Privacy Policy
Effective 21 August 2026. Last updated 21 August 2026.
This policy describes what the app actually does, taken from its source code rather than from a template. See also What this policy assumes.
The short version, for parents.
Meerkat Universe has no advertising, no third-party analytics, and no in-app purchases. It cannot access the camera, microphone, location, photos or contacts. Children cannot type messages to each other, and cannot type a name — names are chosen from a fixed list we wrote.
A player under 13 gets the whole game and sends us nothing at all — their progress lives on the device, and there is no account to create. Players 13 and over can optionally sign in, which is what lets progress survive a lost or replaced device.
1. Who is responsible for your data
Meerkat Universe is operated by Or Shamir, an individual trading as the developer of the app ("we", "us").
Contact for any privacy question or request:
- Email: meerkatuniverse.support@gmail.com
- Postal address: available on request by email. Meerkat Universe is developed by one person rather than a company, so the email above reaches the operator directly and is the fastest route for any request under this policy.
For the purposes of the UK and EU General Data Protection Regulation, we are the data controller for the information described here.
2. Who this app is for, and what changes by age
Meerkat Universe is a game anyone can play, and it is designed to appeal to young children. We treat it as directed to children for legal purposes whatever store category it appears in, and build it to the requirements that follow — the United States Children's Online Privacy Protection Act (COPPA), the UK Age Appropriate Design Code, and Article 8 of the UK and EU GDPR.
The app asks once how old the player is, and that answer changes what it collects. We do not store a date of birth — only whether the player told us they are under 13.
| If the player is… | What happens |
|---|---|
| Under 13 | The whole game, and nothing personal ever leaves the device. Every level, the shop and all the tutorials, with progress saved on the device itself. No account, no cloud save, no leaderboard and no friends — so there is nothing about that child on our servers at all. |
| 13 or over | The same game, and optionally an account: cloud save so progress survives a lost device, and the Social Hub described in section 3.3. |
Why it works this way. Asking a player's age is not the same as asking a parent's permission, and we are not willing to treat it as though it were. So instead of collecting a child's information and then trying to justify it, the app simply does not collect any: under 13, there is no account to create and no data to send. If the answer is corrected later to under 13, any account is signed out and the published profile removed.
An assumption a reviewer should check. This design rests on the position that collecting nothing personal from a self-declared under-13 player requires no verifiable parental consent, because there is nothing to consent to. That is the intended reading of COPPA's requirements: the Act governs the collection of personal information from children, and this app collects none from them.
3. What the app collects, and why
3.1 If your child plays without signing in
Everything stays on the device. Game progress, sound settings and a randomly generated player identifier are stored locally and are never sent to us. We hold no information about a player who has not signed in, other than the anonymous product and crash data in sections 3.4 and 3.5.
3.2 If your child signs in (13 and over)
Signing in with an Apple or Google account creates an account identifier, and lets progress be saved so it survives a lost, replaced or reset device.
| What | Why |
|---|---|
| An account identifier from Apple or Google | To recognise the same player across devices |
| Game progress — level reached, in-game Beetles earned and spent, items owned | So progress is not lost with the device |
| A device installation identifier and revision counters | To merge saves correctly and detect conflicts between devices |
3.3 If your child uses the Social Hub
The Social Hub lets a child appear on a leaderboard and add friends. Using it publishes a small profile that other players can see:
| What | Notes |
|---|---|
| A display name | Chosen from a fixed list we wrote. A child cannot type a name, so a name can never contain personal information or anything we have not approved in advance. |
| A friend code | A randomly generated code used to add a friend. It identifies a player within the game only. |
| The level reached | What the leaderboard ranks. |
| A chosen picture | Selected from a fixed set of illustrations in the app. Not a photograph, and not uploaded. |
| Friend requests and friendships | Which players are connected to which. |
There is no messaging of any kind in Meerkat Universe. Children cannot send each other text, images, audio or anything else. There is no chat, no comments, no profile text and no free-text field anywhere in the app.
3.4 Crash reports
When the app crashes, a diagnostic report is sent so the fault can be fixed. It records what the software was doing — the app version, which screen was open, which game level was running, whether the device was online — and never who was playing. No name, friend code or account identifier is attached to a crash report.
3.5 Product measurement
The app records a small number of events describing how the game itself is going: a round started, a round finished, an item bought with in-game Beetles. These are sent to our own server, not to any third-party analytics service.
Two design choices are worth stating plainly, because they are enforced in the code rather than by policy. The events a build may send are restricted to a fixed list written into the app, so a new kind of event cannot be added without changing the app. And the app sends no identifier with them at all — there is no field for a name, friend code, account or device in the data that leaves the device. Where a player is signed in, our server records the account identifier so that a deletion request can find and remove the events.
4. What we never collect
- No advertising, and no advertising identifiers. The app contains no ads and no ad network.
- No third-party analytics or behavioural profiling. This is enforced by an automated check that fails the build if such a package is ever added.
