Account identity
When you sign in with GitHub or Google, we receive the provider account identifier and the profile fields the provider returns, normally your name, email address and avatar. We do not receive your provider password.
Loading Complexity
privacy.notice · updated 18 July 2026
This notice explains what Complexity-ML and LABO AI store, why it is needed, where it goes, and how you can export or delete it.
When you sign in with GitHub or Google, we receive the provider account identifier and the profile fields the provider returns, normally your name, email address and avatar. We do not receive your provider password.
If you add an OpenAI key for Ask LABO, it is encrypted before database storage. The interface only receives a short prefix and status. The secret is decrypted on the server only to perform the request you initiate, and it is never included in your data export.
Graphs, custom cards and presets are stored locally in your browser by default. They are not account cloud storage. Deleting your account does not clear browser storage; use your browser controls to remove it from that device.
When you invoke Ask LABO, your prompt and the graph context needed for the plan are sent through the Complexity server to OpenAI using your provider key. Do not include personal or confidential data that is unnecessary for the request.
Controller
Boris Peyriguere / Complexity-ML
Paris, France
For a private rights request not covered by the self-service controls, contact the maintainer through the Complexity-ML organization contact channel. Never post identity documents or API keys in a public issue.
Complexity-ML contact →Account data is processed to authenticate you, provide the account and agent features you request, secure access and prevent abuse. Service delivery is based on performance of the requested service; security and service integrity rely on legitimate interests. We do not use account data for advertising.
Data is handled by the service maintainer and by infrastructure providers needed to operate the service: Vercel for web hosting, the configured PostgreSQL/Neon infrastructure for account records, GitHub or Google for OAuth, and OpenAI only when you invoke the LABO agent. Those providers process data under their own terms and applicable transfer safeguards.
Account records, encrypted provider keys and cloud conversations are retained while your account exists, then removed when you use Delete account, subject to short-lived infrastructure backups and security logs controlled by hosting providers. Browser-local LABO data remains on that device until you clear it. Provider keys can be removed independently at any time.
You can access a machine-readable copy of account data, remove a provider key, sign out, and permanently delete the account from Account settings. Depending on the applicable law, you may also request access, correction, restriction, objection or portability and lodge a complaint with the CNIL. Requests are handled without undue delay and normally within one month.
The service uses an authentication cookie required to keep you signed in. Authenticated LABO workspaces are stored in the account-scoped server database; guest workspaces are temporary and are not persisted in browser storage. No advertising cookies are set by Complexity. Third-party links and embedded services may apply their own policies.
Material changes will be reflected on this page with a new update date. If a change requires a new choice from you, it will be presented before the affected processing begins.