We take privacy as seriously as you do. This policy explains how and why we collect, use, share, and protect your personal information, and how you can check and control the information we hold about you. By using the Little Lock Book app or website, you acknowledge this policy. Questions? Email us at support@littlelockbook.com.

Who we are

In this policy, "we", "us", and "our" mean Little Lock Book Pty Ltd (ACN 698 519 943) ("Little Lock Book"), Sydney, Australia. Little Lock Book is the controller for the personal information you provide when using the app. You can reach us at support@littlelockbook.com.

Whenever we collect and handle personal information, we are bound by the Australian Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs).

Information we collect

We only collect information that is reasonably necessary to provide the app and the services described in this policy.

Information you provide

Required to use the app:

Optional — you choose whether to provide these:

Information collected automatically

Information from third parties

How we use information

We use the information we collect for the following purposes.

Providing the app

Use of Device Contacts

Safety, security, and compliance

Other

Commercial activities — your controls

This section describes commercial uses that go beyond operating the app.

The following are off by default — you opt in by giving us consent or through Profile → Privacy preferences and can withdraw at any time:

Where we rely on your consent for any of the above, you can withdraw it at any time through Profile → Privacy preferences or by emailing support@littlelockbook.com. Withdrawing consent does not affect the lawfulness of processing before withdrawal.

The following are on by default. You can opt out at any time through Profile → Privacy preferences. Our lawful basis for each is legitimate interests.

Aggregated and de-identified data

We use aggregated data (counts and statistics about groups of users) and de-identified data (records with direct identifiers removed) to improve the app, develop new features, analyse trends, and produce insights.

When we de-identify data, we apply technical safeguards (removal of direct identifiers, suppression of unique records, minimum group sizes for any output) and operational safeguards (manual review before any external publication), so that re-identification is not reasonably practicable. Aggregated and de-identified outputs are not personal data under most privacy laws.

We may share de-identified and/or aggregated data with carefully selected external partners. Basically, we want to be able to tell our partners that "this many people are interested in Thai food on a Friday night in the Sydney area". Where outputs derived from your data are intended for external publication or partnership use, the "insights" control in Profile → Privacy preferences governs your inclusion.

Sensitive information

Health and medical cards

Cards in the Health & Medical category are treated as sensitive personal information. Cards about individual practitioners are stored privately to you and are not shared.

By marking a card as Health & Medical and saving it, you consent to Little Lock Book storing this information under this policy. Our lawful basis for processing this sensitive information is your explicit consent.

You can withdraw your consent at any time by deleting the relevant card or your account. Deleting a Health & Medical card removes it immediately; account deletion removes all data within 30 days.

Gender data

If you enable the practitioner filter, we collect an optional gender preference to help personalise search results. In giving us your gender you consent to us processing it.

You can withdraw consent and delete this data at any time in your Profile settings. If you do not enable the practitioner filter, we do not collect gender data.

Service providers (sub-processors)

We use the following service providers to operate the app. Each provider is bound by a data processing agreement or equivalent contractual terms that require them to handle your data consistently with this policy and applicable law.

We will update this list before any new service provider that handles your personal data begins processing. Where the change introduces a new category of data, we will notify you in the app at least 14 days before the change takes effect, so you have time to object or delete your account.

Where your data is stored

Your personal data is stored on Firebase (Google Cloud) in the Sydney region. Email and SMS delivery, content-safety screening, crash reporting, and some operational services may transit outside Australia, including to providers in the United States and the European Union (crash reports are processed in Sentry's EU region). Depending on where you are located, this may mean that your personal information is transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.

We will take steps reasonably necessary to ensure that your personal information is treated securely and in accordance with this Privacy Policy, and no transfer of your personal information will take place to an organisation or a country unless there are adequate controls in place including the security of your data and personal information.

Who can see what you share

The visibility of each card you create is determined by the audience option you choose: Only me, On request, Specific people or groups, or Whole circle.

Members of your circle do not see the tier you have privately placed them in, and do not see the full list of who else is in your circle.

Saved copies. If someone you've shared a card with saves it to their own Lock Book, they keep their own copy. Their copy remains in their Lock Book even if you later delete the original or stop sharing it.

Share links. If you share a card by link outside the app, anyone who receives the link can see a limited preview of that card.

Discoverability. Each card can be set to reach beyond your circle. If you allow this, it may surface to people one or two hops out. Extended Friends see your first name and your note; the Network tier sees your note without your name. No profile photo is shown. You set this per card through its audience setting. 'Name displayed to extended friends' in Profile → Privacy preferences removes your name; your note is always shown. To see how many cards reach these tiers, go to Profile → Who can see what; to see which, filter the All category by trust level.

Your rights

Subject to your local law, you may have the following rights in relation to your personal information. We may ask to verify your identity.

