Privacy Policy

Last updated: August 28, 2026

Policy versions covered:

  • Version 1.0.0 (currently available in the App Store): Privacy Policy version 2026-07-17, described directly on this page and preserved at https://boldfinch.net/lazy-lion-matcha/privacy-policy/versions/2026-07-17/
  • First later App release with Analytics choices and server-data deletion: consent notice version 2026-08-11; the prepared August 25, 2026 AdMob updates and recipient/destination appendix take effect only when a separate publication workflow makes that later App release publicly available

This Privacy Policy describes how Boldfinch HB ("we", "us", or "our") collects, uses, and shares information when you use the Lazy Lion Matcha mobile application ("App"). The App is currently available in the United States and Canada on iOS and Android. See also our Terms of Service: https://boldfinch.net/lazy-lion-matcha/terms

Version scope. This is the single Privacy Policy URL linked from the App Store. It directly describes version 1.0.0 and prepared rules for a first later consent-based release with server-data deletion. If your App has no Settings → Analytics choices entry, the version 1.0.0 rules apply. The consent-based and August 25, 2026 AdMob rules apply only once the later App version is publicly available. Prepared text does not approve a country, regional privacy flow, transfer, or release.

1. About the App

Lazy Lion Matcha is a mobile application that helps users brew matcha drinks at home. The App is currently available in the United States and Canada on iOS and Android. The App does not require account registration, login, or any form of personal identification. All recipes are stored locally on your device. All recipe generation and naming happens entirely on-device — no AI or external API calls are made for recipe content.

2. Information We Collect

2.1 Information You Provide

The App does not ask you to provide any personal information such as your name, email address, or payment details. Recipes you create are automatically saved solely on your device and are never transmitted to our servers.

2.2 Information Collected Automatically

When you use the App, third-party services may process the following information as described in Section 3:

  • Product analytics data in version 1.0.0 — PostHog receives a pseudonymous device identifier and usage events such as screens viewed, recipes generated, recipe interactions, settings changes, and ad-gate interactions
  • Optional product analytics data in a later version with Analytics choices — PostHog receives the same categories only after you select Allow analytics
  • Device metadata — operating system version, device model, and app version, collected for crash reporting purposes
  • Ad-related data in the prepared later release — IP address and coarse location, user-agent, device and operating-system information, App and ad-unit request context, consent and ATT status, an advertising identifier only when available and permitted, ad or creative interactions, diagnostic and fraud signals, and click or impression data

The ad-related categories can be personal or pseudonymous information in context, even where they do not include a name or email address. They support contextual ad delivery, optional personalization where separately permitted, measurement, security, and fraud prevention. They are not anonymous merely because Boldfinch does not use them to identify you by name.

Third-party services may also automatically collect standard technical and network data as part of their normal operation — such as IP address, device type, operating system, app version, and coarse region derived from IP.

The following information is explicitly not collected: recipe names, ingredient lists, search queries, or any free-text content you enter or generate in the App.

No directly identifying information (such as your name, email address, or precise location) is collected.

2.3 Automated Decision-Making and Profiling

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

3. Third-Party Services

The App integrates the following third-party services. Each operates under its own privacy policy, which we encourage you to review.

3.1 PostHog (Product Analytics)

Version 1.0.0 (currently available). We use PostHog to understand how users interact with the App. PostHog assigns a pseudonymous device-level identifier and collects the usage events listed below. It is not controlled by an in-app Analytics choices setting in this version.

First later release with Analytics choices and server-data deletion. PostHog is optional product analytics. It is not initialized and no analytics event is sent unless you select Allow analytics. Choosing No thanks, leaving the choice unresolved, or a problem storing the choice leaves PostHog disabled. This product-analytics choice is separate from the Google UMP and Apple ATT choices for advertising.

In both versions, we do not intentionally attach direct identifiers such as your name or email address to PostHog events. Data is processed in PostHog's US Cloud infrastructure (us.posthog.com) and usage events are retained for up to 12 months.

The PostHog SDK may also attach default properties to events automatically — such as operating system, app version, device type, and app lifecycle state — in addition to the custom events listed below.

PostHog is the only service for which Boldfinch can use the complete Data deletion ID to perform a requester-specific lookup. In the first later release, you may provide that ID to request an understandable copy of matching PostHog records or, where applicable, a machine-readable JSON or CSV export. Access and portability requests are separate from deletion requests.

