Lazy Hippo Development logo Lazy Hippo development
Home Privacy Terms Delete data Contact

Legal

Privacy Policy

Effective: 12 August 2026 Last updated: 12 August 2026

This policy explains what personal data Lazy Hippo Development collects, why we collect it, who we share it with, and how you can get it deleted. It covers our apps, this website, and our Instagram and Meta integrations.

Contents

  1. Who we are
  2. What this policy covers
  3. What we collect and why
  4. Our apps
  5. Meta, Facebook and Instagram
  6. Legal bases for processing
  7. Service providers
  8. International transfers
  9. How long we keep data
  10. Security
  11. Your rights and choices
  12. Children
  13. Changes to this policy
  14. Contact us

1. Who we are

Lazy Hippo Development is a sole-proprietor indie software studio registered in the Republic of Korea. We are the data controller for the personal data described in this policy.

Lazy Hippo Development

Business Registration No. 121-57-33103

다산지금로163번길 6, 한강 프리미어갤러리 제, 6층 P618호, 남양주시 12284, South Korea

Privacy contact: hippo@lazyhippodev.com

2. What this policy covers

This policy applies to:

  • The website lazyhippodev.com and its subdomains.
  • Our mobile applications: Tochi, Bommi, Fosia and Bavi.
  • Our official social media profiles, including our Instagram and Facebook presence.
  • Any Meta Platform integration we operate, as described in section 5.

Each app also publishes its own privacy notice with app-specific detail. Where an app notice is more specific than this document, the app notice governs for that app:

  • Tochi privacy notice
  • Bommi privacy notice
  • Fosia privacy notice

Our general approach. We do not sell personal data. We do not share it with data brokers. We do not use the content you create inside our apps — your journal entries, habit records, pet health records or task lists — to target advertising to you or anyone else.

3. What we collect and why

CategoryExamplesWhy we process it
Account data Email address, authentication identifier, display name, sign-in provider (Apple, Google) To create and secure your account, sync your data across devices, and restore your backups
Content you create Journal entries and moods (Tochi); habit records and check-ins (Bommi); pet profiles, vet documents, expenses and health metrics (Fosia); tasks and focus sessions (Bavi) To provide the core function of the app. Stored locally on your device, and in our cloud only where you enable sync, backup or sharing
Uploaded documents and images Photographs of vet receipts and lab reports (Fosia), and the values extracted from them To extract expenses and health metrics you have asked us to record. Extraction results are shown to you for review before anything is saved
Purchase data Product identifier, transaction and receipt identifiers, subscription status, entitlement, restore history To unlock paid features and validate subscriptions. We never receive your full payment card details
Usage and analytics data App version, device model, operating-system version, session counts, feature usage, screen views, coarse region inferred by the provider, pseudonymous installation identifiers To understand which features are used, find broken flows, and improve the apps
Diagnostics Crash reports, stack traces, performance traces To diagnose and fix failures. We do not intentionally attach your app content to crash reports
Support communications Your email address, the message you send, and any screenshots you attach To answer your question and keep a record of the request
Website data IP address, browser and device type, referring page, pages viewed, store-link clicks, campaign parameters To keep the site running securely and measure which of our own links and campaigns bring visitors
Meta and Instagram data See section 5 See section 5

We do not require you to provide a name, phone number, precise location, or contacts to use our apps, and we do not request advertising permissions in order to unlock features.

4. Our apps

All four apps are built local-first: your content lives in a database on your device and leaves it only for features you deliberately turn on, such as cloud backup, sharing, or an optional AI feature.

Tochi — mood tracker and journal

Processes the moods and journal entries you write. These are private to your account and are not used for advertising or profiling.

Bommi — quit-habit companion

Processes habit records, check-ins, relapses, reasons and goals. If you choose AI-assisted Rescue, the details needed to generate a response may be sent through our backend to OpenAI and used only to return that response.

Fosia — pet health record

Processes pet profiles, photographs of vet receipts and lab reports, extracted expenses and health metrics, medication routines, and shared-care membership. If you invite another caregiver to a pet profile, the records on that profile become visible to the people you approve, and you can remove them or reset the invite code at any time.

Bavi — ADHD planner and focus

In development. Processes the tasks and focus sessions you create. This policy will be updated before Bavi is released if its processing differs from the above.

Not professional advice. Our apps are self-management tools. Tochi and Bommi are not medical advice, diagnosis, treatment or emergency care. Fosia is a care record and is not veterinary advice — it does not diagnose or treat, and it is not a substitute for a qualified veterinarian.

