Privacy Policy
Effective Date: July 29, 2026 · Last Updated: July 29, 2026. This policy explains what data FixedLayer Labs collects, why we collect it, how we protect it, and how you can access or delete it — across our website and all our products.
This policy applies to fixedlayer.com and to every FixedLayer Labs product and subdomain, including Traxpense, TrackMyOffice, and ClearMail.
1. Who We Are & What This Policy Covers
This website and its associated applications are operated by FixedLayer Labs(“FixedLayer Labs”, “we”, “us”, “our”), a technology engineering firm. We are the data controller for the personal data described in this policy.
fixedlayer.com showcases our engineering services — AI-powered software, cloud platforms, automation systems, data pipelines, and scalable digital products — and lets visitors read published insights, contact us about a project, and sign in to access client portals, saved project briefs, and personalized content.
This single policy covers the FixedLayer Labs website and all FixedLayer Labs products, including Traxpense (personal finance), TrackMyOffice (workflow automation), and ClearMail (email productivity). Where an individual product processes data that the others do not, this policy calls that out explicitly and the product itself discloses it again at the moment consent is requested.
2. Accounts & Authentication
Some features and products require an account. We offer “Sign in with Google” as our primary authentication method. Authentication is handled by the identity provider — we never see, receive, or store your password. The provider returns an authorization token plus the specific data covered by the permissions you approve.
We request access and data strictly according to each application’s use case, and only the minimum permissions that use case requires. Every permission we request is shown to you on the provider’s own consent screen before any access is granted. By signing in and approving that consent screen, you agree to this Privacy Policy and to our Terms of Service, and you authorize us to access and process the approved data solely to deliver the features you requested. If you do not agree, simply decline the consent screen or do not sign in.
| Category of access | Why we request it |
|---|---|
| Basic identity (name, email, profile picture) | Requested by every FixedLayer Labs application. Gives us your name, email address, and profile picture so we can create your account, securely identify you at each sign-in, prevent duplicate accounts, and send essential service email. |
| Product-specific API access | Requested only by the specific application whose core feature requires it, and only when you actively use that feature. For example, an inbox-cleanup product must be granted mail access in order to list, unsubscribe from, archive, or delete the messages you select. The exact permissions are always named on the consent screen. |
| Anything not needed for the feature | Never requested.We do not ask for permissions “just in case”, and we do not broaden a granted permission without putting you through a fresh consent screen. |
Our commitments regarding account and identity data:
- We access only the data required to provide and improve the user-facing feature you asked for.
- We never sell user data, and we never transfer it for advertising, marketing, credit-scoring, or other unrelated purposes.
- We do not use user data to train, fine-tune, or evaluate generalized or foundational AI/ML models.
- Humans do not read your personal data, except with your explicit consent for a specific support request, where necessary for security or abuse investigations, to comply with applicable law, or on data that has been aggregated and de-identified.
- Authentication tokens are encrypted at rest, scoped to your account, and destroyed when you disconnect or delete your account.
You can review and revoke our access at any time from your identity provider’s account permissions page, or by writing to privacy@fixedlayer.com.
3. Third-Party API Integrations
Certain FixedLayer Labs products integrate with third-party services to deliver their core functionality. For example, ClearMail connects to the Gmail API to help you clean up your inbox, and other products may connect to calendar, productivity, or financial data services.
FixedLayer Labs’ use and transfer of information received from any third-party API adheres to that provider’s terms of service and user data policies. Where applicable — including the Google API Services User Data Policy and its Limited Use requirements — we comply fully.
Concretely, this means data obtained through third-party APIs is used only to provide or improve the user-facing features that are prominent in the requesting application; is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with your notice; is not used or transferred for serving advertising; and is not read by humans except in the narrow circumstances listed in Section 2.
Each product discloses which third-party integrations it uses and what data it accesses at the moment you connect that integration.
4. Information We Collect
4.1 Account and identity data. Your name, email address, profile picture, account identifier, and the timestamps of your sign-ins. Collected when you create an account or sign in.
4.2 Third-party API data. Only the data covered by the permissions you approved, accessed only while you use the relevant feature. Where possible we process this data transiently (in memory, for the duration of your request) rather than storing it. Where a feature genuinely requires storage — for example caching message metadata so a cleanup list loads quickly — we store the minimum fields needed, encrypted, and delete them when you disconnect.
4.3 Product-specific data. Depending on the product you use, we may collect data you enter directly — such as financial transactions in Traxpense, meeting schedules and workflow data in TrackMyOffice, or inbox data in ClearMail. This data is collected only to operate the features you use.
4.4 Content you provide. Contact-form submissions, project briefs, support messages, and any documents you deliberately upload or share with us.
4.5 Technical and usage data. IP address, browser and device type, referring pages, and timestamps, captured in server logs for observability, rate-limiting, DDoS mitigation, and performance benchmarking.
4.6 Payment data. Where a product is paid, payments are handled by our payment processor. We receive confirmation and billing metadata; we never store full card numbers.
We do not knowingly collect special-category data (health, biometric, political, religious, or precise geolocation data), and we ask that you do not submit it through our forms.
5. How We Use Your Information
- Authenticate you and keep your session and account secure.
