Layout Privacy Policy
Last updated: October 3, 2026
Layout is provided by MZRS. It helps you find places and events, create plans, keep an agenda, and share plans. This policy explains the information used by these features and the choices available to you. For privacy questions or requests, email mzrs.projects@gmail.com.
Information you provide
Account and contact information. If you create an account, we process your email address, authentication information, and an account identifier. You can also provide a name, phone number, and profile information. Supabase provides our authentication and database services. Account confirmation and password reset emails are delivered through our email provider, Resend.
Plans and preferences. We process the information you use to create and manage plans, such as destinations, dates, times, party size, budget, interests, selected vibes, saved places, custom stops, notes, booking status, and feedback. Layout uses saved preferences and signals such as favorites, stop changes, completed plans, and feedback to personalize recommendations and reduce repeated suggestions.
Optional personal preferences. You may provide dietary preferences, allergies, accessibility needs, or preferences about alcohol and age-appropriate activities. These details can be sensitive. They are optional. You can review, change, or remove saved preferences in Settings under Profile and Manage Preferences.
AI planning
Layout uses OpenAI through our server to interpret planning requests, help build plans, and produce requested recaps. AI can be used by both Plan Builder and Discover, including when you use the planning controls without typing a message.
Before the first AI planning request, Layout asks for your permission to send this information to OpenAI. You can decline and continue using manual Browse and saved-plan features. The choice is saved separately for the current account or guest use on that device. You can withdraw permission for future requests in Settings → Privacy → Withdraw AI permission. This affects new planning or recap actions; work already in progress may finish. Withdrawing permission does not erase requests already processed or previously saved plans.
When you submit a message in the planner, its text and the current planning context are sent for AI processing. This context includes your selected destination, dates, times, plan type, vibes, party size, budget, and search radius. Anything personal you include in the message can be included in that processing.
Plan generation can also use selected and saved preferences, dietary choices, learned taste and feedback summaries, trip notes, and candidate venue information, including venue locations. A requested recap uses the plan title, stops, notes, completion information, and relevant context. We do not add your account password to these AI requests.
If you explicitly describe your own allergy in the planning message, Layout can add it to your saved allergy preferences for future booking notes. Other trip-specific preferences can be retained with the resulting plan. Allergies are not a guarantee that a venue or meal is safe; confirm your requirements directly with the venue.
The chat draft is held in the running app rather than saved as a permanent conversation history. This does not mean that all information from the request is temporary: extracted preferences, trip notes, generated plans, and service records can be stored as described in this policy. You can omit optional sensitive information from your requests.
Location and nearby services
With your device permission, Layout can use your current location for nearby searches, route guidance, travel estimates, and planning. You can also choose a city or place manually. Denying device location permission does not prevent a manually selected destination from being used or sent to the services needed for that feature.
Searches and routes can send coordinates, search terms, place identifiers, dates, and filters to our server and the relevant providers. Selected and recent locations are stored on the device. Destinations and stop locations may also be retained in saved plans, planning records, and provider caches. Location is therefore not processed only in temporary memory.
You can manage location permission in your device settings and change the selected location in Layout.
Service providers
Layout uses the following services for the features you use:
- Supabase: authentication, cloud data, server functions, plan sharing, and operational records.
- OpenAI: interpretation of planning messages, itinerary assistance, and requested recaps.
- OpenAI ChatGPT Sites: hosting public app-link pages, including technical connection information and website traffic metrics such as page views and visitor counts.
- Google Maps and Places, Yelp, and OpenStreetMap services: place search, location lookup, maps, venue details, reviews, and photos, depending on the feature and available provider.
- Ticketmaster: searches for scheduled events and links to event information or tickets.
- OpenRouteService and OSRM: routes and travel estimates using the origin and selected stops.
- OpenWeatherMap: forecasts for a plan's location and time.
- Resend: account-related email delivery.
- Sentry: crash and error reporting, including technical app, operating-system, and device information. Layout does not enable session replay, screenshots, or view-hierarchy recording for this reporting. App-generated JavaScript reports are filtered to remove personal request content.
Providers receive the information needed for their part of the feature. They may also process technical connection information, such as IP addresses, when a device or our server connects to their service. Their processing and retention are also governed by their applicable terms and privacy policies.
Sharing, booking, and device features
Shared plans. Sharing a plan sends the selected plan content to the sharing service or app you choose. Anyone with a working share link or code can access the shared content. Included notes, custom stops, destinations, and schedules may reveal personal information. Review them before sharing. A recipient can import or retain a separate copy; deleting your original account or plan does not remove copies already received by others. Hosted share links are configured to expire after 30 days.
Public app-link pages. Opening a Layout web link can contact our website host before handing you to the app. The host processes the web request and technical connection information and provides website traffic metrics. The app-link page itself does not fetch your plan content or require a ChatGPT account.
Booking and external links. Layout can use your profile contact details and dietary or allergy preferences to fill a booking sheet. Review and edit those details before proceeding. If you copy booking details, they are placed on the device clipboard. Opening a venue, reservation, ticket, or navigation provider takes you to that provider's service. Details you submit there are handled by that provider; opening a link alone does not guarantee that every profile field or note is transferred. Deleting Layout data does not cancel an external reservation or delete the provider's separate records.
Reminders and calendar. If you enable notification permission and reminders, Layout schedules plan reminders on your device. Exporting a plan to a calendar requires calendar permission and writes the plan's event details to a writable calendar. Your calendar provider may sync those entries. Removing data from Layout does not automatically remove calendar entries or exported files that you created.
Storage, security, and retention
Layout stores working data, preferences, selected locations, and cached content on your device. Account features also store data in Supabase. The profile preference sync setting controls that preference synchronization; it does not turn off the network requests needed for searches, AI generation, account features, or sharing, and it does not delete data already stored in the cloud.
Our app and server service requests use encrypted HTTPS connections. Access to account data is controlled through authentication and database access rules. No storage or transmission method is completely secure.
Saved account content is retained to provide your account features until you remove it or delete the account. Planning activity and technical request/error records are also used to operate, troubleshoot, and protect the service. Deleting a saved plan alone does not delete all of those separate records.
Successful account deletion removes the account and associated records covered by Layout's account deletion process. A deletion receipt containing hashed identifiers and completion status is given a 30-day expiry to reconcile interrupted deletion requests; expired receipts are removed by subsequent cleanup. Hashed request-limit counters and non-account provider caches have separate cleanup. Infrastructure logs, backups, and records held independently by other providers are subject to their retention settings and obligations rather than an instant device erase. Contact us for help identifying data that remains relevant to your request.
Your choices and deletion requests
You can edit account contact information, manage saved preferences, reset learned taste information, remove saved plans, and change notification and location permissions through Layout or your device settings. Resetting preferences is separate from deleting your account or previously saved plans and notes.
To delete your account, sign in and open Settings → Profile → Delete account permanently, then follow the confirmation prompts. Account deletion cannot be undone. The process also clears the account's local Layout data and scheduled reminders on the device where deletion is completed.
If you cannot use the app, email mzrs.projects@gmail.com from the account email address with the subject Layout account deletion request. You may also request deletion or correction of specific data without deleting your account. Describe the request without sending your password. We may need to verify account ownership before acting.
The Layout Account and Data Deletion page also explains how to request deletion. Depending on where you live, additional privacy rights may apply; contact us to make a request.
Changes to this policy
We will update this page when Layout's data practices change and revise the date above. Contact mzrs.projects@gmail.com with questions about this policy.
Layout