Privacy Policy
Last updated: 11 September 2026
ServiceLabs is a developer utilities platform operated by Finnoto (“we”, “us”). This policy explains what information we handle when you use servicelabs.dev, the console at app.servicelabs.dev and the API at api.servicelabs.dev (together, the “Service”), and why.
Information we collect
Account information. Your email address, name and role, and, if you sign in with a password, a one-way (argon2id) hash of that password. If you turn on two-factor authentication, we store its secret encrypted. We record when you last signed in.
Google sign-in. If you choose “Continue with Google”, we request only the
openid, email and profile scopes. From Google we
receive your email address, whether it is verified, your name, your Google account
identifier and your Google Workspace domain. We use these solely to sign you in and to
create or link your ServiceLabs account.
Sessions and API keys. For each signed-in session we keep a hashed session token, its creation and expiry time, your IP address and browser user agent. For API keys we store the key's name, a short display prefix, a one-way hash of the key (never the key itself), its permissions and when it was last used, plus an encrypted signing secret for callbacks.
Jobs. Every utility call is recorded as a job: the input you send (for example the URLs of documents to process and any options), any metadata you attach, the resulting file links, status, timings, error messages, the callback URL if you set one, and the calling IP address and user agent.
Files. The utilities fetch documents from the URLs you provide, process them, and store the resulting files. Output files are stored in cloud object storage and are reachable by anyone who has their link. Links are long and unguessable, but do not use the Service for documents that must never be accessible via a link.
Usage and logs. We keep aggregated usage statistics (request counts, success rates and latency per utility and per API key) and operational server logs (IP address, request path, status and timing).
How we use information
- To provide the Service: authenticate you, run the utilities you call, deliver results and callbacks.
- To secure the Service: rate limiting, preventing abuse, investigating incidents.
- To operate and improve it: monitoring availability, usage and performance.
- To contact you about your account or the Service.
We do not sell personal information, and we do not use it for advertising.
Google user data
ServiceLabs's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google account data only to sign you in; we do not transfer it to third parties except as needed to provide the Service, and we do not use it for advertising or to train models.
Cookies and local storage
The console sets a single, strictly necessary session cookie (du_session,
HTTP-only) to keep you signed in, and stores display preferences such as light or dark
theme in your browser's local storage. We do not use analytics or advertising cookies. The
website loads fonts from Google Fonts, which means Google receives your IP address when
you visit it.
Service providers
We rely on these providers to run the Service, each processing information only on our behalf:
- Amazon Web Services: runs the utilities and stores output files (Mumbai region, ap-south-1).
- Cloudflare: DNS, TLS and traffic protection in front of the Service.
- Google: sign-in with Google, and web fonts on the website.
The Service itself runs on servers operated by Finnoto.
Retention
- Job records (inputs, metadata, results and errors) are deleted 90 days after creation.
- Output files are kept for a limited period and may be removed without notice. Download anything you need to keep.
- Sessions expire after 14 days of inactivity and are then deleted.
- Aggregated usage statistics are kept to track usage over time; they contain no document content.
- Account data is kept while your account exists; an administrator can disable or remove it at any time.
Security
All traffic is encrypted in transit (HTTPS). Passwords and API keys are stored only as one-way hashes; two-factor and signing secrets are encrypted at rest. Access is limited by roles, and external (guest) accounts can only see their own keys, jobs and usage.
Your choices and rights
You can view and update your profile in the console and turn two-factor authentication on or off. To ask for a copy of your information, a correction, or deletion of your account, contact us at [email protected]. You can also revoke ServiceLabs's access to your Google account at any time from your Google account permissions.
Changes
We may update this policy. We will change the date at the top when we do, and tell account holders about material changes.
Contact
Questions about this policy: [email protected].