Last updated 2 September 2026
Sagito makes no network requests. There is no server, no account, no sign-in, no analytics, no advertising, no crash reporting and no third-party SDK that phones home. Everything the app knows lives in storage on the device it is installed on, and the publisher never receives any of it. The only information that ever leaves a device passes directly to another family's device, through a camera or a code the parent shares — and only after a grown-up has unlocked it with the PIN.
This was verified, not assumed: there is no fetch, no HTTP client and no telemetry anywhere in the app's source, and as of 2 September 2026 there is no dependency in the project capable of contacting a server at all. The web addresses that appear in the question bank are provenance records for public-domain texts — they say where a passage was transcribed from, and are never requested at runtime.
This is the version to show in the app. Written to be read by a nine-year-old, because the ICO's Children's Code asks for privacy information "in clear language suited to the age of the child" — not a shorter version of the grown-up one.
The name you picked. You typed it when you started. A nickname is absolutely fine — Sagito doesn't mind what you call yourself, and you can leave it blank.
How you're getting on. Which questions you answered, which ones were tricky, how long you took, your points, your coins, your cards and your campsite.
Your friends. Just the ones a grown-up said yes to.
On your device. That's it. Sagito doesn't send any of it anywhere. There is no Sagito computer somewhere keeping a copy, because there isn't a Sagito computer at all. If you turn the internet off completely, everything still works exactly the same.
When you swap or send a card, your friend's device sees the name you picked and which card you sent. Nothing else — not your score, not how you're doing, not what you find hard. The nicknames you give your own cards stay with you.
The code a grown-up uses to add a friend in the first place is different: it doesn't have your name in it at all, just something your grown-up made up for your whole house, like "The Robertses". That's because a code like that can get passed around, and your name shouldn't go anywhere your grown-up hasn't said yes to.
Ask your grown-up. They can delete everything, and it really is gone — it was only ever on your device, so there's nothing left anywhere else. You don't have to say why.
Sagito is published by QNL LTD, 92 Cloonmore Avenue, Orpington, Kent, BR6 9LQ, company number 09869549. QNL LTD is the data controller. Questions about this policy, or about data held about you, go to Quang Luong at privacy@sagito.app. QNL LTD has not appointed a Data Protection Officer and is not required to: Article 37 applies to public authorities, large-scale systematic monitoring, and large-scale special-category processing, and none of those describe this app.
Because the app sends nothing to us, we hold no personal data about you or your child and have nothing to look up, export or delete on your behalf. Everything is on your device, under your control.
| What | Why it exists | Where it lives |
|---|---|---|
| Child's first name or nickname | Labels the profile; shown to a friend on a swap | Device storage |
| Answers, timings, accuracy, level | Shows progress and adapts difficulty | Device storage |
| Points, coins, cards, campsite items | The game | Device storage |
| Card nicknames the child gives | The child's own | Device storage — never sent |
| Parent PIN and recovery word | Locks the grown-up area | Device storage |
| Approved friends | So cards can be swapped | Device storage |
"Device storage" means the app's own private area on the phone or tablet, which other apps cannot read. It is included in an iCloud or Google device backup if you have one switched on — that backup is between you and Apple or Google, and we have no access to it.
Not stored, at all: the child's age or date of birth, location, photographs, contacts, device advertising identifiers, IP addresses, email addresses, adult names, or anything from a third-party tracker.
On the age, specifically. The app used to ask for it, to decide where the questions should start. It no longer does. The adaptive ladder measured the child properly within a sitting or two regardless, so the field amounted to collecting a piece of personal data about a child in order to seed a number the app was about to overwrite. Every child now begins in the same place and the first few sets work out where they actually are. Ages held in saves made before 31 August 2026 are deleted when the app next opens.
Friend invites, gifts and card swaps are carried by a QR code or a link that goes directly from one device to another. There is no server in the middle.
There are two kinds of code, and they carry different things on purpose.
An invite code, which starts a connection, contains a household label you choose yourself — "The Robertses", "Flat 3" — a random pairing id, and the time it was made. It does not contain any child's name. This changed on 2 September 2026: it used to carry the child's display name, and an invite is precisely the code that might reach a household nobody has approved yet, because it can be screenshotted, forwarded or read over a shoulder. The label need not be anybody's real name and is no more personal than the recovery word.
A gift or swap code, which moves a card or an item between two families who are already connected, does contain the sending child's display name — so the other child knows who sent it. That is the intended behaviour rather than an oversight: by this point a grown-up on each side has approved the other, and a phone without the matching pairing refuses the code, which is what makes a forwarded one harmless.
Neither contains any adult's name, any email address, any location, any progress or score, or any id that follows a child between families.
Codes expire — 24 hours for an invite, 3 days for a gift — so a screenshot cannot be reused indefinitely. Both making and accepting one sits behind the parent PIN, so a child cannot connect to anyone without a grown-up.
One thing worth knowing: if you send a code through a messaging app rather than by holding two phones together, that app carries the contents in the message under its own privacy policy rather than ours. For an invite that is a household label; for a gift it is a child's nickname. Holding the phones together avoids it entirely.
There is no chat, no comments and no free text of any kind travelling between users. The only text one child's device shows another is the display name they chose. This is deliberate and it is why the app needs no moderation system.
Used for exactly one thing: reading a friend's QR code, behind the parent PIN. No image is captured, saved or transmitted. iOS and Android will ask your permission the first time, and declining it only means codes must be shared as links instead.
Nothing can be bought yet. There is no in-app purchase library in the app, so no transaction of any kind is currently possible, and nothing in the app implies otherwise.
Optional extra camps, and a subscription that widens the question bank, are sold through Apple's In-App Purchase or Google Play Billing. Those transactions happen entirely between you and Apple or Google — we receive confirmation that a purchase was made and no payment details, no card number, no billing address and no name. If a payment provider is used to check that confirmation, it is named here before it is introduced. See the terms of use for what a purchase gets you.
On the free questions. The app ships with 2,063 of its 3,334 questions available without paying, and practice never stops: when those have all been seen the app keeps going and serves the ones met least often first. There is no countdown, no interstitial and nothing that halts a child mid-session. That is a design decision as much as a commercial one — a nine-year-old's practice should not stop in order to prompt a purchase.
Under UK GDPR you and your child have rights to see, correct, delete, export and object to the use of personal data. Because everything is on your device, these are things you do yourself rather than ask us for. All of them are in the grown-up area, behind the PIN:
Because we hold nothing, there is no request you can make to us that would produce data — but if any of the above does not work as described, tell us at privacy@sagito.app and we will fix it.
If you are unhappy, please tell us at privacy@sagito.app first. You can also complain to the Information Commissioner's Office at ico.org.uk or 0303 123 1113.
For as long as you keep the app installed. There is no retention period for us to set, because we hold nothing.
A connection server is designed and not built. Today two families connect by holding phones together or sharing a code, which works only while both are to hand. The server would carry an invite to a family who is not in the room, and hold a gift or a swap while the other phone is off.
When it ships, the claim at the top of this document — that Sagito makes no network requests — stops being true, and this policy will be rewritten before that happens rather than after. What it is designed to hold is already decided and deliberately small: an opaque household id generated on the device, the household label you chose, a notification token, invite codes and their expiry, which households are connected, and items in transit — deleted the moment they arrive. It holds nothing about a child. No nickname, no answers, no scores.
The other change on the horizon is payment, covered above.
If this changes we will say so in the app before the change takes effect, and the date at the top will be updated.