Legal

Privacy Policy

How Laarpi handles personal data, in plain language: what we collect, how the agent's AI processing works, what lives in your own accounts, the few cookies we set, how long we keep things, and your rights. Draft pending legal review.

Updated

Draft, pending legal review. This is a plain-language draft of our privacy policy. A lawyer is reviewing it, and the final version will add our registered company details and data protection contact. If anything here is unclear, write to [email protected].

This policy explains how Laarpi ("we", "us") handles personal data when you visit laarpi.com, use the Laarpi studio, publish sites, list them in the community, or ask our team to build a site through Build with experts. It sits alongside our terms of service.

The short version: we collect what we need to run the agent and your account, we send your project to AI model providers so the agent can work, payments for your Laarpi plan go through Polar, your own site's data goes to your own Supabase and Polar accounts, and we don't sell personal data to anyone.

What we collect

Your account. Your name, email address, and either a password (we store only a secure hash of it) or the basic profile Google or GitHub shares when you sign in with them, such as your name, email and avatar. When you sign in, we record the session along with its IP address and browser details, so we can keep you signed in and spot misuse.

Your projects. What you write to the agent and your answers to its questions, the plan it writes, the files of your site and every saved version, reference images you upload, and the screenshots the agent takes of your site to check its own work. We also record each agent turn: when it ran, whether it finished, and how much it used, so we can meter credits.

Billing. Your plan, billing period, seat count and credit balance, and a record of every credit movement. Payments are handled by Polar, which acts as merchant of record. Polar collects your payment details and billing address; we never see your full card number. Polar shares with us what we need to run your plan, such as your subscription status and billing country.

Connected accounts. If you connect Supabase or Polar to a project, we store the access tokens they give us, encrypted, plus the details needed to wire your site: for example, your Supabase project's address and public key, or your Polar product and checkout links.

Community listings. If you list a site, its title, description, tags and cover image, and your display name and avatar, become public. For view counts, we combine the visitor's IP address, browser string and the date into a keyed one-way hash and store only that hash with the date. We do not store the IP address or browser string for a view.

Build with experts. If you fill in the experts form, we collect what you give us: your name, email, company, your idea, the type of site, budget and timeline ranges, reference links and, if you choose, a phone or WhatsApp number. We also record the country your request came from.

Your region. To show the right prices, we read the country your request comes from, as reported by our hosting provider. We use it for pricing only.

When you contact us. The emails you send and our replies.

Basic usage data. Our servers keep standard request logs for security, debugging and abuse prevention. We may use privacy-friendly analytics that do not use cookies or build profiles of individual visitors, to understand which pages are useful and where people get stuck.

How we use it

  • To run Laarpi: sign you in, run the agent, build and preview your sites, publish them, and keep your versions.
  • To bill you: manage your plan, meter credits, and handle refunds with Polar.
  • To keep Laarpi safe: prevent abuse, fraud and attacks, enforce the terms, and investigate problems.
  • To support you: answer questions and fix issues in your account.
  • To improve Laarpi: understand, in aggregate, how the product is used and where the agent falls short.
  • To talk to you: send messages about your account, billing, security and significant changes. We won't send marketing emails unless you've agreed to them, and you can stop them at any time.

Where data protection law asks for a legal basis, we rely on performing our contract with you (running the service you signed up for), our legitimate interests (security, fraud prevention and improving the product, balanced against your rights), legal obligations (tax and accounting records), and your consent where we ask for it.

How the AI processing works

Laarpi's agent is powered by AI models from third-party providers, such as Anthropic and OpenAI. To do its work, the agent sends them what it needs for each turn: your messages and answers, the plan, the relevant files of your site, reference images you uploaded, and screenshots of your site.

We use these providers under their commercial API terms, under which, by default, they don't use the data we send to train their models. They may keep it for a limited time to operate their service and prevent abuse, under their own policies.

We don't use your private projects to train AI models. Don't put anything into a project that you aren't comfortable having processed this way, such as passwords, card numbers or other people's sensitive personal data.

Your site's data lives in your accounts

When Laarpi connects your site to Supabase and Polar, those are your accounts. Sign-ups, profiles, form submissions, orders and payments from your site's visitors go to your Supabase project and your Polar account, not to us. For that data, you decide what is collected and why, and you are responsible for your site's own privacy notice. Laarpi acts on your instructions to set up those accounts, using the access you granted, and you can revoke it at any time.

When people visit a site published through Laarpi, our hosting serves the pages and keeps standard request logs. Published sites load open-source libraries, such as three.js and GSAP, from a public content delivery network (jsDelivr), so visitors' browsers also connect to that network to fetch them. Read more about how the backend works on the website backend page.

