Privacy notice.
What lazer.sh collects, why, who else sees it, and how to get it back or get rid of it. Written to be read, not to be survived.
Effective 1 August 2026 · Last updated 31 July 2026
01Who we are
lazer.sh is a private container registry. This notice explains what we collect when you use the registry, the panel at panel.lazer.sh, and the website at lazer.sh, and what we do with it. For the purposes of UK and EU data protection law we are the controller of the account and usage data described here.
Questions, requests, or complaints: [email protected]. We aim to respond within 30 days.
02What we collect
| Category | What it is | Why we hold it |
|---|---|---|
| Account | Email address and username. We do not hold a password — you sign in with a single-use code sent to your email | To create and authenticate your account |
| Sessions | A signed session identifier stored in an httpOnly cookie, plus the IP address and user agent of the device that signed in | To keep you signed in and to let you see and revoke active sessions |
| API keys | A name, the scopes you granted, an expiry, and a hash of the key itself. We never store the key in a form we can read back | To authorise registry and management requests, and to show you what exists so you can revoke it |
| Registry content | Project and repository names, tags, manifests, layer digests, and the image layers themselves | This is the service. It is your content and we treat it as confidential |
| Usage and request logs | Timestamps, IP address, user agent, request path, response status, and byte counts for registry and API requests | Security, abuse prevention, debugging, and metering your storage |
| Billing | Your plan, subscription state, and the identifier our payment provider uses for you | To charge the correct amount and to apply the right entitlements |
We do not collect or store card numbers, bank details, or billing addresses. Checkout runs entirely on our payment provider's infrastructure and we receive only the subscription state described above.
We do not use advertising or analytics trackers, and we do not sell or share personal data for advertising.
03Why we are allowed to hold it
- Contract — account, session, registry content, and billing data are needed to provide the service you signed up for.
- Legitimate interests — request logs are kept to secure the platform, investigate abuse, and diagnose faults. We keep them narrow and short-lived to stay proportionate.
- Legal obligation — invoices and tax records are retained for as long as the law requires.
- Consent — used only for optional product email. You can withdraw it at any time without affecting your account.
05Who else touches your data
We use a small number of subprocessors. Each is bound by a data processing agreement and may only act on our instructions.
| Provider | Role | Region |
|---|---|---|
| Cloudflare | Object storage for image layers and the edge network that serves pulls | Global edge, primary storage in the EU |
| Polar | Merchant of record — checkout, subscriptions, invoicing, and tax | EU / US |
| Our hosting and database provider | Runs the control plane and stores account and metadata records | EU |
| Our email provider | Delivers transactional email such as sign-in codes, invites, and billing notices | EU / US |
We may also disclose data where we are legally compelled to, and will tell you unless we are prohibited from doing so.
06International transfers
Image layers are cached at edge locations worldwide so that pulls are fast. Where personal data leaves the UK or EEA, the transfer relies on an adequacy decision or on Standard Contractual Clauses together with the UK Addendum. You can ask us for a copy of the safeguards that apply.
07How long we keep it
We keep data for as long as we need it for the purpose we collected it, and no longer.
- Account and project records — for the life of the account, then removed after closure.
- Image layers and manifests — until you delete them, or shortly after account closure. Garbage collection then removes the underlying bytes.
- Request logs — up to 90 days.
- Security and abuse records — kept for as long as we need them to keep the platform safe.
- Invoices and tax records — as long as tax law requires, currently six years.
A deleted record can persist for a period afterwards in operational copies taken for resilience. Those copies are encrypted and are not used for anything other than restoring the service.
08How we protect it
- Data is encrypted in transit with TLS and at rest in object storage.
- API keys and sign-in codes are stored as one-way hashes. We cannot recover them and neither can anyone who obtains the database.
- Every registry request is authorised against the scopes on the presented credential before any lookup happens.
- Access to production data is limited to the people who need it to run the service.
If a breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and tell you without undue delay.
09Your rights
Depending on where you live you may have the right to access a copy of your data, correct it, delete it, restrict or object to how we use it, receive it in a portable format, or withdraw consent you previously gave.
Some of these you can exercise yourself in the panel — you can delete repositories and images, and revoke keys and sessions. For anything else, including closing your account or getting a copy of your data, email [email protected] and we will handle it. We will not charge you or degrade your service for making a request.
If you are in the UK you can complain to the Information Commissioner's Office; elsewhere in the EEA, to your local supervisory authority. We would rather you raised it with us first.
10Children
lazer.sh is a developer tool and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, tell us and we will remove it.
11Changes to this notice
If we make a material change we will email account holders and update the date at the top of this page at least 14 days before it takes effect. Continuing to use lazer.sh after that date means the updated notice applies to you.