To exercise any right, email support@littlelockbook.com from the address associated with your account. We will respond within 30 days, or sooner where required by your local law.

Supervisory authorities: In Australia: Office of the Australian Information Commissioner (oaic.gov.au). In the United Kingdom: Information Commissioner's Office (ico.org.uk). In the EU: your national data protection authority.

How long we keep your personal data

We keep personal data while your account is active. When you delete your account, we delete personal data within 30 days, including from backups, subject to limited retention required by law or for the establishment, exercise, or defence of legal claims.

Account and profile data
While your account is active. Deleted within 30 days of account deletion, including from backups.

We may retain sufficient information to ensure that blocked or suspended users cannot subscribe for another account.

Cards, notes, and photos
While your account is active. Archived cards deleted after 30 days in archive.
Circle and sharing data
While your account is active. Deleted within 30 days of account deletion.
Sign-in (OTP) codes
10 minutes from issue.
Pending invite codes
90 days if unused.
Product analytics events
Up to 12 months from the date of the event. Aggregated daily summaries derived from them are retained indefinitely (they are not personal data).
Crash reports and diagnostics
Retained by our crash-reporting provider for up to 90 days, then deleted automatically.
Other interaction and usage logs
Up to 12 months from the date of the event.
Reports you submit, and reports about your content
Up to 24 months, so we can identify repeat behaviour and meet our safety obligations.
Block lists
While your account is active, or until you unblock the person.
Security audit records
Up to 24 months.
Opt-in / opt-out preferences
Retained for as long as needed to honour them.

Security

We use industry-standard safeguards to protect personal data, including encryption in transit and at rest, database-level access controls, rate limiting, and re-authentication for irreversible actions such as account deletion.

No system is perfectly secure. If you believe you have found a security issue, email support@littlelockbook.com with the subject line "Security".

If there is a data breach

A data breach is a security event that compromises the confidentiality, integrity, or availability of personal data. We may have to notify regulators when we have reasonable grounds to believe an eligible data breach has occurred.

If a security event puts your personal data at risk, we will:

Age requirement

Little Lock Book is for people aged 16 and over. We base your age on the date of birth (month and year) you provide at sign-up, and we do not knowingly collect personal data from anyone under 16. We may suspend accounts we reasonably believe belong to someone under 16. We may ask you to prove that you are over 16 if we reasonably believe you have lied about your age.

If you believe we have collected information from someone under 16, contact us at support@littlelockbook.com and we will delete the account and all associated data within 7 days.

Compliance statement

UK and EU (GDPR)

Additional information for our UK and EU based users.

Controller: Little Lock Book Pty Ltd (ACN 698 519 943).

Lawful bases: We process personal data on one or more of the following bases, depending on the specific activity.

Data minimisation: We collect only the personal data that is adequate, relevant, and limited to what is necessary for the purposes described in this policy.

Cross-border transfers: Personal data is stored in Australia and you have voluntarily transferred that data to us. Where data is transferred to providers in the United States or other jurisdictions, we rely on the international transfer regimes of our suppliers.

Automated decision-making: We do not use solely automated decision-making that produces legal or similarly significant effects on you. Our recommendation features sort and present cards from your circle and network, and we use automated content-safety screening. You can contact us at support@littlelockbook.com if you believe content was blocked in error, and a person will review it.

California (CCPA / CPRA)

Categories of personal information collected: Identifiers; geolocation at suburb-to-country level (suburb, city or region, state, postcode, country, and the latitude and longitude of any place you save); internet or other electronic network activity information (the first-party product analytics events described above, recorded against a random analytics identifier, and crash and diagnostic data not linked to your identity); and sensitive personal information you choose to provide (such as gender preference or Health & Medical card information).

Purposes: As described in "How we use information" above.

Sale or sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioural advertising. These are distinct categories under the CPRA and we confirm neither applies. If we begin to do either, we will notify you in the app at least 14 days before the change takes effect, provide a "Do Not Sell or Share My Personal Information" option in the app, and honour any opt-out you have set.

Do Not Track: Our app does not respond to browser-based Do Not Track signals because we do not perform the cross-site tracking they are designed to limit.

Your CCPA / CPRA rights: Right to know, delete, correct, limit use of sensitive personal information, opt out of any sale or sharing, opt out of automated decision-making, and non-discrimination.

Automated decision-making. Under the CPRA, you have the right to opt out of automated decision-making, including profiling, that produces legal or significant effects. Our recommendation features present cards from your network but do not produce decisions with legal or similarly significant effects on you. If you have questions about how recommendations work or wish to limit personalisation, contact us at support@littlelockbook.com.

Changes to this policy

We may update this policy from time to time. Where the change is material, we will notify you in the app before it takes effect. The effective date at the top of this policy shows when the current version was published.

Contact

For any privacy enquiries, email support@littlelockbook.com.