Laybell Privacy Policy
Last Updated: July 3, 2026
1. Introduction, Who We Are, Defined Terms & Scope
Effective Date: June 13, 2026. Last Updated: June 13, 2026. This is the operative date referenced throughout this Policy, including in Section 21 (Changes to This Privacy Policy).
This Privacy Policy explains how Laybell LLC, a Maryland limited liability company registered with the Maryland Department of Assessments and Taxation ("Laybell", "we", "us", or "our"), collects, uses, discloses, and protects personal data when you use the Laybell mobile application for iOS and Android (bundle identifier com.laybell.app), our website at laybell.app, and the related features and services we provide (together, the "Service").
Laybell is a mobile social-media and music application. It combines a social feed, short-form video (reels), 24-hour stories, slideshow posts, direct messages, comments, likes, saves, shares and reposts, follows, public and private playlists, gamified badges and points, and user-uploaded music. In this Policy, "you" or "User" means the person using the Service; "Content" or "User Content" means anything you create, upload, post, or share on the Service; and "Audio Content" means music or other audio files you upload.
Defined terms across legal regimes: In this Policy, "personal data" (the term used under the EU and UK GDPR) and "personal information" (the term used under U.S. state privacy laws) are used interchangeably and have the meaning given to them by the law that applies to you. "Process" and "processing" mean any operation performed on personal data, such as collecting, storing, using, sharing, or deleting it.
Laybell is the data controller (under European and United Kingdom law) and the "business" (under United States state privacy laws) responsible for the personal data described in this Policy. Our identity and contact details are in Sections 1 and 22.
Data Protection Officer: We have assessed our processing activities and have determined that we are not required to appoint a Data Protection Officer under Article 37 of the GDPR. We keep this assessment under review given the scale of our profiling and recommendation activities. You may direct all data-protection questions to privacy@laybell.app, and EU and UK users may also contact our Article 27 representatives identified in Section 19.
The Service is offered first in the United States but is available globally, including to individuals in the European Economic Area (EEA) and the United Kingdom (UK). Because our users come from many places, we have written this Policy to meet the strictest applicable standard. It is designed to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), other U.S. state privacy laws including the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act, the Connecticut Data Privacy Act, the Maryland Online Data Privacy Act (MODPA), and the U.S. Children's Online Privacy Protection Act (COPPA). Where a specific law gives you additional rights, the sections below explain them. The specific rights available, and any limits on them, depend on your state or country of residence; some U.S. states (for example, Utah and Iowa) provide fewer rights than others, and we honor the rights your jurisdiction's law grants you.
This Privacy Policy is incorporated into and forms part of our Terms of Service. The Terms of Service contain our binding arbitration agreement, class-action and class-arbitration waiver, jury-trial waiver, 30-day arbitration opt-out, informal dispute-resolution process, small-claims-court carve-out, Maryland governing-law and venue provisions, the limitation of liability and warranty disclaimers, the User Content license (including the "use this song" inter-user license and your representations, warranties, and indemnity for audio you upload), and the carve-out preserving the mandatory rights of EU, UK, and certain other consumers to bring claims in their home courts. Please read both documents. By creating an account or using the Service, you acknowledge the practices described here. Nothing in this Policy or our Terms removes any right you have under mandatory local consumer-protection or data-protection law.
2. A Quick Summary
We have included a short, plain-English summary for convenience. It does not replace the full Policy below, and the detailed sections control if there is any difference.
- We collect the data you give us (such as your email, username, date of birth, gender, and the Content you post) and a limited amount of data we generate as you use the Service (such as engagement metrics and an anti-fraud device identifier).
- We collect a limited amount of sensitive information, namely your account credentials, your date of birth and derived age, and your gender. We keep these private and use them only as described in this Policy.
- Location and contacts access are optional. If you enable location, we only store a coarse, low-precision area (roughly an 11-kilometer grid) plus a city name. If you enable contacts, we only send salted hashes of phone numbers and emails to find friends; we never upload your raw address book.
- Media you publish (your posts, avatar, stories, slideshows, and uploaded audio) is stored in public storage buckets and is accessible by anyone who has the link. Only upload media and audio that you own or are comfortable making public, and for which you hold all necessary rights.
- We do NOT sell your personal data. We do NOT share it for cross-context behavioral advertising with third parties. We use NO third-party advertising, analytics, or crash-reporting tools. All advertising on Laybell is first-party and self-serve.
- We do NOT use the data of users we know to be under 18 for targeted advertising or ad profiling. Minor accounts default to the most privacy-protective settings.
- Laybell Premium is an optional paid subscription. It is billed by the Apple App Store or Google Play and managed through our provider RevenueCat; Laybell never receives or stores your payment-card details. Our paid promotion features (Spotlight and Ad Manager) are currently in preview and those payments are simulated. We do not store payment-card numbers ourselves.
- You have rights over your data, including access, correction, and deletion. You can delete or hide your account in the app or contact us at privacy@laybell.app.
- The Service is for users 13 and older. It is not directed to children under 13, and we block account creation when a date of birth indicates the user is under 13.
3. Categories of Personal Data We Collect, How We Collect It, and Whether It Is Required
We collect only the categories of personal data described below. We do not collect more than this, and we do not invent uses beyond what is stated. Some data you provide directly; some is generated automatically as a necessary part of operating the Service; and some you choose to provide by enabling an optional feature. Our categories of sources are: (i) information you provide directly (for example, at sign-up and during onboarding); (ii) information generated automatically as you use the Service (for example, engagement and stream-accounting data); and (iii) information from your device, with your permission, when you enable an optional feature (for example, your device camera, photo library, document picker, coarse location, and address book).
Whether providing data is required: Some data is required to provide the Service. You must provide an email address, a username, a password, and a date of birth to create an account; without these we cannot create your account or verify that you meet our minimum age, and you will not be able to use the Service. Providing this data is a requirement of entering into our contract with you. Location, contacts access, your phone number, a gender other than "Prefer not to say," and the profile link are all optional, and declining them only disables the related features. We provide a notice at the point of collection in the app at the relevant onboarding and permission steps (for example, when we ask for your date of birth, gender, location, or contacts).
3.1 Account and Identity Information
When you create an account, we collect your email address, your chosen username (5 to 30 characters), and your display name. Your password is handled by our authentication provider, Supabase, and is stored only in a hashed (one-way encrypted) form; we never see or store your plain-text password. Account sign-up uses email and password only; we do not currently offer third-party or social sign-in (no Google, Apple, or Facebook login).
