Laby

Privacy Policy

Laby — the label maker for tiny printers

Last updated: 27 August 2026 · Effective: 27 August 2026 Canonical URL: https://labykit.com/privacy


The short version


1. Who is responsible for your data

The controller under the EU General Data Protection Regulation (GDPR) is:

Fasky e.U. Albert-Schweitzer-Gasse 8 8020 Graz Austria

Email: hello@labykit.com

We are a small company and have not appointed a Data Protection Officer, as we are not required to under Art. 37 GDPR.

This policy covers the Laby mobile app for iOS and Android, and the website at labykit.com.


2. What Laby deliberately does not do

We think the clearest way to describe a privacy policy is to start with what is absent:


3. Data that stays on your device

The following never leaves your phone unless a section further down says otherwise:

What Where it is kept
Your label documents (sizes, text, barcodes, positions) The app’s private document storage
Photos you add to a label Copied into the app’s private storage as an image file, addressed by a content hash
Cropped or scaled versions of those photos The app’s private cache, disposable
Label previews (thumbnails) The app’s private storage
Your paired printer (model, and the identifier your operating system uses to reconnect to it) Local device storage
Small settings flags, e.g. whether you have seen onboarding Local key-value storage

We have no server-side copy of any of this and no way to read it.


4. Ask Laby (the AI feature)

Ask Laby is the feature where you describe a label in your own words — “jam jar label for strawberry, 2026” — and the app lays one out for you. This is the only feature that sends content you authored off your device.

What is sent

When you tap Ask, the app sends the following to our own server (api.labykit.com, a Cloudflare Worker), which forwards the relevant parts to an AI provider:

What is never sent

Who processes it

Processor Role Location
Cloudflare, Inc. Hosts the Ask Laby endpoint and routes model requests Global edge network, request served near you
Google LLC (Gemini API) Generates the label layout US / global
OpenAI, L.L.C. Screens the prompt for prohibited content before it is processed; may alternatively serve as the layout model US
RevenueCat, Inc. Counts the ask against your allowance US

Which model provider serves a given request is a server-side configuration and may change; the categories of data sent do not.

Note that your prompt text is sent to OpenAI’s moderation endpoint for a content check even when Google’s model produces the layout. This screening exists so that Laby refuses requests for content we will not help with; refused prompts do not cost you an ask.

Retention

Processing your prompt is necessary to perform the service you asked for — Art. 6(1)(b) GDPR (performance of a contract). The content screening rests on our legitimate interest in preventing misuse of the feature — Art. 6(1)(f) GDPR.

Please review what the AI produces

The layouts Ask Laby returns are generated automatically and can be wrong. Check every label before you print it, and never rely on generated text for anything that has to be correct by law — ingredients, allergens, dosages, hazard warnings, or regulated markings. See the Terms of Use.


5. Purchases and Laby Pro

Laby Pro is sold as an auto-renewing subscription through the Apple App Store and Google Play. We never see your payment details — Apple and Google process the payment and tell us only whether an entitlement is active.

We use RevenueCat, Inc. to manage subscription state and the monthly Ask Laby allowance. RevenueCat receives and stores:

Legal basis: performance of a contract, Art. 6(1)(b) GDPR. RevenueCat acts as our processor under a data processing agreement, and their privacy policy is at https://www.revenuecat.com/privacy. Apple’s and Google’s own handling of your purchase is governed by their respective privacy policies, as the controllers of that payment relationship.

Restoring a purchase asks the store whether the current store account owns a subscription; it does not create an account with us.


6. Anonymous analytics and crash reports

Laby uses Aptabase (Aptabase, Lda.) for anonymous product analytics, on their EU-hosted instance, so this data does not leave the European Union. Aptabase is built to work without cookies, without persistent device identifiers and, per its documentation, without storing IP addresses — an approximate country is derived at ingest and the address discarded.

The entire analytics surface of the app is five events, and this is the complete list:

Event What it carries
app_started Nothing beyond the fact that the app launched
onboarding_use_case_selected Which of the fixed choices you tapped (home, business, shipping, office, unsure)
onboarding_completed Whether a printer was connected during onboarding
printer_connected Printer brand and model, the protocol variant, battery level, and whether it happened during onboarding
printer_connect_failed Printer brand and model, and an internal error code

Alongside each event, the Aptabase SDK sends standard technical context: app version and build, operating system and version, device model, locale and a short-lived random session identifier.

Deliberately excluded, as a rule we hold ourselves to in code: the text on your labels, your prompts, your photos, file names, and the Bluetooth name or address of your printer (some printers advertise a name derived from their serial number, so those are treated as identifiers and never sent).

