Lit Teen Social
Support & Legal

Privacy Policy

Effective Date: 12 July 2026

This policy explains what personal data Lit Teen Social collects, how it is used, when it is shared, how long it is kept, and what rights users and parents have.

0. How to Read This Policy

This Privacy Policy uses the same two-layer structure as our Terms of Service. “KEY POINTS, In Plain English” boxes summarize each section for quick reading. They are a convenience, not a substitute for the full text; if the two ever conflict, the full text controls. We have written this policy to meet the standard set by the EU General Data Protection Regulation (“GDPR”) for all users, wherever they live, because we believe those protections are good practice everywhere, not only where they are legally required.

1. Key Terms Used in This Policy

To keep this policy readable, we use a few defined terms:

  • App / Service: the Lit Teen Social mobile application and related services.
  • Personal data: any information that identifies you or could reasonably be linked to you.
  • Processing: anything we do with personal data, such as collecting, storing, using, sharing, or deleting it.
  • Controller: the party that decides why and how personal data is processed. We are the controller for the data described here, except where we say another party (such as KWS) is the controller.
  • Age of digital consent: the age below which a parent or guardian must give permission before certain data about a young person can be processed. It varies by country, commonly between 13 and 16.
  • KWS: Kids Web Services (Kids Web Services Ltd, UK), our third-party age-assurance and parental-consent provider, described in Sections 5 to 8.

2. Who We Are and the Scope of This Policy

This Privacy Policy explains how Lit Teen Social & Adventures (currently incorporating in Estonia as Lit Teen Social & Adventures OÜ) (“we,” “us,” or “our”) collects, uses, shares, and protects personal data in connection with the App. It should be read together with our Terms of Service.

2.1 Who This Policy Covers

This policy applies to all users of the App, teens using the App with parental consent and adult users, as well as parents and legal guardians who interact with our age-verification and parental-consent process on behalf of a child.

2.2 Our Approach to Children’s Privacy

Because a significant portion of our users are minors, we design our data practices around data minimization for children specifically: we collect the least personal data necessary to provide the Service safely, we do not use a minor’s data for behavioral advertising or to build advertising profiles, and we do not sell a minor’s personal data under any circumstances.

2.3 One Global Standard, Everywhere

The App is available worldwide, not only in our primary launch markets of Canada, the United States, and the European Union. Rather than applying a lower standard depending on local law, we apply the protections in this policy, built to the GDPR standard, to every user, everywhere. A user in a country with no specific data-protection law receives the same rights described in Section 16 as a user in the EU. The only exception to universal access is where applicable law imposes an outright restriction we must follow, such as the hard-ban age restrictions described in Section 7, which we apply based on a user’s detected location.

3. The Personal Data We Collect

3.1 Information You Provide

  • Account information: email address, username or display name, password (stored in hashed form), and date of birth.
  • Profile information: profile photo, bio, and anything else you choose to add to your profile.
  • Content: posts, photos, videos, comments, Stories (24-hour disappearing content), and direct messages you create or send.
  • Verification information: we receive only your verification status and the minimum information needed to apply the right rules, not the underlying documents (see Section 5).
  • Third-party login information: if you sign in with Google, Facebook, or Apple, we receive basic profile information (name, email, profile picture, account ID). See Section 14.
  • Communications: information you provide when you contact support or report content.
  • Prize-fulfilment information: if you win a contest, giveaway, or sweepstakes run in the App and the prize has to be delivered to you, we collect the recipient name, mailing address, and an email address or other delivery contact, and in some cases a phone number required by the carrier. Where the winner is below the applicable age of digital consent, we collect this from the verified parent or guardian instead, not from the teen. See Section 11.4.

3.2 Information Collected Automatically

  • Device and session information: device ID, device name, operating system, user agent, IP address, locale, country or region, and in some cases city or approximate coordinates if location permission is granted, collected by our own backend for security, session management, and compliance.
  • Usage data: features used, screens viewed, session length, and crash or error logs.
  • Push notification data: if you grant permission, OneSignal collects a device push token, your platform, push permission status, and your Lit Teen Social user ID to deliver notifications. See Section 14.