3.2 Date of Birth and Derived Age (Private)
During onboarding (the "About you" step) we require your date of birth. We use a neutral age screen that asks every user to enter their date of birth before an account is created, without indicating what age is required to register and without encouraging anyone to misstate their age. We use your date of birth to calculate your age and to enforce our minimum-age rule (you must be 13 or older). If the date of birth you enter indicates you are under 13, we block account creation and do not retain the date of birth beyond what is needed to enforce the age gate. Your date of birth and your derived age are PRIVATE; they are never displayed publicly on your profile or to other users.
3.3 Gender (Private)
During onboarding we ask you to select a gender from a preset list, which includes a "Prefer not to say" option. Your gender is PRIVATE and is never shown publicly. We use it only for personalization and, for adult users who have given the necessary consent, for first-party ad targeting (see Sections 4 and 16). We apply heightened internal safeguards to gender (we describe it in this Policy as information we treat as sensitive, meaning we limit and protect its use); Section 4.8 explains how this relates to special-category data under the GDPR and Section 14 explains how we treat it under U.S. state law.
3.4 Optional Profile Link (Public)
You may add an optional external link to your profile (for example, to another website or social profile). If you provide it, this link is PUBLIC and visible to anyone who can see your profile.
3.5 Optional Phone Number
You may optionally provide your own phone number. If you do, it is stored locally on your device (in the app's local storage, AsyncStorage) to pre-fill your profile. On our servers we store only a salted hash of your phone number, not the number itself, so it can be used for friend-matching (see Section 3.7).
3.6 Coarse Location (Optional)
Location is OPTIONAL and is off by default. If you enable it, we request foreground-only location permission through expo-location. We store only COARSE location: your latitude and longitude rounded to about one decimal place (roughly an 11-kilometer area), plus a reverse-geocoded city name. Reverse geocoding is performed on your device by your operating system; your coarse coordinates are not sent to a separate third-party geocoding service. We never store your precise position and we do not perform background or continuous tracking. Coarse location is used only to power "people near you" and related recommendations. You can disable location at any time in the app, which clears the stored area, and you can revoke the permission in your device settings. Because we collect only a coarse, low-precision area and not your precise position, this location data is not "precise geolocation" and is not "sensitive personal information" under the CCPA/CPRA.
3.7 Contacts and Friend-Matching (Optional; Includes Non-Users)
Access to your device contacts is OPTIONAL and is requested through expo-contacts only if you choose to find friends. When you do, we send only SALTED HASHES of the phone numbers and email addresses in your address book to our server in order to look for matches and suggest accounts to follow. Your RAW contacts are NEVER uploaded or stored. Matching happens through an access-controlled server function. By enabling this feature, you confirm that you have the authority to share your contacts with us for this limited purpose.
We are honest about the limits of this measure: a hash is a one-way transformation, and we use a salt to make matching harder to reverse, but phone numbers are low-entropy, so hashing with a salt is a meaningful privacy safeguard rather than absolute anonymization. You can decline or later revoke contacts access in your device settings.
Processing of non-users' data: Your address book may contain information about people who are not Laybell users. We process salted hashes of these contacts solely to find matches at the time you use the feature. Where the GDPR applies, our legal basis is our legitimate interests in operating a friend-matching feature that you have asked us to run (GDPR Article 6(1)(f)); we have carried out a balancing assessment for this processing. We discard the hashes of non-matched contacts promptly after matching and do not retain them; we do not build profiles of non-users, do not send them invitations or marketing, and do not use these hashes for advertising. Any individual whose information may have been processed this way can contact us at privacy@laybell.app to object or request deletion.
3.8 Device Identifier (Anti-Fraud)
We generate a per-install device identifier (a UUID) that is stored locally on your device. It is not cryptographic, and it resets if you reinstall the app. We use it only as a friction and abuse-prevention signal, primarily to cap stream credits and prevent farming or other abuse of the Service. It is not a reliable unique-person identifier and is not used for advertising.
3.9 Push Notification Token
If you enable notifications, we collect and store an Expo push notification token together with your device platform (iOS or Android) on our servers. Push notifications are delivered to your device through Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM). We use this token solely to deliver push notifications such as likes, comments, follows, and messages. You control these through per-category toggles in the app and through your device's operating-system settings.
3.10 Camera, Microphone, and Photo Library
To create posts, stories, reels, slideshows, and ad creatives, and to pick audio files, the app uses camera and photo-library access through expo-camera and the device image picker, and a document picker to select pre-existing audio files. When you record a video within the app, the microphone is used to capture the audio that is part of that video, and that audio becomes part of your User Content. There is NO always-on or ambient microphone recording, and we do not record audio in the background. Separately uploaded Audio Content (audio posts) is not recorded by us; it consists of pre-existing audio files that you choose and upload through the document picker.
3.11 User Content and Activity
We collect and store the Content and activity you generate on the Service, which may include: posts, 24-hour stories, reels, slideshows, comments, likes, saves, shares and reposts, follows, direct messages (including message bodies, shared post links, and read status), public and private playlists, uploaded Audio Content, badges and points, ad and Spotlight campaigns, and song attributions. When another user uses your audio via the "use this song" feature, we store two distinct things: (i) the Audio Content file itself, which is served from public storage as described in Section 5; and (ii) attribution metadata (the song id, title, and artist) that links the re-use back to you. The audio file is the rights-bearing material you must own; the attribution metadata is the link that gives you credit.
3.12 First-Party Engagement Analytics
We track engagement using FIRST-PARTY tools only. This includes likes, comments, saves, shares, views, streams, follower growth, and peak engagement times, which we use to power creator analytics dashboards. We do not use Google Analytics, Firebase Analytics, Mixpanel, Amplitude, Sentry, the Meta SDK, or any other third-party analytics, advertising, or crash-reporting tool.
3.13 Stream Accounting Data
To count plays fairly and prevent fraud, your listening progress is stored locally on your device (in AsyncStorage) and validated on our servers. Roughly 30 seconds of genuine forward listening counts as one "stream" credit, capped at about three credits per 24 hours per post per device. Ambient or attached-song listens are counted separately. We use the device identifier described in Section 3.8 to apply these caps. Stream counts are engagement metrics only and have no monetary value; we explain in Section 17 that we currently pay no royalties or other compensation for streams or for use of your audio.
3.14 Advertising and Spotlight Data
If you use our paid promotion features, we collect campaign settings (such as objective, placements, schedule, total and daily budget, and CPM bid), your ad creative content and call-to-action URLs, your advertiser or business name and business flag, the timestamp on which you accepted our advertising policy, and transaction records. Because payments are currently simulated and in preview, those transaction records are recorded with a provider value of "simulated" and a status, and we do not collect or store payment-card numbers or banking details during preview. When you view or interact with an ad or Spotlighted post, we log that event (impression, click, skip, or completion) to measure campaigns, bill them when billing goes live, and prevent fraud.
