Privacy Policy
This Privacy Policy explains how Shila Lab ("we", "us", "our") collects, uses, and protects your personal data when you use the Shila Lab website (the "Service"). Shila Lab is operated by 2V HUB PTE. LTD., a private limited company incorporated under the laws of Singapore (UEN: 202441147N), with its registered office at 68 Circular Road, #02-01, Singapore 049422.
We are committed to protecting your privacy and complying with the Singapore Personal Data Protection Act 2012 (PDPA) and, where it applies to users based in the European Economic Area, the EU General Data Protection Regulation (GDPR).
1. Data we collect
Account data (when you sign up)
- Email address
- Password (hashed by our auth provider; we never see it in plain text)
- If you sign in with Google: your Google email and basic profile info
Usage data (created as you use the Service)
- XP, level, copied prompts, favourites, badges, daily streak
- Categories and prompts you've viewed
- Timestamps of activity
Technical data (automatic)
- IP address (briefly, for security and abuse prevention)
- Browser type, device, operating system
- Referrer URL
We do not collect: phone, postal address, payment info (the Service is free), behavioural advertising profiles, or special categories of data.
2. Why we use your data, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the Service (your account, save your progress) | Contract performance |
| Keep the Service running, prevent abuse and fraud | Legitimate interest |
| Improve the Service via aggregated analytics | Legitimate interest |
| Send service emails (password reset, security, important changes) | Contract / legitimate interest |
| Marketing emails (if you opt in) | Consent |
3. Who we share data with
We share your data only with the following processors, who act on our instructions under data-protection contracts:
- Supabase Inc.: authentication and database. Data is stored in Europe.
- Google LLC: only if you sign in with Google. We receive only the data you authorize.
- Netlify, Inc.: site hosting and server logs.
We do not sell your personal data to anyone, ever. We do not share it with advertisers or data brokers.
4. International transfers
Some processors are based outside the European Economic Area (in particular the United States). We rely on Standard Contractual Clauses (SCCs) approved by the European Commission, plus supplementary safeguards where required, to ensure your data is adequately protected.
5. How long we keep your data
- Account data: as long as your account is active.
- After account deletion: deleted within 30 days, except where law requires longer retention.
- Server logs: 30 days.
- Backups: rotated out within 60 days.
You can delete your account at any time from your profile page, and your data goes away.
6. Your rights
Depending on the law that applies to you (PDPA, GDPR, or other), you have the right to:
- Access the data we hold about you
- Correct inaccurate data
- Delete your data (right to be forgotten under GDPR)
- Restrict processing in certain cases
- Port your data (machine-readable export)
- Object to processing based on legitimate interest
- Withdraw consent at any time, for any processing based on consent
- Lodge a complaint with the relevant data protection authority:
- Singapore: the Personal Data Protection Commission (PDPC)
- EU / EEA: your local supervisory authority (in France, the CNIL)
To exercise these rights, email us at privacy@ai-seo-prompts.com. We respond within 30 days.
7. Cookies and local storage
We use only essential technical storage to make the Service work:
- An authentication session (set by our auth provider) when you log in
- Your interface preferences (sidebar state, theme, etc.) in your browser's local storage
We do not use advertising cookies, third-party tracking cookies, or behavioural profiling. If we add privacy-friendly analytics in the future (such as Plausible or Fathom), we will update this policy; those tools do not use cookies and do not track individuals.
8. Security
We use industry-standard security: HTTPS everywhere, hashed passwords, row-level security on the database so each user can only access their own row. No system is perfectly secure; if a personal-data breach occurs that affects you, we will notify you and the relevant supervisory authority (PDPC for Singapore, or your local EU DPA where GDPR applies) as required by law.
9. Children
The Service is not directed at children under 16. If we learn we have collected data from a child under 16 without parental consent, we will delete it.
10. Changes to this policy
We may update this policy from time to time. Material changes will be notified in the Service or by email. The "Last updated" date at the top of this page reflects the current version.
11. Contact
2V HUB PTE. LTD.
68 Circular Road, #02-01, Singapore 049422
Email: privacy@ai-seo-prompts.com
Data protection contact: dpo@ai-seo-prompts.com