Privacy Policy

Effective: 2026-05-12 / Last updated: 2026-09-13

This Privacy Policy sets out how Lablate (the “Service”) handles users' personal information. The Service is designed so that research data is never stored on the operator's servers: your research data is kept on your own computer or in your organization's cloud storage.

1. Operator

  • Operator: Atsushi Sakurai (桜井惇), an individual
  • Address: not published continuously, as the Service is run by an individual. It will be provided without delay on request to the contact address below.
  • Contact: lablate.app@gmail.com

2. Information we collect

The Service collects the following information from users.

  • Credentials: email address, display name, and basic profile information obtained from the authentication provider (Google, Microsoft, and the like).
  • Access logs: IP address, user agent, referring URL, and access timestamp — the ordinary logs collected automatically by our hosting provider, Vercel.
  • Anonymous usage statistics: page views, country (inferred from IP), and feature-usage events (connecting a folder, creating a page, importing a dataset, exporting a PDF). These are collected by Vercel Web Analytics without cookies and in a form that cannot identify an individual. They never include the contents of research data, folder names, or file names.
  • Error reports: when a fault occurs in the Service, the error message, stack trace, URL of the page where it occurred, browser and OS type, and timestamp, together with an anonymous user identifier (while signed in, an irreversible hash of the account ID; when signed out, a random per-device ID). These are collected by the error-monitoring service Sentry. Email addresses, display names, and the account ID itself are never sent. Because an error message may contain a fragment of user-derived text, messages are truncated to 200 characters before they are sent.

What the Service does not collect: your research data — text, numbers, plots, images, attachments, and so on — is never transmitted to the Service's servers. Research data is stored only in a folder on your local computer, or — if and only if you enable the integration — in your own Google Drive. You may point that local folder at a folder synced by organizational cloud storage such as OneDrive, but that synchronization is performed by the operating system; the Service never calls that storage provider's API.

3. Purposes of use

Collected information is used only for the following purposes.

  • Authenticating users and maintaining signed-in state.
  • Statistical analysis for providing, operating, and improving the Service, carried out after processing the data into statistics that cannot identify an individual.
  • Notifying users of important matters such as specification changes, incidents, and amendments to the terms.
  • Responding to misuse and maintaining safe operation of the Service.
  • Responding to enquiries from users.

4. Disclosure to third parties and processors located overseas

The Service entrusts the storage and processing of users' personal information to the providers below, limited to what is necessary to operate the Service. Both are corporations located outside Japan (in the United States) and therefore constitute “third parties in a foreign country” under the Japanese Act on the Protection of Personal Information.

  • Supabase, Inc. (country: United States; data centre location: Tokyo region)
    Entrusted with: storage of credentials such as email address and display name

    The data centre is located in Japan (Tokyo region), but because the operating entity is a United States corporation, this is treated as provision to a third party in a foreign country.

  • Vercel Inc. (country: United States)
    Entrusted with: delivery of the Service's application and collection of access logs
  • Functional Software, Inc. (service name: Sentry) (country: United States; data stored in: United States)
    Entrusted with: collection and storage of error reports

Although all of these processors are located outside Japan (in the United States), they apply appropriate safeguards to the handling of personal data, and the Service has entered into agreements with them covering the secure handling of personal data (their respective standard data processing terms). For an overview of the personal data protection regime in the United States, please refer to the website of Japan's Personal Information Protection Commission.

Reference: Personal Information Protection Commission, “Provision to third parties in foreign countries” (Japanese)

Personal information is not provided to any third party other than those above, except where required by law or where the user has consented.

5. Handling of Google user data in the Google Drive integration

Only when you enable the Google Drive integration does the Service read and write research data to your own Google Drive. This section is the disclosure required by the Google API Services User Data Policy, including its Limited Use requirements.

  • Scope requested: drive.file only. The Service can reach the folder you select in the picker and the files it creates itself; the rest of your Drive is not visible to it.
  • Purpose: solely to save your research data to, and read it back from, your own Google Drive.
  • Where it goes: the traffic runs directly between your browser and the Google Drive API. Research data never passes through the Service's servers.
  • No transfer or secondary use: data obtained from Google Drive is never provided or sold to third parties, never used for advertising, and never used to train AI or machine-learning models. Humans do not read it, except where required by law, where you have given explicit consent, or where necessary for security purposes.
  • Access tokens: the access token obtained through authorization is stored only inside your browser (IndexedDB) and is never sent to the Service's servers. It is short-lived (roughly one hour by Google's default), and no refresh token is obtained or stored.
  • Revoking access: you can revoke the Service's access at any time under "Third-party apps & services" in your Google Account. After revocation the Service can no longer reach your Google Drive.

6. Cookies and similar technologies

The Service uses cookies and similar technologies for the following purposes.

  • Maintaining authentication state (keeping you signed in).

Authentication is the only purpose for which the Service uses cookies. Neither the anonymous usage statistics (Vercel Web Analytics) nor the error reports (Sentry) use cookies.

Cookies can be disabled in your browser settings, but doing so may make some features of the Service unavailable.

7. Retention periods

  • Credentials: for as long as the account is active, and for a reasonable period after deletion.
  • Access logs: the hosting provider's standard retention period (generally days to a few weeks).
  • Error reports: the error-monitoring provider's standard retention period.
  • Research data: not retained by the Service at all. It is stored only in the user's own storage.

8. Your rights

You have the following rights in respect of your personal information. Please make any request to the contact address below.

  • Request disclosure of your personal information.
  • Request correction, addition, or deletion of your personal information.
  • Request that use of your personal information be suspended.
  • Delete your account (credentials are deleted at the same time).

How to make a request

  • Where to send it: the email address in "12. Contact" below.
  • Identity verification: please send the request from the email address registered to your account; that serves as verification. If you write from a different address, we may ask you to verify your identity separately.
  • Fee: none.
  • Response: we aim to reply to the address you wrote from within two weeks.

9. Security

The Service takes the following measures to prevent leakage, loss, or damage to the personal information it collects.

  • Encryption of communications over HTTPS.
  • Encrypted storage of credentials (using the standard features of Supabase Auth).
  • A design in which research data is never stored on the operator's servers.
  • Removal of identifying information from error reports (hashing of the user identifier, truncation of error messages, and exclusion of console logs and URL query strings from what is sent).

10. Use by minors

Minors — users under the age of 18 — may use the Service only with the consent of a parent or legal guardian.

11. Amendments to this Policy

The Service may amend this Policy as necessary. Significant changes will be posted on this page and, where appropriate, notified to users.

12. Contact

Please direct any enquiries about this Policy to:

Privacy Policy - Lablate