LEGAL

Privacy notice.

What lazer.sh collects, why, who else sees it, and how to get it back or get rid of it. Written to be read, not to be survived.

Effective 1 August 2026 · Last updated 31 July 2026

01Who we are

lazer.sh is a private container registry. This notice explains what we collect when you use the registry, the panel at panel.lazer.sh, and the website at lazer.sh, and what we do with it. For the purposes of UK and EU data protection law we are the controller of the account and usage data described here.

Questions, requests, or complaints: privacy@lazer.sh. We aim to respond within 30 days.

02What we collect

CategoryWhat it isWhy we hold it
AccountEmail address and username. We do not hold a password — you sign in with a single-use code sent to your emailTo create and authenticate your account
SessionsA signed session identifier stored in an httpOnly cookie, plus the IP address and user agent of the device that signed inTo keep you signed in and to let you see and revoke active sessions
API keysA name, the scopes you granted, an expiry, and a hash of the key itself. We never store the key in a form we can read backTo authorise registry and management requests, and to show you what exists so you can revoke it
Registry contentProject and repository names, tags, manifests, layer digests, and the image layers themselvesThis is the service. It is your content and we treat it as confidential
Usage and request logsTimestamps, IP address, user agent, request path, response status, and byte counts for registry and API requestsSecurity, abuse prevention, debugging, and metering your storage
BillingYour plan, subscription state, and the identifier our payment provider uses for youTo charge the correct amount and to apply the right entitlements

We do not collect or store card numbers, bank details, or billing addresses. Checkout runs entirely on our payment provider's infrastructure and we receive only the subscription state described above.

We do not use advertising or analytics trackers, and we do not sell or share personal data for advertising.

04Cookies

We set three cookies and none is used for tracking:

  • A session cookie, httpOnly and same-site, that keeps you signed in to the panel. Removing it signs you out.
  • A theme preference, so the site remembers whether you chose light or dark.
  • The example tab you last opened on the home page, so it is still selected when you come back.

Because both are strictly necessary or set at your direction, we do not show a consent banner. If that ever changes, we will ask first.

05Who else touches your data

We use a small number of subprocessors. Each is bound by a data processing agreement and may only act on our instructions.

ProviderRoleRegion
CloudflareObject storage for image layers and the edge network that serves pullsGlobal edge, primary storage in the EU
PolarMerchant of record — checkout, subscriptions, invoicing, and taxEU / US
Our hosting and database providerRuns the control plane and stores account and metadata recordsEU
Our email providerDelivers transactional email such as sign-in codes, invites, and billing noticesEU / US

We may also disclose data where we are legally compelled to, and will tell you unless we are prohibited from doing so.

06International transfers

Image layers are cached at edge locations worldwide so that pulls are fast. Where personal data leaves the UK or EEA, the transfer relies on an adequacy decision or on Standard Contractual Clauses together with the UK Addendum. You can ask us for a copy of the safeguards that apply.

07How long we keep it

We keep data for as long as we need it for the purpose we collected it, and no longer.

  • Account and project records — for the life of the account, then removed after closure.
  • Image layers and manifests — until you delete them, or shortly after account closure. Garbage collection then removes the underlying bytes.
  • Request logs — up to 90 days.
  • Security and abuse records — kept for as long as we need them to keep the platform safe.
  • Invoices and tax records — as long as tax law requires, currently six years.

A deleted record can persist for a period afterwards in operational copies taken for resilience. Those copies are encrypted and are not used for anything other than restoring the service.

08How we protect it

  • Data is encrypted in transit with TLS and at rest in object storage.
  • API keys and sign-in codes are stored as one-way hashes. We cannot recover them and neither can anyone who obtains the database.
  • Every registry request is authorised against the scopes on the presented credential before any lookup happens.
  • Access to production data is limited to the people who need it to run the service.

If a breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and tell you without undue delay.

09Your rights

Depending on where you live you may have the right to access a copy of your data, correct it, delete it, restrict or object to how we use it, receive it in a portable format, or withdraw consent you previously gave.

Some of these you can exercise yourself in the panel — you can delete repositories and images, and revoke keys and sessions. For anything else, including closing your account or getting a copy of your data, email privacy@lazer.sh and we will handle it. We will not charge you or degrade your service for making a request.

If you are in the UK you can complain to the Information Commissioner's Office; elsewhere in the EEA, to your local supervisory authority. We would rather you raised it with us first.

10Children

lazer.sh is a developer tool and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, tell us and we will remove it.

11Changes to this notice

If we make a material change we will email account holders and update the date at the top of this page at least 14 days before it takes effect. Continuing to use lazer.sh after that date means the updated notice applies to you.