01
Who handles your information
Strataga, LLC operates LayoutLark. This Privacy Policy covers personal information handled through our website, hosted design workspace, account emails, support, and connected-app features. Strataga is responsible for deciding how account, service-operation, and support information is used. Contact us at support@layoutlark.com for privacy questions or requests.
LayoutLark is a free beta design and prototyping service. This notice describes the current service, including access from a connected AI client; it does not govern an independent AI provider or a website you visit through an external link. If a separate signed data-processing agreement applies to information you provide on behalf of an organization, that agreement also governs the processing it covers.
You do not have to create an account to read public pages. A name, email address, password, email verification, and eligibility/terms acknowledgments are required to create a hosted account. Without them we cannot provide an authenticated workspace. Project content and AI connections are optional.
02
What we collect and where it comes from
| Category | Information and source | Why it is needed |
|---|---|---|
| Account and security | Your name, email address, password hash, verification status, account identifiers, sign-in sessions, verification/reset records, and the versions and time of your terms/privacy acknowledgments and eligibility confirmation. You provide account details; the service generates security records. | Create and protect your account, verify ownership, manage access, and record your agreement. We do not store your password in readable form. |
| Your workspace | Designs, text, uploaded images and assets, external asset URLs, components, styles, prototype connections, selected projects, revision history, checkpoints, and exports. These come from you or an application you authorize. | Save, edit, display, render, recover, and export your work. |
| Connected applications | Client identifiers, requested and approved permissions, consent records, access/refresh credentials, revocations, and the tool inputs and content sent through the connection. | Authenticate the client, enforce its permissions, and carry out requested actions. |
| Technical and usage information | IP addresses, browser/user-agent information, request paths, timestamps, response/error information, security events, and rate-limit records, collected by the app or hosting infrastructure. With your permission, local browser storage saves canvas preferences. | Deliver pages, prevent abuse, maintain sessions, diagnose failures, and keep the service working. |
| Support and reports | Your contact details, correspondence, and information you choose to include in a support, security, rights, or content complaint. | Respond to the request, investigate the issue, and document its resolution. |
We do not request payment-card details, government identifiers, precise device location, or sensitive health or biometric information. Please use fictional or de-identified content in design examples and do not put passwords or other highly sensitive information in projects or support messages.
We do not automatically receive an AI provider’s entire conversation history. We receive the tool requests and information that its connection sends to LayoutLark. Text included in a request or saved design may itself contain information from your conversation.
03
How we use information
We use information to provide your account and workspace; fulfill rendering, export, and AI-tool requests; send essential verification and password-reset emails; secure the service; investigate errors or abuse; respond to support and privacy requests; maintain agreement records; and meet legal obligations.
We do not sell personal information, rent mailing lists, share personal information for cross-context behavioral advertising, or use it for targeted advertising. The current website has no advertising pixels or third-party product-analytics scripts. We do not use your project content to train our own general-purpose AI models or give private projects to other customers.
We do not make decisions about eligibility for credit, employment, housing, insurance, or similar significant matters through automated profiling. Automated authentication and rate limits protect the service; contact support if you believe they have wrongly restricted you.
04
Legal bases where applicable
Where European, UK, or other law requires a legal basis, we rely on the following, as applicable to the activity:
- Providing the service you request: processing necessary to establish and perform the account/service agreement, including saving designs, account communications, and carrying out authorized tool actions.
- Legitimate interests: proportionate security, fraud prevention, troubleshooting, support, and maintaining evidence of agreements and disputes, after considering your rights and reasonable expectations.
- Legal obligations: processing required by applicable law, court orders, and legally required responses to rights requests.
- Consent: when a particular optional activity legally requires consent. We will seek it separately; acknowledging this policy does not consent to unrelated purposes.
If we rely on consent, you may withdraw it without affecting earlier lawful processing. You may object to processing based on legitimate interests; see “Your choices and privacy rights.” Permission to connect an AI client can be withdrawn in account settings.
06
Your AI connection is your choice
You can use the visual editor without connecting an AI provider. When you connect one, review the requested read and edit permissions. Disconnect it through account settings to revoke future access through that connection. Signing out also invalidates connected access tied to that session.
Disconnecting does not delete messages, files, or other copies already held by the provider. Use that provider’s controls or contact it to request deletion. Our statement about not training our own models does not describe an independent AI provider’s practices.
In supporting browsers, public WebMCP tools disclose product information. Signed-in browser tools can read a bounded view of your current workspace using your session; they do not bypass account permissions. A browser agent you authorize can receive the information it reads.
07
Cookies and browser storage
Authentication cookies maintain sign-in sessions and protect account flows. Security state also supports OAuth connections. Canvas preferences such as zoom and position are stored in your browser’s local storage only if you choose “Allow preferences” in the cookie popup. “Essential only” leaves this optional storage off. Your cookie choice is remembered in local storage for up to 180 days, after which we ask again. Use the “Cookie settings” button to change your choice at any time. Choosing “Essential only” removes saved canvas preferences and stops saving them; it does not remove your designs or sign you out. Blocking necessary cookies can prevent sign-in or connected-app features from working. You may clear cookies and local storage in your browser; doing so does not delete server-side projects or another provider’s copies.
