Privacy notices
One section per product. Each section describes only that product’s current data behavior. Contact for every product: hello@llab08.com.
- QRForge
- 鬼怪INDEX (horror-idx)
- SideView
- food-clashing
- KanBridge / ToneBridge
- JPlove
- promptLib
- Cat Dex (petdex)
- r 著數 (coupons)
- GitHub Builder (Githubuilder)
- FoodEasy
- Blocktail
- Block puzzle game (name pending)
- Color Flood (working title)
- AI Wardrobe (aiWardrobe)
- Hong Kong Law Ordinance 香港法例 (Legal-libApp)
- Immigration Info (immigrationApp)
- AI Image Validator (photo-validator)
- AI Image Validator Pro prototype (aiImageDetector)
- Fengshui Master (fengshuiMaster)
- gexDataSale
- EarningFast
- Hum
- MimicCall
- SaaS Health Score (saasCheck)
- StatementSync (easystatement)
- HKbills
- Check-in Photographer (checkin-App)
QRForge privacy
Live at makeqrcode.art
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Data this product handles
- Accounts through Supabase Auth on the studio VM GoTrue: email and Google.
- Saved QR codes and their destination URLs.
- Scan events stored as SCAN_SALT hashes.
- AI quota on the signed-in account.
Hosting is Vercel. Auth is self-hosted GoTrue at supabase.llab08.com.
Contact: hello@llab08.com · Updated 7 September 2026 · top
鬼怪INDEX (horror-idx) privacy
Live at horror.llab08.com
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Data this product handles
No accounts. The page stores exactly two localStorage keys on your device:
hx-shelfhx-sm-counter
After AdSense approval, ads appear only on list pages. Screening rooms and individual records do not carry ads. Google and its partners may use cookies or device identifiers to serve ads; see Google’s partner-sites policy and ad settings.
Hosting is Vercel. The host may keep short access logs. We do not use them to identify anyone.
Contact: hello@llab08.com · Updated 7 September 2026 · top
SideView privacy
Marketing site at sideview.llab08.com. Desktop builds are not signed or published.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Data this product handles
The public site is static HTML. No account. No first-party analytics.
It does load one third-party resource: the page’s web font (Hanken Grotesk) comes from Google Fonts, so opening it requests files from fonts.googleapis.com and fonts.gstatic.com. That request tells Google your IP address, your browser’s user agent and which page asked for the font; see Google’s privacy policy. Nothing else on the site contacts a third party.
Unsigned desktop builds are not published. This page does not describe a downloadable app that does not exist.
Web apps you might later open inside a SideView window would keep their own policies. None of those are shipping now.
Contact: hello@llab08.com · Updated 7 September 2026 · top
food-clashing privacy
Not ready for public or store review. Its current VITE_-configured AI credential would be exposed to browser clients if this build were published. Do not submit this URL to App Store, Play, or AdSense.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Data this product handles
- Forced login through Supabase.
- User input is sent to the third-party provider OpenRouter.
Because the current client build would expose that configured credential, this product stays off the public internet this season.
Deleting your account
You can delete your account and its data in the app under Account → Delete account (the person icon at the top right); deletion is immediate and permanent, and you can also write to hello@llab08.com if you can no longer sign in.
Contact: hello@llab08.com · Updated 7 September 2026 · top
KanBridge & ToneBridge privacy policy
Applies to: 漢橋 KanBridge (com.kanbridge.app) and ToneBridge (com.isriver.tonebridge). Last updated: 2026-09-06.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Summary
Both apps work entirely offline. They do not collect, transmit, or share any personal data. There are no accounts, no analytics, no advertising, no crash reporting, and no network requests of any kind. Both apps ask for no device permission — the only entry in either Android bundle is the framework’s own app-scoped permission guarding a broadcast receiver inside the app, which grants no access to anything on your phone.
Data stored on your device
Your study progress (review history, card scheduling state, settings) is stored only in the app's private storage on your device. It is deleted when you uninstall the app.
Backups you create
The "Export" feature writes a JSON file that you choose where to save or share (via your device's share sheet). That file contains only your study data; the app never uploads it anywhere. What you do with the exported file is under your control.
Text-to-speech
Pronunciation uses audio bundled with the app and/or your device's built-in speech engine. No text is sent to any server by the app. Your operating system's own TTS engine may have its own privacy terms.
Children
The apps are rated for all ages and, because no data is collected, no data about children is collected either.
Changes
If a future version ever collects data (for example optional cloud sync), this policy will be updated first and the change will be described in the app's release notes.
Contact
Content disclaimer
JLPT word lists have not been published officially since 2010; KanBridge's decks are curated study lists. ToneBridge's decks are curated study lists aligned to HSK bands. Neither app is affiliated with the JLPT organisers or with Hanban/CLEC.
Last updated: 2026-09-06 · top
JPlove privacy
Live at jplove.vercel.app. A static site (Astro) hosted on Vercel; it can be installed as a progressive web app.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Data this product handles
- No accounts and no server-side data. The site has no backend of its own; the event guide is a static data file built into the site.
- No analytics scripts. As of the date below the site loads no Google Analytics, gtag, Umami, Plausible or any other third-party analytics script. If that ever changes, this section is updated first.
- Stored on your device: one localStorage key,
jplove:saved, holding the IDs of events you mark as saved. A service worker caches the app shell and event data for offline use and keeps an image cache (jplove-images, at most 50 images, 30 days). Clearing the site’s data in your browser removes all of it. - The share button uses your device’s share sheet (or the clipboard) with the page address; “add to calendar” produces an .ics file inside your browser. Nothing is sent to us.
- Links to official event pages lead to third-party sites with their own policies.
Advertising
The site shows no advertising today and loads no advertising script. When advertising is added it will appear only on list and gallery pages, and this section is updated to name the ad provider and describe the consent step before the first ad request is made.
