Privacy Policy
Effective Date: June 19, 2026
1. Introduction
LayerV, Inc. (“LayerV,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services, including the LayerV Discord Bot, the LayerV Slack Bot, any other LayerV bot or integration offered through a third-party communication platform (the “Bot”), and the LayerV API and developer offerings.
LayerV, Inc. is a Delaware corporation. For privacy inquiries, contact us at privacy@layerv.ai.
2. Information We Collect
Information You Provide
- Contact Information. Name, email address, phone number, organization, and job title when you apply for early access or contact us.
- Identity Provider. Which identity provider your organization uses (e.g., Okta, Azure AD).
- Use Case Information. Description of your intended use of our services.
- Communications. Records of correspondence when you contact us.
- Developer Information. Information you provide when registering for an API key or developer account.
Information Collected Automatically
- Log Data. IP address, browser type, pages visited, referring URL, and access times.
- Device Information. Device type, operating system, and browser version.
We do not use tracking cookies, advertising cookies, or third-party analytics services on this website. We collect only server-side logs necessary for security and operational purposes.
Anonymous Page Analytics
We collect anonymous, cookieless page analytics to understand how visitors use our website. This includes pages visited, referrer domain, UTM campaign parameters, device type, browser family, scroll depth, and time on page. This data is collected by our own first-party service with no cookies, no personally identifiable information, no fingerprinting, and no third-party analytics services. We honor the Do Not Track (DNT) browser signal and skip collection for users who enable it.
Information Collected Through the LayerV Bot
When you use the Bot, we collect the following categories of information:
- Platform Account Identifiers. Your user identifier and username on the underlying communication platform (such as your Discord user ID or your Slack member ID), and identifiers for the server, workspace, or channel in which the Bot is invoked. We receive this data directly from the underlying platform pursuant to that platform's developer terms.
- Bot Command Data. The commands you issue to the Bot, the timestamps of those commands, and any parameters submitted with them.
- qURL Token Metadata. For each qURL token generated through the Bot, we collect the token identifier, generation timestamp, expiration timestamp, configured access policy, and records of successful and unsuccessful access attempts.
- Content Submitted to the Bot. Any image, file, link, or other content you submit to the Bot for sharing or processing. Content is encrypted in transit and at rest. LayerV's architecture is designed so that LayerV does not hold or have routine operational access to the cryptographic credentials required to decrypt or view the unencrypted content. Content is stored on LayerV cloud infrastructure (currently Amazon Web Services) in the United States and is purged on an operational cadence determined by LayerV. See Section 27.7 of our Terms of Service for additional detail.
- Conversation Messages (Assistant and Agent Features). When you mention the Bot, message it directly, or enable its in-channel assistant in a channel it has been added to, the Bot receives the messages in that conversation in order to generate its responses. The Bot uses these messages solely to produce replies within that conversation and does not use them to build user profiles or for advertising. See Section 4 below for the third-party AI provider that processes this content.
Note on Third-Party Platform Storage. When you upload content to a Discord server, Slack workspace, or any other third-party communication platform on which the Bot operates, that platform also stores a copy of the content on its own infrastructure (for example, on Discord's content delivery network). LayerV does not control that storage, the URLs generated by the platform, or the access controls the platform applies. Platforms commonly process uploaded content in ways that are independent of LayerV, including but not limited to: serving content from their own content delivery networks under URLs the platform controls; caching attachments on the recipient's mobile device in operating-system attachment caches; transmitting attachment thumbnails through push-notification services (such as Apple Push Notification service or Firebase Cloud Messaging); generating link-unfurl preview images cached on third-party servers; and retaining content for periods determined by the platform's own retention policies, which may differ materially from LayerV's.
The encryption and architectural representations described above apply only to content stored on LayerV infrastructure, not to content stored or processed by the underlying communication platform. See Section 27.7A of our Terms of Service for additional detail, including the specific exposure scenarios described in that section.
- Operational Logs. Bot performance, error, and security logs, including the IP address from which Bot interactions originate where this information is available to us.
We do not request or collect platform email addresses, payment information, or any other sensitive personal data through the Bot beyond what is described above.
