Privacy Policy
CoLabEx, operated by Mactranova Group, LLC. Effective September 21, 2026 · version 2026-09-21.
- We collect what you give us (your account, your work, your class activity) and a little that happens automatically (a sign-in cookie, when you were last active, technical error reports).
- We don’t sell your personal information, we don’t show ads, and we don’t run advertising or analytics trackers.
- Other people can see what your settings let them see: a public profile you turn on, a project you make public, a class you join. Nothing is public unless you or your organization makes it so.
- You can download your data and delete your account yourself in Settings. You must be at least 16 to use CoLabEx.
1. Who we are
CoLabEx is a project-management and learning platform operated by Mactranova Group, LLC (“we”, “us”), based in Cedar Lake, Indiana. This policy explains what personal information we collect through the CoLabEx website and app, how we use and share it, and the choices you have. For most purposes we are the “controller” (the party deciding how your information is used); for class data an institution gives us, see section 6.
2. Information we collect
Information you give us.
- Account: your name, email address and password (we store only a one-way scrambled version of the password, never the password itself), and any backup email addresses you add.
- Profile: anything you choose to add — a bio, skills, portfolio and work history, and your visibility choices.
- Your work: projects, tasks, comments, messages, documents, files you upload, submissions, ratings, goals, time entries, budget and expense records, and time off you declare.
- Learning: class membership, course enrollments and completions, quiz and practice scores, skill points, badges and credentials.
- Feedback: messages you send through the Feedback button, and the page you were on when you sent them.
- Billing: if billing is turned on for an organization you belong to, payment is handled by our payment processor; we don’t store full card numbers.
Information collected automatically.
- A sign-in cookie that keeps you signed in (see section 7).
- When you were last active and a daily activity total. These power the Available/Busy indicator and time tracking. We do not record what you do on your screen, take screenshots or track your keystrokes.
- Technical error reports when something breaks: the error message, the page it happened on, your browser type, and your account id so we can fix the problem.
- Records needed to keep the service secure, such as counts of recent sign-in attempts from an account or network address.
Information from others. A teacher, project manager, company or team may add or invite you using your email address, so we receive your address from them. If you use a class code, we record that you joined the class.
3. How we use information
- To provide the service: show you your projects, tasks, classes and messages; let you collaborate; keep a record of who did what; and send notifications you have not turned off.
- To keep the service and its users safe: confirm your email address, prevent abuse and guessing of passwords, investigate problems, and enforce our Terms.
- To fix and improve CoLabEx, including reading error reports and the feedback you send.
- To communicate with you about your account, security and important changes.
- To comply with the law and protect our rights.
AI features. If you use an AI feature (a project summary, task suggestions, or the feature finder), the text you ask it to work on is sent to our AI provider to produce the result. Please don’t include information you are not permitted to share. We limit how many AI requests can be made each day.
Legal bases (for people in the EEA or UK). We process information to perform our contract with you (providing the service), for our legitimate interests (security, improving the service, understanding problems), with your consent where we ask for it, and to meet legal obligations.
4. How we share information
With other people, as you or your organization choose. What others can see depends on the setting: a profile you make public, a project or company page that is made public, your name and work inside a project you belong to, a class roster (visible to the class’s instructors), or a guest link a project manager creates (anyone who has the link can see it).
With service providers that help us run CoLabEx, only as needed for their job:
- Vercel — hosting, and file storage for uploads.
- Neon — our database.
- Anthropic — processing text for AI features.
- Ably — the live “who’s here” presence indicator.
- Cloudflare — a bot check on sign-up and similar forms.
- Resend — sending our emails (when enabled).
- Stripe — payments (when billing is enabled).
- Google — only if you choose to connect your Google account to a feature.
- Any web address you choose to connect to a custom dashboard widget — our servers fetch that address on your behalf, so its owner sees requests from CoLabEx’s servers, and we store the address and (encrypted) any key you give us for it.
For legal reasons or safety — if we believe disclosure is required by law, or is needed to protect people or our rights. In a business change — if Mactranova Group, LLC is involved in a merger, sale or similar transaction, your information may transfer as part of it, and we will tell you if that changes how it is handled.
