Privacy Policy
Layven stores what your agents write, attributes it to whoever wrote it, and nothing else. This page states exactly what data we hold, why, and how to get rid of it.
Last updated 4 August 2026
Who we are
Layven is a trading name of Trueguard OÜ, a company registered in Estonia under registry code 17143347, registered address Valukoja tn 8/2, Lasnamäe linnaosa, 11415 Tallinn, Harju maakond, Estonia. For anything to do with privacy or this policy, contact info@layven.io.
We have not appointed a Data Protection Officer. Article 37 GDPR doesn't require one for a company our size doing what we do.
Controller or processor: it depends on the data
For your files, the metadata around them (paths, versions, sizes), and the workspace activity log, we are a processor. You are the controller: you and your agents decide what gets written and who has access; we run the system that stores it on your instruction.
For your account data, billing records, anything to do with the marketing site or our server logs, and any support conversation you have with us, we are the controller, and that data is ours to look after under our own legal basis.
What we hold
Account data
Email, name, organization name, and role. If you set a password, it is stored only as a hash, so we cannot see or recover it. If you sign in with Google instead, we store an identifier for your Google account so we recognise you next time, and no password at all.
Sign in with Google
Optional, and only if you choose it. Google tells us your name, your email address, whether Google has verified that address, and an identifier for your Google account. We ask for nothing else: no contacts, no Drive, no calendar, no access to anything in your Google account. We store the name, the email address and the identifier, and nothing further. Google separately sees that you signed in to Layven, along with your IP address, and handles that under its own privacy policy. If you would rather not involve Google, use an email address and password.
Agent tokens
The label you gave a token, a one-way hash of its secret, a non-secret identifier so you can tell your tokens apart in the console, and a last-used timestamp. Secrets are never stored in plaintext.
File content
Whatever you or your agents write, stored compressed and encrypted. Where identical content is stored only once to save space, that only ever happens within a single workspace. Content is never shared or deduplicated across different customers.
Metadata
Paths, version numbers, sizes, and content types for every file.
Activity log
Changes to a workspace: writes, edits, moves, deletes, restores, locks and searches, each timestamped and attributed to the specific agent token or user that performed it. Creating an agent token or connecting a new client is recorded the same way. Simply opening or reading a file is not recorded.
Billing
Your Stripe customer ID, subscription tier, and billing period. No card data ever reaches us; Stripe handles that directly.
Server logs
Request ID, method, URL, and timestamp for requests to our infrastructure. We do not log request bodies.
What we don't do
There is no advertising, no ad network, no tracking pixel, and no data broker anywhere on this site or in the product. We do not sell your data, we do not share it for advertising, and we do not build profiles to sell to anyone. No Google Analytics, no Mixpanel, no CRM, no support widget, no error-tracking service.
We do run product analytics, described under Analytics below. It never touches your files or anything about them.
We self-host our fonts, so loading a Layven page makes no request to Google for them. There is one exception, and it is worth stating precisely: our three sign-in pages — logging in, registering, and accepting an invitation — load Google's sign-in script so that the Sign in with Google button can work. That request discloses your IP address to Google. No other page on this site and no page in the console contacts Google at all, and you can always sign in with an email address and password instead.
One honest qualifier: our hosting providers' own access logs contain connection data, including IP addresses. That is ordinary web infrastructure, not tracking on our part, and we'd rather say it here than have you find it out later.
Analytics
We use PostHog to understand which pages and features people actually use, so we know what to fix and what to build. We run it on PostHog's EU Cloud in Frankfurt, Germany, and we serve it through our own domain rather than loading a script from someone else's. Your data stays in the EU.
It records pages you visit, clicks and form interactions, your browser and device, your IP address, and, once you are signed in, your user ID.
We rely on legitimate interests here, not consent, so you will not see a cookie banner. That is a deliberate call: we think running one EU-hosted, first-party analytics tool that never sees customer content is proportionate, and we would rather state it plainly than bury it behind a banner nobody reads. You may disagree, and you have an absolute right to object under Article 21. Email info@layven.io and we will exclude you, or set Global Privacy Control or Do Not Track in your browser and we will honour it.
Cookies
A session cookie with a 30-day expiry, set when you log in. It keeps you signed in and does nothing else. It is strictly necessary for the service to work.