Events collected include:

  • Lifecycle — app opened, app backgrounded (captured automatically in version 1.0.0; only after analytics has been allowed in the later consent-based release)
  • Navigation — screen viewed; back to start tapped
  • Recipes — recipe generated (drink type, serving size, sweetness, strength, and source — config or surprise; no recipe names or ingredient content); saved recipe opened from history or recent recipes (drink type and whether a rating exists); recipe rated (star value and drink type); recipe deleted (count only)
  • Settings — units changed (weight and volume display preferences)
  • Reviews — review prompt requested (star rating that triggered the prompt — 1 to 5)
  • Advertising — ad notice shown, ad shown, ad skipped, ad failed, ad error, ad bypassed (daily quota already used; includes optional trigger: generate, history, or recent)

3.2 Google AdMob (Advertising)

Prepared global AdMob core for the next App release. This section states the global technical and product facts. It does not approve advertising, a legal basis, a privacy flow, a transfer, or a release in any jurisdiction.

The App is free and ad-supported. It can attempt an interstitial when you enter a recipe instructions screen, including after generating a recipe or opening one from History or Recent. At most one interstitial is attempted per local calendar day. Where the applicable jurisdiction permits the model and the daily gate applies, the contextual-ad attempt is a condition of that free recipe path. The short ad notice is shown before the attempt. Choosing Maybe later, cancelling, or dismissing the notice leaves that gated path without opening the recipe in those markets.

No-fill, network error, legal or technical ineligibility, or display failure can allow the recipe to continue. That technical fallback is not a guaranteed ad-free tier.

Contextual delivery and optional personalized advertising are separate purposes. Personalization, profiling, cross-app tracking, and advertising identifiers remain disabled unless the applicable privacy flow, UMP state, ATT state on iOS, platform signals, and the confirmed-adult App profile permit them. An applicable regional rule overrides this global description.

Boldfinch's identified contractual counterparty for the ordinary AdMob flow is Google Ireland Limited. Google may act as an independent controller for ordinary AdMob services. An initial request goes to Google, which may send bid-request data server-to-server to Authorized Buyers. A winning creative can then cause device-side requests to Google, a Buyer or DSP, an advertiser or ad server, or certified Creative, measurement, verification, or fraud-prevention providers. Some auction notifications can also be server-to-server. Boldfinch does not have a direct contract with every Buyer, and this does not mean Google is the only technical recipient.

The final provider-controlled serving outcome can be personalized advertising, non-personalized advertising (NPA), Limited Ads, or no request. UMP rejection, NPA, Limited Ads, ATT refusal, and other privacy signals can limit personalization, identifiers, or whether an App-level request is allowed. They do not make advertising anonymous or processing-free, and they do not by themselves prove that all personal or pseudonymous processing, international processing, storage, or downstream disclosure has stopped.

Google describes Ads Services as using global infrastructure. Google does not provide Boldfinch with a product-specific country list for every request, bid, creative, measurement event, or fraud check. The countries, retention, and actual involvement of dynamic recipient categories can be unknown or change. Current published Google report and general retention information, together with its gaps, is in Section 11 and the appendix below.

Boldfinch does not maintain an AdMob user record indexed by the App's Data deletion ID. We can explain our advertising configuration and use of AdMob, but cannot use that ID to retrieve a requester-specific Google advertising profile. Requests concerning information Google processes as an independent controller must use Google's applicable privacy controls and request channels.

The prepared versioned AdMob recipient and destination appendix provides the identified parties, dynamic categories, serving-mode data and storage/access information, destinations, explicit unknowns, evidence date, and reassessment triggers:

https://boldfinch.net/lazy-lion-matcha/privacy-policy/admob-recipients/

3.3 Sentry (Crash Reporting)

The App uses Sentry to collect crash and error reports. Sentry captures allowlisted device metadata (OS version, device model, app version), stack traces, and limited diagnostic context to help diagnose technical issues. A beforeSend filter removes user objects, the Data deletion ID, tags, extra fields, request data, fingerprints, and non-allowlisted breadcrumbs before an event leaves the device. We do not intentionally attach a name, email address, account identifier, or Data deletion ID to a Sentry event. Crash report data is stored on Sentry's US cloud servers.

