Privacy Notice
Last updated 2 September 2026
haas-lab lets you upload firmware and run it on physical ESP32-C3 hardware that we operate, then streams the serial output back to your browser. This notice describes what personal data that involves, and it describes the system as it is actually built rather than as we would like it to be.
In short
- We collect your name, email address and avatar from Google or GitHub when you sign in, plus records of the jobs you run.
- We use one third-party analytics service, PostHog, to see which parts of the product are used — but only if you turn it on. It is off until you do, and you can turn it off again at any time without losing access to anything. We do not use advertising and we do not sell personal data.
- Your data is stored outside Korea — with Cloudflare, with Prisma, and (if you turn analytics on) with PostHog. Section 5 sets out exactly what goes where.
- To see, correct, export or delete your data, email privacy@haas-lab.com. There is no self-service button for this yet; a person handles it.
1.Who is responsible
haas-lab is operated by an individual based in the Republic of Korea. That person decides why and how the personal data described here is processed, and is the point of contact for any question about it.
There is no company behind haas-lab yet — no incorporated entity of any kind. We would rather tell you that than name one that does not exist. If that changes, this section changes with it and the date at the top moves.
Write to privacy@haas-lab.com. We aim to respond within 10 working days.
2.What we collect
We do not ask for a password. Everything in the first row arrives from the identity provider you choose at sign-in.
| Data | Where it comes from |
|---|---|
| Account identity — your name, email address, profile-image URL, the provider you used (Google or GitHub) and your account identifier at that provider. | Google or GitHub, when you sign in |
| Sign-in tokens — the access, refresh and ID tokens the provider issues for your account, and a session identifier for this browser. | Google or GitHub, at sign-in |
| API tokens— a label, a creation and last-used timestamp, and the token’s permissions. The token secret itself is stored only as a one-way hash and cannot be read back, by us or anyone else. | Created by you |
| Jobs — the firmware binary you upload, its size, the device it ran on, timestamps, status, cost, any simulation result, and the serial output the board produced. | Created by you and by the hardware |
| Credits — your balance and a ledger of every credit movement, including its reason and any note attached. | Generated by the service |
| Account standing — reputation tier and score, account status, any lock and its stated reason, hardware leases, and damage reports raised against a job. | Generated by the service and by administrators |
| Feedback — the subject and body of anything you send us, and our reply. | Created by you |
| Webhooks — any callback URL you configure and its delivery history. | Created by you |
| Connection and diagnostic records — IP address, browser user-agent, requested URL and timing, together with application error logs. Cloudflare generates these in the course of serving the request. | Automatic, on every request |
| Product analytics (only if you turn it on) — a record that a page was viewed or an action taken, with the page path stripped of any job identifier; the browser, operating system, device type, screen size, timezone and language; the referring site; and a random identifier PostHog keeps in this browser, which is not linked to your account — we never tell PostHog who you are. We do not send your name, email address, avatar, IP address, approximate location, firmware, filenames, serial output, feedback text or API-token names. | Your browser, when you have turned analytics on |
Firmware binaries are treated as your content. We do not inspect them beyond the automated safety checks needed to protect the hardware, described in the documentation. If you put personal data inside a firmware image or print it over the serial port, it lands in the job record like anything else.
3.Why we process it, and on what basis
| Purpose | Basis |
|---|---|
| Creating your account, signing you in, and keeping you signed in | Necessary to perform our agreement with you |
| Queueing, flashing and running your firmware, and returning its serial output | Necessary to perform our agreement with you |
| Metering and settling credits, holding escrow, and keeping an audit trail of every balance change | Necessary to perform our agreement with you |
| Protecting shared hardware from damage and abuse — safety checks, rate limits, reputation, account locks and damage reports | Our legitimate interest in keeping physical equipment usable for everyone |
| Diagnosing faults and keeping the service running | Our legitimate interest in operating a working service |
| Answering the feedback and support messages you send us | Necessary to perform our agreement with you |
| Seeing which parts of the product are used, so we work on the right things | Your consent, which you can withdraw at any time |
We do not build a profile of you to predict or influence what you do, we do not make automated decisions with legal or similarly significant effects about you, and we do not use your data to train machine-learning models. If you turn analytics on, we count what happens in the product, under a random per-browser identifier that is not linked to your account, so we can see which features are used.
4.Where it is stored
| What | Where |
|---|---|
| Accounts, jobs, credits, tokens, feedback — every structured record | A managed PostgreSQL database operated by Prisma Data, Inc., in the Asia Pacific (Singapore) region — that is, in Singapore |
| Firmware binaries and stored serial logs | Cloudflare R2 object storage |
| Live serial output while a job is running, and its short replay buffer | A Cloudflare Durable Object dedicated to that job, holding roughly the last 500 events |
| The application itself, and request and error logs | Cloudflare Workers, running on Cloudflare's global network |
| Product analytics events, if you have turned them on | PostHog's service in the United States |
Until August 2026 the service ran from a single workstation in Korea. It no longer does, and that is the reason this notice exists in its current form.
