Privacy notice
LabButler is self-hosted software. The organisation running this installation is the data controller; contact them for requests about your data. This page describes what the software itself stores and transmits.
Cookies
LabButler sets two first-party cookies, both strictly necessary to operate the site: a session cookie that keeps you signed in, and a CSRF cookie that protects forms against cross-site request forgery. No analytics, advertising, or other third-party cookies are used, so no cookie consent is required.
Local storage
The dashboard remembers a short list of recently viewed entries in your browser's local storage to personalise your start page. This data never leaves your browser.
Account data
Your account stores your name, email address, and lab memberships with their roles. This is required to provide the service and to scope what you can see and do. Records you create or change (items, requests, comments, attachments) are linked to your account.
Audit log
Changes to inventory and procurement data are recorded in an append-only audit log together with the acting user and timestamp. This serves traceability and accountability within your lab (legitimate interest) and cannot be edited or deleted through the application.
Login protection
To defend against password guessing, failed sign-in attempts are recorded with the IP address and the username used. After repeated failures the combination is temporarily locked out. These records serve security (legitimate interest).
External services
All pages are served entirely from this installation โ no fonts, scripts, or images are loaded from third parties, and no tracking takes place. One optional feature contacts an external service: when you press the GHS suggestion button on a chemical, the server queries PubChem (a service of the U.S. National Institutes of Health) with the CAS number you entered. Your browser never contacts PubChem, and no personal data is transmitted โ only the CAS number and the server's own address.
The application may send emails (for example password resets) through the mail server configured by the operator of this installation.