Privacy Policy
Questions about this document? Write to legal@layerport.app.
This policy describes what LayerPort collects when you use LayerPort, why, and what you can do about it. It covers the hosted service, including the private workspace where captures and generated files are stored while your account exists.
What we collect
Account data
LayerPort authenticates with Google and nothing else. When you sign in, Google gives us your account identifier, email address, display name and profile picture URL. We store those, plus the time you createdthe account and the time you were last seen. We also store the time of your first useful capture and of your first export or publish. We never receive your Google password, and we do not create one.
Sessions
A session is an opaque random identifier held in an HttpOnly cookie. We store only a keyed hash of it, so a copy of our database does not yield working sessions. Sessions expire, and signing out deletes them.
Project and verification records
For each project you link we store its private workspace and captured website files, the source hostname, detected platform, lifecycle state, run logs, exports, and timestamps of verification and authorization. When you confirm that you own a site or have its owner's permission, we record that confirmation for that site: the project, the source host and URL, the exact sentence shown to you, the time, your address, your browser string and the interface language. Verification tokens are stored as keyed hashes only. Other accounts cannot read that workspace.
Security and abuse records
We store the address a request arrived from, the browser string it carried, and the time, for sign-ins, acceptances of these documents, and administrative actions. These are the records that let us investigate a compromised account or an abuse report, and they are the reason the previous sentence is specific rather than reassuring.
Acceptance records
When you accept these documents we record which document, which version of it, the exact sentence shown to you, the time, your address, your browser string and the interface language. That record is what makes an agreement provable, for you as much as for us. You can export it from your account. Together with the per-site authorization confirmations above, it is the one record that outlives a deleted account; see below.
Measurement
We count page views ourselves: a date, which page, whether the visitor was signed in, and the host they arrived from. There is no identifier, no cookie and no profile behind that count, and the rows are aggregates rather than a log of visits. We do not use third-party analytics, advertising networks or cross-site trackers — but we do measure, and describing that as “no analytics” would be untrue.
Forms on sites you publish
If you enable the built-in form endpoint on a site you publish, submissions from that site's visitors arrive here — whatever fields your form contains, plus the submission time and an abuse-scoring signal. For that data you decide what is collected and why; we process it on your instructions in order to show it to you. Do not collect sensitive categories of data through it.
Your brand on handoffs
On plans that include it, you can save your agency or studio's name, a contact email, a website and a short note. We store them with your account and print them where you ask: in the guide inside your ZIP export, in the README of a site you publish to Vercel through LayerPort, and as the sender name and reply-to address of form notification emails. Anyone who receives those files or emails sees them. You can change or delete them in your account at any time; files already delivered keep what they had.
Payment records
No card numbers, expiry dates or security codes. Payment is handled by Paddle, which acts as our Merchant of Record: Paddle sells the subscription to you on its own checkout, processes the payment and issues the invoice, so we never see or store card data. What we keep is the Paddle customer and subscription identifiers, the plan bought, its status, interval and renewal date — the minimum needed to know what an account is entitled to. The payment data Paddle collects is governed by Paddle's own privacy notice.
What we never collect
- No passwords. Sign-in is delegated to Google entirely.
- No card numbers, expiry dates or security codes.
- No advertising identifiers, and no data sold or shared for advertising, ever.
Why we process it, and for how long
- To sign you in and keep you signed in — sessions expire and are deleted.
- To create and store projects in a private hosted workspace — kept until you delete the project or account, subject to the rolling backup period described below.
- To enforce authorization — verification records are what let us refuse a migration; kept while the account exists, since they are the evidence behind a decision.
- To apply plan limits and reconcile billing — our local entitlement mirror is deleted with the account; Paddle retains its own financial records under its legal obligations.
- To learn whether new accounts reach a working result — the two dates above feed aggregate counts in our own admin console (how many new accounts capture and export, and how soon); they are not shared with anyone and are deleted with the account. This purpose is not needed to provide the service: you can object by writing to privacy@layerport.app.
- To investigate abuse — security and abuse records are kept for up to 180 days, and longer for a specific report that is still open or that led to a decision.
- To prove what was agreed and declared — acceptance records and per-site authorization confirmations are kept while the account exists and for 3 years after it is deleted, then erased automatically. What is kept after deletion carries no email and no name: a random account identifier, the words accepted or confirmed, the time, the address, the browser string and, for a confirmation, the site. It is kept to answer a rights holder, a payment dispute or a regulator about what you agreed to and which sites you said you were authorized to capture, and for nothing else.
Encrypted backups rotate out within 35 days, so a deletion reaches them when the backup holding it expires rather than instantly. Until then they are not used for anything else, and if one is ever restored, every deletion made since is applied again before the service comes back.
Who else is involved
We use Google for authentication, Paddle as Merchant of Record for payments, tax and invoicing, Hetzner for hosted compute, storage and backups, and Resend for transactional account and renewal email. Some of these process data outside Baja California, Mexico; that transfer happens because it is necessary to provide the service you asked for.
We do not sell personal data and we do not share it for advertising or cross-context behavioural profiling.
Your rights
You can ask us to give you a copy of what we hold, correct it, delete it, or stop a particular use of it — the rights called ARCO under Mexican law and access, correction, deletion and opt-out elsewhere. Two of them are buttons rather than requests:
- Export. Account settings has a button that returns everything held about your account, as JSON.
- Delete. Account settings first cancels any recurring Paddle subscription, then deletes the account, sessions, hosted workspace, project links, form messages received on your sites, export history, scheduled syncs and verification records. Acceptance records and per-site authorization confirmations are kept for 3 years without your email or name, as described above, then erased. If Paddle cannot confirm cancellation, deletion stops and the account remains.
- Withdraw consent. Marketing consent is a switch in your account and withdrawing it takes effect at once. Withdrawing consent to the terms means closing the account.
- Ask a person. Write to privacy@layerport.app. We answer within 20 days and act on an accepted request within 15 days of that answer.
Requests are handled by Adrian Fernando Santelis Mendoza, the operator named in the Contact page.
If something goes wrong
If a breach affects your rights materially we will notify affected accounts without delay, describe what happened and what data was involved, say what we have done about it, and tell you what you can do. Report a suspected vulnerability or exposure to privacy@layerport.app.
Where data is processed
The responsible party is Adrian Fernando Santelis Mendoza at Calle Cordillera Himalaya 186, Col. Nuevo Milenio, C.P. 21387, Mexicali, Baja California, México in Baja California, Mexico. The hosted workspace and backups are processed by Hetzner in Germany; Google, Paddle and the email provider may process data in other countries under their own privacy terms and contractual safeguards.
Children
This is a professional tool. It is not offered to anyone under 18, and accounts are not knowingly created for them.
Changes
Material changes bump the version of this document. When that happens you are asked to accept the new version the next time you use a feature it governs — not told that continuing counts as agreement.
Questions: privacy@layerport.app.