Privacy

Layer recommends what to wear for your run. It uses only the data it needs to do that, never sells your data, and never tracks you across other apps.

Your location

Layer uses your location to fetch local weather and recommend what to wear. It’s used to generate your recommendation, not to profile you, and it’s not linked to your identity for advertising. If you don’t grant location, you can enter a place manually.

Your coordinates go to the weather services that return the forecast: Open-Meteo (the default source) and, as a backup, WeatherAPI.com through our own server, so no key ever ships in the app. To tell you whether it’s raining right now, we also read public radar from RainViewer and, in the United States, the National Weather Service. None of these requests carry your name, email or account — only a location and a time. If you’re signed in on the iOS app, you can optionally switch to Apple Weather (WeatherKit) as your forecast source; Open-Meteo stays the default and the automatic fallback there too.

Your account

Layer uses Sign in with Apple to create your account. You can use Apple’s Hide My Email relay — Layer works fine with it. We store your account identifier and email address to operate your account. If you choose a display name, we store that too. When you’re signed in, your runs, kit, closet items, shoes, preferences and optional gear photos are copied to your private iCloud account. Layer’s team cannot access that private CloudKit data. It lets your data sync between devices and return after you delete and reinstall the app.

Bug reports

When you report a bug, you can choose to include an email address. We use it only to send the report’s reference number and to reply if more detail would help. The address stays with the private raw report and is not copied into the GitHub triage issue. Leaving it blank does not prevent the report from being submitted.

Feature requests

Layer Feedback is a separate public portal. If you sign in there, we store your email for authentication and notifications. Ideas, comments, votes, and display names you publish may be visible to anyone. We also retain limited IP address, browser, and security metadata to prevent abuse and operate the service. Do not post private run, health, or account details.

Feature-request data is processed by Oracle Cloud (hosting), Cloudflare (network security, bot protection, backups), and Resend (authentication and notification email). Deletion requests are handled within 30 days: public content is removed or anonymized, and expired encrypted copies disappear as the backup retention schedule rolls forward.

Help Center search and article feedback

You can read the public Help Center without signing in. When you search it, Layer Feedback stores the search text, a normalized copy, the Help Center language, the number of results, and the time of the search. Search rows are deleted after 90 days. Do not enter private run, health, exact location, account, or authentication details in a search.

If you mark an article helpful or not helpful, Layer Feedback stores that choice, the time, and, when you are signed in, a link to your portal account. You may optionally explain an unhelpful vote; that explanation is cleared after 180 days while the helpfulness choice may remain as anonymous aggregate feedback. Deleting the portal account removes its link from retained article feedback.

Strava (optional)

If you connect Strava, Layer reads your recent runs — start time, sport type, duration, distance, and approximate start location — so each run arrives with the weather it happened in, and your Strava shoes with their mileage. It does not read your heart rate. Those runs and shoes are stored on your device and, while you’re signed in, in your private iCloud account; our backend only exchanges, refreshes and revokes the access token. This is optional — you can skip it and use a default effort baseline, and disconnect it any time, which revokes Layer’s access. Layer never posts to Strava. More on the Strava connection.

Apple Health (optional and read-only)

If you choose Request access in Settings, Layer asks Apple Health for read-only access to completed workout records. It filters those records to completed running workouts and uses only the workout identifier, start and end time, activity type, and source name to match a workout to a run already in your Layer Log. Layer does not read heart rate, route, distance, calories, or other Health data, and it never writes to Apple Health.

Apple Health workout data and the resulting match stay on your device. They are not sent to Layer’s servers, analytics, or any other third party, and are never used for advertising, marketing, or data mining. Access is optional, can be changed in Apple’s Health or Settings app, and Layer remains usable if you decline. Apple intentionally prevents apps from learning whether read access was denied, so Layer does not guess or repeatedly prompt you.

Photos of your gear (optional)

If you add your own gear, Layer uses your camera or photo library to attach a photo, and can save a share card to Photos. Those images belong to your kit, are used to show and name your actual items, and are never sold or used for advertising. When you’re signed in, they are copied to your private iCloud account so they can sync and survive a reinstall.

