Privacy Policy for LitNow

Last Updated: May 08, 2025

Version: v1.0


1. Introduction

LitNow ("we," "our," or "us") is committed to safeguarding your privacy while delivering a secure, anonymous social video platform. LitNow is not designed for, marketed to, or intentionally used by minors. This Privacy Policy governs all data practices across our mobile application ("App"), including data collection, processing, storage, and sharing. By accessing or using LitNow, you acknowledge and consent to the practices described herein. Continued use of the App constitutes acceptance of future revisions to this policy.


2. Scope & Policy Updates

2.1 Effective Date

This policy takes effect on May 08, 2025.

2.2 Modifications

We may update this policy to reflect technological advancements, legal requirements, or operational changes. Material revisions will be communicated via:


3. Data Collection & Processing

3.1 Account System

Device-Generated Accounts

3.2 Data Categories

Data TypeCollection PurposeRetention Period
Device InformationAccount binding, fraud prevention (e.g., UUID, OS version, model)90 days post-account deletion
Usage LogsPerformance optimization (e.g., crash reports, latency metrics)30 days
User-Generated ContentService delivery (uploaded videos, picture)Deleted 30 days post-removal
Network MetadataConnectivity diagnostics (IP address, SSID)7 days

3.3 Explicit Exclusions

We DO NOT collect:


4. Permissions & Controls

4.1 Required Permissions

PermissionFunctionalityUser Control
CameraVideo recording/chatRevocable via device settings
MicrophoneSend voice message/Video chatRevocable via device settings
Network AccessContent delivery/real-time interactionsMandatory for core functionality

4.2 Optional Permissions

PermissionUse CaseOpt-In Mechanism
Storage AccessSaving/uploading media filesRuntime prompt with granular folder selection

5. Security & Encryption

5.1 Technical Safeguards

5.2 Operational Protocols


6. User Rights & Requests

6.1 Core Rights

6.2 Request Processing

  1. Email MgodinTeam@outlook.com with subject line "CCPA/GDPR Access Request"

  2. Include User ID (found in Settings > ID) for verification

  3. Fulfillment Timeline:

    • Access: Completed within 30 days

    • Complaints/Deletion: Investigated by human moderators within 72 hours


7. Third-Party Integrations & SDK Management

7.1 Core Functional SDKs

To enable real-time interactions, we integrate the following third-party SDKs after rigorous vendor assessments:

ProviderService TypeData ProcessedJurisdictionCompliance Measures
AgoraReal-Time Video/Audio- Device model, OS version - Network metrics (latency, packet loss) Ephemeral audio/video stream dataGlobal (Primary: Singapore)- ISO 27001 certified - GDPR-compliant data transfer (SCCs + supplementary measures) - CCPA-aligned data processing
RongCloudInstant Messaging- Anonymous user ID (hashed device identifier) - Message metadata (send/receive timestamps) - Encrypted message contentGlobal (Primary: Germany)- GDPR Article 28 Processor Terms - Data routed via EU/UK servers - Annual penetration testing by TÜV SÜD

Key Disclosures:

  1. Agora Media Processing:

    • Temporary stream data cached on edge nodes ≤72 hours

    • End-to-end encryption via AES-128-GCM with DTLS 1.2 key exchange

    • Data processing ceases immediately upon camera/microphone permission revocation

  2. RongCloud Messaging:

    • All messages use TLS 1.3 encryption in transit

    • Message retention: Message content is stored exclusively during transmission and the configured retention period, with complete cryptographic erasure from all server nodes upon expiration. Auto-deleted after 14 days by default (configurable to 1-30 days)

7.2 User Control Mechanisms

Operational Controls

  1. Regional Compliance Assurance:

    • All data processing adheres to jurisdictional requirements through:

      • EU/UK Users: Storage and transit within EEA-based infrastructure

      • Global Default: Encrypted transfer via ISO 27001-certified networks

  2. Data Flow Restrictions:

    • Service traffic automatically routes to geographically appropriate nodes based on:

      • User IP address (non-persistent geolocation lookup)

      • Legal entity registration country

Technical Safeguards

Advanced Requests

Submit via MgodinTeam@outlook.com with subject line "PRIVACY REQUEST":

7.3 Compliance Safeguards


8. Age Restrictions & Protections

8.1 Age Gate

8.2 Child Privacy Protections

We do not knowingly collect, store, or process data from minors. When potential child-related content is identified:

8.3 Children’s Safety Protocol

Our enhanced child protection framework is detailed in: LitNow Child Safety Protocol


9. International Data Transfers

We operate globally and may process data in locations outside your jurisdiction:


10. Contact & Dispute Resolution

10.1 General Inquiries

Primary Contact Methods:

10.2 Arbitration

Disputes resolved via binding arbitration under AAA(American Arbitration Association) rules, except for small claims (<$10,000).


Archive of Previous Versions:

Initial Privacy Policy (v1.0) in effect May 08, 2025. Archived versions available at here upon updates.