Legal

Privacy Policy

This policy explains what personal data Laya Studio processes when you use the website, dashboard and API, why, where, for how long, and the rights you have under the Swiss Federal Act on Data Protection (nFADP) and the EU General Data Protection Regulation (GDPR).

Last updated ·

1. Who is responsible

The controller for the processing described in this policy is Laya Studio, Switzerland (“Laya Studio”, “we”, “us”), which operates a hosted API for the open-source Laya decision model. Laya Studio is independent and not affiliated with the model’s authors. For any privacy question or request, contact privacy@laya.studio. Full operator details are in the Imprint.

2. Our two roles: controller and processor

As controller we decide how your account, billing, website and usage-metadata data is processed. This policy covers that.

As processor we process the content of API requests (the text, questions and prompts you or your application send) only on behalf of the customer who sends it and only to return an answer. For that content the customer is the controller, and our Data Processing Agreement applies. If your data reaches us through someone else’s application, their privacy notice explains that processing; please contact them first.

3. Data we process

  • Account data: email address, name (optional), workspace name, membership and role, authentication identifiers, and sign-in records kept by our authentication provider (time, IP address, user agent). If you sign in with Google, we receive your name, email address and Google account identifier from Google.
  • API keys: stored only as a SHA-256 hash with a short display prefix.
  • Billing data: handled by Stripe. We store a Stripe customer reference, subscription reference, plan, credit balance and a ledger of credit grants and purchases, never card numbers. Stripe may collect your billing address and tax ID for invoicing and tax.
  • Request metadata: timestamp, request id, API key id, endpoint, model, status and error code, number of questions, token and credit counts, latency, and the backend that served the request.
  • Request content: the text and questions you send are processed in memory to produce an answer and are not stored or used for training. For the chat agent, see §7.
  • Technical and security data: when you visit the site or call the API, our hosting provider Cloudflare processes your IP address, request URL, time, status and user agent to deliver the service, rate-limit abuse (the public demo is rate-limited by IP address) and protect against attacks.
  • Communications: emails you send us and our replies; transactional emails we send you (sign-in links, account and billing notices).

You provide account data to create an account; without it we cannot provide the service. Everything else is generated by your use of the service.

5. Retention

  • Request content: not retained; discarded from memory when the answer is returned.
  • Request metadata: deleted after 30 days.
  • Daily usage totals (per workspace and key: requests, questions, tokens, errors, latency): for the life of the account, for billing and your usage history.
  • Account data: until you delete your account; deleted within 30 days of a deletion request.
  • Billing and accounting records (invoices, payments, credit ledger): 10 years, as required by Swiss law, even after account deletion.
  • Hosting and security logs at Cloudflare: a few days, then deleted by the provider.
  • Emails with us: as long as needed to handle the request, then deleted unless they are business records we must keep.

6. Swiss data residency

Laya Studio answers your questions on GPUs located in Switzerland, keeps its account database in Zurich, and never writes the content of a request to disk. Turn on Swiss-only mode and a request can never leave the country, not even as a failover.

  • GPUs in Switzerland: Our primary inference pool runs on dedicated GPUs located in Switzerland. Every API response tells you where it was processed in the x-laya-region header.
  • Swiss-only mode: One switch per workspace (or the x-laya-residency: ch header per request) and requests are only ever answered in Switzerland. If the Swiss pool is unavailable you get an error, never a silent detour abroad. It is an add-on: +15% credits per request, still about 20% below Jev.
  • Zero content retention: The text and questions you send are processed in memory and discarded when the answer is returned. They are never written to a database or log, and never used to train anything. One exception to know about: the optional chat agent (POST /v1/ask, the MCP ask tool, dashboard Chat) first passes your prompt to a third-party language model to plan the questions, in the US by default and in Switzerland under Swiss-only mode.
  • Account data in Zurich: Accounts, API keys (stored only as SHA-256 hashes), credit balances and usage metadata live in a Postgres database in the AWS Zurich region (eu-central-2).
  • Minimal metadata, 30 days: For billing and debugging we keep request metadata only — time, status, number of questions, latency — for 30 days. Daily totals are kept for invoicing.
  • Encrypted end to end in transit: All traffic uses TLS. The API gateway runs on Cloudflare’s network, which forwards requests encrypted and does not store their content; the GPU servers accept requests only from our gateway.

No retention plus Swiss processing makes Laya Studio a fit for sensitive text such as patient messages, clinical intake notes, HR cases or financial correspondence — the kind of data that should not sit in a US AI provider’s logs.