Hosting is Vercel. The host may keep short access logs. We do not use them to identify anyone.
Contact: hello@llab08.com · Updated 7 September 2026 · top
promptLib privacy
Live at promptlib.llab08.com. A read-only prompt library served from the studio server behind Cloudflare.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Data this product handles
- No accounts, no sign-in and no forms. The site only answers read requests and stores nothing you send; a search term travels in the page address and therefore appears in the access log like any other request.
- No cookies. The page keeps one localStorage key on your device,
promptlib.uiLocale, holding the interface language you picked. Clearing the site’s data in your browser removes it. - Server logs: the application container keeps standard access logs (request path, time, status and the client address as seen by the server). They rotate automatically and are used only to run the service and to investigate abuse. Cloudflare proxies the hostname and processes connection data under its own privacy policy.
- Rate limiting keeps a short-lived, in-memory count of requests per client address (about one minute). It is never written to disk.
- No analytics scripts. As of the date below the site loads no Google Analytics, gtag, Umami, Plausible or any other third-party analytics script or font. If that ever changes, this section is updated first.
- Images: the upstream libraries include example images; this site does not serve them until their licence is confirmed, so it is text-only for now.
- Links to upstream galleries, repositories and original posts lead to third-party sites with their own policies.
Advertising
The site shows no advertising today and loads no advertising script. When advertising is added it will appear only on list and gallery pages, and this section is updated to name the ad provider and describe the consent step before the first ad request is made.
Prompt text is mirrored from community libraries and keeps the licence of the source it came from — CC BY 4.0 for the curated repositories, MIT for the pinned full-corpus repositories, and no stated licence for the PixelForge catalog snapshot. Every source, with the pinned commit where the source is a repository, is listed on the attribution page, and the licence of a single prompt is printed on that prompt’s page.
Contact: hello@llab08.com · Updated 7 September 2026 · top
Cat Dex (petdex) privacy
Applies to the offline cat-breed dex app for Android and iOS, titled Cat Dex (猫咪图鉴 / 貓咪圖鑑 / ねこ図鑑 in its other languages); working title petdex. The same notice is shown inside the app.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Summary
The app works offline. There are no accounts, no sign-in, no analytics, no crash reporting, no advertising SDK and no network requests of its own; the Android store build declares no INTERNET permission. Nothing is sent to us.
Stored on your device
Your collection progress (revealed entries, reveal tokens, language choice) is kept only in the app’s private storage on this device and is deleted when you uninstall the app.
Photos
Adding a photo to an entry only uses your camera or photo library to confirm you took a picture. The photo is not checked, uploaded or kept; the temporary copy is deleted immediately.
Breed scanning (if present in your build)
Some test builds include a “Scan a cat” feature that sends the chosen photo to a third-party AI service to suggest breeds. Store builds ship without it unless this section says otherwise.
Advertising
None as of the date below: the app contains no ad SDK and shows no ads. If a future version adds ads, this section is updated first.
Links
The privacy screen in the app opens this page in your system browser; that is the app’s only outbound link.
Children
The app does not knowingly collect personal data from anyone, including children.
Contact: hello@llab08.com · Updated 7 September 2026 · top
r 著數 (coupons) privacy
Applies to the weekly Hong Kong coupon scanner and deals board, working title r 著數 (repository name coupons): a web app hosted on Vercel that can be installed as a progressive web app. The same notice is linked from the app’s footer.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Summary
No accounts and no sign-in. No analytics as of the date below: the app loads no Google Analytics, gtag, Umami, Plausible or any other third-party tracking script. If a future version adds analytics, this section is updated first. Advertising is covered below.
Scanning coupons (OCR)
Text recognition runs inside your browser with tesseract.js. The photo or screenshot you scan is processed on your device and is never uploaded to us. On first use the browser downloads the OCR engine and the Traditional Chinese and English language files from public content-delivery networks (jsDelivr and tessdata.projectnaptha.com); those hosts see the download request, not your images.
Your wallet
Scanned coupons, their thumbnails, “used” marks and a copy of the current week’s board are kept only in this browser’s IndexedDB storage. Nothing is synced to a server. Clearing the site’s data in your browser, or uninstalling the installed app, removes all of it. A service worker caches the app shell for offline use.
Deals board
When enabled, the weekly deals board is fetched from our server, which caches listings collected from third-party sites (MoneyHero, 小斯 / FlyForMiles, 里先生 / Mr. Miles and merchants’ own pages) for about six hours. The fetch is a plain request for that week’s board; it carries no identifier of you beyond what any web request carries (IP address, browser type). The board is not yet available while the terms of those sources are being confirmed; the app then says so instead of showing sample data.
Paste a link
If you paste a link to add a coupon, our server fetches that page once to read its title and dates, then returns them to your browser. The link is not stored, and only public web addresses are accepted.
Merchant logos
Cards may show a merchant icon loaded from Google’s favicon service (google.com/s2/favicons) for the merchant’s domain. Your browser makes that request directly, so Google sees your IP address and the merchant domain, not the coupon.
Advertising
The app shows no advertising today and loads no advertising script. When advertising is added it will appear only on list and gallery pages — not on your wallet or a scan — and this section is updated to name the ad provider and describe the consent step before the first ad request is made.
Hosting
The app is hosted on Vercel and the shared weekly board on our own database server. Hosts may keep short access logs; we do not use them to identify anyone.
Children
The app does not knowingly collect personal data from anyone, including children.
Contact: hello@llab08.com · Updated 7 September 2026 · top
FoodEasy privacy
Applies to the FoodEasy mobile app for iOS and Android (repository name food-easy): a finder for licensed restaurants in Hong Kong built on the Food and Environmental Hygiene Department’s open data. The “Privacy notice” entry in the app’s Profile tab opens this section.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Summary
Browsing restaurants needs no account. Reviews, photos and favourites need a sign-in with Google or Apple. No advertising and no analytics as of the date below: the app loads no ad SDK and no tracking library. If a future version adds an ad unit, this section is updated first.
