llab08

Privacy notice

GitHub Builder (Githubuilder) privacy

Applies to the GitHub Builder web app (repository name Githubuilder): a web app hosted on Vercel that sells one-time “runs” which create repositories with backdated commits on your own GitHub account, executed by a background worker on our own server. The app’s footer and its /privacy page link here.

This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The section below explains this product’s data handling and current availability.

Purchases and generation are disabled. No new run can be bought or executed as of the date below. The purchase, token and generation paragraphs describe processing when those features are enabled. Advanced runs will use Anthropic as the AI model provider, through our gateway, as described below.

Account

You sign in through our authentication server with GitHub, Google or an email link. We keep the account id, the email address and, when the sign-in provider supplies them, a display name and avatar URL. We store no password for social sign-in.

Purchases

Runs are one-time purchases processed by Stripe. Card details are entered on Stripe’s checkout page and never reach us. We keep the Stripe customer, checkout-session and payment identifiers, the amount and currency, and the status of each run so that it can be shown on your account page.

Running a job: your GitHub token

To start a run you type a GitHub username, the email address that should appear on the commits, a personal access token and, depending on the tier, a date range and the name, language and description of each repository. The token is encrypted the moment it reaches our server, held only while the run is queued or running, used by the worker solely to create repositories and push commits to your GitHub account, and deleted when the run finishes or fails. It is never written to logs. Use a short-lived token and revoke it on GitHub afterwards. The username, email address, dates and repository names, languages and descriptions are kept with the run record so you can see what was done.

AI generation (Advanced runs)

When Advanced runs are enabled, the worker sends the language (up to 50 characters) and description (up to 500 characters) you enter for each of the two repositories to llab08’s own AI gateway at sub2api.llab08.com. The gateway runs on our server, and connections to it pass through Cloudflare. It passes the text to a third-party AI model provider, which plans the repository’s files; the worker then sends the language with each planned file’s path and purpose, as written by the model, the same way to generate that file’s code. Repository names, your GitHub username, the commit email address and your GitHub token are not sent to the gateway or the provider. If a generation step fails, the worker’s error log on our server records the language and the description or file path, and for a failed file also the repository name. If pushing to GitHub fails, that log records your GitHub username and commit email address.

The AI model provider used through our gateway is Anthropic, with its Claude models. Another provider may be used later only after this section is updated. Anthropic processes the text under its own terms; we make no promise on its behalf about how long it keeps it or whether it uses it to train models.

Emails

When email sending is enabled we send one welcome email through Resend after an account is created. No newsletters.

No ads, no analytics

The app shows no advertising and, as of the date below, loads no analytics or other third-party tracking script. If a future version adds a cookie-less analytics script, this section is updated first.

Hosting and retention

The web app runs on Vercel; the worker and the database run on our own server. Hosts may keep short access logs; we do not use them to identify anyone. Run records stay with your account until you ask us to delete it: write to the address below and we remove the account and its run history.

Contact: hello@llab08.com · Updated 24 September 2026 · All privacy notices