Privacy Policy
LittleStep is made by 5Lab Group Co., Ltd. (Bangkok, Thailand), the data controller for everything described here. This policy describes the app as it is actually built — if something is not listed below, the app does not do it.
The short version. We collect a parent's email address, a child's first name and birthday, a few interests, and anything you choose to type about your child. We use it to write that child's stories. We do not sell it, we do not advertise, there is no analytics or tracking SDK in the app, and you can delete all of it from inside the app in two taps.
1. What we collect
| What | Why |
|---|---|
| Your email address | It is how you sign in — we mail you a six-digit code and a link, and there is no password to lose. It is also how we reach you about the account. |
| Your name (optional) | Only if you tell us. Used to address you in the app and in email. |
| Your child's first name and birthday | The name appears in the stories; the birthday sets the child's age, which decides what is developmentally right for today. |
| Interests and what you type about your child | The free-text notes you write during setup, in your own words. They are what makes a story sound like your child's rather than anyone's. |
| Appearance traits (optional) | A small fixed set — age band, skin tone, hair style, hair colour — so the illustrations look like the same child every time. You can pick these by hand. See §3 if you use a photo. |
| A device identifier | A random value the app generates on first launch and stores on the device. It is not your advertising ID, not your IDFA/AAID, and not tied to your hardware. It is what lets a device keep today's plan before you have signed in. |
| What was delivered and opened | One row per day per device: which story or moment you were given and whether it was opened. It stops repeats, fills your library, and returns an unopened day to the pool so you do not lose it. |
| Ordinary server logs | Requests to our servers, including IP address, kept briefly for security and to fix faults. |
What we do not collect
- No advertising identifiers, and no ad networks — there are no ads in LittleStep.
- No third-party analytics or tracking SDK is bundled in the app.
- No location, no contacts, no microphone, no health data.
- No payment data. LittleStep is in Free Beta: nothing is sold in the app, so there is no card to store.
- This website loads no third-party fonts, scripts, cookies or trackers of any kind.
2. About children
LittleStep is a tool for a parent or guardian to use. The account belongs to an adult, the app is operated by an adult, and children do not create accounts, sign in, or communicate with anyone through it. There is no chat, no user-generated content shared between families, no social feature and no public profile.
The information about a child in LittleStep is information you chose to give us about your own child, and you can see and delete all of it at any time. We do not use it to build an advertising profile, we do not sell it, and we do not share it with anyone except the processors listed in §4, which exist only to make the app work.
3. If you use a photo
You may optionally offer a photo so the illustrations resemble your child. When you do, the picture is sent once to our AI provider, which reads a handful of traits from it — an age band, a skin tone, a hair style, a hair colour.
The photo itself is never written to our disks or our database. Only the short list of traits is saved, and the drawings are generated from that list alone — the photo never reaches the illustrator. You can always skip the photo and choose the same traits by hand; nothing in the app is withheld if you do.
4. Who else sees it
We do not sell personal data, and we do not share it for anyone else's marketing. We use a small number of service providers to run the app, each of which sees only what it needs:
| Provider | What it does | What it sees |
|---|---|---|
| Hosting & database | Runs our servers and stores the data, in Singapore. | Everything in §1, at rest. |
| AI provider (OpenRouter and the model it routes each request to) | Writes the stories and draws the illustrations. | The child's first name, age, interests, your notes, the trait list — and, for that one call only, a photo if you offered one. |
| Image storage (Cloudflare R2) | Holds the finished illustrations, so they are not kept in the database. | The picture files. Nothing that names your child — the file name is a random identifier, and the pictures are deleted with your account. |
| Email delivery | Sends your sign-in code and account email. | Your email address and the message. |
We will also disclose data if the law requires it, or to protect someone's safety — and we will tell you unless we are forbidden to.
5. Where it lives, and for how long
Our servers and database are hosted in Singapore, and the finished illustrations are stored in Cloudflare's object storage in the Asia-Pacific region. Our AI and email providers may process requests outside Thailand and Singapore, including in the United States and the European Union; where that happens we rely on the provider's own transfer safeguards.
We keep your account data for as long as the account exists. Sign-in codes expire in minutes. Server logs are kept briefly. When you delete your account (§6), the data is removed from our live systems immediately; encrypted backups are cycled out on their normal schedule, within 30 days.
6. Deleting everything
In the app: Profile → Delete account. It asks once, and then it is done — your family's stories, moments, notes, child profile and sign-in are removed. If you were invited to someone else's family, deleting removes your place on that account and leaves the rest of the family untouched.
You can also ask us to do it without opening the app — see littlestep.app/delete-account.
7. Your rights
Under Thailand's Personal Data Protection Act, and under the GDPR where it applies to you, you may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or withdraw consent. Write to [email protected] and we will answer within 30 days. If you are not satisfied, you may complain to your data protection authority — in Thailand, the PDPC.
Our legal bases are: performing the service you asked for (making today's story), your consent (an optional photo), and our legitimate interest in keeping the service secure and working.
8. Security
Traffic is encrypted in transit. There is no password to steal: sign-in codes and session tokens are stored only as SHA-256 hashes, so a leaked database row cannot be used to sign in. Access to production data is limited to the people who operate the service.
No system is perfect. If a breach affects you, we will tell you and the regulator as the law requires.
9. Changes
If this policy changes in a way that matters, we will say so in the app before the change takes effect. The date at the top always reflects the current version.
10. Contact
5Lab Group Co., Ltd. · Bangkok, Thailand
[email protected]