01 / Scope
The public site and private channel.
This notice applies when you visit thelab.io, speak with an AI perspective, or leave an email address so TheLab can continue the conversation. The AI channel is not a confidential or privileged communication service. Do not send passwords, credentials, regulated data, trade secrets, or other information you are not prepared to share with the service providers described below.
02 / Information
What the system retains.
- Conversation messages, the selected perspective, session and request identifiers, handoff state, and timestamps.
- Your email address if you choose to submit it, together with the conversation and qualification state connected to that handoff.
- Basic request metadata. A salted hash of an IP address is used for rate limiting. If you submit an email address, the associated IP address and user-agent may also be stored with the lead record.
- Hosting and diagnostic logs produced when the site or its API functions are requested.
03 / Use
Why the information is used.
TheLab uses this information to operate the conversation, preserve context, respond to inquiries, deliver requested handoffs, prevent duplicate or abusive use, secure and diagnose the service, and evaluate whether the channel works as intended. TheLab does not sell this information or use it to build advertising profiles.
04 / Providers
Systems that process the channel.
- Vercel
- Hosts the website and API functions and produces request logs.
- OpenAI
- Processes conversation content to generate AI responses.
- Neon
- Hosts the Postgres database containing conversation, lead, notification, and rate-limit records.
- Slack
- Receives a notification when a conversation begins and another if you choose to leave an email address. Notifications include the selected perspective, session identifier, and limited conversation context; the start notification does not include an email address or IP address.
These providers process information under their applicable agreements and privacy terms. The current public experience does not use advertising trackers.
05 / Retention
How long records remain.
Conversation and lead records are retained while reasonably useful for responding, maintaining business records, securing the service, and evaluating the channel. TheLab does not currently apply a fixed automatic deletion period to those records. Rate-limit records stop affecting access after 24 hours of inactivity and are periodically removed. Service providers may retain their own operational records under their respective policies or legal obligations.
06 / Choices
Access, correction, and deletion.
You do not have to use the AI channel or leave an email address. To ask what information TheLab has associated with you, correct it, or request deletion, email b@thelab.io. Include the email address you submitted and the approximate date of the conversation; do not repeat sensitive message content.
TheLab may need to verify a request and may retain information where reasonably necessary for security, legal obligations, or the establishment or defense of claims.
07 / Changes
Updates to this record.
This page may change as the channel or its providers change. The effective date above identifies the current version.