My Lab Trends
← Home

Privacy Policy

Effective date: July 7, 2026

My Lab Trends is built on a simple principle: your health data belongs to you. This policy explains exactly how data flows in this application and what we do and do not do with it.

What data we collect

My Lab Trends does not collect, store, or transmit your lab data to any server we operate. When you upload a CSV file, it is parsed entirely inside your browser. The values never leave your device except to be rendered into charts on your screen.

When you sign in with Google, we receive your name and email address from Google's OAuth 2.0 service. This information is stored only in your browser's sessionStorage for the duration of your session and is discarded when you close the tab.

Google API usage

My Lab Trends uses Google Sign-In to authenticate users. We request only the minimum scopes necessary for the features you actually use. Signing in grants us nothing beyond your basic profile. If you choose to create a starter Google Sheet, we additionally request the drive.file scope, described in the next section. We never request access to Gmail, your existing Drive files, or any other Google service.

My Lab Trends's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Creating a starter Google Sheet

If you don't have a results file yet, the app can create a formatted spreadsheet for you. When you click "Create My Google Sheet," Google asks you to approve the drive.file permission. This is the narrowest Drive scope Google offers: it lets the app create new files and work with files the app itself created, and nothing else. It cannot see, read, list, or modify anything already in your Google Drive.

The spreadsheet is created directly in your own Google Drive. You own it, and it is governed by your Google account settings, not by us. We never store a copy of the sheet, its contents, or your access token on our servers.

Here is exactly how the creation request works. Google issues a temporary access token to your browser, where it is held in sessionStorage for the duration of your session and discarded when the tab closes or you log out. Your browser sends that token, your chosen marker names, and any optional details you entered in the setup wizard to our /api/create-sheet endpoint. That endpoint is a stateless pass-through: it uses the token to create and format the sheet through Google's API within that single request, returns the sheet's link to your browser, and retains nothing. No token, no marker list, no personal details, no logs of your data.

The optional details in the setup wizard (date of birth, sex, height, weight, conditions, pregnancy status) exist only to pre-fill the Personal Information tab of your own sheet. Every field can be skipped.

Revoking access

You can revoke My Lab Trends's Drive permission at any time from your Google account permissions page. Revoking access does not affect sheets already created; they remain yours, in your Drive, and the app can no longer touch them.

Cookies and local storage

My Lab Trends uses sessionStorage to hold your session data, your imported lab records, and the temporary Google access token during your active session. This data is not shared with third parties and is cleared automatically when your browser session ends. We do not use tracking cookies or advertising cookies.

To make reconnecting easier, the app may store a reference to the Google Sheet you created or last imported from (the sheet's file ID and title) in your browser's localStorage. This reference contains no lab values, no health information, and no credentials, and it cannot be used to access your sheet without your Google authorization. It persists between visits so you can reload your data with one click, and you can remove it at any time with the Forget my saved sheet option or by clearing your browser's site data.

Third-party services

My Lab Trends loads Chart.js from a public CDN to render charts, and the Google Sign-In library from Google's servers. These services have their own privacy policies. No advertising networks or analytics services are embedded in this application.

Children's privacy

My Lab Trends is not directed at children under 13. We do not knowingly collect information from children.

Changes to this policy

If this policy changes materially, we will update the effective date at the top of this page. Continued use of the application after changes constitutes acceptance of the updated policy.

Contact

Questions about this policy can be directed to the contact information on the My Lab Trends website.