We take privacy as seriously as you do. This policy explains how and why we collect, use, share, and protect your personal information, and how you can check and control the information we hold about you. By using the Little Lock Book app or website, you acknowledge this policy. Questions? Email us at support@littlelockbook.com.
Who we are
In this policy, "we", "us", and "our" mean Little Lock Book Pty Ltd (ACN 698 519 943) ("Little Lock Book"), Sydney, Australia. Little Lock Book is the controller for the personal information you provide when using the app. You can reach us at support@littlelockbook.com.
Whenever we collect and handle personal information, we are bound by the Australian Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs).
Information we collect
We only collect information that is reasonably necessary to provide the app and the services described in this policy.
Information you provide
Required to use the app:
- Email address and phone number.
- First name and last name.
- Country and suburb.
- Date of birth (month and year only). We use this to verify the minimum-age requirement and for age-appropriate category access.
Optional — you choose whether to provide these:
- Cards you create, including place names, your notes, optional locations, and optional photos.
- Audience settings for each card and any groups you create.
- Vouches, asks, replies, and other interactions you initiate.
- Notification settings and other in-app preferences.
- Gender, if you turn on the practitioner filter.
- Reports you submit about content or members (what you reported and the reason you selected), and your block list.
- Any messages you send to support.
Information collected automatically
- Limited technical details from our server logs, such as IP address and timestamps, together with server-side request logs (the requests made and any errors).
- Crash reports and diagnostics. If the app crashes or encounters an error, we collect a crash report so we can find and fix the problem. Crash reports include technical details such as your device model, operating system version, app version, the error and its technical trace, and a short trail of recent in-app technical events leading up to the error. Crash reports are not used for advertising or tracking.
- Product analytics events. We record how the app is used, but only in a way that is not linked to your account or you personally. We use this information to help us improve the app and design new features, and it informs our "insights" (see below).
- Security audit records relating to account events such as deletions and administrative actions.
- Push notification token, if you grant push notification permission. Used only to send notifications to your device.
- Minimal local storage on your device to keep you signed in and remember your preferences. We do not use third-party advertising cookies or cross-site tracking.
Information from third parties
- Place details and place photos from Google Places when you select a place from autocomplete.
- Email delivery status from Resend (whether transactional emails were delivered).
- SMS delivery status from Twilio, if and when sign-in by SMS is available (whether sign-in codes were delivered).
How we use information
We use the information we collect for the following purposes.
Providing the app
- To create and manage your account.
- To deliver shares to people you choose and route notifications to your circle.
- To send transactional and operational emails (and, when available, SMS), including sign-in codes and invite messages.
- To provide, operate, and improve the app and its features.
- To monitor the app's stability and to diagnose and fix crashes, errors, and performance problems.
- To analyse how the app is used (see "Product analytics events" above) so we can improve product quality, fix problems, and make recommendations more relevant.
- We store your phone number (in a one-way "hash" so that we cannot actually read your phone number) in our contacts database so that we can see if other members are connected to you. See the "Find Friends" description below.
- To display commercial links on cards that connect you to third-party booking, reservation, or retail services. We may receive a referral commission when you use these links.
Use of Device Contacts
- Inviting people. When you tap "Pick from contacts" to invite people to your circle or send an Ask, we request your permission to read your local contact list. Contacts appear only in the picker on your device. If you select a contact, we collect only the name, email address, or phone number you choose to use for that invite or Ask.
- Find Friends. This feature lets you see which of your contacts are already on Little Lock Book. We do this by matching your contacts' email addresses and phone numbers with our members. The matching is done using a one-way "hash" function; which means that we convert your contacts into a string of random text, and then see if that random text matches the hashed contact details of our members. Because we perform the hash of your contacts on your own device, the matching process never sends us your contacts' readable email addresses or phone numbers — only the scrambled hashes leave your device. (If you separately choose to send someone an invite, we do receive that one recipient's details so we can deliver the invitation, as described under "Inviting people" above.) Find Friends only ever reveals people whose details you already hold; it does not expose strangers. You can stop being found by other people's contact matches at any time in Profile → Privacy preferences.
Safety, security, and compliance
- To screen text you submit — such as card notes, asks, replies, and invite messages — using automated content-safety tools before it is shared, and we may review your content manually to respond to reports submitted by members about content or behaviour or we suspect you are acting in breach of our Terms.
- To operate block lists so members you block no longer see or surface your content (and vice versa).
- To detect, prevent, and respond to security events, fraud, and abuse.
- To comply with legal obligations, respond to lawful requests, and enforce our terms.
- To carry out business operations including audits, finance, accounting, and corporate transactions such as a merger, acquisition, or restructure.
Other
- To produce aggregated statistics and trend information about how the app is used and what is recommended. See "Aggregated and de-identified data" below.
- If we sell the business we may transfer your details as part of the sale of our business.
- We may give personal information to law enforcement, regulators, or courts, in all cases as required, authorised, or permitted by law.
Commercial activities — your controls
This section describes commercial uses that go beyond operating the app.
