Legal
Privacy policy
Effective 16 August 2026
1. Scope
This policy explains what Labradoor collects, why we collect it, who we share it with, and what you can do about it. It covers the website and the student, researcher, and company portals. Your use of the platform is also governed by the terms of service.
2. What we collect
Everyone. Email address, a hashed password (we never store the password itself), account role, and the date the account was created. If you sign in, a session cookie named auth that identifies you to the server.
Students. First and last name, year of study, major, what you are looking for, a short bio, and an optional resume in PDF form. We also store the openings you pin, the applications you start or submit together with your answers, the bounties you claim, the work you submit for them (text, links, and uploaded files), your credibility score, and your completed bounty count.
Researchers. First and last name, department profile URL, lab name, verification status, the openings you create and their questions, your lab group and its membership, and the default outreach message you use to contact students.
Companies. Organisation name, website, description, verification status, the bounties and projects you post, and payment records associated with paid bounties.
We do not collect special category information such as health, race, or religion, and you should not put it in a bio, an application answer, or a submission. We do not sell personal information.
3. Why we use it
- To create and secure your account, and to sign you in.
- To run the core product: showing openings to students, showing applicants to the researcher who posted the opening, showing bounty submissions to the organisation that funded the bounty, and showing interested labs to the company whose project they responded to.
- To verify researchers and organisations, and to review bounty submissions and appeals.
- To send service email: address verification, password resets, and decisions on an application you submitted.
- To take and release payment for paid bounties.
- To keep the platform safe, including investigating misuse and enforcing the terms.
4. What other people can see
Some information is shown to other users by design. It is worth knowing exactly what, because this is the part people are most often surprised by.
- Researchers browsing students can see your name, year, major, what you are looking for, your bio, your credibility score, your completed bounty count, and your resume if you uploaded one.
- When you apply to an opening, the researcher who posted it sees your answers, your profile details, and your resume if the opening asked for one.
- When you claim a bounty, the organisation that posted it sees your name, major, year, and everything you submit.
- When a researcher expresses interest in a company project, that company sees the researcher’s name, email, lab name, department page, verification status, and the lab group they applied on behalf of, including that group’s members.
- Administrators can see submissions, appeals, and organisation records in order to review them.
5. Services we rely on
We use a small number of processors. They act on our instructions and only receive what they need.
- Supabase stores uploaded resumes. Access is granted through short lived signed links rather than public URLs.
- Stripe takes and releases payment for paid bounties. Card details go to Stripe directly and are never stored on our servers.
- Resend delivers service email such as verification links, password resets, and application decisions.
- Anthropic powers the optional assistant that helps a researcher draft an opening. What you type into that assistant is sent to Anthropic to generate a response. Do not put confidential or personal information about a third party into it.
- Our database and application hosting providers, who store the data described above.
We also share information where we are legally required to, or where it is necessary to investigate misuse or protect someone’s safety. Some of these providers operate outside your country, so your information may be processed elsewhere under appropriate safeguards.
6. Cookies
We use one cookie, named auth, to keep you signed in. It is set when you sign in, it is not readable by scripts in your browser, and it is removed when you sign out. We do not use advertising or cross site tracking cookies. Your theme preference (light or dark) is kept in your browser’s local storage and never leaves your device.
7. How long we keep it
We keep account information for as long as the account exists. Records tied to a transaction or a review, such as bounty submissions, payment records, and credibility events, are kept while they are needed for those purposes and to meet legal and accounting obligations. Email verification links and password reset links expire shortly after they are issued.
8. Your choices
- You can edit your profile at any time from your portal, and changes take effect immediately.
- You can delete your uploaded resume yourself from your profile.
- You can ask us for a copy of your information, ask us to correct it, or ask us to delete your account and the information tied to it. We will act on the request within a reasonable time, subject to records we are required to keep.
- Depending on where you live, you may also have the right to object to or restrict certain processing, or to complain to a data protection regulator.
Service email such as verification and password resets is necessary to operate an account and cannot be turned off while the account is open.
9. Security
Passwords are hashed. Sessions use a cookie that scripts in your browser cannot read and that is only sent over an encrypted connection. Resumes are served through short lived signed links. No system is perfectly secure, so please tell us promptly if you believe your account has been accessed by someone else.
10. Children
The platform is not intended for anyone under 13, and we do not knowingly collect information from them. If you believe a child has created an account, contact us and we will remove it.
11. Changes and contact
If we change this policy we will post the updated version here with a new effective date, and we will give notice in the product for significant changes. For questions, access requests, or deletion requests, contact boyuanl6@ucla.edu.