We do not use advertising cookies or cross-site behavioral tracking. “Do Not Track” and Global Privacy Control signals do not change that no-sale/no-advertising-sharing practice; we do not begin such processing when a signal is absent. Necessary authentication, security, and operational processing still occurs. If we add optional tracking in the future, we will update this policy and obtain permission or honor opt-outs where required before enabling it.
08
How long information remains
| Information | Retention in the current service |
|---|---|
| Account and workspace records | Kept while your account exists so you can return to your work. Account deletion removes active account, project, asset, history, checkpoint, connection, and agreement records. Deleting an element does not necessarily remove earlier copies in history or checkpoints. |
| Temporary exports | Download access expires after 15 minutes. Expired export files are pruned at startup and on an hourly schedule during normal operation, as well as when new exports are created. Cleanup retries after an outage or failure; expired links remain unusable. |
| Authentication and abuse-prevention records | Sessions have a rolling seven-day lifetime. Verification/reset records and OAuth credentials have their own expiry times. Expired records are pruned at startup and hourly during normal operation. Rate-limit rows older than 24 hours are removed by that cleanup. |
| Transactional emails | Resend’s standard email and log retention is 30 days. These records can contain your email address and account email content. Account deletion in LayoutLark does not immediately erase provider delivery records; contact us for help with a provider-side request. |
| Infrastructure logs and residual copies | Railway manages logs and infrastructure records under its retention controls. Its published log access windows vary by plan from 3 to 90 days; those windows are not a promise of physical deletion at their end. Service deletion does not instantly erase every provider security, legal, or residual backup copy. |
| Support, privacy requests, and exceptional preservation | Kept only as needed to resolve the matter, handle a reasonable follow-up, demonstrate compliance, protect a legal claim, or meet a binding retention obligation. The nature of the issue, an active dispute, and applicable limitation or legal-retention periods determine that time. |
We do not promise user-restorable backups in the beta. If information must be retained for a specific legal or security reason after deletion, its use is limited to that reason. Ask us about a particular record or deletion request at support@layoutlark.com. Copies you export or send to an independent AI provider remain under your or that provider’s control.
09
Your choices and privacy rights
Use account settings to manage sessions, disconnect applications, and delete your account. Export design files from the workspace to keep a copy. To access other personal information, correct account details, request deletion or a portable copy, or ask us to restrict processing, email support@layoutlark.com with “Privacy request” in the subject. You can use the same route to object to processing based on legitimate interests or withdraw any consent we rely on.
Depending on your location and the law’s applicability, you may have rights of access, correction, erasure, portability, restriction, objection, consent withdrawal, and appeal of a denied request. California residents may also have rights to know categories, sources, purposes, and recipients of information, and to limit certain uses of sensitive information. We do not sell or share information for behavioral advertising. We do not penalize you for exercising a privacy right.
We may verify control of the relevant account or request proportionate information before disclosing or changing records. Do not send passwords or verification tokens. An authorized agent may submit a request, subject to appropriate proof of authority and any legally permitted verification. We will respond within the time required by applicable law, explain permitted extensions or exemptions, and provide reasons and an appeal route if we decline a request. For an appeal, reply to our response or email support with “Privacy appeal.”
You may complain to the regulator with jurisdiction where you live, work, or believe a violation occurred. This includes an EU/EEA supervisory authority, the UK Information Commissioner, or the applicable U.S. state authority. Contacting us first is optional and does not limit that right.
10
International access and processing
The Service is available internationally where lawful. Our current hosting and transactional email processing are in the United States; personnel and service providers may handle information in countries where they operate. Those countries may have different privacy laws. LayoutLark does not offer a choice of data-residency region in the beta.
Cross-border processing remains subject to applicable law. Railway and Resend publish data-processing agreements that include international-transfer provisions, including standard contractual clauses where applicable. You may contact support@layoutlark.com for information about the arrangements relevant to your data and how to obtain applicable safeguards. This notice is not a request to waive privacy rights or give blanket consent to otherwise restricted transfers.
11
Security and your responsibilities
The hosted service uses HTTPS, password hashing, verified email, access controls, per-account workspace checks, and scoped application permissions. Access and export links can still be misused if shared, and no system is completely secure. Keep credentials and download links private, review connected clients, and tell us promptly about suspected misuse. Where a security incident requires notice under applicable law, we will provide that notice.
Our design service is not intended to store highly sensitive personal information or act as a records system for regulated data. Do not use real customer or patient records to illustrate an interface. A fictional example usually serves the design purpose without exposing another person’s information.
12
Users under 18
LayoutLark is intended for people aged 16 or older. Users below the legal age of adulthood where they live need the parent or guardian permission described in the Terms of Service. We record an eligibility confirmation, not a date of birth or an independently verified age.
We do not knowingly provide accounts to children under 16. If you believe a younger child has given us personal information, or you are a parent or guardian with a question about a minor’s account, contact support@layoutlark.com. We will investigate and remove information or restrict access as appropriate, subject to applicable legal obligations.
13
Policy changes and contact
We will update the date and version when this notice changes and keep prior published versions available. For material changes, we will give appropriate notice in the service or through account communications before the new practice takes effect where required. An updated notice does not, by itself, authorize a new incompatible use of previously collected information; we will obtain any legally required consent or other valid basis.
Privacy questions, rights requests, and complaints can be addressed to Strataga, LLC at support@layoutlark.com. Please identify the account and request without including unnecessary sensitive information.