LAYR
Support Get the app

Last updated October 5, 2026.

Privacy, without the fog.

HolyFat UG (haftungsbeschränkt), Maria Föhrenbachstraße 15, 79111 Freiburg, Deutschland.

Privacy and data-rights questions go to support@shopholyfat.com.

In short

Layr shows no advertising, uses no tracking and no analytics, and sells no data. Your avoid list, profiles, journal and journal photos stay on your phone and never reach our servers. What the server keeps is what the app needs to work: your account, what you save, what you contribute, and the logs that keep the service secure.

Using Layr without an account

You can search, scan and check labels without an account. Each request reaches our server with your IP address, the app version and the time; these server logs are kept for up to 30 days to run and secure the service. A label you check is screened and not stored. The app can send an installation key so the server can reject clients that are not the Layr app; it identifies an installation, not a person.

Your account

You sign in with Apple or Google. We receive and store the account identifier from that provider, your email address (or Apple's relay address) and, if the provider sends one, a display name. We store your sessions and a record of sign-in events with IP address and device information, to protect the account. We store what you choose to keep in Layr: saved products, shelves and the settings you change, for example change alerts.

Contributions

When you add or correct a product, we store the product details, identifiers, label text, the photos you take, the review history and the points it earns. After review, accepted product facts are published in the catalogue without your name. Photos of a contribution that is never completed are deleted automatically.

Notifications

If you turn notifications on, we store a push token with your platform and app version. Notifications are delivered through Expo's push service (650 Industries, Inc., USA) and then Apple Push Notification service or Firebase Cloud Messaging. You can turn them off in the app or in your phone's settings; the token is then disabled.

Purchases and codes

Purchases. If you buy Layr Premium, the Apple App Store or Google Play takes the payment; we never see your payment details. RevenueCat, Inc. (USA) processes on our behalf, as our processor, an opaque purchase id, your store purchase history and the store's country, so the app and our server know whether Premium is active. No name, email address or health information is sent for this. Transfers to the United States rely on the EU–US Data Privacy Framework or the European Commission's standard contractual clauses. When you delete your account, the purchase record at RevenueCat is deleted too.

If you redeem a Layr Premium code, we store the code and the date it was redeemed with your account. The partner that issued the code learns only whether and when it was redeemed, nothing else about you.

What stays on your phone

Your avoid list and profiles, the journal, its photos and goals, the Offline Cabinet and the data shown in widgets are stored only on your phone. They are not sent to our servers, not backed up by us, and not used to profile you. Your phone's own backup (for example iCloud) may include them under your settings there.

Security and errors

The app can send an installation key so the server can reject clients that are not the Layr app. The key identifies an installation, not a person. Deleting an account revokes the installations linked to it.

If a reporting destination is configured, the server sends the exception class, a short message, and the request id. It is off unless that destination is set. It is not used for advertising.

Legal bases

We process account, saved and contributed data to provide the service you asked for (Art. 6(1)(b) GDPR). Server logs, sign-in records, the installation key and abuse protection rest on our legitimate interest in a secure, reliable service (Art. 6(1)(f) GDPR). Notifications are sent only with your consent, which you can withdraw at any time (Art. 6(1)(a) GDPR). Purchase records are kept to provide Premium and as tax and commercial law requires (Art. 6(1)(b) and (c) GDPR).

Who processes data for us

Hetzner Online GmbH (Germany) hosts the server in its data centre in Helsinki, Finland, and stores our encrypted backups there. RevenueCat, Inc. (USA) processes purchase status. Expo (650 Industries, Inc., USA) delivers notifications. Apple and Google act as independent controllers for sign-in, app distribution, payments and push delivery under their own terms. Each processor acts on our instructions under a data processing agreement. Transfers to the United States rely on the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.

How long we keep data

Account data is kept while the account exists. Deleting the account removes your identity, sessions, saved products, push tokens and purchase record; accepted product facts remain without any link to you. Expired sessions are deleted 30 days after they expire, sign-in records after one year, server logs after 30 days, and backups after 30 days. Records that tax or commercial law requires us to keep are kept for the period the law sets.

Your rights

You have the right to access your data, to have it corrected or erased, to restrict its processing, to receive it in a portable format, and to object to processing based on legitimate interest. Export and deletion are available directly in the app. Where processing rests on consent, you can withdraw it at any time without affecting what happened before. You can also complain to a data protection authority, for example the one responsible for us: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart.

Export and deletion are available in the app. Each one is recorded. Export is limited to the most recent 200 submissions, the most recent 200 points, and the most recent 200 sign-in events, and the response says when it was cut short. Accepted product evidence can remain in the public index after deletion, without the account attached.

Changes to this policy

We update this page when the service changes. The date at the top shows the current version; material changes are announced in the app before they apply.