Legal
Privacy policy
Last updated August 31, 2026
This policy describes how the operator of labhdo.com, doing business as LabhDo (“LabhDo,” “we,” “us”) handles personal data when you use https://labhdo.com, the LabhDo web app, and the Android app. Contact: support@ilike2moveitmoveit.com.
1. What we collect
- Account identity. Sign-in may use Google, Apple, Microsoft, an email magic link, or a passkey. We store the provider user id, email, name, and avatar (when the provider sends them) to create a session. We never receive your Google, Apple, or Microsoft password. Magic-link tokens are hashed at rest and expire in 15 minutes. Passkeys store a public key for this device; the private key stays on your device.
- Move and household data. Account name, move titles, origin and destination labels and optional street addresses, planned dates, rooms, and team invites (email + role).
- Inventory. Box contents, item names, categories, tags, notes, quantity, fragile/high-value flags, model and serial numbers, estimated values, purchase dates, warranties, keep/store/sell/donate status.
- Media. Item photographs, thumbnails, voice recordings, transcripts, condition photos, and insurance documents (receipts, warranties, manuals, appraisals).
- Operational events. Box lifecycle (sealed, loaded, delivered, unpacked), who marked a checkpoint, and security/audit events such as sign-in, export, billing, and deletion.
- Device data stored locally. Theme preference, active account/move ids, and an offline packing queue (IndexedDB) that can hold photos and voice until they sync.
We do not collect payment card numbers. Stripe processes cards on their pages. We do not store phone numbers or date of birth.
2. How we use it
To provide the product: inventory, labels, mover scan pages, search, Ask LabhDo, reports, billing, support, security, and to meet legal obligations. Staff (super administrators) can view account metadata — email, household name, usage counts, billing status, and audit events — to provide support and operate billing. The platform console does not show item names, photos, OCR text, or voice transcripts. We do not sell personal data and we do not run advertising pixels.
3. Photos, voice, and AI
When cloud AI is enabled for an account, item photos and voice audio are sent to OpenAI (or a compatible hosted API you configure) to propose names, tags, OCR text, fragile flags, and transcripts. Packing does not wait on that result. You may disable cloud AI per account in Settings; jobs then stay on a local worker or a heuristic fallback. Optional browser speech-to-text (if you enable it) is processed by your browser vendor, not by LabhDo servers.
4. Public QR pages
Each box has a cryptographically random scan token. Anyone with the URL can see what that box’s visibility setting allows. The default is destination room only — not photos, OCR, or voice. Tokens in printed labels are secret; treat a printed sheet like a key. You can regenerate a token if a label is lost.
5. Storage and processors
Application data lives in PostgreSQL on Railway. Media objects live in Cloudflare R2 (or local disk in development). Object access in production uses short-lived signed URLs; the bucket is not world-readable. The web app is served by Vercel. Authentication uses Google, Apple, Microsoft, email magic links, and passkeys when configured. Payments use Stripe. Transactional email uses Resend or Postmark when configured. See subprocessors.
6. Cookies and similar tech
The HTTP-only movebox_session cookie is required to stay signed in (30 days, Secure on HTTPS, SameSite=Lax). Theme and offline queue are local to your device. Analytics, if enabled, is cookieless (Vercel Analytics or Plausible). Details: cookie notice.
7. Retention
We keep account and inventory data until you delete it or the account is unused and you ask us to erase it. Account deletion starts a 30-day grace window, then we hard-delete database rows and media objects we control. Backups roll off on the host’s backup cycle (typically ≤ 30 days). Audit events related to deletion may be kept up to 12 months. Invite emails we collected solely to match an accept are removed with the invite or the account.
8. Your rights
You can access and correct inventory in the app, export CSV/JSON or a full account archive from Settings, and delete your account at /delete-account or in Settings. If you are in the EEA/UK you may also request access, correction, deletion, portability, and restriction via support@ilike2moveitmoveit.com. We honor those requests with the tools above. We do not operate a paid data-selling business, so there is no “do not sell” opt-out beyond not selling.
9. Children
LabhDo is for adults organizing a household move. You must be 18 to create an account. We do not knowingly collect data from children under 13. Household inventory may include photos of a child’s belongings; that is your content, not a child profile.
10. International transfers
We and several processors are in the United States. If you access LabhDo from elsewhere, your data is processed in the US. Subprocessors publish their own transfer mechanisms (including SCCs where they offer them).
11. Changes
We will post an updated date on this page and, for material changes, prompt a new terms/privacy acceptance in the app (current terms version: 2026-08-31).
These pages are written to match the product as shipped. They are not a substitute for advice from your own counsel. Request a review before you rely on them as a filed contract or DPA.

