layahost

Privacy Policy

Last updated: September 25, 2026

Nielogiczny Karol Labuda, Luzińska 2, 84-217 Zęblewo, Poland, NIP PL5882505100 (“we”) is the controller of personal data processed through layahost. For API content you send, you are the controller and we process it on your behalf, only to answer your requests.

What we collect

DataWhyHow long
Account: name, email, hashed password, security settingsRunning your accountUntil you delete the account
Billing: Stripe customer ID, payment and invoice recordsPayments, invoices, accounting dutiesAs long as tax law requires
API request content (text you send)Computing the decisionProcessed in memory; identical requests may be answered from an in-memory cache for up to 1 hour. Not written to disk unless you enable request text in logs.
Request logs: time, status, verdicts, latency, cost, API key usedYour usage dashboard, billing, abuse prevention7 days
Request text in logs (opt-in, and playground runs)Debugging decisions in your console7 days; you can delete it any time in Settings
Aggregated daily usage (counts, cost, latency)Dashboard and billingUntil you delete the account
Website analytics (pages viewed, referrer, country)Improving the siteSelf-hosted Umami, no cookies, no personal profiles

We never use your API content to train models and never sell personal data.

Processors

Legal bases

Contract (providing the Service and processing API content for you), legal obligation (tax and accounting), and legitimate interests (security, abuse prevention and cookieless analytics).

Your rights

Under the GDPR you can access, correct, delete, restrict or export your data and object to processing based on legitimate interests. You can delete your account in Settings. You may complain to the Polish supervisory authority (Prezes UODO) or your local authority.

Contact

[email protected]. A data processing agreement for API content is available on request.