glow
Logo
Logo

Privacy Policy

Last Updated: June 17, 2026

At Littale ("Platform", "we", "us", "our"), operating as a fully independent software-as-a-service (SaaS) platform, we maintain an absolute commitment to data minimization, informational sovereignty, and user safety. This Privacy Policy serves as our definitive disclosure regarding how we collect, process, isolate, analyze, and permanently cycle data when you interact with the website located at littale.com, our web applications, and our associated core services.

By accessing or initializing an account framework on the Platform, you explicitly acknowledge that you have read, understood, and consented to the regulatory protocols and data architectures described herein. If you do not agree with these standardized practices, you must terminate platform usage immediately.

1. Scope of This Policy and Independent Operation

This framework governs all data vectors flowing through the Platform's isolated operational environment. As an independent SaaS ecosystem, Littale maintains self-contained database infrastructures, technical support communication streams, and dedicated system management boundaries. This Policy establishes the regulatory criteria for our custom storytelling workflows, automated reading vectors, cognitive learning quests, digital asset generations, and virtual cloud subscription management subsystems.

2. Information Gathering and Technical Engagement Analytics

We restrict our data gathering strictly to the technical credentials, diagnostic telemetry, and performance analytics required to host your personal workspace ledger, calculate user performance metrics, and optimize platform engagement.

User-Provided Data & Verification Pipelines: To activate a profile coordinate, the Platform stores necessary credentials including your email address, secure password hashes, and user-selected pseudonyms. For secure account authentication, user validation, and systemic identity access management, we utilize an automated One-Time Password (OTP) verification system dispatched directly through our designated communication routing nodes at support@littale.com. For premium personalized asset synthesis, adult users may submit configuration metrics such as character names, age indicators, and artistic style preferences.

Strict Financial Isolation: To ensure an uncompromised environment, the Platform operates a total financial data isolation boundary. All checkout execution paths, billing data, card profiles, and local taxation audits are handled exclusively by our authorized Merchant of Record, Paddle.com Market Ltd. We never collect, transmit, view, or retain full payment card criteria on our internal database infrastructure.

Automated Technical & Behavioral Telemetry: To guarantee runtime security, evaluate system load, and improve feature interaction loops, the Platform automatically monitors user navigation patterns, processing speed variables, feature utilization, device types, operating systems, and basic network identifiers. This data is aggregated via our dedicated performance analytics pipelines.

3. Consent-Based AI Processing Lifecycle & Image Destruction Pipeline

The Platform incorporates a localized avatar cartoonization module allowing adult users to convert personal reference photographs into stylized, non-realistic illustration characters. To fully satisfy global privacy regulations and avoid unauthorized likeness tracking, this module operates under strict architectural guardrails:

Explicit User Volition & Consent-Based Processing: The submission of any reference image is completely optional and initialized exclusively by the deliberate, affirmative upload action of an authenticated adult user. The explicit legal basis for processing this imagery is user consent, which may be unilaterally revoked at any time by deleting the character model. Users strictly warrant that they possess full legal rights and explicit authority for any uploaded image, strictly limiting uploads to their own personal likeness or that of a minor child under their direct legal guardianship.

Non-Biometric, Stylized Cartoonization: Uploaded source imagery is utilized strictly as a structural design template to render a stylized, fictional cartoon vector. The Platform explicitly does not run facial recognition algorithms, biometric profiling, automated character evaluation, or human categorization tracking. We maintain a zero-tolerance boundary against non-consensual likeness exploitation; the creation of deepfakes, face-swapping arrays, or voice impersonations is strictly blocked and forbidden.

UI Isolation & Deterministic Destruction Lifecycle: The raw, user-uploaded source photograph is instantly processed and systematically masked from public viewports, front-end layers, and shared workspace interfaces. To preserve total data purification, our backend infrastructure logs an unalterable cleanup script that automatically, completely, and permanently scrubs the raw source reference file from our AWS Lightsail architecture exactly six (6) months after its initial upload timestamp.

Model Isolation Guarantee: User-provided imagery and character configurations are strictly isolated. They are never sold, rented, leased, or distributed to external marketing aggregators, and are structurally excluded from public or third-party foundational model training pools.

4. Youth Safety and Asymmetric Classroom Data Separation

The Platform is engineered to strictly maintain compliance with global child safety parameters, including the Children’s Online Privacy Protection Act (COPPA) and the General Data Protection Regulation for Children (GDPR-K).

Adult Operational Mandate: The creation of transactional profiles, modification of billing settings, and upload of character configurations must be executed exclusively by verified adult operators (parents, legal guardians, or authorized educators).

Unauthenticated Classroom Pipeline: Premium creators (such as teachers) may distribute secure, direct reading links to custom storybooks. Students accessing these links can read the complete interactive presentation without registering an account or disclosing any personal identifiers.

Asymmetric Data Segregation: When students register a Free Account to participate in educational quests linked to a classroom book, their input metrics (answers provided, operational errors, and performance scores) are walled off securely. Students can only inspect their personal metrics and standard leaderboard nicknames; they are programmatically blocked from inspecting the granular records of peers. The Premium Creator who generated the master link retains absolute administrative access to view detailed, diagnostic performance data for pedagogical evaluation.

