Privacy Policy for PJey Labs
Last Updated: July 19, 2026
This Privacy Policy explains how PJey Labs collects, uses, shares, stores, and protects personal data when you use our website, applications, and related services (the "Services"). It is a notice about processing and does not make consent a condition of using the Services.
1. Data Controller and Privacy Contact
PJey Labs
For privacy-related questions or requests, please contact:
Email: contact@pjeylabs.com
2. Personal Data We Process
The data processed depends on the Service and features you use:
- Account and identity data: email address, display name or username, user ID, and authentication-provider identifiers.
- User content and service data: notes, documents, settings, preferences, and cloud-synchronisation data you choose to store.
- Technical and diagnostic data: IP address, device and browser type, operating system, app version, language, timestamps, security events, crash reports, and diagnostics.
- Purchase data: transaction identifier, product, subscription status, purchase time, and payment confirmation. PJey Labs does not receive or store full payment-card details.
- Communications: messages, email address, and information you provide in support, privacy, or account-deletion requests.
- Website preference data: the cookie categories you accept or reject and the time and version of that choice.
We receive data directly from you, automatically from the device or Service you use, and, where relevant, from authentication providers, app stores, payment providers, or other services you choose to connect.
3. Purposes and Lawful Bases
- Provide accounts, requested features, cloud storage and synchronisation: necessary to perform our contract with you or to take steps you request before entering a contract.
- Process and administer purchases or subscriptions: performance of a contract and compliance with tax, accounting, and consumer-law obligations.
- Answer support, privacy, and deletion requests: performance of a contract, compliance with legal obligations, and our legitimate interest in supporting users and documenting requests.
- Keep Services secure, prevent fraud and abuse, diagnose faults, and maintain reliability: our legitimate interests in protecting users, systems, and Services, balanced against your rights.
- Comply with law and establish, exercise, or defend legal claims: compliance with legal obligations and our legitimate interests in protecting legal rights.
- Use optional functional, analytics, or marketing technologies on the website: consent, where such technologies are introduced. They remain disabled until consent is given.
Where we rely on legitimate interests, you may ask for information about our balancing assessment and may object to the processing. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out lawfully.
4. Recipients and External Services
We disclose only the data needed for the relevant purpose to service providers acting for us, independent controllers you choose to use, professional advisers, or authorities where legally required. Depending on the Service, recipients may include:
- Google Firebase and Google Cloud: website hosting, delivery of JavaScript modules, Firestore application-catalogue data, authentication, databases, storage, diagnostics, and other backend functions used by a particular app.
- Google Play and Google Groups: app distribution, purchase or subscription administration, and access to testing programmes.
- Microsoft Store or other app stores: app distribution and purchase or subscription administration when you use that store.
- Stripe or another disclosed payment provider: payment processing where offered by a Service.
The public website currently does not load Google Analytics, advertising pixels, OpenAI, or GitHub tracking scripts. If a specific app introduces another provider or an AI feature that sends personal data to a provider, the relevant Service will identify that processing before it occurs and this notice will be updated where required.
5. Data Retention
We keep personal data only for as long as needed for the stated purpose:
- Account data and user content are kept while the account is active and are normally deleted or anonymised within 30 days after a verified deletion request, subject to the exceptions below.
- Residual copies in protected backups may remain until the backup cycle completes, normally no longer than 90 additional days, and are not restored except for disaster recovery.
- Support, privacy, and deletion-request correspondence is normally kept for up to 24 months after the request is closed so we can document and manage it.
- Security and diagnostic records are normally kept for up to 12 months, or longer where needed to investigate an active incident.
- Purchase, tax, and accounting records are retained for the period required by applicable law, normally up to six years after the relevant accounting period.
- The website privacy choice stored on your device expires after 12 months unless you clear it earlier or replace it with a new choice.
We may retain limited data longer where required by law or necessary to establish, exercise, or defend legal claims. When deciding a retention period, we consider the amount and sensitivity of the data, risk of harm, purpose, legal duties, and whether the purpose can be achieved another way.
6. Account and Data Deletion
To request deletion, visit our Delete Account page, select the relevant app, and send the prepared request to contact@pjeylabs.com. You may also email that address directly and identify the Service and account concerned.
We may ask for limited information to verify identity and protect the account. Requests are normally completed within one month. We will explain if the law permits an extension or requires us to retain particular records. The right to erasure is not absolute; legal, accounting, fraud-prevention, security, or legal-claims records may be retained where a lawful exception applies.
7. International Data Transfers
Some providers may process data in the United Kingdom, European Economic Area, United States, or other countries. Where personal data is transferred outside the UK or EEA, we use a lawful transfer mechanism as applicable, such as an adequacy regulation or decision, the European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, together with supplementary safeguards where required.
Contact us if you would like more information about the safeguards relevant to a particular transfer or a copy of applicable contractual safeguards, subject to necessary redactions.
8. Your Data Protection Rights
Subject to the conditions and exceptions in applicable EU GDPR and UK GDPR law, you may have the right to:
- be informed about processing and obtain access to your personal data;
- correct inaccurate or incomplete data;
- request erasure of data;
- restrict processing;
- receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller;
- object to processing based on legitimate interests and object at any time to direct marketing;
- withdraw consent at any time, including through for website technologies; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to lawful exceptions.
We do not currently use personal data on this website for solely automated decisions with legal or similarly significant effects. To exercise a right, email contact@pjeylabs.com. We normally respond within one month and do not charge a fee unless a request is manifestly unfounded or excessive.
9. Complaints
Please contact us first so we can try to resolve your concern. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint. If the EU GDPR applies, you may complain to the data protection authority in the EEA country where you live, work, or believe an infringement occurred.
10. Security
We use appropriate technical and organisational measures intended to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction. These include access controls, encrypted transmission where supported, service-provider controls, and data minimisation. No internet transmission or storage system is completely secure.
11. Children's Privacy
Our Services are not directed to children under 13, and we do not knowingly collect their personal data. A Service offered to children or in a country with a higher digital-consent age may apply a higher age threshold and provide additional information or obtain parental authorisation where required. Contact us if you believe a child has provided personal data without appropriate authorisation.
12. Cookies and Similar Technologies
See our Cookie Policy for details of storage technologies used by this website and how to manage or withdraw consent.
13. Changes to This Privacy Policy
We may update this Privacy Policy when our processing or legal obligations change. We will post the revised version here with a new date and provide additional notice where required. Material changes do not retroactively change a consent choice.