LabFolio is a 501(c)(3) nonprofit dedicated to advancing scientific productivity. We are committed to protecting your privacy and handling your data responsibly.
This Privacy Policy ("Policy") explains what information we collect, how we use it, and your rights regarding your data. This Policy applies to LabFolio ("we," "our," and "us").
By accessing, using, or signing up for our services, you accept the terms of this Policy. By accepting this Policy, you agree that we are the controller of your personal information which is processed in connection with our services.
Information We Collect
We collect personal information in the following ways:
Information you provide to us directly. When you register to use LabFolio we collect the personal information you provide, like your name and email address. We will use this information to enable you to access and use LabFolio or fulfill the request you've made and to track and improve the quality of the services we provide, which may involve asking you about your experience with LabFolio. You may also provide us with additional information, such as to populate your profile with affiliation, ORCID ID, and research areas, which we will use to improve the quality of our services for you, such as organizing your research files across scientific tools with greater accuracy. Finally, you may provide us with information about which files we have imported for you should be associated with which of your research projects. We use this information directly to provide our service to you of organizing your research, and making it shareable.
Information we collect automatically from your use of LabFolio. When you use LabFolio, we may collect information about that usage and other technical information, such as your IP address, browser type and any referring website addresses. We may combine this automatically collected log information with other information we collect about you and use it to keep a record of our interaction and to enable us to support, personalize and improve LabFolio. For example, we may use your information to determine that LabFolio has higher latency for certain browsers, or when serving requests from a particular geography, and we may use that information to improve the performance of LabFolio for you and other users.
Information we collect from third parties that you connect to LabFolio. When you connect one of your research tools or applications to LabFolio and request to import your data from that tool or application, we may collect the following information: security tokens, file content, and file metadata. We use this information to perform our function for you, which is to organize your research across the various tools you use, and to share that organized research with others at your specific request. For example, if you choose to connect your Google Drive to LabFolio, we will first try to discard any files unrelated to your research, and then we will process the minimum amount of file metadata and content necessary to perform LabFolio's function for you. We provide more detail about each third-party integration that we currently offer to you, below.
Information we collect from developers of apps powered by LabFolio. When needed for LabFolio to provide a service that you have requested (like sharing file locations to sync your research across tools), the developers of the apps you use may provide us with identifiers about you, like your name or email address, necessary for us to perform the service for you.
Third-Party Service Integrations
LabFolio allows you to connect third party applications to LabFolio in order to import data from those applications, organize your data across applications, and share your organized data with others. When you choose to connect a service, you explicitly authorize LabFolio to access specific data from that service through a secure authentication process.
Currently Supported Integrations
GitHub
What we access: Repository metadata (including name, owner, URL, repository ID), commit history (including commit message, timestamp, author, and SHA), and commit diffs. We only access commits authored by you.
Permission level: Read-only access to repositories you grant the GitHub App access to
How we store it: We store commit content and diffs only for as long as it takes to process the data as it is ingested. We store repository and commit metadata for as long as it is necessary to perform our service for you.
What we access: Document metadata (including name, modification date, web URL, and owners), revision history (including revision ID, timestamp, and last modifying user), and document content (plain text). We only process documents you own or have modified.
Permission level: Read-only access to your Google Docs and Drive
How we store it: We store document content and plain-text snapshots only for as long as it takes to process the data as it is ingested. We store document metadata and revision history for as long as it is necessary to perform our service for you.
What we access: File metadata (including name, size, last modified date, web URL, folder path, and MIME type), version history, and file content for supported document types (.pdf, .doc, .docx, .txt, .xlsx, .xls, .csv, .md, .tex, .bib). Your display name and email are retrieved to identify your account.
Permission level: Read-only access to your OneDrive files
How we store it: We store file content and version data only for as long as it takes to process the data as it is ingested. We store file metadata and version history for as long as it is necessary to perform our service for you.
What we access: Library collection metadata (including collection name and key) and item metadata (including title, authors, item type, publication date, DOI, URL, abstract, and tags). Unfiled top-level items are also included.
