Legal documents

Seven documents, each one written rather than assembled.

A legal page that could belong to any product tells you nothing about this one. These say what LabFlow handles, who is responsible for it, how long it is kept, which companies see it, and what has not been done yet.

The setseven documents
Documents7
Last reviewed6 August 2026, all seven
Written byThe LabFlow team, not a template
Law firm reviewNone. This is not legal advice
The HIPAA wordConscious, never compliant
Named processors5

Every document is on this page. Choosing one changes the address bar, so the link you copy is the link to that document.

The documents

Terms

The agreement, including the parts that are not finished.

Last reviewed2026-08-06
Clauses12
URL/terms
Also at/terms-of-service

These terms are between you and the provider of LabFlow. If you reached LabFlow through a laboratory, its own agreement with you sits alongside this one and is not replaced by it.


Who this is between#

LabFlow is provided by Ahsan Mahmood, an independent developer. Using the site, creating an account, or operating a tenant means these terms apply to you. Where a laboratory has agreed separate terms with us in writing, those take precedence over these for that laboratory.

What LabFlow is, and four things it is not#

LabFlow is a laboratory information system: registration, ordering, specimen chain of custody, result entry and validation, quality control, and the audited release of reports. It also carries a public directory where a patient can find a laboratory.

Not a medical device

It is not registered as one in any jurisdiction, and it must not be used as one. It records and moves results; it does not measure anything.

Not a diagnosis, and not clinical advice

Nothing it displays is an interpretation. A flag against a reference range is arithmetic, not an opinion, and it is never a substitute for the judgement of a qualified person.

Not an electronic health record

It holds the laboratory's view of a patient, not their clinical history, and it is designed to send results to whatever system does hold that.

Not accredited, and not an accreditation

Using LabFlow does not make a laboratory accredited, compliant, or ready for an assessment. It can hold the records an assessor asks for. Producing them is still the laboratory's work.

Accounts, and who controls them#

Inside a tenant, the laboratory creates accounts, assigns roles and removes people who leave. We do not adjudicate a dispute between a laboratory and its own staff about access. You are responsible for keeping your credentials to yourself; sharing a login inside a laboratory destroys the value of the audit trail, which is the record that protects you when a result is questioned.

Platform staff accounts exist, they are few, and every action they take is written to the same append-only audit trail as everyone else's. Support access to a tenant is not silent.

Acceptable use#

Do not attempt to reach a tenant that is not yours, do not probe the service in a way that risks other tenants' data, and do not upload anything unlawful. Security research is welcome and there is a route for it in the data security document; testing against a live tenant that holds real patient records is not research, it is an incident.

Plans, and the fact that nothing is purchasable#

LabFlow describes three plan shapes: a single laboratory, several under one organisation, and operating the platform for laboratories that are not yours. There is no payment path in the product and nothing on this site can be bought. The plan model exists so that limits are a configuration change later rather than a rebuild; today every limit is effectively unlimited.

A plan is granted by platform staff and carries an end date. When one is in force, these are the terms that apply to it:

  • Cancelling ends the renewal, not the period. A granted plan runs to the end of the period it was granted for, and then stops renewing. You keep what was granted until that date.
  • Payments already made are not refunded.
  • A plan ending never deletes anything. Content over the smaller plan's limits becomes read-only and stays readable and exportable. Deleting a laboratory's records because a plan lapsed would be the worst thing this product could do.

Stated plainly so it is not a surprise later. Read together with the pricing page, which carries the same three shapes and the same absence of a price.

Your data, and what we may do with content#

Everything a laboratory puts into its tenant remains that laboratory's. We claim no ownership of it and we take no licence over it. Nothing inside a tenant is used to build or improve anything, which includes every patient record, order, result, report and quality-control run, on every plan.

What sits outside a tenant is treated differently, and the difference is stated here rather than left to be inferred.

We may use non-clinical content from free accounts, meaning support messages, product feedback and bug reports, together with aggregate, de-identified usage statistics, to improve the features we build. Patient records, orders, results and any clinical content are never used this way, on any plan. Nor is anything a patient writes in a satisfaction answer — clause 09. Content in a paid plan is not used to improve features without your explicit consent. You can object at any time, and moving to a paid plan stops it.

Aggregate means a count with no tenant, laboratory or person identifiable in it, which is why this clause and the statement that a tenant's data never leaves its own boundary are both true at once.

The same clause appears in the privacy policy at clause 06, with the legal reasoning for why clinical content is carved out.

Clinical responsibility stays with the laboratory#

This is the most important clause on the page.

