Effective October 11, 2026
FullFactory privacy policy
Leech Labs operates FullFactory, a calibration-management application for manufacturers, laboratories, and quality teams. This notice covers the FullFactory iOS, Android, and web applications, their connected services, and these app-specific information pages.
Account and workspace information
In connected mode, we receive and store your account name, email address, account identifier, authentication information, and workspace membership and role. Credentials are submitted to our configured Neon authentication service to sign in, verify your email, or recover your account. Workspace invitations include the invited email address. We use this information to authenticate users, provide access, send verification and recovery messages, administer workspaces, and protect the service.
Records and uploads
Information you enter or import is transmitted to our configured cloud database. This includes organization and provider details, instrument identifiers and descriptions, locations you label within a facility, purchase information, calibration measurements and dates, technician names, notes, and audit attribution. Facility labels are user-entered business records; the app does not obtain your device's geographic location. Optional certificate attachments are PDF, PNG, or JPEG files, with their filename, type, size, and upload metadata. Connected attachments are transmitted to private cloud object storage and associated with your workspace. A photo included in an attachment is therefore uploaded, even though camera scanning itself is local.
Camera, files, and local storage
Camera access is used to scan instrument QR labels and barcodes. The scan supplies the decoded value to the app; the FullFactory scanning workflow does not upload the camera feed. You can deny camera access and enter an Asset ID manually. Files are read only when you choose them for import or attachment. Imports transmit the resulting records in connected mode. Exports and documents prepared for native sharing use the device's app cache. You decide where to send them through the operating system share sheet.
Local demo builds keep their demonstration records and selected certificate files on the device, using local storage and IndexedDB. Reset demo data clears the demo records; clearing the app's storage also removes locally stored files. Demo mode is distinct from the connected production app. Sessions, preferences, workspace selection, invitation state, and unfinished form drafts may be stored on the device. Web/PWA builds cache the application shell; this does not provide offline synchronization of cloud records.
Purposes and access
We use account information, records, and files to provide calibration management, maintain traceable history, show certificates, generate reports and exports, manage team permissions, recover accounts, and respond to support requests. Authorized members of your workspace can access information according to their role. Inviting a person or sharing an export makes the selected information available to the recipients you choose.
Service providers and technical information
Our configured infrastructure uses Neon for authentication, PostgreSQL data access, certificate functions and private object storage, and Hostinger for the hosted web application and app information pages. The repository documents the current database region as AWS us-east-2. Authentication email delivery uses the configured Neon sender. These services receive the requests needed to operate the app, including network connection information such as IP addresses. Our certificate service emits a limited error code when a request fails. Provider logging, backups, and operational records can have separate retention practices; we do not promise that requests leave no server logs or are processed without retention. For details, see Neon's privacy policy and Hostinger's privacy policy. If you contact support by email, we receive the content and contact information you send and use them to respond.
Advertising, analytics, and AI
This version has no enabled advertising SDK, advertising tracking, cloud AI processing, subscriptions, or in-app purchase flow. We do not use app data for advertising tracking. This does not mean the connected app collects no data: account information, workspace records, and selected uploads are stored by its services. Changes to these features will require updated disclosures.
The Android barcode plugin bundles both ZXing and Google ML Kit. The current app leaves the library selection at its default, which selects ZXing in the bundled plugin. ML Kit also has an initialization component in the Android package. Google documents that ML Kit processes scanning input on the device and, when its APIs are used, sends performance and usage metrics, app/device information, error codes, and installation identifiers to Google over HTTPS. We have not verified whether package initialization alone sends any such metrics in this app, and do not promise that the bundled SDK produces no technical telemetry. See Google's ML Kit privacy information and its Android data disclosure for the documented processing.
Security
Connected service URLs use HTTPS. Workspace access is checked by database membership and role policies. Certificate objects are private, with authorized viewing through short-lived signed URLs. These controls reduce unauthorized access; they do not guarantee that a service or file is risk-free. Do not upload unnecessary personal information or secrets in certificate files or notes.
Retention and deletion
Cloud records persist until removed through an authorized process. Archiving an instrument preserves its history. Calibration and audit history and attached document metadata have no ordinary client deletion path. Account deactivation preserves memberships and historical attribution and is not account deletion. The current app does not promise a fixed automatic deletion period or that backups disappear immediately.
You can request account and associated personal-data deletion through Leech Labs support. Ownership and shared calibration records require review: the current database prevents removing an account while it owns a workspace. Identify any workspaces you own so support can address ownership and shared records with you. Any applicable retained information and the reason for retention must be explained when your request is handled. This page does not promise that deleting a local installation deletes cloud records or copies shared with others.
Your choices
You may decline camera access, choose whether to upload attachments, export available workspace records, sign out, and contact us about access, correction, or deletion. Workspace permissions may limit edits to shared records. Remove copies you exported from the destinations you control separately.
Children and changes
FullFactory is designed for professional calibration and quality work. It is not designed as a children's service. This notice will be updated when app data handling changes, with a new effective date.
Contact Leech Labs
For FullFactory support or privacy questions, email support@leechlabs.io. Include only information needed for your request. Do not send passwords, verification codes, or unnecessary certificate files.