Because Sentry events are not linked to the Data deletion ID, Boldfinch cannot use a requester-supplied Data deletion ID to locate or attribute a specific Sentry report and cannot provide a requester-specific Sentry export based on that ID. This attribution limitation is not a claim that diagnostic data can never be personal information under applicable law.

3.4 Share Feature (share_plus)

The App includes a sharing feature that allows you to share recipes with other apps or people via the OS share sheet. Sharing is entirely user-initiated. No data is sent to us or any third party as a result of sharing.

3.5 In-App Review

After you rate a recipe 1 to 5 stars for the first time, the App may present the platform's native in-app review prompt (Apple's App Store review prompt on iOS; Google Play's in-app review prompt on Android). Whether the prompt appears is controlled by the platform and may vary by device. We do not receive your review text or star rating submitted to the App Store or Google Play. Version 1.0.0 logs only that a review prompt was requested (the star rating used as the trigger) via PostHog; the later consent-based release does so only after you select Allow analytics. No recipe content is included.

4. Local Data Storage

All recipes you create in the App are automatically saved locally on your device using an embedded database (SQLite via the Drift library). The following preferences and identifiers are stored on-device using SharedPreferences and are not uploaded to our servers or accessible to us as a remote profile:

  • unit display preferences (weight and volume)
  • the date of the last ad gate shown (used to enforce the once-per-calendar-day ad limit)
  • whether an in-app review prompt has already been requested
  • in the later consent-based release: the Analytics choices decision and related notice metadata
  • in the later consent-based release: the Data deletion ID used for PostHog access and deletion requests
  • in the later consent-based release: a durable age-handling profile derived from platform age signals (used only to select protective advertising and analytics treatment on the device)

Uninstalling the App removes this on-device data.

5. Permissions and Your Choices

5.1 Permissions

The App does not request access to your camera, microphone, location, contacts, photo library, or push notifications.

5.2 Your Choices

  • Product analytics in version 1.0.0: This version has no Analytics choices setting. Version 1.0.0 has no Data deletion ID or Settings → Legal → Delete server data entry. You may email info@boldfinch.net to exercise your data-protection rights, but this version does not provide the ID-based lookup flow.
  • Product analytics in the first later consent-based release with server-data deletion: You can choose Allow analytics or No thanks at first start after the choice is shown. The effective technical control for changing this device-local choice and stopping future App-to-PostHog capture on that device is Settings → Analytics choices in the App. Support cannot change this setting remotely by email. Withdrawing consent clears the App's local PostHog state, but it does not automatically delete information already processed by PostHog; access and deletion requests remain available separately.
  • Advertising privacy choices in the prepared later release: Applicable privacy and consent flows can differ by jurisdiction. When Settings → Ad privacy choices is available, it is the effective technical control for revisiting the Google UMP choice. On iOS, the separate Apple ATT permission can be changed in iOS Settings → Privacy & Security → Tracking. Support cannot remotely change either device-local setting by email. These controls can limit personalized advertising and cross-app tracking, but NPA or Limited Ads can still involve personal or pseudonymous data for contextual delivery, measurement, security, or fraud prevention. A global policy is not consent or approval for a regional flow.
  • Local recipe data: Uninstalling the App removes all saved recipes and on-device preferences. We cannot access or delete this data remotely.

5.3 PostHog access, portability, and server-data deletion in the first later release

The first later App release with Analytics choices and server-data deletion contains the ID-based request flow. The Data deletion ID is the App installation's pseudonymous identifier used to associate accepted PostHog analytics with a deletion request.

Open Settings → Legal → Delete server data in that later release. You can copy the complete Data deletion ID or choose Email deletion request to contact info@boldfinch.net.

The website cannot read or retrieve your Data deletion ID. There is no website deletion form or automated deletion service; you must provide the complete Data deletion ID copied from the App.

For an access or portability request, email the complete Data deletion ID and state that you want a copy rather than deletion. Boldfinch can search the exact PostHog identifier and return matching PostHog event records in an understandable form and, where applicable, as JSON or CSV. An access request does not delete the records. If you request access followed by deletion, we prepare the access copy before starting the separate deletion process.

When support processes the request, it covers only stored PostHog analytics data associated with the submitted Data deletion ID. It is not an analytics or crash-reporting opt-out. If analytics is allowed again or remains allowed, future PostHog collection continues with the same Data deletion ID and may require a later deletion request.

Sentry crash-report data is excluded from this ID-based access and deletion path. We do not send the Data deletion ID to Sentry and cannot use it to attribute a Sentry event to a requester.

