Privacy Policy & Legal Notice
What Data We Collect
We collect the minimum amount of information needed to provide the service:
- Discord OAuth data — When you sign in with Discord, we receive your Discord user ID, username, email, and avatar. We do not receive your password or message history. This is used solely to identify your session.
- Session token — A short-lived server-side session is maintained to keep you logged in. This token holds your Discord ID, display name, and any access roles. It is not shared with third parties.
We do not collect analytics, sell any data, or use third-party advertising networks.
Your Progress Data Stays on Your Device
All progress data — item ownership, mastery states, resource counts, event timers, and any other personal tracking — is stored locally on your device only, using encrypted local storage.
This data never leaves your device. It is not transmitted to our servers, not backed up to any cloud, and not accessible to us. If you uninstall the app or use the delete all data functionality in the app, your data is gone — we have no copy of it.
About the Desktop App (Windows)
Little Genius is a Windows desktop application. It runs on your machine alongside the game. Whatever it does to keep your data in sync is strictly read-only, entirely passive, and has no effect on gameplay whatsoever.
The desktop app does not:
- Touch or modify any game files
- Inject code into the game process
- Exploit any vulnerability
- Transmit personal data to any external server
- Access anything beyond what you explicitly enter or authorize yourself
All data you enter or sync remains on your device. No credentials are stored permanently; any session information is held in memory only and cleared on exit.
Security
We have designed Little Genius to be as safe as a companion app of this kind can reasonably be:
- All local data is encrypted at rest using the browser's secure storage APIs
- No plaintext credentials or tokens are written to disk
- Session tokens are short-lived and invalidated on logout
- The codebase does not contain any obfuscated or minified third-party scripts that we cannot account for
- The desktop binary is distributed via signed GitHub Releases and supports auto-update over HTTPS
No system is perfect. If you discover a security issue, please contact us privately via our Discord server before disclosing publicly.
Authentication
Currently, Little Genius requires a Discord account to sign in as well as require you to be IN our discord server. This is used as a security layer to limit access during open beta and to prevent abuse of server resources. We do not use your Discord identity for any other purpose.
We are actively exploring native Avakot account registration as an alternative, which would remove the dependency on Discord entirely. When that is available, you will be able to migrate or register without a Discord account.
We do not share your Discord identity with any third party, nor do we post to Discord on your behalf.
Cookies & Local Storage
We use a single session cookie to maintain your login state. No tracking cookies, no advertising cookies, no cross-site trackers.
Local browser storage (IndexedDB) is used exclusively for your personal progress data as described above.
Age Requirements
Little Genius is not directed at children under 13. Because sign-in requires a Discord account, Discord's own age requirements (13+, or 16+ in some jurisdictions) apply. We do not knowingly collect information from anyone under those ages.
Changes to This Policy
If this policy changes in a meaningful way, we will announce it in our Discord server. The "last updated" date at the top of this page will always reflect the most recent revision.
Contact
For privacy questions, data concerns, IP takedown requests, or security disclosures:
- Discord: discord.gg/UzmSvvkhXw
- Project home: lg.avakot.org