lAvArt

Privacy Policy

What we hold, who else sees it, where it lives, and how to get it back or have it removed. Written from the code, not from a template.

Last updated

1Who we are

lAvArt is operated by LAS LEICESTER LTD, a company registered in England and Wales, number 15207933, based in Leicester, United Kingdom.

For questions about this policy, or to make any request described in it, email info@lavart.ai. A person reads that address.

2Two kinds of people, two different roles

This is the part most policies skip, and it decides everything below.

You, the studio. When you sign up, we decide what to collect and why. We are the controller of your account data.

Your clients. When you add a client and send them a quote, we hold their name, their email address and a record of when they opened your document — but we hold it because you asked us to, on your instructions. For that data you are the controller and we are your processor. Your client never signed up with us and, in most cases, has never heard of us. We treat that as a reason for restraint, not a loophole.

There is one honest exception, and we would rather write it here than have you find it: when you use AI drafting, your client’s name is included in the text we send our AI supplier (section 5). That was our design decision, not your instruction.

3What we hold about you

DataWhy
Email address and passwordTo sign you in. Passwords are handled by our authentication provider and we never see or store them ourselves. If you sign in with Google or Microsoft we receive your email address and name from them, and no password exists.
Your name and studio detailsYour practice name, address, logo, branding and document settings — because they print on the documents you send.
Your documentsQuotes, invoices, line items, saved blocks and templates. This is the product.
Subscription statusWhich plan you are on and whether it is active. Card details are handled entirely by Stripe and never reach us.
Usage countsHow many quotes and AI generations you have made this month, so plan limits can be applied.

4What we hold about your clients

DataWhy
Name and email addressYou enter them. They print on the document and address the email.
Phone, address, currencyOptional fields you may fill in.
When they opened itOpening a quote or invoice link records the date, so you can tell whether it arrived. A date only — not their IP address, their device, or their location.
Their replyIf they accept, request changes or decline, we store that choice and any note they leave, up to 600 characters. We email it to you.

We do not use your clients’ details for anything except producing and delivering your documents. We never market to them, and we never contact them on our own account.

5AI drafting, and what we send

When you press Draft scope, Suggest line items or Polish, we send your brief to Anthropic’s Claude API. The text we send includes your practice name, the project title, the discipline and project type, the RIBA stages on your lines, the brief you typed — and your client’s name. Polishing also sends the scope text being polished, and your house-style note if you have set one.

Anthropic does not train its models on data submitted through its API. We do not train any model on your content, and we never will without asking you first, in plain terms, and letting you say no.

If you would rather your client’s name never left the platform, write the brief without it — the drafting works fine with “the client”.

6Who else touches the data

Everyone on this list, and nobody else. Each is bound by its own contract with us to process data only on our instructions.

WhoWhat they receive
SupabaseThe database, file storage and sign-in. Everything described above is stored here.
VercelHosting for this website and the product, plus request logs. Also page-view analytics — see section 8.
RenderOur PDF service. It receives the full content of a document each time one is rendered, produces the file and keeps no copy. Like any web service it writes request logs, which record that a render happened rather than what was in it.
AnthropicThe AI prompt described in section 5 — including your client's name.
ResendEmail delivery. Receives your client's email address and the contents of the message: the document total, the links, and any note your client wrote back to you.
StripeYour own subscription to lAvArt: your studio name, your email, and your card details, which go to Stripe directly and never through us. Your clients are never sent to Stripe, and neither are your fees.
SentryError reports from the product and the PDF service, so we can fix faults. Configured not to attach personal data, and session recording is switched off.
Google FontsOur PDF service fetches the typefaces it prints with. Google sees a request for a font from our server — no document content, and nothing about you or your client.

7Where your data lives

Our database and file storage are hosted by Supabase in Tokyo, Japan (AWS ap-northeast-1). Our web hosting and email delivery run in the United States and the European Union.

That means personal data is transferred outside the United Kingdom. The UK Government recognises Japan as providing an adequate level of data protection, so no additional safeguard is required for that transfer. Transfers to our other suppliers rely on the UK International Data Transfer Addendum in our contracts with them.

We would rather this data sat in the UK or the EU, and we intend to move it. When we do, this section will change and we will say so.

8Cookies, and the analytics we do run

We set two cookies. Neither tracks you across other websites.