Recipes and preferences remain local to your device; the website and support cannot read them, and they are not part of the PostHog deletion request. Uninstalling the App removes this on-device data.

6. Children's Privacy and Age Signals

The App is not directed at children under the age of 13. Users must be at least 13 years old to use the App (see our Terms of Service at https://boldfinch.net/lazy-lion-matcha/terms). We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information through the App, please contact us at info@boldfinch.net.

Prepared later release — platform age signals. On supported devices, the App may read a minimized age-range signal from the platform (Apple Declared Age Range on iOS; Google Play Age Signals on Android) to choose a protective on-device advertising and analytics treatment. The App stores only a durable handling profile on the device (for example confirmed adult versus protective teen or child treatment). It does not ask you to type your age or birthdate into the App.

Where the mapped range may include under-13 users, the App applies child-directed advertising treatment, does not present the PostHog Analytics choices sheet, and keeps PostHog disabled. Where the range starts at least at 13 but is not confirmed 18+, the App applies a protective teen treatment (including non-personalized ad requests) and may still show Analytics choices. A confirmed 18+ signal allows the ordinary adult advertising path subject to UMP and, on iOS, ATT. If the platform does not support age signals or the result is unknown, the App uses the protective default.

These platform signals are used for compliance and protective configuration. They are not used to build a marketing profile of the user.

7. Regional supplements for the next App release

Status: PENDING. These regional sections are prepared public text for the next App release. They are not current availability statements, legal-basis findings, consent records, transfer approvals, language approvals, or market-activation decisions. A private jurisdiction review must determine the applicable law, user choices, and allowed advertising outcomes before a market is activated.

7.1 United Kingdom — PENDING

The United Kingdom is a planned market. This section does not make the App available in the United Kingdom or establish a UK GDPR or PECR legal basis. Before any UK activation, the private review must assess the applicable UK rules, device storage or access, advertising outcomes, transfers, user choices, and required notices.

7.2 Canada and Québec — PENDING

Canada and Québec are not approved for the next App release. The separate Québec transfer PIA and Canada release gate remain PENDING / NOT APPROVED. The global AdMob description above is not a Québec legal basis and does not establish adequate protection, a qualifying written agreement, a French-language message requirement, or a Canada launch decision.

Canada-wide privacy requests

If Canadian privacy law applies to our handling of your personal information, you may contact us to:

  • ask how personal information about you is collected, used, or disclosed
  • request confirmation and an understandable copy of personal information that we can locate about you
  • where Québec's portability rules apply, request eligible computerized personal information in a structured, commonly used technological format
  • challenge the accuracy or completeness of personal information and request an appropriate correction
  • use the device controls in Section 5.2 to withdraw consent for future optional analytics, advertising personalization, or cross-app tracking
  • challenge our compliance or make a privacy complaint

The categories of information, purposes, recipients, retention periods, and international processing locations are published in Sections 2, 3, 11, and 12. An individual access response will still confirm what matching records were located and explain their use and disclosure; the public explanation does not replace that response.

The App has no customer account or editable user profile. PostHog events record historical App activity rather than profile fields that Boldfinch can rewrite. If you challenge an event or support record as inaccurate, incomplete, ambiguous, or handled contrary to applicable law, we will assess the request and correct, annotate, stop using, or delete information where technically possible and legally required. If no correction can be made, we will explain why and identify available recourse where required.

Boldfinch HB's owner is the person accountable for privacy practices and receives access, portability, correction, deletion, and complaint requests at info@boldfinch.net. We may need enough information to verify that the request concerns you. Email cannot remotely change the App's device-local analytics, UMP, or ATT settings; use the controls in Section 5.2 for future collection on that device. If we refuse all or part of a request, we will explain the reason and available recourse where required.

You may also contact the Office of the Privacy Commissioner of Canada. Its guidance and complaint information are available at https://www.priv.gc.ca/en/report-a-concern/file-a-formal-privacy-complaint/

Additional Québec information

Québec residents may make a written access, portable-format, or rectification request to the privacy contact above. Eligible computerized personal information collected from you, including through your activity, may be provided in a structured and commonly used technological format. Information created or inferred by analysis is excluded where the law provides, and serious practical difficulties may limit the requested format. We will respond within 30 days when the Québec private-sector privacy law applies. If you are dissatisfied with the response or do not receive one within the applicable period, you may seek recourse through the Commission d'accès à l'information du Québec: https://www.cai.gouv.qc.ca/protection-renseignements-personnels/citoyens-protection-renseignements-personnels/recours-devant-commission

PostHog and Sentry process data in the United States, and Google may process AdMob data on global infrastructure as described in Section 12. The current Québec transfer assessment records evidence limitations and the Canada release remains blocked. It does not state that adequate protection has been legally established. A release-owner business decision or Google technical setting is not legal evidence or regional approval.

