonymous demo sessions currently have no automatic expiry. They contain the idea text someone typed, with no name or email attached, and nothing in the system deletes them on a schedule. We are adding that. Until we do, they persist, and we would rather write that sentence than leave you to assume otherwise.


9. What you can ask us to do

You can ask us to show you what we hold about you, correct it, delete it, give you a portable copy of it, object to what we are doing with it, or withdraw a consent you gave. If you are in the EEA or the UK these are rights under the GDPR. If you are in California you have comparable rights under the CCPA and CPRA, including the right not to be discriminated against for exercising them.

Email privacy@ignitionlaunch.io. A person reads it, not a ticketing system.

We will ask you to prove you are who you say you are, because handing someone else's data to the wrong person is its own kind of breach. We aim to respond within thirty days, and the law gives us one month for GDPR requests and forty five days for CCPA requests, extendable where permitted.

We are one person and a small product, not a company with a privacy department. What that means in practice is that we handle these by hand rather than through a self service dashboard. It does not mean we handle them slowly.

If you are unhappy with how we have handled it, you can complain to your local data protection authority. If you are in the EEA or the UK, you do not need our permission to do that and you do not have to come to us first.


10. The things we do not do

We do not make automated decisions about you that produce legal effects. The readiness score and the stress test verdict are opinions about your pitch, generated by a model, and nothing turns on them except your own judgement.

We do not knowingly collect anything from children. The product is not for anyone under sixteen.

We do not currently touch blockchain data, wallet addresses, GitHub accounts, or Discord and Telegram identifiers, despite an earlier version of this policy anticipating that we might. If that changes, we will update this before it changes, not afterwards.


11. If you publish a dataroom

If you are a founder publishing a dataroom, two things are on you rather than on us.

Anyone with the link can open it. It is not access controlled beyond being unguessable. Do not put anything in it you would not want forwarded.

And if you put someone else's personal information into it, a cap table, a list of advisors, a customer roster, then in the language of the law you are the controller of that information and we are processing it for you. We are not in a position to answer for it. Please do not do it.


12. Security

We use RLS on the database, we encrypt in transit, we do not store card numbers, and we do not store passwords in a form we can read.

We are not going to tell you your data is perfectly safe, because nobody can say that honestly. If we ever have a breach that affects you, we will tell you.


13. Changes

If we change this policy in a way that matters, we will tell you rather than quietly changing the date at the top. Small corrections we will just make.


14. Contact

ReLo LLC, doing business as Ignition 1309 Coffeen Avenue STE 1200 Sheridan, Wyoming 82801

Privacy requests: privacy@ignitionlaunch.io Everything else: info@ignitionlaunch.io https://ignitionlaunch.io

© 2026 ReLo LLC. All rights reserved.PrivacyTermsGlossary