Privacy
Effective August 31, 2026 · hosted pilot
Layups Connect is an open-source credential broker. This policy describes the hosted pilot at connect.layups.ai. A self-hosted deployment is controlled by its operator and should publish its own policy.
Data we handle
When you connect a provider account, the hosted pilot may process:
- your verified provider account identifier, such as an email address;
- OAuth access and refresh tokens and the scopes you approved;
- connection status, expiry, revocation, and security audit events; and
- basic request metadata needed to secure and operate the service.
How we use it
We use this data only to establish, secure, refresh, deliver, and revoke the connections you request; to prevent abuse; and to operate and improve the service. We do not sell account data, use it for advertising, or use provider data to train general-purpose AI models.
Google user data
The initial Google capability requests identity information and permission to send mail. Layups Connect stores the resulting OAuth grant but does not read mailbox contents. Any application using a delivered access token remains responsible for its own provider API behavior and user authorization.
Storage and disclosure
OAuth grants are encrypted before storage in a Cloudflare Durable Object. We disclose data only to infrastructure providers acting for us, when required by law, or when needed to protect users and the service. Secrets and provider response bodies are excluded from application audit logs by design.
Control and deletion
You can revoke access in your provider account at any time. During the pilot, email seth@layups.ai to request access to or deletion of your hosted connection data. We may retain limited security records when required for fraud prevention or legal compliance.
Contact
Questions can be sent to seth@layups.ai.