Privacy Policy
Effective date: 22 July 2026
EnglishBahasa Melayu
1. What LazyBook is
LazyBook (accessible at https://www.lazybook.app) is a software service that helps creators and businesses — primarily in Malaysia — understand, plan, create and manage content for Facebook Pages they are authorized to manage. LazyBook connects to Facebook exclusively through Meta's official APIs.
2. Who operates LazyBook
LazyBook is operated by an independent software operator based in Malaysia (referred to in this policy as "we", "us" or "the operator"). Contact: syazwan.sarawak@gmail.com. If a registered legal entity later operates the service, this policy will be updated to name it.
3. Information we collect
Account information. When you register we collect your email address and, optionally, a display name. Authentication is provided by Supabase; passwords are handled by that service and are never visible to us in plain text.
Workspace information. Workspace names, membership, roles, and settings you configure (such as brand and audience details you choose to enter).
Facebook and Page information (only after you connect). If you choose to connect a Facebook account, we collect, with your explicit authorization through Facebook Login: your Facebook user ID; the list of Pages you manage with their names, categories and Page task capabilities; and Page access tokens. If and when the related features are enabled for your account, we may also store Page posts, Page and post performance metrics ("insights"), and comments on your Page's posts, in each case only as permitted by the specific Meta permissions you granted.
Current versus planned collection. Today the connection collects only the read-level data described above (Page list, Page identity, granted permissions). Features such as post history import, insights analytics, publishing and comment management are rolled out progressively; each requests its own additional Meta permissions from you at activation, and no such data is collected before you grant them.
Content you create or upload. Drafts, media files, brand documents and other content you add to your workspace.
Technical information. Standard server logs (IP address, user agent, timestamps) and authentication cookies necessary to keep you signed in.
4. Meta permissions we use
The initial Facebook connection requests only pages_show_list (to list Pages you manage) and pages_read_engagement (to read basic Page information). Additional permissions — such as read_insights for analytics, pages_manage_posts for publishing, or comment-related permissions — are requested separately and only when you activate the feature that needs them. We request the smallest permission set required for the features you actually use.
5. Why we process this data
We process each category of data to: authenticate you and secure your account; show you your own Page information and performance; generate analytics, baselines and recommendations for your Pages; create and (when enabled) publish content you approve; provide customer support; comply with legal obligations; and protect the service against abuse.
We do not sell personal data. We do not use your Page data to advertise to third parties.
6. How access tokens are protected
Facebook access tokens are encrypted at rest using authenticated encryption (AES-256-GCM) before they are stored. Raw tokens are never displayed to users, never included in web pages or browser responses, never placed in URLs, and are excluded from application logs. Tokens are deleted when you disconnect Facebook.
7. AI processing
Some LazyBook features use third-party AI model providers to analyse or generate content (for example, drafting a post or summarising performance). When these features are used, selected content — such as a draft, your brand description, or aggregated performance figures — may be sent to an AI provider to produce the result. We apply data minimization: we send the minimum content needed for the feature, we do not send access tokens, and we do not send commenter personal data for model training. AI features that would process personal data from your community are configurable at the workspace level.
8. Service providers
We use a small number of infrastructure providers to run LazyBook: Supabase (database, authentication and storage), Vercel (hosting), Meta Platforms (the Facebook APIs you connect through), AI model providers for the features described above, and — when billing launches — Stripe for subscription payments. Each provider processes data only as needed to provide its service. Billing card details are handled by the payment provider and never stored by LazyBook.
9. Cookies and analytics
LazyBook uses cookies for authentication sessions and to remember your language preference (Bahasa Melayu or English). We do not run third-party advertising trackers. If privacy-respecting product analytics are added, this policy will be updated first.
10. Data retention and deletion
Account and workspace data are retained while your account is active. Facebook connection data (tokens, Page records and synced Page data) is deleted when you disconnect Facebook or delete your account. We may retain limited records where required for legal, billing, security or fraud-prevention purposes. See our Data Deletion instructions for exact steps.
11. Deauthorization and Meta-initiated deletion
If you remove LazyBook from your Facebook settings, Meta notifies our deauthorization endpoint and we mark the connection revoked and stop all further API access for it. If you use Facebook's "Delete your information" option for LazyBook, Meta notifies our data-deletion endpoint; we then delete the Facebook data we hold for that connection and issue a confirmation code, and you can check progress at any time on our deletion status page using that code.
12. Security
We apply industry-standard measures including encrypted transport (HTTPS), encryption of stored credentials and tokens, row-level database isolation between workspaces, role-based access, audit logging of sensitive actions, and least-privilege access to production systems. No online service can guarantee absolute security; we notify affected users of incidents as required by applicable law.
13. Cross-border processing
Our database is hosted in Singapore (AWS ap-southeast-1). Hosting, AI and payment providers may process data in other regions where they operate. Where personal data is transferred outside Malaysia we take reasonable steps to ensure it receives an adequate level of protection, consistent with the Personal Data Protection Act 2010 (PDPA).
14. Your rights
Subject to applicable law — including the Malaysian PDPA — you may: access the personal data we hold about you; request correction of inaccurate data; withdraw consent to processing (which may limit what the service can do for you); disconnect your Facebook account at any time from Settings; and request deletion of your data. To exercise any of these rights, email syazwan.sarawak@gmail.com. We will acknowledge requests within 7 days and respond substantively within 30 days.
15. Meta Platform data
Data received from Meta's APIs is handled in accordance with the Meta Platform Terms and Developer Policies applicable to the permissions you granted. We use Platform Data only to provide the features you asked for, we do not sell it, and we delete it on disconnection as described above.
16. Changes to this policy
We may update this policy as the product evolves. The effective date above always reflects the current version, and material changes will be announced in the application before they take effect.
17. Contact
Questions about privacy: syazwan.sarawak@gmail.com.