Data Received but Not Used. When you invoke the Bot, the communication platform includes incidental metadata with each request that the Bot does not use to provide any feature. On Slack, this includes the workspace name, channel name, and your display name sent alongside a slash command; these are used only as a transient security cross-check to prevent form-replay (for example, in the “/qurl feedback” form) and are then discarded. The Bot also receives routing and envelope metadata (such as event and view identifiers) that is not used for any feature and appears only in operational logs used for troubleshooting and abuse prevention. The Bot does not retrieve message history, enumerate workspace members, or access files beyond the content you explicitly submit to it.
Information Collected Through the LayerV API and Developer Offerings
When you use the LayerV API or developer offerings, we collect:
- API Key Identifiers and Usage Data. API key identifiers, request timestamps, endpoint usage patterns, rate limit data, and error logs.
- Source Identifiers. IP addresses and other technical identifiers from which API requests originate.
- Developer Account Information. Information you provided when registering as a developer.
3. How We Use Your Information
We use the information we collect to:
- Process your early access application and evaluate fit for our pilot program
- Communicate with you about our services, including scheduling demos and onboarding
- Respond to your inquiries and provide support
- Send product updates and security advisories (you may opt out at any time)
- Maintain security and prevent fraud
- Comply with legal obligations
For information collected through the Bot and the API, we additionally use it to:
- Operate the relevant service, process your commands or API requests, and generate and validate qURL tokens
- Enforce rate limits and detect abusive usage patterns
- Detect, investigate, and prevent abuse, fraud, infringement, illegal activity, and security incidents
- Enforce our Terms of Service
- Comply with legal process, court orders, and regulatory or law enforcement requests
- Report suspected child sexual abuse material to the National Center for Missing & Exploited Children as required by 18 U.S.C. § 2258A
- Respond to DMCA notices and other intellectual property complaints
- Respond to valid TAKE IT DOWN Act removal requests and state law analogs regarding non-consensual intimate imagery
4. Service Providers and Data Processing
We do not sell your personal information. We share data only with service providers necessary to operate our business:
- Amazon Web Services (AWS). Cloud infrastructure hosting. Data is stored in AWS US regions. AWS maintains its own security certifications, including SOC 2, ISO 27001, and FedRAMP.
- Email Services. Transactional email delivery for application confirmations and communications.
- Discord, Inc. Communications layer through which the Discord Bot operates. LayerV is not affiliated with Discord, and Discord's collection and use of your information is governed by Discord's own Privacy Policy.
- Slack Technologies, LLC (a Salesforce company). Communications layer through which the Slack Bot operates. LayerV is not affiliated with Slack, and Slack's collection and use of your information is governed by Slack's own Privacy Policy.
- Anthropic, PBC. When you use the Bot's assistant or agent features, the content of the relevant conversation is sent to Anthropic's API to generate the assistant's responses (currently the Claude model family). LayerV is not affiliated with Anthropic, and Anthropic's processing of that content is governed by Anthropic's commercial terms and privacy policy. Under those commercial terms, content submitted through the API is not used to train Anthropic's models.
We may also disclose information:
- When required by law, subpoena, or legal process
- To protect our rights, privacy, safety, or property
- To enforce our Terms of Service
- To report suspected illegal activity to the appropriate authorities
- In connection with a merger, acquisition, or sale of assets (with notice to affected users)
5. Data Retention
LayerV retains personal information for the period necessary to fulfill the purposes described in this policy, including providing our services, complying with legal obligations, resolving disputes, enforcing our agreements, and supporting business continuity. Specific retention periods are operational and may change over time based on legitimate business need, security, regulatory requirements, and applicable law.
Information collected through the Bot is retained only as long as needed to operate the service. qURL token metadata is retained for the lifecycle of the token plus a limited period afterward to support security, abuse prevention, and audit. Content submitted through the Bot is encrypted and purged on an operational cadence tied to token expiration, as described in Section 27.7 of our Terms of Service; LayerV does not retain Bot content longer than necessary for these purposes.
Files uploaded through LayerV browser extensions are subject to the retention practices described in the applicable extension privacy policy. For the qURL Gmail extension, see the qURL Gmail Extension Privacy Policy.
CSAM reports and related records are retained as required by 18 U.S.C. § 2258A and applicable law. DMCA notices and counter notices may be retained for the period required to support enforcement of LayerV's repeat infringer policy.
You may request deletion of your data at any time by emailing privacy@layerv.ai. We will honor deletion requests except where retention is required by law, necessary to resolve disputes, or necessary to protect LayerV's rights or the rights of third parties.