7.3 United States, including California — PENDING next-release review

Version 1.0.0 availability in the United States is a legacy state and does not approve the next App release. The United States row remains PENDING for a dated federal and applicable state-law review. If California law applies after that separate review, users may have rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and the California Online Privacy Protection Act (CalOPPA), including:

  • Right to know — you have the right to request disclosure of the categories and specific pieces of personal information we collect, the sources of that information, the business purposes for collecting it, and the categories of third parties with whom it is shared
  • Right to delete — you have the right to request deletion of personal information we have collected from you, subject to certain exceptions
  • Right to correct — you have the right to request correction of inaccurate personal information we hold about you
  • Right to opt out of sale or sharing — we do not sell personal information. Sharing of personal information for cross-context behavioral advertising occurs only if you grant permission via Apple's tracking prompt on iOS and consent via Google's UMP. If permission or required consent is not granted, personalization and cross-app tracking remain disabled. Depending on UMP and other applicable signals, the outcome may be a non-personalized ad, Limited Ads, or no App-level AdMob request
  • Right to limit use of sensitive personal information — we do not collect sensitive personal information as defined under CPRA
  • Right to non-discrimination — we will not discriminate against you for exercising any of your California privacy rights

Categories of personal information collected:

Advertising-related identifiers are used only as described in Section 3.2. The PENDING United States review must separately determine the applicable opt-out, notice, and advertising requirements. NPA or Limited Ads is not a claim that no personal or pseudonymous information is processed.

To exercise your California rights, contact us at: info@boldfinch.net

We will respond to verifiable requests within 45 days as required by law.

11. Data Retention

Google's published report and general retention statements are not a complete AdMob or downstream-recipient retention schedule. In particular, the retention for an Authorized Buyer, advertiser, ad server, Creative host, or other dynamic recipient is PENDING unless a dated source identifies it.

Provider retention sources:

12. International Data Transfers

Boldfinch HB is based in Sweden. PostHog analytics data is stored on PostHog's US Cloud servers when PostHog is used: in version 1.0.0, and in the later consent-based release only where you have selected Allow analytics. Sentry crash report data is stored on Sentry's US cloud servers. Google describes Ads Services as using global infrastructure, but does not publish a product-specific country list for every AdMob request, bid, creative, measurement event, fraud check, or dynamic recipient.

Information processed outside your country can be subject to the laws and lawful-access powers of the destination country. A technical Google statement, a transfer mechanism, or a global policy alone does not establish the legal basis, transfer conclusion, or release approval for a jurisdiction. Those questions remain in the PENDING regional review and the separate private evidence record.

13. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date and the policy versions at the top of this page identify the version-specific rules. The public archive of the July 17, 2026 revision is available at:

https://boldfinch.net/lazy-lion-matcha/privacy-policy/versions/2026-07-17/

The prepared August 25, 2026 recipient and destination appendix is available at:

https://boldfinch.net/lazy-lion-matcha/privacy-policy/admob-recipients/

Its archived prepared snapshot is available at:

https://boldfinch.net/lazy-lion-matcha/privacy-policy/admob-recipients/versions/2026-08-25/

Continued use of the App is not treated as consent for optional product analytics. If a future policy change requires consent, the App will request it through a clear in-app choice before the related analytics processing starts.

14. Governing Law

This Privacy Policy is governed by the laws of Sweden. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts of Sweden. Nothing in this clause limits mandatory rights or regulatory recourse under the laws that apply to you, including PIPEDA or Québec privacy rights for Canadian residents and CCPA/CPRA rights for California residents.

15. Contact Us

If you have questions, access or correction requests, or concerns about this Privacy Policy or our data practices, please contact the person accountable for privacy at:

Boldfinch HB

Skärsnäsvägen 1008

291 56 Arkelstorp, Sweden

Email: info@boldfinch.net

Website: https://boldfinch.net/