5. Meta, Facebook and Instagram

This section describes every way we process data through Meta Platforms, Inc. products. It is written to satisfy the disclosure requirements of the Meta Platform Terms and the Meta Developer Policies.

5.1 Our Instagram and Facebook business profiles

We operate official business profiles for the studio and its apps. When you visit, follow, comment on, react to, or send a direct message to one of these profiles, Meta processes your data under Meta's own Privacy Policy, and we receive:

  • Your public profile information — username, profile picture, and any public account details — when you interact with us.
  • The content of comments and direct messages you send us.
  • Aggregated, non-identifying insights about our profile and posts, such as reach, impressions, follower counts and broad audience demographics.

We use this to reply to you, provide support, and understand which of our posts are useful. For the aggregated page and profile insights that Meta produces, Meta and Lazy Hippo Development act as joint controllers under the Meta Page Insights arrangement; Meta bears primary responsibility for that processing, and you can exercise your rights in respect of it directly with Meta.

5.2 Instagram Login and the Instagram Graph API

We operate a Meta app that connects to Instagram using Instagram Login and the Instagram Graph API. This connection is used to manage our own studio and app business profiles — for example, to read our profile and media, review and respond to comments and messages, and publish or schedule our own content.

We request only the permissions we need. The table below lists the permissions our Meta app uses, what data each returns, and what we do with it.

PermissionData accessedHow we use it
instagram_business_basic Account ID, username, account type, profile picture, media objects and their metadata To identify the connected business profile and display our own account and media in our management tooling
instagram_business_manage_messages Direct messages sent to our business profile, and the sender's username and profile picture To read and reply to support and enquiry messages sent to us on Instagram
instagram_business_manage_comments Comments on our media, and the commenter's username To read, reply to, hide or delete comments on our own posts, including moderating spam and abuse
instagram_business_content_publish Media containers we create, and their publish status To publish and schedule our own marketing posts to our own business profile

Access is granted by the profile owner — us — through Instagram Login, and can be revoked at any time from the Instagram account's Settings → Website permissions → Apps and websites. Revoking access immediately ends our ability to call the API on behalf of that profile.

Where a member of the public appears in this data — because they commented on our post or sent us a message — we process their username, profile picture and message content solely to respond to and moderate that interaction.

5.3 Storage, retention and deletion of Meta data

  • Access tokens are stored encrypted on our backend and are used only to make API calls on behalf of our own profiles. They are deleted when access is revoked or the integration is retired.
  • Message and comment content is retained only as long as needed to handle the conversation and keep a support record, and for no more than 24 months.
  • Insights data is aggregated and non-identifying, and is retained for up to 24 months for year-over-year comparison.
  • We cache the minimum Meta data necessary. Where Meta requires data to be refreshed or deleted, we comply within the required period.
  • You can request deletion of the Meta-derived data we hold about you at any time — see our data and account deletion page.

5.4 What we do not do with Meta data

  • We do not sell, license or rent Meta data, or transfer it to data brokers or advertising networks.
  • We do not use Meta data to build user profiles for advertising, to make eligibility decisions, or for credit, insurance, employment or housing purposes.
  • We do not attempt to identify individuals from de-identified or aggregated Meta data.
  • We do not transfer Meta data to any third party except the infrastructure providers listed in section 7, acting as our processors.

5.5 Meta advertising

If we run advertising on Meta platforms, we use Meta's own campaign tools and aggregated reporting. We do not upload customer lists containing your personal data to Meta for ad targeting, and our apps do not embed the Meta SDK for cross-app advertising tracking.

6. Legal bases for processing

If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR and UK GDPR:

PurposeLegal basis
Providing the app and its core features, including your account and cloud syncPerformance of a contract (Art. 6(1)(b))
Processing purchases and subscriptionsPerformance of a contract (Art. 6(1)(b))
Optional AI features you choose to useConsent (Art. 6(1)(a))
Analytics, advertising measurement and non-essential cookiesConsent (Art. 6(1)(a))
Crash reporting, security and fraud preventionLegitimate interests (Art. 6(1)(f)) — keeping our services working and secure
Responding to your support requests and social media messagesLegitimate interests (Art. 6(1)(f)), or contract where the request concerns your account
Meeting tax, accounting and other legal obligationsLegal obligation (Art. 6(1)(c))

Health-related information you choose to record — such as recovery milestones in Bommi — may be special category data under Art. 9. Where that is the case, we process it on the basis of your explicit consent, given by choosing to enter it, and you can withdraw that consent by deleting the records or your account.

7. Service providers

We share personal data only with providers who process it on our behalf, under contract, and only to the extent needed to deliver a feature or keep our services running.

