Privacy Policy
Last updated: 1 October 2026
This policy explains what Labelisk collects, why, and what you can ask us to do with it. It covers labelisk.com and the Labelisk API.
What we collect
| Data | Why | How long |
| Email address | To identify your account, let you sign in and reset your password | While the account exists |
| Password | To sign you in. Stored only as a scrypt hash; we never see the password itself | While the account exists |
| Logos and fonts you upload | To use them in your renders, the way the printer would | Until you delete them or close the account |
| API keys | To identify calls to the API. Stored only as a hash; the key is shown once, when created | Until you revoke it |
| Render counters | To apply the limits of your plan and show your usage | Account counters are kept; counters by IP address, used for people without an account, are deleted after 7 days |
| Session records: IP address, browser identification, dates | To keep you signed in and let you see and end sessions you do not recognise | 30 days, or until you end the session |
| Messages sent through the contact form, including attachments | To answer you | While needed to handle the request |
What we do not keep
The label formats you render are not stored. They are processed in memory to produce the image and discarded. The same goes for the images produced: they are returned to you and not archived.
We do not use advertising cookies, analytics or tracking of any kind. The only cookie is the one that keeps you signed in, and it is removed when you sign out.
Legal basis
We process this data to perform the contract with you (running the Service and your account), to meet legal obligations (billing records), and under our legitimate interest in keeping the Service secure and working — for example, recording the IP address of a session or a failed sign-in attempt. Where the GDPR or the Brazilian LGPD requires consent, we ask for it.
Who processes data with us
- Oracle Cloud — hosting of the servers that run the Service.
- Resend — delivery of transactional email (password reset, contact messages).
- Creem — payment processing and merchant of record. Payment and billing data is handled by them, under their own privacy policy; we never see your card details.
We do not sell personal data, and we do not share it for advertising.
International transfers
The Service runs on servers located in Brazil. The providers above may process data in other countries under the safeguards required by applicable law.
Your rights
You can access, correct, export or delete your data, withdraw consent and object to processing. Most of it is self-service on your profile page: change your password, delete logos and fonts, revoke keys and end sessions. For anything else — including deleting your account and everything in it — write to support@labelisk.com and we will answer within 30 days.
Security
Traffic is encrypted with HTTPS. Passwords and API keys are stored only as hashes. The database is reachable only from the server itself, backed up daily, and the backups stay on the same server, with the same access restrictions. We will notify affected users and the authorities about any incident that puts personal data at risk, as the law requires.
Children
The Service is meant for professional use and is not directed at children.
Changes
If this policy changes materially, we announce it by email and update the date at the top.
Contact
Questions about privacy, or to exercise any of the rights above: write to support@labelisk.com or use the contact form. We answer within 30 days.