Privacy notice

Lararia is private by default. This page says what we keep, why, and for how long.

Last updated 2 October 2026

The short version

Contents
  1. 1. Who is responsible
  2. 2. Two roles, two documents
  3. 3. What we keep, why, and for how long
  4. 4. Your content, in short
  5. 5. Cookies and your browser
  6. 6. Who we share it with
  7. 7. Data outside the EU
  8. 8. Your rights
  9. 9. Do you have to give us data?
  10. 10. Security
  11. 11. Changes

1. Who is responsible

COMPANY_LEGAL_NAME (SIREN), COMPANY_ADDRESS, runs Lararia. For the data in this notice, we are the controller: the one who decides why and how the data is used. Contact for anything about your data: PRIVACY_EMAIL.

We have not appointed a data protection officer. We are not required to, given what we process. Questions go to the address above.

2. Two roles, two documents

Data about a company is not personal data, but the name and email of a person, a sole trader's details, and everything about a private buyer are. This notice is for those people.

3. What we keep, why, and for how long

WhatWhere it comes fromWhyLegal basisHow long
Account record: a one-way hash of your account number, the date it was madeMade when you open an accountTo let you sign in and use the serviceContract (GDPR Art. 6(1)(b))While the account exists. An account with no plan, no credit and no use for 3 years is deleted.
Your API tokens: a hash of each token, the label you give itThe account pageTo let your tools use your accountContractUntil you delete the token or the account
Your free Laya key, and a count of its uses per dayThe account page and the Laya serverTo give the free key and apply its daily limitContractKey: while the account exists. Daily counts: 90 days
Plans and agents per key, subscription statusYour choices and our payment providerTo run the plan you pay forContractWhile the plan runs, then as billing records
Payments, credit and spend (the ledger), invoicesOur payment provider and our serversTo bill you and keep accountsLegal duty to keep accounting records (Art. 6(1)(c); French commercial code L123-22)10 years after the end of the financial year, then deleted. Daily spend detail: 62 days
Billing details: your name or business name, address, billing email, VAT number if you have one, payer nameYou, at checkout on our payment provider's pageTo bill you, apply the right VAT, and send order confirmations, service and legal notices. For VAT we must keep proof of your country: your billing address and the country of your cardContract and legal duty (VAT rules: Regulation 282/2011 art. 24b, art. 286 CGI)Same as payments: 10 years. Our payment provider keeps its own copy under its own rules
Who is buying (private person or business), your terms acceptance and, for private buyers, the request to start right away, each with the date and the terms versionOur checkout step and our payment provider's checkoutTo show who agreed to what, and which rules applyLegal duty to prove consumer information and consent (French consumer code L221-7), and legitimate interest: proving the contract (Art. 6(1)(f))As long as the contract, plus 5 years (the French time limit for claims)
Order, cancellation and withdrawal messages we send you or you send usOur emailTo confirm your order, your cancellation or your change of mind, as consumer law requiresContract and legal dutyAs long as the contract, plus 5 years
Request log: time, request id, model, sizes, status. No content, no account numberOur serversTo keep the service running, find faults, measure downtimeLegitimate interest: running a reliable service7 days at most
A scrambled (hashed) form of your IP address when you open an accountYour connectionTo stop mass account creationLegitimate interest: security1 day
Waitlist entry: what you asked for when our servers were fullYour requestTo give you room when it frees upContract (steps before it)Until the request is met, or 12 months
Emails you send usYouTo answer youLegitimate interest: answering you3 years after the last exchange, longer if needed for a dispute

We do not keep your account number in readable form, so we can't send it to you or reset it.

Deleted records can stay in our backups, and in our host's copies of the server, for up to 14 days before they are gone.

4. Your content, in short

We never see what you send through a key to your agents or to Spot. It is encrypted on the way, from your tools all the way into sealed chips: hardware that walls off the running service from the company that hosts it and from our team (confidential computing). It is opened only inside them, where the model works on it. Outside the seal, our servers and our team only ever get encrypted data, plus counts like its size. You can check this yourself with our public check. No system is perfect, so our site lists what the seal protects against, and what it doesn't (terms section 12.7).

