Privacy Policy
Last updated: 2026-08-02
LabGL Inc. ("LabChure", "we", "us") explains in this policy what personal data we collect when you use LabChure, how we use, share, and protect it, and the rights you have over it.
1. Who we are and what this policy covers
LabChure is operated by LabGL Inc. (Chanhyoung Lee), a company incorporated in the Republic of Korea, business registration number 374-86-02316, with its registered office at B-301, 40 Geumto-ro 80beon-gil, Sujeong-gu, Seongnam-si, Gyeonggi-do, Republic of Korea. For the purposes of data protection law, we are the controller of the personal data described in this policy.
This policy covers three groups of people: (a) visitors to our website (labchure.com), (b) account holders who use the LabChure service, and (c) visitors who view brochures that our customers publish through LabChure (served on labchure.site or on a customer's own domain). Section 3 describes what we collect about brochure visitors.
The content of a published brochure itself is chosen and controlled by the customer who published it. If you have questions about the content of a specific brochure, contact its publisher; if you believe a brochure violates the law or our terms, you can also contact us.
2. Data we collect
Account data. When you register with an email address we store your email, display name, and a one-way cryptographic hash of your password (PBKDF2) — we never store the password itself. When you sign in with Google, we request only the "openid email profile" scope and store the unique account identifier (subject), email address, display name, and the time the email was verified. We never receive your Google password, and we do not store Google access or refresh tokens, your profile photo, or any other Google account data.
Content you upload. Source files you upload (PDF, Office documents, images, and similar), the text and images extracted from them, and the brochures generated from them. This content is processed to produce your brochures and stored on your behalf. It may include personal data contained in your documents — you are responsible for having the right to upload it (see our Terms of Service).
Billing data. Payments are processed by Polar, our merchant of record. We never receive or store your card number or full payment details. We store your subscription or purchase status, plan, and order identifiers needed to operate your account.
Usage and log data. Standard technical logs needed to operate and secure the service (request logs, timestamps, error diagnostics), your language preference, and — for sign-in and sign-up endpoints — your IP address is used transiently for rate limiting to protect against abuse.
AI call records. For each AI operation we record token counts, cost, latency, model used, and a hash of the output for billing and quality control. These records do not contain the text of your documents or of the generated copy.
Transactional email. We send service email to your registered address: a verification link when you create an account, and a password reset link when you request one. These links carry a short-lived signed token and no other personal data. We do not send marketing email, and there is nothing to unsubscribe from — turning these off would remove your only way to recover an account.
3. Analytics — published brochures and our website
When someone views a published brochure or clicks a button on it, we record a view or click event so the publisher can see how their brochure performs. We designed this measurement to be minimal and cookie-free:
- No cookies and no third-party scripts are used on published brochures — the page is a self-contained document.
- We do not store the visitor's IP address. It is immediately converted to a SHA-256 hash using a salt that rotates daily, so the same visitor can only be recognized within a single day and never across days.
- We store the browser's User-Agent string (truncated to 400 characters), the referring URL if the browser sends one, a derived device type (desktop / mobile / tablet / bot), the brochure and language viewed, and for clicks the destination URL.
- We do not collect the visitor's name, precise location, or country.
- Raw events are automatically deleted after 90 days. Only aggregated daily statistics (view counts per brochure, with no per-visitor data) are kept and shown to the publisher.
- On labchure.com itself (our marketing pages and app) we additionally measure aggregate traffic through Vercel Web Analytics, which is also cookie-free: no analytics cookies are set, no advertising or cross-site identifiers are used, and visitors are counted from a hash derived from the request. We receive only aggregated reports — page paths, referring sites, region, device type — and cannot identify an individual visitor from them.
- Within that measurement we record a few product events that contain no personal data: that a sign-up completed, which content page it came from, and that a checkout was started. They carry no name, e-mail address, or account identifier. Published brochures are not part of this — they carry no third-party script at all.