3.3 Information We Do Not Collect Directly

We do not request or knowingly collect government identification numbers, payment-card details, or biometric data directly. Where any of these are involved in age or parental verification, they are handled by KWS under its own privacy practices (Section 5); we do not receive or store this underlying data ourselves.

4. Our Legal Bases for Processing Your Data

We launch in Canada, the United States, and the European Union, so this policy is built to satisfy several overlapping frameworks at once, including the GDPR, Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applicable provincial laws, and the US Children’s Online Privacy Protection Act (“COPPA”) for our US users under 13, including the amended COPPA Rule in effect in 2026. Where these frameworks differ, we apply whichever standard is more protective of you. Under these frameworks, we rely on the following legal bases:

  • Performance of a contract: to create your account and provide the core features you signed up for.
  • Verifiable parental consent: for users below the applicable age of digital consent, we rely on consent from a verified parent or guardian before processing the child’s data beyond the minimum needed to complete verification itself.
  • Legal obligation: where we must process data to comply with law, such as responding to a valid legal request or fulfilling mandatory child-safety reporting.
  • Legitimate interests: for limited purposes such as platform security, abuse prevention, and improving performance, balanced against your rights, and, for minors, applied conservatively given their heightened need for protection.
  • Consent: for optional features such as opt-in marketing, which you can withdraw at any time.

5. Age Verification and the Role of KWS

5.1 Who KWS Is

We use Kids Web Services (“KWS”), operated by Kids Web Services Ltd, a specialist age-assurance provider based in the United Kingdom, to help verify age and manage parental consent. KWS offers modular services that can include an Age Gate (determining, from age and location, whether a user is above or below the applicable age of digital consent), Parent Verification, and Consent Management. KWS acts as an independent data controller for the personal data it processes during verification and operates under its own privacy policy.

5.2 How Verification Works and What Happens to Your Data

When you create an account, KWS determines the age of digital consent applicable in your location and verifies whether you meet it, using methods that vary by location (which may include document-based checks, payment-card verification, or mobile-number verification, depending on availability). The underlying identity, document, payment, and any biometric information used during verification are processed by KWS, not by us. Based on KWS’s published practices, this information is used only to reach a verification outcome and is not retained by KWS as identity records; KWS retains only a limited record (such as a hashed identifier and the outcome) so that a parent or user does not need to re-verify across other services that use KWS. We receive only the outcome, pass or fail, and the minimum information needed to apply the correct rules.

5.3 Re-Verification

We may periodically re-verify age or consent status, particularly around your transition from minor to adult, so that your account continues to reflect the appropriate protections and permissions.

6. How We Determine Which Rules Apply to You

Different countries set different minimum ages and different rules for young users. To apply the correct rules to you, we determine your applicable jurisdiction, and we do this carefully rather than simply trusting what a user types in.

6.1 Detected Location Comes First

Your applicable jurisdiction is determined primarily by your device’s detected physical location, not solely by your stated country of residence. When you sign up, you may also enter a country of residence.

6.2 When Location and Stated Residence Conflict

Where your detected location and your stated country of residence differ, we apply whichever jurisdiction’s rules are stricter. We do not allow a user to select a country of residence in order to gain access to a more permissive set of rules than those that apply to the user’s actual physical location. This protects young users from opting into weaker protections by changing a setting.

6.3 Our Compliance Record

We maintain a record of these determinations, including detected location signals, stated residence, the applicable age threshold, and which rules were applied, as part of our compliance documentation. We keep this record because we may need to demonstrate to a regulator that we applied the correct age rules to a given user. This record is retained as described in Section 12 and is disclosed to regulators only where appropriate or legally required.

7. Hard-Ban Jurisdictions

In some countries, applicable law prohibits minors below a specified age from using social media at all, regardless of parental consent. Where a user’s detected location (or stated country of residence, if stricter) is in such a jurisdiction and the user’s verified age falls below the applicable threshold, we block that user, and parental consent does not override a statutory hard ban.

As of the Effective Date, this includes, without limitation, users under 16 in Australia, Indonesia, and Malaysia, and is expanded as additional jurisdictions bring comparable laws into force (for example, France, Greece, and the United Kingdom on their respective effective dates). A blocked user is told that the service is not available in their jurisdiction for their age group. Because these laws change frequently, this list is maintained operationally through our age-assurance configuration and may be updated without a formal amendment to this policy.