PostHog analytics cookies, set on layven.io and its subdomains, which let us tell a returning visit from a new one. These are not strictly necessary, and as explained under Analytics we set them under legitimate interests rather than asking for consent.
If you use Sign in with Google, Google's script stores a small value in your browser on layven.ioso that its prompt does not ask you again after you have dismissed it. It also reads Google's own cookies for accounts.google.comas part of signing you in. Those cookies are Google's, set when you signed in to Google, not something we set or can read.
That is the complete list. No advertising cookie, no tracking pixel, and nothing shared with an ad network.
Legal bases
- Contract: running your account, the service itself, and billing you, is necessary to perform the agreement you accepted when you signed up.
- Legitimate interests: security, abuse prevention, rate limiting, and server logs, so the service stays reliable and safe to run; and the product analytics described under Analytics, so we can improve what we build.
- Legal obligation: accounting and tax records we're required to keep.
Nothing here rests on consent, so there is no consent to withdraw. Where we rely on legitimate interests you can object at any time under Article 21, and for analytics we will act on that without asking you to justify it.
Where your data lives
Your account data, file metadata, and all file content are held on infrastructure at OVHcloud in Gravelines, France. The marketing site and web console are hosted by Vercel and served from an EU region. Product analytics runs on PostHog's EU Cloud in Frankfurt, Germany. See Sub-processors for the complete list.
Sub-processors
We use a small number of specialized providers to run Layven: infrastructure, payments, and email. Sub-processors lists every one of them, what they do, and what data reaches them. That page is the authoritative list; we'll email account owners before adding a new one that touches your data.
International transfers
No file content and no file metadata ever leaves the EU. The bytes and everything about them stay in France, on the infrastructure above.
A few providers that handle the non-file parts of the business sit outside the EU: Vercel is US-headquartered, though our site serves from an EU region, under a DPA with Standard Contractual Clauses. Stripe processes payments in Ireland with an onward transfer to Stripe, Inc. in the US, also under SCCs. Resend, which sends our account and billing email, is US-based and also covered by SCCs.
Retention and deletion
Version history is kept for 30 days on Free and one year on Pro; versions older than that are purged once they are no longer the current one. On Scale and Enterprise, version history is kept indefinitely and never purged.
The workspace activity log follows its own schedule. Entries are kept for 30 days on Free, and for one year on Pro and Scale. Older entries are deleted permanently and cannot be restored. On Enterprise the activity log is kept indefinitely, unless your agreement sets a shorter period.
Deleting your account (Article 17) removes your personal details, your credentials, and your access to any organization you belonged to. If you are the sole owner of an organization, deleting your account deletes that organization and everything in it as well. Past activity entries are kept for audit integrity until the retention period above expires, and they no longer identify you or contain any personal data. Invoices and accounting records are kept for the statutory retention period under Estonian law.
Your rights
Under GDPR you have the right to access, rectify, erase, restrict, and object to how we process your data, plus the right to take your data elsewhere. Portability is easy here, because your files already export as plain files. To exercise any of these, email info@layven.io; we respond within one month.
If you are not satisfied with our answer, you can complain to Estonia's data protection authority, the Andmekaitse Inspektsioon.
If you are an end user of a workspace that belongs to one of our customers, direct your request to that customer. They are the controller for that data, and we assist them as processor.
Security
- TLS in transit everywhere.
- Agent tokens are high-entropy secrets, stored only as one-way hashes, and revocable instantly.
- File content is encrypted at rest by our storage provider using provider-managed keys.
- Every token is scoped to specific workspaces with read-only, read-write, or admin access, plus optional path-prefix allow/deny rules.
- Rate limits contain abuse and runaway agents.
- If a breach occurs, we notify without undue delay, and within 72 hours where Article 33 applies.
Children
Layven is a business and professional tool. It is not directed at, and is not intended for use by, anyone under 16.
Changes
We may update this policy. Changes are posted here with a new date at the top; if a change is material, we'll email account owners directly.
Contact
Trueguard OÜ, registry code 17143347, Valukoja tn 8/2, Lasnamäe linnaosa, 11415 Tallinn, Harju maakond, Estonia. info@layven.io for anything to do with privacy, or to request a Data Processing Agreement.