3.15 IP Address (Security and Legal Evidence Only)
For a limited set of security-relevant actions — uploading media, submitting a report about content or another user, and downloading a file you purchased in the Shop — our servers record the IP address the request came from, together with the time and your device’s browser/app user-agent string. Your app does not send us this address; it is read from the network request itself, because a value supplied by a device cannot be relied upon as evidence.
We use this data for three purposes only: to respond to reports of illegal content, including reports we are legally required to make to the National Center for Missing & Exploited Children; to investigate fraud and abuse; and to respond to payment disputes about purchases you made. We do NOT use IP addresses for advertising, tracking, profiling, or analytics, and we do not record them for ordinary browsing, listening, or messaging.
We retain these records for 13 months and then delete them, except where a specific record must be preserved longer because it relates to an open investigation or a legal obligation. You can request a copy of the IP records associated with your own account at any time using the contact details in this policy.
4. How and Why We Use Your Data (and Legal Bases)
We use personal data only for the purposes below. For users protected by the GDPR or UK GDPR, we have identified the legal basis for each purpose. Where we rely on legitimate interests, we have performed and documented a Legitimate Interests Assessment (a balancing test) for that processing, a summary of which is available on request at privacy@laybell.app. Where we rely on consent, you may withdraw it at any time, as easily as you gave it, without affecting processing that already took place.
4.1 To Provide and Operate the Core Service
We use your account information and User Content to create and maintain your account, host and display the Content you choose to post, deliver and store your direct messages, and provide the core features you have asked for (your feed of accounts you follow, your playlists, your profile, and your interactions with other users). Legal basis: performance of our contract with you (GDPR Article 6(1)(b)). We rely on this basis only for what is genuinely necessary to deliver the core Service you requested.
4.2 For Recommendations, Ranking, and Profiling
To make the Service useful, we use your activity and genre affinity, and, if you have enabled them, coarse location and contacts, to power recommendations such as the ranked feed, explore genre clusters, "people near you," and suggested accounts, and to build first-party engagement profiles. Legal basis: our legitimate interests in providing a relevant and engaging social experience and surfacing content and accounts likely to interest you (GDPR Article 6(1)(f)). We have performed a balancing assessment for this profiling, and you have the right to object to it at any time under Article 21 (see Section 13). Where a feature depends on optional location or contacts access, that access is based on your consent (Article 6(1)(a)) given through the in-app or operating-system permission prompt.
4.3 To Enforce Our Minimum-Age Rule and Comply with Law
We use your date of birth and derived age to enforce the 13+ requirement and to comply with COPPA and other legal obligations, and we use data as needed to respond to legal requests and copyright (DMCA) notices and counter-notices. Legal basis: compliance with a legal obligation and our legitimate interests in lawful operation (GDPR Articles 6(1)(c) and 6(1)(f)).
4.4 For Security, Anti-Fraud, and Stream Integrity
We use the device identifier, stream-accounting data, and activity logs to detect and prevent fraud, fake engagement, stream farming, abuse, and circumvention of our anti-fraud systems, and to keep the Service secure. We also use automated and manual measures to detect prohibited content, including child sexual abuse material. Legal basis: our legitimate interests in protecting the Service and our users, and compliance with a legal obligation where applicable (GDPR Articles 6(1)(f) and 6(1)(c)).
4.5 For Push Notifications
We use your push token to send notifications you have enabled. Legal basis: your consent (GDPR Article 6(1)(a)), withdrawable through in-app toggles and device settings. Withdrawal is as easy as enabling it and we will not treat continued use of the Service as consent to notifications.
4.6 For Ad Personalization and Targeting (Adults Only)
For users we know to be 18 or older, we may use age range, gender, genre affinity, and location radius to personalize first-party ads and Spotlight promotions. In the EEA, UK, and Switzerland, personalized advertising is OFF by default and is enabled only if you give specific, affirmative opt-in consent; if you do not, you receive only non-personalized or house ads. Outside the EEA, UK, and Switzerland, ad personalization for adults is on by default and you may turn it off using the in-app "Limit ad targeting" control. When you limit ad targeting, the change applies account-wide and server-side, so it stops the use of your profile and affinity signals for targeting across all of your sessions and devices, and we serve only non-targeted or house ads. We never use gender for ad targeting without the consent required in your jurisdiction. We do NOT use the data of users we know to be under 18 for ad personalization, targeted advertising, or ad profiling. Legal basis: consent for ad personalization (GDPR Article 6(1)(a)); measurement of ad delivery relies on our legitimate interests (GDPR Article 6(1)(f)).
4.7 For Creator Analytics
We use first-party engagement data to build creator analytics dashboards for you. Legal basis: our legitimate interests in helping creators understand their audience (GDPR Article 6(1)(f)), for which we have performed a balancing assessment.
4.8 A Note on Sensitive and Special-Category Data
We do not seek to collect special-category data under GDPR Article 9 (such as data revealing racial or ethnic origin, religious beliefs, health, or sexual orientation), and we do not use your data to infer special categories about you. We collect gender from a preset list (including "Prefer not to say") and treat it with heightened safeguards: we keep it private, never show it publicly, and use it for ad targeting only where you have given the consent your jurisdiction requires. Where local law would treat gender or any inferred data as special-category data, we will not process it for that purpose without your explicit consent under Article 9(2)(a). We do not collect precise geolocation, and we do not derive biometric identifiers from your voice or images or run any facial- or voice-recognition systems; we do not collect or process biometric identifiers within the meaning of applicable state biometric-privacy laws.
5. Public-by-Default Content, Profiles, and Public Storage Buckets
Laybell is a social platform, so some information is public by design. We want you to understand clearly what is visible to others before you post.
PUBLIC information includes your username, display name, avatar, bio, your optional profile link, and the media and Content you publish (posts, reels, stories, slideshows, public playlists, and the Audio Content you upload). Other users, and in many cases the general public, can see this Content.
PRIVATE information includes your date of birth and derived age, your gender, your phone number, your email address, your direct messages, your private playlists, and your coarse location coordinates. We do not display these publicly.
IMPORTANT - public storage buckets: Media you publish to posts, avatars, stories, and slideshows, and the Audio Content (audio posts) you upload, are stored in PUBLIC storage buckets operated by our hosting provider, Supabase. This means the underlying files (including image, video, and audio files) are accessible as files by URL to anyone who has the link, even without logging in, and may be cached by us, by Supabase, or by content-delivery networks. As a result, copies may persist for a period after you delete Content in the app or after a 24-hour story expires, and copies may remain if other users have re-shared your Content or attached your Audio Content to their own posts using the "use this song" feature (see Section 9). Because of this design, you should only upload media and Audio Content that you are comfortable making public and for which you own or control all necessary rights. We describe the technical and organizational measures and improvements relating to these buckets in Section 18, and we apply additional protections to the media of users we know to be minors as described in Section 12.
