Privacy Policy

Updated: 25 August 2026
Effective: 25 August 2026

This Privacy Policy applies when you select the Singapore service infrastructure in Acorn Steps. Acorn Steps is offered under the LumaHart brand and is operated by Suzhou Luzhu Network Technology Co., Ltd. ("we", "us", or "our"), which is responsible for the personal data described in this Policy.

Changing the display language changes only the language in which information is shown. It does not change the service infrastructure you selected. We will not silently move you to a different service region or change who controls an account, a purchase, or a child's data.

1. Before you use the service

Please read this Policy together with the Children's Privacy Policy where a child is involved. A parent or guardian controls the account, purchases, and rights relating to a child's data. Features that do not require an account may be used anonymously first. A child must not independently make purchase, consent, or data-rights decisions.

If you do not agree with this Policy, do not select or continue using the Singapore service infrastructure.

2. Personal data we process and why

We process only the data reasonably needed for the purposes described below. The data available in a particular session depends on the features you choose to use.

2.1 Anonymous use and service data

Some features can be used before an account is linked. We may assign an app-scoped identifier and process records, progress, preferences, or other content that you choose to create through the service. We use this data to provide the requested features, keep the service state consistent, and support recovery or synchronisation where available.

2.2 Account and authentication data

If a parent or guardian chooses an account-based feature or Sign in with Apple, we process the account identifier, app identifier, authentication result, and the information Apple makes available following the user's authorisation. We use this data to create or link the account, authenticate the user, prevent unauthorised access, and restore eligible service data.

The Singapore service region does not enable China-region WeChat login or mobile-number login.

2.3 Child-profile and family-managed data

A parent or guardian may create or manage a child profile and related service records. This may include profile information, settings, progress, and content entered or generated through the features the family chooses to use. We process this data to provide those features and to allow the parent or guardian to manage the child's experience and exercise the child's data rights.

2.4 Purchase data

When a parent or guardian makes a purchase through Apple, Apple processes the payment credentials. We may receive and store product, transaction, receipt-validation, purchase-status, and entitlement information needed to verify the purchase, provide the purchased feature, prevent fraud, and handle support or accounting matters. We do not receive the full payment-card number from Apple.

2.5 Device, network, and security data

We may process the app version, operating-system and device information, language and time-zone settings, network status, IP address, request time, error or diagnostic information, and security events. We use this data to deliver requests, maintain service reliability, investigate faults, prevent abuse, and protect accounts and data.

The Singapore service region does not enable China-region advertising, Umeng analytics, or China domestic device-vendor remote-push services. We do not use personal data in this region for behavioural advertising, marketing email, third-party product recommendations, or remote marketing notifications.

2.6 Support, privacy, and account-deletion requests

When you contact us or submit an account-deletion request, we process the information needed to handle the request. For an account-deletion request, this currently includes the user and app identifiers, reason category, details you provide, optional contact information, IP address, user agent, device information, request status, review information, and audit records.

3. Device permissions

If a feature needs access to a protected device capability, the app will request the relevant system permission when you choose that feature. You may refuse or later withdraw a permission in the device settings. The affected feature may then be unavailable, but unrelated features should remain available where technically possible.

4. Service providers and disclosures

We disclose or make personal data available only where needed for the purposes described in this Policy. We do not disclose personal data for behavioural advertising or third-party marketing in the Singapore service region.

4.1 Apple

Apple provides Sign in with Apple and in-app purchase services. Apple processes data under its own terms and privacy policy. We receive only the authentication, transaction, and entitlement information needed by Acorn Steps for the purposes described above.

4.2 Administrator collaboration service

When the administrator-notification service is configured, information needed to review an account-deletion request may be sent to an authorised Feishu/Lark collaboration channel. This may include the user identifier, app identifier, reason, request details, and optional contact information. Designated administrators use the information only to receive, review, and audit the request.

4.3 Authorised personnel and professional support

Authorised personnel may access necessary Singapore-region data from outside Singapore for system operations, customer support, security, and account-deletion handling. Access is limited by role, confidentiality duties, access controls, and audit measures. Where an external professional adviser or service provider is needed, we limit the data and purpose and require appropriate protection.

