LavaEgg stagingTest environment. No live payments. Use synthetic test accounts only.
LavaEgg

Privacy Policy

Effective date: August 3, 2026

This Privacy Policy explains how LavaEgg collects, uses, shares, and protects information when you use the LavaEgg website, Android app, iOS app, and client workbench.

Who this policy covers

This policy applies to LavaEgg, including the LavaEgg Android app, iOS app, website, and client workbench. LavaEgg is the developer and operator of these services.

Information we collect

LavaEgg collects information you provide directly and information generated by normal app and website use.

  • Contact messages: name, email address, phone number, and message text submitted through the public contact form.
  • Bindi conversations: questions and responses, page path, referral hostname, response timing, browser and device category, a shortened pseudonymous visitor label derived from a one-way network hash, and limited abuse-detection signals. LavaEgg does not store the visitor's raw network address in the Bindi conversation record.
  • Phone Bindi operational records: limited event categories, service-action outcome, timing, a masked caller number showing only the last four digits, and a server-side one-way fingerprint used only for repeat-call grouping. Full caller numbers, caller location or area-code inferences, caller audio, caller transcripts, caller-specific response content, and free-text notes are not retained, and phone records are not joined to separate booking or callback phone data.
  • AI Academy coaching: only after you explicitly consent, LavaEgg stores your lesson messages and Bindi's responses for auditing and AI Academy experience improvement. Your lesson messages are sent to xAI to generate Bindi's responses; LavaEgg disables storage on those response requests. If you use the microphone, its recording is sent to xAI for transcription and LavaEgg does not store the audio. Authorized LavaEgg administrators may review stored Academy transcripts.
  • Referral attribution: referral code, referring partner account identifier, visit identifier, visit and expiration timestamps, and a signed HttpOnly browser cookie that can associate a later LavaEgg account signup with the referring partner for up to 90 days.
  • Account information: email address, display name, Firebase user identifier, sign-in provider, and account role when you sign in or create an account.
  • Profile and workbench information: username, phone number, profile image or logo URL, project details, project status, messages, notes, and attachments that you add or that LavaEgg adds while serving your account.
  • Analytics and diagnostics: screens viewed, buttons selected, sign-in events, contact submission events, app platform, and high-level failure reasons used to understand reliability and improve the service.

How we use information

LavaEgg uses collected information to operate the app, respond to messages, support client work, secure accounts, and improve the product.

  • Respond to project inquiries and support requests.
  • Create and maintain client accounts and workbench access.
  • Credit a referral partner when a valid referral visit leads to a LavaEgg account signup.
  • Show project information, messages, attachments, and account details to authorized users.
  • Monitor reliability, debug failures, measure feature usage, and improve the user experience.
  • Audit consented AI Academy lessons and improve the Academy training experience.
  • Protect the app, website, data, and accounts from misuse or unauthorized access.

Authentication and service providers

LavaEgg uses Google Firebase and Google Cloud services for authentication, database storage, file storage, cloud functions, app checks, and analytics. AI Academy lesson messages are processed by xAI to generate Bindi's responses, and LavaEgg disables storage on those response requests. Optional Academy microphone recordings are processed by xAI for transcription and are not stored by LavaEgg as audio. If you use Google sign-in, Google provides authentication data needed to sign you into LavaEgg. If you use Sign in with Apple, Apple provides authentication data needed to sign you into LavaEgg. If you use email and password sign-in, Firebase Authentication manages the credential flow; LavaEgg does not store your password in app code or public source control.

When information is shared

LavaEgg does not sell personal information. Information may be processed by service providers that help operate the app and website, including Google Firebase, Google Cloud, and xAI for consented AI Academy coaching. Stored Academy transcripts are available only to the learner who owns the session and authorized LavaEgg administrators performing audit and experience-improvement review. LavaEgg may also share information if required by law, to protect rights and security, or with your direction when work on your project requires it.

Data retention

LavaEgg keeps account, project, message, contact, and claimed referral-attribution information for as long as needed to provide the service, support the business relationship, meet legal or security obligations, and maintain accurate business records. The complete stored AI Academy lesson session, including its transcript, duplicate model-context messages, and session metadata, is scheduled for automatic deletion 90 days after consent; the learner can delete it earlier. Referral cookies expire after 90 days. Public Bindi conversation records are scheduled for deletion after 90 days and can be deleted earlier by an authorized LavaEgg administrator. You can request deletion or correction using the contact information below.

Your choices

You can choose not to submit the contact form, not to create an account, not to add optional profile or project information, or not to consent to AI Academy transcript storage. Without transcript-storage consent, LavaEgg does not start a live stored Academy lesson. During an active lesson you can export the transcript as JSON or permanently delete the stored lesson session. You can also request access, correction, export, or deletion of personal information by contacting LavaEgg.

Children's privacy

LavaEgg is intended for business and client collaboration use. It is not directed to children under 13, and LavaEgg does not knowingly collect personal information from children under 13.

Security

LavaEgg uses practical security measures such as Firebase-backed authentication, role-aware access, restricted configuration, and secure deployment practices. No online service can guarantee absolute security, but LavaEgg works to protect the information used to operate the app and serve clients.

Changes to this policy

LavaEgg may update this policy as the app, website, or legal requirements change. The effective date above shows when this policy was last updated.

Contact

Questions or requests about this Privacy Policy can be sent to michael.smith@lavaegg.com.

Ask Bindi