Trust & transparency
Privacy policy
What LayerWorth collects, why it is used and how to contact us.
Last updated October 10, 2026
Key points
- Your data serves your workflow. Account and workspace records support the tools you use. Public calculations run in your browser.
- Separate choices. Marketing email and optional analytics have independent preferences.
- A way to reach us. Contact privacy@layerworth.com for access, correction, deletion or available export assistance.
Plain-language highlights. Read the full details below, including applicable exceptions and rights.
On this page
Operator and contact
LayerWorth LLC operates LayerWorth. For privacy requests, contact privacy@layerworth.com.
Information you provide
Accounts collect a display name, email address and credentials handled by Supabase Auth. Printing experience is optional. We store account identifiers, onboarding preferences, currency defaults and marketing-email choices. Password confirmation is used for validation and is not stored in application profiles.
Teams store memberships, invitation email addresses and subscription details. Their workspaces can store product recipes, notes, material and printer profiles, component costs, marketplace rules and calculation snapshots. Public calculations run in your browser; saving workspace records is a separate action.
Pricing comparison baselines and quick calculator quotes are temporary in-page data. Saving a quote in the Pro or Studio Quotes tool stores its business and customer names, optional business contact email and phone, reference, validity date, item descriptions, quantities, prices, shipping, notes and status in the workspace. Authorized workspace members can access these records. Ready quotes can be shared using expiring, revocable customer links. Anyone holding a link can view its customer-facing details and respond; customer identity is not independently verified. We store the response name, decision, timestamp and frozen quote version and snapshot. When a workspace member explicitly sends a quote email, we share the recipient address, customer and business names, reference, total, up to three item summaries, expiry, customer link and the sender’s verified account email as the reply address with Brevo for transactional delivery, and store the recipient, attempt time and send status. Workspace owners can save shared business details and default quote notes for future quotes. We store quote activity records, including actor display names, actions, versions and timestamps, for authorized workspace members. We also store private in-app response notifications and their read state for the quote creator and latest sharing member while they belong to the workspace. If you enable optional quote response emails, we send your verified account address, the quote title and response summary, and a signed-in dashboard link to Brevo for transactional delivery. We retain a private delivery record to prevent duplicate sends. You can turn these alerts off in Notification Preferences independently of marketing. Customer quote pages do not load product analytics. Copying or downloading puts the summary in your clipboard or a file on your device. You decide where to share it; saving a calculation is a separate action.
Support messages may contain contact details, account IDs and information you choose to send. Do not send passwords, authentication codes, card numbers or API secrets.
Payments and technical information
Stripe handles checkout and payment details. LayerWorth stores or processes payment customer and subscription identifiers, verified billing events and entitlement status. The application does not provide its own full card-number entry form.
Hosting, authentication, payment and email providers may process request metadata such as IP addresses, timestamps, delivery information and security logs to operate their services. Essential cookies support login, recovery and preferences. See /analytics for optional analytics controls.
How information is used
Information is used to operate accounts and workspaces, calculate and save estimates, process subscriptions, deliver transactional messages, provide support, protect the service and meet legal obligations. Marketing messages require the separate marketing preference; declining analytics does not change that preference.
With browser analytics permission, PostHog receives filtered product events and browser error reports. Names, emails, passwords, raw error messages, calculator amounts, auth tokens and URL query strings are excluded by the application event policy. Account-linked events use an environment-prefixed support ID, which is pseudonymous rather than anonymous. Session replay and automatic form capture are disabled.
Service providers and sharing
Vercel hosts the application, Supabase provides authentication and database services, Stripe processes billing, PostHog provides product analytics and operational monitoring, and Brevo delivers configured transactional emails. These providers process information necessary for their functions.
Cloudflare Turnstile checks supported authentication and affiliate-application forms for automated abuse. Cloudflare may process request and device information, including IP addresses, to perform those security checks. Verification tokens are sent to Supabase for authentication or checked by LayerWorth for applications. These checks protect the service and do not depend on optional analytics permission.
Team members can access information across that team’s workspaces according to their role and the current plan. We may disclose information where required by law or necessary to investigate abuse, protect rights or carry out a business transfer with appropriate safeguards. The current application does not implement advertising trackers or a sale of customer data.
Operational monitoring and analytics choices
Account-linked browser analytics and request-based product events require accepted analytics-cookie permission, which you can withdraw at /analytics. Before a choice and after rejection, basic cookieless measurement counts public-page visits without stored analytics identifiers or account identification. PostHog uses request IP/user-agent information to generate a daily server hash, then discards the IP from the event. Supported Do Not Track and Global Privacy Control signals disable both browser measurement modes.
Authentication, payment processing, security controls, filtered server error reporting and verified subscription/webhook monitoring continue independently of optional analytics. Operational feature flags may use account identifiers to safely enable or pause functions. Declining analytics does not disable these functions.
Retention and deletion
We retain information as needed to provide the service, resolve support issues, maintain security and meet applicable recordkeeping obligations. Downgrading preserves saved work while access may be restricted. Cancellation alone does not delete an account.
Deleting a saved item, workspace or team removes it from normal access but initially retains the record separately for recovery and support. Deleting a workspace or team also disables its shared quote links. Restricted administrative access can review retained records. We keep aggregate creation and deletion counts that do not include item contents or customer contact details; these counts can remain after content is permanently removed.
Request access, correction, deletion or available export assistance at privacy@layerworth.com. We may verify identity and authority before acting. Shared workspace records, required billing records and backup copies can need different handling. Deletion requests are subject to applicable retention obligations.
Rights, security and international processing
Depending on location, you may have rights to access, correct, delete, restrict or object to processing, obtain a copy, withdraw consent or complain to a supervisory authority. Mandatory rights are not limited by this policy. Service providers may process information outside your country of residence, subject to applicable safeguards.
We use access controls, tenant permissions and provider security features, but no internet service can guarantee complete security. The service is intended for adults, not children. Contact privacy@layerworth.com if information from a child may have been provided.
Affiliate referrals and applications
If you begin an affiliate application before signing in, your answers are saved in browser-local storage for up to seven days so you can return after authentication. A seven-day essential HttpOnly cookie carries your email and name to the sign-in or signup form. The application is sent for review only after you verify your account and submit. Saved answers are cleared after submission or when an expired draft is revisited; clearing browser storage removes the draft sooner.
We operate an affiliate program with unlisted applications, email invitations, reviewed creator terms, and verified subscription attribution. We process application contact information, channel and audience information, referral identifiers, verified account associations, and related subscription payment records. Affiliates receive aggregated counts and their own earnings; they do not receive referred customers' names, email addresses, card information, or private team records.
A referral link saves a host-only, HttpOnly cookie only after you explicitly choose to remember it. It expires seven days after your first visit and does not restart when another link is opened. A valid referral code entered by a verified customer can also associate a referral with that account. Optional referral attribution is separate from analytics and marketing email. You can clear pending referral attribution through /analytics; completed transactions and required accounting records remain.
Changes
Material changes will be reflected in a dated policy and communicated where required.