Last updated: July 19, 2026
Our commitments, in plain language
- We never sell your data and never use your lab’s content for advertising.
- We never delete your data on our own initiative — you stay in control, and data is removed only when you choose to delete it or ask us to.
- Each lab’s data is isolated at the database level, encrypted in transit and at rest.
- You can export your data anytime, and you can request access, correction, or deletion of your personal data.
Overview
LabOps Lite (“LabOps Lite”, “we”, “us”) provides a lab information management platform for research labs. This policy explains what information we handle when you create an account, run a lab, and use the product — and how we protect it. We aim to collect only what the service needs to work.
Information we collect
Account information. When you sign up, we collect your name, email address, and a securely hashed password. If you sign in with Google, we receive basic profile information (your name and email) from Google to create and identify your account. Authentication is handled by our infrastructure provider; we do not store your password in plain text.
Lab content you create. The data you enter to run your lab — inventory, orders, samples and their history, protocols and runs, experiments, projects, tasks, calendar events, notes, team members, equipment bookings, messages, custom fields, and any files you upload and attach to records. This content belongs to your lab.
Payment information. Subscriptions are processed by Stripe. Your card details go directly to Stripe and are never stored on our servers. We retain only a subscription identifier and whether a plan is active.
Technical information. Basic session cookies required to keep you signed in, and standard server logs (such as timestamps and error information) needed to operate and secure the service.
Lab content you create. The data you enter to run your lab — inventory, orders, samples and their history, protocols and runs, experiments, projects, tasks, calendar events, notes, team members, equipment bookings, messages, custom fields, and any files you upload and attach to records. This content belongs to your lab.
Payment information. Subscriptions are processed by Stripe. Your card details go directly to Stripe and are never stored on our servers. We retain only a subscription identifier and whether a plan is active.
Technical information. Basic session cookies required to keep you signed in, and standard server logs (such as timestamps and error information) needed to operate and secure the service.
How we use information
We use your information to provide and maintain the service, authenticate you, process subscription payments, respond to your messages, keep the platform secure, and improve how it works. We do not sell your data, we do not share it for anyone else’s advertising, and we do not use your lab’s content to train external AI models.
How your data is shared
We share data only with the service providers (our “sub-processors”) that make LabOps Lite run, acting on our behalf under their own privacy and security commitments:
- Supabase — our managed database, authentication, and encrypted file storage provider; it hosts your lab’s data and uploaded files in the United States.
- Vercel — hosts and serves the LabOps Lite web application.
- Stripe — processes payments and manages subscriptions.
- Resend — delivers our transactional and notification emails, such as team invitations and the optional weekly digest; it receives the recipient’s email address and the message content.
- Google — only if you choose to sign in with Google, to authenticate you.
Data isolation & security
Each lab’s data is isolated at the database level using row-level security, so members of one lab cannot access another lab’s data. Connections are encrypted in transit, and data is encrypted at rest by our infrastructure provider. Uploaded files are stored in a private bucket and served only through short-lived, signed links to authorized lab members. You can read more on our Security page. No system is perfectly secure, but we take reasonable measures to protect your information, and you are responsible for keeping your own login credentials secure.
Data breach
If we become aware of a security incident that compromises your personal data, we’ll take prompt steps to investigate and address it, and we’ll notify affected labs without undue delay where required by applicable law, along with the information you need to respond.
Data retention & deletion
We never delete your data on our own initiative, and we never sell it. Your lab’s content stays intact and available for as long as your lab is active — including if a subscription lapses. Data is removed only when you choose it: when you delete a record, close your lab, or ask us to delete your data.
When you delete data or close a lab, we remove the affected data from our active systems within a reasonable period. Copies may persist for a limited time in routine encrypted backups before those backups cycle out, and we may retain the minimum records we’re legally required to keep (for example, payment and tax records). Because we don’t delete on our own, you remain in control of removing content you no longer wish to store.
When you delete data or close a lab, we remove the affected data from our active systems within a reasonable period. Copies may persist for a limited time in routine encrypted backups before those backups cycle out, and we may retain the minimum records we’re legally required to keep (for example, payment and tax records). Because we don’t delete on our own, you remain in control of removing content you no longer wish to store.
Your rights & choices
You can access and export your lab’s core data (inventory, samples, protocols, projects, tasks, notes, and calendars) directly in the app at any time. You may also request a full export, correction, or deletion of your personal data by contacting us, and we’ll respond within the timeframe required by applicable law. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA — including the rights to access, correct, delete, and port your data, and to object to or restrict certain processing. We honor valid requests under applicable law and will not discriminate against you for exercising these rights. Our commitment not to delete data on our own does not limit your right to have your data deleted on request.
International users
LabOps Lite is operated from, and its infrastructure providers may process and store data in, the United States and other countries. If you use the Service from outside those countries, you understand that your information may be transferred to and processed in a country with different data-protection laws than your own.
Cookies
We use only the essential cookies required to keep you signed in and to operate the service. We do not use advertising or cross-site tracking cookies.
Children
LabOps Lite is intended for use by researchers and is not directed to children. We do not knowingly collect personal information from children, and we do not knowingly allow anyone under the age required by applicable law to create an account.
Changes to this policy
We may update this policy as the product evolves. When we make material changes, we’ll update the date above and, where appropriate, notify you in the app.
Contact us
Questions about this policy or your data? Email us at support@labopslite.com or through our contact page.