Privacy Policy
How Laarpi handles personal data, in plain language: what we collect, how the agent's AI processing works, what lives in your own accounts, the few cookies we set, how long we keep things, and your rights. Draft pending legal review.
Draft, pending legal review. This is a plain-language draft of our privacy policy. A lawyer is reviewing it, and the final version will add our registered company details and data protection contact. If anything here is unclear, write to [email protected].
This policy explains how Laarpi ("we", "us") handles personal data when you visit laarpi.com, use the Laarpi studio, publish sites, list them in the community, or ask our team to build a site through Build with experts. It sits alongside our terms of service.
The short version: we collect what we need to run the agent and your account, we send your project to AI model providers so the agent can work, payments for your Laarpi plan go through Polar, your own site's data goes to your own Supabase and Polar accounts, and we don't sell personal data to anyone.
What we collect
Your account. Your name, email address, and either a password (we store only a secure hash of it) or the basic profile Google or GitHub shares when you sign in with them, such as your name, email and avatar. When you sign in, we record the session along with its IP address and browser details, so we can keep you signed in and spot misuse.
Your projects. What you write to the agent and your answers to its questions, the plan it writes, the files of your site and every saved version, reference images you upload, and the screenshots the agent takes of your site to check its own work. We also record each agent turn: when it ran, whether it finished, and how much it used, so we can meter credits.
Billing. Your plan, billing period, seat count and credit balance, and a record of every credit movement. Payments are handled by Polar, which acts as merchant of record. Polar collects your payment details and billing address; we never see your full card number. Polar shares with us what we need to run your plan, such as your subscription status and billing country.
Connected accounts. If you connect Supabase or Polar to a project, we store the access tokens they give us, encrypted, plus the details needed to wire your site: for example, your Supabase project's address and public key, or your Polar product and checkout links.
Community listings. If you list a site, its title, description, tags and cover image, and your display name and avatar, become public. For view counts, we combine the visitor's IP address, browser string and the date into a keyed one-way hash and store only that hash with the date. We do not store the IP address or browser string for a view.
Build with experts. If you fill in the experts form, we collect what you give us: your name, email, company, your idea, the type of site, budget and timeline ranges, reference links and, if you choose, a phone or WhatsApp number. We also record the country your request came from.
Your region. To show the right prices, we read the country your request comes from, as reported by our hosting provider. We use it for pricing only.
When you contact us. The emails you send and our replies.
Basic usage data. Our servers keep standard request logs for security, debugging and abuse prevention. We may use privacy-friendly analytics that do not use cookies or build profiles of individual visitors, to understand which pages are useful and where people get stuck.
How we use it
- To run Laarpi: sign you in, run the agent, build and preview your sites, publish them, and keep your versions.
- To bill you: manage your plan, meter credits, and handle refunds with Polar.
- To keep Laarpi safe: prevent abuse, fraud and attacks, enforce the terms, and investigate problems.
- To support you: answer questions and fix issues in your account.
- To improve Laarpi: understand, in aggregate, how the product is used and where the agent falls short.
- To talk to you: send messages about your account, billing, security and significant changes. We won't send marketing emails unless you've agreed to them, and you can stop them at any time.
Where data protection law asks for a legal basis, we rely on performing our contract with you (running the service you signed up for), our legitimate interests (security, fraud prevention and improving the product, balanced against your rights), legal obligations (tax and accounting records), and your consent where we ask for it.
How the AI processing works
Laarpi's agent is powered by AI models from third-party providers, such as Anthropic and OpenAI. To do its work, the agent sends them what it needs for each turn: your messages and answers, the plan, the relevant files of your site, reference images you uploaded, and screenshots of your site.
We use these providers under their commercial API terms, under which, by default, they don't use the data we send to train their models. They may keep it for a limited time to operate their service and prevent abuse, under their own policies.
We don't use your private projects to train AI models. Don't put anything into a project that you aren't comfortable having processed this way, such as passwords, card numbers or other people's sensitive personal data.