The following are off by default — you opt in by giving us consent or through Profile → Privacy preferences and can withdraw at any time:
- Marketing communications about Little Lock Book and related products.
Where we rely on your consent for any of the above, you can withdraw it at any time through Profile → Privacy preferences or by emailing support@littlelockbook.com. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
The following are on by default. You can opt out at any time through Profile → Privacy preferences. Our lawful basis for each is legitimate interests.
- Third-party commercial partnerships and sponsorships.
- Aggregated insights — your de-identified usage data may be included in statistics shared with selected partners.
- Findable by contacts — your profile may appear when another user matches their contacts against our members.
Aggregated and de-identified data
We use aggregated data (counts and statistics about groups of users) and de-identified data (records with direct identifiers removed) to improve the app, develop new features, analyse trends, and produce insights.
When we de-identify data, we apply technical safeguards (removal of direct identifiers, suppression of unique records, minimum group sizes for any output) and operational safeguards (manual review before any external publication), so that re-identification is not reasonably practicable. Aggregated and de-identified outputs are not personal data under most privacy laws.
We may share de-identified and/or aggregated data with carefully selected external partners. Basically, we want to be able to tell our partners that "this many people are interested in Thai food on a Friday night in the Sydney area". Where outputs derived from your data are intended for external publication or partnership use, the "insights" control in Profile → Privacy preferences governs your inclusion.
Sensitive information
Health and medical cards
Cards in the Health & Medical category are treated as sensitive personal information. Cards about individual practitioners are stored privately to you and are not shared.
By marking a card as Health & Medical and saving it, you consent to Little Lock Book storing this information under this policy. Our lawful basis for processing this sensitive information is your explicit consent.
You can withdraw your consent at any time by deleting the relevant card or your account. Deleting a Health & Medical card removes it immediately; account deletion removes all data within 30 days.
Gender data
If you enable the practitioner filter, we collect an optional gender preference to help personalise search results. In giving us your gender you consent to us processing it.
You can withdraw consent and delete this data at any time in your Profile settings. If you do not enable the practitioner filter, we do not collect gender data.
Service providers (sub-processors)
We use the following service providers to operate the app. Each provider is bound by a data processing agreement or equivalent contractual terms that require them to handle your data consistently with this policy and applicable law.
- Google / Firebase — authentication, database, file storage, Cloud Functions, and push notification delivery (Firebase Cloud Messaging routes through Apple Push Notification Service on iOS). Data stored in the Sydney region (australia-southeast1). Google's standard data processing terms apply.
- Resend — transactional email delivery.
- OpenAI — automated content-safety screening. Text you submit (such as card notes, asks, replies, and invite messages) is checked against OpenAI's moderation service before it is shared, to detect content that breaches our terms. This text is processed in the United States and is used only for safety screening — it is not used to train OpenAI's models.
- Sentry — crash and error reporting. Crash reports (described under "Information collected automatically" above) are processed and stored in Sentry's European Union region. We configure Sentry so that reports are not linked to your identity.
- Twilio — SMS delivery of sign-in codes, if and when sign-in by SMS is available. Your phone number is processed only to deliver the code.
- Google Places — place autocomplete, place details, and place photos.
- Netlify — hosting of our website and invite landing pages.
- Apple and Google — app distribution and any future App Store / Play Store billing.
We will update this list before any new service provider that handles your personal data begins processing. Where the change introduces a new category of data, we will notify you in the app at least 14 days before the change takes effect, so you have time to object or delete your account.
Where your data is stored
Your personal data is stored on Firebase (Google Cloud) in the Sydney region. Email and SMS delivery, content-safety screening, crash reporting, and some operational services may transit outside Australia, including to providers in the United States and the European Union (crash reports are processed in Sentry's EU region). Depending on where you are located, this may mean that your personal information is transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.
We will take steps reasonably necessary to ensure that your personal information is treated securely and in accordance with this Privacy Policy, and no transfer of your personal information will take place to an organisation or a country unless there are adequate controls in place including the security of your data and personal information.
Who can see what you share
The visibility of each card you create is determined by the audience option you choose: Only me, On request, Specific people or groups, or Whole circle.
Members of your circle do not see the tier you have privately placed them in, and do not see the full list of who else is in your circle.
Saved copies. If someone you've shared a card with saves it to their own Lock Book, they keep their own copy. Their copy remains in their Lock Book even if you later delete the original or stop sharing it.
Share links. If you share a card by link outside the app, anyone who receives the link can see a limited preview of that card.
Discoverability. Each card can be set to reach beyond your circle. If you allow this, it may surface to people one or two hops out. Extended Friends see your first name and your note; the Network tier sees your note without your name. No profile photo is shown. You set this per card through its audience setting. 'Name displayed to extended friends' in Profile → Privacy preferences removes your name; your note is always shown. To see how many cards reach these tiers, go to Profile → Who can see what; to see which, filter the All category by trust level.
Your rights
Subject to your local law, you may have the following rights in relation to your personal information. We may ask to verify your identity.
- Access — request a copy of the personal data we hold about you. You can also export your data directly from the app.
