LayerMate

Privacy Policy

Last updated: 21/08/2026
LayerMate — the desktop app, and the in-browser demo on this site — processes your 3D model files entirely on your own device. Your library, and anything you try in the browser demo, is never uploaded anywhere. This page covers the much smaller, separate set of data collected by this website itself, for the account you use to buy and download the software.

1. What we collect

  • Account: your email address and a securely hashed password. We never store or see your actual password — see "How your password is protected" below.
  • Purchases: the amount, currency, and status of any purchase, plus Stripe's own transaction/session IDs, used to confirm you're entitled to download the app. Your card details never reach us — see "Payments" below.
  • Reviews/feedback: if you submit a star rating or written feedback, it's stored against your account until you edit it or an admin removes it.
  • Password reset requests: if you request a reset, we temporarily store a one-way hash of the reset token (not the token itself, and not recoverable from the hash) for 30 minutes.
  • Website analytics: which pages get visited, the referring site, and a coarse country/region resolved from your IP address at that moment — never your actual IP address, never your browser/device details, and never tied to your account or a tracking cookie. See "Analytics" below.
  • Optional advertising measurement: if you choose to allow it, we may use Meta's advertising tools to understand whether an advertisement led to a visit, checkout, or purchase. Depending on the event, this may include the page visited, the action taken, purchase value and currency, device or browser information, IP address, advertising identifiers, and a one-way-hashed version of your email address used for matching. See "Advertising measurement" below.

2. What we don't collect

  • We don't sell or rent your information to anyone.
  • The desktop app itself never sends us your files, folder structure, filenames, or anything about your library. The only thing it contacts us for on its own is checking whether a newer version exists — a plain, anonymous request to a static file, not tied to your account in any way.
  • We never send Meta or any other advertising provider your 3D model files, filenames, folder names, model geometry, library contents, or anything you process through LayerMate or the browser demo.

3. Trying it in your browser

The "Try it" demo on this site runs entirely inside your own browser tab. When you pick a folder or files, your browser reads them locally using the file-access features built into the browser itself — nothing is uploaded to our servers, and no file, filename, folder name, geometry, colour, or any other detail about what you scanned is ever sent to us or to anyone else. We have no way to see what you tried it on, and no account is needed to use it.

The page itself is served like any other page on this site, so it's subject to the same anonymous, cookie-free page-view analytics described below (just the page path and a coarse country) — that's the only thing about visiting this page that reaches us. Nothing from a session is saved anywhere, by us or in your browser — no cookies, no local storage. Close or reload the tab and everything from that session, including any thumbnails generated, is gone for good.

4. How your password is protected

Passwords are hashed with bcrypt — a one-way, industry-standard algorithm — before they're ever written to disk. Even we can't read your actual password back out. Logging in issues a random session token stored in a cookie your browser's page scripts can't read (HttpOnly), and that token can be revoked at any time — for example, automatically, the moment you reset your password.

5. Payments

Handled entirely by Stripe. Checking out takes you to Stripe's own secure payment page — your card number, expiry, and CVC go directly to Stripe and never touch our servers. We only receive back a payment confirmation, an amount, and Stripe's own reference IDs. Stripe's handling of your information is governed by Stripe's own privacy policy.

6. Emails

Transactional emails — currently just password reset links — are sent through Resend, an email delivery service. We only send one if you actually request a password reset.

7. Analytics

LayerMate's own website analytics are self-hosted and cookie-free. Each page view records the page path, the referring site (if any), and a coarse country/region resolved from your IP address at that moment. The IP address itself is never written to our database — it's used for that one lookup and discarded. These analytics are separate from the optional advertising measurement described below.

8. Advertising measurement

We advertise LayerMate through services including Facebook and Instagram. If you choose to allow advertising measurement, we may use the Meta Pixel and Meta Conversions API to understand whether an advertisement resulted in a website visit, checkout, or purchase; measure the performance of our advertising; and improve which advertisements are shown to people likely to be interested in LayerMate.

Meta may use cookies, pixels, advertising identifiers, and similar technologies to collect or receive information from this website and elsewhere on the internet. Meta handles that information under its own privacy policy. Optional advertising measurement does not receive any files or file details from the browser demo.

Advertising measurement is non-essential. Where the option is available, you can reject it without losing access to the website, browser demo, checkout, downloads, or desktop application. You can also manage information Meta receives from other businesses through Meta's off-Facebook activity controls.

9. How long we keep it

  • Account and purchase records are kept for as long as your account exists. Purchase records may be retained afterward for bookkeeping/tax purposes even if you delete your account.
  • Password reset tokens expire and are automatically cleared after 30 minutes.
  • Rate-limiting records (used only to slow down repeated login/signup attempts from the same source) are automatically cleared after about an hour.
  • Analytics records are kept in aggregate for measuring site traffic — they were never tied to your identity to begin with.
  • Information handled by Meta for advertising measurement is retained by Meta according to its own policies and the settings of our Meta business account.
  • The browser demo (Try it) keeps nothing at all, for any length of time — there's nothing on our servers to retain in the first place, since the files never reach us.

10. Your choices

You can delete your own account at any time from your dashboard — this permanently removes your login, purchase history, and reviews from our systems. Stripe keeps its own transaction records independently, as required for payment processing and fraud prevention, so deleting your LayerMate account doesn't delete Stripe's records of a payment you made.

You can reject optional advertising measurement through the privacy choices presented on the site where those tools are enabled. Your choice does not affect the essential session cookie used to keep you securely logged in.

You're also welcome to email support@layermate.app any time to ask what we hold about you, correct it, or have it deleted manually.

11. International visitors

This site is operated from Australia. Third-party services we rely on — Stripe, Resend, Railway (our hosting provider), and Meta when optional advertising measurement is enabled — may process data in other countries as part of providing their services to us.

12. Changes to this policy

If this policy changes in a material way, we'll update the date at the top of this page.

13. Contact

support@layermate.app

Because your downloads folder deserves better.
© 2026 LayerMate. All rights reserved.
Pricing Support Licence Privacy