Skip to content
Legal

Privacy Policy

Last updated: July 14, 2026

This policy explains what personal data layernote collects, why we collect it, and the choices you have. It applies to layernote.io and everything connected to it. The short version: we collect what we need to run the product, we don’t sell your data, and you stay in control.

1. Who we are

layernote is the controller for the personal data described in this policy. You can reach us at info@layernote.io.

2. Data we collect

  • Account data: your name, email address, and password hash, or your Google profile basics if you sign up with Google.
  • Content: the projects, comments, files, and URLs you bring into layernote, including screenshots we render of pages you review.
  • Billing data: your plan and invoicing details. Card numbers go directly to our payment provider and never touch our servers.
  • Usage data: logs and product analytics, such as which features are used, collected as aggregated or pseudonymised data where possible.
  • Guest data: the display name a guest reviewer chooses when they comment through a share link.

3. Why we use it

  • to provide and secure the service (contract);
  • to run features you ask for, like the design comparison of a design against a live site (contract);
  • to improve the product with aggregated usage insight (legitimate interest);
  • to send product updates you can opt out of at any time (legitimate interest or consent);
  • to meet legal obligations such as tax record-keeping.

We don’t sell personal data, and we don’t use your content to train machine-learning models.

4. Cookies

We use a small set of cookies and similar storage: essential ones for the site to work, and optional analytics and marketing ones that only run with your consent. The details, and the controls to change your choice, live in our cookie policy.

5. Who we share it with

We share data only with the processors we need to run layernote: hosting and infrastructure, payment processing, email delivery, and analytics. Each processor is bound by a data-processing agreement. When you connect a third-party service yourself, such as Figma or a coding agent over MCP, we share the data that connection needs and nothing more.

We disclose data to authorities only when the law requires it.

6. International transfers

Where a processor stores data outside the European Economic Area, we rely on an adequacy decision or the European Commission’s Standard Contractual Clauses.

7. Retention

We keep your data for as long as your account exists. When you delete your account, we delete your personal data and content within 30 days, except for records we must keep longer for legal reasons, such as invoices. Backups roll off on a fixed schedule after that.

8. Your rights

Under the GDPR you can ask us for access to, correction of, deletion of, or a portable copy of your personal data, and you can object to or restrict certain processing. Email info@layernote.io and we’ll respond within a month. You can also complain to your data-protection authority; in the Netherlands that’s the Autoriteit Persoonsgegevens.

9. Security

Data is encrypted in transit and at rest, access is limited to the people who need it, and we review that access regularly. No system is perfectly secure, but if a breach ever affects your data we’ll notify you and the authorities as the law requires.

10. Changes to this policy

When we change this policy in a meaningful way we’ll update the date at the top and notify you by email or in the app before the change takes effect.