Privacy Policy
Last updated July 29, 2026
Layersmith is built so that the honest answer to "what do you do with my images?" is usually nothing, because we never receive them. This policy explains exactly what runs where, what little we store, and your rights over it.
Images
Free local features — opening an image, AI grab, wand/lasso/brush selection, subject separation, edge cleanup, shadow scaffold, and every export (PSD, ORA, PNG) — run entirely in your browser. Your image is never transmitted to us or anyone else, with one exception you control: if a job goes wrong you may press “Didn’t work? Send us this image”, which uploads that one image so we can diagnose it. Nothing is sent unless you press it, and what you send is deleted within 24 hours. Metadata (EXIF, including GPS) is discarded during import because the image is re-encoded through a canvas.
Server AI features are opt-in, clearly labelled with a credit cost, and only run when you click them. When you use one, the relevant pixels are sent over HTTPS to our servers, processed, and returned — and not retained at all beyond processing. The only images that rest on our servers are the ones you deliberately send us with the “send us this image” button, and those are deleted automatically within 24 hours by a storage lifecycle rule. We never use your images to train AI models, and we never share them with third parties for their own purposes.
Server-processed images, in detail
When you use a single-image server feature (subject separation, occlusion fill, object detection), the pixels are streamed to our server AI, processed, and streamed back — we store no copy, our logs contain no image content, and the pixels are processed transiently and never used to train models.
Images you report to us are the one place images rest on our servers. If you press “Didn’t work? Send us this image”, that single image is held in storage with an automatic lifecycle rule that deletes it within 24 hours, and is used only to work out why the tool failed. Batch processing, which previously uploaded whole folders, was withdrawn in August 2026 and no longer exists.
Some paid tools send your image off your device
Your free, in-browser tools never upload anything on their own (see above — the one exception is the “send us this image” button, which only acts when you press it). The paid, credit-metered tools do send image data off your device. Most run on our own servers (Cloudflare) — object and subject detection, masking, the standard fill, and text scanning — and are covered by our 24-hour deletion rule.
A few opt-in tools, each labelled with a credit cost on the button, additionally send image data to an external AI provider, because no model we run in-house matches their quality yet:
- Remove people (and finding people/objects to cut out) sends your image, downscaled, to Anthropic (Claude) to locate them.
- HD fill / erase / extend background send only a cropped region around your selection to Replicate (FLUX) to generate the fill; a second provider (OpenAI) is a rare fallback if the first is unavailable.
- Upscaling low-resolution art for print separations sends that image to Pruna AI, reached through Cloudflare's model catalogue. It only runs when you explicitly choose to upscale after we tell you the art is below print resolution — never automatically. The image is held briefly in our own storage so the model can read it, and deleted as soon as the upscale returns.
We call every provider through their API — inference only, to run the model on your image. We never train any model on your images, and we don't permit our providers to either. Anthropic does not train on API data and lets us keep ownership; Replicate, OpenAI and Pruna AI process for inference and delete their copies per their policies (the OpenAI fallback retains data up to 30 days, for abuse monitoring only). Our own 24-hour rule still applies to everything on our side. If you'd rather nothing leave your device, stick to the free in-browser tools and the standard (non-HD) fill.
Illegal content
Child sexual abuse material (CSAM) and any content that sexualizes minors are prohibited — see our Terms. We want to be precise about how that is enforced today: we do not currently run automated hash-matching against CSAM databases on images processed by our servers. Automated hash-checking at upload is planned, and this policy will be updated to describe it once it is actually in place. Until then, enforcement is report- and review-driven: we act where we become aware of apparent CSAM, whether through a report, a notice from a payment or infrastructure provider, or our own investigation of an account. Abuse investigation is the only purpose for which a server-processed image may be examined by a person.
Where we identify apparent CSAM we report it to the appropriate authorities — the Canadian Centre for Child Protection (Cybertip.ca) and/or the National Center for Missing & Exploited Children — as the law requires, together with associated account information, and we preserve related evidence for law enforcement. The legal basis is our legal obligation and the overriding public interest in child safety.
Account data
If you create an account we store: your email address, session records, your credit ledger (grants and usage), and per-job metadata (counts and timestamps — not image content). Payment details are handled by Stripe; we never see your card number. Purchases are sold through Link, a Stripe company, acting as merchant of record, so Link receives the billing details you enter at checkout — including the name and billing address it needs to calculate tax — and sends your receipt. We receive the fact of the purchase and your credit balance, not your payment details. Their handling is described in Stripe's privacy policy.
Cookies
We set exactly one cookie: rl_session, an HttpOnly authentication cookie that keeps you signed in for up to 30 days. No advertising cookies and no cross-site tracking. The one other thing we store on your device is the per-tab analytics id described under Analytics — sessionStorage, not a cookie, gone when the tab closes.
Analytics
For product analytics we use INSG, a cookieless, privacy-first tool we build ourselves. It sets no cookies, uses no client-side storage, stores no IP addresses, and records only aggregate behavioural signals (scroll depth, clicks, performance) — never your image content. It is served from our own subdomain, stats.layersmith.app, so the analytics request never leaves our domain. It does not run at all on the editor or your account pages.
We also record our own product usage: which page you opened, which tool you pressed, whether a job finished, and how long it took. No image, no pixels, no file names — an event name and a few numbers. This is how we find out that a feature is failing or that a wait is too long.
To make those events readable as one visit rather than a pile of unconnected counts, each browser tab is given a random id, stored in that tab's sessionStorage. It is not a cookie, it is never sent anywhere but to us, and it is derived from nothing about you or your device — it is a random number. Closing the tab ends it permanently; open the site again tomorrow and you are a new, unrelated visit to us. We cannot use it to recognise you, to follow you across sites, or to build a profile, and we do not try to.
We also record which site sent you here — but only its domain name, such as google.com, never the full address of the page you came from, which could carry someone else's search terms or identifiers. If you arrive from a link we published with campaign tags on it (utm_source and similar), we keep those three tags too. That is the whole of it: a domain and, at most, three short labels we wrote ourselves. It is recorded once when your tab first reaches us, it is discarded when the tab closes along with the id above, and it tells us which of our efforts actually bring people here.
Two other requests do leave our domain on marketing pages, and neither touches your images: Google Fonts serves a webfont, and Cloudflare — who host this site — receive a page-view beacon from their own analytics. Both see the ordinary information any web request carries, such as your IP address and the page URL.
Emails
We send sign-in links and receipts, and — if you opt in — occasional product updates you can opt out of with one click. Transactional email is delivered via Resend.
Your rights
- Access & export: ask and we'll provide the account data we hold on you.
- Deletion: on request (or from your account page) we irreversibly anonymize your account: your email, sign-in identities, and payment link are removed and replaced with a random identifier, and every session is destroyed. Transaction records are retained in this anonymized form for accounting, as tax law requires — they can no longer be connected to you. Signing up again afterwards creates a completely fresh account. Exception: where the law requires preservation — for example in connection with an unlawful-content report or legal process — the required information is preserved and provided to authorities notwithstanding a deletion request.
- Correction: your email can be updated on request.
We operate from British Columbia, Canada, and handle personal information in accordance with PIPEDA and BC PIPA. If you're in the EU/UK, the practices above are our GDPR posture too: data minimisation by architecture, no profiling, no automated decision-making about you.
Contact
Privacy questions: contact us. We aim to respond within 7 days.