Little Shrine · Legal

Privacy Policy

Read the document that accompanies the app.

This website

A small, private moment in your browser

This notice describes this website and its brief trial. The app’s separate draft Privacy Policy follows below.

For website privacy questions or requests, write to dvdandroidapp@gmail.com. We may need to verify your authority before disclosing or changing personal information.

App Privacy Policy

Operator
Kiwi Tree
Release
buddha-legal-v1-draft.1
Status
draft
Effective date
Not set
Privacy version
1.0.0-draft.1
PRIVACY POLICY
Draft for release review · Kiwi Tree

Operator and contact
Little Shrine is operated by Kiwi Tree. Contact dvdandroidapp@gmail.com for support or privacy requests.

Local practice
On this device we store the selected figure, inventory, settings, prayer durations and activity dates, care, collection and local balance. We do not record the words of your prayers. Device-local records are not automatically imported into a connected account. Device loss or clearing app data may remove local records.

Country and age screening
Your confirmed country/region, optional age range, policy version and screening time are stored on this device, separately from practice. We do not request an exact age, birthday or location permission. Device locale only suggests a country. Google Play may ask whether to share an age range, or require verification or app approval. We retain restrictive ranges, source information, installation references and unresolved verification/approval restrictions so another answer or sign-out cannot erase them. Country/age records are not synchronized to Firebase in this implementation. Missing age may allow local-only use. See Children and Age Eligibility.

Legal records
A local notice records the displayed legal release, document fingerprints and acknowledgment time. This is not account agreement. Pending account setup stores the authenticated account identifier, the displayed agreement, an operation identifier and click time. Successful account agreement is recorded by the server with document identity and server time and cached on the device for offline access. These records are separate from practice. Local preferences are ordinary app storage, not a promise of encrypted or tamper-proof storage.

Connected services
When configured, Firebase Authentication and App Check initialize at startup. They may process identity, device, security and network information before legal acknowledgment. Connected accounts store identity, collection, wallet ledger, prayer/care activity, reward claims, gift status, operation receipts, device supplies and purchase-verification records. Firebase and Google provide authentication, hosting, security and database services; their processing and transfers depend on service configuration. We do not claim all processing stays in your country.

Payments
Google Play handles payment details. Our service receives purchase tokens, product/order references, verification, consumption and refund information needed to credit the correct account and prevent duplicates. Do not send payment credentials to support.

Private gifts
Greetings are encrypted on the sender’s device. The decryption key stays in the private link fragment, separate from ciphertext sent to the service. Anyone with the complete link may read the greeting. Gift metadata includes sender/recipient identifiers, the digital item, status and timestamps. Keep links private. Accepted gifts remain with their recipients when the sender deletes their account.

Optional features
This build does not collect optional analytics or crash diagnostics. Legal acknowledgment/agreement does not enable them. Android reminder permission is optional. Email and sharing actions open applications you choose; drafting an email does not send it. Those destinations have their own privacy practices.

Retention and deletion
Local records remain until removed from app storage. Account deletion removes the account and its subcollections and authentication identity, and cancels pending sent gifts and clears their messages. Some purchase/refund records, deletion markers and accepted gift records remain for transaction integrity and recipient entitlements. We do not promise fixed retention deadlines that this implementation does not enforce. Signing out preserves local practice and pending account work; it is not account deletion. Eligibility protections remain on this installation after sign-out or account deletion.

Your choices and requests
Use Legal & privacy → Privacy requests or email dvdandroidapp@gmail.com for access, correction or deletion requests and concerns about children’s data. We verify identity or authority proportionately before disclosing or changing account information. Non-waivable privacy rights remain available. We cannot recover prayer words that were never recorded or device-only data that never reached our services. Do not send passwords or complete private gift links.

Security and changes
Access controls, App Check, authentication, transactional payment verification and gift encryption reduce risks; no system is guaranteed secure. Material notice changes carry a new release and are presented for review. Review the actual deployed services and applicable requirements before approving this draft for public release.