Layve.
Data How it works Questions
EN
  • English
  • Français
  • Deutsch
  • Español
  • Italiano
Sign in Create my space

Privacy policy

Last updated: 26 September 2026

This policy explains what information Layve collects, why, how long it is kept and what your rights are. It covers two services: the presentation site (layve.io) and the platform (app.layve.io).

Who is responsible

The controller is the publisher of Layve, whose details appear in the legal notice. For any question about your data: hello@layve-app.com. No data protection officer has been appointed so far: this address serves that purpose.

The layve.io site collects no data

  • The site has no account, no form that sends data to our servers, no audience measurement, no advertising and no tracking tool.
  • It uses no cookies and stores nothing in your browser.
  • We keep no access log of visits to the site.
  • One connection to a third party: the typefaces are loaded from the Fontshare service (Indian Type Foundry). As with any file downloaded from a server, that service receives your IP address and the technical details of your browser. We have no access to them.
  • The text you write in the "describe your goal" box stays in your browser. It is sent nowhere until you click the button. The button then opens the platform and passes it this text in the part of the address after the # sign, which the browser never sends to a server.

The app.layve.io platform

What we process

  • Company: its name, public information from official registers (SIREN number, head office address, activity, headcount, legal form) and from its website and social accounts.
  • Account: work email address, password (kept only in an irreversible encrypted form), first and last name if you give them, department, role and how you produce content today.
  • Requests: the text of the request, place, preferred time slot, instructions, the person to contact on site (name and phone if you give them), validated plans, feedback and usual instructions. These form your company's "memory", which makes later analyses more accurate.
  • Content: photos and videos you add or that professionals deliver, and the edits proposed to you.
  • Technical data: IP address, browser type, connection dates and times, security log.
  • Two factor authentication: the key that generates the codes (encrypted) and backup codes (kept in an irreversible encrypted form).

If you name a contact person, or have people photographed, you make sure you have the right to do so and have informed them.

Research on your company: public information only

To prepare your plans, Layve reads information that is publicly available about companies: the official company register (Annuaire des Entreprises, GLEIF), open databases (Wikidata, OpenStreetMap, the IGN Géoplateforme), the company's public website, its public pages on social networks, online press and web archives. Layve signs in to no private account and bypasses no protection. We do not seek to collect data about individuals: if a public source mentions an executive, that mention is used only to identify the company.

Why we process this information

  • Creating and managing your account, preparing your plans, organising shoots, producing and delivering content, sending you the emails the service needs: performance of the contract.
  • Securing the platform (authentication, abuse limits, security log): legitimate interest in protecting the service and its users.
  • Meeting our accounting obligations and answering authorities: legal obligation.

We do not sell your data, we do not advertise and we do not use it to train our own models.

Who receives your data

  • OVH SAS (France): hosting of the platform and the site.
  • OpenAI, Anthropic and Google (artificial intelligence providers): to propose a plan, they receive the text of your request, the public context of your company and your space's memory. They receive no password, email address or file.
  • Higgsfield: when you ask for a photo to be animated, it receives the chosen photo for the time of processing. Other edits are made on our own servers.
  • Google Workspace: sending and receiving emails.
  • Professionals (photographers, videographers): they receive the mission information they need, meaning the brief, place, date and on site contact.
  • Let's Encrypt: security certificates, no personal data.
  • Authorities, when the law requires it.

Some of these providers are located in the United States. These transfers rely on the mechanisms provided by the GDPR: an adequacy decision or standard contractual clauses.

How long we keep it

  • A request made before an account is created: 3 days after the last activity, then deleted if no account is created.
  • Pending email confirmation: 24 hours.
  • Sign in: 12 hours of inactivity, 7 days at most.
  • Security log: 90 days.
  • Account, requests, memory and files: as long as the account is active, then deleted at your request within one month, unless the law requires us to keep them.
  • Billing data, once payments are offered: legal accounting periods.

Cookies

The site sets no cookies. The platform uses only cookies that are strictly necessary for it to work. They need no consent and are not used for advertising, audience measurement or tracking:

  • layve_d: remembers your request before the account is created (3 days).
  • layve_s: keeps you signed in (7 days at most).
  • layve_p: waits for your email confirmation (24 hours).
  • layve_lang: remembers the language you chose (12 months), only if you choose a language.

The first three carry the __Host- prefix, cannot be read by scripts and travel only over encrypted connections.

Security

Encrypted connections, passwords protected by a strong hashing algorithm, mandatory two factor authentication, encrypted secrets, customer files stored with private access, limits on sign in attempts, a security log. No system is infallible: in case of a breach that presents a risk to your rights, we inform you and the data protection authority within the legal deadlines.

Your rights

You can ask for access to your data, its correction or erasure, restriction of or objection to its processing, its portability, and set instructions for what happens to it after your death. Write to hello@layve-app.com: we reply within one month and may ask for proof of identity if in doubt.

You can also lodge a complaint with your data protection authority. In France this is the CNIL: 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.

Layve is intended for professionals and not for minors.

Changes

We may update this policy, for example when a service changes. The date of the last update is at the top of the page; for an important change we say so on the site.

Layve.

hello@layve-app.com

  • Data
  • How it works
  • Layve Pro
  • Terms of use
  • Terms of sale
  • Privacy policy
  • Legal notice
  • English
  • Français
  • Deutsch
  • Español
  • Italiano