Privacy Policy

Our privacy policy and how we use your data

1. Introduction

This Privacy Policy explains how We Are Small ("we", "us", or "our") collects, uses, shares, and protects your personal information when you use our browser-based 3D Solar System explorer and related services ("Service").

We are committed to protecting your privacy and handling your data with transparency. This policy applies to all users of our Service, including account holders and visitors to our website.

2. Information We Collect

2.1 Information You Provide

Direct Data Collection

  • Account InformationName, email address, and password when you register for an account
  • Profile InformationOptional profile photo and display preferences
  • Payment InformationBilling details processed securely by Stripe when you purchase premium access (we do not store your full card details)
  • CommunicationsMessages sent to our support email, feedback, and any survey responses

2.2 Information Collected Automatically

Automatic Data Collection

  • Usage DataFeatures used, actions taken within the 3D explorer, and interaction patterns
  • Device InformationDevice type, operating system, browser type, WebGL capabilities, and screen resolution
  • Log DataIP addresses, access times, pages viewed, and referring URLs
  • Cookies and Similar TechnologiesSee our Cookie Policy for details

2.3 Information from Third Parties

Third-Party Data Sources

  • Single Sign-On ProvidersIf you log in via Google or other SSO providers through Supabase, we receive your name and email address

3. How We Use Your Information

Service Delivery

  • • Provide, maintain, and improve the 3D explorer
  • • Process premium purchases and manage your account
  • • Deliver premium content and features
  • • Provide customer support

Communication

  • • Send service-related notices and updates
  • • Respond to support requests
  • • Send marketing communications (with consent)

Improvement & Analytics

  • • Analyze usage patterns to improve features
  • • Optimize 3D rendering performance
  • • Monitor and prevent technical issues

Legal & Security

  • • Protect against fraud and unauthorized access
  • • Enforce our Terms of Service
  • • Comply with legal obligations

5. How We Share Your Information

We do not sell your personal information.

We may share information with:

5.1 Service Providers

Third parties who perform services on our behalf:

  • Supabase (authentication, database, and data storage)
  • Stripe (payment processing)
  • Cloudflare (CDN, hosting, and content delivery)

These providers are contractually bound to protect your data and use it only for specified purposes.

5.2 Business Transfers

In connection with a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any change in ownership or use of your information.

5.3 Legal Requirements

We may disclose information if required by law or to:

  • Comply with legal process or government requests
  • Protect our rights, privacy, safety, or property
  • Enforce our Terms of Service
  • Protect against legal liability

6. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. After account termination:

Account Data
90 days

Unless legally required to retain

Purchase Records
7 years

For tax and legal purposes

Billing Records
7 years

For tax and legal purposes

Aggregated Data
Indefinite

Retained in anonymized form only

7. Data Security

We implement industry-standard security measures to protect your data:

Encryption in transit (TLS) and at rest
Role-based access controls and authentication via Supabase
Secure payment processing via Stripe (PCI-DSS compliant)
Regular security reviews and updates
Row-level security policies on all database tables
Incident response procedures

While we take extensive precautions, no system is completely secure. We encourage you to use strong passwords and enable multi-factor authentication when available.

8. International Data Transfers

We operate globally and may transfer your data to countries outside your residence. For transfers from the EEA, UK, or Switzerland, we use:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Other legally recognized transfer mechanisms

9. Your Rights

9.1 All Users

AccessRequest a copy of your personal data
CorrectionUpdate inaccurate information
DeletionRequest deletion of your data
Data PortabilityExport your data in a machine-readable format
Opt-OutUnsubscribe from marketing communications

9.2 EEA/UK/Swiss Residents (GDPR)

  • Right to restrict processing
  • Right to object to processing based on legitimate interests
  • Right to withdraw consent at any time
  • Right to lodge a complaint with a supervisory authority

9.3 California Residents (CCPA/CPRA)

  • Right to know what personal information we collect and share
  • Right to request deletion of personal information
  • Right to opt-out of "sale" or "sharing" of personal information (we do not sell your data)
  • Right to non-discrimination for exercising your rights

To exercise these rights, contact us at hello@wearesmall.cloud or use the settings in your account.

10. Children's Privacy

We Are Small is an educational tool suitable for children, but account creation requires users to be at least 13 years old. Children under 13 may use the free 3D Solar System explorer without creating an account. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information through account registration, please contact us immediately.

11. Third-Party Links

Our Service may contain links to third-party websites. We are not responsible for their privacy practices. We encourage you to review their privacy policies before providing personal information.

12. Updates to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes via email or through the Service. Your continued use after such notification constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us: