Security & Trust

Privacy Policy

Last updated: September 6, 2026

1. Overview

Welcome to Layora ("Service"). We respect your privacy and are committed to protecting the personal data of our users. This Privacy Policy describes how we collect, use, store, and share your information when you access or use Layora, its companion features, and daily scoreboard tracking.

2. Information We Collect

To run the daily study schedules, calendar exports, and leaderboard features, Layora collects and processes limited categories of information:

  • Account Information: We collect your alias/username, email address, and profile details provided during onboarding or sign-in (managed securely via Clerk authentication).
  • GitHub Integration Data: When you provide your public GitHub username, our background sync job periodically queries the official GitHub GraphQL API to fetch the number of daily commits, pull requests, and review contributions. We only store the daily counts and do not read repository contents or code.
  • LeetCode Integration Data: When you provide your public LeetCode username, we fetch public problem submission counts (Easy, Medium, and Hard solves) to compute daily study points.
  • Calendar OAuth Tokens: If you authorize Google Calendar synchronization, we store the OAuth access and refresh tokens securely in our backend database to export your study schedules.
3. How We Use Your Information

We use the collected data for the following essential purposes:

  • Formulating daily rhythm templates and academic schedule planners.
  • Aggregating and posting points on the global scoreboard/leaderboard.
  • Automating scheduling changes and exports to your Google Calendar.
  • Analyzing global progress metrics to improve Layora's features.
4. Data Sharing & Security

We do not sell, rent, or trade your personal information with third parties. Only your public display name, public GitHub/LeetCode usernames, and total aggregated points/contribution counts are visible to other logged-in users on the public scoreboard. All private communication tokens (such as calendar sync variables or session hashes) are encrypted and stored securely.

5. Browser Extension

The Layora Quick Access browser extension for Chrome, Edge, Brave and Firefox is covered by this same policy. It is an optional companion to your Layora account, and it works only after you sign in on this site and press Connect on the Extension page.

  • What it reads: only your own account name and email address, your saved quick launchers, and your course list with their platform and progress. It requests nothing else.
  • What it never reads:your browsing history, your open tabs, or the content of any page you visit. The extension runs a script on exactly one page — Layora's own Extension page — and that script does nothing but pass the pairing token to the extension.
  • Where it sends data: only to Layora at layora239.vercel.app. It contacts no analytics service, no advertiser, and no other third party.
  • What it stores on your device:a pairing token and a cached copy of your own launchers and courses, kept in the browser's local extension storage so the popup opens instantly. Uninstalling the extension deletes both.
  • How pairing works: connecting mints a token tied to your account rather than using your password, which the extension never sees or stores. We keep only a hashed form of that token on our servers, and you can revoke it for any browser at any time from the Extension page.
6. User Rights & Data Erasure

You maintain full ownership of your data profile. You have the right to edit your username mappings, clear active integrations, or wipe all saved account records at any time. Please contact us to request the permanent deletion of your cached parameters, database rows, and sync configurations.

7. Contact Us

If you have any questions or data requests regarding our privacy standards, you can reach out directly via:
Email: vidwathkaranth@gmail.com