Location
The map and the “nearby” search use your device location only while the app is open and only after you grant the system location permission. Your coordinates are sent to our database server to run that one nearby query; they are not stored. If you decline the permission the app still works with search by name or district.
Restaurant data
Restaurant names, addresses, districts, licence types, endorsements and expiry dates are the “Restaurant licences” dataset published by the Food and Environmental Hygiene Department through DATA.GOV.HK, with map coordinates from the CSDI portal, used under the Terms and Conditions of Use of DATA.GOV.HK. This is public licensing data about premises, not data about you; it is refreshed on our server once a day.
Sign-in
Sign-in runs through our own authentication server (supabase.llab08.com) with Google or Apple as the identity provider. We store the account identifier the provider returns, your e-mail address, the display name the provider shares and sign-in timestamps. We never receive your Google or Apple password. Google or Apple see that you signed in to FoodEasy, under their own privacy policies.
Reviews, photos and favourites
Star ratings, review text and photos you post are user content: they are stored on our server and shown to every user of the app next to the restaurant, without editorial review before publication. Reviews are displayed without your name or e-mail address. Favourites are private to your account. Any signed-in user can report a review; a moderator can hide a reported review, after which only its author and moderators can still see it. Photos are kept in a private storage bucket and served through short-lived links.
Deleting your data
You can delete your own reviews in the app. “Delete account” in the Profile tab removes your account together with your reviews, photos, favourites and reports immediately and permanently; there is no waiting period. You can also write to the address below.
Hosting and maps
Account data and user content are stored in a database on a server we operate. Map tiles come from Apple Maps on iOS and Google Maps on Android under their respective terms, so those services see the map area you view. Our server keeps short access logs that we do not use to identify anyone.
Children
The app does not knowingly collect personal data from anyone, including children.
Contact: hello@llab08.com · Updated 7 September 2026 · top
Block puzzle game (name pending)
Applies to our block-building tower-defence game for iOS and Android. The store name is still being chosen; this heading and anchor will be updated before release. The “Privacy notice” link on the game’s home screen opens this section.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the game does today.
Summary
The game plays offline and needs no account. The only data that can leave your device is a nickname and a score, and only when you choose to submit them to the online leaderboard. No advertising and no analytics as of the date below: the app loads no ad SDK and no tracking library.
Online leaderboard (optional)
When a run ends you can type a nickname and tap “Submit score”. We then store that nickname, the score, the wave reached and the time of submission on a database server we operate (supabase.llab08.com). Nothing identifies you: there is no account, no e-mail address and no device identifier. A random token created for the current app session is sent with each submission so the server can limit how often one device submits. A fresh token is created the next time you open the app, and it is never shown on the leaderboard. The app does not keep it once you close it, but we do: it is written to our rate-limiting log, which is deleted after an hour, and — as of 6 September 2026 — a copy is also held on the stored run, which is not deleted. Removing it from the stored run is pending; this section will be updated once that is done. The server also keeps the submitting network address for at most one hour, only to limit repeated submissions, then deletes it.
Nicknames and scores are public: every player of the game can see the top entries. Please do not use your real name if you do not want it shown. If you never tap “Submit score”, the game sends nothing.
Advertising (planned)
A later version is planned to show full-screen ads between games only, with a consent prompt where the law requires one. Before that version is released this section will name the ad provider and what it collects; until then there are no ads.
Removing an entry
To have a leaderboard entry removed, write to the address below with the nickname and the approximate time of submission.
Children
The game does not knowingly collect personal data from anyone, including children; the nickname field is free text and players are asked not to enter real names.
Contact: hello@llab08.com · Updated 7 September 2026 · top
Color Flood (working title)
Applies to our colour-flood puzzle game for iOS and Android (repository name colorFlood). The store name may change; this heading and anchor will be updated before release. The “Privacy notice” entry in the game’s Settings tab opens this section.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the game does today.
Summary
The game runs entirely on your device and needs no account. Your scores, difficulty history and haptic setting are kept only in the app’s local storage on your device; nothing is sent to us and there is no online leaderboard. No advertising and no analytics as of the date below: the app loads no ad SDK and no tracking library.
Advertising (planned)
A later version is planned to show full-screen ads between games only, with a consent prompt where the law requires one. Before that version is released this section will name the ad provider and what it collects; until then there are no ads.
Deleting your data
“Reset Statistics” in the Settings tab clears the stored scores; uninstalling the app removes everything the game stored.
Children
The game does not knowingly collect personal data from anyone, including children.
Contact: hello@llab08.com · Updated 7 September 2026 · top
AI Wardrobe (aiWardrobe) privacy
Applies to the AI Wardrobe app for iPhone and Android (bundle id com.aiwardrobe.com). The same notice is linked from the app’s Settings screen.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Summary
The app catalogues your clothes, picks outfits from your own items using simple rules (your season and weather tags, skipping what you wore recently, then a random pick from the least-worn) and builds packing lists by count. Despite the name there is no AI or ML model in it, and nothing you add is sent to a model or to any other service. It needs an account. No ads and no advertising SDK. No third-party analytics as of the date below; if a future version adds crash reporting or analytics, this section is updated first.
Account
Sign-in (email and password, an email sign-in link, or Google) runs on our own authentication server at supabase.llab08.com. If you choose Google, Google authenticates you and returns your e-mail address, name and avatar to that server; we never see a password. We store your email address and, if you enter or Google returns it, your name. The same sign-in identity is shared with other llab08 products that use this server.
