Last updated: September 6, 2026
Our commitments, in plain language
- We never sell your data and never use your lab’s content for advertising.
- We do not delete active-lab data without your direction. Lapsed labs receive notice and an export opportunity before any future retention limit applies.
- Each lab’s data is isolated at the database level, encrypted in transit and at rest.
- You can export your data anytime, and you can request access, correction, or deletion of your personal data.
Overview
LabOps Lite (“LabOps Lite”, “we”, “us”) provides a lab information management platform for research labs. This policy explains what information we handle when you create an account, run a lab, and use the product — and how we protect it. We aim to collect only what the service needs to work.
Information we collect
Account information. When you sign up, we collect your name, email address, and a securely hashed password. If you sign in with Google, we receive basic profile information (your name and email) from Google to create and identify your account. Authentication is handled by our infrastructure provider; we do not store your password in plain text.
Lab content you create. The data you enter to run your lab — inventory, orders, samples and their history, protocols and runs, experiments, projects, tasks, calendar events, notes, team members, equipment bookings, messages, custom fields, and any files you upload and attach to records. This content belongs to your lab.
Payment information. Subscriptions are processed by Stripe. Your card details go directly to Stripe and are never stored in the LabOps Lite database. Stripe receives the account email, lab name and internal lab identifier needed to create the billing customer and associate the subscription with the right workspace. We retain Stripe customer and subscription identifiers, the selected plan, and its activation state.
Technical information. Basic session cookies required to keep you signed in, and standard server and privacy-filtered error/performance telemetry (such as timestamps, routes, device/runtime context, and error information) needed to operate and secure the service. Error monitoring is configured not to send request bodies, cookies, authorization headers, user identity, or recognizable credentials.
Lab content you create. The data you enter to run your lab — inventory, orders, samples and their history, protocols and runs, experiments, projects, tasks, calendar events, notes, team members, equipment bookings, messages, custom fields, and any files you upload and attach to records. This content belongs to your lab.
Payment information. Subscriptions are processed by Stripe. Your card details go directly to Stripe and are never stored in the LabOps Lite database. Stripe receives the account email, lab name and internal lab identifier needed to create the billing customer and associate the subscription with the right workspace. We retain Stripe customer and subscription identifiers, the selected plan, and its activation state.
Technical information. Basic session cookies required to keep you signed in, and standard server and privacy-filtered error/performance telemetry (such as timestamps, routes, device/runtime context, and error information) needed to operate and secure the service. Error monitoring is configured not to send request bodies, cookies, authorization headers, user identity, or recognizable credentials.
How we use information
We use your information to provide and maintain the service, authenticate you, process subscription payments, respond to your messages, keep the platform secure, and improve how it works. We do not sell your data, we do not share it for anyone else’s advertising, and we do not use your lab’s content to train external AI models.
How your data is shared
We share data only with the service providers (our “sub-processors”) that make LabOps Lite run, acting on our behalf under their own privacy and security commitments:
- Supabase — our managed database, authentication, and encrypted file storage provider; it hosts your lab’s data and uploaded files in the project region we configure.
- Vercel — hosts and serves the LabOps Lite web application.
- Stripe — processes payments and manages subscriptions; it receives billing-contact and lab-identification details needed to associate a payment with the correct workspace.
- Resend — delivers our transactional and notification emails, such as team invitations and the optional weekly digest; it receives the recipient’s email address and the message content.
- Sentry — receives privacy-filtered application error and performance telemetry when monitoring is enabled, so we can detect and diagnose failures.
- Cloudflare Turnstile — performs a privacy-preserving security challenge on authentication forms when bot protection is enabled.
- Google — only if you choose to sign in with Google, to authenticate you.
Data isolation & security
Each lab’s data is isolated at the database level using row-level security, so members of one lab cannot access another lab’s data. Connections are encrypted in transit, and data is encrypted at rest by our infrastructure provider. Uploaded files are stored in a private bucket and served only through short-lived, signed links to authorized lab members. You can read more on our Security page. No system is perfectly secure, but we take reasonable measures to protect your information, and you are responsible for keeping your own login credentials secure.
Data breach
If we become aware of a security incident that compromises your personal data, we’ll take prompt steps to investigate and address it, and we’ll notify affected labs without undue delay where required by applicable law, along with the information you need to respond.
Data retention & deletion
We do not delete an active lab’s content without its direction, and we never sell it. If a subscription lapses, we preserve the lab during a reasonable recovery and export period. We may later remove inactive lab content only after advance notice to the account owner and a final opportunity to export or reactivate.
When you delete data or close a lab, we remove the affected data from our active systems within a reasonable period. Copies may persist for a limited time in routine encrypted backups before those backups cycle out, and we may retain the minimum records we’re legally required to keep (for example, payment and tax records). A specific inactive-lab retention period will be published before automated deletion is enabled; until then, inactive-lab deletion is handled by request.
When you delete data or close a lab, we remove the affected data from our active systems within a reasonable period. Copies may persist for a limited time in routine encrypted backups before those backups cycle out, and we may retain the minimum records we’re legally required to keep (for example, payment and tax records). A specific inactive-lab retention period will be published before automated deletion is enabled; until then, inactive-lab deletion is handled by request.
Your rights & choices
You can access and export your lab’s core data (inventory, samples, protocols, projects, tasks, notes, and calendars) directly in the app at any time. You may also request a full export, correction, or deletion of your personal data by contacting us, and we’ll respond within the timeframe required by applicable law. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA — including the rights to access, correct, delete, and port your data, and to object to or restrict certain processing. We honor valid requests under applicable law and will not discriminate against you for exercising these rights. Our commitment not to delete data on our own does not limit your right to have your data deleted on request.
International users
LabOps Lite is operated from, and its infrastructure providers may process and store data in, the United States and other countries. If you use the Service from outside those countries, you understand that your information may be transferred to and processed in a country with different data-protection laws than your own.
Cookies
We use only the essential cookies required to keep you signed in and to operate the service. We do not use advertising or cross-site tracking cookies.
Children
LabOps Lite is intended for use by researchers and is not directed to children. We do not knowingly collect personal information from children, and we do not knowingly allow anyone under the age required by applicable law to create an account.
Changes to this policy
We may update this policy as the product evolves. When we make material changes, we’ll update the date above and, where appropriate, notify you in the app.
Contact us
Questions about this policy or your data? Email us at support@labopslite.com or through our contact page.