Privacy Policy
Effective date: August 29, 2026
Lamp. (the "Service") is a collection of browser-based apps for children, operated by a sole proprietor based in Japan trading as Lamp. (the "Operator", "we", "us"). Because the Service is made for young children, it is designed from the ground up to collect as little data as possible — and to collect no personal information about children at all. This policy explains what little we do collect, why, and what your rights are.
1. Our approach at a glance
- No account, no identifier — until a parent chooses to sign in. Simply using the Service creates no account and no identifier of any kind. Everything runs locally in your browser. A sign-in happens only when a parent or guardian chooses to purchase (or restore) a paid plan, or to use the account-based parent features: backup to the parent's own Google Drive, and the break signal sent to the family's devices.
- No personal information about children. We do not ask for or collect a child's name, date of birth, photos, voice, or contact details. Sign-in, when it happens, is done by the parent or guardian with their own Google account.
- No advertising, no behavioural tracking. The Service contains no ads, no ad networks, no behavioural profiling, and currently no analytics tools.
- Camera stays on the device. Apps that use the camera process the video entirely on your device. Camera images are never sent to our servers (if a parent uses the optional backup feature, they are copied to that parent's own Google Drive — see section 4).
- Creations stay on the device. Drawings, music, and other works your child makes are stored in the browser's local storage on your device, not on our servers. If a parent chooses to use the backup feature, the backup goes directly from the browser to the parent's own Google Drive; it never passes through our servers and we cannot see it.
2. Information we collect and why
Until a parent signs in, we collect nothing and create no account or identifier at all. All settings, creations, and usage limits are handled locally on your device. The table below therefore applies only once a parent chooses to sign in (to purchase or restore a plan, or to use the backup or break-signal features).
| Data | When it is collected | Purpose |
|---|---|---|
| Parent's Google account information (email address and the account identifier ("uid") issued by our authentication provider, Firebase Authentication, when the parent signs in with Google) | Only when a parent signs in with their Google account — behind the parental gate — to purchase or restore a paid plan, or to use the backup or break-signal features | Managing the plan (keeping it across devices and restoring it on a new device by simply signing in again), and delivering the break signal to any device signed in with the same Google account (we do not identify or store anything about individual devices) |
| Plan status ("entitlements": free / paid plan and its validity, plus the customer and subscription identifiers issued by our payment provider and the billing state), attached to the signed-in Google account | When a subscription starts, changes, or ends | Providing the features of the plan you purchased |
| Break signal: the start and end time of a break chosen by the parent, whether it was set to last until the next day, the time the signal was sent, and a random identifier for that signal (one record per account; each new signal overwrites the previous one, and a finished signal is deleted) | Only when a parent uses the "break signal" feature | Relaying the parent's instruction to the devices signed in with the same Google account. No history of signals, play time, device names, or child information is kept |
| Error reports (optional): what went wrong (error type, message and technical stack trace, the page path such as "/parent"), basic device information (browser user-agent, screen size, language, time zone, available storage), the local profile identifier, the signed-in account identifier and plan if the parent is signed in, and any free-text note the parent chooses to write | Only when a parent explicitly presses "Send" on the error-report dialog. Records are kept on the device until then, and nothing is sent automatically — there is no "always send" setting. The full contents are shown for review before sending | Finding and fixing the cause of a failure (for example a backup that did not work). No artwork, photos, child names, or content typed by children is included, and page addresses never include anything after "?" or "#" |
That is the complete list. We do not collect names, addresses, phone numbers, precise location, contact lists, photos, audio, or advertising identifiers.
Separately from the table above, our hosting and database provider (Google / Firebase) keeps ordinary technical records — such as IP address, browser type and timestamp — as part of serving the site securely. These records are deleted automatically after 30 days. We may read them in aggregate — for example, how many visits came from each country — but we do not use them to identify individuals or to build profiles. We use no analytics or advertising SDKs, and set no cookies for analytics or advertising.