Wardrobe data and photos
Clothing items, tags, storage locations, outfits, wear history, packing lists and workday preferences are stored in our own database. Photos of your clothing are stored in our own storage service, in private buckets that only your account can read. The app has no receipt capture: no screen adds or uploads a receipt, and no receipt image or receipt text exists for your account. If a later version adds receipt capture, or sends receipt images to a text-recognition provider, this section is updated first.
Subscriptions
Premium is sold as an in-app subscription through the App Store or Google Play. Apple or Google processes the payment; RevenueCat (RevenueCat, Inc.) validates the store receipt and tells our server whether your subscription is active. RevenueCat receives an app user identifier that we map to your account and the store transaction details; it does not receive your wardrobe data. We never see your payment card.
Deleting your account
Settings → Delete Account removes your photos from storage, all wardrobe data, your subscription record and the sign-in identity itself, immediately and permanently. Store subscriptions are cancelled through the App Store or Google Play, not by deleting the account.
Hosting
Database, authentication and storage run on our own server. Hosts may keep short access logs; we do not use them to identify anyone.
Children
The app is not directed at children under 13 and does not knowingly collect personal data from them.
Contact: hello@llab08.com · Updated 7 September 2026 · top
GitHub Builder (Githubuilder) privacy
Applies to the GitHub Builder web app (repository name Githubuilder): a web app hosted on Vercel that sells one-time “runs” which create repositories with backdated commits on your own GitHub account, executed by a background worker on our own server. The app’s footer and its /privacy page link here.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Account
You sign in through our authentication server with GitHub, Google or an email link. We keep the account id, the email address and, when the sign-in provider supplies them, a display name and avatar URL. We store no password for social sign-in.
Purchases
Runs are one-time purchases processed by Stripe. Card details are entered on Stripe’s checkout page and never reach us. We keep the Stripe customer, checkout-session and payment identifiers, the amount and currency, and the status of each run so that it can be shown on your account page.
Running a job: your GitHub token
To start a run you type a GitHub username, the email address that should appear on the commits, a personal access token and, depending on the tier, a date range and repository descriptions. The token is encrypted the moment it reaches our server, held only while the run is queued or running, used by the worker solely to create repositories and push commits to your GitHub account, and deleted when the run finishes or fails. It is never written to logs. Use a short-lived token and revoke it on GitHub afterwards. The username, email address, dates and repository descriptions are kept with the run record so you can see what was done.
AI generation (Advanced runs)
For Advanced runs the repository names, languages and descriptions you enter are sent to a third-party language-model provider (OpenRouter, or our own model endpoint) to generate the code. Your GitHub token is not sent to that provider.
Emails
When email sending is enabled we send one welcome email through Resend after an account is created. No newsletters.
No ads, no analytics
The app shows no advertising and, as of the date below, loads no analytics or other third-party tracking script. If a future version adds a cookie-less analytics script, this section is updated first.
Hosting and retention
The web app runs on Vercel; the worker and the database run on our own server. Hosts may keep short access logs; we do not use them to identify anyone. Run records stay with your account until you ask us to delete it: write to the address below and we remove the account and its run history.
Contact: hello@llab08.com · Updated 7 September 2026 · top
Blocktail privacy
Applies to the Blocktail mobile game for iOS and Android (repository name blocktail_flutter): an offline arcade game in which you steer a snake through falling blocks. “Privacy notice” in the game’s Settings screen opens this section.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the game does today.
Summary
The game runs entirely on your device. There is no account, no sign-in and no server: nothing you do in the game is sent to us or to anyone else. We collect no personal data.
Data kept on your device
Your settings (grid size, difficulty, sound on/off, whether the tutorial was completed) and the local high-score table (the name you type after a round, the score and round statistics) are stored only in the app’s private storage on your device. They never leave the device and are removed when you uninstall the game. The name you enter is free text of up to ten characters; you can enter “AAA” or leave it blank.
Advertising and analytics
None as of the date below: the game loads no ad SDK and no analytics or tracking library, and it requests no network permission. We plan to add interstitial ads shown between rounds in a later version; before such a version is released this section will name the ad provider, describe the consent step and explain what that provider receives.
Permissions
The game asks for no device permission. The “Privacy notice” link in Settings opens this page in your browser; the browser, not the game, then handles that request.
Children
The game collects no personal data from anyone, including children.
Contact: hello@llab08.com · Updated 7 September 2026 · top
Hong Kong Law Ordinance 香港法例 (Legal-libApp) privacy
Applies to the Hong Kong Law Ordinance mobile app for iOS and Android (repository name Legal-libApp, bundle id com.hklegal.library): an offline-first, bilingual reader for Hong Kong legislation. The “Privacy policy” row in the app’s Settings → About opens this section.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Summary
The app collects no personal data. It has no account and no sign-in, shows no advertising and loads no analytics, crash-reporting or tracking library. It is ad-free by design: it contains no ad SDK.
Data kept on your device
Your settings (language, theme, font size), bookmarks, recently viewed documents, search history, the downloaded legislation library and a record of which data version was downloaded and when are stored only on your device. Nothing is uploaded. “Clear Data” in Settings, or uninstalling the app, erases all of it.
Downloading the legislation library
The app connects to the internet for one purpose: fetching legislation data from our content delivery network (cdn.llab08.com, served by Cloudflare from storage we operate on Cloudflare R2). This happens when you download or update the library from Settings (“Check for Updates”, “Download All Assets”) and when you open a document that is not yet stored on your device. A fresh install downloads six compressed collection bundles and a manifest; later updates fetch only the files that changed. The app has no background communication. These requests carry no personal information, no device identifiers and no analytics. Cloudflare may keep short-lived standard server logs (IP address, time, file requested) under its own privacy policy; we do not use them to identify anyone.