We do not sell your personal information, and we do not share it with advertisers. We do not run advertising or analytics trackers.
5. Public information
Some things are public by design when you or your organization choose it: a public profile, a company, team or institution profile, a public project or task on the marketplace, a class a teacher posts on the public class board, and course credential verification pages. Please think before making something public; anything public can be seen, copied and indexed by others.
6. Schools, classes and students
A class is run by an instructor, usually on behalf of an institution. Instructors and their institution decide how a class is used and can see the roster and the work students submit in it. When an institution or instructor gives us student information, we handle it on their behalf as a service provider and use it to run the class — not for advertising, profiling or selling.
A class code or invite link lets a person join; keep it private if the class is. If you are a student, your school’s own privacy policy and any agreement it has with us also apply, and your school is your first contact for questions about your education records. If you are a school and need a data-protection agreement, contact us.
Grades, scores and class results are not shown on a public profile unless the student chooses to share them. Skill points, badges and credentials a person earns can appear on their profile according to their visibility settings.
7. Cookies and similar technology
We use one essential cookie to keep you signed in, and your browser’s local storage to remember display choices such as theme, text size and menu state. We do not use advertising cookies or third-party analytics cookies. Our bot-check provider may set its own technical cookie on the pages where the check appears. You can clear cookies and local storage in your browser at any time; you will be signed out and your display choices will reset on that device.
8. How long we keep information
We keep your information while your account is open. When you delete your account (Settings → Your data), your name, email address, bio, picture, skills, settings, connections and backup emails are removed and your account can no longer be used to sign in. We keep what belongs to other people’s shared records: the work you did on shared projects, ownership and financial records (for example, who completed which task), and messages or comments you wrote in shared conversations — these remain, shown as “Deleted user”. We also keep an audit log of important actions (such as approvals, permission changes and security events); it is append-only by design, so entries made before you deleted your account still show the name recorded at the time. We may also keep information we must keep by law. Backups are overwritten on our providers’ regular schedules. Error reports and security counters are kept only as long as they are useful for fixing problems and keeping the service safe.
9. Security
We protect your information with measures that include encrypted connections, one-way hashing of passwords, checks on every page and request that you are allowed to see what you are asking for, limits on repeated sign-in attempts, email confirmation of accounts, optional two-factor sign-in with an authenticator app, and an append-only audit log of important actions. No system is perfectly secure. If you believe your account has been compromised, or you find a security problem, please tell us right away.
10. Your choices and rights
- Access and correction. You can see and edit most of your information in your profile and Settings, and manage your email addresses there.
- Export. In Settings → Your data you can download a copy of your account data as one file. You can also download task lists, expenses and portfolio data as CSV files.
- Deletion. You can delete your account yourself in Settings → Your data (see section 8 for what stays). If you can’t sign in, contact us and we’ll help; we aim to complete requests within 30 days.
- Email choices. You can turn most notification emails off in Settings; we will still send essential account and security messages.
- Visibility. You control your profile visibility and what you share publicly.
If you are in the EEA or UK you also have the right to object to or restrict certain processing, to data portability, to withdraw consent, and to complain to your local data-protection authority. If you are a California resident you have the right to know what personal information we collect, use and disclose, to request deletion or correction, and not to be discriminated against for using these rights. We do not sell or “share” personal information as those terms are defined in California law. To make a request, contact us (section 14); we may need to verify your identity, and we will respond within the time the law allows.
11. Children
CoLabEx is not for anyone under 16. We do not knowingly collect information from people under 16. If you believe a child has given us information, contact us and we will delete it.
12. International use
We are based in the United States and our providers process information in the United States. If you use CoLabEx from another country, you understand your information will be transferred to and processed in the United States, where data-protection laws may differ from those where you live. Where the law requires safeguards for such transfers, we rely on appropriate mechanisms with our providers.
13. Changes to this policy
We will post any change here with a new effective date and version. If a change is significant, we will tell you by email or inside CoLabEx before it takes effect. Continuing to use the service after a change means you accept it.
14. Contact us
You can reach us with the Feedback button inside CoLabEx; a dedicated support email address will be published here. Please include enough detail for us to find your account and understand your request.
See also our Terms of Service.