Trust & transparency
Privacy policy
What LayerWorth collects, why it is used and how to contact us.
Last updated October 6, 2026
Operator and contact
LayerWorth LLC operates LayerWorth. For privacy requests, contact privacy@layerworth.com.
Information you provide
Accounts collect a display name, email address and credentials handled by Supabase Auth. Printing experience is optional. We store account identifiers, onboarding preferences, currency defaults and marketing-email choices. Password confirmation is used for validation and is not stored in application profiles.
Workspaces can store memberships, invitation email addresses, product recipes, notes, material and printer profiles, component costs, marketplace rules and calculation snapshots. Public calculations run in your browser; saving workspace records is a separate action.
Support messages may contain contact details, account IDs and information you choose to send. Do not send passwords, authentication codes, card numbers or API secrets.
Payments and technical information
Stripe handles checkout and payment details. LayerWorth stores or processes payment customer and subscription identifiers, verified billing events and entitlement status. The application does not provide its own full card-number entry form.
Hosting, authentication, payment and email providers may process request metadata such as IP addresses, timestamps, delivery information and security logs to operate their services. Essential cookies support login, recovery and preferences. See /analytics for optional analytics controls.
How information is used
Information is used to operate accounts and workspaces, calculate and save estimates, process subscriptions, deliver transactional messages, provide support, protect the service and meet legal obligations. Marketing messages require the separate marketing preference; declining analytics does not change that preference.
With browser analytics permission, PostHog receives filtered product events and browser error reports. Names, emails, passwords, raw error messages, calculator amounts, auth tokens and URL query strings are excluded by the application event policy. Account-linked events use an environment-prefixed support ID, which is pseudonymous rather than anonymous. Session replay and automatic form capture are disabled.
Service providers and sharing
Vercel hosts the application, Supabase provides authentication and database services, Stripe processes billing, and PostHog provides product analytics and operational monitoring. Email service providers deliver transactional messages. These providers process information necessary for their functions.
Shared-workspace information is available to authorized members. We may disclose information where required by law or necessary to investigate abuse, protect rights or carry out a business transfer with appropriate safeguards. The current application does not implement advertising trackers or a sale of customer data.
Operational monitoring and analytics choices
Account-linked browser analytics and request-based product events require accepted analytics-cookie permission, which you can withdraw at /analytics. Before a choice and after rejection, basic cookieless measurement counts public-page visits without stored analytics identifiers or account identification. PostHog uses request IP/user-agent information to generate a daily server hash, then discards the IP from the event. Supported Do Not Track and Global Privacy Control signals disable both browser measurement modes.
Authentication, payment processing, security controls, filtered server error reporting and verified subscription/webhook monitoring continue independently of optional analytics. Operational feature flags may use account identifiers to safely enable or pause functions. Declining analytics does not disable these functions.
Retention and deletion
We retain information as needed to provide the service, resolve support issues, maintain security and meet applicable recordkeeping obligations. Downgrading preserves saved work while access may be restricted. Cancellation alone does not delete an account.
Request access, correction, deletion or available export assistance at privacy@layerworth.com. We may verify identity and authority before acting. Shared workspace records, required billing records and backup copies can need different handling. Deletion requests are subject to applicable retention obligations.
Rights, security and international processing
Depending on location, you may have rights to access, correct, delete, restrict or object to processing, obtain a copy, withdraw consent or complain to a supervisory authority. Mandatory rights are not limited by this policy. Service providers may process information outside your country of residence, subject to applicable safeguards.
We use access controls, tenant permissions and provider security features, but no internet service can guarantee complete security. The service is intended for adults, not children. Contact privacy@layerworth.com if information from a child may have been provided.
Changes
Material changes will be reflected in a dated policy and communicated where required.