Legal

Privacy policy

Last updated [date]

Effective [date]

Little Learners is made for children aged 4–6, so this policy is written for the parent reading it. In short: we collect the least we can, your child's name and progress stay on the device wherever possible, there is no advertising or tracking of any kind in the app, and you can see or delete everything at any time. The rest of this page is the detail behind those sentences.

Template — not yet publishable

Every [highlighted placeholder] on this page must be replaced with your real details, and the finished text must be reviewed by a lawyer qualified in your jurisdiction before you publish or submit to the app stores. COPPA, the GDPR and the ICO Age Appropriate Design Code all apply to an app for under-13s, and each store reviews this page against them.

1 · Who we are

Little Learners is published by [Company legal name], registered at [registered address]. We are the data controller for the information described here. This policy covers the Little Learners app on iOS and Android and this website. It does not cover the App Store or Google Play themselves, which have their own policies.

2 · What we collect

Everything the app holds is listed below. Nothing else is collected, and nothing here is optional beyond what the table says.

Information the app holds
InformationWhy we have itWhose it is
Parent email and passwordTo create the account, let you sign back in, and send the confirmation email if you ask us to delete data.Parent
Child's first name and age bandSo the app can greet them and pick the right difficulty. A nickname works just as well — we never ask for a surname or date of birth.Child
Avatar, or a photo you uploadOptional. Lets a child recognise their own profile. Stored on the device only.Child
Game progress and time in appStars, completed stages and minutes played, so progress is remembered and the Parent Zone summary works.Child
Screen timer settingsTo end a session when you said it should end.Parent
Subscription statusAn anonymous store receipt token telling the app whether Premium is active. No card details ever reach us.Parent
Device and crash diagnosticsOptional and off unless you opt in. Device model, OS version and the point of failure — no profile data, no identifier that points back to you.Device

What we never collect

  • No email address or phone number for a child
  • No precise location, GPS or background location
  • No contacts, calendar, microphone recordings or photo library scanning
  • No advertising identifiers (IDFA, GAID), fingerprinting or cross-app tracking

3 · Children's privacy

The app is intended for children under 13 and is built to meet COPPA, the GDPR's provisions on children's data and the ICO Age Appropriate Design Code. In practice that means six commitments:

  • Only a parent can set things up. Accounts, profiles, purchases and settings all sit behind a parent gate a young child cannot pass.
  • We collect only what the games need. A first name and an age band is the whole of it. No surname, no birthday, no school.
  • Nothing a child enters is ever public. Names, photos and progress are visible only inside your own app.
  • No chat, no messaging, no social login. There is no way for anyone to contact your child through the app.
  • No behavioural advertising or profiling. We never use a child's data to target anything, and we do not sell or share it for advertising.
  • You can review or delete everything, whenever you like. Parent Zone → Privacy & data, or the deletion page.

If you believe a child has given us information without your consent, email [privacy@yourcompany.com] and we will delete it.

4 · How we use information

Only for the things a parent would expect: running the games and saving progress, keeping your account and subscription working, honouring your screen-timer choices, replying when you contact us, fixing crashes you've opted to report, and meeting our legal and tax obligations. We do not use any of it to build profiles, to advertise, or to train models.

Our legal bases under the GDPR are: performance of a contract with you (running the app and your subscription), your consent (optional crash reports and any photo you upload), legitimate interests (keeping the service secure), and legal obligation (financial records). Where we rely on consent, you can withdraw it at any time in Parent Zone → Privacy & data.

5 · Who we share it with

We do not sell personal data and we never share children's data for advertising. The full list of processors is below; each is contractually bound to use the data only on our instructions.

Service providers
ProviderWhat it does
Hosting
[provider name]
Runs our servers and stores account data in [hosting region].
Apple App Store
Google Play
Process all payments and subscriptions, and distribute the app. We receive only an anonymous receipt token — never your card number, billing address or full name.
Crash reporting
[provider name]
Receives anonymous technical crash reports, and only if you opted in. Configured with advertising identifiers and user IDs disabled.
Email delivery
[provider name]
Sends account, confirmation and support emails to parents. No child data is included in any email.

We may also disclose information if the law requires it, or to a buyer if the business is ever sold — in which case this policy continues to apply and we will tell you before anything changes.

6 · Photos and the camera

A profile photo is entirely optional — most families use one of the drawn avatars instead. If you choose a photo, the app asks the system for one-off access to that single image; it never browses or scans your library, and it does not request camera access at all. The image is stored in the app's private storage on the device and is not uploaded to us, backed up to our servers, or included in crash reports. Removing it in Parent Zone → Children deletes the file immediately.

7 · Advertising and tracking

There is no advertising in Little Learners — no banners, no interstitials, no rewarded video, no cross-promotion. There are no ad networks, no analytics SDKs, no social media SDKs and no tracking pixels in the app. We do not use advertising identifiers, we do not fingerprint devices, and there is nothing in the app that follows your child anywhere else.

This website sets no cookies and runs no analytics. Our host keeps standard server logs (IP address, page requested, timestamp) for [14 days] for security purposes only.

8 · How long we keep it

  • Profiles and progress — until you delete them, or until the account is inactive for [24 months], after which we delete them automatically.
  • Support emails[12 months] from your last reply.
  • Crash reports[90 days].
  • Billing and tax records[6 years], because the law requires it. Held separately from your account and containing no child data.
  • Encrypted backups — overwritten on a [90 day] cycle after deletion.

9 · Your rights and choices

As the parent or guardian you can ask us to give you a copy of everything we hold, correct anything wrong, delete everything, restrict or object to a particular use, or export your data in a portable format. You can also withdraw consent for crash reporting or remove a profile photo at any time without contacting us. We respond within [30 days] and never charge for a request.

The fastest routes are Parent Zone → Privacy & data inside the app, or the account deletion page on this site. If you are in the UK or EU and unhappy with how we've handled a request, you can complain to your national data protection authority — in the UK, the Information Commissioner's Office. Residents of [California / other jurisdictions] may have additional rights described in [relevant local law].

10 · Security

Data in transit is encrypted with TLS and data at rest is encrypted on our servers. Passwords are stored only as salted hashes. Access to production systems is limited to the people who need it, protected by multi-factor authentication, and logged. No system is perfect, so if a breach ever affects your data we will tell you and the relevant regulator within the timeframes the law requires.

11 · International transfers

Account data is stored in [hosting region]. Some of our providers operate in [other regions]; where data leaves the UK or EEA we rely on [UK IDTA / EU Standard Contractual Clauses / adequacy decision] and carry out a transfer risk assessment for each one.

12 · Changes to this policy

If we change anything material we will update the dates at the top of this page and show a notice in the Parent Zone the next time you open the app. Where the law requires it we will ask for your consent again. We will never reduce your protections retroactively without telling you first.

13 · Contact us

Privacy questions: [privacy@yourcompany.com]
Everything else: [support@yourcompany.com]
Post: [Company legal name, registered address]
Data protection representative: [name and contact, if required]

You can also use the contact form. This policy is governed by the law of [jurisdiction].