Lamp.

Privacy Policy

Effective date: August 29, 2026

Lamp. (the "Service") is a collection of browser-based apps for children, operated by a sole proprietor based in Japan trading as Lamp. (the "Operator", "we", "us"). Because the Service is made for young children, it is designed from the ground up to collect as little data as possible — and to collect no personal information about children at all. This policy explains what little we do collect, why, and what your rights are.

1. Our approach at a glance

2. Information we collect and why

Until a parent signs in, we collect nothing and create no account or identifier at all. All settings, creations, and usage limits are handled locally on your device. The table below therefore applies only once a parent chooses to sign in (to purchase or restore a plan, or to use the backup or break-signal features).

DataWhen it is collectedPurpose
Parent's Google account information (email address and the account identifier ("uid") issued by our authentication provider, Firebase Authentication, when the parent signs in with Google) Only when a parent signs in with their Google account — behind the parental gate — to purchase or restore a paid plan, or to use the backup or break-signal features Managing the plan (keeping it across devices and restoring it on a new device by simply signing in again), and delivering the break signal to any device signed in with the same Google account (we do not identify or store anything about individual devices)
Plan status ("entitlements": free / paid plan and its validity, plus the customer and subscription identifiers issued by our payment provider and the billing state), attached to the signed-in Google account When a subscription starts, changes, or ends Providing the features of the plan you purchased
Break signal: the start and end time of a break chosen by the parent, whether it was set to last until the next day, the time the signal was sent, and a random identifier for that signal (one record per account; each new signal overwrites the previous one, and a finished signal is deleted) Only when a parent uses the "break signal" feature Relaying the parent's instruction to the devices signed in with the same Google account. No history of signals, play time, device names, or child information is kept
Error reports (optional): what went wrong (error type, message and technical stack trace, the page path such as "/parent"), basic device information (browser user-agent, screen size, language, time zone, available storage), the local profile identifier, the signed-in account identifier and plan if the parent is signed in, and any free-text note the parent chooses to write Only when a parent explicitly presses "Send" on the error-report dialog. Records are kept on the device until then, and nothing is sent automatically — there is no "always send" setting. The full contents are shown for review before sending Finding and fixing the cause of a failure (for example a backup that did not work). No artwork, photos, child names, or content typed by children is included, and page addresses never include anything after "?" or "#"

That is the complete list. We do not collect names, addresses, phone numbers, precise location, contact lists, photos, audio, or advertising identifiers.

Separately from the table above, our hosting and database provider (Google / Firebase) keeps ordinary technical records — such as IP address, browser type and timestamp — as part of serving the site securely. These records are deleted automatically after 30 days. We may read them in aggregate — for example, how many visits came from each country — but we do not use them to identify individuals or to build profiles. We use no analytics or advertising SDKs, and set no cookies for analytics or advertising.

Backups are not something we collect. If a parent uses the backup feature, the device's data (creations and settings) is written directly from the browser into the parent's own Google Drive, in a folder named "Lamp. backup". We never receive or store it, and the permission Lamp. requests from Google covers only files that Lamp. itself created — not the rest of your Drive. You can delete the folder from Google Drive at any time.

3. Children's privacy (COPPA / GDPR)

4. Camera and microphone

Some apps can use your device's camera (for example, to place a face stamp in a drawing). The video is processed entirely on your device by the browser and is never uploaded, stored, or seen by us. The same applies to any microphone recordings made inside the apps: they are stored only in your browser's local storage. You can revoke camera and microphone access at any time in your browser settings.

If a parent uses the backup feature (section 6 of the Terms of Service), this data is included in the backup. Face cut-outs used for stickers, camera images saved inside apps, and voice recordings are all part of the app data stored on the device, and a backup copies that data to the parent's own Google Drive. Even then it does not pass through our servers and we cannot see it — but it does leave the device. Unless you use the backup feature, none of this data ever leaves your device.

5. Payments

Subscriptions are sold through Paddle, our payment provider acting as merchant of record. Paddle collects and processes the payment information (such as card details and billing address) under its own privacy policy; we never receive your card details. We receive only what is needed to activate your plan (for example, a confirmation that a subscription for your account is active). See Paddle's privacy policy at paddle.com/legal/privacy.

6. Where your data is stored (service providers)

7. Data retention and deletion

8. Your rights

Depending on where you live (for example, under the GDPR in the EU/UK or the Act on the Protection of Personal Information in Japan), you have the right to:

To exercise any of these rights, email us at the address below. If you are in the EU/UK, you also have the right to lodge a complaint with your local data protection authority.

9. Changes to this policy

If we change this policy — for example, when we add a feature or when the law changes — we will post the updated policy on this page and announce material changes on the Service in advance in a reasonable manner. The effective date at the top shows the current version.

10. Contact

Privacy questions and requests: makoto.develop@gmail.com

プライバシーポリシー

発効日: 2026年8月29日

Lamp.(以下「本サービス」)は、日本在住の個人事業者 (屋号: Lamp.。以下「運営者」)が 運営する、子ども向けブラウザアプリ集です。本サービスは幼い子ども向けであるため、 収集するデータを最小限にし、子どもの個人情報は一切収集しないことを 設計方針としています。本ポリシーでは、収集するわずかなデータとその目的、 利用者の権利について説明します。

1. 方針の要点

2. 収集する情報とその目的

保護者がサインインするまで、運営者は何も収集せず、 アカウントも識別子も一切作成しません。設定・作品・利用時間の制限などは、 すべて利用者の端末内で処理されます。したがって下表は、保護者がサインイン (プランの購入・復元、またはバックアップ・きゅうけいの合図の利用のため)を 選択した場合にのみ適用されます。

