1. Who we are
Guru Labs, L.C. operates labconsole.com and the LabConsole service at app.labconsole.com. For account and billing data, Guru Labs decides how the data is used and is the controller. Classroom content and student session data belong to the training organization that runs the classroom; Guru Labs processes them on that organization's behalf. Students with a question about their data should start with their training provider, which controls the classroom.
2. Information we collect
Account and access-request data: name, email address, and organization. Passwords are stored only as salted hashes.
Billing data: the subscription plan, invoices, and, for accounts with a card on file, the card brand, the last four digits, and an opaque payment reference issued by Intuit. The card number itself is entered in the browser and sent directly to Intuit; it never reaches a LabConsole server.
Classroom data: rooms, schedules, machine configurations, usage metering, chat messages, and presence. Students join with an access code and a display name; no student account, email address, or password is collected. The live views of lab screens that instructors and students see are streamed, not recorded, and presentation audio and video are live only.
Technical data: IP addresses and request logs, kept for operations and security.
3. How we use information
Data is used to operate the service, provide support, bill subscriptions, secure the platform against abuse, and send service email: invitations, receipts, billing notices, and operational announcements. Guru Labs does not sell personal data, does not use it for third-party advertising, and does not use customer content to train machine-learning models.
4. Cookies and similar technologies
The application uses two first-party cookies: a session cookie and a CSRF protection cookie. This marketing site uses Cloudflare Web Analytics, which is cookieless, and a visitor-tracking script served from mtc.labconsole.com by marketing-automation software Guru Labs hosts itself. That script sets first-party cookies on labconsole.com to recognize a returning browser across visits and to associate those visits with a contact once someone requests access. A visit that arrives through a tagged campaign link (a URL carrying utm parameters or a click id) also sets a short-lived first-party session cookie so that, if you then request access, the request records which campaign brought you; untagged visits set no such cookie. The data stays with Guru Labs; no third-party advertising network receives it, and there are no cross-site tracking cookies. Signup and invitation forms use Cloudflare Turnstile for bot protection; Turnstile evaluates browser signals and the requesting IP address, and Cloudflare processes that data under its own privacy policy.
5. Customer images and lab content
Uploaded VM images, courseware, and the contents of lab machines are customer content. Organizations are isolated from one another, and content is processed only to run the customer's classrooms. Guru Labs staff access customer content only to operate the service, to provide support the customer asked for, or when the law requires it. Content is deleted on the schedule in the terms of service: a 30-day export window after account closure, then deletion.
6. Sharing and processors
LabConsole runs on hardware Guru Labs owns in its Salt Lake City, Utah datacenter, not on a third-party cloud. Three providers process data to make the service work: Cloudflare (network delivery, bot protection, and cookieless analytics), Intuit (payment processing), and Google Workspace (delivery of service email). Guru Labs discloses data beyond that only when required by law, and challenges overbroad demands where it can.
7. Retention and security
Account data is kept while the account is active. Billing records are kept as long as tax and accounting law requires. Classroom data is deleted with its classroom, and technical logs are kept only as long as operations and security need them.
Every connection to the service is encrypted with TLS. Passwords are hashed, card numbers are never stored, and organizations are isolated at the platform level. If a breach affects an organization's data, Guru Labs notifies that organization's administrators without undue delay.
8. Your rights
Account holders may request access to, correction of, or deletion of their personal data by email. Organization administrators manage member data directly in the application. Deletion requests are honored unless billing or legal records must be retained, in which case the data is kept only for that purpose. Students should direct requests to their training organization, which controls the classroom data.
9. Children
LabConsole is a professional training platform and is not directed to children under 16. Organizations are responsible for the eligibility of the learners they admit to their classrooms.
10. Changes and contact
Changes to this policy are posted here, and material changes are emailed to organization administrators before they take effect. Privacy questions and requests: [email protected].