5.Who receives it, and overseas transfer
We do not sell personal data and we do not share it for anyone else’s marketing. Data reaches the following companies because they run infrastructure on our behalf, and they process it only on our instructions.
| Recipient | What they receive | Country |
|---|---|---|
| Cloudflare, Inc. | Everything transmitted to or from the site: account and job data in transit, firmware binaries and serial logs at rest, live job feeds, and connection records including your IP address | United States, with processing across Cloudflare's global network, which includes facilities outside Korea |
| Prisma Data, Inc. | All structured records — your account identity, sign-in tokens, jobs, credit ledger, API-token metadata, feedback and account standing | Incorporated in the United States; the database itself is in Singapore (Asia Pacific (Singapore)) |
| Google LLC / GitHub, Inc. | Whichever you choose to sign in with learns that you signed in to haas-lab, and returns your name, email address and avatar to us. Their own privacy notices govern what they then do with that. | United States |
| PostHog, Inc. | If you turn analytics on: page paths with job identifiers removed, the actions listed in section 2, and a random identifier PostHog keeps in this browser, which is not linked to your account. Not your name, email, avatar or IP address. | United States |
Because these companies and their facilities sit outside the Republic of Korea, using haas-lab necessarily involves transferring your personal data overseas, for the whole time your account exists, for the purposes in section 3. The categories transferred are the ones listed above.
If you do not want your personal data transferred on these terms, do not create an account; if you already have one, write to us and we will close it and delete the data described in section 6. We cannot operate the service without these transfers, so refusing them and using haas-lab are not compatible.
We may also disclose data where the law requires it, and to professional advisers under a duty of confidence. If the business is ever sold or reorganised, we will tell you before your data moves to a different operator.
6.How long we keep it
Being plain about this: no scheduled process deletes user data today. Deletion happens when you ask for it, or when we close your account. We would rather say that than publish a retention schedule nothing enforces.
| Data | Kept for |
|---|---|
| Account identity, credits and account standing | As long as your account is open |
| Sign-in tokens and browser sessions | Until they expire, you sign out, or you disconnect the provider |
| API tokens | Until you revoke one or close your account |
| Jobs, firmware binaries and serial logs | As long as your account is open, unless you delete the job |
| Credit-ledger entries | As long as your account is open. Individual entries are never edited or removed while it is — the ledger is an audit trail, and a balance that cannot be reconstructed is not one |
| Feedback you send us | As long as your account is open |
| Cloudflare request and error logs | Under Cloudflare's own retention for the logging features we have enabled; we do not extend it |
| Product analytics events | Held by PostHog for 1 year; we do not extend it. Because nothing sent to PostHog identifies you, there is no record of you there to delete when you close your account; events already sent stay until that period ends, and turning analytics off stops any more being sent at once. |
When you close your account we delete your identity, jobs, firmware, serial logs, tokens, feedback and ledger. We may keep a minimal record that a given account existed and was closed, where we need it to resolve an outstanding damage report or to meet a legal obligation, and no longer than that requires.
7.Your rights, and how to use them
You can ask us to:
- confirm whether we hold personal data about you, and give you a copy;
- correct anything inaccurate;
- export your data in a machine-readable form;
- delete your account and the data described in section 6;
- stop or restrict a particular use; and
- explain anything in this notice that is unclear.
Email privacy@haas-lab.com from the address on your account. If you write from a different address we will ask you to prove control of the account one, because acting on an unverified deletion request is its own kind of breach.
There is no button in the interface for these yet. A person receives the request and carries it out against the database. We would rather tell you that than imply an automation that does not exist. You can already revoke an individual API token yourself from your settings, and delete an individual job from its page.
If you are in Korea and are not satisfied with our response, you may contact the Personal Information Protection Commission or the Korea Internet & Security Agency’s privacy call centre (dial 118).
8.What we do not do
- No advertising, no advertising identifiers, no ad networks.
- We use one analytics service, PostHog, and only for people who turn it on. It tells us which pages are visited and which actions are taken; it does not record your screen, your keystrokes, what you type into forms, or what you copy. We do not share anything with anyone for their own marketing.
- No selling or renting of personal data.
- No use of your firmware, serial output or feedback to train machine-learning models.
- No accounts for children. haas-lab is a developer tool and is not directed at anyone under 14. If we learn that a child has created an account we will delete it.
- No health, payment-card, biometric or government-identifier data. Do not send it to us; if you do, we will delete it.
9.Keeping data safe
Access to production data is limited to the people who operate the service. API token secrets are stored only as one-way hashes. Traffic to the site is encrypted in transit. Administrator actions check a database-backed permission on every request rather than trusting the interface.
We are not going to tell you the service is “secure” or claim certification under any framework, because neither has been independently verified. If we ever discover a breach affecting your personal data, we will notify you and the relevant authority as the law requires.
10.Changes to this notice
When we change how data is handled — a new recipient, a new country, a new purpose — we will update this page and change the date at the top. For a change that materially affects you, we will tell you before it takes effect rather than after.
Questions about this notice go to privacy@haas-lab.com.