Legislation content
The legislation text is © The Government of the Hong Kong Special Administrative Region, reproduced from Hong Kong e-Legislation (Department of Justice) as published through DATA.GOV.HK under its Terms and Conditions of Use. The app is not an official government product; for authoritative versions consult elegislation.gov.hk.
Children
The app is suitable for all ages and collects no data from anyone, including children.
Contact: hello@llab08.com · Updated 7 September 2026 · top
gexDataSale privacy
Applies to the gexDataSale web app (repository name gexDataSale): a static site on Vercel that sells one-time downloads of historical intraday options gamma-exposure (GEX) datasets, served by an API on our own server. The site’s footer and its /privacy page link here. Datasets are not on sale yet; this notice describes the app as built.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Summary
No accounts and no sign-in. No ads, no advertising SDK and, as of the date below, no analytics or other third-party script. If a future version adds a cookie-less analytics script, this section is updated first.
Purchases
Payment runs on Stripe Checkout. Card details are entered on Stripe’s page and never touch our servers. We keep an order record: the symbol, date range and file format you chose, the Stripe checkout-session and payment identifiers, an order id and the e-mail address you enter at checkout. The e-mail address and order id are kept so that re-download links can be issued and honoured; the order id is also printed on the Stripe receipt. Write to the address below to have an order record deleted; a deleted order can no longer be re-downloaded.
Free samples and rate limiting
One free sample per network address: we store a salted hash of your IP address, never the address itself, to enforce that limit and to rate-limit requests. The salt is a server secret; changing it clears the ledger.
Downloads
Generated files are stored temporarily in Cloudflare R2 behind time-limited links and expire automatically; a paid file is regenerated from the order id on request.
Hosting and logs
The site runs on Vercel; the API and its database run on our own server. Hosts may keep short access logs (request path, time, status, hashed client address); we do not use them to identify anyone.
Children
The service is not directed at children under 13 and does not knowingly collect personal data from them.
Contact: hello@llab08.com · Updated 7 September 2026 · top
Fengshui Master (fengshuiMaster) privacy
Applies to the Fengshui Master mobile app for iOS and Android (repository name fengshuiMaster, bundle id com.fengshuimaster.app) and the API it talks to at fengshui-api.llab08.com. “Privacy policy” in the app’s Profile screen opens this section.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Summary
The app computes Bazi (Four Pillars) charts, name (five-grid) analyses, home fengshui audits, I-Ching readings and Qimen time windows from rules in traditional texts. To do that it sends the details you type — a name, a birth date and hour, a time zone and, optionally, coordinates or a home’s facing direction — to our server, which returns the result. These are personal data. There is no advertising, no analytics and no tracking library in the app.
What we process and where
Calculations run on a server we operate (the API above). Without an account, the details you enter are used for that request only and are not written to our database. With an account, your email address, a password hash, your language and time-zone preferences and the PDF reports you generate are stored with the account in our database and file store; the chart data used for a report is kept only inside that PDF file. A report can be downloaded only by the account that created it. The app also keeps your profile (name, birth date and hour, time zone) and your last chart on your device so it can open without a network.
AI features
The app contains optional “explain with AI” features. They are switched off in the current release and nothing is sent to any language-model provider. If a later release enables them, this section will name the provider, say exactly what is sent and give you a way to opt out before anything leaves our server.
Deleting your data
Profile → “Delete account” permanently removes the account, its stored analyses and every report file. Clearing the app’s data or uninstalling it removes the profile and chart kept on the device. You can also email hello@llab08.com from the address on the account.
Server logs
Requests reach the server through Cloudflare, which — like our own server — keeps short-lived standard access logs (IP address, time, path). We use them only to keep the service running and do not combine them with account data.
Nature of the content
Charts and readings are a cultural decision framework offered for reflection and entertainment. They are not predictions and not medical, financial, legal or other professional advice; the app says so at onboarding and under every result.
Children
The app is not directed at children and we do not knowingly collect data from anyone under 13.
Contact: hello@llab08.com · Updated 7 September 2026 · top
Immigration Info (immigrationApp) privacy
Applies to the Immigration Info mobile app for iOS and Android (repository name immigrationApp, bundle id app.immigrationinfo.mobile): country profiles for ten destinations compiled from official government pages, a comparison view, a chat assistant and a recommendation form. The “Privacy” link on the app’s Countries screen opens this section.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Summary
The app has no accounts and no sign-in, shows no advertising and loads no analytics, crash-reporting or tracking library. Browsing country profiles sends ordinary requests to our server and nothing else. The only personal data that can reach us is what you type into the chat or the recommendation form.
Chat and recommendations
Questions you type in Chat, and the details you enter for a recommendation (nationality, profession, family situation, budget and goals), are sent to our server. The server looks up matching excerpts of the country profiles and sends your text together with those excerpts to our configured large-language-model provider, which generates the answer; the provider receives that text and nothing about your device. We do not use your questions to train any model.
Sub-processor for this feature: our configured LLM provider. Owner to confirm: the provider’s name and its data-processing terms will be named here before launch; until then no statement is made about the provider’s own retention or training practices.
Chat history lives only in the server’s memory for the current conversation: up to the last twenty messages, discarded after one hour without activity or when the service restarts. It is never written to our database.
Data kept on your device
Bookmarked countries are stored only in the app’s private storage on your phone; they are never uploaded and disappear when you uninstall the app.
Server logs and rate limits
Our server keeps an access log with each request’s network address, method, path, status and timing for operations and abuse control, and uses the network address to limit how many chat requests a client can make per minute. Chat and form contents are not written to the log. Logs rotate automatically and we do not use them to identify anyone.
Content
Country profiles are compiled from official government pages and reviewed before publication; every profile and every chat answer cites its source. They are general information, not legal advice.
Children
The app does not knowingly collect personal data from anyone, including children.
