Privacy Policy
Last updated 2026-10-02
Laydyne is operated by レイラインディー, a sole-proprietor business in Japan ("we", "us"). This policy explains what we collect when you use laydyne.com and the Laydyne Studio, MCP and API (the "Service"), why we collect it, who processes it on our behalf, and the choices you have. We handle personal information in accordance with the Act on the Protection of Personal Information of Japan and other applicable law.
1. What we collect
We collect only what the Service needs to work:
- Account data. Your email address, a hashed password (never the password itself), the time you signed up and the language you chose. Email confirmation and password-reset codes are kept only until they expire.
- Session data. A session cookie that identifies your login, the time it was created, and the IP address and browser user-agent string at that time. Sessions expire after 30 days at the latest.
- Projects you save. Your working space normally stays in your browser. A cloud project that you save on a Pro plan contains the spatial model, the recent conversation and any images you added as floor-plan underlays. Saving is manual, not automatic.
- AI requests. When you use the built-in assistant or AI-assisted drafting, the conversation, the current scene and the attachment you provided are sent to the selected AI provider. We record which model was used, token counts and an estimated cost so we can apply plan limits; attachments sent only for AI processing are not stored separately by us.
- MCP relay data. Tool requests and results between your AI agent and your Studio tab pass through our servers and are held briefly for delivery. Agents that call tools inside the page (WebMCP) do not use that relay.
- Billing data. Payments are handled by Stripe. We store the Stripe customer and subscription identifiers, the plan, the billing interval, the paid period and the subscription status. We never receive or store card numbers.
- Diagnostics. Fixed error codes, counts and timestamps from our servers and from browser error reports, without message bodies, email addresses or credentials. These records are kept for a limited period, currently seven days.
- Usage analytics. On laydyne.com we use Google Analytics to count page views and a small set of product events (such as opening Studio, starting a sign-up, exporting a project or clicking Upgrade). It sends the pages you view, the event names, your browser and device type, a cookie identifier and a truncated IP address to Google LLC in the United States, for the purpose of measuring how the site is used. It is loaded only on the production site.
- Bot protection. Sign-in and sign-up forms are protected by Cloudflare Turnstile, which may process your IP address and browser signals to tell people from bots.
2. Why we use it
- To create and secure your account, deliver confirmation and reset emails and keep you signed in.
- To provide the features you ask for: building and saving spaces, running simulations, relaying MCP tool calls and answering AI requests.
- To bill Pro subscriptions, confirm paid periods and apply plan limits such as monthly AI model calls and storage.
- To keep the Service reliable and secure: detecting abuse, diagnosing failures and preventing automated attacks.
- To understand how the public site is used so we can improve it, in aggregate.
- To respond when you contact us, and to meet legal obligations.
3. Who processes it for us
We do not sell personal information. The following providers process data on our behalf, each limited to the purpose listed:
- Cloudflare, Inc. hosts the Service (Workers, D1 database, Durable Objects) and provides Turnstile bot protection. Data may be processed in Cloudflare data centres outside Japan.
- Stripe, Inc. and Link. Pro subscriptions are sold by Link, Stripe’s merchant-of-record service, which receives the details you enter at checkout as an independent controller under its own privacy policy, sends receipts and billing emails, and handles payment support. We receive only the identifiers and subscription status listed above.
- Resend, Inc. delivers sign-in, confirmation and password-reset emails.
- OpenAI and Google (Gemini) receive the content of AI requests when you use AI features. We send only what a request needs, through their business APIs. Under the API terms that apply to us as of the date above, these providers do not use API inputs to train their models and may retain them for a limited period for abuse monitoring. We do not control their terms.
- Google Analytics collects usage statistics on the public site.
- Have I Been Pwned is used to reject passwords that appear in known breaches. Only a short prefix of a hash of your password is sent, never the password.
These providers process data mainly in the United States, and Cloudflare also in other countries where it operates data centres. Those countries have different personal-data rules from Japan; we rely on each provider’s contractual commitments and security measures, and will tell you on request which safeguards apply to a given provider.
5. How long we keep it
- Account, session and cloud project data: for as long as your account exists. Expired sessions and codes are removed.
- Billing records: for as long as needed to manage your subscription and to meet accounting and tax obligations, which in Japan can be up to seven years.
- AI usage records (model, token counts and estimated cost per call; no message content): for as long as your account exists, for plan limits and cost reconciliation.
- Diagnostics: currently seven days.
- MCP relay messages: until delivered or expired, typically minutes.
6. Your choices and rights
You can export every project you own at any time from Studio. Changing or resetting your password ends every other session. To access, correct, stop the use of or delete the personal information we hold, or to delete your account, email us at the address below from your registered address; we will confirm it is you and respond without undue delay, normally within two weeks. Deleting your account removes your cloud projects and usage records. If you have an active subscription we cancel it when the account is deleted, with no refund for the remaining period. Deleted data can remain in database backups for up to 30 days. Billing records that we are required to keep are retained for the statutory period.
You may opt out of Google Analytics with browser settings or the Google opt-out extension. Blocking the session cookie prevents signing in.
7. Security
Passwords are hashed, sessions carry an absolute expiry, MCP links are tied to your login and can be revoked, and administrative access is limited to the operator. No service can promise perfect security; if we learn of a breach affecting your data we will notify you as the law requires.
8. Children
The Service is intended for professional use and is not directed to children under 16. We do not knowingly collect personal information from children.
9. Changes to this policy
We may update this policy as the Service changes. The date at the top shows the latest revision. For material changes we will post a notice on the site or email registered users before the change takes effect.
10. Contact
Questions and requests about personal information: [email protected]. Operator details are listed in the commercial transactions notice.