Privacy Policy
Last updated: August 28, 2026
This Privacy Policy explains what information Lappka handles, why it is used, where it goes, and the choices available to you. Lappka is operated by Ilya Zoria.
1. Information you provide
Account information. Google sign-in and Supabase Authentication provide information such as your email address, name, profile image, account identifier, and authentication records.
Project content. Lappka stores project names, app context, screenshot images, generated or edited copy, layouts, settings, localization data, backgrounds, and generated images.
AI inputs. Prompts, chat history supplied with a request, app context, screenshot text, and selected images are processed when you use AI planning, feedback, copy, translation, or image generation.
Support information. Feedback messages are associated with your account identifier and email address and may be delivered through Resend to Lappka’s support inbox.
2. Information collected automatically
With your permission, Lappka uses PostHog to understand website and product usage. Analytics may include acquisition source and campaign parameters, pages viewed, account and plan status, project and screenshot counts, feature, template and localization usage, checkout and export activity, usage-limit prompts, operation outcomes, and browser or device information.
Lappka links product analytics to your account after sign-in so that funnels, plan conversion, feature adoption, and retention can be measured. Analytics events are designed not to include screenshot contents, uploaded files, AI prompt text, complete payment details, or raw error messages. Lappka disables PostHog autocapture and session recording.
PostHog stores an analytics identifier and your consent preference in browser storage. Analytics collection is disabled by default and begins only after you select “Allow analytics.”
Supabase authentication uses cookies to maintain your signed-in session. Lappka also uses session storage for temporary checkout intent, project creation state, and similar short-lived interface state.
3. How information is used
Information is used to authenticate accounts, save and render projects, process uploads and exports, generate AI content, localize screenshot sets, provide subscriptions and fish allowances, prevent abuse, troubleshoot errors, analyze product usage, respond to feedback, and comply with legal obligations.
Where applicable, processing is based on performing the service you request, legitimate interests in operating and securing Lappka, consent for optional technologies where required, and compliance with legal obligations.
4. Screenshot storage is public-addressable
Uploaded screenshots, backgrounds, thumbnails, and generated card images are currently stored in a Supabase Storage bucket configured for public URLs. Project database records are protected by account-level access controls, but anyone who obtains a direct asset URL may be able to view that file.
Do not upload secrets, private customer data, health information, financial information, or other sensitive personal information. Deleting a project is designed to remove its associated project files, but cached copies may remain temporarily.
5. AI processing
Lappka sends the information needed for an AI request to OpenRouter, which routes it to the configured model provider. Current features use OpenAI-family text models and Google Gemini image models through OpenRouter. Providers may process prompts, product context, screenshot images, and generated output under their own data practices.
Do not include sensitive personal information in AI prompts or screenshots. Review OpenRouter’s Privacy Policy and the relevant model provider’s terms for more information.
6. Service providers
Lappka uses Supabase for authentication, database, and file storage; Stripe for checkout, subscription management, and payment processing; OpenRouter and model providers for AI requests; PostHog for analytics; Resend for email; Google for sign-in and fonts; and Unsplash when you search for stock imagery.
Stripe receives payment details directly. Lappka stores Stripe customer and subscription identifiers, plan status, billing period information, fish usage, and transaction records, but does not store complete card numbers.
7. Retention and deletion
Project data is retained while your account or project remains active. You can delete individual projects in the product. Billing, transaction, security, and webhook records may be kept as needed for accounting, fraud prevention, dispute resolution, and legal compliance.
Analytics data is retained according to Lappka’s configured PostHog retention settings and may be kept in aggregated form for longer where it no longer identifies you.
Lappka does not currently provide a self-service account deletion control. To request account deletion or access to your information, email ilya.zoria.business@gmail.com. Some information may be retained where legally required or necessary to establish or defend legal claims.
8. International transfers
Lappka’s providers may process information in the European Economic Area, the United States, and other countries. PostHog is configured with EU API endpoints, but its subprocessors and other providers may operate internationally and rely on appropriate transfer mechanisms where required.
9. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your personal information, and to withdraw consent where processing relies on consent. You may also have the right to complain to your local data protection authority.
You can allow, reject, or later change optional analytics through the “Cookie settings” control in Lappka’s website footer. Rejecting analytics does not prevent you from using Lappka. Withdrawing consent stops future analytics collection on that browser.
To exercise a privacy right, contact ilya.zoria.business@gmail.com. Lappka may need to verify your identity before completing a request.
10. Security and children
Lappka uses access controls, authenticated APIs, row-level database policies, and encrypted connections. No system is completely secure, so you should keep source copies of important assets and avoid submitting sensitive information.
Lappka is intended for people who can legally enter into a service agreement and is not directed to children.
11. Changes and contact
This policy may change when Lappka’s product, providers, or legal obligations change. The updated date appears at the top of this page.
Questions or requests can be sent to Ilya Zoria at ilya.zoria.business@gmail.com.