Contact: hello@llab08.com · Updated 7 September 2026 · top
AI Image Validator (photo-validator) privacy
Applies to the AI Image Validator mobile app for iOS and Android (repository name photo-validator; store name pending): it estimates whether a photo is AI-generated from three signals (file metadata, error-level analysis and a detection model) and from Content Credentials (C2PA) when the file carries them. The “Privacy Policy” row in the app’s Settings opens this section.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Summary
Images you check are uploaded to our server, analysed in memory and discarded: the server never writes the image to disk and keeps no copy. What stays on the server is the result record described below, tied to your account. The app shows no advertising and loads no analytics or tracking library.
Images
When you check an image, the original file (JPEG, PNG, WebP or HEIC, up to 15 MB) is sent over HTTPS to our server, decoded in memory, examined and released when the check finishes. No image is sent to any third-party service; the detection model runs on our own server. Location data embedded in the file is not read.
What the server stores for each check
The verdict and score; the per-stage scores and the internal signals behind them (whether the file has EXIF metadata, the camera make and model and the editing-software tag if the file carries them, the file format, and the model’s probability); a SHA-256 fingerprint of the file, so that re-checking the same image returns the earlier result instead of running again; the name and version of the detection model; the Content Credentials state and, when a credential is present, the signer name and its claim; warnings, processing time and the time of the check. The fingerprint cannot be turned back into the image. The app displays only the scores; the internal signals stay on the server.
Account and history
Sign-in is by email and password on our own authentication server (supabase.llab08.com), which stores your email address and sign-in timestamps; the same sign-in identity is shared with other llab08 products that use this server. Each check is stored under your account identifier so your history follows you across devices, and every request carries your session token. On this device the app keeps a small thumbnail of each checked image for the History screen, your session token, and an anonymous per-install identifier that is sent with requests but not stored with your checks. Thumbnails never leave the device.
Deleting your data
“Clear History” in Settings deletes every stored check for your account on the server and the thumbnails on this device, immediately. To delete the account itself, write to the address below; in-app account deletion is planned before release.
Permissions
Camera and photo-library access are requested only when you take or pick an image to check; the app does not scan your library in the background.
Hosting and logs
The analysis server, database and authentication server run on infrastructure we operate; requests pass through Cloudflare, which forwards the connecting network address so the server can limit how many checks an address can make per minute (that address is held in memory for the rate limit, not written to our logs). Access logs hold a request id, method, path, status and timing — never image contents — and are not used to identify anyone.
Accuracy
Results are indications, not proof; no published accuracy figure applies to this pipeline yet. Do not rely on a result alone for any decision with legal, financial, safety or reputational consequences.
Children
The app is not directed at children under 13 and does not knowingly collect personal data from them.
Contact: hello@llab08.com · Updated 7 September 2026 · top
AI Image Validator Pro prototype (aiImageDetector)
Applies to the unreleased prototype in the repository aiImageDetector. It is not available in any store; whether it is folded into AI Image Validator (photo-validator) above or archived is an open decision (D-25).
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong.
Summary
The prototype collects no personal data: it has no account, no server and no analytics or ad library. Image checking is switched off in it: the screen that used to simulate a result, the camera and gallery pickers that fed it, and the History screen’s fixed sample rows (whose thumbnails were loaded from images.pexels.com) were all removed on 6 September 2026, so it now makes no outbound request at all and reads no photo. If it is ever released it will share the AI Image Validator (photo-validator) backend, and the section above applies.
Contact: hello@llab08.com · Updated 7 September 2026 · top
EarningFast privacy
Applies to the EarningFast web app (repository name EarningFast): an earnings calendar and real-time 8-K results dashboard hosted on Vercel, backed by two API services on our own server. The app’s footer, its /privacy and /terms pages and the sign-up form link here.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Account
You sign in with an e-mail address and password on our own authentication server at supabase.llab08.com. We store the e-mail address and, if you enter it, your name. The same sign-in identity is shared with other llab08 products that use this server.
Watchlist and webhooks
Tickers you add to your watchlist, and any Discord or Telegram webhook URLs you register for alerts, are stored per account in our own database and are visible only to your account. Webhook URLs are treated as secrets: the app never displays them again, they are used solely to deliver the alerts you asked for, and they are deleted when you remove the webhook or the account. Alerts delivered to Discord or Telegram are then handled under those services’ own privacy policies.
Market data
The earnings calendar and results are collected from public sources — SEC EDGAR filings (sec.gov) and the NASDAQ earnings calendar — and are the same for every user. Our server makes those requests, not your browser, and they carry no information about you.
Requests your browser makes to third parties
Company logos are loaded from Clearbit (logo.clearbit.com) or, as a fallback, ui-avatars.com, and the Inter typeface is loaded from Google Fonts (fonts.googleapis.com, fonts.gstatic.com). Each of these sees your IP address and the file requested under its own privacy policy; none receives your account details.
AI chat
The chat feature is not enabled in the current version. If a later version enables it, your messages would be sent to a language-model provider to generate answers; this section is updated first and the app says so before you send a message.
Advertising and analytics
The app shows no advertising today and loads no advertising script. When advertising is added it will appear only in the dashboard shell, never inside a chart, and this section is updated to name the ad provider and describe the consent step before the first ad request is made.
As of the date below the app loads no analytics or other third-party tracking script. If a future version adds one, this section is updated first.
Hosting and retention
The web app runs on Vercel; the API services, the database and authentication run on our own server. Hosts may keep short access logs; we do not use them to identify anyone. Account data stays until you ask us to delete it: write to the address below and we remove the account, the watchlist and the webhooks.
Children
The app is not directed at children under 13 and does not knowingly collect personal data from them.