Crash reporting is enabled in the same SDK. When the app hits an unhandled error, it reports the error type, message and stack trace from Laby’s own code, plus the technical context above. A stack trace is machine data, but we cannot rule out that an error message occasionally contains a fragment of the value that caused it.

Legal basis: our legitimate interest in understanding which printers people actually use, where connection fails, and where the app crashes — Art. 6(1)(f) GDPR. You can object to this processing at any time by writing to hello@labykit.com.


7. Bluetooth and your printer

Laby connects to thermal label printers over Bluetooth Low Energy. That connection is direct, device-to-printer; nothing about it is routed through us.

What we retain locally is your paired printer’s model and the identifier your OS uses to reconnect. “Forget printer” in Settings removes it.


8. Photos

If you add a photo to a label, iOS or Android shows its own picker and Laby receives only the images you pick. A copy is written into the app’s private storage so the label still renders after you edit or delete the original.

Photos are used purely to draw and print your label. They are never uploaded, never sent to the AI, and never included in analytics.


9. Support, feedback and reports


10. International transfers

Some of the providers above (RevenueCat, OpenAI, Google, Cloudflare) are established in the United States or process data globally. Where personal data is transferred outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses together with the supplementary measures set out in each provider’s data processing agreement. Our analytics provider is hosted inside the EU.

You may request a copy of the relevant transfer safeguards by writing to hello@labykit.com.


11. How long we keep things

Data Retention
Your labels, photos and settings On your device until you delete them or uninstall the app — we have no copy
Ask Laby prompts and generated layouts Not stored by us; retained briefly by the AI provider for abuse monitoring, then deleted
Ask Laby request logs (metadata only) A short period for debugging and abuse prevention
Subscription and allowance records For the life of the subscription and afterwards as long as tax and commercial law requires (in Austria, generally 7 years for billing records held by Apple, Google and us)
Anonymous analytics events Retained by Aptabase in aggregate; they are not personal data we can trace to you
Support email As long as needed to resolve your request, plus statutory retention

12. Your rights

Under the GDPR you have the right to request access to your personal data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21). Where processing rests on consent, you may withdraw it at any time without affecting processing already carried out.

To exercise any of these, write to hello@labykit.com.

One honest caveat: because Laby has no accounts, we usually cannot identify you from the data we hold — anonymous analytics events and an anonymous RevenueCat ID cannot be traced back to a person. Under Art. 11 GDPR we are not required to acquire additional information just to identify you. If you can supply information that lets us locate a specific record (for example, the anonymous customer ID shown in the app, or the store transaction ID of your purchase), we will act on your request.

You also have the right to lodge a complaint with a supervisory authority. The competent authority for us is:

Österreichische Datenschutzbehörde Barichgasse 40–42, 1030 Vienna, Austria https://www.dsb.gv.at · dsb@dsb.gv.at

You may also complain to the authority in your own country of residence.


13. Children

Laby is a general-audience utility and is not directed to children. We do not knowingly collect personal data from children under 14 (the age of digital consent in Austria under §4(4) DSG). If you believe a child has provided us with personal data, contact hello@labykit.com and we will delete it.


14. Security

Labels are stored inside the app’s private, OS-sandboxed storage, which other apps cannot read. All network traffic — to our Ask Laby endpoint, to the stores and to RevenueCat — travels over TLS. API keys for the AI providers live only on our server and are never present in the app, which is why Ask Laby is routed through our own endpoint rather than calling a model provider directly from your phone.

No system is perfectly secure. If we ever become aware of a breach affecting your personal data, we will notify the Austrian Data Protection Authority within 72 hours and inform affected users where the GDPR requires it.


15. Changes to this policy

If we change how Laby handles data, we will update this page and change the “Last updated” date. Material changes will be announced in the app before they take effect. Continuing to use Laby after a change means the updated policy applies.


16. Contact

Fasky e.U., Albert-Schweitzer-Gasse 8, 8020 Graz, Austria hello@labykit.com


Appendix — App Store privacy label mapping

Provided for transparency; it reflects the same facts as above.

Apple data type Collected? Linked to you? Used for tracking?
Contact info, contacts, health, financial info, location, browsing history, search history, sensitive info No No
Photos or videos Not collected — processed on device only No
User content (label text, prompts) Ask Laby prompts only, not stored by us Not linked No
Identifiers (anonymous purchase ID) Yes Not linked to identity No
Purchases Yes (subscription status) Not linked to identity No
Usage data (product interaction) Yes, anonymous Not linked No
Diagnostics (crash data, performance) Yes, anonymous Not linked No