Legal · last updated 17 August 2026
Privacy Policy
We collect what the program needs and nothing else. Administrators see who is keeping up, not what anyone answered. Nothing is sold, and no learner data is used to train AI models.
Who is responsible for what
Layup is operated by Shaurya Singh. For data about administrators, buyers and people who use our public mini-course generator, we decide what is collected and why, so we are the controller.
For data about learners inside a customer organisation, the customer decides who is enrolled and why. The customer is the controller and we act on its instructions as a processor. If you are a learner and want your data removed, ask your administrator first; if that is difficult, write to us and we will help.
What we collect
From administrators and buyers
- Name, work email address and Google account identifier.
- Organisation name, and the settings chosen for the program.
- Billing contact details and subscription state. Card details go straight to Paddle and never reach us.
From the roster
- Each learner’s name, work email address and optional team or group, as uploaded by an administrator.
From learners using the product
- Which lessons were opened and finished, when, and how long they took.
- Exercise answers and attempts, including whether the first attempt was right.
- Email delivery events for the lessons we send: delivered, opened, clicked, bounced.
- Email preferences, snoozes and opt-outs.
From the public mini-course generator
Anyone can generate a short course without an account. That surface holds four kinds of data, and nothing else:
- The topic you typed and the course generated from it, stored so the page can be reopened.
- Share links: long, unguessable web addresses. They are not indexed by search engines, and you can ask us to revoke one at any time.
- An email address, if you choose to save a course. We use it to send you the link and, if you agree, occasional product email. Every message has an unsubscribe link.
- Rate-limit keys. To stop abuse we count requests per IP address and per email address. We do not store either one: we store a keyed HMAC hash of it, and each entry expires by itself after hours or days.
Automatically
- Server and error logs, including IP address and browser, kept to keep the service working and secure.
- Page analytics on public marketing pages only, via Cloudflare Web Analytics. It sets no cookies, builds no profile and does not follow anyone across sites.
What an administrator can and cannot see
This is a deliberate product decision, not a setting we forgot to expose. A graded conscript stops answering honestly, so administrators get what they need to run the program and nothing that enables monitoring an individual.
| The administrator sees | The administrator never sees |
|---|---|
| Weekly completion rate and its trend | Which answer a person chose, question by question |
| Per person: done, in progress or not started, and the date finished | Whether a person opened or clicked an email |
| Per person: how many questions were right first time | What time of day a person studied |
| Quiz scores as a team distribution, and the most-missed question | Per-question timings and where people dropped off |
| Median time to complete a lesson | Anything else |
An organisation may switch on assessment mode, which makes per-person quiz scores visible to its administrators. When it is on, every learner is told so on the first screen of every lesson. The wording on that screen always matches the setting in force.
Why we are allowed to process it
- To perform the contract: running the program, sending lessons, reporting completion, taking payment.
- Legitimate interests: keeping the service secure, preventing abuse of the free generator, fixing errors, and understanding in aggregate which lessons work.
- Consent: product email to people who saved a mini-course. Withdraw it with the unsubscribe link in any message.
- Legal obligation: tax and accounting records held by Paddle as merchant of record.
How AI generation uses your data
Lessons are generated by Anthropic’s API. We send the topic, the audience description an administrator wrote, and source notes we supply.
We do not send learner names, email addresses, or answer histories. Where a lesson is personalised, it is personalised from a pseudonymous summary of events, not from anyone’s identity.
Under Anthropic’s commercial terms, inputs and outputs sent through their API are not used to train their models. We do not use your data to train models either.
Who else processes it
We use a small number of vendors to run the service. This is the complete list. We will update this page before adding another.
| Vendor | What it does | What it receives |
|---|---|---|
| Anthropic | Generates lesson content from an approved topic | Topic, audience description and our own source notes. No learner names, email addresses or answers. |
| Vercel | Hosting and application runtime | Everything the application serves, plus request logs. |
| Neon | Managed Postgres database | Account, roster, course and progress records. |
| Resend | Sends lesson, reminder and report email | Recipient email address and the rendered message. |
| Paddle | Merchant of record: payment, invoicing and sales tax | Buyer billing details. Paddle is the seller of record and an independent controller of that data. |
| Cloudflare | DNS, bot protection, cookie-free page analytics, file storage | Request metadata on public pages; stored course assets. |
| Sentry | Error monitoring | Scrubbed error reports. Tokens, email addresses and answer content are removed before sending. |
| Upstash | Rate limiting on public endpoints | Short-lived counters keyed by an HMAC hash. No raw IP addresses or email addresses. |
Our infrastructure runs in the United States. Where personal data moves from the UK or the European Economic Area, it is covered by the standard contractual clauses in each vendor’s data-processing agreement.
How long we keep it
| Data | Kept for |
|---|---|
| Learner progress and answers | While your organisation has an account |
| Product analytics events | 13 months |
| Email delivery events (sent, delivered, bounced) | 90 days |
| Payment webhook payloads | 30 days, encrypted |
| Course revisions and how they were generated | While the revision exists |
| Report snapshots | While your organisation has an account |
| Mini-course content and its share link (public generator) | Until you revoke the link or ask us to delete it |
| Email address given to save a mini-course | Until you unsubscribe or ask us to delete it |
| Rate-limit keys (HMAC hashes of an IP address or email address) | Hours to days, each key carries its own expiry |
When an organisation cancels, we keep its data for 30 days so it can be exported, then delete it. Ask us to delete it sooner and we will.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to it. You can also ask for an export in a portable format.
Write to support@withlayup.com. We answer within 30 days. If you are a learner in a customer organisation, we will usually pass the request to that organisation, because it is the controller of your learning data.
If you think we have handled your data badly, you can complain to your local data-protection authority. We would rather you told us first.
How we protect it
- Traffic is encrypted in transit; stored data is encrypted at rest.
- Every record carries the organisation it belongs to, and the database enforces that boundary as well as the application.
- Sign-in tokens are stored hashed, expire, and are revoked when someone is removed from a roster.
- Error reports are scrubbed of tokens, email addresses and answer content before they leave our servers.
- Administrator actions are recorded in an audit log: roster changes, publishing, exports, billing and assessment-mode changes.
No service is perfectly secure. If a breach affects your data, we will tell you and the relevant authority without undue delay.
Children
Layup is a workplace product and is not intended for anyone under 16. We do not knowingly collect their data. If you believe we have, email us and we will delete it.
Changes to this policy
If we change how we use personal data, we will update this page and change the date at the top. For a change that materially affects you, we will also email your administrators.
The rest of the agreement is in our Terms of Service.
Questions about this policy go to support@withlayup.com. The service is provided by Shaurya Singh, trading as Layup.