1. Scope and service model
This policy applies to VU Lab’s website, accounts and creator tools. VU Lab is an independent third-party creator service and is not affiliated with, endorsed by, sponsored by, operated by or part of IMVU.
VU Lab separates server account records from projects kept in your browser. Signing in does not turn browser-local projects into cloud backups.
2. Account information and policy evidence
When you register, VU Lab stores your normalized email address, display name, account identifier, account role, account status and email-verification timestamp, together with creation and update timestamps. New public accounts receive a FREE entitlement but cannot use creator tools until email verification is complete.
Registration also stores separate server-authoritative acceptance records containing the account ID, acceptance timestamp and version identifiers for the Terms of Use and Privacy Policy. This evidence supports future renewed acceptance if a policy changes materially. Account roles may include user, admin and owner; Owner Permanent Pro is an internal administrative grant, not a purchasable subscription.
3. Email verification and account communications
VU Lab uses your email address to send the required account-verification message and security or account communications. The verification URL contains a cryptographically random token, not a password, session, role or entitlement claim. VU Lab stores only a SHA-256 hash of that token with the account ID, creation time, 24-hour expiry and optional consumption time.
Successful activation atomically records the account verification time and consumes the token. Requesting a resend uses persistent pseudonymous rate limits and invalidates prior outstanding verification tokens. The response is deliberately generic so an arbitrary email-address probe does not reveal whether an account exists. Temporary delivery failure does not create a duplicate account; the user can safely request another message.
4. Authentication credentials
VU Lab uses password authentication. Passwords are not stored in plaintext. The server stores a salted scrypt password hash and a password-provider subject associated with the account.
VU Lab does not ask for or use IMVU passwords, IMVU cookies or IMVU session credentials.
5. Sessions and essential cookies
After a successful sign-in by a verified account, VU Lab sets one essential opaque session cookie named vu_lab_session. It is HTTP-only, uses SameSite=Lax, is marked Secure in production, applies across the site and has a maximum lifetime of 14 days. The server stores only a SHA-256 hash of the session token with the account ID and creation and expiry times.
Signing out revokes the current server session and clears that cookie. Expired sessions are deleted during session checks. VU Lab does not currently use analytics, advertising or other non-essential tracking cookies, so no cookie-consent banner has been added for the implemented service.
5. Subscription and entitlement information
VU Lab stores FREE or PRO entitlement state, status, start and end times where applicable, and fields reserved for a future payment provider, customer, subscription and verified payment reference. Live checkout and Paystack payment processing are not currently connected, so VU Lab does not currently collect card or bank details through the service.
6. Security and anti-abuse information
Public login and registration use persistent abuse controls to prevent automated signup, password guessing, credential stuffing and high-frequency authentication traffic. VU Lab creates keyed HMAC digests for normalized account identifiers, trusted network identifiers and account/network pairs. Separate HMAC domains prevent the same raw value from producing the same digest for different identifier types.
The abuse table stores only the action, scope, 64-character keyed digest, window start, attempt count, optional block-until time, expiry and update time. It does not store raw IP or network addresses, plaintext email addresses, attempted passwords, password hashes, session tokens, user-agent strings, human-verification tokens or Turnstile responses.
Retention is rule-bounded: short request buckets expire after 1–2 hours, login-failure buckets after 2–24 hours, and daily registration buckets after no more than 48 hours. Expired rows are deleted opportunistically and can also be removed by scheduled database maintenance.
7. Human verification
Registration can be configured with no external human-verification provider or with Cloudflare Turnstile. When Turnstile is disabled, VU Lab does not send registration verification data to Cloudflare.
When Turnstile is enabled, the registration page obtains a verification token and VU Lab sends Cloudflare that token, VU Lab’s secret verification key and, when a trusted address is available, the visitor’s network address. VU Lab checks the returned success, action and hostname values but does not persist the token or Cloudflare’s verification response.
8. Browser-local creator projects
Shop Studio
Shop Studio saves a versioned draft in your browser’s localStorage when the project contains meaningful work. The draft can include the collection name, notes and product IDs, names, image URLs, product URLs and featured selection. Starting over removes that browser record.
Range Builder
Range Builder similarly saves its range name, notes, product details and complete-look groupings in localStorage. Starting over removes that browser record.
These localStorage drafts remain on that browser profile until you clear them, clear site data or the browser removes them. They are not uploaded to the VU Lab account database, are not synchronized across devices and are not cloud backups.
9. Temporary and in-session creator data
The Shop Studio → HTML Lab handoff uses sessionStorage. It contains a mapped product-page project, is valid for up to 15 minutes and is removed when HTML Lab consumes it. Browser session storage may also be cleared when the tab or browsing session ends.
