Last updated: 6 October 2026
1. Data Controller
Lab2go – Maritta Schmid
Forststraße 24 · 73529 Schwäbisch Gmünd, Germany
hello@lab2go.net
2. Data Collected
- Account data (name, email address, payment details)
- Health and biomarker data that you actively record in the app
- Log data (log files, device information, cookies)
3. Purposes of Processing
- Provision and personalization of the Lab2go platform including analyses and reminders
- Communication with users, support and product updates
- Compliance with legal documentation and retention requirements
4. Legal Basis
We process data on the basis of Art. 6(1)(a) GDPR (consent) and Art. 6(1)(b) GDPR (performance of a contract), and, for health data, Art. 9(2)(a) GDPR.
For health data we ask for a separate, explicit consent at registration, in the web app and in the mobile app (Art. 9(2)(a) GDPR). Without it, Lab2go cannot store any health data. For accounts created before this request existed, we ask once afterwards.
Log data is additionally processed on the basis of Art. 6(1)(f) GDPR (legitimate interest in operation, security and audience measurement).
5. Retention Period and Deletion
We store personal data only for as long as is necessary for the respective purpose or required by statutory retention periods. You can delete data at any time directly in the app or request erasure of all your data.
6. Disclosure to Third Parties
We use the following service providers to operate the website and the Lab2go apps. No disclosure for advertising purposes takes place.
- Database, sign-in and file storage (web app and mobile app): Supabase. All account and health data is stored in the Frankfurt am Main region (EU). The provider is Supabase Inc., based in the USA.
- Analysis of uploaded lab reports: When you upload a report, the document is passed via the automation service n8n (n8n Cloud, EU instance) to Mistral AI SAS (based in Paris, France) for text recognition. Mistral AI structures the recognised text into individual lab values. In this step, health data, including the name and date of birth shown on the report, is transmitted to n8n and Mistral AI.
- Emails: System emails (registration confirmation, password reset, confirmation of an email change) and manager invitations are sent by Resend (based in the USA). It receives the email address and, for invitations, additionally your name and the profile name. No health data is transmitted.
- Payment: Subscriptions in the web app are processed by Stripe Payments Europe Ltd. (Ireland). Stripe receives your email address and your account identifier and collects payment details itself; it does not receive health data. In the mobile app, purchase through the Apple App Store is intended; the subscription status is then managed by RevenueCat (based in the USA), which receives a pseudonymous user identifier and purchase events for this purpose, but no email address, name or health data.
- Hosting: The website is delivered via Netlify and Cloudflare, the web app via Lovable and Cloudflare. This involves access data (IP address, browser identifier, requested address). Cloudflare is based in the USA.
- Web analytics and feedback: Plausible Analytics (Plausible Insights OÜ, Estonia), PostHog (PostHog Inc., EU cloud in Frankfurt) and Userback (Userback Pty Ltd, Australia); details are in sections 9 and 10.
7. Your Rights
- Access, rectification, erasure and restriction of processing
- Withdrawal of consent already given, with effect for the future
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Data portability and right to lodge a complaint with the competent supervisory authority
You withdraw the consent for health data in the web app under Settings › Account and in the mobile app under Settings › Consents. With the withdrawal, the processing of your health data ends and we delete your account with all data. Processing up to the withdrawal remains lawful.
8. Security
- Account and health data stored in a data centre in Frankfurt am Main (EU); which service providers handle individual processing steps, and where they are based, is set out in section 6
- Encryption of sensitive data at rest and in transit
- Role-based access control and logging
9. Web Analytics
So that we can see which pages are read, we measure the reach of the website with two tools: Plausible Analytics and PostHog. Both are integrated via Cloudflare Zaraz. When a page loads, Zaraz receives the page address, page title, referrer, screen and window size, colour depth and time zone, and sets the cookie cf_zaraz_client (valid for lab2go.net and its subdomains, lifetime one year); its value is empty. Plausible itself sets no cookies and works without consent. PostHog works in two stages, depending on whether you agree in the consent banner (see below). There is no cross-site tracking.
Plausible Analytics. The provider is Plausible Insights OÜ (Estonia, EU). Your browser loads the Plausible script directly from plausible.io and sends the measurement request there. In the process, your IP address reaches Plausible for technical reasons. According to Plausible, it is neither stored nor shared with third parties.
Usage statistics with PostHog. The provider is PostHog Inc. (USA), with which we have concluded a data processing agreement under Art. 28 GDPR. The data is stored in PostHog's EU Cloud in Frankfurt. The script and the measurement requests run via our own address t.lab2go.net, a forwarding service operated by PostHog.