Your site's data lives in your accounts
When Laarpi connects your site to Supabase and Polar, those are your accounts. Sign-ups, profiles, form submissions, orders and payments from your site's visitors go to your Supabase project and your Polar account, not to us. For that data, you decide what is collected and why, and you are responsible for your site's own privacy notice. Laarpi acts on your instructions to set up those accounts, using the access you granted, and you can revoke it at any time.
When people visit a site published through Laarpi, our hosting serves the pages and keeps standard request logs. Published sites load open-source libraries, such as three.js and GSAP, from a public content delivery network (jsDelivr), so visitors' browsers also connect to that network to fetch them. Read more about how the backend works on the website backend page.
Who we share it with
We share personal data only with the services that help us run Laarpi, and only what each one needs:
| Who | Why |
|---|---|
| AI model providers, such as Anthropic and OpenAI | To run the agent on your projects |
| Polar | To sell and bill your Laarpi plan, as merchant of record |
| Hosting, database and storage providers | To run the app, store your projects and serve your published sites |
| Google and GitHub | Only if you choose to sign in with them |
| Supabase and Polar (your accounts) | To set up your site's backend, on your instructions |
| Our team chat tool | To alert our team when you send a Build with experts request |
| Privacy-friendly analytics, if enabled | To count page use without cookies or personal profiles |
We may also disclose data when the law requires it, to protect people's safety or our rights, or as part of a merger or sale of the business, in which case this policy would continue to protect your data. We do not sell your personal data, and we do not share it for advertising.
Cookies and similar storage
We keep this small.
| Name | What it does | How long |
|---|---|---|
| Sign-in session cookie | Keeps you signed in to the studio | Up to 30 days, refreshed as you use Laarpi |
laarpi_region | Remembers the currency you chose for prices: US dollars, euros or Indian rupees | 1 year |
laarpi_india_banner | Remembers that you closed the India pricing banner | 30 days |
The studio also saves small interface preferences in your browser's local storage, such as the width of a panel. We don't use advertising or cross-site tracking cookies. Sites you publish may set their own cookies, for example for sign-in through your Supabase project; that is part of your site's own privacy notice.
How long we keep it
| Data | How long |
|---|---|
| Account, projects, versions and published sites | While your account is open. Deleted within 30 days of deleting your account; backups roll off within a further 35 days |
| Sign-in sessions | Until they expire, up to 30 days after last use |
| Billing and credit records | As long as tax and accounting law requires, often 6 to 10 years |
| Connected account tokens | Until you disconnect the account or delete the project |
| Community view hashes | Kept only to count views once a day per visitor; never linked to you |
| Build with experts requests | For the project, then up to 2 years after our last contact, unless you become a client |
| Server request logs | Up to 30 days, longer only when investigating abuse |
Remixes that other people made of a site you listed are their projects, and stay with them if you delete your account.
Security
We encrypt data in transit, store connected account tokens encrypted at rest and never send them to the browser, and serve generated sites from separate domains from the Laarpi app, so a site's code can't act as you in your account. Tables Laarpi creates in your Supabase project have row-level security switched on. No system is perfectly secure; if you find a vulnerability, please write to [email protected].
International transfers
Our providers may process data in countries other than yours, including the United States. Where the law requires it, we rely on safeguards such as standard contractual clauses for those transfers.
Your rights
Depending on where you live, including under the EU and UK GDPR, India's Digital Personal Data Protection Act and US state privacy laws, you can ask to:
- see the personal data we hold about you and get a copy;
- correct it;
- delete it;
- take your data elsewhere;
- object to or limit some uses, and withdraw consent you've given;
- nominate someone to exercise your rights if you can't.
Email [email protected] from the address on your account. We may need to confirm it's you. We'll answer within the time the law sets, and within 30 days at most. You can also complain to your local data protection authority.
Children
Laarpi is not for children. You need to be at least 16 to use it. If you think a child has given us personal data, tell us and we'll delete it.
Changes to this policy
We'll update this policy when Laarpi changes. If a change is significant, we'll tell you by email or in the studio before it takes effect. The date at the top shows the last update.
Contact
Privacy questions and requests: [email protected]. More ways to reach us are on the contact page.


