Privacy Policy

Last updated: August 8, 2026

1. Information We Collect

When you sign in with Apple or Google, we receive the provider account identifier and, when the provider supplies them, your verified email address and display name.

We store the URLs, titles, descriptions, thumbnails, and collections you create. We also collect limited operational events such as sign-in, save, update, deletion, error type, platform, and timing data. Saved URL query strings are not included in operational event properties.

If you submit feedback, we receive your message and technical context such as the current page, viewport, and browser user agent.

On macOS, selected text and clipboard contents are read only when you invoke Save to Laters or Quick Save. They are processed locally to find an HTTP or HTTPS URL and are not sent to Laters until you confirm the save.

2. How We Use Information

We use this information to authenticate you, synchronize and organize your library, generate link previews, prevent abuse, diagnose failures, respond to feedback, and improve Laters. We do not sell your personal information.

3. Link Processing and Third Parties

When you save a link, Laters may request the public webpage to extract metadata and a limited amount of readable text. If AI enrichment is enabled, Upstage receives the URL origin and path, existing metadata, and truncated page text to produce a title and description. URL query strings and fragments are removed before that request.

Apple and Google process sign-in, Vercel provides hosting, aggregate analytics, and performance measurements, and GitHub receives feedback submitted through the in-app feedback form. These providers process data under their own privacy terms.

If you connect an AI agent through Settings, the connected provider may receive the saved URLs, titles, descriptions, thumbnails, collection names, and follow information needed for tools you approve. Laters does not send saved webpage bodies through this connection. The provider may separately visit a public URL using its own capabilities and processes information under its own terms and privacy policy.

4. Security

Sessions use random opaque tokens. Browser tokens are stored in secure HttpOnly cookies, native tokens are stored in the Keychain, and server session tokens are hashed at rest. Link fetching rejects private network destinations and applies request, redirect, and response-size limits.

AI connections use scoped OAuth access, short-lived access tokens, rotating refresh tokens, and hashed token storage. Tool requests are rate-limited and destructive actions require explicit safeguards.

5. Retention and Account Deletion

Your account data remains available while your account is active. Deleting your account from Settings removes your account, sessions, saved links, collections, and user-linked AI connections and operational events from the Laters database. Infrastructure and third-party providers may retain limited security or delivery logs for the periods described in their policies.

6. Your Choices

You can edit or delete saved links and collections, change your display name, sign out, or permanently delete your account from Settings. AI enrichment is only used when the service integration is enabled by Laters.

You can disconnect an AI agent from Settings at any time. This stops future access to Laters, but it cannot remove information already returned to or used by that provider.

7. Changes and Contact

We may update this policy as Laters changes. The current date is shown above. Questions can be sent to laters.space@gmail.com.

Privacy Policy | Laters