8. How Parental Consent Works

If you are below the applicable age of digital consent, KWS manages verifying that your parent or guardian is an adult and obtaining their verifiable consent before your account becomes fully active. We receive confirmation of the outcome; we do not receive or store the underlying documents, payment information, or biometric data used to reach it.

US users under 13. This process is designed to satisfy COPPA’s verifiable-parental-consent requirement before we collect personal information from a child under 13. Consistent with the amended COPPA Rule, we obtain separate consent before any disclosure of a child’s personal information to a third party for purposes that the Rule treats as requiring their own consent (such as third-party advertising or AI development), and we do not engage in those uses for children. A parent may review or delete their child’s information, or revoke consent, at any time (Section 16).

Canadian users. Consistent with PIPEDA’s meaningful-consent requirements, we explain what we collect and why in plain language before consent is given, and a parent or guardian may withdraw consent at any time, subject to legal or contractual limits.

Withdrawal of consent. A parent or guardian who has consented may withdraw it at any time using the details in Section 17. Withdrawal results in deletion or deactivation of the associated account, subject to any retention we are legally required to maintain.

9. How We Use Your Data

We use the personal data described in Section 3 to:

  • Create, maintain, and secure your account;
  • Provide core App features, including posting, messaging, and connecting with other users;
  • Verify your age and, where applicable, manage parental consent;
  • Detect, investigate, and act on content or conduct that violates our Terms or Community Guidelines, including removing or suspending accounts, and report to authorities where legally required or where we have a good-faith belief it is necessary for safety;
  • Respond to support requests and to data-rights requests;
  • Administer contests, giveaways, and sweepstakes offered in the App and deliver prizes to winners;
  • Diagnose technical issues and improve the App’s performance and features; and
  • Comply with legal obligations, including responding to valid legal requests.

9.1 What We Do Not Do

We do not sell your personal data, to anyone, for any reason. The App may display advertising scoped to general categories of products and services teens commonly use (for example, clothing brands, restaurants, or trending products). That advertising is shown based on general content categories, not on profiles built from any individual user’s personal activity, and we do not use a minor’s personal data to build individualized advertising profiles. Every ad is reviewed by a human for age-appropriateness before it is served. We do not use your content or personal data to train third-party artificial-intelligence models.

10. Location Data

Location is important to how the App works safely, so we treat it carefully and explain it separately here.

  • For legal and age purposes: your device’s detected location is used to determine the laws applicable to you and to enforce jurisdiction-specific age restrictions, as described in Sections 6 and 7.
  • For Link Ups: your general area is shared with the connections you invite; your exact location is revealed to a connection only once they actively join a Link Up. Link Up details are visible only to your approved connections.
  • For Deals and Steals: the deals locator uses your device location to show offers available near you. This is used to display nearby deals, not to track your movements.
  • What we do not do: we do not use location data for advertising targeting, and we do not continuously track your location in the background beyond what these purposes require.

You can control location permission through your device settings, though some age and safety features depend on our ability to determine your general jurisdiction.

11. Feature-Specific Data Practices

11.1 Stories

When you post a Story, the content is visible to your connections for 24 hours and then automatically removed from the App. Stories follow the same moderation and content standards as other content. The 24-hour expiry removes the Story from the App; we do not control content a connection may have saved or shared before expiry.

11.2 Message Editing and Deletion

You can edit or delete your own messages within the App. When you delete a message, it is replaced with a deletion placeholder visible to other participants and is permanently removed from our servers within our standard retention cycle. We are not responsible for content already seen or saved by others before deletion.

11.3 Events and Link Ups

Where you use event-sharing or Link Up features, we process the meetup details you provide (such as time, general location, and the connections you invite) to display them to the connections you choose. Link Ups are visible only to your existing approved connections, and parents or guardians do not currently have visibility into a teen’s planned Link Ups. We encourage any parent or guardian providing consent to read Section 11 of our Terms of Service before consenting.