HTML Lab editing state is held in the active page. Image Lab, GIF Lab, Music Cutter, Snapshot Studio, Shop Studio banner editing and the current Spotlight image preview process selected files through browser memory, canvas, audio APIs or temporary object URLs. The implemented tools do not upload those selected local files to a VU Lab file-storage service. Temporary data is lost when it is reset, released or the page/session ends unless you download an export yourself.
10. Public IMVU information
When you request a public creator or product lookup, VU Lab sends the username, creator ID, product ID or supported public URL needed to perform the request to VU Lab’s server. The server requests publicly available profile, product, lineage, image or productdata information from IMVU endpoints. Responses may be cached for short technical intervals under the application’s framework cache settings.
Returned public information can include names, public IDs, profile and product images, creator status, public profile details, product metadata, ownership information and derivation relationships. VU Lab does not use private IMVU credentials to perform these lookups.
11. Product Extractor
Product Extractor requires a signed-in account with PRO access. In hosted production, it accepts an IMVU product ID and operation mode, then uses approved public IMVU product and productdata sources to return product details, derivation relationships or eligible texture resources. Server memory may temporarily contain downloaded public manifests and resource bytes while a request is processed.
The hosted extractor does not read a subscriber’s IMVU Studio projects, browser IndexedDB, Downloads folder, local Studio cache or other local files. Explicitly enabled local-development and fixture providers can read configured private server-side paths, but those providers are blocked in production and cannot be selected by supplying a filesystem path in a request.
12. Radio Studio and network requests
Radio Studio sends search and station identifiers to VU Lab, which queries the public Radio Browser directory. Playing a station causes your browser to connect directly to that station’s stream host, so the station operator can receive ordinary connection information such as your network address and browser request details.
VU Lab can ask a station host for a bounded sample to validate a public stream, and it notifies Radio Browser when a listed station is played. If you submit your own public stream URL for checking, VU Lab temporarily processes that URL and destination hostname to validate it; the implemented checker does not create a persistent database record.
13. Creator Promotion and Spotlight
The homepage Spotlight booking interface currently stages campaign details in localStorage on that browser. An uploaded preview image is represented by a temporary browser object URL and is not a production upload. A separate server campaign workflow exists only for development: it can process account ID, public creator/product information, campaign text, dates, computed price and development payment references in process memory. Production campaign creation, payment confirmation and lifecycle endpoints are disabled.
14. Retention and deletion
Account and entitlement records are retained while the account is maintained and as needed to operate or secure it. VU Lab has not implemented a self-service account-deletion endpoint. Session and anti-abuse retention are described above. Browser-local projects remain under your browser’s storage controls until you clear them or use the relevant Start Over action.
Because no approved public contact is configured yet, account deletion, access or correction requests cannot be operationally received through a published mailbox. That contact must be supplied before launch. VU Lab will not invent a fixed retention period for account records or future payment records before an approved operational schedule exists.
15. Security
VU Lab uses server-only database credentials, salted password hashing, hashed session tokens, HTTP-only cookies, same-origin checks for account mutations, entitlement checks, production fail-closed storage behavior, persistent rate limits and bounded external requests. No internet service can guarantee absolute security, and users should use a unique password and protect access to their devices and email accounts.
16. Your choices and rights
You can sign out to revoke the current session and use creator-tool reset controls or browser site-data controls to remove browser-local drafts. Depending on the law that applies to you, you may have rights to request access, correction, deletion, restriction or objection concerning personal information.
An approved mailbox for privacy and account-data requests is still required. Do not launch public registration until the owner configures and monitors that public contact channel.
17. Third-party services and international processing
Current external services include Neon/PostgreSQL infrastructure for production authentication storage, Vercel or another configured hosting/proxy environment, optional Cloudflare Turnstile, IMVU public endpoints, Radio Browser and independent radio stream hosts. Links to external radio providers or other sites lead to services with their own terms and privacy practices.
These services and their infrastructure may process data in countries other than your own. The repository does not establish VU Lab’s business location or promise a particular data-hosting country, so this policy does not make an unsupported data-localization claim.
18. Account age eligibility
VU Lab accounts are for users aged 16 or older. Users who are under the age of majority where they live may use VU Lab only where permitted by applicable law and with any consent from a parent or legal guardian required by that law. Users are responsible for meeting the account eligibility requirements in the Terms of Use.
VU Lab does not currently ask for or store a date of birth solely to create an account, does not request identity documents for age checks and does not perform identity-based age verification. Optional Turnstile processing is an anti-abuse measure, not age verification. VU Lab does not classify creator projects or vary creator-tool permissions based on project content.
19. Changes to this policy
VU Lab may update this policy when the service, providers or legal obligations change. Material changes should be posted here with a revised update date. Payment processing and production Spotlight operations will require specific policy updates before those features go live.