Draft — not yet in force.
This document is an unreviewed working draft. Every TODO below needs a real value, and the whole thing needs review by a lawyer before it means anything. Remove this notice when that's done.
Privacy Policy
Last updated August 6, 2026
LabLink helps university students find research labs and faculty mentors at their own institution. This page describes what we collect, why we collect it, and who else sees it.
Who we are
LabLink is operated by TODO: legal entity name and mailing address. For any question about this policy or your data, contact us at TODO: contact email address.
What we collect when you sign in
You sign in with your university account, through either Google or Microsoft depending on which your school uses. We do not create or store a password.
From your identity provider we receive:
- Your university email address.
- Your display name, as your school has it.
- A link to your profile photo, when the provider supplies one. Microsoft accounts generally do not, in which case we show your initial instead.
We derive your institution from your email domain, and we use your email address to verify a faculty profile claim by matching it against the contact address already published for that researcher.
What we do not collect
Signing in does not give LabLink access to your mailbox, your files, your calendar, or your contacts. The permission screen your school's provider shows on first sign-in covers reading your basic profile and keeping you signed in — nothing more. We never see your password.
What you give us as you use the service
- Your research interests. The text you write when searching for a lab, and any follow-up messages in the assistant conversation.
- Files you attach to a search, if you attach any.
- Your student profile. Department, year, and a short bio, which you can edit or leave blank.
- Your workspace. The matches a search returned and the filters you applied, so you can come back to them on another device.
- Which faculty profiles you open and star. Opening a profile records that you were interested in it; starring one saves it to your own list. We record each professor once per student, so revisiting someone changes nothing.
What we tell professors
Faculty profiles are built without the researcher's involvement, so we write to them to say students are reading their work and invite them to claim their profile. What we send is a count — how many students have shown interest — and nothing more.
We never tell a professor which students opened or starred their profile, and we never send them your name, your email, your search text, or anything else from your account. A professor cannot see who is interested in them, only how many.
Faculty profiles built from public sources
Profiles of researchers are assembled from publicly available scholarly records — principally OpenAlex, an open index of published work — together with a short summary generated by an AI model from those public records. They are created without the researcher's involvement, which is why any researcher can claim their own profile and correct it.
Summaries are machine-generated and may be inaccurate or out of date. If you are a researcher and want your profile corrected or removed, write to TODO: contact email address and we will act on it within TODO: state a response window, e.g. 30 days.
Who else your data goes to
We do not sell your data and we do not use it for advertising. We rely on these providers to run the service, and each sees only what it needs:
- Google (Firebase) — sign-in, and storage of your student profile and workspace.
- Microsoft — sign-in only, for students at schools on Microsoft 365.
- Render — hosting and our database of accounts and faculty profiles.
- OpenAI — receives your research-interest text in order to match you to labs. Do not put anything confidential in a search.
- Perplexity— receives a researcher's name and institution in order to draft their profile summary. No student data is sent.
- OpenAlex — the public source of scholarly records.
We may also disclose data where the law requires it. TODO: confirm this list against every service actually in production before publishing, and add a data-processing basis if you take EU or UK users
Stored on your device
We keep a small amount of state in your browser rather than on our servers: your theme preference, which side of the platform you signed in as, which school your searches default to, and a copy of your most recent search session. Clearing your browser storage removes all of it. We do not use advertising or tracking cookies.
How long we keep it
Account records and your student profile are kept while your account exists. TODO: state retention for search history and deleted accounts, and confirm it matches what the code actually does
Your choices
- You can edit your student profile at any time.
- You can ask us to delete your account and the data associated with it by writing to TODO: contact email address.
- Researchers can claim, correct, or request removal of a profile, as described above.
TODO: add the specific rights you need to offer for your users' jurisdictions — e.g. access, correction, portability, objection
Children
LabLink is intended for university students and faculty and is not directed at children under 13. TODO: revisit if you ever admit dual-enrollment or pre-college students
Changes to this policy
We will update the date at the top of this page when this policy changes, and will give notice in the app if the change is significant.
See also Privacy Policy and Terms of Service.