Little Wins

YOUR INFORMATION

Privacy policy draft

Draft reviewed 30 September 2026

Who operates Little Wins

NEWTON PHYSIQUES LIMITED operates Little Wins. Public contact details, required company particulars and the final policy effective date are awaiting confirmation.

Information the app stores

The hosted family app stores account identifiers, usernames, names and family membership; password hashes and sign-in sessions; invitation and recovery records; appreciation posts, replies and reactions; chores, points, rewards and pocket money records; family check-ins and plans; personal reflections, focus choices and account preferences; and parent-only conversations. Optional text may include information about feelings or family life.

Why information is used

The app uses these records to authenticate accounts, restrict access by family and account role, share family activity, maintain task and money records, save personal content and support account recovery. The final policy must confirm the legal grounds for processing, child-account arrangements and any operational logging.

Who can see your content

Family journal content is visible to family members. Parent-only conversations are restricted to parent accounts in the app. Personal reflections are accessible through the author's signed-in account, separate from the family journal and shared family export.

The service operator can access server databases and backups, including reflections and parent-only content. Account access controls are not end-to-end encryption. Anyone using an unlocked signed-in device may see that account's content.

Hosting and other services

The current app API is hosted on Railway. Server records and backups are processed by the hosting infrastructure. This public website is hosted through ChatGPT Sites. Final hosting locations, subprocessors, international-transfer arrangements and provider logging must be confirmed before this policy is adopted.

Little Wins has no advertising or analytics integration.

Security and access controls

The server code requires HTTPS for non-local deployments, stores passwords as salted scrypt hashes, and uses account and family-role checks to restrict access. Browser session cookies use HttpOnly and SameSite controls, with Secure enabled for HTTPS. Authenticated API responses are marked not to be cached. These safeguards do not prevent the operator from accessing stored records and backups. The release deployment and operational access arrangements still require verification.

Device storage and sessions

The app uses sign-in session cookies and device storage needed for its operation, including preferences and drafts. This website does not add an analytics script or a data-submission form.

Exports, retention and deletion

Parents can export shared family records. The shared export excludes personal reflections and parent-only conversations; it is not a complete personal-data export. Full personal export and account/family deletion are still being completed.

Clearing a saved reflection removes its current content; previous server backups may retain copies. Retention periods, backup expiry, treatment of shared records and request handling have not yet been finalised. See deletion status.

Children and your rights

The app includes parent and child accounts within invited families. Intended launch ages and parent authorisation arrangements are awaiting confirmation. The final policy must explain applicable access, correction, erasure, restriction, objection and portability rights, how to exercise them, and the relevant complaints route.

Before launch

This draft requires confirmed operator contact details, age arrangements, legal grounds, hosting and transfer details, retention and backup rules, and a verified rights-request process. It must be reviewed against the release implementation before use as the app's published privacy policy.