This Privacy Policy explains how Small World(“we”, “us”) collects, uses, and protects information when you use the Small World Platform and its tools (the “Service”), hosted at smallworld.tools and its subdomains. The Service is an internal suite of tools built for Small World staff.
Who can use the Service
Access is restricted to authorised Small World team members who sign in with an approved Google account. We do not offer the Service to the general public.
Information we collect
When you sign in and use the Service, we process:
- Account information from Google Sign-In — your name, email address, and profile picture — used to authenticate you and control access.
- Usage analytics — lightweight, behavioural events (which tool was used, when, and whether a core action completed) so we can measure adoption. We track behaviour, not identity, and do not build profiles of you.
- Error diagnostics — technical error reports (via Sentry) to help us fix bugs. We scrub personally identifiable information from these reports.
- Files you create or pick— some tools can export their output to your Google Drive (for example, exporting a timeline to Google Sheets). This uses Google’s per-file
drive.filepermission, which only covers files the Service creates or files you explicitly select with the Google picker.
How we use Google user data
We use your basic identity data (name, email, profile) solely to authenticate you and control access. Where a tool offers export to Google Drive or Sheets, we request Google’s per-file drive.file scope: the Service can only read and write files it created or that you explicitly picked — it cannot see the rest of your Drive, Docs, or any other Google Workspace content. File access is used only to perform the export you asked for. We do not use Google user data for advertising, and we do not sell it.
Limited Use disclosure
The Service’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we store and protect data
Google access tokens are stored securely and used only to call Google APIs on your behalf during a session. Authentication is handled over encrypted connections. We retain analytics and error data only as long as needed to operate and improve the Service.
Sharing
We do not share your personal information or Google user data with third parties, except for the infrastructure providers that run the Service on our behalf (such as our hosting, database, and error-tracking providers) and where required by law.
Your choices
You can revoke the Service’s access to your Google account at any time from your Google Account permissions page. To request deletion of your account data, contact us at the address below.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date at the top of this page.
Contact
Questions about this policy? Email ted@tedspace.me.