Who we are
Laytuh is made by Wingbie Inc. ("we", "us"). We decide what happens to the personal data described here, which makes us its controller. You can reach us at support@laytuh.com about anything on this page.
What we collect
Your account
- Email address. You sign in with a one-time code sent to your email. If you sign in with Google, Apple or Facebook instead, that provider tells us your email address and an account ID. With Apple you can hide your address, and we get a private relay address instead.
- Account ID. A random identifier our sign-in provider creates for you.
- Name and handle, if you add them. A display name, and a handle if you set up a creator page.
- Settings. Your timezone, quiet hours, how many reminders a day you allow, theme, and similar choices.
What you save
- Links and what you type. The link you share to Laytuh, any note you add, when you want it back, and corrections you make to where it was filed.
- Details we find for a link. The title, caption, preview image and, for places, the name, address and opening hours we look up. Preview images from some sites expire within days, so we may keep a copy of the preview so your card doesn't break.
- Text from screenshots. When you share a screenshot, your phone reads the text in it. Only the recognised text or link becomes part of the save. The image itself stays in the app's private storage on your phone and is removed once the save is complete, unless you choose to keep it.
- What you do with saves. Marking something done, "Did it" or "Not now" on a reminder, and the boards, polls and votes you make. We use these to decide what to bring back and when.
Features you turn on
- Notifications. If you allow them, your phone gives us a push token (a device address from Google or Apple) so we can send reminders.
- Ask. The questions you type into Ask, which we answer from your own saves. We count how many you ask each day to apply a daily limit.
- The Laytuh agent. If you switch it on, we keep a log of what it looked at, what it suggested, and what you approved or declined, so it never suggests something you already turned down.
App diagnostics and usage (optional)
The Laytuh apps use Google Analytics for Firebase and Firebase Crashlytics. On by default; turn either off any time in You → Privacy → "Share anonymous usage to make Laytuh better", which controls both together.
- Usage events. A closed list of app actions (for example a save being created, a card opening, a reminder being acted on) and buckets like how many spaces or saves you have. No titles, links, notes, search queries or other content — only the event name and the closed set of values it allows.
- Crash and diagnostic reports. If the app crashes, Crashlytics sends the stack trace, app state and device details at that moment. We tag reports with a one-way hash of your account ID, never the ID or your email itself.
- Device and install identifiers. A Firebase installation ID, a Google Analytics app-instance ID and a Crashlytics install ID, none of which are your advertising ID (we don't collect or use one).
- Approximate location. We don't ask for or use the location permission. Google Analytics for Firebase infers a coarse, city-level location from your masked IP address for these usage events only; we never see or store a precise location.
People who don't have an account
- Voting on a shared poll. When someone opens a poll link and votes, we set a cookie with a random ID so each browser votes once. Cloudflare Turnstile checks the vote comes from a person, which involves your browser and IP address. We don't link the vote to a name.
- The old waitlist. The waitlist is closed now that Laytuh is in the stores. If you joined it before launch, we still hold your email address and where the link you followed came from (for example the name of the ad campaign in it), until you ask us to remove them.
Our website
On laytuh.com only, and only if you choose Accept in the cookie banner, we use Google Analytics to count visits and see which pages work, and the Meta Pixel to measure our ads on Facebook and Instagram. They set cookies and receive your browser details, the pages you view and whether you tapped a store button, never your email address. If you choose No thanks, neither loads. You can change your mind any time with Cookie settings at the bottom of the site. None of this runs in the Laytuh apps.
Technical records
Our servers and providers record requests the way any website does: IP address, device and browser type, time, and the address requested. We use these to keep Laytuh working and to stop abuse.
What we don't collect
- Your precise location. The app doesn't ask for location permission. If we add nearby reminders later, they will be off until you turn them on, and this page will say so first. (Optional app analytics can infer a coarse, city-level location from your IP address — see App diagnostics and usage.)
- Your photo library, contacts, calendar, messages or microphone.
- Your advertising ID. There are no ads and no ad trackers in the Laytuh apps.
- Your browsing history. A link you share to Laytuh is something you chose to send us, not something we watched you open.
How we use it
- To run your vault: store your saves, sync them between your devices, and show them to you.
- To understand a save: fetch the link's details, work out which space it belongs in (Watch, Read, Buy, Go or Ideas), and look up a place when the save is one.
- To bring things back: send a reminder when there's a real reason (a date you wrote, a trip your saves point to, something you asked us to remind you about), and a weekly digest for the rest. You control how often.
- To answer Ask using only your own saves.
- To run the agent when you turn it on. It suggests; it doesn't act on anything that needs your say-so until you approve it.
- To publish what you choose to share: boards, polls and your creator page.
- To keep Laytuh safe: check public text for spam and abuse, rate-limit, and investigate misuse.
- To email you sign-in codes and, rarely, notices about your account or this policy.
We don't sell your personal data, and we don't use what you save to build a profile for anyone else. The only data shared for advertising is the optional website measurement described under Our website, and only if you accept it.
Where the law asks us to name a legal basis (for example in the UK and EU): running your account and the features you use is performance of our contract with you; keeping Laytuh secure and fixing it is our legitimate interest; notifications, the agent, app analytics and crash reporting, and website analytics and ads measurement rely on your consent, which you can withdraw at any time in settings; and we keep some records because the law requires it.
Automated processing
Most of what Laytuh decides happens on your phone first: reading screenshots, and filing a save from its link and caption. When your phone can't tell, our servers ask an AI model to classify the save. Ask, the agent, and our check on public text also use AI models.
