Skip to content
LabTether

Privacy Policy

Effective date: July 14, 2026

LabTether is designed first as self-hosted software. In the default deployment model, the hub, database, agents, and connected infrastructure run under the control of the operator who deploys them rather than under a LabTether-hosted SaaS service.

This page explains the main categories of data processed by:


1. Who Controls Data In A LabTether Deployment

For a self-hosted LabTether deployment, the operator who runs the hub is generally the primary controller of the data collected through that deployment.

That means:

If you are using LabTether on behalf of a team, household, or client environment, you are responsible for making sure your deployment and policies are appropriate for that environment.

2. Data The Hub Processes

Depending on which features you enable, a LabTether hub may process:

Because the product is self-hosted, this data normally stays inside the infrastructure, network, and storage footprint selected by the operator.

3. Data Stored Locally On iPhone And iPad

The iOS app stores a limited set of data locally on the device to support login, offline resilience, and operator preferences.

This can include:

The iOS and iPadOS apps require origin-only hub URLs and use https for non-loopback hubs. Shipping builds include an optional Allow Untrusted TLS setting for private or self-signed hubs. It is off by default, applies only to the exact selected hub origin, and is cleared when that hub is changed or forgotten. When enabled, transport remains encrypted but the certificate does not verify the hub's identity. Installing and trusting the hub CA remains recommended, but the user may choose this compatibility setting instead.

4. Data Stored Locally On macOS

The macOS menu bar agent stores operator-entered secrets in the macOS Keychain and uses local runtime files only as needed to launch the embedded agent process.

Depending on configuration, the macOS surface may locally store:

5. Optional Mobile Telemetry

The iOS app includes an optional Share Mobile Telemetry setting that is off by default and requires explicit opt-in. When enabled, the app sends authenticated mobile observability events to the configured LabTether hub.

These events are intended for product reliability and operator troubleshooting and can include:

This telemetry is best-effort, queued, and batched. In the current implementation, it is sent to the configured hub's POST /telemetry/mobile/client endpoint rather than to a separate LabTether-operated analytics service.

You can enable or disable this setting from the iOS app under Settings → Behavior → Share Mobile Telemetry.

6. Push Notifications, Live Activities, And Lock-Screen Content

If you enable notifications on iOS:

Those preferences can include severity threshold, quiet hours, digest timing, and category or toggle selections needed for delivery behavior.

Incident and remote-session Live Activities are enabled by default and can be disabled in the iOS app settings. When enabled, LabTether may show incident or remote-session status on the lock screen or Dynamic Island. The default detail mode is redacted rather than full-detail exposure. Full detail is an explicit operator choice in app settings.

7. Device Permissions Used By The iOS App

The iOS app currently uses these platform permissions:

Biometric matching is handled by the operating system. LabTether uses the result of that local device-owner approval flow; it does not receive raw biometric templates.

8. Third Parties And External Services

Depending on how you deploy LabTether, data may also be processed by services you choose to use alongside the product, including:

For example, if you use Tailscale, your Tailscale configuration and policies are governed by Tailscale's terms and privacy practices rather than this document.

9. Retention And Deletion

Retention is primarily determined by the operator's deployment and configuration choices. LabTether includes retention controls for several hub-side data classes, but the exact retention behavior depends on how the deployment is configured.

On iOS sign-out, the app clears:

The hub URL is retained for faster re-login unless the operator explicitly changes or clears the saved hub configuration.

Eligible non-owner accounts can request permanent account deletion in the iOS app. The selected hub deletes that local user account and revokes its sessions. Infrastructure records, security audit history, configured retention data, and backups may remain under the hub operator's retention and backup policies. An owner must transfer ownership before deleting the owner account.

10. Security And Operator Responsibilities

LabTether's security posture, transport rules, and secrets-handling model are documented in the project's security documentation. Operators are responsible for:

11. Contact

For general support, setup help, or non-security questions, visit the LabTether GitHub organization.

This page may be updated as the public release contract evolves. When that happens, the effective date at the top of this page will change.