English
Privacy Policy and Legal Notice
What data we collect
We collect the minimum amount of information needed to provide the service:
- Discord OAuth data - When you sign in with Discord, we receive your Discord user ID, username, email, and avatar. We do not receive your password or message history. This is used solely to identify your session.
- Session token - A short-lived server-side session is maintained to keep you logged in. This token holds your Discord ID, display name, and any access roles. It is not shared with third parties.
We do not collect analytics, sell any data, or use third-party advertising networks.
Your progress data stays on your device
All progress data - item ownership, mastery states, resource counts, event timers, and any other personal tracking - is stored locally on your device only, using encrypted local storage.
This data never leaves your device. It is not transmitted to our servers, not backed up to any cloud, and not accessible to us. If you uninstall the app or use the delete-all-data functionality in the app, your data is gone - we have no copy of it.
About the desktop app (Windows)
Little Genius is a Windows desktop application. It runs on your machine alongside the game. Whatever it does to keep your data in sync is strictly read-only, entirely passive, and has no effect on gameplay whatsoever.
The desktop app does not:
- Touch or modify any game files
- Inject code into the game process
- Exploit any vulnerability
- Transmit personal data to any external server
- Access anything beyond what you explicitly enter or authorize yourself
All data you enter or sync remains on your device. No credentials are stored permanently; any session information is held in memory only and cleared on exit.
The desktop app does require an internet connection, as it needs to directly retrieve data from the Avakot API. The app cannot run offline due to this interaction.
Security
We have designed Little Genius to be as safe as a companion app of this kind can reasonably be:
- All local data is encrypted at rest using the platform's secure storage APIs
- No plaintext credentials or tokens are written to disk
- Session tokens are short-lived and invalidated on logout
- The codebase does not contain obfuscated or minified third-party scripts that we cannot account for
- The desktop binary is distributed via signed GitHub Releases and supports auto-update over HTTPS
No system is perfect. If you discover a security issue, please contact us privately via our Discord server before disclosing publicly.
Authentication
Currently, Little Genius requires a Discord account to sign in and you must also be a member of our Discord server. This acts as a security layer during the open beta and helps limit abuse of shared infrastructure. We do not use your Discord identity for any other purpose.
We are actively exploring native Avakot account registration as an alternative, which would remove the dependency on Discord entirely. When that is available, you will be able to migrate or register without a Discord account.
We do not share your Discord identity with any third party, nor do we post to Discord on your behalf.
Cookies and local storage
We use a single session cookie to maintain your login state. No tracking cookies, no advertising cookies, and no cross-site trackers.
Local browser storage (IndexedDB) is used exclusively for your personal progress data as described above.
Age requirements
Little Genius is not directed at children under 13. Because sign-in requires a Discord account, Discord's own age requirements apply. We do not knowingly collect information from anyone under those ages.
Changes to this policy
If this policy changes in a meaningful way, we will announce it in our Discord server. The last updated date at the top of this page will always reflect the most recent revision.
Contact
For privacy questions, data concerns, IP takedown requests, or security disclosures:
- Discord: discord.gg/UzmSvvkhXw
- Project home: lg.avakot.org