Privacy Policy
Last updated: July 24, 2026
1. Who We Are
LaPeTo ("we", "us") provides the Lazy Person's Tool — an AI service that turns uploaded content into platform-ready social copy. This policy explains what personal data we handle and how.
2. Data We Collect
- Account data: email address, display name, authentication provider (email or Google), and — if you sign in with Google — the profile information Google returns.
- Uploaded content: images and video files you submit for analysis, plus any brand profiles, goals, keywords, and hashtags you save.
- Generated content: the AI outputs produced for your analyses, stored so you can revisit them.
- Usage data: credits consumed, analyses run, timestamps, feature toggles, and rate-limit events.
- Technical data: IP address, browser/device information, and logs necessary to operate and secure the Service.
3. How We Use Data
- To provide, maintain, and improve the Service.
- To process uploads through our AI providers and return results to you.
- To enforce credit limits, rate limits, and access tiers.
- To communicate service updates and respond to support requests.
- To detect abuse and comply with legal obligations.
4. AI Processing and Subprocessors
To generate copy we transmit your uploaded media and prompt context to third-party AI model providers via the Lovable AI Gateway. These providers process the content solely to return results and do not retain it to train their models under our configuration. We use trusted infrastructure providers for hosting, database, storage, and authentication.
5. Legal Bases (EEA/UK)
Where GDPR applies, we process data based on: (a) performance of a contract (providing the Service), (b) our legitimate interests (security, product improvement), and (c) your consent where required (e.g., optional analytics).
6. Retention
Analyses are retained for the duration associated with your access tier (7 days on Free, 90 days on Solo, up to 10 years on Pro). Account data is retained while your account is active. You can request deletion at any time from Settings; residual copies in backups are purged on our standard rotation.
7. Security
We use encryption in transit, Row-Level Security on our database, private storage buckets scoped to your user ID, and role-based access controls. No system is perfectly secure; report suspected issues to security@lapeto.app.
8. Your Rights
- Access, correct, or delete your personal data.
- Export your analyses and brand profiles.
- Withdraw consent for optional processing.
- Lodge a complaint with your local data protection authority.
Exercise these rights from Settings or by emailing privacy@lapeto.app.
9. Cookies
We use strictly necessary cookies and local storage to keep you signed in and remember basic preferences. We do not sell personal data.
10. Children
The Service is not directed at children under 16 and we do not knowingly collect their data.
11. Changes
We will notify registered users of material changes to this policy by email or in-app notice before they take effect.
12. Contact
Privacy questions: privacy@lapeto.app.
This document is provided for transparency and does not constitute legal advice. Consult qualified counsel for your specific situation.