Last updated: August 1, 2026.
LapLapLa respects your privacy. This Privacy Policy explains what information the service processes, why it is needed, where it may be sent, and which materials remain only on your device.
LapLapLa collects pseudonymous usage statistics. Events may include page views; session start and end; opening, progressing through, and completing content; active time; progress and completion of lessons, books, and stories; language changes; use of maps, studios, and other tools; creation and export of local projects; opening external links; and technical errors.
For analytics, LapLapLa creates a persistent random visitor UUID in localStorage and a random session UUID in sessionStorage. These identifiers do not contain your name or email address, but they allow events from the same browser or the same session to be associated with one another.
Raw analytics events are stored in Supabase and are normally deleted after approximately 15 days. After that period, anonymized aggregate reports that do not contain identifiers of individual visitors or sessions may be retained.
The main LapLapLa service is intended for users aged 16 and over. It is not intended for users under the age of 16.
Search queries may be sent to LapLapLa servers. When you search for images, GIFs, videos, or other media, a query may also be sent to GIPHY, Pexels, Pixabay, Reddit, or Imgflip in order to return relevant results.
Some media search queries may be stored briefly in a Supabase cache to improve performance and avoid repeating the same external request.
LapLapLa uses Sentry for error reports and performance diagnostics. A report may include a stack trace, route or URL, browser type, runtime environment, and technical request context. Sentry performance tracing may also measure a small sample of requests and application operations.
Sentry is configured with sendDefaultPii disabled. Cookies, authorization tokens, request bodies, email addresses, and other recognized sensitive fields are removed or filtered before an event is sent, to the extent covered by the current filtering configuration.
Vercel, which hosts LapLapLa, may also create standard technical hosting and server logs, such as request routes, timestamps, status codes, network information, and runtime diagnostics.
An IP address may be processed to limit request frequency, prevent abuse, and protect the service. If distributed rate limiting through Upstash is enabled, a SHA-256 hash of the IP address and request counters may be sent to Upstash for the duration of the relevant rate-limit window.
LapLapLa does not use the IP address to determine your location and does not request precise or approximate device geolocation. The application does not use advertising identifiers or advertising SDKs.
Regular users do not need an account. Restricted administrative access may use Google OAuth and Supabase Auth. During an administrative sign-in, the administrator's email address, user identifier, OAuth session, and required authentication tokens may be processed solely to verify and secure administrative access.
Drawings, locally created studio projects, user-selected files, and voice recordings are processed and stored on the device using browser storage, IndexedDB, data URLs, or temporary blob URLs. LapLapLa does not upload the contents of those materials to its servers. Analytics may record that a project was created, recorded, shared, or exported, but not the drawing, recording, or project file itself.
If text from a creative tool is used to find suitable media, derived search words may be sent through the media search process described above.
LapLapLa uses Supabase for its database, analytics storage, public content storage, and administrative authentication; Sentry for errors and diagnostics; Vercel for hosting and server logs; and, when enabled, Upstash for distributed request limiting.
GIPHY, Pexels, Pixabay, Reddit, and Imgflip may receive media search queries. YouTube provides embedded videos and may receive standard browser and playback request information under Google's policies. Google OAuth is used only for administrative authentication. Each provider processes data under its own terms and privacy policy.
LapLapLa uses HTTPS and takes reasonable technical measures to protect information in transit and restrict access to server-side data. However, no online service can guarantee complete security.
You may contact us at juliamakhlinfiurst@gmail.com to request information about the processing of your data or to request the correction or deletion of applicable data. Because LapLapLa does not create accounts for regular users, locating pseudonymous analytics events may require your visitor UUID or other technical information that makes it possible to identify the relevant records. Some anonymized aggregate information cannot be linked to a specific user and therefore cannot be individually accessed, corrected, or deleted. Requests are handled in accordance with applicable law.
We may update this Privacy Policy when the service or its data practices change. The current version is published on this page.