Skip to content
LittleStone— home
LittleStone

Privacy policy

What we collect, why, how long we keep it, and what you can ask us to do about it. This notice covers three separate groups: people who visit this website, people who will use our applications once they are released, and people who apply for a job.

Effective
Last updated
Version
2.0.0

Who we are Link to this section: Who we are

This website, and the software we publish, are operated by a Limited Liability Company (LLC) registered in Delaware, with a registered office at 131 Continental Dr, Suite 305 Newark (New Castle) 19713 Delaware. Under the GDPR we are the controller of the personal data described here — meaning we decide why it is collected and what happens to it.

We build and publish our own software. We are not an agency and we do not take briefs, so nothing here describes work done on behalf of a client. When our applications are released, the seller name shown on the App Store and Google Play will be LittleStone, LLC — the same company as the one named above.

For anything in this notice, write to contact@littlestone.world. For help with an application once one exists, write to contact@littlestone.world.

We have not appointed a Data Protection Officer. We are a handful of people, and we are not of a size or type that requires one under Article 37. Appointing one we did not need would misrepresent how this company is run.

What this notice covers Link to this section: What this notice covers

This notice covers three groups of people, and they are kept apart on purpose, because what we hold about each of them is different.

  • Visitors to this website — the contact form and what a web server necessarily records to serve a page.
  • People who use our applications, once an application has been released. That includes anything an application sends to a model, and anything a purchase leaves behind.
  • People who apply for a job. That is the applicants section near the end.

Two relationships sit outside this notice:

  • Where a business customer uses our software to handle personal data about their own staff or their own customers, we act as a processor on their instructions. Their privacy notice governs that data, and our agreement with them — including any data processing addendum — says what we may do with it.
  • Employment and contractor relationships are covered by separate notices given directly to the people concerned.

What we collect Link to this section: What we collect

Three sources: what you deliberately give us, what a web server necessarily records, and — once an application is released — what that application needs in order to do its job.

Data you give us Link to this section: Data you give us

  • Contact form: your name, your email address, your organisation if you supply one, what the enquiry is about, any optional context the form asks for, and the message itself.
  • Email: whatever you choose to put in it, plus the routing information every email carries.
  • Job applications: the materials you send us. See the applicants section.

Please do not send us special category data — health, political opinions, religious beliefs, biometric or genetic data, trade union membership, or data about sex life or sexual orientation — through the contact form. We have no need for it and no lawful basis to hold it.

Data collected automatically Link to this section: Data collected automatically

  • Server logs kept by our hosting provider: the requested URL, the time, the response status, the referring page and the user agent string.
  • A hashed form of your IP address, used to rate-limit the contact form. The raw address is hashed with a secret salt before it is stored, and the unhashed value is never written to our own storage. This is enforced in code, not just promised here — see how we build.

Cookies and similar technologies are covered in the separate cookie policy.

What our applications will collect Link to this section: What our applications will collect

This describes the shape of it. When each application is released, its own store listing carries the data-collection disclosure Apple and Google require, and it has to match what is written here.

  • Content you put into the application — what you type, import, or create. Some of it never leaves your device. Where a feature sends it somewhere, the AI section below says exactly where.
  • Account data, but only where an application has accounts at all. Some will not. Where there is an account, that means an email address or a sign-in identifier, and the settings tied to it.
  • Diagnostics: the device model, the operating system version, the version of our application, and the state it was in when something failed. Crash reports are about the failure, not about you.
  • Purchase records, where an application charges for anything. See payments below.

We do not want your contacts, your photo library, your precise location, your health data, or your microphone unless a specific feature genuinely needs one of them. Where a feature does need one, the operating system asks you first, the request explains what it is for, and saying no leaves the rest of the application working.

Some of our applications are planned to be free with no payments and no accounts at all. Where that is true of the one you are using, most of this section simply does not apply to you.

Payments and purchases Link to this section: Payments and purchases

Where an application offers a subscription or an in-app purchase, the payment goes through the store, not through us. Apple and Google collect and hold your payment details under their own privacy policies. We never see your card number, and we could not retrieve it if you asked.

What reaches us is a record that a purchase happened, what it entitles you to, and whether a subscription is still active. Business customers who license our software under a contract are invoiced directly, and for them we hold the contact and billing details that any invoice requires.

