legal

privacy policy

Last updated: August 9, 2026

The short version

  • Searching needs no sign-in. We measure tool use under an opaque identifier supplied by the assistant host; it is not your name, email address, or chat transcript.
  • The website sets no cookies and runs no analytics, trackers, or ad scripts.
  • We never receive your conversation — only the arguments a tool call carries.
  • Requesting a table is where we collect directly identifying details. You type them into a form yourself. The form calls our reservation tool, and we pass your name to that one restaurant only after you consent. Your email is used for updates and is not shared with the restaurant.

What we receive when you search

lazypaca is a public MCP server at https://api.lazypaca.com/mcp. When your assistant calls a search tool, we receive only that call's arguments: a free-text query, a district, categories, an opening-date bound, a sort order, and a result limit — or a list of place identifiers. The host may also send an opaque subject identifier and an opaque session identifier. We hash both before storage. We do not receive the surrounding chat, your ChatGPT profile, or anything else the assistant knows about you.

We keep the allowed tool-call arguments for 90 days, together with the tool name, success or failure, duration, and result count. We use them to understand active use, improve search, and measure the search-to-reservation funnel. After 90 days we delete the raw events and inactive identifier links, retaining only anonymous daily totalssuch as calls, distinct users and sessions, response time, and conversions. We never store the whole MCP request body, IP address, User-Agent, precise coordinates, credentials, or fields outside this allowlist in the analytics tables. Cleanup runs daily, so deletion can complete during the 24 hours after an event reaches 90 days old.

The map component can receive a coarse locationfrom the assistant (city level, supplied by the host — never a field you fill in). We use it for one thing: centering the map and drawing a “you are here” pin. It never filters search results, and we do not log or store it.

Requesting a table

Some restaurants let you request a table through lazypaca. This is the only feature that collects personal data. It requires Google sign-in so the email address belongs to the person making the request. You enter your name in the form; the form then calls our reservation tool. The assistant may receive the resulting name and reservation status so it can continue the conversation without asking for the same information again.

  • What we collect. Your name, the verified email address and stable subject identifier supplied by Google, optional request notes, the restaurant, date, time, party size, consent time, and reservation status. We do not collect a phone number or payment information.
  • How identities are linked. If a signed-out search and a later signed-in reservation carry the same opaque host identifier, we attach the hashed host identifier and hashed Google subject to one internal user record. We do not use the link for advertising or to build a no-show profile.
  • Why. To authenticate you, process and manage the request, prevent duplicate or abusive requests, and email you status updates.
  • Who receives it. The restaurant you chose receives your name, requested date and time, party size, and any note needed to handle the request. It does not receive your email address from us. The form names the restaurant before you consent; without consent, we do not create the request.
  • How long we keep it. Personal fields are erased 90 days after the requested visit date. We may retain non-personal status and audit records after those fields are erased. We keep no no-show profile.
  • Your control. You can ask the assistant to view or cancel your own request after signing in, or write to support@ongleam.com to access, correct, or delete it.

There is no payment, no deposit, and no cancellation fee. Filing a request does not guarantee a table — the restaurant decides whether to accept it, and we email the result.

Our emails carry no advertising. They contain the request and its status.

What our servers log

Operational application logs record the MCP method name and duration, not query text, request bodies, or reservation names and emails. The separate, access-controlled analytics tables contain only the allowlisted fields and retention described above. Our hosting provider additionally keeps standard network logs that include the IP address of whatever client connected — usually the assistant's servers, or your own address if you connected the endpoint directly from your machine.

Where the restaurant data comes from

Listings are built from the Ministry of the Interior and Safety's nationwide restaurant licence dataset (전국일반음식점표준데이터), published on Korea's public data portal under a licence with no usage restrictions. We normalize and classify it ourselves. It is factual information about businesses, not personal data about you.

Who else is involved

  • Amazon Web Services (region ap-northeast-2, Seoul) hosts the service, database, search index, and infrastructure logs as our processor.
  • Google provides OAuth sign-in, and Google Workspace delivers reservation emails as our processor.
  • Discord receives operator alerts for reservation events. Those alerts can include the restaurant, requested date and time, party size, and an internal booking code, but not your name or email address.
  • MapTiler serves the map tiles. Tile requests are made by the map component running in your assistant, so MapTiler sees those requests and their IP address.

We do not sell or rent anything to anyone, and we do not use your requests to train models.

What we never ask for

Our tools have no input field for payment card data, health information, government identifiers, credentials, or precise coordinates — you can verify this in the tool schemas your assistant shows you. Please do not send such data in a search query; we have no use for it.

This website

The site is static HTML with no cookies, analytics, ad scripts, social scripts, or web fonts. It does not collect form submissions or account data.

Your choices

  • Remove the lazypaca connector in your assistant's settings and every data flow described above stops immediately.
  • Write to us to request access to or deletion of a usage identity and its raw events. For a reservation, you can also ask the assistant to view or cancel it after signing in.
  • Restaurant owners can request a correction or removal of a listing — see support.

Children

lazypaca is a general-audience restaurant search service. It is not directed at children, and we do not knowingly collect personal data from anyone under the age of 14. If you are under 14, please do not use the reservation feature. If we learn we hold such data we delete it.

Changes

If this policy changes we will update this page and the date above. Material changes will be summarized at the top.

Contact

lazypaca is operated by Ongleam Inc. (Seoul, Republic of Korea). Privacy questions: support@ongleam.com. See also our terms of service.