These models run on Cloudflare Workers AI. Cloudflare processes the text for us and states that it does not use customer content to train models. We don't train models on your saves either.
Automated decisions here only affect things like which space a save lands in, when a reminder is worth sending, or whether public text is held back. You can move a save, change your reminder settings, or contact us if something you published was blocked.
Who helps us run Laytuh
These companies process data for us, on our instructions, only to provide their service. We require them to protect it at least as well as this policy does. None of them may use your data for their own purposes, except that Google and Meta also apply their own policies (Google, Meta) to the optional website measurement data.
| Provider | What they do | What they receive |
|---|---|---|
| Supabase | Database, sign-in and account storage | Your account, settings and everything you save |
| Cloudflare | Our servers and website, AI models, preview-image storage, bot checks on poll votes, email delivery | Requests to our servers, saves being processed, poll votes, sign-in code emails |
| Google Firebase Cloud Messaging | Delivers notifications on Android | Your push token and the reminder (a save ID and why it's back) |
| Apple Push Notification service | Delivers notifications on iOS | Your push token and the reminder |
| Google Analytics for Firebase | Optional in-app usage analytics, on by default, off in You → Privacy | Closed-vocabulary usage events, install/instance IDs, coarse IP-based location; never titles, links or notes |
| Firebase Crashlytics | Optional in-app crash and diagnostic reporting, on by default, off in You → Privacy | Stack traces, app state, device metadata, a hashed account ID |
| Google Places | Finds the place a save is about | The place name or address from the save, not who you are |
| Meta, TikTok and YouTube (oEmbed) | Return the title and preview for a post you saved | The link to that post, from our servers |
| Google Analytics | Counts visits to laytuh.com, only if you accept cookies | Browser details, pages viewed and taps on the store buttons (no email address) |
| Meta Pixel | Measures our ads on Facebook and Instagram, only if you accept cookies on laytuh.com | Browser details, pages viewed and taps on the store buttons (no email address) |
| Google, Apple and Meta sign-in | Sign you in, only if you choose them | The sign-in request; they send us your email and account ID |
When we fetch a link you saved, the request comes from our servers, not your phone, so the site you saved doesn't see your IP address.
We may also disclose data if the law requires it, to protect someone's safety, or to a buyer if Laytuh is ever sold, in which case this policy keeps applying to your data and we'll tell you first.
What's public
Your vault is private by default. Something becomes public only when you publish it:
- Your creator page at laytuh.com/@yourhandle shows your handle, display name and the boards you mark public.
- A public board shows its name, description and items to anyone.
- A poll you share can be opened by anyone with the link. They see the question, the options and the tally, not who voted.
Anything you publish can be seen, copied or shared by others. Make it private again, or delete it, and we stop showing it.
How long we keep it
- Account and saves: for as long as you have an account. You can delete single saves at any time.
- When you delete your account: your account and everything linked to it is removed from our live database straight away. Backups kept by our database provider expire on a rolling schedule, and deleted data disappears from them when they do. We never restore a deleted account from a backup. Details are on the data deletion page.
- On your phone: saves cached in the app are removed when you sign out or uninstall. Screenshot images are removed once their save is complete, unless you chose to keep them.
- Daily counters (for Ask and agent limits) reset every day.
- Technical records are kept briefly by our providers for security and debugging, then discarded.
- Old waitlist emails: until you ask us to remove yours.
- Anonymised figures: counts that can't identify you (for example, how many saves came back in a week, or which websites usually belong in which space) may be kept after your account is gone.
Your choices and rights
- See and take your data: email support@laytuh.com and we'll send you a copy of your saves.
- Correct it: edit any save, your name or your handle in the app.
- Delete it: delete a save, take an item off a board, or delete your whole account. See data deletion.
- Withdraw consent: turn off notifications or the agent in the app or your phone's settings, or turn off app analytics and crash reporting any time in You → Privacy. Signed in with Google, Apple or Facebook? You can also remove Laytuh from that account's settings.
- Ask us: email support@laytuh.com to access, correct, delete, restrict or object to how we use your data, or to get it in a portable format. We reply within 30 days.
Depending on where you live (for example the EU, UK, or California), these are legal rights, and you can also complain to your data protection authority. We don't sell or share personal information as California law defines those terms, and we don't treat you differently for using your rights.
Security
- Everything between the app and our servers is encrypted in transit (HTTPS).
- Each person's data is walled off at the database level, so one account can't read another's.
- The keys that can change anything on the server live only on the server, never in the app.
- On your phone, your sign-in is sealed with the phone's secure hardware (Android Keystore, iOS Keychain), and the Android app is excluded from cloud backups.
No system is perfectly secure. If a breach affects your data, we'll tell you and the authorities as the law requires.
Children
Laytuh isn't for children under 13, or under the minimum age for using online services without a parent's consent where you live. We don't knowingly collect their data. If you think a child has an account, email us and we'll delete it.
Where data is processed
Our providers run servers in several countries, so your data may be processed outside the country you live in. When data leaves the UK or EU, we rely on our providers' standard contractual clauses or an equivalent legal safeguard.
Changes
If we change this policy, we'll update the date at the top. If a change affects how we use data you've already given us, we'll tell you in the app or by email before it takes effect.
Contact
Wingbie Inc., support@laytuh.com. Privacy questions, requests and complaints all go to this address.