Effective August 25, 2026

Privacy should stick.

Labeloo is local-first. You can build and print label sheets without creating an account or sending address data to us.

Local workflow

The browser app and extension save label projects in browser storage on your device. Printing is performed by your browser. Labeloo does not upload a local project merely because you edit, import, export, or print it.

Local field checks for email syntax, U.S. ZIP formatting, and missing address parts run in your browser. They are formatting checks, not postal-deliverability guarantees.

Local data remains until you clear it, uninstall the extension, reset browser storage, or remove it yourself.

Wiplash.ai account and project sync

Labeloo uses Wiplash.ai single sign-on. When you sign in, Labeloo receives an opaque account identifier, your name, email address, and session expiration from the shared Wiplash identity service. Labeloo does not receive your Wiplash password or an upstream identity- provider token. The hosted app uses an essential HttpOnly session cookie. The extension stores an opaque, expiring Labeloo app session in extension storage.

Signing in does not upload your current label project. If you separately enable project sync, we process the project name, label and address content, sheet settings, and revision metadata. Synced projects are isolated by Wiplash account and encrypted at rest. Signing out keeps the local copy and disables automatic sync on that browser.

Google Sheets Editor add-on

The optional Labeloo Google Sheets add-on runs inside the spreadsheet you currently have open. It reads displayed values only from the selection, surrounding table, used sheet range, or custom A1 range you choose. It does not request Google Drive access, enumerate your files, read formulas, comments, collaborators, or revision history, or write to spreadsheet cells.

Header detection, row boundaries, field mapping, and preview occur in the add-on sidebar. Opening, refreshing, or mapping a range does not upload its values. After you click Continue in Labeloo, the add-on sends only the mapped label records plus the workbook, sheet, and range names over HTTPS to the first-party Labeloo account service.

A Wiplash.ai connection is required for this handoff. The add-on stores an opaque, revocable connector credential in Google Apps Script user properties until it expires or you disconnect. Label content is held in an encrypted, account-bound, single-use receipt for no more than ten minutes and is removed after the first consumption or automatic expiry. Spreadsheet values and credentials are not placed in the handoff URL.

Spreadsheet and Google Drive imports

Files selected from your device are parsed locally. A public or anyone-with-link Google Sheet is downloaded directly from the link you provide after you grant optional docs.google.com access. That shared-link path does not use Google OAuth.

Private Google Drive import is available only after Wiplash.ai sign-in. Google separately asks you to choose one Google Sheets file using the narrow drive.file permission. The first-party Labeloo account service temporarily processes the chosen file ID, file name, Google authorization code and access token, and exported workbook bytes to return that spreadsheet to Labeloo. It does not request blanket Drive access, return Google tokens to the app, or retain those tokens for later use.

The exported workbook is limited to 25 MB and held in memory for no more than ten minutes. It is removed after the first download and is not saved as a cloud project unless you later enable project sync.

Labeloo's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Commercial API

API users may submit address data for import normalization or PDF rendering. Those request bodies and generated PDFs are processed to return the requested output and are not saved as cloud projects unless the caller separately uses a project-sync endpoint.

We retain hashed API credentials, usage counts, operation types, timestamps, and security logs for authentication, billing, abuse prevention, and reliability. API keys are shown once; only hashes are stored afterward.

What we do not do

Extensions and third parties

If another browser extension appears on a Labeloo page or print dialog, that extension is controlled by its own permissions and policies. Labeloo does not activate unrelated extensions. Account identity and optional sync are hosted by Wiplash.ai. Google processes the separate Drive authorization and selected-file request under its own terms and privacy policy. Browser stores and other external links are governed by those providers.

Cookies, security, children, and changes

Labeloo does not use advertising or analytics cookies. The account service uses essential signed-session and sign-out cookies for SSO, plus CSRF protection. We use access controls, encrypted transport in production, encrypted project storage, and revision conflict checks. No system is perfectly secure. Labeloo is not directed to children under 13.

We may revise this policy as the service changes. Material changes will receive a new effective date.

Your choices

You can use Labeloo locally, sign out while retaining a local copy, remove local data through your browser, and request access, correction, export, or deletion of account data. Security and operational backups may persist for a limited period according to Wiplash retention procedures. For privacy requests, email support@wiplash.ai.