4.4 Legal requirements and corporate changes

We may disclose data where required by applicable law, legal process, or a competent authority, or where reasonably necessary to protect users, the service, or legal rights. If a merger, acquisition, restructuring, or transfer of the relevant business affects control of personal data, we will require the recipient to protect the data and provide any notice or choice required by applicable law.

5. Storage and access across borders

Core business data for the Singapore service region is stored in Singapore. Database backups and disaster-recovery copies are also maintained in Singapore.

As described above, authorised personnel outside Singapore may remotely access necessary data. A remote access session or a service-provider disclosure can constitute processing outside Singapore even when the primary database remains in Singapore. We therefore do not represent that all processing occurs only in Singapore. Remote access must remain limited to authorised purposes and personnel and must be protected as required by applicable law.

6. Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy or to meet applicable legal and reasonable business needs.

When the relevant purposes have been fulfilled and retention is no longer necessary for legal or business purposes, we will delete the personal data or remove the means by which it can be associated with an identifiable individual. We do not apply a general six-month minimum to all Singapore-region personal data.

7. Children's data

For the parental-consent rules in this Policy, a child under 13 years of age requires the involvement of a parent or guardian. Singapore data-protection guidance also treats individuals under 18 as children for certain safeguards; this Policy does not reduce any protection that applies to users aged 13 to 17. Where consent is required for a child under 13, we provide the relevant notice to and obtain consent from the child's parent or guardian before processing the child's personal data. The parent or guardian manages the account, purchases, child profile, and requests to access, correct, delete, or otherwise control the child's data. Where we communicate directly with a child, we use language appropriate to the child's age and understanding.

The Children's Privacy Policy provides additional information. If we learn that a child under 13 provided personal data without the required parent or guardian involvement, please contact us so that we can review the circumstances and take appropriate action.

8. Your rights and choices

Subject to applicable law and relevant exceptions, a parent or guardian may:

Contact clientservice@deardeer.net.cn to exercise these rights when the requested action is not available in the app. We may need information reasonably necessary to verify the requester's identity and authority, particularly for requests relating to a child. Withdrawing consent does not affect processing already carried out lawfully, and some features may no longer be available after withdrawal.

9. Account deletion

A parent or guardian may submit an account-deletion request in the app settings. After the request is accepted, it enters review and the app signs out of the current session. We will complete the review within 7 calendar days after receiving the request.

This seven-day period is a review period. It does not mean that every server-side record has been immediately and physically deleted. After approval, access to the account is disabled under the current process. Other personal data is deleted or de-identified under Section 6 when it is no longer necessary for legal or business purposes. Purchase, deletion-request, security, dispute, and audit records that remain necessary may be retained.

Clearing the app's local data or uninstalling the app does not delete server-side data. An account-deletion request is also separate from cancelling an Apple purchase, requesting a refund, or managing any entitlement handled by Apple.

10. Security

We use reasonable administrative and technical measures appropriate to the nature of the data and the risks involved. These measures include limiting access to authorised roles, confidentiality obligations, access review and logging, service-security controls, and incident-handling procedures. No storage or transmission method is completely secure, so we cannot guarantee absolute security.

11. Changes to this Policy

We may update this Policy when the service, data practices, or applicable requirements change. We will provide notice and obtain consent or another lawful basis where required before materially different processing begins. Changing the interface language alone does not change the applicable service region or privacy policy.

The final approved page will show its update and effective dates. Internal region and revision identifiers are maintained for consent evidence, integrity checks, and rollback; they are not intended as the main user-facing title.

12. Contact

Data controller and operator: Suzhou Luzhu Network Technology Co., Ltd.
Brand: LumaHart
Data protection and privacy contact: clientservice@deardeer.net.cn

This contact channel receives privacy, children's-data, access, correction, and deletion requests.

13. Language

This Policy is available in English, Simplified Chinese, Traditional Chinese, Japanese, Korean, Spanish (Spain), French (France), German (Germany), Portuguese (Brazil), Italian, Arabic (Saudi Arabia), Hindi, Indonesian, Thai, Vietnamese, Turkish, and Russian. We will take reasonable steps to keep the substance of all language versions consistent. If an irreconcilable difference of interpretation arises from translation, the English version will prevail to the extent permitted by applicable law.