Privacy Policy

Effective: 2026-05-12 / Last updated: 2026-09-25

This Privacy Policy sets out how Lablate (the “Service”) handles users' personal information. The Service is designed so that research data is never stored on the operator's servers: your research data is kept on your own computer or in your organization's cloud storage.

1. Operator

  • Operator: Atsushi Sakurai (桜井惇), an individual
  • Address: not published continuously, as the Service is run by an individual. It will be provided without delay on request to the contact address below.
  • Contact: lablate.app@gmail.com

2. Information we collect

The Service collects the following information from users.

  • Credentials: email address, display name, basic profile information obtained from the authentication provider (Google, Microsoft, and the like), sign-in timestamps, and the IP address and user agent used to sign in (recorded by our authentication platform, Supabase Auth, to keep you signed in and to respond to misuse; only if you sign in).
  • Access logs: IP address, user agent, referring URL, and access timestamp — the ordinary logs collected automatically by our hosting provider, Vercel.
  • Anonymous usage statistics: page views, country (inferred from IP), and feature-usage events (connecting a folder, creating a page, importing a dataset, previewing or exporting a PDF). These are collected by Vercel Web Analytics without cookies and in a form that cannot identify an individual. They never include the contents of research data, folder names, or file names.
  • Error reports: when a fault occurs in the Service, the error message, stack trace, URL of the page where it occurred, browser and OS type, and timestamp, together with an anonymous user identifier (while signed in, an irreversible hash of the account ID; when signed out, a random per-device ID). These are collected by the error-monitoring service Sentry. Email addresses, display names, and the account ID itself are never sent. Because an error message may contain a fragment of user-derived text, messages are truncated to 200 characters before they are sent.
  • Bug reports and suggestions: what you submit through the in-app report form (the type, your message, an email address if you choose to enter one, and any images, screenshots, or files you attach), together with the URL of the page (without the query string), browser and OS type, display language, screen size, and the anonymous user identifier described above. These are collected by Sentry's User Feedback feature. A screenshot is taken only when you press "Attach current screen", and you can remove or redact it before sending.

What the Service does not collect: your research data — text, numbers, plots, images, attachments, and so on — is never transmitted to the Service's servers. The only exception is what you yourself attach and send through the bug report form (including anything visible in a screenshot), which is sent to Sentry. Research data is stored only in a folder on your local computer, or — if and only if you enable the integration — in your own Google Drive. You may point that local folder at a folder synced by organizational cloud storage such as OneDrive, but that synchronization is performed by the operating system; the Service never calls that storage provider's API.

3. Purposes of use

Collected information is used only for the following purposes.

  • Authenticating users and maintaining signed-in state.
  • Statistical analysis for providing, operating, and improving the Service, carried out after processing the data into statistics that cannot identify an individual.
  • Notifying users of important matters such as specification changes, incidents, and amendments to the terms.
  • Responding to misuse and maintaining safe operation of the Service.
  • Responding to enquiries from users.
  • Investigating bug reports and suggestions, fixing and improving the Service, and replying to the reporter (only if an email address was provided).

4. Disclosure to third parties and processors located overseas

The Service entrusts the storage and processing of users' personal information to the providers below, limited to what is necessary to operate the Service. Both are corporations located outside Japan (in the United States) and therefore constitute “third parties in a foreign country” under the Japanese Act on the Protection of Personal Information.

  • Supabase, Inc. (country: United States; data centre location: Tokyo region)
    Entrusted with: storage of credentials such as email address, display name, sign-in timestamps, and the IP address and user agent used to sign in

    The data centre is located in Japan (Tokyo region), but because the operating entity is a United States corporation, this is treated as provision to a third party in a foreign country.

  • Vercel Inc. (country: United States)
    Entrusted with: delivery of the Service's application and collection of access logs
  • Functional Software, Inc. (service name: Sentry) (country: United States; data stored in: United States)
    Entrusted with: collection and storage of error reports and of bug reports and suggestions (including attachments)

Although all of these processors are located outside Japan (in the United States), they apply appropriate safeguards to the handling of personal data, and the Service has entered into agreements with them covering the secure handling of personal data (their respective standard data processing terms). For an overview of the personal data protection regime in the United States, please refer to the website of Japan's Personal Information Protection Commission.

Reference: Personal Information Protection Commission, “Provision to third parties in foreign countries” (Japanese)

Personal information is not provided to any third party other than those above, except where required by law or where the user has consented.

5. Handling of Google user data in the Google Drive integration

Only when you enable the Google Drive integration does the Service read and write research data to your own Google Drive. This section is the disclosure required by the Google API Services User Data Policy, including its Limited Use requirements.

