Skip to content
Laver
Home Features Pricing Docs
Sign in Start free

What we hold, and why

Privacy Policy.

Laver is a place to keep your team's work. This explains what we collect, what we do with it, who else sees it, how long we keep it, and how to take it away.

Effective date 2 August 2026

Questions about your data?
support@developyn.com

On this page

  1. Who we are
  2. What we collect
  3. Website analytics
  4. Cookies and local storage
  5. Why we may hold it
  6. Who else sees it
  7. How long we keep it
  8. Your rights
  9. How we protect it
  10. Children
  11. Changes and contact

01

Who we are

Laver is operated by Developyn Ltd, registered in England and Wales at 42 Kittiwake Drive, Brierley Hill, DY5 2QJ. For the personal data described here, Developyn Ltd is the data controller. You can reach us at support@developyn.com.

Where you use Laver for an organisation, that organisation decides what work content goes into its workspaces and who may see it. For that content, the organisation is the controller and we act on its instructions.

02

What we collect

Your account. Your first and last name, email address, and a hash of your password — the password itself is never stored, and the hash cannot be reversed. Optionally a phone number and a profile picture, if you add them. If you turn on two-factor authentication, a secret for your authenticator app and hashes of your backup codes.

Your work. Everything you put into Laver: workspaces, boards, tickets and their comments, subtasks, labels, sprints, wiki pages and their version history, and any files you attach. We treat this as yours. We do not read it except when you ask us to look at something, or where we must to keep the service running, safe or lawful.

Billing. Your plan, billing interval, seat count and the identifiers Stripe gives us for your customer and subscription records. Card details never reach our servers — they go directly to Stripe.

Security and audit records. Sign-ins, password and email changes, session revocations, and similar account events, so that you and we can see what happened to an account.

Technical logs. Our servers log requests, including IP address and browser user-agent, to run and secure the service.

03

Website analytics, without following you

We count visits to our public pages. Each page view records the path, the host of the referring site (never the full referring URL, which can carry the words somebody typed into a search box), a campaign source if a link carried one, and a visitor hash.

That hash is a SHA-256 of the current date, a server-side secret, your IP address and your user-agent, truncated. It lets us recognise two page views on the same day as one browser. It rotates at midnight, so views on different days cannot be joined together at all, and it cannot be turned back into an IP address. Your IP address itself is not stored in the analytics table.

There is no cookie, no third-party analytics service, and no advertising or profiling. That is why Laver has no cookie banner: there is nothing to consent to.

04

Cookies and local storage

Laver sets no tracking cookies. It does keep a small amount of data in your browser's local storage so that you stay signed in and the app remembers how you left it. That is covered in full, key by key, in our Cookie Policy.

05

Why we are allowed to hold it

Most of what we hold, we hold to perform our contract with you: your account, your workspaces and their content, and the billing records that go with a paid plan.

Security records, technical logs and the aggregate analytics above rest on our legitimate interests in keeping the service available, keeping accounts safe from people who should not be in them, and understanding which of our pages are useful. We have weighed those interests against your privacy; the analytics design above is the result.

Where we must keep records to satisfy tax or accounting rules, we rely on our legal obligations. We do not rely on consent for anything described here, and we do not sell personal data or use it for advertising.

06

Who else sees it

Other members of your workspace see the work you put in it, according to the roles and access levels its owners and admins set. That is the point of a shared workspace, and it is worth remembering before you write something in one.

We use a small number of service providers, each for one job:

  • Stripe — payments and subscription billing. Card details go to Stripe rather than to us.
  • Mailgun — sending transactional email (verification, password resets, billing notices), through its European infrastructure.
  • Google Cloud Storage — storing files you upload and profile pictures.
  • DigitalOcean — the servers the application and database run on.

Each is bound by a contract to process data only on our instructions. Where a provider processes data outside the UK, we rely on the appropriate safeguards — the UK Addendum, or the EU Standard Contractual Clauses.

We will also disclose data where the law requires it, and to a buyer if Laver is ever sold — in which case this policy travels with it and we will tell you.

07

How long we keep it

Your account and its content stay while your account is open. If you delete your account, it is closed immediately and scrubbed 30 days later: your name is replaced, and your email, phone number, profile picture, verification codes, reset codes and two-factor secrets are removed.

A stub of the account row survives that scrub on purpose, because tickets, comments and wiki history point at it — removing it entirely would tear holes in a shared workspace's history that other people are relying on. What is left carries no personal data.

Content in a workspace belongs to that workspace, so leaving one does not remove what you wrote in it. Billing records are kept as long as tax and accounting rules require.

08

Your rights

Under UK and EU data protection law you can ask for a copy of your personal data, ask us to correct it, ask us to delete it, ask us to restrict or object to how we use it, and ask for it in a portable form.

Two of those are buttons rather than requests. Export in your profile downloads a JSON file of your account and your content — the workspaces you belong to, your tickets, your assignments and your comments. Delete account starts the process described above. For anything else, write to support@developyn.com and we will answer within one month.

If you think we have handled your data badly, please tell us first — but you can complain to the Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EEA.

09

How we protect it

Passwords are hashed with Argon2. Two-factor authentication is available with an authenticator app and single-use backup codes. Changing your password revokes every existing session, because a password change is the one moment we know the old credential may be in someone else's hands. Sessions have a maximum age they cannot be renewed past.

Traffic is encrypted in transit. Uploaded files are scanned for malware before they are stored. Sensitive endpoints are rate limited, and every request is checked against the workspace it claims to belong to.

No service can promise perfect security. If a breach affects your personal data and is likely to be a risk to you, we will tell you and the regulator within the time the law allows.

10

Children

Laver is for people aged 18 and over and is not directed at children. If you believe a child has given us personal data, tell us and we will remove it.

11

Changes, and how to reach us

If we change this policy we will update the effective date above, and for anything significant we will tell account holders by email before it takes effect.

Write to Developyn Ltd, 42 Kittiwake Drive, Brierley Hill, DY5 2QJ, or email support@developyn.com.

Laver

Work, without the busywork.

Small teams Documentation Terms Privacy Cookies Sign in Create account
© 2026 Developyn. Developyn® is a registered trademark.