6. Direct Messages and Inter-User Content
Direct messages on Laybell (including message bodies, shared post links, and read status) are stored on our systems through Supabase. They are accessible to the participants in the conversation. They are NOT end-to-end encrypted.
We access message content only where strictly necessary and proportionate. We do not generally monitor private messages, and we access them only in response to specific reports, valid legal requests, or detected abuse, or where we are required to do so by law. Where the GDPR applies, our legal basis is our legitimate interests in safety and in enforcing our Terms (Article 6(1)(f)) or compliance with a legal obligation (Article 6(1)(c)). We may also use automated and manual measures to detect prohibited content, including child sexual abuse material, in content and, where necessary for safety or legal compliance, in messages; we report apparent child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC) as described in Section 7. Remember that anyone you message can screenshot, copy, or retain your messages outside our control.
Translation of messages: If you choose to translate a message using the in-app translation feature, the text of only that specific message is sent to our machine-translation subprocessor (see Section 7) solely to generate the translation. This is optional, happens only for the message you tap to translate, and does not otherwise change the private, participant-only nature of your direct messages.
7. How We Share and Disclose Data; Our Subprocessors
We keep our list of third parties short and closed. We share personal data only as described below, and we maintain data-processing agreements (including the Standard Contractual Clauses where required) with our processors.
7.1 Subprocessors and Service Providers
Supabase, Expo, Apple, and Google act as our service providers, contractors, and/or processors. Where the CCPA applies, Supabase and Expo are our service providers or contractors and are contractually restricted to processing personal data only for the business purposes we specify. Apple and Google may act as independent third parties for some functions (such as app distribution, push-notification delivery, and future billing) under their own privacy policies. In addition, a machine-translation provider (currently Google Cloud Translation) processes only the specific text you choose to translate, and Giphy acts as an independent third party that powers GIF search under its own privacy policy.
- Supabase, Inc. - our primary processor. Supabase provides authentication (including hashed-password storage), our Postgres database, file storage, and serverless RPC/edge functions. Media for posts, avatars, stories, and slideshows, and uploaded Audio Content, is stored in PUBLIC storage buckets and is accessible by URL, as explained in Section 5. Supabase relies on underlying cloud-infrastructure subprocessors to host its services; we maintain, and make available on request at privacy@laybell.app, a current list of subprocessors and the hosting region(s) in which your data is stored.
- Expo, with push delivery via Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM) - used solely to deliver push notifications to your device. Expo, Apple (APNs), and Google (FCM) are recipients of your push token and notification payload for this purpose; see Section 8 for the transfer mechanism that applies to them.
- Apple App Store and Google Play - used for app distribution and for in-app-purchase billing. When you purchase Laybell Premium, Apple or Google processes the transaction and is the recipient of the payment information you provide to them; Laybell receives confirmation of your subscription status but not your payment-card details. For Spotlight and Ad Manager, which remain in preview with simulated payments, no payment processor receives data today, and if and when real billing launches for those features we will add the relevant processor(s) (for example, a card processor) to this list and update this Policy before charging you.
- RevenueCat, Inc. - used to manage and validate Laybell Premium subscriptions across the Apple App Store and Google Play. RevenueCat receives a per-user identifier and your subscription, entitlement, and purchase-event data (such as the product purchased, status, and renewal or expiry), processed in the United States, so that we can grant and verify Premium benefits and keep your status in sync across your devices; it does not receive your payment-card details.
- Machine-translation provider (currently Google Cloud Translation, operated by Google LLC) - when you use the in-app translation feature to translate another user's comment, message, caption, or profile text into your language, the text of only that specific item is sent through our servers to a machine-translation provider to generate the translation and, where available, detect its source language. We currently use Google Cloud Translation, which processes the submitted text solely to return the translation; we do not send your account identity, your other content, or your conversation history. Translation is optional and runs only for the item you choose to translate. If we change translation providers, we will update this list.
- Giphy, Inc. - powers the GIF search and trending GIFs in our GIF picker. When you open the GIF picker and search, your search terms and the network request metadata Giphy needs to respond (including your IP address) are sent directly to Giphy, which returns matching GIFs and hosts them from its own servers under its own privacy policy. We do not send Giphy your identity, your messages, or your other content. GIFs you have saved or created within Laybell ("My GIFs") are stored by Supabase, not Giphy.
7.2 Advertiser Reporting
When you view or interact with an ad or Spotlighted post, the advertiser receives only aggregate, de-identified metrics computed on our servers (such as impressions, unique reach, clicks, and completions). Advertisers never receive your identity, contact details, profile, or user-level event data. We maintain any de-identified data in a form that cannot reasonably be linked to you, do not attempt to re-identify it, and contractually require the same of recipients. This holds when real billing launches.
7.3 Other Disclosures
We may disclose data to comply with law, legal process, or valid government requests; to enforce our Terms; to protect the rights, safety, and security of Laybell, our users, or the public; and, in connection with a merger, acquisition, financing, or sale of assets, to a successor entity (in which case we will continue to protect your data consistent with this Policy). In line with U.S. law (18 U.S.C. 2258A), we report apparent child sexual abuse material to NCMEC, which may include providing related data to NCMEC and law enforcement.
7.4 Our Host / Non-Publisher Status
Laybell hosts content created by its users. Under 47 U.S.C. 230 and 17 U.S.C. 512, Laybell acts as an interactive computer service provider and host; we are not the author or publisher of User Content or Audio Content uploaded by users, and we respond to copyright infringement claims under the DMCA process described in Section 20 and in our Terms of Service.
7.5 What We Do NOT Do
We do NOT sell your personal data. We do NOT share it for cross-context behavioral advertising. We do NOT use advertising networks or data brokers, and we use NO third-party advertising, analytics, or crash-reporting tools (no Google Analytics, Firebase Analytics, Mixpanel, Amplitude, Sentry, or Meta SDK). All advertising on the Service is first-party and self-serve.
8. International Data Transfers
We are based in the United States, and your personal data is processed in the United States and potentially in other countries where we or our processors operate. Our primary processor, Supabase, Inc., hosts our database and storage in the United States; we will identify the specific hosting region in our subprocessor list, available on request at privacy@laybell.app. Push tokens and notification payloads are processed by Expo, Apple (APNs), and Google (FCM), which may process this data in the United States and other countries. If you purchase Laybell Premium, your transaction is processed by Apple or Google, and your subscription is managed by RevenueCat, Inc., which process the related data in the United States. If you are located in the EEA, the UK, or Switzerland, transferring your data to the United States means it goes to a country whose data-protection laws may differ from your own.
