Legal documents

Seven documents, each one written rather than assembled.

A legal page that could belong to any product tells you nothing about this one. These say what LabFlow handles, who is responsible for it, how long it is kept, which companies see it, and what has not been done yet.

The setseven documents
Documents7
Last reviewed6 August 2026, all seven
Written byThe LabFlow team, not a template
Law firm reviewNone. This is not legal advice
The HIPAA wordConscious, never compliant
Named processors5

Every document is on this page. Choosing one changes the address bar, so the link you copy is the link to that document.

The documents

Cookies and local storage

Every key this site writes, and why no banner appears.

Last reviewed2026-08-06
Clauses7
URL/cookies
AdvertisingNone today

You can check every claim on this page yourself. Open your browser's developer tools, look at storage for this site, and compare it with the table in clause 02.


Mostly not cookies#

Almost nothing here is a cookie. Your preferences are kept in your browser's local storage, which never travels with a request, and your filters and search terms are kept in the address bar rather than stored at all. The page keeps the name Cookies because that is the address it is indexed under and the word people search for.

The complete table#

Everything LabFlow stores in your browser, where it lives and how long it lasts
WhatWhereWhyHow long
Appearance preferencesLocal storageLight or dark, the colour treatment, corner radius, density, text size, typeface, panel background, cursor, motion and sound. Ten settings, one per control in the theme panel.Until you clear it
Sign-in sessionLocal storageKeeps you signed in between page loads. Set by the database platform's identity service.Short, with refresh. Ends at sign-out
Push subscriptionLocal storage and the browser's own push storeIdentifies this browser to the notification service. Only exists if push is switched on, and it is off by default.Until you revoke notifications
Filters, tabs and searchnot storedThese live in the address bar, so a link you copy shows what you were looking at and a refresh does not lose your place.Not stored at all
Advertising or cross-site identifiersnone todayNo advertising network is present on this website today, and no identifier is shared with one. LabFlow expects to carry advertising, so this row states a current build rather than a permanent promise: an advertising cookie appears in this table, and a consent banner appears with it, in the same change that introduces one.Not applicable yet

All of it is written through one storage layer rather than by each feature reaching for the browser directly, which is why this table can be complete rather than approximately complete.

Nothing here follows you off this site today#

There is no advertising network, no social media pixel, no remarketing tag and no cross-site identifier on these pages, and nothing on them is embedded from a third party that could set one. That is checkable rather than asserted, which is why clause 02 can be complete rather than approximately complete.

The heading says today on purpose. LabFlow expects to carry advertising, and the Android app already declares the advertising identifier permission for that reason — app permissions clause 05. So this clause describes a build instead of promising a future, and clause 04 explains why that distinction is the honest way to write it.

One part of it is not a description and does not move: no advertising or cross-site identifier is loaded on a signed-in clinical route. A page showing a patient's results is not a page that carries an advert.

Measurement, in the same words the privacy policy uses#

Product measurement, where it is switched on, receives event names and route patterns only. It does not receive a patient identifier, an accession number, a result value, a free-text note or the contents of any record.

If a session-replay or heatmap tool is ever added, it will appear in the table in clause 02 and in the processor table in the privacy policy before it is switched on, and it will be blocked from every signed-in clinical route.

Why this is phrased as a commitment rather than as a denial. The tempting sentence here is "we do not record your session". It is easy to write, it is currently true, and it is exactly the sentence that turns into a lie the day somebody adds a heatmap tool and updates only the privacy policy. A cookies page and a privacy policy that disagree is the cheapest false statement a site can make, and it is almost always an accident of that shape. So both pages carry this paragraph, in the same words, and changing one without the other is visible.

Why there is no consent banner#

Consent is required for storage that is not necessary for a service you asked for. Everything in clause 02 is either strictly necessary, meaning the sign-in session, or a preference you set yourself by using a control, meaning the appearance settings, or something you explicitly turned on, meaning push notifications. None of it is analytics or advertising placed without asking.

So there is nothing to consent to, and a banner would be theatre. If that ever stops being true, the banner arrives in the same change as the thing that made it necessary.

Clearing it, and what you lose#

The theme control in the header resets every appearance setting in one action. Your browser's own site-data controls clear the rest, and revoking notification permission removes the push subscription.

What you lose by clearing it: the site goes back to its default appearance and you are signed out. No laboratory data is stored in your browser, so nothing you have entered into LabFlow is affected by clearing site data on any device.

Do Not Track and Global Privacy Control#

Both signals are honoured. Today honouring them changes nothing you would notice, because clause 03 is what it is: nothing here follows you off this site, so there is no cross-site profile for a signal to switch off. They are named so that a reader can hold us to them when the table in clause 02 grows — and clause 03 says plainly that advertising is expected, so when is the right word there rather than if.

Four things no document on this page can do for you.

Legal pages are usually written to close questions. These are here to open the four that a careful buyer should ask next, because a page that leaves you feeling reassured has probably done you a disservice.

They are not legal advice, and no lawyer has read them

They are written to be accurate rather than to be defensible. Your counsel should read the terms and the HIPAA statement and expect to negotiate.

They are not a contract you can rely on for production

The governing-law clause is open and there is no business associate agreement. Both are named in the documents rather than left for you to discover.

They cannot describe your laboratory's obligations

Risk analysis, training, access review, physical safeguards and a tested contingency plan stay yours whichever system you run.

They are not evidence that any of it is implemented

A document describing a safeguard reads exactly like a document describing an intention. Ask to see the audit trail and ask to be refused a tenant that is not yours.

One page owns each fact, and the rest point at it.

Seven documents that each state a retention window are seven chances for six of them to be out of date. So each fact has a single home, and everywhere else is a link.

Retention

The four windows, and what each is anchored to

Results and reports, pathology material, the audit trail, specimen movement. The numbers live in one place and every other mention links to it.

Processors

Which companies see anything, and what each receives

Four named, with the specific thing each one gets. The cookies page describes what reaches your browser; this describes what reaches somebody else's server.

Owned by /privacy-policy, clause 03

Measurement

What analytics receives, and the commitment about session replay

Deliberately stated in identical words on two pages, so that changing one without the other is visible rather than quiet.

Stated twice: privacy clause 05, cookies clause 04

Permissions

Every Android permission, with the four-way agreement rule

The manifest, this page, the privacy policy and the store declaration must say the same thing before a build is released.

Gaps

What is missing, listed rather than omitted

No business associate agreement, no external audit, no penetration test, no tested restore, no governing-law clause, no availability commitment.

HIPAA clause 04, security clause 11

If a clause is wrong, that is worth an email.

These were written by the team that built the product, which makes them accurate about the software and untested as law. A correction, a challenge, or a question about how a specific safeguard actually works will be answered by a person who can check the code rather than by somebody reading from the same page you are.

Revision historypublished

All seven documents were rewritten in one pass on 6 August 2026. Every future revision is dated and published as an entry in the feed, so a change to a policy is something you can subscribe to.