4. How we use data, and legal bases
We use the data above to: create, publish, and serve your brochures; authenticate you and keep your account secure; process subscriptions and purchases; show publishers aggregated brochure statistics; operate, debug, and improve the service; enforce our terms; and comply with legal obligations.
Where the EU/UK GDPR or similar laws apply, our legal bases are: performance of our contract with you (providing the service, billing); our legitimate interests (securing and improving the service, measuring published brochures in the minimal form described in section 3, preventing abuse); your consent where required (for example, optional sign-in with Google); and compliance with legal obligations.
We do not sell personal data, we do not use your data for third-party advertising, and we do not use automated decision-making that produces legal or similarly significant effects about you.
5. AI processing of your content
LabChure's core function is to analyze the documents you upload and generate brochure copy from them. To do this, relevant parts of your content are transmitted to the AI providers listed in section 6: Anthropic and Microsoft Azure AI (text generation and review), Azure OpenAI (embeddings used for search inside your own workspace), and Azure Document Intelligence (text extraction from scanned PDFs).
Under the terms of these providers' commercial API data policies, content submitted through their APIs is not used to train their models.
Your content is used only to produce output for your own workspace. We do not use one customer's content to generate another customer's brochures, and we do not use your content to train models.
AI-generated output can contain errors or omissions. LabChure provides evidence-grounding and review tools, but you must review generated content before publishing it (see our Terms of Service).
6. Service providers and other disclosures
We rely on a small number of service providers (processors) to run LabChure. Each processes data only as needed to deliver its part of the service, under its own data processing terms:
- Microsoft Azure (database and file storage, hosted in the Korea Central region; also Azure AI services listed below) — account data, uploaded content, generated brochures, analytics events.
- Azure Communication Services — delivery of transactional email (account verification and password reset); receives your email address and the message we send you.
- Anthropic (United States) — AI text generation and review; receives relevant excerpts of your uploaded content.
- Microsoft Azure AI Foundry / Azure OpenAI — fallback AI text generation, and embeddings for search within your workspace.
- Azure AI Document Intelligence — text extraction from scanned or image-based PDF files.
- Cloudflare (global network) — hosting and delivery of published brochures (labchure.site and custom domains), including R2 object storage.
- Vercel (United States / global network) — hosting of the LabChure web application, and cookie-free aggregate website analytics (Vercel Web Analytics).
- Polar (United States) — payment processing as merchant of record; handles your payment details under its own privacy policy.
- Google (United States) — optional "Sign in with Google" authentication only.
7. International data transfers
Our primary data storage (database and uploaded files) is located in the Republic of Korea (Microsoft Azure, Korea Central region). To operate the service we transfer certain data to providers in other countries, as listed in section 6 — principally the United States (Anthropic, Polar, Vercel, Google) and the global delivery networks of Cloudflare and Vercel that serve content from locations near each visitor.
In each case the data transferred is limited to what the provider needs for its role: content excerpts for AI processing, published brochure files for delivery, payment data for billing, and sign-in data for authentication. Data is retained by these providers for the duration of the processing task or as described in their data processing terms.
These transfers are necessary to provide the service you request. Our providers commit to recognized transfer safeguards (such as standard contractual clauses) in their data processing terms. If you do not wish your data to be transferred as described, please do not use the related features — note that AI processing and brochure delivery are core to the service and cannot be provided without these transfers.
8. Cookies and similar technologies
We use no advertising cookies and no third-party analytics cookies anywhere — not on our website and not on published brochures. Our website analytics (section 3) is cookie-free by design, which is why you are not shown a cookie consent banner. The complete list of what we set in your browser is:
- NEXT_LOCALE (cookie, 1 year) — remembers your language choice on labchure.com.
- labchure_oauth_state (cookie, 10 minutes, HttpOnly) and labchure_oauth_rt (cookie, 5 minutes, HttpOnly) — short-lived, encrypted cookies used only during Google sign-in to protect the sign-in flow; deleted as soon as it completes.