Contact: hello@llab08.com · Updated 7 September 2026 · top
Hum privacy
Applies to the Hum app for iOS and Android (repository name hum-music): a client for Subsonic-compatible music servers (Navidrome, Airsonic, Gonic and others) that you run yourself. The app links here from its connect screen and from Settings → About.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Your own server, not ours
Hum ships with no server, no music library and no account with us. On first run you enter the address of a music server you operate or have been given access to, together with your username and password for it. Every request the app makes — sign-in, browsing, searching, streaming, playlists, starring — goes only to that server, at the address you typed. We do not run, see or relay any of it.
What is stored on the device
The server address, username and password are kept in the device’s secure storage (the iOS Keychain; Keystore-backed encrypted storage on Android) so you do not have to sign in again; “Log out” in Settings removes them. Cover art is cached on the device for speed, and playback state may be kept locally. Nothing is stored anywhere else.
What your server receives
As the Subsonic protocol requires, each request carries your username, a salted token derived from your password (not the password itself), and the client name “hum”. What the server keeps or logs is decided by whoever operates it.
Plain-HTTP servers
Self-hosted servers on a home network are often reachable only over plain HTTP, so the app allows it. On such a connection your sign-in and the music travel unencrypted across that network; use an https address whenever your server offers one.
No ads, no analytics, no accounts
The app shows no advertising, contains no analytics or crash-reporting SDK, and has no sign-in with us. We receive no data from it.
Permissions
Internet access, to reach the server you enter; background audio with a playback notification, so music keeps playing with the screen off. No location, contacts, microphone or camera.
Children
The app is not directed at children under 13 and does not knowingly collect personal data from them.
Contact: hello@llab08.com · Updated 7 September 2026 · top
MimicCall privacy
Applies to the MimicCall app for iOS and Android (repository name mimiccall): consent-first session recording that runs entirely on your device. The app links here from its About screen.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Everything stays on the device
MimicCall has no server, no account and no network access of its own: on Android it declares no internet permission, and on iOS it makes no network requests. The video, photos and audio it records are written only to the app’s private storage on the device. The only way a recording leaves the device is when you export it yourself from the Recordings screen, which hands a copy to an app you choose through the system share sheet.
Consent
Before the app can be used at all you must accept a consent notice: you are responsible for obtaining the consent of everyone you record, as the law where you are requires. A recording indicator is shown in every session screen style while a capture is running; no style can hide it.
Encryption and the PIN
On first run you choose a 6-digit PIN. It wraps a randomly generated key that encrypts recordings (AES-256-GCM) before they reach storage. The PIN itself is never stored, so a forgotten PIN means the encrypted recordings cannot be recovered — by you or by us. Encryption is a setting: it is on by default, and when you turn it off the app says so plainly on the session screen and next to each unencrypted recording. The short loop clip that plays during a session is stored unencrypted so that it can be played back.
Export and delete
The Recordings screen lists every capture and lets you export or delete each one, or delete all of them at once. Uninstalling the app removes them all. On Android, captures are excluded from cloud backup and from device-to-device transfer — the app switches backup off entirely. On iOS that exclusion is not in place: captures sit in the app’s private storage, which iCloud Backup and encrypted computer backups include like any other app data, so exclude MimicCall from iCloud Backup in iOS Settings if you do not want copies of them there.
Permissions
What the app asks you for: camera and microphone, to record (photo mode holds no microphone at all), and photo-library access only when you choose a video from your gallery as the loop clip. It asks for nothing about your location or contacts, and it has no internet permission — that one is stripped out of the Android build, so the app cannot open a network connection at all.
The Android bundle also carries permissions that the camera, gallery-picker and video-player libraries it is built on declare for themselves, and Google Play lists these on the store page: view network connections, prevent the phone from sleeping, and read your shared storage (on Android 9 and older, write to it as well) — that last one is how the gallery picker reaches your video on devices without the modern photo-library permission. There is also the Android framework’s own app-scoped permission guarding a broadcast receiver inside the app. None of them lets anything leave your phone.
No ads, no analytics, no accounts
The app shows no advertising, contains no analytics or crash-reporting SDK, and has no sign-in. We receive no data from it.
Children
The app is not directed at children under 13 and does not knowingly collect personal data from them.
Contact: hello@llab08.com · Updated 7 September 2026 · top
SaaS Health Score (saasCheck) privacy
Applies to the SaaS Health Score web app (repository name saasCheck): a web app hosted on Vercel that scores a software business from its public website and the answers you type, with the API and the database on our own server. The app’s /privacy and /terms pages link here.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
The website you submit
You paste a website URL. Our server fetches the publicly accessible pages of that site to produce the report. The domain is also sent to Google PageSpeed Insights and Mozilla HTTP Observatory for performance and security scores, and the fetched content together with any questionnaire answers you type (for example revenue, churn or runway figures) is sent to a third-party language-model provider to write the analysis. Submit only sites and figures you are permitted to share.
Account, evaluations and chat
You can run a limited number of evaluations without an account; for those we keep the IP address only to enforce the daily limit. If you sign in with Google or GitHub we receive the email address and provider user id — no password. Evaluation results and the chat sessions you hold about a report are stored with your account so you can reopen them; write to the address below to have them removed.
PDF reports
A report can be exported as a PDF file. The PDF is built from the stored evaluation and contains the same data as the on-screen report.
Purchases (Pro)
Pro is a subscription processed by Stripe. Card details are entered on Stripe’s checkout page and never reach us. We keep the Stripe customer and subscription identifiers and the plan status so that your plan can be shown in the app.
No ads, no analytics
The app shows no advertising and, as of the date below, loads no analytics or other third-party tracking script; error monitoring may use Sentry. If a future version adds a cookie-less analytics script, this section is updated first.
Hosting and retention
The web app runs on Vercel; the API, the database and authentication run on our own server. Hosts may keep short access logs; we do not use them to identify anyone. Evaluations, chat sessions and subscription records stay with your account until you ask us to delete it: write to the address below and we remove the account and its reports.