CookieWhat it does
Sign-in sessionKeeps you signed in. Strictly necessary — the product cannot work without it.
lv-themeRemembers whether you chose the dark or light interface, for a year. A preference, not a tracker.

We use Vercel Web Analytics to count page views on this website and on the signed-in product. It sets no cookie and reads nothing from your device, which is why you are not being asked to consent to one — there is nothing stored on your equipment to consent to. It gives us aggregate counts, not profiles, and we rely on our legitimate interest in knowing whether the site works.

It is deliberately switched off on the pages your clients see. The quote and invoice links your clients open carry no analytics at all. Measuring someone who never signed up, on a page they were sent by you, is not ours to do.

We do not use advertising cookies, tracking pixels, or any third-party marketing tools.

9Links you share, and how private they are

A quote or invoice link contains a long random address. Anyone holding that address can open the document without signing in — that is the point of it, because your client should not need an account to read your quote. It cannot practically be guessed, and it is rate-limited against anyone trying.

It is not, however, a secret once you have sent it. Treat the link the way you would treat the PDF itself: a forwarded email forwards the access.

The rendered PDF is stored privately. Downloads go through a check on our side and are handed out as links that expire within a minute, so a quote link that has passed its Valid until date stops serving the document — including from an email sent months ago. Invoice links do not currently expire.

10How long we keep things

Your documents stay until you remove them. We do not delete a studio’s quotes or invoices on a schedule — they are your business records, and in most jurisdictions you are required to keep them for years.

AI prompts are cleared after about 90 days. The log of what we sent our AI supplier — which contains your brief and your client’s name — has its contents removed after roughly three months, leaving only the date, the type of request and the token count we need to apply your plan limits. We say “about” and “roughly” deliberately: the clearing runs off normal traffic rather than a timer, so on a quiet period a record can outlive the window by a while. We would rather describe that accurately than round it up into a promise.

Deleting your studio deletes everything. When you delete a studio from Settings, the clients, quotes, invoices, templates, saved blocks and stored PDFs go with it, and so does your account. We keep no backup copy to restore you from, which is the honest position rather than the comfortable one.

11Your rights, and how to actually use them

Under UK data protection law you can ask us to:

RightHow
See what we holdSettings → Your data → Download my data gives you everything in one file, immediately. You do not need to ask.
Take it elsewhereThe same file is machine-readable JSON, for the data you gave us.
Delete itSettings → Your data → Delete studio removes everything, immediately and permanently.
Correct itEdit it in the app, or email us if something is wrong that you cannot reach.
Object, or restrictEmail info@lavart.ai. We will reply within 30 days.

If one of your clients asks to be erased, email info@lavart.ai and we will do it by hand within 30 days. There is no button for it yet, and we would rather say so than ship one that quietly fails: a client named on a quote cannot simply be deleted, because the invoice that names them is your accounting record too. What we do instead is remove their identifying details and leave the figures intact.

If you think we have handled your data badly, please tell us first — but you have the right to complain to the Information Commissioner’s Office at any point, and you do not need our permission to do it.

12Security, plainly

Every studio’s data is separated inside the database itself, by rules the database enforces rather than by application code remembering to filter. Traffic runs over HTTPS and browsers are told to refuse anything else. Rendered PDFs are stored privately and reached only through links that expire within a minute. Our pages send a content-security policy that stops a script loading from anywhere but us, and refuse to be embedded in another site. Our PDF service can only reach a small set of destinations on the internet.

Your session cookie is not marked HttpOnly, and we would rather say so than let you assume otherwise. The library we use to keep you signed in reads that cookie from the page itself, so marking it would sign everyone out. It is marked Secure, so it never crosses an unencrypted connection.

Some of our server-side work necessarily runs with elevated database access, as any application’s does — sending an email on your behalf, or letting a client open a link they have no account for. Those paths are the ones we review hardest.

What we do not have: a security certification, an independent penetration test, or a formal incident-response accreditation. We are a small company and we would rather tell you that than imply otherwise. If you find a security problem, email info@lavart.ai and we will take it seriously and credit you if you would like.

13Children

lAvArt is a tool for professional practices. It is not intended for anyone under 18 and we do not knowingly hold data about children.

14Changes

When this policy changes we update the date at the top. If a change materially affects how we handle your data — a new supplier, a new purpose, a new location — we will email you about it rather than quietly editing the page.