Privacy Policy
This policy says what LabLingo collects, why, on what basis, who receives it, how long we keep it and how to control it. It describes what the service actually does. The controller is Shahzain Khurram, Pakistan. Contact: the form on the Contact page. Postal address: No postal address is published.
Who is responsible
Shahzain Khurram, Pakistan, decides why and how your data is processed (the "controller"). Contact: the form on the Contact page.
Without an account (guest)
A guest analysis stores nothing about you or your report. The text of your PDF, or the image of your photo or scan, is held in memory for that one request and sent to our AI provider to read it. Your confirmed values are sent again to write the explanations. The results stay in your open browser tab and are gone when you close it. Uploaded files are never written to disk or a database.
Data we process and why (with the legal basis)
Lab results and the values you confirm are health data. We process them only to read your report and write explanations, on the basis of your explicit consent, which you give before your first analysis and can withdraw in Settings. Account data (email address, password hash, saved reports, reminders, visit summaries, plan and payment records) is processed to provide the account you asked for (contract). Security and abuse limits (a hashed form of your IP address, event counts) are processed for our legitimate interest in keeping the service safe and available. Feedback, contact messages, waitlist entries and deletion requests are processed to answer you (legitimate interest, or your consent for the waitlist email). Consent records (what you agreed to, which version, when) are kept to show that consent was given.
What each field is for
Email: sign-in, confirmation and password-reset emails, replies. Password: stored only as a hash by Supabase Auth. Reports: values, units, reference ranges, statuses, explanation text, date and language, so you can see, compare and track them. Reminders and visit summaries: the features you use. Plan and payments: to give you access and keep accounting records. IP address: used in memory and as a daily hashed key for rate limits, never stored in raw form. Browser details and page path: sent with feedback so we can reproduce problems. We do not collect your date of birth, name or address.
Who receives data
Our service providers are listed on the Subprocessors page: Supabase (database and sign-in), Vercel (hosting), Groq (AI that reads reports and writes explanations), our email provider, the payment services you choose (Lemon Squeezy for cards when switched on; your bank, JazzCash or Easypaisa for the manual methods), and Vercel Web Analytics only after you accept analytics. We do not sell your data and do not share it with advertisers.
Transfers to the United States
Groq stores any data it retains in the United States, and Vercel and Supabase may process data outside your country. Per Groq's documentation, inference data is not retained by default and may be logged for up to 30 days only for reliability or abuse investigation. We do not claim that Zero Data Retention is enabled.
How long we keep data
Guest data: not kept. Account data: until you delete the account. Abuse counters: 24 hours. Payment-webhook records: 90 days. Waitlist entries: 12 months. Feedback and contact messages: 24 months. Completed deletion requests and completed payment requests: 12 and 24 months. Event counts (no identity): 24 months. Payment ledger rows: kept for accounting, with the link to your account removed when the account is deleted. Backups: Supabase's routine backups age out on their own schedule.
Your rights
You can download all your reports and markers as a CSV, delete your account and its data, withdraw consent to analysis, and change email preferences in Settings. People without an account can ask us to delete their data on the Delete my data page. We reply within 30 days. You can also ask us what we hold, to correct it or to stop processing it by writing to the form on the Contact page. We apply these rights to everyone, wherever you live.
Children
LabLingo is for adults aged 18 or older. A parent or guardian must be the one using it for a child. If you believe a child has used the service, contact us and we will delete the data.
Security
Connections use HTTPS. Account data is protected by row-level security rules in the database, so one account cannot read another's reports. The admin panel is protected by a hashed password and a signed session. No system is perfectly secure, and we cannot promise that it is.
Complaints
Please contact us first at the form on the Contact page and we will try to put things right. You may also have the right to complain to the data-protection authority where you live.
Changes
If this policy changes in a way that matters, we will ask you to agree again before you continue to analyze reports.