OFFICIAL DOCUMENT
Privacy Policy
Explains what data we collect, why we use it, who receives it, retention, and your rights.
1. Who is responsible
The operator shown on this page is responsible for personal data in Little Spark. Use the listed privacy email for questions, rights requests, or complaints. The real entity, address, and service region must be configured before production.
2. Data we collect
We may process account and contact details, guardianship, child nickname and age, interests and application data, granular permissions, project content and responses, mentor notes, growth reports, help and safeguarding actions, login security records, AI draft audits, and data-rights requests. We do not require a child's public real name or intentionally collect unnecessary precise location.
3. Purposes and grounds
Data supports accounts, application review, safe groups, mentor support, visibility choices, safeguarding, service security, abuse prevention, legal duties, and reliability. Depending on location, grounds may include contract, guardian authorization, legitimate interests, vital interests, or legal obligation. Optional AI and media processing use separate choices.
4. Visibility and recipients
Content is visible only according to the child's choice and group role. Parents normally see growth trends and shared reports, not every raw expression. Necessary data may be handled by contracted cloud, email, security, and enabled AI providers. We do not sell child personal data or use it for behavioral advertising.
5. Transfers, security, and incidents
Provider locations may involve international processing; the operator must document locations and safeguards before launch. Controls include least privilege, audit trails, staff MFA, and encryption in transit. No system is perfectly secure; incidents that may affect your rights will be addressed and notified under applicable rules.
6. Retention
Data is kept only as long as needed for the stated purpose, disputes, child protection, or legal duties. Temporary abuse controls, invitations, AI audits, and safeguarding records have different periods, after which data is deleted or de-identified. Parents can review governance information and request deletion in their account.
7. Your rights and choices
Subject to local law, you may request access, copies, export, correction, deletion, restriction, or objection, and withdraw consent-based permissions. Withdrawal does not undo earlier lawful processing. Parents can manage child permissions; children may also say no, ask for help, or stop sharing. You may complain to the local data protection authority if unresolved.