11.4 Contests and Prize Fulfilment

The App offers contests, giveaways, and sweepstakes with real prizes. Some are run by us and some are sponsored by a participating business, but every one of them is administered by us, and we send every prize ourselves. Section 15 of our Terms of Service sets out how they work.

What we collect, and when. We do not ask for a mailing address in order to enter. We ask only after a winner has been selected, only from that winner, and only where the prize physically has to be delivered. What we collect is the recipient name, the mailing address, an email address or other delivery contact, and, where a carrier requires it, a phone number.

Winners who are minors. Where a winner is below the applicable age of digital consent, we do not collect a mailing address from the teen. We contact the verified parent or guardian on file, obtain their separate consent to fulfilment, collect the delivery details from them, and ship the prize to them. Where a winner is a minor above that age, we may still require parental or guardian confirmation before shipping, and the rules for that contest will say so. Our legal basis is verifiable parental consent for a minor winner, and performance of our obligations under the contest rules for an adult winner.

Sponsors never receive it. Where a contest is sponsored by a business, the sponsor supplies the prize to us and we deliver it. The sponsor does not receive the name, mailing address, email address, phone number, or any other personal data of any entrant or winner, whether a minor or an adult. A sponsor may not collect entries directly or run its own entry form for a contest offered in the App, and entering a contest never enrols you in marketing from us or from anyone else. A sponsor receives only aggregate, non-identifying figures such as the number of entries. If we want to announce a winner publicly, we ask that winner, or the parent or guardian of a minor winner, for separate optional consent first, and we use no more than a first name and last initial.

Who else sees it, and for how long. Delivery details are shared only with the shipping carrier engaged to deliver that prize, and only to the extent the carrier needs them to make the delivery. We use them for nothing else: not for marketing, not for advertising, not for profiling, and we do not sell them. We delete them once delivery is complete and any delivery problem is resolved, and no later than 30 days after that point, unless a longer period is legally required, for example where the value of a prize creates a tax record-keeping obligation. If a prize is never claimed or the consent needed to deliver it is not given, we delete whatever we collected for it. Retention is summarized in Section 12.

12. How Long We Keep Your Data

We retain personal data only as long as necessary for the purposes in this policy. Our general baseline retention is 30 days, after which data is automatically deleted from our servers, except as noted below or where a longer period is legally required.

Data typeRetention
Account and profile dataRetained while your account is active; deleted or anonymized within 30 days of account deletion, unless a longer period is legally required.
MessagesStored for a minimum of 30 days to support moderation and safety review, then automatically deleted.
Moderation and safety recordsRetained for 30 days after resolution, then automatically deleted, unless a longer hold is legally required or needed for an active safety matter.
Jurisdiction / age-determination recordsRetained while the account is active to demonstrate correct application of age rules, then deleted or anonymized.
Verification and consent recordsUnderlying verification data is deleted by KWS per its published practices; we retain only the outcome and consent record while the account is active, to demonstrate compliance.
Prize-fulfilment data (winners only)Collected only after a win; deleted once the prize is delivered and any delivery issue is resolved, and in any event within 30 days of that point. Deleted promptly if a prize is unclaimed or fulfilment consent is not given. Retained longer only where legally required, such as a tax record-keeping obligation.

We may retain data longer where required by law, where necessary to resolve a dispute, or where necessary to enforce our agreements and protect the safety of our users.

13. How We Share Your Data

13.1 Service Providers

We share personal data with third-party service providers who perform services on our behalf, under contracts that restrict their use of the data to the purpose we engaged them for. Our current providers include:

ProviderPurpose and data involved
KWS (Kids Web Services Ltd, UK)Age verification and parental-consent management. KWS acts as an independent controller for verification data; we receive only the outcome (see Sections 5 to 8).
OneSignalPush-notification delivery (device token, platform, notification metadata, user ID).
GoogleAuthentication via Google Sign-In (name, email, profile picture, account ID).
Meta (Facebook)Authentication via Facebook Login (name, email, profile picture, account ID). Advertiser-ID collection and auto app events are disabled in our implementation.
AppleAuthentication via Sign in with Apple (Apple user ID, email, verification status).
StripePayment processing for businesses and advertisers only. Stripe does not process payments from App users.
Shipping carriers (e.g. postal and courier services)Delivery of contest prizes only. Receives the recipient name, delivery address, and where required a delivery contact number or email, for that delivery only. Used only for winners, never for entrants (see Section 11.4).
DigitalOceanCloud hosting and infrastructure. Provider may change as the platform scales; this section will be updated if it does.
Crash-reporting tool (e.g. Firebase Crashlytics)To be integrated before or at launch; collects device and error data on a crash. This section will be updated with specifics before activation.