- Provide the specific features you requested — displaying your name and photo, associating data and settings with your account, and performing the actions you initiate through connected integrations.
- Respond to inquiries, deliver support, and communicate about your project.
- Send essential service notices (security alerts, policy updates, billing). Marketing email is opt-in only and always includes an unsubscribe link.
- Maintain reliability and security: debugging, monitoring, fraud and abuse prevention.
- Comply with legal, tax, and regulatory obligations.
We do not sell or rent personal information, we do not share it with data brokers, and we do not use it for cross-context behavioural advertising.
6. Legal Bases for Processing
Where the GDPR or UK GDPR applies, we rely on: consent (sign-in with third-party providers, optional integrations, marketing email); performance of a contract (providing the product or service you signed up for); legitimate interests (security, abuse prevention, service improvement, responding to business inquiries); and legal obligation (accounting and lawful requests). You may withdraw consent at any time without affecting processing already carried out.
8. Data Retention
| Data | Retention period |
|---|---|
| Account and profile data | For as long as your account is active; deleted within 30 days of account deletion. |
| Authentication tokens | Until you disconnect, revoke access, or delete your account — then revoked and destroyed immediately. |
| Data obtained via third-party APIs | Processed transiently wherever possible; any cached copy is deleted on disconnect or within 30 days of account deletion. |
| Product data (transactions, workflows, etc.) | For as long as your account is active; deleted within 30 days of account deletion. |
| Contact-form and support messages | Up to 24 months, then deleted or anonymized. |
| Server and security logs | Typically 90 days. |
| Billing and tax records | As long as required by applicable financial law. |
Encrypted backups may retain data for a short additional window before being rotated out.
9. Revoking Access & Deleting Your Data
You are always in control. You can:
- Revoke third-party accessfrom your identity provider’s account permissions page (e.g. myaccount.google.com/permissions for Google). We stop all API access immediately.
- Disconnect integrationsfrom within the application’s account or settings screen, which revokes the token on our side and clears cached data.
- Delete your accountfrom the application’s settings, or by emailing privacy@fixedlayer.com from your registered address. We acknowledge within 5 business days and complete erasure within 30 days, except where law requires us to retain specific records.
- Request an export of your data in a portable, machine-readable format at the same address.
10. Security & Encryption
We approach privacy through strict engineering isolation. Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Authentication tokens and secrets are stored encrypted and never exposed to the browser. We use isolated VPC environments, least-privilege access controls, audit logging, and dependency scanning across our multi-cloud infrastructure, and we operate to SOC 2 readiness standards.
No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant supervisory authority without undue delay and, where required, within 72 hours of becoming aware.
11. International Data Transfers
FixedLayer Labs operates globally and our infrastructure providers may process data in regions outside your own, including India, the European Union, and the United States. Where data leaves the EEA, UK, or another restricted region, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses together with technical measures including encryption and access control.
12. Your Privacy Rights (GDPR / CCPA / DPDP)
Depending on where you live, you may have the right to: access the personal data we hold about you; correct inaccurate data; delete your data; restrict or object to processing; withdraw consent; receive your data in a portable format; and lodge a complaint with a supervisory authority.
California residents (CCPA/CPRA):you may request disclosure of the categories and specific pieces of personal information collected, request deletion or correction, and opt out of “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are defined, and we will never discriminate against you for exercising a right.
India (DPDP Act, 2023): you may access, correct, and erase your data, nominate another individual to exercise your rights, and raise a grievance with us before escalating to the Data Protection Board.
To exercise any right, email privacy@fixedlayer.com. We verify identity through your registered email address and respond within 30 days, free of charge.
14. Children’s Privacy
Our services are intended for users aged 16 and older (18 where required by local law) and are not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@fixedlayer.com and we will delete it promptly.
15. Zero AI/LLM Training Guarantee
Any documentation, codebases, API schemas, proprietary datasets, or personal data shared with us — whether during discovery, architectural scoping, or ordinary product use — is strictly protected. We explicitly guarantee that your data will never be used to train, fine-tune, or evaluate public or private foundational AI or LLM models, either by us or by any sub-processor acting on our behalf.
Every consultation initiated through our contact channels is treated with the same confidentiality as a formally executed Non-Disclosure Agreement. If your legal counsel requires a bespoke framework or a Data Processing Agreement before technical discovery, contact legal@fixedlayer.com.
16. Changes to This Policy
We may update this policy as our products evolve. The “Last Updated” date at the top always reflects the current version. For material changes — particularly any change to the data we request or how we use it — we will notify you by email or an in-product notice before the change takes effect, and where required we will ask for renewed consent.
17. Contact Us
Questions, requests, or complaints about privacy? We answer every message.
Privacy & data requests
privacy@fixedlayer.comLegal, DPA & compliance
legal@fixedlayer.comProduct support
support@fixedlayer.comEntity
FixedLayer Labs — data controller for fixedlayer.com and all FixedLayer Labs products.
— 08 / If you got this far
Tell us what's slow, broken, or impossible on your stack.
We'll read it personally, and reply within a working day with whether we think we're the right team for it. If we're not, we'll tell you who probably is.