ProviderPurposeData involved
Google Firebase (Google LLC / Google Ireland Ltd)Authentication, database, storage, cloud functions, hosting, notifications, analytics, crash reportingAccount data, synced content, usage and diagnostic data
Apple Inc.Sign in with Apple, App Store distribution and paymentsAuthentication identifier, email address, purchase data
Google Play (Google LLC)Android distribution and paymentsPurchase and subscription data
RevenueCat, Inc.Subscription and entitlement managementPurchase identifiers, subscription status, pseudonymous app user ID
OpenAI, L.L.C.Optional AI features, where you choose to use themOnly the content needed to generate the requested response
Meta Platforms, Inc.Our Instagram and Facebook business profiles and the integration in section 5Profile interactions, comments, direct messages, aggregated insights
Google Analytics (Google LLC)Website measurement, subject to your consent choiceWebsite usage data, pseudonymous identifiers

We may also disclose personal data where we are legally required to, to protect the rights and safety of our users or ourselves, or as part of a business transfer, in which case we will give notice and apply appropriate safeguards.

8. International transfers

We are based in South Korea and our providers operate globally, so your data may be processed in countries other than your own, including the United States. Where we transfer personal data out of the EEA, the UK or Korea, we rely on an adequacy decision where one applies, and otherwise on Standard Contractual Clauses or the equivalent safeguard offered by the provider, together with the provider's own supplementary technical measures.

9. How long we keep data

DataRetention
Content stored locally on your deviceUntil you delete it, reset the app, or uninstall the app. This copy is under your control
Account and synced cloud contentUntil you delete your account, after which it is removed from live systems promptly and from backups within 30 days
Purchase and transaction recordsUp to 5 years, where required by Korean tax and accounting law
Analytics and diagnostic dataUp to 14 months, or the provider's default retention window if shorter
Support correspondenceUp to 24 months after the request is resolved
Meta comments, messages and tokensAs set out in section 5.3

10. Security

We use platform authentication, access controls, encrypted connections in transit, encryption at rest for credentials and access tokens, and the managed security controls of our cloud providers. Access to production data is limited to the studio owner. No system is completely secure, and we cannot guarantee absolute security. If a breach affects your personal data and poses a risk to you, we will notify you and the competent supervisory authority as required by law.

11. Your rights and choices

Everyone

  • Delete your account and cloud data from inside the app, or by request — see our deletion page.
  • Decline or revoke tracking, analytics and notification permissions in your device settings.
  • Choose not to use optional features such as AI assistance, cloud backup or shared care.
  • Revoke our Instagram access from your Instagram account settings.

EEA and UK (GDPR / UK GDPR)

You have the right to access, rectify, erase, restrict or object to processing, the right to data portability, and the right to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with your local supervisory authority.

South Korea (PIPA)

You have the right to be informed of, access, correct, suspend the processing of, and delete your personal information, and to seek redress through the Personal Information Dispute Mediation Committee or the Korea Internet & Security Agency (KISA) privacy call centre (118).

California (CCPA / CPRA)

You have the right to know, delete, and correct personal information, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA, and we do not knowingly sell the personal information of anyone under 16. We will not discriminate against you for exercising a right.

Brazil (LGPD)

You have the rights of confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent.

To exercise any right that is not available directly in the app, email hippo@lazyhippodev.com. We respond within 30 days. We may need to verify your identity — usually by asking you to write from the email address on the account — before we act on a request.

12. Children

Our apps are not directed to children under 13, or under the higher minimum age that applies where you live — 14 in South Korea, and 16 in parts of the EEA. We do not knowingly collect personal data from children below that age. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Changes to this policy

We may update this policy as our apps change. We will revise the "last updated" date above, and for material changes we will give additional notice in the app or by email before the change takes effect. Continuing to use our services after a change means you accept the updated policy.

14. Contact us

Lazy Hippo Development

Business Registration No. 121-57-33103

다산지금로163번길 6, 한강 프리미어갤러리 제, 6층 P618호, 남양주시 12284, South Korea

Email: hippo@lazyhippodev.com

Delete your data: lazyhippodev.com/account-deletion

Lazy Hippo Development

Warm & helpful apps from Seoul, Korea.

Legal

Privacy Policy Terms & Conditions Data & account deletion

Contact

hippo@lazyhippodev.com

Lazy Hippo Development · Business Registration No. 121-57-33103

다산지금로163번길 6, 한강 프리미어갤러리 제, 6층 P618호, 남양주시 12284, South Korea (KR)

© 2026 Lazy Hippo Development. Made slowly, with love, in Seoul.