1. The Short Version
A child can play all normal Lady Beetle gameplay without signing in. Local progress and settings continue to work offline. A parent or guardian may choose an account to sync progress and use per-level leaderboards.
Choosing Google or Apple establishes only an authentication session; no player data is uploaded at that point. Before the first account upload, a separate screen collects the public nickname, age and country, states the data use, and records the versioned account acknowledgement accounts-2026-07-v1, which a parent or guardian gives by continuing. Profile changes, Reset Progress, sign-out and account deletion each remain behind an adult-control gate. Accepting an earlier policy that described a no-account game does not count as consent to this feature.
There are no advertisements, behavioural advertising profiles, purchases, chat, direct messaging, free-form biographies, player search, or precise-location access. Leaderboard names and scores are public to signed-in players, as described below.
2. Who Operates Lady Beetle
Lady Beetle is operated by PPLST Tech, India. Parent, guardian, privacy, deletion, and grievance requests can be sent to admin@pplsttech.com. Parents can also follow the account deletion instructions.
Postal address: Office No. 933, B-3, Spaze I.T. Park, Sector 49,
Gurugram, Haryana 122018, India.
Telephone: +91 99107 91039 or
+91 84280 58239.
Grievance Officer and privacy contact: Arjun Bhilare.
3. Information Used by the Game
| Information | How it is used | Where |
|---|---|---|
| Tilt readings | Move the beetle while playing. They are not retained or uploaded by Lady Beetle. | Device memory |
| Settings and signed-out progress | Audio, haptics, tilt choice, tutorial state, unlocked levels, active level, stars, and best times. | Device storage |
| Player details entered in Settings | A parent may enter a name, age and country in Settings without creating an account. While signed out these stay on the device, are not transmitted to us or anyone else, and are removed when the app is uninstalled. They are used to fill in the profile if an account is later created. | Device storage |
| Account and provider record | Firebase user ID, Google or Apple provider, account lifecycle, and consent records. Firebase Authentication may retain an email or provider detail supplied by Google or Apple. It is never shown on leaderboard rows. | Firebase Authentication and restricted account records |
| Player profile | Generated or parent-edited public nickname, confirmed two-letter country, integer age, age-setting and update timestamps, current age, and policy versions. | Firebase Cloud Firestore |
| Cloud progress and scores | Unlocked and active level, maximum stars, local best times, one best leaderboard time and same-run stars for each level, achievement time, import status, and retry identifiers. | Firebase Cloud Firestore |
| App integrity and service data | Firebase App Check attestation tokens and limited technical request information help protect the service and diagnose failures. | Google/Firebase services |
Lady Beetle does not ask for a date of birth. The age is an integer. It increases on the server on each calendar anniversary of the date it was set. A parent can correct age or country.
4. Country Suggestion and Location
The app reads the device locale’s region code to suggest a country, falls back to India (IN) when no valid region is available, and asks a parent to confirm it. The locale suggestion does not request GPS, precise location, contacts, or a location permission. The confirmed country is uploaded because it is a genuine leaderboard ranking attribute.
5. What Other Players Can See
Signed-in players can view per-level rankings. A leaderboard row shows only rank, public nickname, formatted completion time, optional stars from that same run, and a “you” highlight for the current player. Rows do not show email, provider identifier, Firebase user ID, raw age, or country.
Not every name on a leaderboard is a real player. While a board holds fewer than twenty real times, Lady Beetle fills the remaining places with fictional entries so that a new player has someone to race. These entries are invented by the app on the device, are not other children, and are presented in the same style as real rows. They are never stored, never uploaded, and never counted in anyone’s statistics; their times are generated to sit around the current player’s own best time. Once twenty or more real times exist for a board, no fictional entries appear on it at all. No real child’s rank, time or nickname is altered by this.
Country and age still affect server-side selection. Boards can show My Country or Global, independently combined with My Age or All Ages. A player’s selection of which board to view is saved locally and does not alter the player profile.
Nicknames are trimmed and checked server-side for length, characters, control codes, and obvious contact-like content. Invalid values receive a generated friendly nickname. Version 1 has no chat, messaging, player discovery, public report button, or moderation console. A parent can report a concern through Support; automated checks cannot catch every inappropriate or identifying name.
6. Why We Use This Information
- Authenticate the optional player chosen by a parent.
