Privacy Policy

Last updated: July 17, 2026

This Privacy Policy describes how Boldfinch HB ("we", "us", or "our") collects, uses, and shares information when you use the Lazy Lion Matcha mobile application ("App"). The App is distributed on the US Apple App Store and US Google Play. By using the App, you agree to the practices described in this policy. See also our Terms of Service: https://boldfinch.net/lazy-lion-matcha/terms

1. About the App

Lazy Lion Matcha is a mobile application that helps users brew matcha drinks at home. The App is distributed on the US Apple App Store and US Google Play. The App does not require account registration, login, or any form of personal identification. All recipes are stored locally on your device. All recipe generation and naming happens entirely on-device — no AI or external API calls are made for recipe content.

2. Information We Collect

2.1 Information You Provide

The App does not ask you to provide any personal information such as your name, email address, or payment details. Recipes you create are automatically saved solely on your device and are never transmitted to our servers.

2.2 Information Collected Automatically

When you use the App, certain information is collected automatically through third-party services (described in Section 3):

  • Usage data — anonymous, device-level events such as screens viewed, recipes generated, recipes opened from history, star ratings set, unit preference changes, recipe deletions, and ad gate interactions
  • Device metadata — operating system version, device model, and app version, collected for crash reporting purposes
  • Ad-related data — contextual signals used to serve advertisements; cross-app tracking for ad personalization occurs only if you grant permission via Apple's App Tracking Transparency (ATT) prompt on iOS and via Google's User Messaging Platform (UMP) consent flow

Third-party services may also automatically collect standard technical and network data as part of their normal operation — such as IP address, device type, operating system, app version, and coarse region derived from IP. We do not use this data to identify you personally.

The following information is explicitly not collected: recipe names, ingredient lists, search queries, or any free-text content you enter or generate in the App.

No directly identifying information (such as your name, email address, or precise location) is collected.

2.3 Automated Decision-Making and Profiling

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

3. Third-Party Services

The App integrates the following third-party services. Each operates under its own privacy policy, which we encourage you to review.

3.1 PostHog (Analytics)

We use PostHog to understand how users interact with the App. PostHog assigns an anonymous, pseudonymous device-level identifier and collects usage events. No personal identifiers are attached to these events. Data is stored on PostHog's US Cloud infrastructure (us.posthog.com) and retained for up to 12 months.

The PostHog SDK may also attach default properties to events automatically — such as operating system, app version, device type, and app lifecycle state — in addition to the custom events listed below.

Events collected include:

  • Lifecycle — app opened, app backgrounded (captured automatically)
  • Navigation — screen viewed; back to start tapped
  • Recipes — recipe generated (drink type, serving size, sweetness, strength, and source — config or surprise; no recipe names or ingredient content); saved recipe opened from history or recent recipes (drink type and whether a rating exists); recipe rated (star value and drink type); recipe deleted (count only)
  • Settings — units changed (weight and volume display preferences)
  • Reviews — review prompt requested (star rating that triggered the prompt — 1 to 5)
  • Advertising — ad notice shown, ad shown, ad skipped, ad failed, ad error, ad bypassed (daily quota already used; includes optional trigger: generate, history, or recent)

3.2 Google AdMob (Advertising)

The App displays interstitial advertisements served by Google AdMob when you navigate to a recipe instructions screen — including when generating a new recipe or opening a saved recipe from history or recent recipes — subject to a once-per-calendar-day limit on your device (see Section 4). By default, ads are non-personalized and contextual — no behavioural profiling or cross-app tracking is used for ad targeting unless you explicitly permit it.

On first launch, the App presents Google's User Messaging Platform (UMP) consent flow before any ad request is made. On iOS, when an ad is about to be shown, the App presents Apple's App Tracking Transparency (ATT) prompt after you confirm the ad notice and before the ad loads — but only if your tracking preference has not yet been set. Cross-app tracking for ad personalization is used only if you consent via UMP and, on iOS, grant permission in the ATT prompt. If you deny tracking, restrict it, or have not yet been asked, ads are requested as non-personalized only. Ad requests are built dynamically based on your UMP consent state and, on iOS, your ATT preference. After the daily ad gate has been used, further recipe opens that day proceed without an advertisement.

Google does not disclose a specific data storage region for AdMob to app developers. Ad-related data may be processed on Google's global infrastructure; Google generally routes traffic to data centers closest to the user, but the exact storage location is not defined or selectable by us.

For advertising, Google may also process data as an independent controller under its own privacy policy, in addition to processing we direct through the AdMob SDK.

3.3 Sentry (Crash Reporting)

The App uses Sentry to collect crash and error reports. Sentry captures device metadata (OS version, device model, app version) and crash stack traces to help diagnose technical issues. Personal identifiers are actively stripped from crash reports via a beforeSend filter before any data leaves the device. No personal identifiers are intentionally attached to crash reports. Crash report data is stored on Sentry's US cloud servers.

3.4 Share Feature (share_plus)

The App includes a sharing feature that allows you to share recipes with other apps or people via the OS share sheet. Sharing is entirely user-initiated. No data is sent to us or any third party as a result of sharing.

