LayerSend
Legal

Privacy Policy

Last updated: October 4, 2026

1. Who we are

LayerSend (layersend.org) is operated by In-box, a business based in New Zealand ("we", "us"). We decide how and why your personal data is used by the service, so we are the "controller" of it. This policy explains what we collect, why, and what your choices are.

2. What we collect

  • Account data: your email address and display name. Your password is handled by our sign-in provider, which stores it only as a hash.
  • Your content: the design images you upload, and the slices, text, links, settings and generated templates you create from them.
  • Klaviyo connection data: the nickname you give a Klaviyo account and its private API key. The key is encrypted before it is stored.
  • Billing data: payments are handled by Stripe. We store your Stripe customer and subscription identifiers and the status and dates of your subscription. We never see or store your card number.
  • Technical data: sign-in cookies and the standard logs that our hosting provider keeps when you visit, such as IP address, browser type and the pages requested.
  • Messages you send us, such as support emails.

We do not ask for more than this, and we do not collect sensitive categories of data on purpose. Please do not upload designs that contain sensitive personal data about people.

3. How we use it

  • To run the service: sign you in, store your projects, and push templates to the Klaviyo accounts you choose.
  • To process the AI features you use, such as font detection, alt text and layout suggestions.
  • To take payment and manage your subscription.
  • To send emails the service needs: sign-up confirmation, magic sign-in links, password reset, a reminder before a free trial ends, and a test email when you ask for one.
  • To give you support and answer your questions.
  • To keep the service secure, prevent abuse and fix problems.
  • To meet our legal and tax obligations.

Where the GDPR or UK GDPR applies, our legal bases are: performing our agreement with you (running the service and billing), our legitimate interests (security, preventing abuse and improving reliability), complying with the law, and your consent where we ask for it.

We do not sell your personal data. We do not use it for advertising, and we do not use advertising or analytics trackers on the site.

4. AI processing

When you use an AI feature, we send the relevant part of your design (for example a cropped image of one section) to an AI model through OpenRouter, which routes the request to a model provider. Our current models are Google Gemini and Qwen. We send only what is needed for the feature you used, and we do not use your content to train AI models.

Those providers process the request under their own terms and privacy policies. Please avoid uploading designs that you are not allowed to share with them.

5. Who we share data with

We use a small number of service providers to run the service. They process data on our behalf, for the purposes below:

  • Supabase: database, sign-in and file storage for your account, projects and uploaded images.
  • Vercel: hosting and delivery of the website and application.
  • Stripe: payments, subscriptions and the billing portal.
  • OpenRouter, and the AI model providers it routes to (currently Google Gemini and Qwen): processing design crops for the AI features.
  • Brevo: sending the emails the service needs, such as sign-in and password emails and trial reminders.
  • Klaviyo: only when you push a template. We send the template and its images to the Klaviyo account you chose, using your own API key.

We may also share data when the law requires it, to protect our rights or the safety of others, or as part of a sale or reorganisation of the business, in which case we will make sure this policy continues to protect your data.

6. Cookies

We only use cookies that the service needs to work. We do not use advertising or analytics cookies, so there is no cookie banner to accept.

  • Sign-in session cookies, set by our sign-in provider (Supabase). They keep you signed in and are refreshed as you use the site.
  • A short-lived checkout cookie (it lasts about five minutes). After you complete a payment it lets your new subscription take effect while Stripe confirms it to us.

7. International transfers

We are based in New Zealand, and most of our providers operate in the United States and other countries. Your data may therefore be processed outside the country where you live. Where the law requires it, we rely on safeguards such as standard contractual clauses or the providers' data protection commitments.

8. How long we keep data

  • We keep your account and content while your account is active.
  • When you delete a project, we delete the project and its stored image files. When you remove a Klaviyo account from the service, we delete its stored API key. Templates that you already pushed stay in your Klaviyo account, because they belong to you there.
  • The app does not yet have a button to delete your whole account. To close your account, contact us. We will delete your account and content within 30 days, except records we must keep for legal or tax reasons, such as billing records.
  • Our providers may keep copies in their backups for a short period after deletion.

9. Your rights

Depending on where you live, you may have the right to: see the personal data we hold about you, have it corrected, have it deleted, receive a copy of it in a usable format, object to or limit some uses of it, and withdraw consent you gave. This includes rights under the GDPR and UK GDPR, the California Consumer Privacy Act, and the New Zealand Privacy Act 2020.

To use any of these rights, contact us. We may need to confirm it is really you first. We will not treat you worse for using your rights.

If you are not happy with how we handle your data, please tell us first so that we can try to fix it. You can also complain to your local data protection regulator, such as the Office of the Privacy Commissioner in New Zealand or your national authority in the EU or UK.

10. Security

  • Traffic between your browser and the service is encrypted with TLS.
  • Klaviyo API keys are encrypted at rest and are only decrypted on our servers, at the moment you push.
  • Access to your projects and accounts is limited by database access rules, so people only reach the data they are allowed to see.
  • Passwords are stored as hashes, not in readable form.

No system is perfectly secure, so we cannot promise absolute security. If we learn of a breach that affects your data, we will tell you and the authorities as the law requires.

11. Children

LayerSend is not for anyone under 16, and we do not knowingly collect data from children. If you think a child has given us data, contact us and we will delete it.

12. Changes to this policy

We may update this policy. If a change is significant, we will tell you by email or in the service before it takes effect. The date at the top shows when it was last updated.

13. Contact

For privacy questions, or to use your rights, contact us.

Email us at gavin@in-box.co.nz.