Store-level analytics Link to this section: Store-level analytics

How AI features handle your data Link to this section: How AI features handle your data

An application that sends what you type to a model on a machine somewhere else is doing something materially different from one that runs a model on your phone. That difference is the most consequential thing we can tell you, so it gets a table of its own rather than a clause buried in a list.

Our applications will use both. Which mode applies is decided feature by feature, on what the feature has to do — not by a single company-wide policy. Nothing has been released, so the table below describes the two modes rather than named features. When an application ships, this table gains one row per feature that uses a model, and each row says which mode that feature is in.

How each mode of AI processing handles your data
FeatureWhere the model runsWhat leaves the deviceRetention
A feature the application marks as running on your deviceOn your device. The model ships inside the application.Nothing. No network request is made in order to run the model, and nothing is sent to us.None by us, because we never receive it. What you put in and what comes out stay on the device and go when you delete the application.
A feature the application marks as using a hosted modelA hosted API operated by [MODEL_PROVIDER] — this detail has not been filled in yet, processing in [MODEL_PROVIDER_REGION] — this detail has not been filled in yet.The input you give that feature, and the context that feature needs to answer. Not your contacts, not your photo library, not your location, and no account identifier unless the feature cannot work without one.We hold the input only for as long as the request takes. The provider holds it for [MODEL_INPUT_RETENTION] — this detail has not been filled in yet. Whether that provider may use it to train its own models is recorded as: [MODEL_TRAINING_POSITION] — this detail has not been filled in yet.

You are told which mode a feature uses, in the application Link to this section: You are told which mode a feature uses, in the application

A privacy policy nobody reads is not consent. So the disclosure lives where the decision is made: the application tells you, in the interface, whether a feature runs on your device or sends your input to a hosted model — and it tells you before you use it, not afterwards in a settings screen you had no reason to open.

Where a feature is optional rather than part of what the application is for, it is off until you switch it on, and switching it off again stops any further processing. Where a feature is the application — where turning it off would leave nothing behind — we say so plainly rather than offering a toggle that does not really exist.

What is done with what you type Link to this section: What is done with what you type

We do not train models on your input. We have no model of our own being trained, and if that ever changes it will be a separate, opt-in decision announced before it happens, not a quiet edit to this page.

The hosted provider's position is a different question, and it is theirs rather than ours. Our part is to get it in writing and publish it: [MODEL_TRAINING_POSITION] — this detail has not been filled in yet. Where the answer is not acceptable, the answer is to change provider, not to soften the sentence.

Please do not put special category data into a hosted feature. Health details, political or religious views, biometric data, or anything about sex life or sexual orientation should stay on your device. Where a feature is designed for that kind of material, it runs on the device, and it says so.

Why we use it, and for how long Link to this section: Why we use it, and for how long

Under the GDPR every use of personal data needs a lawful basis. This table sets out ours, alongside how long each kind of data is kept. Rows that concern applications describe processing that will begin when an application is released.

Purposes, lawful bases and retention periods
PurposeDataLawful basis (Art. 6)Retention
Providing an application you have installedAccount data where the application has accounts, your settings, the content the application works on6(1)(b) — performance of the contract you enter into by using itUntil you delete your account or the application. On-device content goes when the application does.
Payments, subscriptions and in-app purchasesThe purchase record and subscription status the store passes to us6(1)(b) — performance of that same contractWhile the entitlement lasts, then as long as tax and accounting law requires the record to be kept
Running a feature that uses a model on your deviceWhatever you give that feature6(1)(b) — the feature is part of the product you asked forNever held by us. It does not leave your device.
Running a feature that uses a hosted modelThe input you give that feature, and the context it needs6(1)(b) — the feature is part of the product you asked forHeld by us for the length of the request. The provider period is in the AI table above.
Running an optional feature that you switched on yourselfThe input you give that feature6(1)(a) — your consent, withdrawable in the application at any timeAs above. Withdrawing stops any further processing.
Crash reports and error diagnosticsDevice model, operating system version, application version, the state it was in when it failed6(1)(f) — legitimate interests in finding out what is broken and fixing itNinety days, then deleted
Keeping the site and our applications secureServer logs, hashed IP address, rate-limit records6(1)(f) — legitimate interests in a service that stays up and is not abusedThirty days for rate-limit records. Server logs as retained by our hosting provider.
Answering an enquiry you send usContact form fields, email content6(1)(b) — steps taken at your request before entering a contractTwo years from our last exchange, then deleted
Supplying and supporting software under a business contractBusiness contact details, licence records, support correspondence6(1)(b) — performance of that contractFor the term of the contract, then as long as the law requires
Remembering your cookie choicesThe consent record itself6(1)(f) — legitimate interests in honouring the choice you madeSix months, then we ask again
Any non-essential cookiesAs described in the cookie policy6(1)(a) — your consentUntil you withdraw consent
Meeting a legal obligationWhatever the obligation covers6(1)(c) — legal obligationAs long as the obligation requires

