laya.tools / Legal

Privacy Policy

What personal data laya.tools collects, why, who processes it and how to exercise your GDPR rights.

Updated September 25, 2026

Privacy Policy

This policy explains what personal data laya.tools collects, why, who else sees it and what you can do about it. It applies to laya.tools, its emails and its newsletter.

1. Who is the controller

The controller of your personal data is:

Nielogiczny Karol Labuda Luzińska 2, 84-217 Zęblewo, Poland NIP 5882505100 · REGON 526924027 Contact: [email protected]

We have not appointed a data protection officer. Write to the address above with any privacy question and a real person will answer.

2. What we collect and why

Browsing the directory

You can browse laya.tools without an account and without giving us anything. We process the technical data every web request carries (see "Technical and log data" below).

Account and sign-in

laya.tools has no passwords. When you sign in or submit a project we store your email address, the time you confirmed it and when you last signed in. Sign-in links are single-use and expire after 30 minutes; we store only a hash of the link, never the link itself. We process this to run your account, which is performance of our contract with you (Art. 6(1)(b) GDPR).

Project submissions

When you submit or claim a project we store the URL, the name, tagline, description, categories and links you enter, and the logo and screenshots you upload. This information is published on laya.tools - that is the point of a listing - so do not put personal data in it that you don't want public. Uploaded images are re-encoded on our server, which strips metadata such as camera or location data. Basis: performance of our contract with you (Art. 6(1)(b) GDPR).

To pre-fill the form and suggest categories, the public information about the project you submit (its README, description or web page) is sent to an AI model through OpenRouter. We send project information, not your email address.

Payments

If you buy a Featured placement or a one-time listing, Stripe processes the payment. We receive the amount, the product, the email you pay with and Stripe's reference numbers. We never receive or store your card details. Basis: performance of the contract and our accounting and tax obligations (Art. 6(1)(b) and 6(1)(c) GDPR).

Newsletter

If you subscribe, we store your email address, where you subscribed and when. We send the weekly digest only because you asked for it, which is consent (Art. 6(1)(a) GDPR). Every newsletter has a one-click unsubscribe link, and unsubscribing stops the emails immediately.

Transactional email

We email you when you submit a project, when it goes live, when a payment is confirmed or not completed, when your badge can no longer be found, and when you ask for a sign-in link. These are part of the service, not marketing.

Public projects and posts we list

The directory is built from public sources: GitHub repositories, npm packages, Hugging Face models and Spaces, and public posts on X about Laya. For these we show what the author already published - the project or post, the author's public handle and avatar, and a link back to the original. Our legitimate interest (Art. 6(1)(f) GDPR) is running a useful directory of the Laya ecosystem. If you are the author and want something removed or corrected, write to [email protected] and we will do it.

Technical and log data

Your IP address, browser user agent, the pages you request and error logs. We use them to keep the site secure, stop spam and abuse, and fix problems. Forms are protected by Cloudflare Turnstile, which checks whether a visitor is human. Basis: our legitimate interest in a working and secure service (Art. 6(1)(f) GDPR).

Analytics

We use Umami, a self-hosted analytics tool on our own infrastructure. It counts page views, referrers and coarse device and country information without cookies and without a cross-site identifier, and it does not build a profile of you. Nothing is sent to an advertising network. Basis: our legitimate interest in knowing which pages are useful (Art. 6(1)(f) GDPR).

3. What we do not do

  • We do not sell your personal data.
  • We do not share it with advertising networks or data brokers.
  • We do not use it to train AI models.
  • We do not run behavioural or cross-site tracking.

4. Who processes data on our behalf

Processor Purpose Where
Hetzner Online GmbH Hosting, servers and backups Finland and Germany
Cloudflare, Inc. DNS, CDN, bot protection (Turnstile) Global, EU edge
Stripe, Inc. / Stripe Payments Europe Payment processing EU and USA
PurelyMail Email delivery USA
OpenRouter, Inc. and the AI model provider it routes to Reading public project information to suggest a tagline and categories USA

Where a processor is outside the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses or another mechanism permitted under Chapter V GDPR. We can send you details on request. We may also disclose data where the law requires it, or to establish or defend legal claims.

5. Cookies

We do not use advertising or tracking cookies, so there is no cookie banner. The cookies we set are strictly necessary:

Name Purpose Lifetime
layatools-session Keeps your session and form state Session, up to 2 hours idle
XSRF-TOKEN Protects forms against cross-site request forgery Same as the session
remember_web_… Keeps you signed in after you use a sign-in link Until you sign out, up to 400 days

Cloudflare may set its own security cookies to tell browsers from bots.

6. How long we keep data

  • Account data: while your account exists, then deleted within 30 days of your request.
  • Published listings: while the project is listed. You can ask us to remove your listing at any time.
  • Newsletter: until you unsubscribe.
  • Payment records: 5 years from the end of the accounting year, as Polish tax law requires.
  • Server and application logs: 14 days.
  • Backups: up to 6 months, after which deleted data is gone from them too.
  • Support correspondence: up to 3 years.

7. Your rights

Under the GDPR you can ask us for access to your data, a copy of it, correction, deletion, restriction of processing, or data portability, and you can object to processing based on our legitimate interest. Where we rely on your consent (the newsletter) you can withdraw it at any time without affecting what happened before. Write to [email protected]; we answer within one month.

You also have the right to complain to the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl), or to the authority where you live.

8. Children

laya.tools is a directory for developers and is not directed at children under 16. We do not knowingly collect their data.

9. Changes

If we change this policy in a way that matters, we will say so on this page and, for material changes, email registered users. The date at the top shows when it was last updated.