3.5 In-App Review

After you rate a recipe 1 to 5 stars for the first time, the App may present the platform's native in-app review prompt (Apple's App Store review prompt on iOS; Google Play's in-app review prompt on Android). Whether the prompt appears is controlled by the platform and may vary by device. We do not receive your review text or star rating submitted to the App Store or Google Play. We log only that a review prompt was requested (the star rating used as the trigger) via PostHog analytics; no recipe content is included.

4. Local Data Storage

All recipes you create in the App are automatically saved locally on your device using an embedded database (SQLite via the Drift library). Your unit display preferences (weight and volume), the date of the last ad gate shown (used to enforce the once-per-calendar-day ad limit), and whether an in-app review prompt has already been requested are stored on-device using SharedPreferences. None of this data is uploaded to our servers or accessible to us.

5. Permissions and Your Choices

5.1 Permissions

The App does not request access to your camera, microphone, location, contacts, photo library, or push notifications.

5.2 Your Choices

  • Personalized ads and cross-app tracking: On iOS, you can deny permission when prompted via Apple's App Tracking Transparency dialog, or later in Settings → Privacy & Security → Tracking. Ad consent is collected via Google's User Messaging Platform on first launch. You can change your UMP ad consent at any time in the App via Settings → Ad privacy choices.
  • Local recipe data: Uninstalling the App removes all saved recipes and on-device preferences. We cannot access or delete this data remotely.

6. Children's Privacy

The App is not directed at children under the age of 13. Users must be at least 13 years old to use the App (see our Terms of Service at https://boldfinch.net/lazy-lion-matcha/terms). We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information through the App, please contact us at info@boldfinch.net.

7. Your Rights Under GDPR (EU/EEA Users)

Although the App is currently available in the US only, we are committed to GDPR compliance in anticipation of future EU/EEA availability. If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of access — you may request a copy of the personal data we hold about you
  • Right to erasure — you may request deletion of your personal data ("right to be forgotten")
  • Right to rectification — you may request correction of inaccurate personal data
  • Right to restriction — you may request that we restrict processing of your data
  • Right to data portability — you may request a machine-readable copy of your data
  • Right to object — you may object to processing based on legitimate interests
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time

Data Controller:

Boldfinch HB

Skärsnäsvägen 1008

291 56 Arkelstorp, Sweden

VAT: SE969803944401

Email: info@boldfinch.net

To exercise your rights or ask questions, contact us at info@boldfinch.net. You also have the right to lodge a complaint with your national supervisory authority (in Sweden: Integritetsskyddsmyndigheten, imy.se).

Legal basis for processing:

  • Analytics (PostHog): Legitimate interests in improving the App
  • Advertising (AdMob): Legitimate interests in monetising the App; consent via UMP and ATT on iOS for personalized advertising and cross-app tracking
  • Crash reporting (Sentry): Legitimate interests in maintaining App stability

8. Your Rights Under CCPA/CPRA (California Residents)

If you are a resident of California, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and the California Online Privacy Protection Act (CalOPPA):

  • Right to know — you have the right to request disclosure of the categories and specific pieces of personal information we collect, the sources of that information, the business purposes for collecting it, and the categories of third parties with whom it is shared
  • Right to delete — you have the right to request deletion of personal information we have collected from you, subject to certain exceptions
  • Right to correct — you have the right to request correction of inaccurate personal information we hold about you
  • Right to opt out of sale or sharing — we do not sell personal information. Sharing of personal information for cross-context behavioral advertising occurs only if you grant permission via Apple's tracking prompt on iOS and consent via Google's UMP. If you do not grant permission, non-personalized ads are served based on contextual signals only
  • Right to limit use of sensitive personal information — we do not collect sensitive personal information as defined under CPRA
  • Right to non-discrimination — we will not discriminate against you for exercising any of your California privacy rights

Categories of personal information collected:

Advertising-related identifiers are used only as described in Section 3.2 (non-personalized by default; personalized cross-app advertising only with UMP and ATT consent where applicable).

To exercise your California rights, contact us at: info@boldfinch.net

We will respond to verifiable requests within 45 days as required by law.

9. Data Retention

10. International Data Transfers

Boldfinch HB is based in Sweden. PostHog analytics data is stored on PostHog's US Cloud servers. Sentry crash report data is stored on Sentry's US cloud servers. Google does not publish a specific data storage location for AdMob; ad-related data may be processed internationally on Google's global infrastructure. PostHog, Google, and Sentry rely on Standard Contractual Clauses (SCCs) and other approved transfer mechanisms under GDPR for any such international transfers.

11. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the App after changes are posted constitutes acceptance of the revised policy.

12. Governing Law

This Privacy Policy is governed by the laws of Sweden. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts of Sweden. Nothing in this clause limits the mandatory rights you have under the laws of your country of residence, including GDPR rights for EU/EEA residents and CCPA/CPRA rights for California residents.

13. Contact Us

If you have questions, requests, or concerns about this Privacy Policy or our data practices, please contact:

Boldfinch HB

Skärsnäsvägen 1008

291 56 Arkelstorp, Sweden

Email: info@boldfinch.net

Website: https://boldfinch.net/