Our legitimate interests, and the balance we struck Link to this section: Our legitimate interests, and the balance we struck

Where we rely on legitimate interests we are required to weigh our interest against your rights, and to be able to explain the result. There are three of them and the reasoning is short.

Security and abuse prevention: the interest is keeping a public website and a set of applications working, and being able to investigate an outage or an attack. The data is minimal, IP addresses are hashed rather than stored, and none of it builds a profile.

Crash and error diagnostics: the interest is fixing software that failed on your device. A crash report describes the failure — where the code stopped, on what device, on what version — and we take the narrowest report that will let us reproduce the problem. It is not used to work out who you are or what you were writing.

In every case the data is not combined with anything else, is never sold, and is never shared for advertising. Someone using a piece of software would reasonably expect it to do this much. On that basis we consider the interest is not overridden — but you can object, and the objection route is below.

Who else sees it Link to this section: Who else sees it

We do not sell personal data. We do not share it for advertising. We do not disclose it for the independent purposes of anyone else, with the one exception set out at the end of this section.

Personal data is handled on our behalf by the service providers listed on the sub-processors page, each under a written contract that limits them to acting on our instructions. That page names every provider, what it does, where it processes data, and the transfer mechanism relied on. Once an application ships, the hosted model provider named in the AI table is on that page too.

The app stores are a different relationship and it is worth being exact about it. When you install an application or buy something inside one, Apple or Google is not acting on our instructions — each is its own controller for that transaction, under its own privacy policy, and we have no say in what it collects. What we receive back is the purchase record described above.

We may also disclose data where the law requires it — a valid court order, for instance. Where we are legally permitted to tell you that has happened, we will.

International transfers Link to this section: International transfers

We are established in the United States, so personal data reaching us leaves the European Economic Area and the United Kingdom. A hosted model call does the same thing, at the moment you use the feature.

A transfer out of the EEA needs a specific legal mechanism, and the mechanism belongs to the recipient rather than applying in general. For each provider we rely on one of the following, and the sub-processors page records which applies to which:

  • The EU–US Data Privacy Framework, where that recipient is certified under it and the transfer falls inside the scope of its certification. Certification is checked on the official list, not taken from a marketing page.
  • The Standard Contractual Clauses adopted by the European Commission in Decision 2021/914, supplemented by a documented transfer impact assessment and, where that assessment calls for them, additional technical measures.
  • For the United Kingdom, the UK International Data Transfer Addendum to those clauses.

The hosted model provider, [MODEL_PROVIDER] — this detail has not been filled in yet, processes in [MODEL_PROVIDER_REGION] — this detail has not been filled in yet. Where that region is outside the EEA, one of the mechanisms above covers it and the sub-processors page says which. Where a feature runs on your device instead, there is no transfer at all, because nothing leaves the device.

You can ask us for a copy of the relevant clauses. We will send them with any commercially confidential terms redacted.

Your rights Link to this section: Your rights

If the GDPR or UK GDPR applies to you, you have the following rights. They are not absolute — each has conditions and exceptions in the legislation — but we will always tell you which one we are relying on if we cannot do what you asked.

  • Access — a copy of the personal data we hold about you, and an explanation of what we do with it.
  • Rectification — correction of anything inaccurate, and completion of anything incomplete.
  • Erasure — deletion, where one of the Article 17 grounds applies.
  • Restriction — a pause on processing while something is disputed.
  • Portability — the data you gave us, in a structured, machine-readable form.
  • Objection — to any processing based on legitimate interests, including the diagnostics and abuse prevention described above.
  • Withdrawal of consent — at any time, and as easily as it was given. Withdrawal does not undo processing that was lawful before you withdrew.

