Log inStart building →
LAST UPDATED 2026-09-24

Privacy policy.

This page explains, in plain words, what PrjLab (prjlab.com and the PrjLab CLI) does with personal data, why, and what you can do about it. It is written to meet the EU General Data Protection Regulation (GDPR) and applies wherever you are.

Who is responsible

PrjLab is run by its founder, Abdellah Jaize, who is the controller of your personal data. Contact for everything about privacy, including requests to exercise your rights: info@prjlab.com. PrjLab has no data protection officer because the law does not require one for a service of this kind and size.

What we process, why, and on what legal basis

PurposeDataLegal basisKept for
Your account and repositories: sign-in, storing what you push, sharing it with the people you choose, showing public repositoriesIdentity identifier from the sign-in service, handle, display name, bio, repositories, versions, files, invitations and accessContract (Art. 6(1)(b)): this is the service you asked forUntil you delete it; see Retention
Keeping the service secure and working: web server logs, error logs, rate limits, the access audit logIP address, browser user agent, requested address and time; which account changed access to which repository and whenLegitimate interest (Art. 6(1)(f)) in protecting the service and your data from misuse (Recital 49)Server logs 14 days, error logs 30 days, access audit log 2 years
Moderation: handling reports, suspending accounts, restricting or removing content that breaks the law or the termsThe report, the content concerned, the decision, its reason and source; the administrator who took itContract (Art. 6(1)(b)) to enforce the terms; legitimate interest (Art. 6(1)(f)) in protecting others; legal obligation (Art. 6(1)(c)) where a law requires actionDecided reports 1 year after the decision; moderation notices and the admin audit log 2 years
Product analytics and session replay (only if you accept)Pages visited (without identifiers or file paths), clicks (without the text on the page), errors; replays of public pages with all text masked; after sign-in, your account identifier and handleConsent (Art. 6(1)(a)); you can withdraw it any timePer PostHog's retention settings for our project; deleted from PostHog on request
Backups so the service can be restored after a failureEncrypted copies of the database and stored filesLegitimate interest (Art. 6(1)(f)) in not losing your data; security of processing (Art. 32)30 daily and 8 weekly copies (about two months)
Answering your emails and requestsYour email address and what you writeContract or legitimate interest (Art. 6(1)(b)/(f)); legal obligation for data-protection requests (Art. 6(1)(c))As long as needed to answer and follow up

You need to give an email address to the sign-in service to create an account; without it there is no account. Everything else is up to you. PrjLab does not make decisions about you by automated means alone: every moderation decision is taken by a person. PrjLab never sells personal data and shares nothing with advertisers.

What you push

Files, project instructions, project memory and saved AI sessions can contain personal data, yours or other people's, and secrets. You decide what you push and are responsible for having the right to store it. Everything is encrypted at rest with a key held by the service; PrjLab can decrypt it to show previews and serve clones to the people you allow, so this is not end-to-end encryption. Private repositories are visible only to you and the people on their Access tab. Making a repository public publishes every version to anyone on the internet, including search engines, until you make it private again or delete it. The CLI skips obvious secrets such as .env files and keys, but it is a safety net, not a scanner.

Administrators and moderation

A small number of administrators run the service. They can see account and repository metadata (handles, names, sizes, dates, collaborators and version messages) to help you and to keep the service safe, but the admin tools never show the contents of private files, memory or sessions. Every administrative change and every opening of an account's details is written to an audit log. If an administrator suspends your account or restricts your content, you are told what was decided, why, and how to contest it (see the terms).

Reports about content

Anyone can report content through /report. We store the report, including the name and email address if the reporter gives them, only to handle it, and delete it one year after a decision. We do not tell the person whose content was reported who reported it, unless a law requires it.

Cookies and browser storage

NamePurposeLifetimeNeeds consent
__Host-prjlab (cookie)Keeps you signed inAt most 1 hourNo, strictly necessary
__Host-prjlab_login (cookie)Protects the sign-in handshake10 minutesNo, strictly necessary
prjlab-consent (local storage)Remembers your analytics choiceUntil you clear itNo, it records your choice
ph_* (local storage)PostHog analytics identifierUp to 1 yearYes, only after you accept

The CLI stores its sign-in token in your operating system's credential store; prj logout removes it.

Analytics and session replay

PrjLab can use PostHog (EU cloud) to learn which pages work and which break. Nothing from PostHog is loaded, stored or sent until you choose; if your browser sends a Global Privacy Control signal we treat it as a refusal. If you accept analytics, page views are reported without repository identifiers, query strings or file paths, clicks without the text on the page, and browser errors. Session replay is a separate choice and only runs on public pages (home, docs, blog, explore, privacy, terms) with all text masked; it never runs on repository, account or admin pages. You can change your choice at any time: . Withdrawing stops analytics at once and clears PostHog's data from your browser.

Who else processes data

Microsoft, PostHog, Cloudflare and Google are US companies and may process some data in the United States. Such transfers rely on the EU–US Data Privacy Framework (European Commission Decision (EU) 2023/1795 of 10 July 2023) and on the European Commission's standard contractual clauses; write to info@prjlab.com for a copy of the safeguards.

How long data is kept

Your rights

You can ask for access to your data, correction, erasure, restriction of processing and a copy in a portable format, and you can object to processing based on legitimate interest. Where we rely on consent you can withdraw it at any time without affecting what happened before. Much of this is self-service in account settings: edit your profile, download your data as JSON, end browser sessions and delete your account. For anything else write to info@prjlab.com; we answer within one month (two more months for complex requests, and we tell you if so) and may ask you to confirm your identity. Requests are free. A suspended account keeps these rights.

You also have the right to complain to a data protection authority, in particular in the EU country where you live, work or where you think the infringement happened.

Age

PrjLab is for people aged 16 and over. If we learn that an account belongs to someone younger, we delete it.

Changes

Material changes are announced on the blog and dated at the top of this page before they take effect.