For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on appropriate safeguards. For Supabase, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum for UK transfers), supplemented by technical and organizational measures such as encryption in transit, access controls, and data minimization, and/or the EU-U.S. Data Privacy Framework and its UK extension where the processor is certified. For Expo, Apple (APNs), and Google (FCM), we rely on the Standard Contractual Clauses, the UK Addendum, and/or those providers' Data Privacy Framework certifications where applicable. You may request more information about the safeguards we use, and a copy of the relevant clauses where available, by contacting privacy@laybell.app.
9. Data Retention and Deletion
We keep personal data only for as long as needed for the purposes described in this Policy, to comply with our legal obligations, to resolve disputes, and to prevent fraud and abuse. The retention periods or criteria for each category are below. References to a number of days or months reflect our standard practice and may be adjusted to meet legal or security requirements.
- Account data (identifiers, profile fields, and your User Content): retained while your account is active, and deleted or de-identified within approximately 30 days after you delete your account, subject to the legal-hold and fraud-prevention exceptions below.
- 24-hour stories: auto-expire after 24 hours; underlying storage objects are removed and only transient cache or backup copies may persist temporarily as described below.
- Salted contact hashes: hashes of non-matched contacts are discarded promptly after matching; any retained matched results are deleted when you revoke contacts access or delete your account, and in any event within approximately 30 days of revocation.
- Device identifier: stored per-install on your device and reset on reinstall; not retained server-side beyond what is needed for the anti-fraud caps it supports.
- Push tokens: retained until you disable notifications or the token becomes invalid, and then deleted.
- Stream-accounting records and ad-event logs: retained for approximately 12 months for fraud detection, measurement, and security, then deleted or de-identified.
- Campaign and transaction records (including simulated-payment records): retained for approximately the period required for tax, accounting, and legal recordkeeping (generally several years where required by law), then deleted or de-identified.
- Copyright and DMCA records: records of copyright infringement notices, counter-notifications, and repeat-infringer strikes associated with an account are retained for as long as needed to operate our DMCA repeat-infringer policy and preserve our legal protections, even after the related content or account is deleted.
- Sensitive information (account credentials, date of birth and derived age, and gender): retained while your account is active and deleted upon account deletion, subject to legal-hold exceptions.
- Backups: routine backups purge on a rolling cycle of approximately 30 to 90 days; deletion requests propagate to backups within that cycle.
- An account that has been hidden and remains inactive for about three months may be deleted.
- We delete the data of users we discover to be under 13 promptly and without undue delay (see Section 11).
- Safety and moderation records: when you or another user reports content or an account, or where we otherwise detect a violation, we retain the report and a snapshot of the reported content together with related metadata (for example, the author and timestamps) even after the underlying post, content, or account is deleted. We keep these records for as long as reasonably necessary to review and act on the report, enforce our Terms of Service and Community Guidelines, keep the Service and our users safe, cooperate with law enforcement and report apparent child sexual abuse material to NCMEC as described in Sections 6 and 7, and establish, exercise, or defend legal claims. Content or accounts placed under a legal hold (for example, because of an active investigation, a preservation request, or anticipated litigation) are preserved and cannot be removed through the in-app deletion tools until the hold is lifted.
Deletion of public-bucket media: When you delete Content or your account, we delete or make inaccessible the underlying storage objects in our public buckets (not just the in-app reference) within approximately 30 days, and we purge cached copies on the rolling cycle described above. Some limits apply: copies of public-bucket media may persist temporarily in caches, content-delivery networks, and routine backups until they purge; we may retain certain records where genuinely necessary for an enumerated legal exception, for legal holds, or to prevent fraud and abuse; and aggregate or de-identified data may be kept longer. Audio Content that other users have attached to their own posts via the "use this song" feature, and Content that other users have independently re-shared, may remain on the Service after you delete the original, as described in Section 5 and consistent with the license in our Terms of Service; this persistence is limited to the audio file or content as embedded in others' posts and does not extend to your account data. On a verified deletion request, we will de-link such copies from your identity where reasonably possible and, where your Content was made public, take reasonable steps under GDPR Article 17(2) to inform other controllers who hold copies. A contractual license does not override a statutory deletion right; we honor the statutory exceptions, not a blanket license carve-out.
10. Security and Data Breaches
We use reasonable technical and organizational measures to protect personal data. These include authentication managed by Supabase with hashed passwords, encryption of data in transit (TLS), access controls and row-level security in our database, salted hashing for contact matching, server-side access controls that limit bulk access to hashes, and anti-fraud measures such as device-based caps with server-side validation.
Data protection by design and by default (GDPR Articles 25 and 32): We design the Service to protect personal data. Private fields (date of birth, age, gender, phone number, email, direct messages, and coarse location) are access-controlled and never exposed publicly. For media, content that you affirmatively choose to publish to the world is served from public storage buckets, while we are moving avatars and the media of users we know to be minors to access-controlled storage served via short-lived signed URLs, and we are evaluating signed and expiring URLs for additional media categories. We provide clear notice before you upload, but we do not rely on that notice alone to satisfy our obligations; we apply the technical measures described here.
We are honest about the limits of security: no method of transmission or storage is 100% secure, and you are responsible for keeping your password confidential. As explained in Section 5, media you publish to our public storage buckets is intentionally public and accessible by URL, and the contact-hash salt is a privacy safeguard rather than absolute anonymization.
If a personal-data breach occurs, we will notify the competent supervisory authority within 72 hours of becoming aware of it where required by GDPR Article 33, and we will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms under Article 34. We will also comply with applicable U.S. state breach-notification laws; for Maryland residents, under the Maryland Personal Information Protection Act we will notify affected individuals as soon as reasonably practicable and within the timeframe the Act requires (generally no later than 45 days after discovery), with notice to the Maryland Attorney General as required. We will typically notify you by email and/or in-app message.
11. Children's Privacy
The Service is intended for users who are at least 13 years old. It is NOT directed to and not intended for children under 13. We do not knowingly collect personal data from children under 13.
We use a neutral age screen that asks every user to enter their date of birth before an account is created, without indicating what age is required to register and without encouraging anyone to misstate their age. If the date of birth entered indicates the user is under 13, we block account creation and do not retain the date of birth beyond what is needed to enforce the age gate. If we otherwise learn that we have collected personal data from a child under 13, we will delete that data promptly and without undue delay and terminate the associated account, and we will do so without conditioning deletion on contacting the child.
Users between 13 and 17 must have permission from, and use the Service under the supervision of, a parent or legal guardian, and we obtain a parental-permission acknowledgment at onboarding for these users. Accounts of users we know to be 13 to 17 default to the most privacy-protective settings: location and contacts access are off and not promoted, ad personalization and ad profiling are turned off and not available, and we do not use their age, gender, genre affinity, or location for targeted advertising or profiling. Such users receive only non-targeted or contextual ads.
