Privacy Policy
Last updated: 8 August 2026
This Privacy Policy explains how LayerCall ("LayerCall," "we," "us") collects, uses, and protects information when you use our website and fraud & trust-signals API (the "Service"). We built LayerCall to reduce fraud, and we take a data-minimizing approach: we collect only what we need to run the Service.
Information we collect
- Account information. When you sign up, we store your email address and, if you use Google sign-in, the basic profile information Google provides (name, email). We do not store passwords — authentication is handled by Google or a one-time email link.
- API usage. For each API request we record metadata such as the endpoint called, timestamp, whether the result was cached, and which API key was used, to meter usage and bill accurately.
- Data you send to the API. To score a lookup, you send us values such as an IP address, email, phone number, or domain. We process these to return a risk score. We do not use the raw values you submit to build advertising profiles or sell them.
- Signup risk score. When you create a LayerCall account we run our own fraud check on your signup — the same one we sell — using the email address you registered with and the IP address you registered from. We keep the resulting score, the verdict, and the names of the signals that fired. We do not store a second copy of your email or IP for this purpose; both are already held to operate your account. This runs once, at account creation, and never again on later sign-ins. Our lawful basis is legitimate interest in preventing abuse of our own free tier (GDPR Recital 47 recognises fraud prevention as such an interest). The score is advisory and is not used to automatically refuse or close an account.
- Cookies. We use a single essential cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.
How we use information
- To provide, secure, and improve the Service.
- To authenticate you and protect your account.
- To meter usage, enforce plan limits, and process billing.
- To detect abuse of the Service itself and maintain our fraud-signal accuracy.
- To respond to support requests and send essential service notices.
Our reputation network (privacy by design)
LayerCall maintains a reputation signal built from lookups across the network. Each observed value is stored as a keyed HMAC-SHA256 digest — computed with a secret held outside the database — alongside counters: how often the value was seen, and how many customers reported it as abusive. We do not store the raw IP addresses, emails, phone numbers, or domains.
The key matters, and we would rather explain it than leave it implied. A plain hash is only as strong as the range of values that can go into it, and these ranges are small: there are roughly 4.3 billion IPv4 addresses in total, and phone numbers and registered domains are no more numerous. Anyone holding a table of plain hashes could work through every possible value until the digests matched. Because ours are computed with a secret that is not stored alongside them, that does not work — recovering a value would need both a copy of the database and the key.
We treat these digests as personal data regardless. They are pseudonymised rather than anonymous, and the rights described below apply to them in full.
Data processors we use
We rely on a small number of reputable providers to run the Service:
- Vercel — application hosting.
- Supabase — database and authentication.
- Google — optional sign-in (OAuth).
- Dodo Payments — payment processing for paid plans, acting as merchant of record. Card details are handled by them; we never see or store your card number.
- DB-IP — IP geolocation data.
Data retention
We keep account and usage data for as long as your account is active and as needed to provide the Service, comply with legal obligations, and resolve disputes. You can request deletion of your account and associated data at any time (see "Your rights" below). Reputation-network digests are kept for as long as they remain useful as a fraud signal. They cannot be searched by an email address or an IP on their own, so a deletion request should name the value you want removed and we will compute the digest and delete it.
Security
API keys are stored only as hashes, never in plain text. Data is encrypted in transit (HTTPS). We restrict internal access to production data. No system is perfectly secure, but we design to minimize what could be exposed.
Your rights
Depending on where you live (for example under the GDPR or similar laws), you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise these rights, email us at support@layercall.com and we will respond within a reasonable time.
International transfers
LayerCall is operated from India and uses providers that may process data in other countries. Where required, we rely on appropriate safeguards for international transfers.
Children
The Service is intended for developers and businesses and is not directed to children under 16. We do not knowingly collect data from children.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notifying you.
Contact
Questions about privacy? Email support@layercall.com.