Designed to support compliance with the Swiss Federal Act on Data Protection (nFADP, in force since 1 September 2023) and the EU GDPR. Our Data Processing Agreement is part of the Terms; a signed copy is available on request from privacy@laya.studio.

Please note: You remain responsible for your legal basis to process personal and health data. Laya Studio holds no formal certification (such as ISO 27001) today and does not sign HIPAA BAAs.

More detail: Swiss data residency and Security.

7. Where request content can go

  • Decisions (all API and dashboard requests): answered on our GPU server in Switzerland. If it is unavailable or overloaded and your workspace or request is not in Swiss-only mode, the request may be answered by a cloud GPU provider (RunPod) in a data centre in the EU/EEA instead; the response header x-laya-region shows where it ran. In Swiss-only mode this failover never happens.
  • Chat agent (POST /v1/ask, the MCP ask tool, dashboard Chat): before Laya answers, your prompt is sent to a language model through the phi-cloud API to plan the questions. By default that model is Mercury (Inception Labs, United States). In Swiss-only mode it is a model hosted by Infomaniak in Switzerland, and a plan routed anywhere else is discarded. Don’t use the chat agent outside Swiss-only mode for data that must stay in Switzerland; the plain decision API does not involve any language model.
  • The public demo on our website always runs in Swiss-only mode.

8. Recipients and service providers

We share personal data only with service providers that help us run Laya Studio (processors bound by data processing terms), with Stripe and Google where they act as independent controllers for payments and sign-in, and with authorities where the law requires it. The full, current list, with what each receives and where, is on our Subprocessors page. In short:

  • Cloudflare (hosting, API gateway, DNS, security, queues; global network, US company)
  • Supabase (authentication and database, hosted in the AWS Zurich region, eu-central-2; US company)
  • Stripe (payments, invoicing and tax; US/Irish entities)
  • Resend (transactional email; United States)
  • Google (Sign in with Google, only if you use it)
  • RunPod (failover GPU inference in EU/EEA data centres, never used in Swiss-only mode; US company)
  • phi-cloud and the model providers behind it: Inception Labs (United States) or Infomaniak (Switzerland), for the chat agent only

9. International transfers

Our account database is in Switzerland. Some providers above are based in, or may process data in, other countries, including the United States. Switzerland and the EU recognise each other as providing adequate protection. For countries without an adequacy decision, such as the United States, we rely on the recipient’s certification under the EU-U.S. and Swiss-U.S. Data Privacy Framework where available, and otherwise on the European Commission’s Standard Contractual Clauses with the adaptations required for Swiss law, together with supplementary measures such as encryption in transit and not storing request content. You can request a copy of the relevant safeguards from privacy@laya.studio.

10. Cookies and local storage

We use no advertising or analytics cookies. We use only what the service needs:

  • Sign-in cookies set by our authentication provider to keep you logged in to the dashboard (strictly necessary).
  • Local storage in your browser for interface preferences such as a collapsed sidebar, a chosen code language or a migration checklist. It never leaves your device.
  • Third-party pages and resources: Stripe Checkout and the billing portal (payments), Google’s sign-in script (on the login and signup pages), the API reference viewer loaded from jsDelivr (on /docs/api), and the in-browser speech model downloaded from Hugging Face and jsDelivr (only if you use dictation in the playground; your audio stays on your device). These providers receive your IP address and may set their own cookies under their own policies.

11. Security

We use TLS on every connection, hash API keys, isolate tenants with database row-level security, keep GPU servers off the public internet, and restrict access to production systems. No system is perfectly secure; if we become aware of a breach affecting your personal data we will notify you and the competent authority as the law requires. See Security.

12. Your rights

Subject to the applicable law, you have the right to information about and access to your personal data, to rectification, to erasure, to restriction of processing, to receive your data in a portable format, to object to processing based on legitimate interests, and to withdraw any consent at any time with effect for the future. To exercise them, email privacy@laya.studio from the address on your account; we may need to verify your identity and will reply within 30 days. For request content we process as a processor, we will pass your request to, or help, the customer responsible for it.

You may also complain to a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch); in the EU/EEA the authority of your place of residence or work; in the UK the Information Commissioner’s Office.

13. Children

Laya Studio is a developer service not directed at children. You must be at least 16 years old (or the age of digital consent where you live, if higher) to create an account.

14. Changes

We will post changes here and update the date above; material changes are notified by email in advance.