In the EEA and UK, the digital age of consent varies by country (generally between 13 and 16). For users in the EEA and UK who are below the applicable digital age of consent in their country, we do not rely on the child's own consent for consent-based processing; instead, we set the floor for consent-based features (such as ad personalization, optional location, and optional contacts) to the applicable local digital-consent age, and we obtain verifiable parental consent through a parent-email confirmation step before enabling any consent-based processing for those users, or we restrict those features. A parent or guardian who believes a child has provided us with personal data, or who wishes to review or request deletion of a child's data, may contact us at privacy@laybell.app. California residents who are registered minors have the right to request removal of Content they posted; see Section 14.
12. Minors and Heightened Protections (All Jurisdictions)
In addition to the children's-privacy rules in Section 11, we apply heightened, privacy-protective defaults to every account we know to be held by a user under 18 (i.e., a user whose date of birth indicates they are 13 to 17), wherever they are located:
- We do not use the personal data of users we know to be under 18 for targeted advertising, ad personalization, or profiling for ads. These users receive only non-targeted or contextual ads.
- Optional location and optional contacts access are off by default and are not promoted to minor accounts; "people near you" location features are disabled or restricted for minors.
- We do not sell the personal data of any user, and we do not process the sensitive data of users we know to be under 18 beyond what is strictly necessary to provide the Service.
- For users we know to be under 18, we are rolling out additional storage protections for their media — moving from open public-bucket URLs toward access-controlled storage served via short-lived signed URLs (see Section 10). Until that rollout is complete, media a minor publishes is stored as described in Section 5, and when content or an account is deleted we promptly remove the underlying files from storage.
These protections are designed to meet the minor-protection requirements of the Maryland Online Data Privacy Act and similar laws in Colorado, Connecticut, and other states, as well as COPPA-adjacent expectations, and they apply as defaults rather than only on request.
13. Your GDPR and UK GDPR Rights
If you are in the EEA, the UK, or Switzerland, you have the following rights regarding your personal data, subject to legal conditions and exceptions:
- Access - to obtain confirmation of, and a copy of, the personal data we hold about you.
- Rectification - to have inaccurate or incomplete data corrected.
- Erasure - to have your data deleted in certain circumstances (the "right to be forgotten"), subject to the retention limits and exceptions in Section 9.
- Restriction - to limit how we process your data in certain situations.
- Portability - to receive certain data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
- Objection - to object to processing based on our legitimate interests, including the profiling described in Section 4.2, and to object to direct marketing at any time.
- Withdraw consent - to withdraw consent at any time where we rely on it (for example, location, contacts, push notifications, and ad personalization), as easily as you gave it.
- Lodge a complaint - to complain to your local supervisory authority (for UK users, the Information Commissioner's Office).
Automated decision-making and profiling: We use algorithms to rank and recommend content (for example, the feed, explore genre clusters, people-near-you, and suggested accounts) and to target first-party ads for adult users using age range, gender, genre affinity, and location. Although we do not make solely-automated decisions that produce legal effects or similarly significant effects on you, we do provide meaningful information about this profiling: the logic broadly uses signals such as your activity (likes, follows, listens, and comments) and genre affinity and, if you have enabled them, coarse location and contacts, to predict what content and accounts are likely to be relevant to you. The main consequence is the order and selection of the content, recommendations, and ads you see. You can object to this profiling under Article 21 and can limit ad personalization using the "Limit ad targeting" control (account-wide and server-side) or by withholding consent in the EEA, UK, and Switzerland.
To exercise your rights, email privacy@laybell.app or use the in-app account deletion and hiding tools. We respond to GDPR and UK GDPR requests within one month, extendable by up to two further months for complex or numerous requests, in which case we will inform you within one month of the reasons. Requests are free of charge unless they are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse the request, and we will tell you why and how to complain or seek a judicial remedy. We may need to verify your identity before acting on a request; we will match your request to your existing account data (for example, by requiring it to come from your account email or to be made while signed in) and will not ask for additional sensitive identification unless reasonably necessary.
14. Your U.S. State Privacy Rights (California and Other States)
If you are a resident of California, Virginia, Colorado, Connecticut, Maryland, or another U.S. state with a comprehensive privacy law (such as Texas, Oregon, Montana, Delaware, Iowa, New Jersey, New Hampshire, Tennessee, Minnesota, Nebraska, Indiana, and Utah), you have rights regarding your personal data. The specific rights and how they apply depend on your state of residence; some states (for example, Utah and Iowa) do not provide all of the rights listed below, and we honor the rights your state's law grants you.
14.1 Rights Available to You
- Right to know and access - to learn what personal information we collect, use, and disclose, and to obtain a copy.
- Right to delete - to request deletion of personal information we collected from you, subject to legal exceptions.
- Right to correct - to request correction of inaccurate personal information.
- Right to data portability - to obtain your data in a portable format.
- Right to opt out of sale, sharing, targeted advertising, and profiling - see Sections 14.3 and 14.4.
- Right to limit the use of sensitive personal information - see Section 14.5.
- Right to non-discrimination - we will not discriminate against you for exercising your rights.
- Right to appeal - in Virginia, Colorado, Connecticut, Maryland, and similar states, you may appeal our decision on your request; see Section 14.6.
14.2 Categories of Personal Information Collected, Sources, Purposes, and Recipients
Since the Service launched and in the 12 months preceding the Last Updated date, we have collected the categories described in Section 3, which under the CCPA/CPRA map to: identifiers (email, username, display name, salted contact hashes, push token, device identifier); protected classification characteristics under California or federal law (age and gender); sensitive personal information (account log-in credentials, and we additionally treat date of birth/derived age and gender with heightened protection as described in Section 14.5); commercial information (campaign settings and simulated-transaction records); internet or other electronic network activity (engagement and stream-accounting data and ad-event logs); approximate (coarse) geolocation, if you enabled it; audio, electronic, and visual information (the Audio Content, video, images, and other media you upload); and inferences drawn for personalization and recommendations.
Sources: we collect this data (i) directly from you, (ii) automatically as you use the Service, and (iii) from your device address book (salted contact hashes only) if you enable contacts. Purposes: we collect it for the business and commercial purposes described in Section 4. Recipients: we disclose each category only to the processors named in Section 7 (Supabase for authentication, database, and storage; Expo, Apple/APNs, and Google/FCM for push; and Apple/Google for distribution and future billing), for the legal and safety purposes in Section 7.3, and to NCMEC for child-safety reporting; advertisers receive only aggregate, de-identified metrics as described in Section 7.2. Media you publish is also made available to the public by URL from our public storage buckets, as described in Section 5. We have not sold or shared personal information for cross-context behavioral advertising. We retain each category for the periods or per the criteria in Section 9.
