Privacy Notice

Last updated 2 September 2026

haas-lab lets you upload firmware and run it on physical ESP32-C3 hardware that we operate, then streams the serial output back to your browser. This notice describes what personal data that involves, and it describes the system as it is actually built rather than as we would like it to be.

In short

  • We collect your name, email address and avatar from Google or GitHub when you sign in, plus records of the jobs you run.
  • We use one third-party analytics service, PostHog, to see which parts of the product are used — but only if you turn it on. It is off until you do, and you can turn it off again at any time without losing access to anything. We do not use advertising and we do not sell personal data.
  • Your data is stored outside Korea — with Cloudflare, with Prisma, and (if you turn analytics on) with PostHog. Section 5 sets out exactly what goes where.
  • To see, correct, export or delete your data, email privacy@haas-lab.com. There is no self-service button for this yet; a person handles it.

1.Who is responsible

haas-lab is operated by an individual based in the Republic of Korea. That person decides why and how the personal data described here is processed, and is the point of contact for any question about it.

There is no company behind haas-lab yet — no incorporated entity of any kind. We would rather tell you that than name one that does not exist. If that changes, this section changes with it and the date at the top moves.

Write to privacy@haas-lab.com. We aim to respond within 10 working days.

2.What we collect

We do not ask for a password. Everything in the first row arrives from the identity provider you choose at sign-in.

DataWhere it comes from
Account identity — your name, email address, profile-image URL, the provider you used (Google or GitHub) and your account identifier at that provider.Google or GitHub, when you sign in
Sign-in tokens — the access, refresh and ID tokens the provider issues for your account, and a session identifier for this browser.Google or GitHub, at sign-in
API tokens— a label, a creation and last-used timestamp, and the token’s permissions. The token secret itself is stored only as a one-way hash and cannot be read back, by us or anyone else.Created by you
Jobs — the firmware binary you upload, its size, the device it ran on, timestamps, status, cost, any simulation result, and the serial output the board produced.Created by you and by the hardware
Credits — your balance and a ledger of every credit movement, including its reason and any note attached.Generated by the service
Account standing — reputation tier and score, account status, any lock and its stated reason, hardware leases, and damage reports raised against a job.Generated by the service and by administrators
Feedback — the subject and body of anything you send us, and our reply.Created by you
Webhooks — any callback URL you configure and its delivery history.Created by you
Connection and diagnostic records — IP address, browser user-agent, requested URL and timing, together with application error logs. Cloudflare generates these in the course of serving the request.Automatic, on every request
Product analytics (only if you turn it on) — a record that a page was viewed or an action taken, with the page path stripped of any job identifier; the browser, operating system, device type, screen size, timezone and language; the referring site; and a random identifier PostHog keeps in this browser, which is not linked to your account — we never tell PostHog who you are. We do not send your name, email address, avatar, IP address, approximate location, firmware, filenames, serial output, feedback text or API-token names.Your browser, when you have turned analytics on

Firmware binaries are treated as your content. We do not inspect them beyond the automated safety checks needed to protect the hardware, described in the documentation. If you put personal data inside a firmware image or print it over the serial port, it lands in the job record like anything else.

3.Why we process it, and on what basis

PurposeBasis
Creating your account, signing you in, and keeping you signed inNecessary to perform our agreement with you
Queueing, flashing and running your firmware, and returning its serial outputNecessary to perform our agreement with you
Metering and settling credits, holding escrow, and keeping an audit trail of every balance changeNecessary to perform our agreement with you
Protecting shared hardware from damage and abuse — safety checks, rate limits, reputation, account locks and damage reportsOur legitimate interest in keeping physical equipment usable for everyone
Diagnosing faults and keeping the service runningOur legitimate interest in operating a working service
Answering the feedback and support messages you send usNecessary to perform our agreement with you
Seeing which parts of the product are used, so we work on the right thingsYour consent, which you can withdraw at any time

We do not build a profile of you to predict or influence what you do, we do not make automated decisions with legal or similarly significant effects about you, and we do not use your data to train machine-learning models. If you turn analytics on, we count what happens in the product, under a random per-browser identifier that is not linked to your account, so we can see which features are used.

4.Where it is stored

WhatWhere
Accounts, jobs, credits, tokens, feedback — every structured recordA managed PostgreSQL database operated by Prisma Data, Inc., in the Asia Pacific (Singapore) region — that is, in Singapore
Firmware binaries and stored serial logsCloudflare R2 object storage
Live serial output while a job is running, and its short replay bufferA Cloudflare Durable Object dedicated to that job, holding roughly the last 500 events
The application itself, and request and error logsCloudflare Workers, running on Cloudflare's global network
Product analytics events, if you have turned them onPostHog's service in the United States

Until August 2026 the service ran from a single workstation in Korea. It no longer does, and that is the reason this notice exists in its current form.

5.Who receives it, and overseas transfer

We do not sell personal data and we do not share it for anyone else’s marketing. Data reaches the following companies because they run infrastructure on our behalf, and they process it only on our instructions.