Who we share it with

We share personal data only with the services that help us run Laarpi, and only what each one needs:

WhoWhy
AI model providers, such as Anthropic and OpenAITo run the agent on your projects
PolarTo sell and bill your Laarpi plan, as merchant of record
Hosting, database and storage providersTo run the app, store your projects and serve your published sites
Google and GitHubOnly if you choose to sign in with them
Supabase and Polar (your accounts)To set up your site's backend, on your instructions
Our team chat toolTo alert our team when you send a Build with experts request
Privacy-friendly analytics, if enabledTo count page use without cookies or personal profiles

We may also disclose data when the law requires it, to protect people's safety or our rights, or as part of a merger or sale of the business, in which case this policy would continue to protect your data. We do not sell your personal data, and we do not share it for advertising.

Cookies and similar storage

We keep this small.

NameWhat it doesHow long
Sign-in session cookieKeeps you signed in to the studioUp to 30 days, refreshed as you use Laarpi
laarpi_regionRemembers the currency you chose for prices: US dollars, euros or Indian rupees1 year
laarpi_india_bannerRemembers that you closed the India pricing banner30 days

The studio also saves small interface preferences in your browser's local storage, such as the width of a panel. We don't use advertising or cross-site tracking cookies. Sites you publish may set their own cookies, for example for sign-in through your Supabase project; that is part of your site's own privacy notice.

How long we keep it

DataHow long
Account, projects, versions and published sitesWhile your account is open. Deleted within 30 days of deleting your account; backups roll off within a further 35 days
Sign-in sessionsUntil they expire, up to 30 days after last use
Billing and credit recordsAs long as tax and accounting law requires, often 6 to 10 years
Connected account tokensUntil you disconnect the account or delete the project
Community view hashesKept only to count views once a day per visitor; never linked to you
Build with experts requestsFor the project, then up to 2 years after our last contact, unless you become a client
Server request logsUp to 30 days, longer only when investigating abuse

Remixes that other people made of a site you listed are their projects, and stay with them if you delete your account.

Security

We encrypt data in transit, store connected account tokens encrypted at rest and never send them to the browser, and serve generated sites from separate domains from the Laarpi app, so a site's code can't act as you in your account. Tables Laarpi creates in your Supabase project have row-level security switched on. No system is perfectly secure; if you find a vulnerability, please write to [email protected].

International transfers

Our providers may process data in countries other than yours, including the United States. Where the law requires it, we rely on safeguards such as standard contractual clauses for those transfers.

Your rights

Depending on where you live, including under the EU and UK GDPR, India's Digital Personal Data Protection Act and US state privacy laws, you can ask to:

  • see the personal data we hold about you and get a copy;
  • correct it;
  • delete it;
  • take your data elsewhere;
  • object to or limit some uses, and withdraw consent you've given;
  • nominate someone to exercise your rights if you can't.

Email [email protected] from the address on your account. We may need to confirm it's you. We'll answer within the time the law sets, and within 30 days at most. You can also complain to your local data protection authority.

Children

Laarpi is not for children. You need to be at least 16 to use it. If you think a child has given us personal data, tell us and we'll delete it.

Changes to this policy

We'll update this policy when Laarpi changes. If a change is significant, we'll tell you by email or in the studio before it takes effect. The date at the top shows the last update.

Contact

Privacy questions and requests: [email protected]. More ways to reach us are on the contact page.

Questions

Fair questions

Do you train AI models on my projects?

No. We don't use your private projects to train AI models, and we use our AI model providers under API terms where, by default, they don't train their models on the data we send.

Can Laarpi see my customers or my revenue?

Not in the normal course of things. Sign-ins, form data and orders from your site go to your own Supabase and Polar accounts. Laarpi holds an encrypted access token so it can set those accounts up on your instructions, and you can revoke it at any time.

What cookies does Laarpi use?

A sign-in cookie so you stay logged in, and two small preference cookies on the marketing site: your pricing region and whether you closed the India pricing banner. No advertising cookies.

How do I delete my account?

Email [email protected] from the address on your account. We delete your account and projects within 30 days, unpublish your sites and remove your community listings. Backups roll off within a further 35 days.

How are community views counted without tracking me?

We combine your IP address, browser and the date into a keyed one-way hash, store only that hash for the day, and count it once. We never store the IP address or browser string for a view.

Is this the final privacy policy?

No. It is a plain-language draft pending legal review. The reviewed version will add our registered company details and data protection contact, and we will tell you before it takes effect.

Related

Start building

Describe the site in a sentence. It asks what matters, then designs and builds it from scratch.

One sentence is enough.