  • Scope requested: drive.file only. The Service can reach the folder you select in the picker and the files it creates itself; the rest of your Drive is not visible to it.
  • Purpose: solely to save your research data to, and read it back from, your own Google Drive.
  • Where it goes: the traffic runs directly between your browser and the Google Drive API. Research data never passes through the Service's servers.
  • No transfer or secondary use: data obtained from Google Drive is never provided or sold to third parties, never used for advertising, and never used to train AI or machine-learning models. Humans do not read it, except where required by law, where you have given explicit consent, or where necessary for security purposes.
  • Access tokens: the access token obtained through authorization is stored only inside your browser (IndexedDB) and is never sent to the Service's servers. It is short-lived (roughly one hour by Google's default), and no refresh token is obtained or stored.
  • Revoking access: you can revoke the Service's access at any time under "Third-party apps & services" in your Google Account. After revocation the Service can no longer reach your Google Drive.

6. Handling of Microsoft user data in the OneDrive integration

Only when the user enables the OneDrive integration does this service read and write research data to the user's own OneDrive (including folders shared with the user by others).

  • Permission requested: Microsoft Graph Files.ReadWrite.All (delegated). Technically this reaches every file on OneDrive the user can access. Microsoft provides no narrow permission equivalent to Google's drive.file, and connecting to a folder shared by another user requires this scope.
  • What is actually accessed: regardless of the scope above, this service reads and writes only under the folder the user connected. No other file is listed or retrieved.
  • Purpose: solely to store and retrieve the user's research data in the user's own OneDrive.
  • Destination: traffic goes directly between the browser and the Microsoft Graph API; research data never passes through this service's servers.
  • No disclosure or secondary use: data obtained from OneDrive is never provided or sold to third parties, never used for advertising, never used to train AI or machine-learning models, and never read by a human (except where required by law, with the user's explicit consent, or where necessary for security).
  • Token storage: tokens obtained through authorization are stored only in the user's browser by the Microsoft Authentication Library (MSAL) and are never sent to this service's servers. Per Microsoft's specification, refresh tokens issued to single-page applications expire after 24 hours, after which authorization is required again.
  • Revoking access: access can be revoked from the list of apps and services in the privacy settings of the Microsoft account. After revocation this service can no longer reach OneDrive.
  • Choosing not to connect: the service can be used without the OneDrive integration, via a local folder (including an OneDrive-synced folder) or the Google Drive integration.

7. Cookies and similar technologies

The Service uses cookies and similar technologies for the following purposes.

  • Maintaining authentication state (keeping you signed in).

Authentication is the only purpose for which the Service uses cookies. Neither the anonymous usage statistics (Vercel Web Analytics) nor the error reports (Sentry) use cookies.

Cookies can be disabled in your browser settings, but doing so may make some features of the Service unavailable.

8. Retention periods

  • Credentials: for as long as the account is active, and for a reasonable period after deletion. The IP address and user agent used to sign in are recorded per signed-in session and are deleted when you sign out or delete your account. Authentication logs follow the authentication platform's standard retention period.
  • Access logs: the hosting provider's standard retention period (generally days to a few weeks).
  • Error reports: the error-monitoring provider's standard retention period.
  • Bug reports and suggestions: the error-monitoring provider's standard retention period. Contact us if you would like a report deleted.
  • Research data: not retained by the Service at all. It is stored only in the user's own storage (except what the user attaches to a bug report).

9. Your rights

You have the following rights in respect of your personal information. Please make any request to the contact address below.

  • Request disclosure of your personal information.
  • Request correction, addition, or deletion of your personal information.
  • Request that use of your personal information be suspended.
  • Delete your account (credentials are deleted at the same time).

How to make a request

  • Where to send it: the email address in "13. Contact" below.
  • Identity verification: please send the request from the email address registered to your account; that serves as verification. If you write from a different address, we may ask you to verify your identity separately.
  • Fee: none.
  • Response: we aim to reply to the address you wrote from within two weeks.

10. Security

The Service takes the following measures to prevent leakage, loss, or damage to the personal information it collects.

  • Encryption of communications over HTTPS.
  • Encrypted storage of credentials (using the standard features of Supabase Auth).
  • A design in which research data is never stored on the operator's servers.
  • Removal of identifying information from error reports (hashing of the user identifier, truncation of error messages, and exclusion of console logs and URL query strings from what is sent).

11. Use by minors

Minors — users under the age of 18 — may use the Service only with the consent of a parent or legal guardian.

12. Amendments to this Policy

The Service may amend this Policy as necessary. Significant changes will be posted on this page and, where appropriate, notified to users.

13. Contact

Please direct any enquiries about this Policy to:

Privacy Policy - Lablate