RecipientWhat they receiveCountry
Cloudflare, Inc.Everything transmitted to or from the site: account and job data in transit, firmware binaries and serial logs at rest, live job feeds, and connection records including your IP addressUnited States, with processing across Cloudflare's global network, which includes facilities outside Korea
Prisma Data, Inc.All structured records — your account identity, sign-in tokens, jobs, credit ledger, API-token metadata, feedback and account standingIncorporated in the United States; the database itself is in Singapore (Asia Pacific (Singapore))
Google LLC / GitHub, Inc.Whichever you choose to sign in with learns that you signed in to haas-lab, and returns your name, email address and avatar to us. Their own privacy notices govern what they then do with that.United States
PostHog, Inc.If you turn analytics on: page paths with job identifiers removed, the actions listed in section 2, and a random identifier PostHog keeps in this browser, which is not linked to your account. Not your name, email, avatar or IP address.United States

Because these companies and their facilities sit outside the Republic of Korea, using haas-lab necessarily involves transferring your personal data overseas, for the whole time your account exists, for the purposes in section 3. The categories transferred are the ones listed above.

If you do not want your personal data transferred on these terms, do not create an account; if you already have one, write to us and we will close it and delete the data described in section 6. We cannot operate the service without these transfers, so refusing them and using haas-lab are not compatible.

We may also disclose data where the law requires it, and to professional advisers under a duty of confidence. If the business is ever sold or reorganised, we will tell you before your data moves to a different operator.

6.How long we keep it

Being plain about this: no scheduled process deletes user data today. Deletion happens when you ask for it, or when we close your account. We would rather say that than publish a retention schedule nothing enforces.

DataKept for
Account identity, credits and account standingAs long as your account is open
Sign-in tokens and browser sessionsUntil they expire, you sign out, or you disconnect the provider
API tokensUntil you revoke one or close your account
Jobs, firmware binaries and serial logsAs long as your account is open, unless you delete the job
Credit-ledger entriesAs long as your account is open. Individual entries are never edited or removed while it is — the ledger is an audit trail, and a balance that cannot be reconstructed is not one
Feedback you send usAs long as your account is open
Cloudflare request and error logsUnder Cloudflare's own retention for the logging features we have enabled; we do not extend it
Product analytics eventsHeld by PostHog for 1 year; we do not extend it. Because nothing sent to PostHog identifies you, there is no record of you there to delete when you close your account; events already sent stay until that period ends, and turning analytics off stops any more being sent at once.

When you close your account we delete your identity, jobs, firmware, serial logs, tokens, feedback and ledger. We may keep a minimal record that a given account existed and was closed, where we need it to resolve an outstanding damage report or to meet a legal obligation, and no longer than that requires.

7.Your rights, and how to use them

You can ask us to:

  • confirm whether we hold personal data about you, and give you a copy;
  • correct anything inaccurate;
  • export your data in a machine-readable form;
  • delete your account and the data described in section 6;
  • stop or restrict a particular use; and
  • explain anything in this notice that is unclear.

Email privacy@haas-lab.com from the address on your account. If you write from a different address we will ask you to prove control of the account one, because acting on an unverified deletion request is its own kind of breach.

There is no button in the interface for these yet. A person receives the request and carries it out against the database. We would rather tell you that than imply an automation that does not exist. You can already revoke an individual API token yourself from your settings, and delete an individual job from its page.

If you are in Korea and are not satisfied with our response, you may contact the Personal Information Protection Commission or the Korea Internet & Security Agency’s privacy call centre (dial 118).

8.What we do not do

  • No advertising, no advertising identifiers, no ad networks.
  • We use one analytics service, PostHog, and only for people who turn it on. It tells us which pages are visited and which actions are taken; it does not record your screen, your keystrokes, what you type into forms, or what you copy. We do not share anything with anyone for their own marketing.
  • No selling or renting of personal data.
  • No use of your firmware, serial output or feedback to train machine-learning models.
  • No accounts for children. haas-lab is a developer tool and is not directed at anyone under 14. If we learn that a child has created an account we will delete it.
  • No health, payment-card, biometric or government-identifier data. Do not send it to us; if you do, we will delete it.

9.Keeping data safe

Access to production data is limited to the people who operate the service. API token secrets are stored only as one-way hashes. Traffic to the site is encrypted in transit. Administrator actions check a database-backed permission on every request rather than trusting the interface.

We are not going to tell you the service is “secure” or claim certification under any framework, because neither has been independently verified. If we ever discover a breach affecting your personal data, we will notify you and the relevant authority as the law requires.

10.Changes to this notice

When we change how data is handled — a new recipient, a new country, a new purpose — we will update this page and change the date at the top. For a change that materially affects you, we will tell you before it takes effect rather than after.

11.Cookies and similar technologies, and how to refuse them

Two kinds of storage are used in your browser.

Necessary. Keeping you signed in and protecting the sign-in form. Without these you cannot use an account, so there is nothing to turn off. They are set when you sign in.

Analytics, only if you turn it on.PostHog stores an identifier in your browser's local storage and a cookie so that separate visits can be counted as one person rather than several. Nothing is stored and nothing is sent until you turn analytics on.

How to refuse. Analytics is off until you turn it on, so refusing means doing nothing. If you have turned it on, turn it off in your profile; we stop sending immediately and clear what is stored in your browser. You can also block or delete these through your browser's own settings, and you can use a tracker blocker — we do not route analytics through our own domain to get past one. Turning analytics off changes nothing else: every part of haas-lab works the same either way.


Questions about this notice go to privacy@haas-lab.com.