LevyLab Inventory — Privacy Policy
Last updated: October 1, 2026
LevyLab Inventory ("the App", package com.asanaofthings.qrscanner) is an
internal laboratory inventory-management tool operated by LevyLab for use by members of
the LevyLab organization. This policy explains what the App collects, how it is used, and
with whom it is shared. The App is restricted to authorized LevyLab accounts and its
backend is accessible only over the organization's private network.
Who this App is for
The App is intended solely for authorized LevyLab personnel who sign in with a
levylab.org Google account. It is not directed to the general public and not
directed to children.
Information we collect
- Account information — when you sign in with Google, we receive your
name, email address, and profile photo to identify you and attribute inventory
changes to you.
- Photos you capture or upload — images of laboratory items and their
QR/location anchors that you take or select within the App, for the purpose of
cataloging inventory.
- Inventory data you enter — item names, quantities, categories,
locations, QR codes, and related notes.
- Diagnostics and usage data — crash reports, performance metrics, and
basic usage analytics collected through Google Firebase (Crashlytics, Performance
Monitoring, Analytics) to keep the App stable.
Device permissions
- Camera — to scan QR codes and photograph items.
- Photos / storage — to select existing images and to temporarily save
captures before they are uploaded.
Permissions are used only for the features described above.
How we use your information
- To authenticate you and control access to the organization's inventory.
- To catalog, search, and track laboratory items and their locations.
- To automatically identify items in photos using an AI vision service (see Sharing).
- To create and update tasks in the organization's project-tracking system.
- To diagnose crashes and improve reliability.
How information is shared
We do not sell your personal information. Data is shared only with the service providers
the App depends on to function:
- Moonshot AI (Kimi vision API) — item photos you submit for automatic
identification are sent to Moonshot's vision API to extract item details. Only the
images and derived text are sent.
- Asana — inventory items and their photos are synced to the
organization's Asana workspace for task tracking.
- Google Firebase — authentication, crash reporting, performance, and
analytics.
Inventory records and photos are otherwise stored on LevyLab's own server and database.
Data retention
Account, inventory, and photo data are retained on LevyLab's systems for as long as the
item records are maintained, or until deleted by an authorized administrator. Diagnostic
data is retained according to Google Firebase's standard retention periods.
Data security
Access requires a valid organizational account, and the backend is reachable only over
the organization's private network (VPN). Authentication tokens are stored encrypted, and
connections to the backend use HTTPS.
Your choices
You may request access to, correction of, or deletion of your personal data, or ask
questions about this policy, by contacting us below. Signing out removes your session from
the device.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the
"Last updated" date above.
Contact
LevyLab — aashita.nyati@levylab.org