Privacy Policy
Last updated 30 September 2026
SharedLayers lets people leave comments pinned to specific places on a web page, through a Chrome extension and a web dashboard. This policy explains what we collect, why, and what you can do about it.
Who is responsible
The data controller is ANY Jacek Troszyński, ul. Stanisława Barańczaka 3a lok. 28, 60-537 Poznań, Poland. For anything in this policy, including requests about your data, write to [email protected].
What we collect
Your account
- Email address, used to sign in, to send you invitations, and to contact you about the service.
- Display name and, if you set one, a profile picture.
- A password, stored only as a cryptographic hash. We never see or store the password itself.
- If you sign in with Google, we receive your email address, name and profile picture from Google. We never receive your Google password, and we ask for no access to Gmail, Drive or any other Google service.
Your comments
- The text of comments and replies you write.
- The address of the page you commented on, and a technical description of the element you pinned it to, which is a CSS selector and coordinates. This is how a comment finds its spot again on your next visit.
- The hostname of sites you create a comment layer for.
- When comments were created, resolved, and which ones you have read.
We do not capture screenshots, page content, form values, or your browsing history. Nothing is recorded on a page unless you place a comment on it.
Invitations
When you invite someone, we store the address you typed so the invitation can be sent and accepted. If they never accept, the invitation expires after seven days.
Guest access
You can join a layer with an access key and a display name, without an account. Guest accounts have no email address attached, and we cannot contact you.
If you buy Pro
Pro is sold by Paddle, our online reseller and merchant of record, so the purchase is made with Paddle, not with us. Paddle collects what it needs to take the payment and issue the invoice, such as your name, email address, country, billing address and payment details. It handles that data as an independent controller under its own privacy policy. We never receive your card or bank details.
From Paddle we receive and keep your Paddle customer and subscription IDs, your plan, its billing period, how many domain blocks it covers, and the dates it renews or ends. We use them to switch your plan on and to show them on your Plan page.
The Plan page in the dashboard loads Paddle's script to show prices and to open the checkout, and the checkout itself is run by Paddle. Paddle may use cookies or similar technology there to process the payment and prevent fraud.
What the extension can do, and what it does
The Chrome extension requests access to all sites. It needs this because a comment can be left on any page you choose, and the permission cannot be narrowed to a list of sites in advance. In practice the extension only reads the address of the current page and the element you click when placing a comment.
It does not read page content, inject anything into pages you have not commented on, or send anything anywhere except to our own service.
Why we are allowed to hold it
| Data | Purpose | Basis (GDPR Art. 6) |
|---|---|---|
| Account details | Give you an account and sign you in | Performance of a contract |
| Comments and layers | Provide the service itself | Performance of a contract |
| Invitation emails | Deliver an invitation you asked us to send | Legitimate interest |
| Service emails | Confirm your address, reset a password | Performance of a contract |
| Subscription details from Paddle | Give you the plan you paid for | Performance of a contract |
Who else processes it
We use a small number of providers, each acting on our instructions:
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | EU |
| Cloudflare | Hosting the website and dashboard, and DNS for sharedlayers.com | Global |
| Resend | Sending email | EU/US |
| Sign in with Google, if you use it | US |
Paddle is not in this table because it does not act on our instructions. As the seller of Pro, it decides for itself how to handle what it collects at checkout (see If you buy Pro above).
We do not sell your data, and we do not share it with advertisers. Transfers outside the EEA rely on the European Commission's Standard Contractual Clauses.
How long we keep it
- Account data: until you ask us to delete it.
- Comments: until you or the layer's owner delete them.
- Deleted layers: hidden from everyone immediately, and erased permanently once the recovery window of seven days has passed.
- Unaccepted invitations: seven days.
- Subscription details: as long as your account exists. Paddle keeps its own records of your purchases, including invoices, for as long as tax law requires.
Your rights
Under the GDPR you may ask for a copy of your data, correct it, delete it, restrict or object to how we use it, or receive it in a portable form. Write to [email protected] and we will respond within one month. You can also complain to your national supervisory authority: in Poland, the President of the Personal Data Protection Office (UODO).
Cookies
We set no advertising or analytics cookies, and use no third-party trackers. To keep you signed in, your browser stores a session token in local storage rather than a cookie. It is required for the service to work and is cleared when you sign out. Paddle's checkout on the Plan page may set cookies of its own, which Paddle's policy covers (see If you buy Pro above).
Children
SharedLayers is not intended for anyone under 16.
Changes
If we change this policy in a way that affects you, we will say so on this page and, where the change is significant, by email.