Permission level: Read-only access to your Zotero library via API key
How we store it: We store item content and collection data only for as long as it takes to process the data as it is ingested. We store library and item metadata for as long as it is necessary to perform our service for you.
OAuth scope: Zotero API key with read-only access to user library (library read permission)
Dropbox
What we access: File and folder metadata (including name, path, size, modification date, and content hash), revision history, and file content for supported document types (.pdf, .doc, .docx, .txt, .xlsx, .xls, .csv, .md, .tex, .bib). Your account ID and display name are retrieved to identify your account.
Permission level: Read-only access to your Dropbox files
How we store it: We store file content and folder structures only for as long as it takes to process the data as it is ingested. We store file metadata and revision history for as long as it is necessary to perform our service for you.
We only access data within the permissions you explicitly grant during the OAuth authorization process
We request the minimum permissions necessary to provide LabFolio's services
We never modify or delete files in your connected services
You can disconnect any service at any time through your LabFolio settings
You can also revoke LabFolio's access directly through the third-party service's account settings
Managing Your Integrations
You can disconnect third-party services at any time from your LabFolio settings. When you disconnect a service, we immediately stop accessing new data from that service. You can also delete any data that we have already imported from your integrations, at any time.
How We Use Your Personal Information
We use the personal information we collect to:
Provide and Improve Our Service
Authenticate your account and provide access to LabFolio
Organize your research files and projects, and make them shareable with others at your request
Analyze usage patterns to improve LabFolio's features and performance
Debug technical issues and ensure service reliability
Send important service updates and changes to our policies
Develop New Features
Analyze user data internally to develop and improve LabFolio's features
Comply With Legal Obligations and Terms
Respond to legal requests and prevent fraud or abuse
Enforce our Terms of Service
Create De-Identified Data
We may create de-identified data for research, analytics, or any other purposes permitted by law.
How We Disclose Your Personal Information
We are committed to not selling your data. We only share your personal information in the following limited circumstances, as permitted by law:
With the developer of the app you are using and as directed by that developer
With the research tools you connect to LabFolio or to an app using LabFolio
With our data processors and other service providers (e.g., hosting providers), partners, agents, or contractors in connection with the services they perform for us or developers
If we believe in good faith that disclosure is appropriate or required to comply with applicable law, regulation, or legal process (like a court order or subpoena)
In connection with a change in ownership or control of all or a part of our business (like a merger, acquisition, reorganization, or bankruptcy).
For any other notified purpose with your consent or at your direction.
Development Partnerships
We may partner with other research tools and services to build integrations that benefit LabFolio users. During development of these integrations, we use test accounts and synthetic data whenever possible.
If development requires access to real user data, we will:
Seek explicit consent from volunteer participants
Limit access to the minimum necessary data
Require partner companies to maintain the same confidentiality and security standards as LabFolio
Delete development data once the integration is complete
You will never be included in a development partnership without your explicit, advance consent.
Data Security
We take appropriate technical and organizational security measures to protect personal information from accidental or unlawful destruction, accidental loss and unauthorized access, destruction, misuse, modification or disclosure, including generally accepted standards designed to protect personal information provided to us, both during transmission and once it is received.
Technical Safeguards
Secure Transfers - All data transmitted between your device and LabFolio uses TLS encryption enforced at every layer: our API and webhook endpoints are served exclusively over HTTPS using AWS-managed TLS certificates (ACM), and all connections to our database are required to use TLS (enforced at the RDS Proxy level).
Secure Storage - All data is stored on Amazon Web Services (AWS) infrastructure in the US East (N. Virginia) region. File content and metadata stored in Amazon S3 are encrypted at rest using AES-256 (SSE-S3). OAuth tokens and ingestion metadata stored in Amazon DynamoDB are encrypted at rest using AES-256 (AWS default encryption). Our PostgreSQL database is encrypted at rest using AES-256 (AWS KMS). Database credentials and OAuth client secrets are stored in AWS Secrets Manager, encrypted using AWS Key Management Service (KMS).
