LittleWorld Privacy Policy
This Privacy Policy describes how LittleWorld (“we”, “us”, “our”) handles information when you use the LittleWorld Android app and related backend services. We do not sell your personal information.
1. Information we collect
Account and authentication
LittleWorld uses Firebase Authentication (Google Firebase project littleworld-cbdf6). Depending on the sign-in methods enabled in the app, you may authenticate with:
- Email and password
- Google Sign-In
Phone, Facebook, and Apple sign-in are not currently enabled for LittleWorld.
When you sign in, Firebase provides a unique user identifier (Firebase UID). We use this UID to associate your account with data stored on our servers.
Profile information stored on our servers
When you create or use a LittleWorld account, our backend may store:
- Firebase UID
- Display name
- Email address (from Firebase or your sign-in provider)
- Profile photo URL (for example, a Google avatar URL or an uploaded image path)
- An optional public ID shown in the app
- Account creation date
- In-app currency balance (coins)
- VIP membership status and expiry, if applicable
We do not accept client-supplied values for sensitive economy fields such as coin balance or VIP status.
Viewing activity and library data
To provide streaming and personalization features, our servers store:
- Favorites — series you save to your list
- Watch history — series, episode, playback progress, and timestamps
- Likes — series you like
- Unlocked episodes — premium episodes unlocked with coins or rewarded ads
- Ad watch counts — daily counts used to enforce ad-unlock limits
The Android app may also keep local copies of favorites, history, or playback state on your device for offline or faster access. Local app data is subject to your device settings and is not separately described here beyond what the app syncs to our servers.
Purchases and in-app economy
LittleWorld supports an in-app coin economy. Coin pack and VIP purchases through Google Play may be enabled or disabled by server configuration. When purchases are enabled and you buy through Google Play, we process:
- Google Play purchase tokens and related order identifiers
- Product identifiers mapped to server-defined coin packs or VIP duration
- Purchase state and acknowledgement status from Google Play
- Transaction records linked to your Firebase UID
Payment processing is handled by Google Play. We do not receive your full payment card details.
Advertising
LittleWorld uses Google AdMob to show ads, including banner, interstitial, and rewarded placements. AdMob and its partners may collect device and usage information according to Google’s policies. On Android, the app may use Google’s User Messaging Platform (UMP) to request advertising consent where required.
For rewarded ads that unlock premium episodes or grant coins, Google sends server-side verification (SSV) callbacks to our backend. These callbacks may include ad transaction identifiers and your Firebase UID when the app provides it through AdMob’s official SSV fields. We use verified callbacks to grant rewards and prevent fraud.
Support communications
If you contact us by email, we receive the information you choose to send (such as your email address, account details, and message content) so we can respond.
Technical and security data
Our servers process standard request metadata needed to operate the service securely, such as IP addresses, request timestamps, and authentication tokens. We use rate limiting and security controls on sensitive API routes.
We do not operate a separate analytics tracking endpoint for user behavior; our legacy tracking endpoint is disabled.
2. How we use information
We use the information above to:
- Create and manage your account
- Authenticate you and protect access to your data
- Stream video content through time-limited secure playback grants
- Sync favorites, history, likes, and unlock status
- Operate the coin economy, rewarded ads, and purchases when enabled
- Respond to support requests
- Maintain security, prevent abuse, and enforce our Terms of Service
- Comply with applicable legal obligations
3. How we share information
We do not sell your personal information. We share information only with service providers that help us operate LittleWorld, including:
- Google Firebase — authentication
- Google AdMob — advertising and rewarded ad verification
- Google Play — in-app purchases and billing verification when enabled
- Cloudflare R2 — private storage and delivery of premium video media processed by our servers
- Hosting infrastructure — our backend API and database on secured servers
These providers process data under their own terms and privacy policies. We may also disclose information if required by law or to protect rights, safety, and security.
4. Video streaming and media
Premium video is not served as permanently public URLs. When you are entitled to watch an episode, our servers issue short-lived playback grants. Video files may be stored on private object storage (Cloudflare R2) or legacy local storage managed by our backend.
5. Data retention
We retain account and usage data for as long as your account is active or as needed to provide the service, resolve disputes, enforce agreements, and comply with legal obligations. Ad verification events and purchase records may be retained for fraud prevention and audit purposes.
6. Account deletion
You can delete your LittleWorld account from within the Android app (where available) or by contacting support. Account deletion requires a valid Firebase ID token for your account.
When deletion is confirmed, our backend permanently removes your profile and associated data, including favorites, watch history, likes, unlocked episodes, reward claims, coin transactions, ad watch records, and purchase records linked to your account. Locally stored profile images uploaded to our servers may be deleted when applicable. Third-party sign-in profile photos hosted by Google or other providers are not deleted from those providers by this action.
Some information may remain in backups for a limited period or where retention is required by law.
7. Security
We use technical and organizational measures appropriate to the service, including authenticated API access, server-side validation of economy actions, encrypted transport (HTTPS), and private media access controls. No method of transmission or storage is completely secure.
8. International processing
LittleWorld uses service providers that may process data in countries other than your own, including the United States and other regions where Google and Cloudflare operate infrastructure.
9. Children’s privacy
LittleWorld is intended for general audiences. We do not knowingly collect personal information from children in a manner that requires parental consent beyond what your app store settings and sign-in choices provide. If you believe a child has provided personal information improperly, contact us through our Support page.
10. Your choices
- You may update certain profile fields through the app where supported.
- You may manage advertising consent through Android and AdMob/UMP controls where available.
- You may delete your account as described above.
- You may contact us with privacy questions at littleworld2026007@gmail.com.
11. Changes to this policy
We may update this Privacy Policy from time to time. The effective date at the top will change when we do. Continued use of LittleWorld after an update means you accept the revised policy.
12. Contact
For privacy-related questions, contact LittleWorld at littleworld2026007@gmail.com.