Template — not yet publishable
Every [highlighted placeholder] on this page must be replaced with your real details, and the finished text must be reviewed by a lawyer qualified in your jurisdiction before you publish or submit to the app stores. COPPA, the GDPR and the ICO Age Appropriate Design Code all apply to an app for under-13s, and each store reviews this page against them.
1 · Who we are
Little Learners is published by [Company legal name], registered at [registered address]. We are the data controller for the information described here. This policy covers the Little Learners app on iOS and Android and this website. It does not cover the App Store or Google Play themselves, which have their own policies.
2 · What we collect
Everything the app holds is listed below. Nothing else is collected, and nothing here is optional beyond what the table says.
| Information | Why we have it | Whose it is |
|---|---|---|
| Parent email and password | To create the account, let you sign back in, and send the confirmation email if you ask us to delete data. | Parent |
| Child's first name and age band | So the app can greet them and pick the right difficulty. A nickname works just as well — we never ask for a surname or date of birth. | Child |
| Avatar, or a photo you upload | Optional. Lets a child recognise their own profile. Stored on the device only. | Child |
| Game progress and time in app | Stars, completed stages and minutes played, so progress is remembered and the Parent Zone summary works. | Child |
| Screen timer settings | To end a session when you said it should end. | Parent |
| Subscription status | An anonymous store receipt token telling the app whether Premium is active. No card details ever reach us. | Parent |
| Device and crash diagnostics | Optional and off unless you opt in. Device model, OS version and the point of failure — no profile data, no identifier that points back to you. | Device |
What we never collect
- No email address or phone number for a child
- No precise location, GPS or background location
- No contacts, calendar, microphone recordings or photo library scanning
- No advertising identifiers (IDFA, GAID), fingerprinting or cross-app tracking
3 · Children's privacy
The app is intended for children under 13 and is built to meet COPPA, the GDPR's provisions on children's data and the ICO Age Appropriate Design Code. In practice that means six commitments:
- Only a parent can set things up. Accounts, profiles, purchases and settings all sit behind a parent gate a young child cannot pass.
- We collect only what the games need. A first name and an age band is the whole of it. No surname, no birthday, no school.
- Nothing a child enters is ever public. Names, photos and progress are visible only inside your own app.
- No chat, no messaging, no social login. There is no way for anyone to contact your child through the app.
- No behavioural advertising or profiling. We never use a child's data to target anything, and we do not sell or share it for advertising.
- You can review or delete everything, whenever you like. Parent Zone → Privacy & data, or the deletion page.
If you believe a child has given us information without your consent, email [privacy@yourcompany.com] and we will delete it.
4 · How we use information
Only for the things a parent would expect: running the games and saving progress, keeping your account and subscription working, honouring your screen-timer choices, replying when you contact us, fixing crashes you've opted to report, and meeting our legal and tax obligations. We do not use any of it to build profiles, to advertise, or to train models.
Our legal bases under the GDPR are: performance of a contract with you (running the app and your subscription), your consent (optional crash reports and any photo you upload), legitimate interests (keeping the service secure), and legal obligation (financial records). Where we rely on consent, you can withdraw it at any time in Parent Zone → Privacy & data.
6 · Photos and the camera
A profile photo is entirely optional — most families use one of the drawn avatars instead. If you choose a photo, the app asks the system for one-off access to that single image; it never browses or scans your library, and it does not request camera access at all. The image is stored in the app's private storage on the device and is not uploaded to us, backed up to our servers, or included in crash reports. Removing it in Parent Zone → Children deletes the file immediately.
7 · Advertising and tracking
There is no advertising in Little Learners — no banners, no interstitials, no rewarded video, no cross-promotion. There are no ad networks, no analytics SDKs, no social media SDKs and no tracking pixels in the app. We do not use advertising identifiers, we do not fingerprint devices, and there is nothing in the app that follows your child anywhere else.
This website sets no cookies and runs no analytics. Our host keeps standard server logs (IP address, page requested, timestamp) for [14 days] for security purposes only.
8 · How long we keep it
- Profiles and progress — until you delete them, or until the account is inactive for [24 months], after which we delete them automatically.
- Support emails — [12 months] from your last reply.
- Crash reports — [90 days].
- Billing and tax records — [6 years], because the law requires it. Held separately from your account and containing no child data.
- Encrypted backups — overwritten on a [90 day] cycle after deletion.
9 · Your rights and choices
As the parent or guardian you can ask us to give you a copy of everything we hold, correct anything wrong, delete everything, restrict or object to a particular use, or export your data in a portable format. You can also withdraw consent for crash reporting or remove a profile photo at any time without contacting us. We respond within [30 days] and never charge for a request.
The fastest routes are Parent Zone → Privacy & data inside the app, or the account deletion page on this site. If you are in the UK or EU and unhappy with how we've handled a request, you can complain to your national data protection authority — in the UK, the Information Commissioner's Office. Residents of [California / other jurisdictions] may have additional rights described in [relevant local law].
10 · Security
Data in transit is encrypted with TLS and data at rest is encrypted on our servers. Passwords are stored only as salted hashes. Access to production systems is limited to the people who need it, protected by multi-factor authentication, and logged. No system is perfect, so if a breach ever affects your data we will tell you and the relevant regulator within the timeframes the law requires.
11 · International transfers
Account data is stored in [hosting region]. Some of our providers operate in [other regions]; where data leaves the UK or EEA we rely on [UK IDTA / EU Standard Contractual Clauses / adequacy decision] and carry out a transfer risk assessment for each one.
12 · Changes to this policy
If we change anything material we will update the dates at the top of this page and show a notice in the Parent Zone the next time you open the app. Where the law requires it we will ask for your consent again. We will never reduce your protections retroactively without telling you first.
13 · Contact us
Privacy questions: [privacy@yourcompany.com]
Everything else: [support@yourcompany.com]
Post: [Company legal name, registered address]
Data protection representative: [name and contact, if required]
You can also use the contact form. This policy is governed by the law of [jurisdiction].