Privacy Policy
This policy explains what personal data Layerbase collects, why we collect it, how we use it, and how deletion works.
Last updated: September 2, 2026
Data We Collect
Layerbase may collect and process:
- account information, including email address, display name, OAuth provider IDs, avatar URLs, role, account status, and login timestamps;
- cloud database metadata, including database names, engines, versions, hostnames, ports, status, plan limits, firewall rules, backup records, and API key metadata;
- database content and backup artifacts that you create or upload to Layerbase Cloud;
- billing and subscription metadata from Polar, such as customer IDs, product IDs, subscription IDs, plan state, and payment status;
- operational logs, diagnostics, IP addresses, user agent data, request metadata, error traces, support messages, and bug reports;
- diagnostic data from the internal tooling described in Diagnostics and Debugging below;
- desktop download and update metadata needed to serve releases and validate entitlements.
How We Use Data
We use data to:
- authenticate users and maintain sessions;
- create, run, stop, back up, restore, and delete databases;
- enforce quotas, rate limits, security controls, and plans;
- process checkout, subscriptions, and entitlement sync;
- provide support, debug incidents, and improve reliability;
- send account and service messages, product updates, and occasional promotional offers you can unsubscribe from;
- detect abuse, fraud, security incidents, and outages;
- comply with legal obligations.
Communications
When you create a Layerbase account, including a free account, you are added to our email list and may receive product updates, announcements, and occasional promotional offers such as coupon codes. Using the service means agreeing to receive these messages.
We keep marketing email infrequent. Every promotional message includes a one-click unsubscribe link, and unsubscribing stops all marketing and promotional email while keeping your account fully active. You can opt back in at any time.
When you unsubscribe, or when your data is erased, we keep a minimal suppression entry containing only your email address, solely to ensure we do not send you marketing again. We keep it until you explicitly opt back in, because an opt-out we forget is not an opt-out. It is never used to contact you.
Service and transactional messages are separate from marketing and are not optional while you have an account. These include sign-in links, security and billing notices, database lifecycle and outage alerts, support replies, and notices of material changes to our policies. We send them because they are necessary to operate your account and the service.
Analytics and Advertising
The public marketing site uses analytics and advertising tools to measure traffic and the performance of our ad campaigns: Cloudflare Web Analytics, Ahrefs Analytics, Google Analytics, and advertising pixels from Reddit, Meta, and X. These tools may process page views, referrers, IP addresses, and browser information, and the advertising pixels may set cookies. They run only on the marketing site, never inside the cloud dashboard or the databases you host with us.
When you arrive from an ad or campaign link, we store the campaign parameters and ad click identifiers in a first-party cookie for 30 days so we can attribute signups to the campaign that brought them. When a signup or purchase happens, we may report that conversion to the advertising platform that referred it, identified by a one-way hash rather than your email address itself. We do not sell personal data, and database content is never used for advertising or analytics.
Diagnostics and Debugging
We use internal logging and debugging tools, running on our own infrastructure, to investigate errors and improve the reliability of the website and the cloud dashboard. These tools have privacy and anonymization safeguards built in: sensitive values such as connection strings, credentials, API keys, environment values, and query results are masked and are not collected, and the content of your databases is never collected. Data these tools hold is covered by account deletion and by GDPR erasure requests, and you can object to their use, or ask us to delete what they hold about you, by contacting bob@layerbase.com. We may need to verify your identity first, as with any other privacy request.
Service Providers
Layerbase uses third-party providers to operate the service, including OAuth providers such as Google and GitHub, Polar for billing, Vercel for the web application, OVHcloud and AWS for cloud compute, Cloudflare for DNS and R2 storage, GitHub for release hosting and workflows, and email or observability providers used for product communication and operations. These providers process data only as needed to deliver their services to Layerbase.
Database Content
You control the content stored in your databases. Layerbase does not sell database content and does not inspect it for marketing. We may access database content or backups when needed to provide the service, troubleshoot an issue at your request, investigate security or abuse, comply with law, or recover from operational failure.
Do not store sensitive regulated data that requires a specific compliance program, region, retention policy, or data processing agreement unless we have agreed to those terms in writing.
Retention
Account records are retained while your account exists. Cloud databases are retained until you delete them, your account is deleted, or we terminate access under the Terms of Service.
Backup retention depends on the current plan, backup system, and operational state. Account deletion is designed to purge cloud database rows, API keys, DNS records, and R2 backups owned by the account. Operational logs are normally retained for about 30 days. Billing records may be retained longer where needed for tax, accounting, fraud prevention, dispute handling, or legal obligations.
When an automated client drafts a project specification before anyone has claimed it, we store that draft for up to 1 day and then delete it if it goes unclaimed, and we create no databases or other resources for it until a person signs in and confirms it.
Deletion Requests
You can delete your own account from the cloud settings page. The deletion flow removes your Layerbase account and triggers cloud-side purge of databases, API keys, DNS records, and backups associated with that account.
You can also contact bob@layerbase.com for account deletion, access, correction, or portability requests. We may need to verify your identity before acting on a request.
If you ask us for full erasure and we verify the request, we go further than the self-serve flow: every backup is deleted including the last copy, and so are the records elsewhere in our systems that name you, such as support requests, bug reports, team invitations, marketing and conversion rows, and the diagnostic data described above. We keep one record of the erasure itself, holding your email address and the request and erasure dates, for 90 days. We keep it so we can show that your request was honoured and when, which European data protection law allows for the establishment, exercise, or defence of legal claims. It is deleted automatically once that period ends.
We also keep a minimal suppression entry containing only your email address, solely to ensure we do not send you marketing again. It has no expiry, because a marketing objection we forget is not an objection, and it is removed only if you later opt back in.
Security
Layerbase uses OAuth authentication, server-side access controls, rate limits, isolated database containers, TLS for public connection paths where supported, backup infrastructure, and operational monitoring. No internet service is perfectly secure; you are responsible for protecting database credentials, API keys, OAuth accounts, and client systems.
Children
Layerbase is not intended for children under 13, and we do not knowingly collect personal data from children under 13.
Changes
We may update this policy as Layerbase changes. If changes are material, we will make reasonable efforts to notify users through the website, dashboard, or email.
Contact
Privacy questions can be sent to bob@layerbase.com.