- No location data.
- No access to the camera, microphone, photos, contacts or files. The app requests none of these permissions.
- No free text. There is nowhere in the app a child can type something that another person will see.
- No purchases. There are no in-app purchases and no payment of any kind. Beetles are earned by playing and have no monetary value.
- No selling or sharing of data. We do not sell personal information, and we do not share it for advertising.
5. Our legal bases (UK and EU)
| Purpose | Legal basis |
|---|---|
| Saving and restoring game progress for a signed-in player | Performance of a contract — the service the user asked for |
| The Social Hub: leaderboard, friend codes, friends | Consent, given by the player — who must have declared they are 13 or over to reach the Social Hub at all |
| Crash diagnostics | Legitimate interests — keeping the app working and safe for children |
| Product measurement | Legitimate interests — understanding whether the game works as intended |
| Security and abuse prevention | Legitimate interests |
Where consent is the basis, it can be withdrawn at any time by deleting the account (section 9), which removes the published profile and the friendships with it.
6. Parents: your rights and how to use them
If you are the parent or guardian of a child who plays Meerkat Universe, you may at any time:
- See what we hold about your child.
- Correct anything that is wrong.
- Delete the account and everything held with it — see section 9.
- Withdraw consent to the Social Hub.
- Refuse further collection — you may ask us to delete what we hold and to stop collecting anything more, while your child continues to play offline.
- Receive a copy of the data in a portable form.
- Complain to your local data protection authority. In the UK that is the Information Commissioner's Office; in the EU it is your national supervisory authority.
To make any of these requests, email meerkatuniverse.support@gmail.com. We may need to ask a question to confirm the request relates to your child's account — usually the friend code shown in the app is enough. We will respond within one month.
7. Who processes data for us
We use Google's Firebase platform to run the service. Google acts as our processor, handling data on our instructions and not for its own purposes:
- Firebase Authentication — sign-in with Apple or Google
- Cloud Firestore and Cloud Functions — saved progress, the Social Hub, product events
- Firebase Crashlytics — crash diagnostics
- Firebase App Check — confirming requests come from a genuine copy of the app
Apple and Google also act as controllers in their own right for the sign-in you choose and for the app store you downloaded from. Their own privacy policies apply to that.
We do not use any other third party, and we have no advertising, marketing or data-broker relationships.
8. Where data is stored, and for how long
Data is stored on Google's infrastructure and may be processed outside your country, including in the United States. Transfers rely on the safeguards Google provides for Firebase, including the European Commission's Standard Contractual Clauses.
| What | Kept for |
|---|---|
| Saved progress and the published profile | Until the account is deleted |
| Friend requests and friendships | Until the account is deleted, or the friend is removed |
| Product events | 400 days, then deleted automatically |
| Crash reports | As long as Firebase Crashlytics retains them (currently 90 days) |
| Data on the device | Until the app is deleted or the player signs out |
9. Deleting an account
Account deletion is available in the app itself: Settings → Account → Delete Account. It removes the saved progress, the published profile, the friend code and the friendships. It cannot be undone.
You can also ask us to delete an account by email, at meerkatuniverse.support@gmail.com. See Delete Account for the full description.
10. Security
Data in transit is encrypted. Access to saved progress is restricted to the account it belongs to, enforced by server-side rules rather than by the app. The player directory is not readable in bulk by any client. We keep the number of people who can reach production data as small as possible — currently one.
No system is perfectly secure. If a breach affects your child's data and presents a risk, we will notify you and the relevant authority as the law requires.
11. Changes to this policy
If we change what the app collects, we will update this page and change the date at the top. Where a change materially affects children's data, we will seek fresh parental consent rather than rely on this page having changed.
What this policy assumed, and what has since shipped
This section is kept rather than deleted, so the record of what the policy once promised in advance survives alongside what is now true.
The age screen has shipped (schema v22). Section 2 describes an app that asks the player's age once and collects nothing personal from anyone under 13, and that is now what the app does: a player who declares under 13 gets the whole game on the device, with no account, no sign-in and no Social Hub. The answer is stored on the device only — never uploaded, and not part of any save that syncs between devices.
Superseded — the parental gate. An earlier draft relied on a parental gate in front of account creation. That was an Apple Kids Category requirement rather than a COPPA one, and the app no longer lists in that category. The age branch replaces it: a child cannot reach account creation at all, so there is nothing for a gate to stand in front of. The gate remains in front of the three things that still leave the app — Help & Legal, the app store link, and signing out — because handing a child to a browser unchallenged is a bad idea whatever category an app lists in.
Also shipped — display names. Names are chosen from a fixed list written in advance; a child cannot type one, and there is no free-text field anywhere in the app. That is what makes section 3.3's claim true, and it is structural rather than a promise to moderate.
12. Contact
Questions about this policy, or about your child's data: meerkatuniverse.support@gmail.com.