データ収集のタイミング目的
保護者の Google アカウント情報(メールアドレスと、Google でサインインした ときに認証基盤 Firebase Authentication が発行するアカウント識別子(uid)) 保護者がペアレンタルゲートの内側で、有料プランの購入または復元、 あるいはバックアップ・きゅうけいの合図の利用のために自分の Google アカウントで サインインした場合のみ プランの管理(複数の端末でのプランの引き継ぎと、新しい端末で再度サインイン するだけで復元できるようにするため)、および同じ Google アカウントでサインイン している端末へ「きゅうけいの合図」を届けるため(運営者は個々の端末を識別する 情報を持たず、保存もしません)
プラン状態(entitlements: 無料/有料プランの種別と有効性、決済プロバイダが 発行した顧客ID・サブスクリプションIDおよび課金状態。サインインした Google アカウントに結びつきます) サブスクリプションの開始・変更・終了時 購入されたプランの機能を提供するため
きゅうけいの合図: 保護者が選んだ休憩の開始・終了時刻、「あしたまで」の指定か どうかの区別、合図を送った時刻、その合図のランダムな識別子(アカウントごとに1件。 新しい合図で上書きされ、終わった合図は削除されます) 保護者が「きゅうけいの合図」機能を使った場合のみ 同じ Google アカウントでサインインしている端末へ保護者の指示を届けるため。 合図の履歴・プレイ時間・端末名・子どもの情報は保持しません
エラーレポート(任意): うまく動かなかったときの内容(エラーの種類・ メッセージ・技術的なスタックトレース、「/parent」のようなページの道すじ)、 端末の基本情報(ブラウザの user-agent・画面サイズ・言語・タイムゾーン・ 空き容量)、端末内のプロファイル識別子、保護者がサインインしている場合は そのアカウント識別子とプラン、および保護者が任意で書いたメモ 保護者がエラーレポートの画面で「送る」を押した場合のみ。 それまで記録は端末内にとどまり、自動で送信されることはありません (「今後は自動で送る」という設定はありません)。送信前に中身を全文確認できます 不具合(たとえばバックアップの失敗)の原因を特定して修正するため。 作品・写真・お子さんの名前・お子さんが入力した文字は含まれず、 ページのアドレスに「?」「#」以降が含まれることはありません

収集するのは以上がすべてです。氏名・住所・電話番号・正確な位置情報・連絡先リスト・ 写真・音声・広告識別子は収集しません。

なお上表とは別に、ウェブサイトの配信とセキュリティのため、委託先である Google(Firebase)のサーバーには、アクセス時のIPアドレス・ブラウザの種類・日時と いった技術的な記録が残ります。この記録は30日後に自動的に削除されます。運営者は 「どの国から何件のアクセスがあったか」といった集計としてこれを見ることがありますが、 個人の識別やプロファイリングには使いません。アクセス解析や広告の SDK は入れておらず、 解析・広告を目的とするクッキーも使いません。

バックアップは運営者が収集するものではありません。保護者がバックアップ 機能を使うと、端末のデータ(作品・設定)はブラウザから保護者自身の Google ドライブの 「Lamp. backup」フォルダへ直接書き込まれます。運営者がそれを受け取ったり保存したりする ことはなく、Lamp. が Google に求める権限は「Lamp. 自身が作成したファイル」に限られます (ドライブ内のほかのファイルには及びません)。フォルダは Google ドライブからいつでも削除できます。

3. 子どものプライバシー(COPPA / GDPR)

4. カメラ・マイクについて

一部のアプリは端末のカメラを使用します(例: おえかきに顔スタンプを置く機能)。 映像の処理はすべて端末内でブラウザにより行われ、アップロード・ 保存されることはなく、運営者が見ることもできません。アプリ内でのマイク録音も 同様に、ブラウザのローカルストレージにのみ保存されます。カメラ・マイクへのアクセス許可は、 ブラウザの設定からいつでも取り消せます。

保護者がバックアップ機能(利用規約第6条)を使った場合、 これらのデータもバックアップの対象になります。シール用に切り抜いた写真、アプリ内に 保存されたカメラ画像、録音した声は、いずれも端末に保存されているアプリのデータであり、 バックアップはそれを保護者自身の Google ドライブへ複製します。この場合も 運営者のサーバーを経由せず、運営者が内容を見ることはできませんが、データが端末の外に 出ることになります。バックアップ機能を使わない限り、これらのデータが端末から出ることは ありません。

5. 決済について

サブスクリプションは、Merchant of Record(記録上の販売者)である決済プロバイダ Paddle を通じて販売されます。カード情報や請求先住所などの決済情報は Paddle が自社のプライバシーポリシーに基づいて収集・処理し、運営者がカード情報を 受け取ることはありません。運営者が受け取るのは、プランを有効化するために必要な 情報(アカウントのサブスクリプションが有効である旨の通知等)のみです。Paddle の プライバシーポリシー: paddle.com/legal/privacy

6. データの保存先(委託先)

7. 保存期間と削除

8. 利用者の権利

お住まいの地域の法令(EU/英国の GDPR、日本の個人情報保護法等)に基づき、 利用者には次の権利があります。

これらの権利を行使される場合は、下記メールアドレスまでご連絡ください。EU/英国に お住まいの方は、所轄のデータ保護機関に苦情を申し立てる権利もあります。

9. 本ポリシーの改定

本ポリシーを変更する場合(例: 機能の追加や法令の改正に伴う場合)は、 改定版を本ページに掲載し、重要な変更については合理的な方法により 事前に本サービス上で告知します。冒頭の発効日が現行版の発効日を示します。

10. お問い合わせ

プライバシーに関するお問い合わせ・各種請求: makoto.develop@gmail.com