Privacy Policy
This policy explains what data we process when you use the Little Big Name application (the app for discovering and choosing your baby's name, as a couple), what we use it for, and what rights you have.
1. Who is responsible
The controller of your data is:
- Owner: Felix Carmona
- Contact email: hello@littlebigname.com
2. What data we process
Your account
- A random internal identifier that does not reveal who you are.
- If you sign in with Google or Apple: the email and name the provider supplies and, if there is one, your profile photo. If you use Apple's option to hide your email, we only receive the relay address Apple generates.
- If you use the app as a guest, we collect no identifying data.
- The name and photo you choose to put on your profile. The photo can come from your sign-in provider or be uploaded by you from your phone's camera or gallery; in that case it is scaled down on your own device before being sent.
- Your usage preferences, such as your language or the name catalog you explore.
- The date you accepted the terms and this policy, so we know whether we have to ask you again when they change.
- Your available swipe quota and when it refills.
Your activity
- The names you rate (the ones you like and the ones you discard), when you do it, and which name catalogs you open.
- If you pair up with your partner: the link between both accounts and the activity the app shares between you — your partner sees your profile and the names you both like, including your matches.
Notifications
- If you turn notifications on, the identifier of your device needed to send them to you.
- To deliver them, Apple and Google receive that identifier together with the text of the notification, which may include your partner's first name and the baby name in question (for example, "Marta also likes Olivia").
Purchases
- The status of your subscription and its renewal date. Payment is processed entirely by the App Store or Google Play: we never see or store your card details, and we keep no receipts or transaction identifiers — those stay in the hands of the store and RevenueCat.
- To check that your subscription is still active we share your internal account identifier with RevenueCat, which uses it as a customer key.
- If you are paired, your partner sees whether your account has an active subscription, because paid access is shared between the two of you.
Analytics and diagnostics
- An anonymous count of app opens, which is also recorded before you create an account. It is not associated with any identifier — yours or your device's — so it cannot be linked to you or connect two uses to each other. It is accompanied only by your country, the platform and the app version.
- Usage events linked to a random pseudonymous identifier. Each event travels with the platform, the app version, the language, your country, a session identifier that groups the stretch of time you have the app open, and device data: model, operating system version, manufacturer and browser engine version. These last four are sent once per batch of events, not per event, and never accompany the anonymous count of app opens. They help us narrow down display bugs that only occur on certain phones or versions.
- These events never contain your profile name, your email or any text you type. They do record which catalog names you like and which you discard, which is precisely what the app exists to help you decide. When you delete your account, the link between you and the pseudonymous identifier is destroyed and the history becomes anonymous.
- Crash reports, with technical device data, to detect and fix bugs. They are associated with your internal account identifier and include which screens of the app you had gone through right before the crash.
- Your IP address, transiently, for security and abuse prevention. It is noted in our server's access logs, which are deleted after 7 days, and is not stored in any of our databases.
- Your country, derived from that IP address to know in which markets the app is used. It is derived on our own server, with a local database: your IP address is not sent to third parties for this, and we do not store it. We store only the country — never the region, the city or your location — and the country is the only answer our system is capable of obtaining.
Advertising
- The app shows Google AdMob ads — only videos you choose to watch, to recover swipes. Only if you give your consent does AdMob use your device's advertising identifier to personalize them; if you do not, non-personalized ads are shown. You can withdraw or change your consent at any time from Settings → Ad privacy, or by writing to us.
- On iOS, the system will additionally ask for permission to track your activity (Apple's App Tracking Transparency prompt). If you decline, the advertising identifier is not used.
- Regardless of what you answer, Apple and Google inform ad networks, through attribution systems that do not identify you (SKAdNetwork on iOS), of whether an ad resulted in an installation of the app.
- Google explains how it handles data when serving ads in How Google uses information from apps that use its services.
Data stored on your device
- The app stores on your own phone your session, your preferences, the name catalog and a copy of the profile photos — yours and your partner's — to work fast and offline. None of this leaves your device.
- On iOS, the session is stored in the system keychain and survives uninstalling: if you reinstall the app, you will still be signed in. To delete your data, uninstalling is not enough — use Delete account inside the app.
3. What for, and on what legal basis
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Providing the service: account, activity, pairing and notifications | Performance of the contract (6.1.b) |
| Managing your purchases and subscription | Performance of the contract (6.1.b) |
| Showing you personalized ads | Consent (6.1.a), withdrawable at any time |
| Showing non-personalized ads and measuring their performance | Legitimate interest (6.1.f) |
| Improving the app and diagnosing failures: anonymous count, pseudonymous analytics, device data and crash reports | Legitimate interest (6.1.f) |
| Knowing in which countries the app is used (country derived from the IP) | Legitimate interest (6.1.f) |
| Security and abuse prevention | Legitimate interest (6.1.f) |
| Complying with legal obligations | Legal obligation (6.1.c) |
4. Who it is shared with
We do not sell your data. It is processed only, on our behalf or as controllers of their own services, by these providers:
- Google — Google sign-in, advertising and ad measurement (AdMob), crash reports (Firebase Crashlytics), notification delivery and payments on Google Play.
- Apple — Apple sign-in, notification delivery and payments on the App Store.
- RevenueCat — purchase and subscription management: receipt validation and subscription status. It receives your internal account identifier as a customer key.
- Amazon Web Services — hosting of profile photos and backups.
5. International transfers
These providers may process data in the United States. Google, Apple and Amazon Web Services are certified under the EU-U.S. Data Privacy Framework, the framework whose adequacy the European Commission has recognized. Transfers to RevenueCat are covered by standard contractual clauses approved by the European Commission.
6. How long we keep your data
- Your account and your activity, for as long as you have an account.
- If you delete your account (from the app itself, or by writing to us), we immediately delete your account, your activity, your photo and the link with your partner.
- Your analytics history is not deleted: it is anonymized. When your account disappears, the only link that existed between you and the pseudonymous identifier is destroyed, so the remaining events can no longer be attributed to any person. We keep that already-anonymous history with no set time limit, to analyze how the use of the app evolves over time.
- The server's access logs, which contain your IP address, are deleted after 7 days.
- Deleted data also disappears from our backups within a maximum of 30 days.
7. Your rights
You can exercise at any time your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw any consent you have given, by writing to hello@littlebigname.com. Erasure is also one tap away, inside the app.
If you believe we have not handled your data correctly, you can complain to the Spanish Data Protection Agency (aepd.es).
8. Minors
Little Big Name is designed for expecting parents. It is not aimed at children under 14, and we do not knowingly collect data from anyone under that age.
9. Changes to this policy
If we change this policy in a material way, we will tell you in the app before the change affects you. The date of the current version always appears at the top of this page.