Backups are not something we collect. If a parent uses the backup feature, the device's data (creations and settings) is written directly from the browser into the parent's own Google Drive, in a folder named "Lamp. backup". We never receive or store it, and the permission Lamp. requests from Google covers only files that Lamp. itself created — not the rest of your Drive. You can delete the folder from Google Drive at any time.
3. Children's privacy (COPPA / GDPR)
- The Service is directed at children, so we take the strictest approach available under the U.S. Children's Online Privacy Protection Act (COPPA) and the EU/UK GDPR rules for children: we simply do not collect personal information from children.
- Until a parent signs in, we create no account and no identifier of any kind — there is nothing on our side that identifies the child, the browser, or the device.
- Everything that involves personal data (signing in with a Google account, purchasing a subscription) is an action taken by the parent, behind a parental gate, using the parent's own information.
- If you believe a child has somehow provided us with personal information (for example, by writing it into a support email), contact us at the address below and we will delete it promptly.
4. Camera and microphone
Some apps can use your device's camera (for example, to place a face stamp in a drawing). The video is processed entirely on your device by the browser and is never uploaded, stored, or seen by us. The same applies to any microphone recordings made inside the apps: they are stored only in your browser's local storage. You can revoke camera and microphone access at any time in your browser settings.
If a parent uses the backup feature (section 6 of the Terms of Service), this data is included in the backup. Face cut-outs used for stickers, camera images saved inside apps, and voice recordings are all part of the app data stored on the device, and a backup copies that data to the parent's own Google Drive. Even then it does not pass through our servers and we cannot see it — but it does leave the device. Unless you use the backup feature, none of this data ever leaves your device.
5. Payments
Subscriptions are sold through Paddle, our payment provider acting as merchant of record. Paddle collects and processes the payment information (such as card details and billing address) under its own privacy policy; we never receive your card details. We receive only what is needed to activate your plan (for example, a confirmation that a subscription for your account is active). See Paddle's privacy policy at paddle.com/legal/privacy.
6. Where your data is stored (service providers)
- Google Firebase (Google LLC) provides our hosting, authentication, and database infrastructure. The data listed in section 2 is stored on Google's servers, which may be located outside your country (including the United States). Google processes this data on our behalf as a processor. See Google's privacy policy at policies.google.com/privacy.
- Paddle processes payments as described in section 5.
- Google Drive (Google LLC) — only if you use the backup feature — holds your backup in your own Google account, under Google's own terms and privacy policy. This is your storage, not ours: we have no access to it and it is not one of our service providers.
- We do not sell or share your data with anyone else, and we do not use third-party analytics or advertising services.
7. Data retention and deletion
- Account data (the parent's Google account email, account identifier, and plan status) exists only if a parent has signed in, and is kept while the account is in use. The break-signal record is a single entry per account that each new signal overwrites, and it is deleted together with the account.
- You can request deletion at any time by emailing us at the address below. We will delete your account and the data associated with it without undue delay, except for records we are legally required to keep (for example, transaction records kept by the payment provider).
- Error reports (if you chose to send any) are kept only for as long as they are useful for diagnosing and fixing the problem, and are deleted once that work is done. They are deleted together with your account on request.
- Data stored locally on your device (creations, settings) can be removed by you at any time by deleting it in the apps or clearing your browser's site data.
8. Your rights
Depending on where you live (for example, under the GDPR in the EU/UK or the Act on the Protection of Personal Information in Japan), you have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- delete your data ("right to erasure");
- receive your data in a portable format;
- restrict or object to certain processing.
To exercise any of these rights, email us at the address below. If you are in the EU/UK, you also have the right to lodge a complaint with your local data protection authority.
9. Changes to this policy
If we change this policy — for example, when we add a feature or when the law changes — we will post the updated policy on this page and announce material changes on the Service in advance in a reasonable manner. The effective date at the top shows the current version.
10. Contact
Privacy questions and requests: makoto.develop@gmail.com