Pseudonymous usage analytics

Layer records product interactions under a random identifier so we can understand which features work and find failures. The identifier is not your name or email, but it persists between visits on the web app and is therefore pseudonymous rather than anonymous. A safeguard blocks personal content such as your email, name, exact location, notes, photos, Strava activity details, and tokens before an analytics event is sent. The web app may also use masked session replay in the United States and Canada; text you type is masked before it is sent. The iOS app does not record session replay. Analytics is never used to track you across other apps.

Crash diagnostics

The iOS app uses Sentry to report native crashes and a small set of categorized failures so we can find and fix problems. Reports include the app version, build, exception type and stack trace. They do not include your Layer account, analytics ID, device or install ID, location, request URLs, screenshots, screen contents, breadcrumb history, free text or raw error details. Sentry is not used for product analytics or tracking, and Layer disables its performance monitoring, sessions, hangs, network capture, replay, logs and profiling features.

Historical waitlist addresses

The waitlist is closed. If you joined before Layer’s public launch, your email remains with our email provider as a record of that signup and any launch message sent to you. We do not sell it or use it for unrelated marketing, and you can ask us to remove it at any time.

We also use the same anonymous product-interaction analytics described above on layertoday.com. This includes which button you tapped, whether you viewed the demo, the first page path in your tab, sanitized campaign tags, and the hostname of an outside site that referred you. We do not record the referrer’s full URL or its query string. These details are tied to a temporary ID that clears when you close the tab, not to your email or identity, and follow the same no-names, no-location, and no-free-text rule. Links from this site to the web app carry the same campaign tags so we can understand the handoff. App Store links may include Apple’s layer_landing campaign code, but Layer does not join Apple’s campaign reporting to a person or to this temporary analytics ID.

Who processes your data

Layer is run by one person on third-party infrastructure. These are the services that touch any of it, and the only reason each one does:

  • Apple — Sign in with Apple; private CloudKit storage for signed-in runners; Apple Health only when you request read-only completed-workout access; and Apple Weather only when you select it. Apple Health workout data and match evidence are excluded from CloudKit.
  • Supabase — our backend and database: your account identifier, email address, display name and invite. Nothing else is stored there.
  • Open-Meteo, WeatherAPI.com, RainViewer, the National Weather Service — forecasts and live radar, from a location and a time only.
  • Apple Weather (WeatherKit) — only if you’re signed in on the iOS app and choose it as your forecast source in Settings. Same location, same time, no other identifying information.
  • Strava — only if you connect it, and only reading.
  • PostHog — the pseudonymous usage analytics and masked web session replay described above, sent through our own domain rather than to PostHog directly.
  • Flagsmith — feature availability. Layer sends a public environment key to retrieve one global set of on/off switches; it does not send your identity, traits, location, or account data.
  • Sentry — identifier-free native iOS crash diagnostics used only to find and fix app failures.
  • Cloudflare — the small services that exchange your Strava token, carry in-app bug reports, keep spam off the feature portal, and hold encrypted feature-portal backups.
  • Oracle Cloud — hosting for the separate Layer Feedback portal.
  • Vercel — hosting for this site and the web app.
  • Our email providers — bug-report receipts and Layer Feedback authentication and notifications. Resend handles the feedback portal.

What we don’t do

No advertising trackers, no ad SDKs, no cross-app tracking, and no selling your data. The Layer Feedback portal uses a session cookie after magic-link sign-in; Layer does not use it for advertising. Service providers may process data only to provide their documented part of Layer.

Your control

You can export or delete your account in the iOS app. Account deletion removes the Supabase account and the synced Layer data from your private CloudKit zone. Deleting the app removes only the device copy, so signing in after a reinstall can restore the private iCloud copy. Public feedback, bug reports, analytics records, and email-provider records use separate systems; contact help@layertoday.com so we can locate and delete or anonymize records those systems do not remove automatically.

Last updated September 1, 2026 · Questions or deletion requests? See Contact.