Privacy Policy
Last revised: September 29, 2026 · Effective immediately for all Little Buddha users.
Encrypted in transit & at rest
TLS 1.3 on every connection, Row-Level Security on every table, and encrypted storage for the photos you upload.
No ads, no trackers
We ship no advertising SDK and no third-party analytics. There is no profile of you for anyone to buy.
Deletion you can actually do
In-app in two taps, or by email. Data is purged from active databases within 30 days, and from backups within 90.
1. Who we are and what this covers
Little Buddha (“Little Buddha”, “we”, “our”, “us”) is the developer and publisher of the Little Buddha app for iOS and Android, and of this website. For the purposes of the EU and UK General Data Protection Regulation, we are the data controller for the personal data described here.
This policy covers the App, any in-app subscription, and this website. It does not cover the stores you install from, or anything you post to a social network.
2. What we collect
We collect only what the App needs to work. Nothing is gathered in the background for advertising. Anything marked optional can be left out entirely, and everything marked required is only what the feature would be meaningless without.
Email address, display name, avatar, optional zodiac sign, and a hashed password or a linked Apple/Google identity.
Required
Journal entries, daily intentions, gratitude notes, private whispers, and the photos you add to your polaroids.
Required
Your daily sky selection and energy level, plus the partner-visibility toggle you control.
Required
Which habits and rituals you created, and when you last tended each one. Never shared unless you share it.
Required
Once you mutually link, the entries you explicitly choose to share: sky updates, the shared garden, and your calendar.
Optional
The store transaction receipt, plan tier and renewal status. Apple and Google hold your card; we never see it.
Optional
Crash stack traces, app version, OS version, coarse device model, and your IP address in server logs.
Required
3. How we use it
Your information is used strictly to provide and secure the Little Buddha experience:
- Displaying your weather, journal, and habits across your authenticated devices.
- Sending attunement notifications and whispers to the partner you have explicitly linked.
- Generating your private monthly keepsakes and starfield memory maps.
- Validating subscription receipts so you keep what you paid for.
- Fixing crashes, answering support requests, and detecting abuse.
- No AI training on your private thoughts. Your journal entries, whispers and sky logs are never used to train general-purpose machine-learning models, and no human reads them unless you ask us for help.
Because we operate no advertising SDK and no third-party trackers, we have neither the mechanism nor any lawful basis for building an advertising profile about you.
4. Why we are allowed to (legal bases)
Where the GDPR or UK GDPR applies, each purpose rests on a specific legal basis.
- Creating and securing your account
- Performance of a contract — Art. 6(1)(b)
- Hosting your entries, photos and logs
- Performance of a contract — Art. 6(1)(b)
- Sharing data with a linked partner
- Consent, which you withdraw by unlinking — Art. 6(1)(a)
- Processing subscription receipts
- Performance of a contract — Art. 6(1)(b)
- Crash diagnostics and abuse prevention
- Legitimate interests in operating a secure service — Art. 6(1)(f)
- Service emails: receipts, security notices, policy changes
- Legitimate interests — Art. 6(1)(f)
- Marketing email, if you ever opt in
- Consent — Art. 6(1)(a), withdrawable at any time
5. How this maps to the store labels
So you can check our store disclosures against this policy yourself, here is exactly how the two correspond.
| Store label | What we actually do |
|---|---|
| Data Linked to You | Contact info; photos or videos; user content; identifiers; purchases; usage data; diagnostics |
| Data Used to Track You | None. We do not request App Tracking Transparency, and use no advertising or cross-app tracking identifiers. |
| Third-Party Advertising | None |
| Data Encrypted in Transit | Yes — HTTPS with TLS 1.3 |
| You Can Request Deletion | Yes — in the app, and at littlebuddha.app/support#deletion |
| Play: Shared with Third Parties | Only the processors in section 7, and only the data each strictly needs to run the App |
| Play: Data Collection Is Optional | Yes — you can use the App without linking a partner or subscribing |
6. How long we keep it
We keep your data only while your account exists. There is no shadow archive.
- Account and content
- For the life of your account, then permanently deleted within 30 days of your request.
- Deletion backups
- Encrypted backups rotate out within 90 days, after which nobody — including us — can restore your data.
- Crash and access logs
- Up to 90 days, then automatically purged.
- Transaction receipts
- As long as tax and accounting law requires in our jurisdiction.
- Support correspondence
- 24 months, so we keep a coherent history of your requests.
7. Who processes it for us
We use a deliberately small number of processors. Each is contractually bound to handle your data only on our instructions, and only for the purposes set out here.
| Provider | Role | Data involved |
|---|---|---|
| Supabase | Database, authentication, encrypted file storage | Account, journal entries, photos, sky logs |
| Apple / Google | Payment, distribution, in-app purchase delivery | Transaction IDs and receipt validation — never your card details |
| Apple / Google sign-in (optional) | Single sign-on | Your verified email address and account identifier |
| Email delivery provider | Receipts, security notices, support replies | Email address and message content |
| Application host | Serving this website and the App API | IP address and request logs |
We disclose personal data to no advertiser, broker or analytics vendor. We may disclose it where the law requires it, or as part of a corporate transaction, in which case you get notice before your data moves to a new controller.
8. Where your data is processed
Little Buddha is developed and operated from India, and our infrastructure providers may process data in other countries, including the United States and the European Economic Area. Where personal data leaves the UK or EEA, we rely on the UK and EU Standard Contractual Clauses and the UK International Data Transfer Addendum, backed by encryption in transit and strict access controls. Write to our privacy address and we will send you a copy of the applicable safeguards.
9. Your rights
Where the GDPR, UK GDPR, CCPA/CPRA or a comparable law applies to you, you have these rights. We respond within 30 days and we do not charge for it.
- Access — get a copy of the personal data we hold about you.
- Portability — receive it in a structured, machine-readable format.
- Rectification — correct anything inaccurate.
- Erasure — have your account and content permanently deleted.
- Restriction and objection — limit or object to processing based on legitimate interests, including any direct marketing.
- Withdraw consent — at any time, without affecting what we did before.
- Non-discrimination — using these rights never costs you access to the App or your subscription.
- Complain — to your supervisory authority, such as the Information Commissioner’s Office in the UK or your national Data Protection Authority in the EU.
To exercise any of these, use the Account & Data Deletion portal or email us. We may ask you to confirm control of the account email address before releasing anything.
10. Children
Little Buddha is intended only for people aged 16 or older and is not directed to children under 13. We do not knowingly collect personal data from anyone under 13, and we do not use the App to gather information about children. Because the App is not designed for minors we are not subject to COPPA collection requirements — but it is age-restricted to 16+ on both stores regardless.
If you believe a child under 13 has given us personal data, write to privacy@littlebuddha.app and we will delete it promptly and without question.
12. How we protect it
Supabase/PostgreSQL with Row-Level Security on every table, TLS 1.3 in transit, encryption at rest for photo storage, hashed credentials, and least-privilege access for engineers. No system is perfect, but no system is unguarded either. More detail is on our Security page.
13. If this policy changes
We may update this policy as the App evolves or the law changes. The revision date at the top always reflects the current version. For material changes — especially anything affecting how we treat your journal content — we will notify you in the App or by email before the change takes effect.
14. Contact us
Questions about this policy, or a request to exercise your data rights, go to our privacy desk. Every substantiated request is answered within 30 days.
General support: hello@littlebuddha.app