6. Data Security
We implement technical and organizational security measures including:
- Encryption in transit and at rest
- Access controls and authentication requirements for personnel
- Regular security assessments
- Incident response procedures
- qURL identity binding and ephemeral access controls for Bot data flows
Content submitted through the Bot is encrypted such that LayerV does not hold or have routine operational access to the cryptographic credentials required to decrypt or view the unencrypted content. See Section 27.7 of the Terms of Service for additional detail.
No method of transmission over the internet is 100% secure. If you believe your data has been compromised, contact us at security@layerv.ai.
7. Your Privacy Rights
All Users
You have the right to:
- Request access to your personal information
- Request correction of inaccurate data
- Request deletion of your data
- Request a portable copy of the personal information you have provided to us
- Opt out of marketing communications
California Residents (CCPA/CPRA)
If you are a California resident, you additionally have the right to:
- Know what personal information we collect, use, and disclose
- Request deletion of your personal information
- Opt out of the sale or sharing of personal information (we do not sell or share your data)
- Non discrimination for exercising your privacy rights
Other U.S. State Privacy Laws
If you are a resident of any U.S. state with applicable consumer privacy legislation (such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Tennessee, Iowa, Indiana, New Jersey, Delaware, New Hampshire, Maryland, Minnesota, Nebraska, or Rhode Island), you may have rights similar to those described above. To exercise rights under any such law, contact us at privacy@layerv.ai.
European Users (GDPR)
LayerV, Inc. is a U.S. based company. LayerV currently focuses on customers in the United States and does not actively market its services to individuals or organizations in the European Economic Area or the United Kingdom. If you are located in the EEA or UK and use our services, your data will be transferred to and processed in the United States.
EU and UK organizations that wish to use LayerV services and require a Data Processing Agreement, Standard Contractual Clauses for cross-border transfers, or other GDPR-aligned arrangements should contact us at info@layerv.ai before integrating. We will respond to data subject requests as required by applicable law.
Response Time
We respond to privacy requests within the time frame required by applicable law. To submit a request, email privacy@layerv.ai.
8. Children's Privacy
Enterprise Services. Our enterprise services are intended for business use and are not directed at individuals under the age of eighteen.
The Bot. The Bot is available to users who meet the minimum age requirements of the underlying communication platform (for example, Discord's general minimum age, or Slack's eligibility rules and any age requirements imposed by the workspace administrator). The age requirements applicable to your use are set by that platform, not by LayerV.
Hard Floor. Regardless of the underlying platform's age policy, we do not knowingly collect personal information from any individual under the age of thirteen in the United States, or under the applicable age of digital consent in any other jurisdiction. If we learn that we have inadvertently collected personal information from a child under the applicable age, we will delete that information as soon as reasonably possible.
If you are a parent or legal guardian and you believe we have collected personal information from your child, please contact us immediately at privacy@layerv.ai and we will delete it.
CSAM Reporting. If LayerV becomes aware of any content that may constitute child sexual abuse material, LayerV will report that content to the National Center for Missing & Exploited Children (NCMEC) in compliance with 18 U.S.C. § 2258A and will preserve and disclose related records to law enforcement as required by law. Because LayerV's architecture does not provide LayerV with routine operational access to the unencrypted content of communications transmitted through the Bot, traditional content scanning is not available to LayerV; see Section 27.13 of the Terms of Service for additional detail.
9. International Data Transfers
Your information is processed and stored in the United States. By using our services, you consent to the transfer of your data to the U.S. We use AWS infrastructure to protect data in transit and at rest.
10. Changes to This Policy
We may update this privacy policy to reflect changes in our practices or legal requirements. Material changes will be communicated by:
- Posting the updated policy with a new effective date
- Email notification to users who have provided contact information
We encourage you to review this policy periodically.
11. Browser Extensions
LayerV publishes browser extensions that interact with third-party applications (currently the qURL Gmail extension). Each LayerV browser extension has its own dedicated privacy policy describing the data processed by that extension. For the qURL Gmail extension, see the qURL Gmail Extension Privacy Policy. For matters specific to a given extension, that extension's policy controls; this Privacy Policy controls for all other LayerV services.
12. Contact Us
For questions about this privacy policy or to exercise your privacy rights:
LayerV, Inc.Email: privacy@layerv.ai
Security Issues: security@layerv.ai