Contact: hello@llab08.com · Updated 7 September 2026 · top
StatementSync (easystatement) privacy
Applies to the StatementSync web app (repository name easystatement): a web app hosted on Vercel that turns bank statement files you upload into a list of transactions in your account. The app’s /privacy and /terms pages link here.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
The statement files you upload
You choose and upload bank statement files. Each file is written to a private storage bucket on our own Supabase server under your user id; the bucket is not public and per-user access controls keep one account’s files out of another account’s reach. Deleting a statement in the app removes both the record and the raw file from that bucket.
How a statement is read
Uploads are not parsed inside the web request. A job is placed on a queue and a separate worker process picks it up, downloads the file from the private bucket and extracts the transactions, then marks the statement processed or failed.
AI extraction (off today)
Extraction can be handed to a third-party AI provider, but only when that is switched on for the deployment. It is switched off today: the worker refuses the extraction step and says so on the statement, so no statement file or its contents is sent to any AI provider. If it is ever switched on, this section names the provider first.
Account and results
You sign in through authentication on our own server; the transactions, categories and statement records produced from your files are stored with your account so you can reopen and export them. Write to the address below to have the account and everything in it removed.
Purchases
Paid plans are processed by Stripe. Card details are entered on Stripe’s checkout page and never reach us. We keep the Stripe customer and subscription identifiers and the plan status so that your plan can be shown in the app.
No ads
The app shows no advertising and ships no advertising SDK. If that ever changes, this section is updated first.
Hosting and retention
The web app runs on Vercel; storage, the database, the worker and authentication run on our own server. Hosts may keep short access logs; we do not use them to identify anyone. Statement files, transactions and subscription records stay with your account until you delete them or ask us to delete the account.
Contact: hello@llab08.com · Updated 7 September 2026 · top
HKbills privacy
Applies to the HKbills template gallery at hkbills.vercel.app: a static collection of Hong Kong-style utility e-bill HTML layout templates (electricity, gas, water) with placeholder branding and fictional sample data. It is not affiliated with any utility company or government department.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the site does today.
Summary
The gallery collects no personal data. There are no accounts, no forms, no cookies set by us, no analytics and no advertising. The pages are static files; nothing you do on them is sent to us.
What the pages contain
Every name, address, account number, meter number and amount shown in a template is fictional: the sample customer is 陳大文 / Chan Tai Man at Example House, account 0000-0000-0000. No real customer’s bill is published, and no real company’s logo, name or account format is used. Each template page and its fields.json are generated from the template source and checked against a list of real utility brand names before they are published.
Hosting and logs
The site is served by Vercel from its content delivery network. Like any web host, Vercel may keep short-lived request logs (network address, requested path, user agent) for security and operations; we add no tracking of our own, and Vercel Web Analytics is not enabled for this site.
Advertising
No advertising is shown today. If advertising is added to the gallery pages later, this section will name the ad provider and describe the consent step before any ad request is made.
Your rights and contact
Because no personal data is collected, there is nothing for us to access, correct or delete. Questions about the templates, including a request to remove a layout, go to the address below.
Contact: hello@llab08.com · Updated 7 September 2026 · top
Check-in Photographer (checkin-App) privacy
Applies to the Check-in Photographer mobile app (repository name checkin-App): a store app for iOS and Android in which you prove you visited a spot in Hong Kong with a location check-in and a photo. The app’s Privacy and Terms screens link here.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The facts below describe what the app does today.
Rewards are not open yet. We have not opened the app to merchant partners, so there are no offers to browse and no vouchers to earn. Checking in and exploring work today. The merchant and voucher paragraphs below say what would apply if rewards open; this section is updated before that happens.
Summary
The app handles location check-ins with photos. Your account lives on our own authentication server; your photos live in our own storage. There is no advertising. Merchant accounts, offers and vouchers are not open: none exist and none are issued in the current version.
Check-ins
When you check in, the app sends your device’s location fix (coordinates and accuracy), the spot you chose, the time, and the proof photo you take inside the app. The server checks that the fix lies within the spot’s area and that you have not already checked in there in the last 24 hours, then stores the check-in with the photo. Photos are used only to validate the check-in; they are stored in a private bucket on our own storage server and are not shown to other users or merchants.
Account
You sign in with Google or Apple through our own authentication server at supabase.llab08.com. We receive the name, e-mail address and avatar the provider shares with us; we never see a password. The same sign-in identity is shared with other llab08 products that use this server.
Merchants, offers and vouchers — not open
There is no way to register as a merchant and no way to publish an offer, so no voucher can be issued: the app holds no offer or voucher data for you, and none of it reaches anyone. When rewards open, merchants would register an account (name, organisation, location) and publish offers tied to spots; when a check-in is approved, matching vouchers would be issued to your account and we would keep each voucher’s code, status and redemption time so a merchant can redeem it once; a voucher would be an offer made by the merchant named on it. None of that happens today, and this section is updated before any of it does.
Spots and events
Spots and cultural events come from Hong Kong open data (tourist attractions, LCSD venues and events, AFCD visitor centres). Requests for this data are made by our server, not by your device. No merchant-supplied spot exists, because there are no merchants.
No ads, no analytics
The app shows no advertising and, as of the date below, loads no analytics or other third-party tracking. Error monitoring may use Sentry when it is configured; if a future version adds either advertising or analytics, this section is updated first.
Hosting and retention
The API, the database, authentication and photo storage run on our own server. Check-ins and photos stay with your account until you ask us to delete it: write to the address below and we remove the account, its check-ins and photos (and any vouchers, if rewards have opened by then). In-app account deletion is not available yet.
Children
The app is not directed at children under 13 and does not knowingly collect personal data from them.
Contact: hello@llab08.com · Updated 7 September 2026 · top