Consent banner. On your first visit, a banner from Cloudflare Zaraz asks whether PostHog may measure you using a cookie. “Accept” and “Decline” are equal. Zaraz stores your choice in the cookie cf_consent (valid for lab2go.net and its subdomains, lifetime one year). You can change your choice at any time via “Cookie settings” in the page footer.
With consent. If you agree, PostHog sets the cookie ph_phc_yxR7pkWmJemNyF82xNqqlGzaBZZLxY0xIsmeTiuE1AN_posthog (valid for lab2go.net and its subdomains, lifetime one year) and stores the same identifier and your choice in your browser’s local storage. PostHog uses it to recognise you on later visits. If you additionally sign in to the web app and agree there to usage statistics, PostHog links this identifier to your pseudonymous account ID (a random number, not your email address or name); visits to the website and the web app can then be combined. Even then, PostHog records only page views and leaving a page; it receives the page address without parameters and anchor, path and host, the referring page without parameters, the previous page and how long it was shown, a session and window identifier, the note that the data comes from the website, and technical fields of PostHog. Page title, time zone, screen size and browser identifier are not transmitted. There are no clicks, inputs or session recordings. If you withdraw consent, the website deletes the cookie and the identifier.
Without consent (decline or no choice). If you decline or make no choice, PostHog sets no cookie and stores nothing in your browser. PostHog then counts the same page views as described above, without session and window identifier. For this, PostHog additionally receives the browser identifier (user agent) of your browser and calculates from it, together with the IP address and a random value that changes daily, a hash value that is used to tell visits on the same day apart. The browser identifier and the IP address are not stored. PostHog creates no user profile and links nothing to a Lab2go account. No location is derived from the IP address. The AI features of PostHog are switched off for our account. If your browser sends the “Do Not Track” signal, PostHog records nothing on the website in either case.
Web app: In the settings of the Lab2go web app you can switch on usage statistics with PostHog. They are off by default; nothing is recorded without your consent. If your browser sends “Do Not Track”, the web app records nothing and does not offer the switch. Only coarse usage events are recorded: the areas of the app you visit as a page template without parameters, sign-up and sign-in, the creation of a measurement (source: manual, text recognition or import), the start and end of a lab-report scan with its result (successful, limit or error), the upload of a document (PDF or image), the creation and acceptance of a share, the invitation of a manager and an export (format). Measurements, document contents, names and email addresses are not transmitted. With your consent, the identifier is linked to your pseudonymous account ID, and PostHog creates a profile for it; the cookie is the one named above. If you withdraw consent, the statistics stop and the identifier is reset.
Mobile app: In the Lab2go mobile app, usage statistics will only come after your consent; their introduction will follow, and we will describe them here before they start.
Legal bases. For Plausible on the website, the legal basis is Art. 6(1)(f) GDPR; our legitimate interest is data-minimising audience measurement. For PostHog with a cookie, the legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG); you can withdraw it at any time with effect for the future via “Cookie settings”. For PostHog’s cookieless counting without consent, the legal basis is Art. 6(1)(f) GDPR; our legitimate interest is data-minimising audience measurement.
For usage statistics in the web app, the legal basis is your consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR, Section 25(1) TDDDG). You can withdraw it at any time with effect for the future by switching the statistics off again in the settings.
10. Feedback Form
The footer of every page has a “Give feedback” button. It opens a choice: text only, screenshot or screen video. Only when you choose an option do we load the feedback form of the provider Userback (Userback Pty Ltd, Australia). Before that there is no connection to Userback, and Userback stores nothing in your browser. The form has fields for your message and, optionally, your name and email address. You decide what is captured; only the option you chose is enabled. There are no file attachments or session recordings. Please do not include any health data in your message, screenshot or video.
When you submit, your browser sends to Userback: the content of the form (with a screenshot or screen video, also the captured screen content), the address and title of the page you are on, the browser identifier (user agent), the window size, the screen resolution and the colour depth. Your IP address reaches Userback for technical reasons when the connection is established. From the click onwards, Userback creates an entry in your browser’s local storage.
We use your feedback to fix errors and improve the website, and we reply to you if you gave an email address. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is feedback on the website. The entry in local storage is permitted under Section 25(2) No. 2 TDDDG because it is necessary for the service you expressly requested. Userback processes the data on our behalf; we have concluded a data processing agreement under Art. 28 GDPR with Userback Pty Ltd. Because Userback is based in Australia, the data is transferred to a third country; standard contractual clauses apply. If you do not use the form, no data is transmitted to Userback.
Privacy Contact
For questions, please contact us at hello@lab2go.net .
We usually answer questions about data protection within 5 working days. We handle requests about your rights, for example for access or deletion, within one month at the latest.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg), Heilbronner Straße 35, 70191 Stuttgart, Germany.