It is used only to answer you, in memory only, inside the seal. It is not kept after your agent is done: a paused conversation stays in memory for at most one hour after the key goes quiet, then it is wiped. Never written to disk or to logs. Never used to train any model.

The demo on our home page and the free Laya key send text to Laya, which runs on a sealed chip that keeps out the company that hosts it. You can check this yourself. Laya does not log what you send. It keeps only a count of uses per key per day.

5. Cookies and your browser

We use no cookies, no analytics and no advertising trackers.

The account page keeps your account number in your browser tab, only while the tab is open (the browser feature called sessionStorage), so you stay signed in. It is cleared when you close the tab. This is strictly needed for the service you ask for, so it needs no consent (ePrivacy Directive Art. 5(3), French data protection law art. 82).

When you pay, you are on the checkout page of our payment provider, PAYMENT_PROVIDER. It may use its own cookies there, for fraud prevention, under its own privacy notice.

6. Who we share it with

We don't sell your data and we don't share it for advertising. We use these partners. Each handles data only for the job listed, under a contract that meets GDPR.

PartnerJobDataWhere
PAYMENT_PROVIDERPayments, invoices, taxBilling details, paymentsPAYMENT_LOCATION, EU
OVH SAS (France)Hosting the website and account pageIP addresses, as traffic passes through its network, and our server's disk, where the database sits encrypted with our keyStrasbourg, France, EU
OVH SAS (France)Our databaseAccount, plans, ledger, waitlist, Laya keysStrasbourg, France, EU
LAYA_HOST_PROVIDERRuns LayaLaya keys (hashed) and daily counts. Text sent to Laya, only inside a sealed chip that the host can't see intoLAYA_LOCATION, EU
VERDA_LEGAL_ENTITY (Verda)Runs the servers for agentsYour content, only inside sealed chips that Verda can't see into. Request logs (no content). A copy of account hashes, token hashes, balances and spend totals, so the servers can check keys and bill useAGENTS_COUNTRY, EU
EMAIL_PROVIDEROur emailEmails you send us, and order, cancellation and notice emails we send youEMAIL_LOCATION, EU

All of them are companies based in the EU. None belongs to a group based outside the EU, and the providers they use to hold our data meet the same rule.

Our payment provider also acts as a separate controller for some purposes, such as fraud prevention and its own legal duties, under its own privacy notice.

We may also share data when the law requires it, for example with tax authorities or a court.

7. Data outside the EU

All the data in this notice is kept and processed in the EU, by us and by the partners above. We do not send it outside the EU. If an authority outside the EU asks us for your data, we do not hand it over unless EU or French law, or an international agreement, requires it.

One thing is outside our partners' list. When you pay by card, your card network (for example Visa or Mastercard) and your bank handle the payment too, as in any card payment, under their own rules and privacy notices. Some card networks are US companies. They see the payment, never your content. Paying by bank transfer or debit (SEPA) avoids card networks.

8. Your rights

You can ask us to:

Write to PRIVACY_EMAIL. We answer within one month. Because accounts have no name or password, we will tell you how to prove an account is yours, for example with a payment receipt. Never send us your account number by email.

If you think we got it wrong, you can complain to the French data protection authority, the CNIL (cnil.fr, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07), or to the authority in your own EU country.

9. Do you have to give us data?

To buy, yes: we need billing details to bill you, meet tax law and send the confirmations consumer law requires. To look around, no: an account needs no name or email.

We make no decisions about you by automated means alone that have legal or similar effects on you.

10. Security

We protect data with measures that fit the risk. For example: your content is opened only inside sealed chips, we never see it, and it is never written to disk; account numbers and tokens are kept only as one-way hashes, and card and bank details never reach our servers (our payment provider handles them). The full list is in Annex 2 of our data processing agreement. If a breach puts you at high risk, we tell you without undue delay.

11. Changes

We may update this notice. The date at the top shows the last change. If a change matters for you, we tell you by email before it applies. This notice applies from EFFECTIVE_DATE.