14.3 No Sale, No Sharing
We do NOT sell your personal information and we do NOT share it for cross-context behavioral advertising as those terms are defined under California and other state privacy laws. We use no third-party ad networks or data brokers.
14.4 Targeted Advertising and Profiling Opt-Out
Our first-party ad personalization uses your profile data (age range, gender, genre affinity, and location radius) to decide which ads to show adult users. Several state laws treat this as targeted advertising or profiling for which you have an opt-out, even though it is first-party. You may opt out at any time using the in-app "Limit ad targeting" control, which applies account-wide and server-side immediately. We do not engage in solely-automated decisions that produce legal or similarly significant effects. We do not use the data of users we know to be under 18 for targeted advertising or profiling. Where required by law, we honor the Global Privacy Control (GPC) and other recognized opt-out preference signals; see Section 15 for how this works on our website versus in the app.
14.5 Sensitive Personal Information
We collect a limited amount of sensitive personal information, namely account log-in credentials, and we additionally treat your date of birth/derived age and your gender with heightened protection. We do not collect precise geolocation (our coarse location is not sensitive personal information under the CCPA). We use this information only as reasonably necessary to provide the Service and for the purposes described in this Policy, and not to infer characteristics about you beyond those purposes. To exercise your right to limit the use and disclosure of sensitive personal information, email privacy@laybell.app. In addition, the "Limit ad targeting" control stops the use of gender and age range for ad personalization across your account.
14.6 How to Exercise State Rights, Request Methods, Verification, Agents, and Appeals
We provide the following methods to submit requests: (1) email privacy@laybell.app and (2) the in-app account tools (including account deletion and hiding). We will confirm receipt of a request within 10 business days where required and will respond within 45 days (for California, Virginia, Colorado, Connecticut, and Maryland), extendable once by an additional 45 days (or 60 days where the law allows) with notice to you. For opt-out requests, we will act within 15 business days. There is no charge to exercise your rights, though we may charge a reasonable fee or decline a request that is manifestly unfounded or excessive, as the law allows; you may make a free access request up to twice in a 12-month period.
Verification: we will verify your identity before responding by matching your request to your existing account data (for example, requiring it to come from your account email or to be made while signed in), and we will not require additional sensitive identification unless reasonably necessary. Authorized agents: you may use an authorized agent to submit a request on your behalf; the agent must provide your signed permission or a valid power of attorney, and we may still ask you to verify your identity directly.
Appeals: if we deny your request, you may appeal by replying to our decision or emailing privacy@laybell.app. We will respond to appeals within 60 days (45 days for California-style requests where applicable). If we deny your appeal, we will provide you a method or link to submit a complaint to your state Attorney General (for example, your state Attorney General's online complaint form).
14.7 Maryland Online Data Privacy Act (MODPA)
For Maryland residents, and consistent with the Maryland Online Data Privacy Act: we limit our collection of personal data to what is reasonably necessary and proportionate to provide the Service (data minimization); we do not sell sensitive data; we do not process sensitive data beyond what is strictly necessary to provide the Service or otherwise without your consent; and we do not process the sensitive data of, sell the personal data of, or engage in targeted advertising toward, any consumer we know to be under 18. Accordingly, we do not use the age, gender, genre affinity, location, or other profile data of users we know to be under 18 for ad targeting or profiling.
14.8 California "Shine the Light" and Minors
California's "Shine the Light" law (Cal. Civ. Code 1798.83) lets California residents request information about disclosures of personal information to third parties for those third parties' direct marketing. We do not disclose personal information to third parties for their own direct marketing. California residents who are registered minors may request removal of Content they posted to the Service by contacting privacy@laybell.app or using in-app deletion tools; note that removal may not be complete where copies have been re-shared by others or persist temporarily in caches or backups, as described in Sections 5 and 9.
15. Cookies, SDKs, On-Device Storage, and Opt-Out Signals
Laybell is primarily a mobile app and does not use third-party advertising or analytics cookies, and it does not perform cross-app or cross-site tracking. We use NO third-party advertising, analytics, or crash-reporting SDKs.
We do use first-party on-device storage technologies needed for the app to work and to keep it secure, including: the app's local storage (AsyncStorage), where we keep items such as your own phone number for profile pre-fill, your listening progress for stream accounting, and any local drafts; the per-install device identifier used for abuse prevention and stream-credit caps; and the Expo push token. These are first-party and used for functionality and security, not advertising. You can reset the device identifier by reinstalling the app and can disable push by revoking the permission in your device settings.
Do-Not-Track and Global Privacy Control: On our website at laybell.app, we treat the Global Privacy Control (GPC) as a valid opt-out of any sale, sharing, or targeted advertising where required by law, and our website does not track you across third-party sites and does not respond to Do-Not-Track signals because we do not perform such tracking. Within the mobile app, GPC is a browser signal that cannot be transmitted; you exercise the equivalent opt-out through the in-app "Limit ad targeting" control, which applies account-wide and server-side. Because we do not sell or share personal data and do not track you across other apps or websites, there is little for these signals to control beyond ad personalization.
16. Advertising, Spotlight, Premium Subscriptions, and Payments
All advertising on Laybell is first-party and self-serve. Our two paid promotion features are Spotlight (paid promotion that ranks an existing post higher in the feed, in packages of roughly 1, 3, or 7 days) and Ad Manager (self-serve campaigns with a budget and CPM bid, placed in the feed, reels, and audio breaks). First-party ad targeting for adult users may use age range, gender, genre affinity, and location radius. You can limit this using the in-app "Limit ad targeting" control, which applies account-wide and server-side, after which only non-targeted or house ads are served. In the EEA, UK, and Switzerland, ad personalization is off by default and runs only with your opt-in consent. We do not use the data of users we know to be under 18 for ad targeting or profiling.
Laybell Premium Subscription
Laybell Premium is an optional, paid auto-renewing subscription. Billing is handled entirely by the Apple App Store or Google Play and is managed through our provider RevenueCat, Inc.; Laybell never receives or stores your payment-card number or banking details. To provide and verify Premium, we process a per-user identifier and your subscription and entitlement data (for example, the product you purchased, purchase and renewal or expiry dates, and active status), which RevenueCat receives and processes in the United States, and we store your subscription expiry on our servers so that your benefits and a supporter badge stay in sync across your devices. Apple or Google, as the seller of record, handles receipts, billing support, refunds, and any payment information you provide to them under their own terms; you can manage or cancel your subscription in your Apple App Store or Google Play account settings. We use this data only to provide, restore, and verify Premium and to prevent fraud and abuse, and never for advertising or ad profiling.