Third-Party Data Security
Data accessed from your connected services (Google Drive, GitHub, etc.) is:
Encrypted in transit and at rest
Subject to the same security measures as data you directly upload to LabFolio
Never shared with other LabFolio users without your permission
Never sold or used for advertising
While we secure data accessed from your connected services, we cannot control the security of those services themselves. Your data in Google Drive, GitHub, Dropbox, and other connected services is also subject to those services' own privacy policies and security practices.
Breach Notification
In the event of a data breach that affects your personal information, we will notify you promptly and provide information about what happened and what steps we are taking.
Data Retention
We only keep your personal information for as long as it is necessary for the purposes for which it was collected or as otherwise permitted by law, after which it will be destroyed, erased or anonymized. For example, if you are a LabFolio user, we will delete your account profile if you close your account, but may however retain certain limited personal information about you to record your association with content you’ve made public, and as required to comply with applicable law.
Your Rights and Choices
Access and Portability
You have the right to:
Access the personal information we hold about you
Request a copy of your data in a portable format (JSON, CSV)
Review what third-party integrations you have connected
Send a written request to our mailing address (see “Contact Us” section below)
When you delete your account:
Your personal information and research data are permanently deleted within 30 days
Data may persist in backups for up to 30 days for disaster recovery
Anonymized usage statistics may be retained for service improvement
Opt-Out of Communications
You can opt out of non-essential communications:
Marketing or newsletter emails (if we send them): Use the unsubscribe link in the email
Service announcements and security notifications: Cannot be disabled as they are essential to the service
Data Processing Objections
Under GDPR, you have the right to object to certain types of data processing. If you are in the EU and wish to object to how we process your data, contact us at jordan.bell.masterson@gmail.com
International Data Transfers
LabFolio is based in California, United States. If you are accessing LabFolio from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States. When we transfer data internationally, we follow applicable data protection laws in doing so. In particular, when we transfer data from the EEA or UK across other international borders, we rely on Standard Contractual Clauses (SCCs), adequacy decisions (including the EU-U.S. Data Privacy Framework where our service providers are certified), and other legally recognized data transfer agreements to ensure your data receives an equivalent level of protection.
Children's Privacy
LabFolio is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without appropriate consent, we will delete it promptly.
Changes to This Privacy Policy
We may update or change this Policy from time to time. If we make any updates or changes, we will post the new policy on LabFolio's website and update the effective date at the top of this Policy. We will also notify developers of any material changes in accordance with our developer agreements, as they may be better positioned to notify you about changes to this Policy.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
If you are in the European Economic Area, we process your personal information a under the following legal bases:
Contractual necessity - Processing necessary to provide LabFolio services you've requested
Legitimate interests - Processing necessary for our legitimate interests in operating and improving LabFolio, provided these interests don't override your rights
Consent - Where you've given explicit consent (such as for optional integrations)
Legal obligations - Where required by law
Your California Privacy Rights
We provide California residents additional rights that are covered under the California Consumer Privacy Act (CCPA):
Right to Know
You can request information about:
Categories of personal information we collect
Sources of that information
Our business purposes for collecting it
Categories of third parties with whom we share it
Right to Delete
You can request deletion of your personal information, subject to certain exceptions.
Right to Opt-Out
We do not sell personal information. If our practices change, we will update this policy and provide an opt-out mechanism.
Non-Discrimination
We will not discriminate against you for exercising these rights.
How to Exercise Your Rights
To exercise these rights, contact us at jordan.bell.masterson@gmail.com. We will verify your identity before processing your request.
Additional Disclosures
Do Not Track Signals
Our service does not currently respond to "Do Not Track" browser signals. We will update this policy if our practices change.
Cookies and Tracking
We use essential cookies only.
Authentication cookies are set automatically by our login system (NextAuth) to maintain your session while you are logged in. These cookies are strictly necessary for the service to function and cannot be opted out of while using LabFolio.
We do not use analytics, advertising, or tracking cookies.
We do not use any third-party tracking pixels or scripts.
You can delete session cookies at any time by logging out or clearing your browser cookies. This will end your active session.