Layrin
PrivacyTermsSecurityContact

Security & local-first protection

Your original data stays on your device.

Layrin protects sensitive text locally before cloud AI is used. You review the protected version, decide what may be sent, and restore the final response locally. Designed around one boundary: original values and local token mappings do not leave your device.

Effective date: July 19, 2026•Last updated: July 23, 2026
EnglishFrançais

Table of contents

1. Data flow at a glance2. Stays local / leaves the device3. Managed AI transit and storage4. You decide what leaves5. Local token mapping6. Account and access safeguards7. Service-provider details8. Website analytics separation9. Enterprise configurations10. Security has limits11. Responsible use12. Security incident response13. Report a security concern14. Trust summary

1. Data flow at a glance

Layrin’s Pro workflow follows a clear boundary: originals and token mappings stay on the local device; after review, protected content may transit through Priova Intelligence’s managed AI service to the AI provider; restoration happens locally.

  1. Local device

    1

    Local protection

    Original text protected on your device.

  2. Local device

    2

    User review

    You approve what may leave the device.

  3. Priova managed AI

    3

    Priova managed service

    Protected context and instruction only.

  4. AI provider

    4

    AI provider

    Receives protected/tokenized content, not originals.

  5. Priova managed AI

    5

    Tokenized response

    Returned through the managed service.

  6. Local device

    6

    Local restoration

    Originals restored only on your device.

Data flow text equivalent: local protection; user review; Priova managed service; AI provider; tokenized response; local restoration.

2. Stays local / leaves the device

Layrin performs the sensitive-value detection, tokenization, review, correction, and restoration workflow locally in the desktop application.

What stays on your device

  • Original text
  • Original names and confidential values
  • Token-to-original mappings
  • Local token vault
  • Review decisions and manual-hide corrections
  • Restored AI response
  • Local draft state where supported by the desktop application

What is sent during managed AI use

  • Protected context reviewed by you
  • Protected instruction reviewed by you
  • Protected AI response returned with tokens
  • No original token values
  • No local token vault
  • No restored response

3. Managed AI transit and storage

For Layrin Pro, Priova Intelligence’s authenticated managed AI service temporarily processes the reviewed protected context, protected instruction, and tokenized AI response so the provider can generate a result and return it to the desktop app. Original text, local token mappings, and restored content stay on your device. Priova does not log or persistently retain managed-AI content payloads. See the Privacy Policy for provider and retention detail.

4. You decide what leaves

Layrin shows the protected version before sending. You can inspect tokens, keep a value original where appropriate, manually hide additional text, and correct classifications where supported. Sending is a deliberate user action. Automated detection can miss information or classify it incorrectly. The Review step lets you inspect the protected version and manually hide anything else you consider confidential.

5. Local token mapping

Tokens replace original values in the protected text. The mapping between tokens and original values remains local. OpenAI sees tokens, not the mapped originals. The returned response contains tokens, and Layrin uses the local mapping to restore the response on your device. Repeated values may use consistent tokens where supported.

6. Account and access safeguards

Layrin account and managed-access controls use a small set of verified safeguards.

Hashed licence records

Server-side licence records store hashes, not plaintext licence keys.

Hashed desktop sessions

Desktop session identifiers are stored as hashes, not plaintext session tokens.

Short-lived cloud access

Installed users receive short-lived signed cloud-access tokens for managed AI access.

Server-side OpenAI key

OpenAI API keys remain server-side; the desktop app does not contain them.

Entitlement checks

Desktop entitlement is checked before managed AI use.

Aggregate usage only

Usage counters contain aggregate counts, not prompts, user text, responses, or token mappings.

7. Service-provider details

Service providers support hosting, authentication, billing, managed AI routing, security, transactional email, and website measurement where applicable. The complete provider table, including what each provider receives, is maintained in the Privacy Policy.

8. Website analytics separation

Website analytics and advertising technologies are limited to the Layrin marketing website and conversion pages. They are not embedded in the Layrin desktop application and are not used to inspect or transmit user document content. Google Analytics, Meta Pixel, and TikTok Pixel require consent before non-essential activation; advanced matching is disabled at launch, and user-entered text fields are not sent as analytics parameters.

9. Enterprise configurations

Enterprise and customer-managed AI credentials or endpoints are Coming soon / deferred until after the beta. They are not currently available as self-serve Protect or Pro features.

10. Security has limits

No software is completely secure. Automated detection may miss information, and users must review before sending. AI providers have their own security and privacy terms. Endpoint compromise, device compromise, malware, clipboard tools, screenshots, and user actions can affect confidentiality. Keep Layrin and your operating system updated, and avoid using Layrin on compromised or shared devices where that would be inappropriate.

11. Responsible use

Use Layrin only with content you are authorized to process. Follow employer and professional policies, review protected text, verify AI output, use qualified professional judgment where required, and do not treat Layrin as legal, medical, financial, or regulatory advice. Report unexpected disclosure or suspicious behavior promptly.

12. Security incident response

Priova Intelligence investigates reported security concerns. Access may be suspended or tokens revoked where necessary. Affected users may be notified where legally required. Logs may be retained longer when necessary for an investigation, and Priova may work with service providers during an incident.

13. Report a security concern

If you believe you have found a security vulnerability or unexpected data exposure, contact security@layrin.com with enough detail for us to investigate. Please do not access, modify, or retain other users’ information.

14. Trust summary

Original values stay local

Original values and token mappings remain on your device.

You review before sending

The Review step is a required human checkpoint before managed AI use.

Protected content only

Only protected content is used for managed AI.

No managed content storage

Managed request and response content is not stored in Priova’s application database or application logs.

Responses restore locally

AI responses are restored using local mappings on your device.

Review still matters

Automatic detection still requires user review.

© 2026 Priova Intelligence. All rights reserved.

Layrin is a privacy product by Priova Intelligence.

PrivacyTermsSecurityContact