Both features are CURRENTLY IN PREVIEW, and all payments are SIMULATED. No real money is charged today; transaction records are recorded with the provider value "simulated" and a status. During preview we do not collect or store payment-card numbers or banking details. If you view or interact with ads or Spotlighted posts, the advertiser receives only aggregate, de-identified metrics (such as impressions, unique reach, clicks, and completions); advertisers do not receive your identity, contact details, or profile.
When real billing launches, purchases of in-app digital promotions (Spotlight and Ad Manager) made inside the iOS and Android apps will be processed through Apple in-app purchase and Google Play billing as required by those platforms' rules; any out-of-app or web purchases, where platform rules permit, may be processed by a card processor. Payment processors will handle and store payment data under their own terms and security obligations. Prices will be in U.S. dollars, taxes may apply, and we will update this Policy and identify any new processors before charging. Advertiser obligations and the rules governing ad content, including that the advertiser is solely responsible for its ad content and legal compliance and that we may review, reject, or remove ads with no guarantee of impressions or results, are set out in our Terms of Service and advertising policy. If your ad creative or Spotlighted post includes Audio Content, you must own or have secured all rights to that audio.
17. Music, User-Uploaded Audio, and No Monetization
All music on Laybell is user-uploaded. There is no licensed catalog and no Spotify or Apple Music integration. You may upload Audio Content only if you own or have secured all necessary rights to it, including the musical composition, the sound recording (master), and any samples, vocals, or third-party material. When you upload Audio Content, you grant Laybell and other users the rights described in the Content License in our Terms of Service, including the right of other users to attach your audio to their own posts and stories via the "use this song" feature with attribution. Your representations, warranties, and the related indemnity for the audio you upload are set out in the Terms of Service.
License survival after deletion: When other users attach your Audio Content to their own posts or stories via "use this song," the license you granted for that use survives your deletion of the original. Deleting your original Audio Content does not revoke the rights other users already obtained to copies they re-shared or attributed, and those copies and attributions may remain on the Service, as further described in Sections 5 and 9 and in our Terms of Service. This survival is limited to the audio as embedded in others' posts and does not extend to your account data.
No royalties or monetization: Stream counts and other engagement metrics are provided for your information only and have no monetary value. Laybell currently pays no royalties or other compensation to creators for streams or for the use of their audio, and no monetization or payout program exists unless we separately offer one to you in writing. Badges and points are gamification only; they have no monetary value and are not redeemable or transferable.
18. Push Notifications
If you enable notifications, we store your Expo push token and platform on our servers and deliver notifications through APNs (Apple) and FCM (Google). We send notifications such as likes, comments, follows, and messages, and we also show in-app notifications. You can control notifications using per-category toggles in the app and by adjusting your device's operating-system settings. We do not send marketing text messages beyond the notifications described here; we may send transactional or security-related communications about your account. Push-notification processing is based on your consent, withdrawable at any time as easily as it was given.
19. EU and UK Representatives (Article 27)
Because we are based in the United States and offer the Service to individuals in the EU and UK, we are required to appoint representatives under GDPR Article 27 and UK GDPR. Our EU representative under Article 27 GDPR is [EU REPRESENTATIVE - NAME, EU ADDRESS, EMAIL - TO BE APPOINTED]. Our UK representative under Article 27 UK GDPR is [UK REPRESENTATIVE - NAME, UK ADDRESS, EMAIL - TO BE APPOINTED]. These representatives are designated before we make the Service available to individuals in the EU and UK, and their contact details above are part of this Policy. EU and UK individuals may contact the relevant representative on any matter relating to the processing of their personal data, and may also contact us directly at privacy@laybell.app.
20. Copyright and DMCA
Laybell complies with the Digital Millennium Copyright Act (17 U.S.C. 512). To report content you believe infringes your copyright, or to submit a counter-notification, contact our designated agent (registered with the U.S. Copyright Office) at dmca@laybell.app or at Laybell LLC, 28 Rivers Edge Ter, Indian Head, MD 20640. Our full notice-and-takedown procedure, counter-notification procedure, and repeat-infringer policy (which results in account termination for repeat infringers) are set out in our Terms of Service. We remove infringing content and terminate repeat infringers in accordance with that policy.
How we process DMCA-related personal data: If you submit a copyright infringement notice or a counter-notification, we will process the personal data in it (such as your name, contact information, and signature) to evaluate and act on the claim, and - as the DMCA requires - we may forward your notice or counter-notice, including your contact details, to the other party (the uploader or the complainant). Legal basis: compliance with a legal obligation and our legitimate interests in operating a lawful notice-and-takedown system (GDPR Articles 6(1)(c) and 6(1)(f)). We retain copyright and repeat-infringer records as described in Section 9.
21. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you, for example through an in-app notice or by email, in advance where practicable, and we will update the "Last Updated" date at the top. For materially new processing or new third parties, we will obtain your consent where the law requires it, and we will keep our subprocessor list accurate.
Your continued use of the Service after the effective date of an updated Policy means you accept the updated Policy, to the extent permitted by law. However, continued use does not constitute consent under the GDPR or UK GDPR. Where we rely on your consent for processing (for example, location, contacts, push notifications, and ad personalization), we will obtain fresh, specific, opt-in consent and will not treat your continued use of the Service as consent. You may withdraw any consent at any time, as easily as you gave it, without affecting prior lawful processing. Changes to the arbitration agreement and dispute-resolution terms in our Terms of Service are governed by the change and opt-out provisions of those Terms and do not apply retroactively to disputes of which we already had notice.
22. Contact Us
If you have questions about this Privacy Policy or your personal data, or if you wish to exercise your rights, please contact us:
- Privacy and data-subject/consumer requests: privacy@laybell.app
- General questions and support (and arbitration opt-out): support@laybell.app
- Copyright and DMCA notices (including counter-notifications), to our designated agent registered with the U.S. Copyright Office: dmca@laybell.app and Laybell LLC, 28 Rivers Edge Ter, Indian Head, MD 20640
- Mailing address: Laybell LLC, 28 Rivers Edge Ter, Indian Head, MD 20640
Laybell LLC is a Maryland limited liability company. EU and UK users also have the right to lodge a complaint with their local data-protection supervisory authority (for the UK, the Information Commissioner's Office). Our EU representative under Article 27 GDPR is [EU REPRESENTATIVE - NAME, EU ADDRESS, EMAIL - TO BE APPOINTED] and our UK representative under Article 27 UK GDPR is [UK REPRESENTATIVE - NAME, UK ADDRESS, EMAIL - TO BE APPOINTED]; you may also contact us at privacy@laybell.app.