Before you create an account
Saved and Maybe choices are stored in this browser, along with name IDs, choice times, and the page where you chose them. The device draft expires after 30 days. Browser storage can be cleared or lost, especially in private browsing. You can clear it from the shortlist drawer.
After sign-in
Clerk provides sign-in and stores the identity details you give it. Little Names stores your Clerk account ID, display name, Saved/Maybe/Pass choices and timestamps, and partner connection in a Cloudflare D1 database. Device choices are attached to the account only after sign-in and confirmed import. Your earlier account decisions are kept unless you deliberately change them.
Sharing with a partner
Only your currently connected partner can view your Saved and Maybe choices and mutual matches. Passed names remain private. Invitations expire after seven days and can be used once. Disconnect removes shared access and keeps each person’s independent choices.
Deleting your account
In the app, open Account settings and choose Delete account. This removes your application choices and partnership and asks Clerk to remove your sign-in identity. If that last step fails, retry to finish it. Your partner’s personal choices remain. A minimal hashed deletion receipt prevents an old signed-in session from recreating the deleted data.
Infrastructure and browser requests
Cloudflare hosts the site and API; Clerk supplies authentication. These services process technical request and authentication information. The site currently loads its fonts from Google Fonts. This release has no advertising pixels. Optional first-party product measurement is disabled globally in this preview. If enabled for launch, each person must choose Allow optional product measurement in Account settings; it is off by default. Both connected accounts must opt in for couple measurement. It records connection and match times, reviewed name IDs during the seven-day activation window, confirmed shortlist imports and invitations, and a deliberate list return on Days 7–14. Copy, share and iPhone handoff clicks, when offered, describe actions taken rather than proof of sending, opening or installation. It does not store your choice decisions in the measurement tables or send your shortlist to an advertising tool. Service providers may keep operational logs under their own policies; deletion from active application tables does not promise instantaneous removal from every provider backup.
Optional reading history
If you allow optional browser reading measurement, it records canonical content pages and save/prompt actions using a first-party HttpOnly cookie. A name-profile path combined with a save action can reveal a name you read or saved. The database stores a hash of the cookie identifier, controlled source labels and server observation times; it does not store raw referrer queries, your full shortlist or passed names in that history. The browser identifier expires after 30 days, and reading history is pruned after 30 days of inactivity. Associating that history with a verified account requires a separate account opt-in; signing in alone does not grant it. Minimal verified signup/source and first-action receipts last at most 365 days. Browser withdrawal removes its history and related attribution, while account withdrawal or deletion removes owned observations. The article-measurement control is optional and defaults off. Collection remains disabled in this preview. Browser history attaches to an account only after independent account opt-in and explicit confirmation.
Your measurement choice and naming status
You can turn optional measurement off in Account settings. This removes your measurement history and related couple records while keeping both personal shortlists. A later opt-in starts fresh observed history. Taking a break or marking naming finished preserves your lists; actions while paused or finished do not count as engagement. No naming email or push reminders are currently sent.
Retention and contact
Optional measurement review IDs are pruned after 14 days; detailed connection attempts after 365 days; aggregate daily operation counters after 30 days. Minimal first-connection, first-activation, first-match and return facts remain while the consenting accounts exist, so reconnecting does not create another newly acquired couple. Deletion or either partner withdrawing removes that couple history. Account data remains until you remove choices or delete the account. Device drafts expire after 30 days. See support for deletion instructions and the current contact status.
This policy describes the web implementation prepared on 2026-10-04. Privacy review and a working support contact are required before enabling optional collection or launching the native app. The native preview uses Clerk authentication, SecureStore for tokens and a seven-day owner-scoped read cache; its SDK inventory and final App Store privacy answers are still under review.