- Correction — correct inaccurate personal data. Most fields can be corrected directly in the app.
- Deletion — delete your account and the personal data associated with it.
- Restriction — ask us to pause processing your data while we address a concern, without requiring you to delete it entirely. For example, if you contest the accuracy of data we hold, you can ask us to restrict processing while we verify it.
- Objection — object to processing carried out on the basis of our legitimate interests, including product analytics.
- Withdrawal of consent — withdraw consent at any time for any processing we carry out on the basis of consent.
- Portability — receive your personal data in a structured, machine-readable format.
- Complaint — lodge a complaint with your local data protection authority.
To exercise any right, email support@littlelockbook.com from the address associated with your account. We will respond within 30 days, or sooner where required by your local law.
Supervisory authorities: In Australia: Office of the Australian Information Commissioner (oaic.gov.au). In the United Kingdom: Information Commissioner's Office (ico.org.uk). In the EU: your national data protection authority.
How long we keep your personal data
We keep personal data while your account is active. When you delete your account, we delete personal data within 30 days, including from backups, subject to limited retention required by law or for the establishment, exercise, or defence of legal claims.
We may retain sufficient information to ensure that blocked or suspended users cannot subscribe for another account.
Security
We use industry-standard safeguards to protect personal data, including encryption in transit and at rest, database-level access controls, rate limiting, and re-authentication for irreversible actions such as account deletion.
No system is perfectly secure. If you believe you have found a security issue, email support@littlelockbook.com with the subject line "Security".
If there is a data breach
A data breach is a security event that compromises the confidentiality, integrity, or availability of personal data. We may have to notify regulators when we have reasonable grounds to believe an eligible data breach has occurred.
If a security event puts your personal data at risk, we will:
- Notify the relevant supervisory authority where required by law.
- Notify affected users without undue delay, with a clear description of what happened, what data was affected, and what steps you can take.
- Provide an updated incident notice on this page or in the app if the event is material.
Age requirement
Little Lock Book is for people aged 16 and over. We base your age on the date of birth (month and year) you provide at sign-up, and we do not knowingly collect personal data from anyone under 16. We may suspend accounts we reasonably believe belong to someone under 16. We may ask you to prove that you are over 16 if we reasonably believe you have lied about your age.
If you believe we have collected information from someone under 16, contact us at support@littlelockbook.com and we will delete the account and all associated data within 7 days.
Compliance statement
UK and EU (GDPR)
Additional information for our UK and EU based users.
Controller: Little Lock Book Pty Ltd (ACN 698 519 943).
Lawful bases: We process personal data on one or more of the following bases, depending on the specific activity.
- Performance of a contract — creating and managing your account, delivering shares and notifications.
- Consent — optional features, Health & Medical cards and Gender data.
- Legitimate interests — product improvement, first-party product analytics, crash reporting and diagnostics, automated content-safety screening, security, displaying third party links to you within the app, use of your aggregated data in external insight or commercial programmes and fraud prevention. You have the right to object to any processing on this basis.
Data minimisation: We collect only the personal data that is adequate, relevant, and limited to what is necessary for the purposes described in this policy.
Cross-border transfers: Personal data is stored in Australia and you have voluntarily transferred that data to us. Where data is transferred to providers in the United States or other jurisdictions, we rely on the international transfer regimes of our suppliers.
Automated decision-making: We do not use solely automated decision-making that produces legal or similarly significant effects on you. Our recommendation features sort and present cards from your circle and network, and we use automated content-safety screening. You can contact us at support@littlelockbook.com if you believe content was blocked in error, and a person will review it.
California (CCPA / CPRA)
Categories of personal information collected: Identifiers; geolocation at suburb-to-country level (suburb, city or region, state, postcode, country, and the latitude and longitude of any place you save); internet or other electronic network activity information (the first-party product analytics events described above, recorded against a random analytics identifier, and crash and diagnostic data not linked to your identity); and sensitive personal information you choose to provide (such as gender preference or Health & Medical card information).
Purposes: As described in "How we use information" above.
Sale or sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioural advertising. These are distinct categories under the CPRA and we confirm neither applies. If we begin to do either, we will notify you in the app at least 14 days before the change takes effect, provide a "Do Not Sell or Share My Personal Information" option in the app, and honour any opt-out you have set.
Do Not Track: Our app does not respond to browser-based Do Not Track signals because we do not perform the cross-site tracking they are designed to limit.
Your CCPA / CPRA rights: Right to know, delete, correct, limit use of sensitive personal information, opt out of any sale or sharing, opt out of automated decision-making, and non-discrimination.
Automated decision-making. Under the CPRA, you have the right to opt out of automated decision-making, including profiling, that produces legal or significant effects. Our recommendation features present cards from your network but do not produce decisions with legal or similarly significant effects on you. If you have questions about how recommendations work or wish to limit personalisation, contact us at support@littlelockbook.com.
Changes to this policy
We may update this policy from time to time. Where the change is material, we will notify you in the app before it takes effect. The effective date at the top of this policy shows when the current version was published.
Contact
For any privacy enquiries, email support@littlelockbook.com.