A person releases a resultalwaysAutomatic checking against ranges, deltas and quality-control state produces a suggestion and a reason. It never releases anything on its own, and there is no configuration that lets it.
Quality control gates the runthe laboratory sets the rulesWhich rules are switched on, and what happens when one fires, is the laboratory's policy. The software enforces the policy it was given; it does not decide the policy.
A critical result reaches a personthe laboratory names themThe escalation path, the acknowledgement, and the timescale are the laboratory's. LabFlow records who was told, when, by which channel, and whether they acknowledged it.

We are not responsible for a clinical decision made using a result, for a result that was entered incorrectly, or for a laboratory's choice of rules. We are responsible for the software recording and moving what it was told, accurately and with an audit trail.

Availability, and the absence of a service level#

There is no uptime commitment, no support response time, and no on-call rota, because the LabFlow team works in one time zone with nobody on call. The service runs on free tiers of the platforms named in the privacy policy, and their limits are ours. A laboratory that needs a contractual availability target does not have one here, and should treat that as a reason to wait rather than as a detail to negotiate later.

Maintenance that takes the service down is announced in advance where it is planned, and afterwards where it is not.

Ending it, and what happens to the records#

You can stop using LabFlow whenever you like, and you can ask for your data back in an open format before you go. We can end an account for a serious breach of clause 04, and we will say which one.

Ending an account does not shorten a retention window that clinical accreditation requires. What is deleted, what is archived, and what is kept until when is set out on the data deletion page, which is the only page that carries those numbers.

Warranties and liability, in plain words#

LabFlow is provided as it is. We do not warrant that it is free of defects, that it will always be available, or that it fits a particular laboratory's workflow. Where the law allows us to limit liability, our liability is limited to the amount paid for the service in the twelve months before the claim, which today is nothing, and that is the honest arithmetic rather than a clever cap.

Nothing here limits liability for death or personal injury caused by negligence, for fraud, or for anything else the law does not permit to be limited.

Governing law: the clause that is genuinely missing#

A governing-law and jurisdiction clause belongs here and is not settled. Rather than name a jurisdiction that has not been chosen, it is left open and marked.

Two consequences follow, and both are in your favour. Nothing on this site is an offer capable of acceptance, and no laboratory should treat these terms as a completed contract for production use. When the clause is written it will be dated, published in the feed, and account holders will be told before it takes effect.

Changes#

Revisions are dated at the top and published in the feed. A change that reduces what you get, or increases what you owe, is sent to account holders by email before it applies.

Four things no document on this page can do for you.

Legal pages are usually written to close questions. These are here to open the four that a careful buyer should ask next, because a page that leaves you feeling reassured has probably done you a disservice.

They are not legal advice, and no lawyer has read them

They are written to be accurate rather than to be defensible. Your counsel should read the terms and the HIPAA statement and expect to negotiate.

They are not a contract you can rely on for production

The governing-law clause is open and there is no business associate agreement. Both are named in the documents rather than left for you to discover.

They cannot describe your laboratory's obligations

Risk analysis, training, access review, physical safeguards and a tested contingency plan stay yours whichever system you run.

They are not evidence that any of it is implemented

A document describing a safeguard reads exactly like a document describing an intention. Ask to see the audit trail and ask to be refused a tenant that is not yours.

One page owns each fact, and the rest point at it.

Seven documents that each state a retention window are seven chances for six of them to be out of date. So each fact has a single home, and everywhere else is a link.

Retention

The four windows, and what each is anchored to

Results and reports, pathology material, the audit trail, specimen movement. The numbers live in one place and every other mention links to it.

Processors

Which companies see anything, and what each receives

Four named, with the specific thing each one gets. The cookies page describes what reaches your browser; this describes what reaches somebody else's server.

Owned by /privacy-policy, clause 03

Measurement

What analytics receives, and the commitment about session replay

Deliberately stated in identical words on two pages, so that changing one without the other is visible rather than quiet.

Stated twice: privacy clause 05, cookies clause 04

Permissions

Every Android permission, with the four-way agreement rule

The manifest, this page, the privacy policy and the store declaration must say the same thing before a build is released.

Gaps

What is missing, listed rather than omitted

No business associate agreement, no external audit, no penetration test, no tested restore, no governing-law clause, no availability commitment.

HIPAA clause 04, security clause 11

If a clause is wrong, that is worth an email.

These were written by the team that built the product, which makes them accurate about the software and untested as law. A correction, a challenge, or a question about how a specific safeguard actually works will be answered by a person who can check the code rather than by somebody reading from the same page you are.

Revision historypublished

All seven documents were rewritten in one pass on 6 August 2026. Every future revision is dated and published as an entry in the feed, so a change to a policy is something you can subscribe to.