- Merge and synchronize game progress across devices.
- Submit, rank, paginate, and display one best score per player and level.
- Keep age and country cohorts accurate after corrections and anniversaries.
- Apply consent versions, rate limits, security rules, and account actions.
- Prevent obvious malformed or implausible score submissions and investigate service failures.
App Check and score bounds reduce automated abuse, but a client-timed game cannot be made completely cheat-proof. We do not claim that leaderboard times are independently verified.
7. Service Providers and International Processing
We use Google Firebase for Authentication, Cloud Firestore, Cloud Functions, App Check, and Hosting. Google Sign-In is available on Android and iOS; Sign in with Apple is also available on iOS. These providers process authentication and technical service data under their own terms and privacy notices.
Data may be processed in countries other than the player’s own, depending on the verified Firebase project location and provider infrastructure. We do not sell player data and do not use it for third-party advertising. We may disclose information when required by law, to protect safety or the service, or to processors working for us under appropriate obligations.
This policy website is served by Firebase Hosting. Hosting and network providers may process ordinary request information such as IP address, time, requested path, and browser metadata for delivery and security. The Site has no advertising, account form, or third-party analytics script.
8. Parent Controls, Retention, and Deletion
- Sign out: cloud data and local progress remain. Signing in again merges them using best-result rules.
- Reset Progress: after adult confirmation and recent authentication, local progress, cloud progress, and the player’s leaderboard entries are removed; the account and profile remain.
- Delete Account: after adult confirmation and recent authentication, Firebase Authentication, private and public profile data, consent records, cloud progress, scores, imports, and other user-linked service records are deleted.
- Apple deletion: when applicable, the app obtains a fresh one-use Apple authorization code and asks Firebase Authentication to revoke Apple authorization before the deletion Function removes the account and linked cloud records.
- Local mode after deletion: deletion returns the device to signed-out play and does not automatically erase the device’s local progress. Reset first if local progress should also be erased.
Operational logs, backups, fraud/security records, or records we must keep by law may remain for a limited period before routine deletion. A failed deletion is kept retryable while the parent is still authenticated; the authentication record is deleted last.
9. Provider Choice
One Firebase account represents one Lady Beetle player. Google/Apple linking and automatic account merging are not supported. The same provider must be used on every device. If Firebase reports a provider conflict, the app stops and asks the parent to use the original provider rather than silently creating or merging identities.
10. Children and Parental Choice
Lady Beetle is child-directed. Account setup and material account changes are designed for a parent or guardian and use the app’s adult-control approach. That gate reduces accidental child access; it is not government-ID verification and does not replace adult supervision.
A parent may decline account setup and keep using local play, ask what information is held, correct profile data, reset it, delete the account, withdraw consent by deleting the account, or raise a complaint. Contact us from an adult email address and do not send a child’s full name, photograph, voice, school, precise location, or other unnecessary details.
11. Security
The app uses authenticated server functions, default-deny Firestore client rules, transaction-safe best-score replacement, bounded requests, rate limits, App Check, server timestamps, and separate private and leaderboard-safe records. No system is perfectly secure. If you believe an account or public nickname creates a risk, contact us promptly.
12. Support Correspondence
If an adult emails support, we receive the address and information they choose to provide. We use it to answer the request, protect the service, and meet legal obligations, then retain it only as reasonably needed. Please do not include unnecessary information about a child.
13. Privacy Requests and Complaints
Depending on where you live, applicable law may give you rights to access, correct, delete, restrict, object, withdraw consent, complain, or receive information about processing. We may need to verify that the requester controls the relevant account. Contact admin@pplsttech.com. You may also contact the relevant data protection authority.
14. Changes to This Notice
We will show a new effective date and policy version when this notice changes. A material new account use requires a fresh versioned acknowledgement before further account upload; prior acceptance is not silently carried forward.
| Version | Effective | Summary |
|---|---|---|
| privacy-2026-07-v2 | 28 July 2026 | Added optional Firebase accounts, cloud progress, public nicknames, per-level leaderboards, age/country cohorts, parent controls, and account deletion. Disclosed that sparse leaderboards are filled with fictional entries. |
| 1.1 | 27 July 2026 | Previous local-only, no-account notice. |
This document describes product behaviour and is not a statement that it has received independent legal review.