- Browser local storage — your sign-in tokens (so you stay signed in) and your selected workspace. These stay in your browser and are removed when you sign out.
- Published brochures set no cookies at all.
9. Data retention and deletion
Account data is kept while your account exists. When you delete an uploaded file in the service, the original file, its parsed text, and images extracted from it are deleted from storage. Published brochures remain online until they are removed (see section 10 and our Terms).
Specific retention periods: raw brochure view and click events — 90 days, then automatically deleted (aggregated daily counts without per-visitor data are retained as statistics); sign-in refresh tokens — at most 14 days, stored only as hashes; AI call records (token counts and costs, no content) — kept for billing and accounting.
When your account is deleted at your request (section 10), we delete or anonymize your personal data and content, including uploaded files and published brochures, except where we must retain records to meet legal, tax, or accounting obligations (for example, transaction records that must be kept under e-commerce and tax law, retained for the statutory period and then deleted). Payment records are held by Polar as merchant of record under its own policy.
10. Your rights
Subject to applicable law, you have the right to: access the personal data we hold about you; correct inaccurate data; delete your data and your account; receive a copy of data you provided (portability); restrict or object to certain processing; and withdraw consent where processing is based on consent, without affecting prior processing.
You can edit your display name, password, and language directly in account settings, and delete uploaded files in your workspace at any time.
For everything else — including account deletion, a copy of your data, or any other request — contact us at support@labchure.com. We may need to verify your identity (normally by confirming control of the account email). We respond without undue delay and at the latest within 30 days.
Exercising your rights is free of charge, and we will not discriminate against you for doing so.
11. Region-specific notices
Republic of Korea. This policy serves as our privacy notice under the Personal Information Protection Act (PIPA). Sections 2–3 describe the items collected, section 4 the purposes, section 9 the retention periods, and sections 6–7 the entrusted processing and overseas transfers. If a dispute is not resolved with us directly, you may contact the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972) or the KISA Privacy Report Center (privacy.kisa.or.kr, 118).
EEA and United Kingdom. The legal bases in section 4 apply to you. You also have the right to lodge a complaint with your local supervisory authority (or the UK ICO). International transfers are described in section 7.
California. We collect the categories of personal information described in sections 2–3 for the purposes in section 4. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. You have the rights to know, delete, correct, and to non-discrimination, exercisable as described in section 10 (including through an authorized agent).
12. Security
We protect data with measures appropriate to a service of our size, including: encryption in transit (TLS) for all connections; encryption at rest provided by our cloud storage providers; one-way hashing of passwords (PBKDF2) and of stored sign-in tokens; workspace-level isolation so one customer's content is not visible to another; least-privilege access to production systems; rate limiting of sign-in endpoints; and analytics that never store raw IP addresses (section 3).
No online service can guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and the competent authorities as required by law.
13. Children
LabChure is a business tool and is not directed at children. You must be at least 14 years old to use it — or older where your local law requires a higher age for consenting to data processing (for example, up to 16 in parts of the EEA). We do not knowingly collect personal data from children below these ages; if you believe a child has provided us data, contact us and we will delete it.
14. Privacy officer, business information, and contact
Privacy officer (Chief Privacy Officer under Korean law): Chanhyoung Lee, support@labchure.com.
LabGL Inc. · Representative: Chanhyoung Lee · Business registration no.: 374-86-02316 · B-301, 40 Geumto-ro 80beon-gil, Sujeong-gu, Seongnam-si, Gyeonggi-do, Republic of Korea · support@labchure.com
15. Changes to this policy
We will update this policy when our data practices change, and post the revised version on this page with a new effective date. For material changes we will give prominent notice on our website before the change takes effect.
This version is effective as of August 2, 2026 and replaces the version dated July 19, 2026.