Privacy Policy
Layerpaint is designed to respect your data. This page explains what we collect, why, and who gets to see it.
The short version
- Your 3D models never leave your browser. All painting, welding, and export happens client-side. We can't see your STL, OBJ, 3MF, or
.layerpaintfiles. - We don't sell your data. Ever. Not to advertisers, not to AI training sets, not to anyone.
- We store only what we need to run your account and process your payment.
What we collect
- Account info — your email address and a hashed password so you can log in across devices.
- Purchase info — which product you bought and when. Payment details (card number, etc.) are handled entirely by Stripe; we never see or store them.
- Anonymous usage analytics — via PostHog, we track page views and button clicks on
layerpaint.appso we can tell if the landing page and app are working. Analytics are anonymous by default and do not contain your 3D models or paint state. - Advertising pixels — if you arrive via a Facebook/Meta ad, a pixel fires to let us know the ad worked. We don't pass your identity to Meta; we pass a conversion event.
What we don't collect
- Your 3D models. They never touch our servers.
- Your paint state, palette choices, or exported files.
- Anything from your filesystem beyond the specific files you drag into the painter — and those stay in the browser.
Who we share with
- Stripe — processes your payment. See stripe.com/privacy.
- Supabase — stores your account and purchase record. See supabase.com/privacy.
- PostHog — anonymous product analytics. See posthog.com/privacy.
- Vercel — hosts the site. See vercel.com/legal/privacy-policy.
- Meta (Facebook) — if you click through from a Meta ad, a conversion pixel fires. See Meta's privacy policy.
We do not share your email with third parties for marketing. You will only hear from us about your purchase or a major product update.
Cookies
We use a small number of essential cookies: one for your logged-in session, one to remember your preferences in the painter. PostHog and Meta may set their own cookies as described above.
Your rights
You can request a copy of what we hold on you, or ask us to delete your account and associated data, by emailing ashley.weyers@gmail.com. We will respond within 30 days.
If you're in the EU or UK, this falls under GDPR. If you're in California, CCPA applies. Both allow you to request access, correction, and deletion.
Changes
If this policy changes materially, we'll notify registered users by email before the change takes effect.
Contact
This template is a plain-language starting point. If you're taking money across borders or serving users in heavily-regulated jurisdictions, have a lawyer review it.