To exercise any of these, write to contact@littlestone.world. We will respond within one month. If a request is genuinely complex we may extend that by up to two further months, and we will tell you within the first month if that happens, and why.

Where an application has accounts, deleting your account from inside it is a route to erasure that does not require you to email anyone, and it is the route we would rather you had. Where a feature runs on your device, we hold nothing: there is nothing for us to send you and nothing for us to delete, and removing the application removes the data with it.

We may need to verify who you are before acting — not as an obstacle, but because handing one person's data to another is itself a breach. We will ask for the least that will do.

If you are in the United States Link to this section: If you are in the United States

Several US states give their residents rights over personal information. Where one of those laws applies to you, you may request access to the personal information we hold, request its deletion or correction, and appeal a decision you disagree with. We will not discriminate against you for exercising any of them — no worse price, no degraded version of the software.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the California Consumer Privacy Act. We honour the Global Privacy Control (opens in a new tab) signal as an opt-out where your browser sends one.

If you apply for a job Link to this section: If you apply for a job

When you apply, we process the materials you send — your CV or equivalent, your covering message, and anything produced during the process such as interview notes or a take-home exercise.

The lawful basis is Article 6(1)(b), steps taken at your request before entering a contract, and for our own record-keeping about the process, Article 6(1)(f) legitimate interests.

  • If we do not make you an offer we keep your application for twelve months, so we can contact you if something suitable opens up. Tell us and we will delete it sooner.
  • If we do make you an offer and you accept, your application becomes part of your employment record and a separate notice applies.
  • We do not use automated decision-making or profiling to screen applications, and we do not put your application through a model. A person reads every one.

Questions about an application: careers@littlestone.world. The open roles are on the careers page.

Automated decision-making Link to this section: Automated decision-making

Our AI features produce output: a suggestion, a summary, a draft, an edit. Producing output is not the same as making a decision about a person, and the distinction matters legally as well as in plain language.

We do not make decisions about you by automated means alone that produce legal effects concerning you, or that similarly significantly affect you, within the meaning of Article 22. Nothing we build decides whether you get credit, a job, an insurance price, a benefit, a tenancy, or access to a service. What a feature returns is material for you to accept, edit or throw away.

We do not profile you for advertising, and we do not score or rank visitors to this website. If any of this changes, this section changes before the feature ships, and we will tell you rather than let you discover it.

Children Link to this section: Children

Our applications are for a general audience. They are not directed at children, they are not designed to appeal to children, and each one carries an age rating on the App Store and on Google Play that reflects that. Where a store requires an age declaration at submission, ours is set to a general-audience rating rather than a children category.

We do not knowingly collect personal data from anyone under 16. In the United States, where the statutory threshold for children's online privacy is lower, we do not knowingly collect from anyone under 13. If you believe a child has given us personal data, tell us and we will delete it and the account it sits in.

How we protect it Link to this section: How we protect it

Transport is encrypted, on the website and in every request an application makes. Access to enquiry data is limited to the people who need it. IP addresses are hashed before storage. Data an application keeps on your device sits in the storage the operating system protects, behind your device lock. Our approach to security, and how to report a vulnerability, is set out on the security page.

No system is perfectly secure, and saying otherwise would be a marketing claim rather than a fact. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and we will notify you directly where the risk is high.

Complaints Link to this section: Complaints

If you think we have handled your data badly, tell us first at contact@littlestone.world — most things are a misunderstanding and can be fixed quickly.

You also have the right to complain to a supervisory authority without coming to us first. In the EEA that is the authority in the country where you live, where you work, or where you think the problem happened. In the UK it is the Information Commissioner's Office.

Changes to this notice Link to this section: Changes to this notice

When this notice changes, the "last updated" date at the top changes with it, and the version number increases. Content cannot change without that date moving — it is checked automatically before the site can be built.

Some changes are more than an edit. If we change where a feature runs its model, what it sends, or how long any of it is kept, we will say so in the application itself as well as here, and before the change takes effect rather than after. If a change materially affects data you have already given us, we will contact you directly where we have a way to.