Public Beta

Beta Privacy Policy

LabHit is currently in public beta. This Beta Privacy Policy describes how we handle your data during the beta period. A formal legal entity is being established, at which point this policy will be replaced with a full Privacy Policy.

Data Controller: LabHit — legal@labhit.dev

1. What We Collect

1.1 Account Data (via GitHub OAuth)

When you sign in, we collect from your GitHub profile:

DataPurposeRequired
Email addressAccount identificationYes
Display namePersonalizationNo
GitHub usernameAccount linkingYes
GitHub numeric IDUnique identifierYes
Avatar URLProfile displayNo

We request minimal OAuth scopes: read:user and user:email. We do not access your repositories, organizations, or code.

We do not store your GitHub access token. It is used once to retrieve your profile, then discarded.

1.2 Usage Data

DataPurpose
Build minutes consumedUsage tracking
Pipeline run metadataService operation
Event timestampsUsage period calculation

1.3 Technical Data (Not Stored Persistently)

DataPurposeStorage
IP addressRate limitingIn-memory only (60s window), never saved to database
HTTP method and pathPerformance monitoringServer logs only

We do not collect: browser fingerprints, location data, tracking cookies, or advertising identifiers.

1.4 Waitlist Data

If you signed up for the launch waitlist on labhit.dev, we collected your email address (stored in Cloudflare KV). You may request deletion at support@labhit.dev.

2. How We Use Your Data

PurposeLegal Basis (GDPR)
Provide and operate the serviceLegitimate interest (Art. 6(1)(f))
Authenticate your identityLegitimate interest
Rate limiting and abuse preventionLegitimate interest
Communicate service updatesLegitimate interest

We do not use your data for advertising, profiling, sale to third parties, or training machine learning models.

3. Cookies

We do not use cookies. Authentication uses JWT tokens in HTTP headers only.

4. Data Sharing

ServiceData SharedPurpose
GitHub (Microsoft)OAuth authorization codeAuthentication
CloudflareIP address (in transit)CDN, DNS

We do not sell or rent your data.

5. Data Storage and Security

Your data is stored in a SQLite database on a server located in Germany (EU). Security measures include:

6. Data Retention

DataRetention
Account dataDuration of account
Sessions30 days or until logout
Usage eventsDuration of account
Server logs90 days

You may request deletion of your data at any time by emailing legal@labhit.dev.

7. Your Rights (GDPR)

You have the right to: access, rectify, erase, restrict processing of, port, and object to processing of your personal data. You may also withdraw consent at any time (revoke GitHub OAuth via GitHub settings).

To exercise any right, email legal@labhit.dev. We will respond within one month.

Supervisory Authority

You may lodge a complaint with the Romanian ANSPDCP:

If you are in another EEA state, you may contact your local data protection authority.

8. International Transfers

Account data is stored in the EU (Germany). GitHub and Cloudflare process some data in the United States under the EU-US Data Privacy Framework.

9. Children

The service is not directed to children under 16. We do not knowingly collect data from children under 16.

10. Changes

We may update this policy. Material changes will be communicated via email. For changes to processing purposes, we will seek explicit consent.

11. Contact