Afterlaunch
Add your launch

Security at Afterlaunch

Connect only accounts you own or are authorized to manage. Publishing a receipt is free, and your first sync creates a private draft for you to review.

Choose the minimum permissions

For Stripe, create a restricted key with the read permissions required for payment data and disable write permissions. Production accepts rk_live_ keys; full secret keys are rejected. Test keys are supported only outside production. A restricted key can still have write permissions, so the prefix alone is not a safety guarantee.

How credentials are stored

Stripe keys and analytics tokens are encrypted with AES-256-GCM before storage. Server-side sync code decrypts them to call the connected providers. Stored credentials are not returned in public receipts or dashboard responses. Encryption does not remove the need to limit permissions and protect your provider accounts.

What is collected and published

Syncs calculate aggregate launch metrics, daily totals, and referrer summaries. Provider responses may contain transaction or event data while being processed; receipt records do not store customer card details or customer contact lists. Review your public metric choices, tagline, and notes before publishing. Anonymous mode hides product identity fields but does not redact identifying text you enter.

Stop access or report a problem

Revoke the key or token in Stripe or your analytics provider to stop access immediately. Use Account & company settings to remove stored credentials and stop future syncs. An in-flight provider request may finish. To report a security issue, email akshatrside@gmail.com. Do not include keys, tokens, or customer data in your message.

See the privacy policy for data handling and deletion requests.