Support inquiries, data requests, and parental-rights requests are handled directly via our contact address in Section 17. We can provide additional detail about any current provider on request.

13.2 Other Users

Content you post is visible to other users based on whether your account is private or public, as described in our Terms. We do not control, and are not responsible for, what other users do with content you have chosen to share with them.

13.3 Legal and Safety Disclosures

We may disclose personal data where required by law (for example, in response to a valid court order or legal process), or where we have a good-faith belief that disclosure is necessary to prevent harm, investigate illegal activity, or protect the safety of a user or the public, including, where legally required, mandatory reporting relating to the safety of a minor.

13.4 Assignment and Business Transfers

As described in our Terms, we may assign the operation of the Service, including the personal data described here, to a successor entity (such as Lit Teen Social & Adventures OÜ once incorporated, or an entity resulting from a merger, acquisition, or reorganization), provided the successor is bound by this policy and maintains the same or greater standard of protection.

13.5 No Sale of Personal Data

We do not sell personal data to third parties, and we do not share personal data with third parties for their own independent marketing purposes. This includes businesses that sponsor a contest or giveaway in the App: they receive no entrant or winner data from us, including no mailing address, under any circumstances.

14. Cookies, Logins, and Other Technologies

14.1 No Cookie-Based Tracking

The App does not use cookie-based tracking. Authentication is handled via secure tokens stored on your device, not cookies. We do not use advertising cookies, tracking pixels, or cross-app tracking technologies.

14.2 Third-Party Login Providers

We offer login via Google Sign-In, Facebook Login, and Sign in with Apple, for authentication only. We receive basic account information (such as name, email, and profile picture) from the provider you use. We do not use these providers for advertising or analytics. In our Facebook implementation, advertiser-ID collection and automatic app-event logging are disabled, and Facebook Login can be disabled via app settings.

14.3 Push Notifications (OneSignal)

We use OneSignal to deliver push notifications for messages, likes, comments, mentions, friend requests, and other activity. OneSignal collects a push subscription token, your device platform, push permission status, and your Lit Teen Social user ID, for notification delivery only, not advertising or cross-app tracking. You can disable push notifications at any time in your device settings. For minor users, push registration is configured to occur only after age verification and parental consent are complete.

14.4 Crash Reporting

We plan to integrate a crash-reporting tool (such as Firebase Crashlytics) before or at launch to identify and fix technical issues. It will collect device information and error data when the app crashes. We will update this section with the specific tool and its practices before it is activated.

14.5 Our Advertising System

Lit Teen Social operates its own internal advertising system. Businesses submit ads through a self-serve portal we build and operate, and all submissions are reviewed by our team for age-appropriateness before any ad is served. We do not use any third-party advertising SDK or ad network, so no external advertising company receives data about our users in connection with ad serving. Stripe processes payments from businesses submitting ads or Deals and Steals listings; it operates entirely on the business side and does not process payments from, or collect personal data from, App users.

15. Marketing Communications

With opt-in consent, we may use your email address or phone number to send Marketing Communications about Lit Teen Social itself, as described in our Terms of Service. This is opt-in only and never on by default. We never send marketing on behalf of any other company, brand, or advertiser, and we never sell, rent, or share your contact information with a third party for their own marketing purposes.

If you are below the applicable age of digital consent, this consent must be given by your verified parent or guardian. You (or your parent or guardian) may withdraw it at any time, free of charge, using the unsubscribe link in every marketing email, the opt-out in every marketing text, or the details in Section 17, without affecting your ability to use the App. We do not use data collected for Marketing Communications for any other purpose without separately informing you.

