Laalten Studio

Privacy

Last updated 27 July 2026

The short version. Signing in stores your Google account's email, name and profile picture. Exporting a design publishes it to the community library, where other signed-in users can see it. There are no analytics, no tracking pixels, no advertising, and no third-party trackers of any kind on this site. Nothing is ever sold or shared for marketing. To have everything deleted, email hello@laalten.com.

What is stored, and why

When you sign in with Google

Google returns a signed token identifying you. From it we store your Google account identifier, your email address and whether Google has verified it, your display name, and the URL of your profile picture. We also record when the account was created and the time of your most recent sign-in. This is what lets the studio know who you are across visits and check your access against the beta invite list.

We never see and never receive your Google password. That exchange happens entirely on Google's own domain.

If you are not on the beta invite list

Your email address and name are recorded on a launch list, along with the date. It is used for exactly one message — a note on the day Laalten opens to the public — and the sign-in screen tells you this has happened at the moment it does. Ask us to remove it at any time and it is gone.

Designs you export

Exporting a design publishes it to the community library. The design's parameters, its name and any description or tags you add are stored and are visible to other signed-in users, who can view and download it. Exporting the same design again adds a new version to the same entry rather than creating a second one. If you do not want a design to be public, do not export it — designing, including everything you do in the studio itself, involves no server and stores nothing.

Photos you upload

If you attach photos of a finished print to one of your designs, those images are stored and shown alongside it. Only you can add photos to your own designs, and you choose whether to add any at all.

Export records

Each export attempt is logged: the format, the quality setting, a hash and the byte size of the design, whether it succeeded or was refused, the reason if it was refused, how long it took, and the time. These exist to enforce daily limits and to let us diagnose failures — the two bugs fixed most recently on this site were found in exactly this log.

Feedback you send

If you submit feedback from inside the studio, we store your message, the email address attached to it, and — so a bug report is actionable — the design you were working on and basic technical context about your session.

Settings

Your studio preferences are stored against your account so the studio opens the way you left it.

Cookies

One cookie: a session cookie that keeps you signed in. It holds a signed session reference, nothing else. It is marked HttpOnly, Secure and SameSite, so it cannot be read by scripts and is not sent from other sites.

There are no analytics cookies, no advertising cookies, and no third-party cookies. This is why you are not shown a cookie banner: there is nothing to consent to beyond the cookie that signs you in.

Your browser's local storage also holds a couple of small flags — whether you have entered the studio before, and whether you have already been added to the launch list — so you are not asked the same thing on every visit. These stay on your machine and are never transmitted.

Who else sees any of this

Google, for sign-in only. When you use Sign in with Google, that interaction is subject to Google's own privacy policy.

Our hosting provider, which operates the server the application and its database run on, in the ordinary course of providing that server.

That is the complete list. There are no analytics providers, no advertising networks, no data brokers, no marketing platforms, and no AI training pipelines. Your data is not sold, rented, or shared for anyone's marketing, ours included.

How long it is kept

Account data is kept while your account exists. Launch-list entries are kept until the launch email is sent or you ask for removal, whichever comes first. Export records are kept as operational logs. Published designs remain in the library until you delete them or ask us to.

Your choices

All of these go to hello@laalten.com. Requests are handled by the person who built the site, so no ticket system stands between you and the answer.

Security

The site is served over HTTPS only. Sign-in tokens are verified against Google on the server, session cookies are signed and scoped, and access to the underlying server is restricted. No system is perfect; if you find a security problem, please write to hello@laalten.com and we will take it seriously.

Children

Laalten is not directed at children under 13 and we do not knowingly collect their data.

Changes

If this policy changes in a way that affects what is collected or who sees it, the date at the top will change and beta testers will be told directly.

Contact

Questions, deletion requests, or anything else about this policy:

hello@laalten.com