This page explains, in plain words, what PrjLab (prjlab.com and the PrjLab CLI) does with personal data, why, and what you can do about it. It is written to meet the EU General Data Protection Regulation (GDPR) and applies wherever you are.
Who is responsible
PrjLab is run by its founder, Abdellah Jaize, who is the controller of your personal data. Contact for everything about privacy, including requests to exercise your rights: info@prjlab.com. PrjLab has no data protection officer because the law does not require one for a service of this kind and size.
What we process, why, and on what legal basis
Purpose
Data
Legal basis
Kept for
Your account and repositories: sign-in, storing what you push, sharing it with the people you choose, showing public repositories
Identity identifier from the sign-in service, handle, display name, bio, repositories, versions, files, invitations and access
Contract (Art. 6(1)(b)): this is the service you asked for
Until you delete it; see Retention
Keeping the service secure and working: web server logs, error logs, rate limits, the access audit log
IP address, browser user agent, requested address and time; which account changed access to which repository and when
Legitimate interest (Art. 6(1)(f)) in protecting the service and your data from misuse (Recital 49)
Server logs 14 days, error logs 30 days, access audit log 2 years
Moderation: handling reports, suspending accounts, restricting or removing content that breaks the law or the terms
The report, the content concerned, the decision, its reason and source; the administrator who took it
Contract (Art. 6(1)(b)) to enforce the terms; legitimate interest (Art. 6(1)(f)) in protecting others; legal obligation (Art. 6(1)(c)) where a law requires action
Decided reports 1 year after the decision; moderation notices and the admin audit log 2 years
Product analytics and session replay (only if you accept)
Pages visited (without identifiers or file paths), clicks (without the text on the page), errors; replays of public pages with all text masked; after sign-in, your account identifier and handle
Consent (Art. 6(1)(a)); you can withdraw it any time
Per PostHog's retention settings for our project; deleted from PostHog on request
Backups so the service can be restored after a failure
Encrypted copies of the database and stored files
Legitimate interest (Art. 6(1)(f)) in not losing your data; security of processing (Art. 32)
30 daily and 8 weekly copies (about two months)
Answering your emails and requests
Your email address and what you write
Contract or legitimate interest (Art. 6(1)(b)/(f)); legal obligation for data-protection requests (Art. 6(1)(c))
As long as needed to answer and follow up
You need to give an email address to the sign-in service to create an account; without it there is no account. Everything else is up to you. PrjLab does not make decisions about you by automated means alone: every moderation decision is taken by a person. PrjLab never sells personal data and shares nothing with advertisers.
What you push
Files, project instructions, project memory and saved AI sessions can contain personal data, yours or other people's, and secrets. You decide what you push and are responsible for having the right to store it. Everything is encrypted at rest with a key held by the service; PrjLab can decrypt it to show previews and serve clones to the people you allow, so this is not end-to-end encryption. Private repositories are visible only to you and the people on their Access tab. Making a repository public publishes every version to anyone on the internet, including search engines, until you make it private again or delete it. The CLI skips obvious secrets such as .env files and keys, but it is a safety net, not a scanner.
Administrators and moderation
A small number of administrators run the service. They can see account and repository metadata (handles, names, sizes, dates, collaborators and version messages) to help you and to keep the service safe, but the admin tools never show the contents of private files, memory or sessions. Every administrative change and every opening of an account's details is written to an audit log. If an administrator suspends your account or restricts your content, you are told what was decided, why, and how to contest it (see the terms).
Reports about content
Anyone can report content through /report. We store the report, including the name and email address if the reporter gives them, only to handle it, and delete it one year after a decision. We do not tell the person whose content was reported who reported it, unless a law requires it.
Cookies and browser storage
Name
Purpose
Lifetime
Needs consent
__Host-prjlab (cookie)
Keeps you signed in
At most 1 hour
No, strictly necessary
__Host-prjlab_login (cookie)
Protects the sign-in handshake
10 minutes
No, strictly necessary
prjlab-consent (local storage)
Remembers your analytics choice
Until you clear it
No, it records your choice
ph_* (local storage)
PostHog analytics identifier
Up to 1 year
Yes, only after you accept
The CLI stores its sign-in token in your operating system's credential store; prj logout removes it.
Analytics and session replay
PrjLab can use PostHog (EU cloud) to learn which pages work and which break. Nothing from PostHog is loaded, stored or sent until you choose; if your browser sends a Global Privacy Control signal we treat it as a refusal. If you accept analytics, page views are reported without repository identifiers, query strings or file paths, clicks without the text on the page, and browser errors. Session replay is a separate choice and only runs on public pages (home, docs, blog, explore, privacy, terms) with all text masked; it never runs on repository, account or admin pages. You can change your choice at any time: . Withdrawing stops analytics at once and clears PostHog's data from your browser.
Who else processes data
Microsoft (Azure and Entra External ID): hosts the service and its backups in the Sweden Central region (EU) and runs sign-in. Covered by Microsoft's Data Protection Addendum.
PostHog: analytics in its EU cloud, only with your consent.
Cloudflare: DNS for prjlab.com and forwarding of email sent to @prjlab.com addresses. Web traffic to PrjLab does not pass through Cloudflare.
Google: email you send to info@prjlab.com is forwarded to the operator's Gmail inbox.
Authorities: only where a law requires it, for example a valid court order.
Microsoft, PostHog, Cloudflare and Google are US companies and may process some data in the United States. Such transfers rely on the EU–US Data Privacy Framework (European Commission Decision (EU) 2023/1795 of 10 July 2023) and on the European Commission's standard contractual clauses; write to info@prjlab.com for a copy of the safeguards.
How long data is kept
Your account and repositories: until you delete them. Deleting your account deletes every repository you own and removes you from repositories shared with you at once. A record with a random retired handle stays so that versions you pushed to other people's repositories keep a valid author.
Browser sessions: valid for at most one hour, deleted a day after they expire.
Web server logs with IP addresses: 14 days. Error logs: 30 days.
Access audit log, moderation notices and the admin audit log: 2 years.
Reports: until decided, then 1 year.
Backups: 30 daily and 8 weekly copies, so deleted data leaves every backup within about two months.
Your rights
You can ask for access to your data, correction, erasure, restriction of processing and a copy in a portable format, and you can object to processing based on legitimate interest. Where we rely on consent you can withdraw it at any time without affecting what happened before. Much of this is self-service in account settings: edit your profile, download your data as JSON, end browser sessions and delete your account. For anything else write to info@prjlab.com; we answer within one month (two more months for complex requests, and we tell you if so) and may ask you to confirm your identity. Requests are free. A suspended account keeps these rights.
You also have the right to complain to a data protection authority, in particular in the EU country where you live, work or where you think the infringement happened.
Age
PrjLab is for people aged 16 and over. If we learn that an account belongs to someone younger, we delete it.
Changes
Material changes are announced on the blog and dated at the top of this page before they take effect.