16. Your Privacy Rights

Subject to certain exceptions and limitations under applicable law, you have the right to:

  • Access: request information about the personal data we hold about you;
  • Rectification: request correction of inaccurate or incomplete data;
  • Erasure: request deletion of your personal data;
  • Restriction: request that we limit how we use your data in certain circumstances;
  • Portability: where applicable, request transfer of certain data in a structured format;
  • Objection: object to our use of your data based on legitimate interests; and
  • Withdraw consent: where we rely on consent (including parental consent), withdraw it at any time, without affecting the lawfulness of processing before withdrawal.

16.1 How to Exercise Your Rights

To exercise any of these rights, contact us using the details in Section 17. If you are a parent or guardian making a request on behalf of a minor, we will take reasonable steps to verify your identity before acting. We will respond to verified requests within one month, and will tell you if we need a reasonable extension for a complex request.

16.2 US State Privacy Rights

Depending on your US state of residence, you may have additional rights (such as the right to know, delete, correct, or opt out of certain processing). We honor verified requests consistent with applicable state law, and we do not discriminate against you for exercising your rights.

16.3 Regulatory Rights

Where required by the data-protection law applicable in your country, you may raise concerns with a relevant data-protection authority. These rights exist independently of our Terms. Once our Estonian incorporation is complete, our primary EU supervisory authority will be the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

17. How We Protect Your Data

We use technical and organizational measures designed to protect your personal data, including encryption of data in transit, access controls limiting internal access on a need-to-know basis, and secure storage of credentials. No system is completely secure, and we cannot guarantee absolute security, but we are committed to addressing vulnerabilities responsibly and promptly.

17.1 Data-Breach Notification

If a breach of your personal data occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, where required by law, and will notify affected users without undue delay where the breach is likely to result in a high risk to them.

17.2 Technical Failures and Data Loss

We take reasonable measures to keep your data secure and intact, but no system is immune to technical failure. As described in our Terms of Service, we are not responsible for loss, corruption, or unavailability of content or account data resulting from a server outage, software bug, crash, or other technical issue. Please do not treat the App as your sole or permanent storage for content you cannot afford to lose.

18. Automated Processing and Moderation

We use automated systems, including rule-based filtering and AI analysis, as part of the layered moderation described in our Terms of Service. These systems help detect policy violations, suspicious patterns, and safety concerns. Automated tools may lead to an account being flagged or temporarily actioned, but accounts actioned by automated systems are handed to our human review team for final determination, and you can appeal an enforcement decision where appropriate. We do not use these systems to make solely automated decisions that produce legal or similarly significant effects on you without human involvement, except where permitted by law for safety and security purposes.

19. Special Notice for Parents and Guardians

We built Lit Teen Social with parents in mind. Before consenting to your child’s account, we encourage you to understand three things in particular: (1) certain features, such as Link Ups, are designed for teen autonomy and are described in Section 11 of our Terms of Service, including that parents do not currently have visibility into planned Link Ups; (2) verification and consent are handled by KWS, which processes the sensitive verification data rather than us; and (3) you may review, correct, or delete your child’s data, or withdraw consent, at any time using the details in Section 17 of our Terms and Section 17 below. If you believe we have collected personal information from a child in a manner inconsistent with this policy, contact us and we will investigate and, where appropriate, delete the information promptly.

20. Changes to This Policy

We may update this Privacy Policy from time to time. If we make a material change, particularly one that expands the categories of data we collect or the purposes for which we use it, we will notify you through the App and/or by email before the change takes effect, and update the Effective Date above. For minors with parental consent on file, a material change of this kind may require renewed parental consent before it applies to that user.

21. Language and Accessibility

This policy is provided in English. Where we make a translation available for convenience and a conflict arises, the English version controls to the extent permitted by applicable law. If you use assistive technology and have difficulty accessing any part of this policy or the App, contact us using the details in Section 22 and we will work with you to provide the information in an accessible format.

22. How to Contact Us

If you have questions about this Privacy Policy or want to exercise any right described in Section 16, contact us at:

During the interim period, the operational contact address is litteensocial@gmail.com.

Lit Teen Social & Adventures (in formation as Lit Teen Social & Adventures OÜ)

[Registered Address, to be confirmed on completion of Estonian incorporation]