5. Third-Party Sub-Processors and Infrastructure Stack

To guarantee high availability, core safety, and performance analysis, the Platform routes specific data vectors through verified, enterprise-grade technology sub-processors. All operational data pipelines are heavily encrypted in transit (via TLS 1.3) and at rest:

  • Vercel, Inc. (Frontend Hosting & Analytics): Manages our public landing layers and client application frames. Vercel tracks basic internet protocol data to cache media components and utilizes Vercel Analytics to capture real-time application vitals, interaction delays, and infrastructure performance metrics.
  • Amazon Web Services, Inc. (AWS Lightsail Infrastructure): Hosts the Platform’s core backend application servers, security access modules, user database files, and encrypted character asset storage arrays.
  • Paddle.com Market Ltd (Merchant of Record): Acts as our legal reseller and infrastructure partner for all global billing management, commercial risk auditing, tax compliance, and payment settlement vectors.
  • Google LLC (Gemini API & Analytics Infrastructure): Serves two critical functions: (1) Our primary engine for narrative text compilation and comprehension quest synthesis via secure enterprise API nodes where inputs are never used to train open-source models; and (2) Our engagement measurement processor via Google Analytics, which aggregates pseudonymous traffic flows, session durations, click interactions, and regional usage densities to optimize our user interface workflows.
  • Lulu Press, Inc. / Lulu.com (Print-on-Demand Infrastructure - Roadmap Staged Node): Designated technical sub-processor selected to manage print-on-demand manuscript assembly, dynamic binding processing, and global geographic delivery logistics. No user information or payload files are transmitted to this secure node until the option is marked live and a user initializes a physical order event.

6. Cookie and Local Storage Ledger

The Platform restricts its cookie and browser storage footprint strictly to functional, security, and analytical diagnostics. We completely reject cross-site targeted profiling networks and commercial advertising pixels. The following tracking tokens are utilized:

  • Authentication & Session Tokens (AWS Lightsail / Core App): Secure, cryptographic tokens are stored in your local storage upon successful login to verify your identity across protected endpoints (`/app/*`) and block unauthorized database queries.
  • Edge Configuration Telemetry (Vercel): Minimal performance variables are deployed to map network routing rules and accelerate client-side interface delivery.
  • Performance & Engagement Analytics Cookies (Google Analytics & Vercel Analytics): Persistent, first-party analytical identifiers are dropped into your local browser environment. These tokens collect un-identified metrics regarding how you traverse our pages, which features are initialized, and where unexpected UI bottlenecks occur. They do not extract your real-world identity or track you outside of Littale.com.
  • Transactional Security Tokens (Paddle): When initiating the dynamic checkout interface or add-on selection modules, Paddle deploys secure cookies to analyze payment state validation, cross-origin security vectors, and fraud mitigation matrices.

Users may modify their browser preferences to reject analytical tracking cookies; however, completely deactivating all functional cookies or clearing local storage tokens will disrupt user authentication frameworks and render the application non-functional.

7. User-Driven Purge Controls and 6-Month Tombstone Policy

Users retain complete control over their content footprints. We provide accessible self-service deletion mechanisms directly inside the User Settings panel:

Content and Character Removal: Users may manually execute the deletion of individual created storybooks or character files. These files are instantly scrubbed from active user dashboard interfaces and client-side viewports.

Permanent Profile Closure: A user may initialize an absolute account termination via the account dashboard. This action immediately kills active application access loops and freezes billing cycles.

The 6-Month Safeguard Vault: To protect platform infrastructure against accidental deletion events, mitigate active credit refund exploitation, and preserve historical records required for financial dispute auditing, all deleted content and accounts enter a "soft-delete" tombstone state. This data is moved to an isolated, encrypted backup archive for exactly six (6) months. Upon completion of this 180-day retention window, the data is automatically, permanently, and irreversibly purged from our AWS Lightsail infrastructure. It cannot be recovered under any circumstances.

8. Your Statutory Rights and Global Compliance Alignment

Regardless of geographical location, the Platform provides all users with unified data sovereignty privileges. You maintain the right to access, inspect, correct, export, or object to the processing of your personal records. For data export requests or specialized compliance inquiries, you may contact our dedicated data privacy desk at our primary technical communications route: support@littale.com. The Platform will execute verified identity requests within thirty (30) business days.

9. Changes to This Privacy Framework

We reserve the right to modify this Privacy Policy at any time to reflect infrastructural enhancements, analytics adjustments, or independent operational parameter shifts. Material updates will be highlighted via explicit platform notices, email transmissions to registered account targets, or timestamp revisions at the peak of this interface.

10. Contact and Compliance Registry

For all formal inquiries concerning this Privacy Policy, analytics pipelines, data lifecycle mechanics, automated verification protocols, or system security architectures, please address your communications to our centralized administration and support desk:

Littale Support & Compliance
Technical Architecture & Privacy Operations
Centralized Communication Endpoint: support@littale.com

Storytelling Reimagined for
Home, School, and Publishing

Littale transforms ideas and photos into illustrated storybooks with interactive learning—perfect for parents, educators, and creators.

Digital Flipbook

Share, read and learn together

Printed Book

Delivered straight to your doorstep

Download

PDF page and cover files to publish & sell

Logo

Solutions

Mobile Apps (Coming Soon)

Google Play
App Store