LessAct
Privacy Policy
This policy explains what information the current LessAct application processes and how it is used.
Last updated: August 18, 2026
1. Overview
This Privacy Policy explains the information LessAct processes when you create an account, sign in, set up a profile, learn, play, or use community features. It describes the current LessAct web application and its authentication services.
2. Information You Provide
When you register with Email and Password, LessAct stores your Email address and a one-way Password hash. LessAct does not store your plaintext Password. If you request an Email correction before verification, the replacement address is kept with the temporary confirmation record; the current Login Email is not replaced unless the new address is confirmed.
Profile information can include a Display Name, bio, and optional profile image. LessAct also creates a stable public username for your profile URL. Display Names do not need to be unique, and changing a Display Name does not change the username in your profile URL.
If you participate in community features, LessAct stores content you submit, such as chat messages, uploaded images, blocks, mutes, and reports.
3. Google Sign-In
LessAct uses Google Identity Services for authentication. When you choose Google Sign-In, LessAct verifies a Google ID credential and receives a stable Google account identifier, Email address and verification status, and—when Google provides them—your name and profile image URL.
For a new account, the name and image can be used as initial profile suggestions. LessAct stores the linked Google identifier and provider Email, but does not store the raw Google ID credential or Google access or refresh tokens.
LessAct does not request Google API scopes and does not access Gmail, Google Drive, Google Calendar, Google Contacts, files, or other Google account content.
A matching Email address does not automatically link Google to an existing LessAct account. Existing-account linking requires the user to authenticate the LessAct account and explicitly complete the link flow.
4. Guest and Service Activity
Product flows may create a Guest account and Guest cookie so learning and game activity can continue before registration. A Guest can be promoted to a new registered account while keeping the same progress and owned data. Merely opening this Privacy Policy or the Terms of Service does not create a Guest account.
LessAct stores information needed for learning and game features, including answers, scores, response times, learning progress, game sessions, matches, ratings, collections, inventory, entitlements, virtual-balance activity, and related operational records.
Public profile details and content posted in shared areas may be visible to other users. Authorized Admin tools can access account, moderation, and service records needed to operate LessAct.
5. Authentication and Security Information
LessAct uses necessary cookies for registered sessions, refresh sessions, request protection, and Guest sessions. It also stores limited session and security information such as User ID, session timing and status, browser or device information, IP address, and security-event records.
Verification and Password recovery links are time-limited and stored in a protected form. Authentication logs and metrics are designed to avoid raw Passwords, credentials, session cookies, and action links.
This information is used to keep sessions working, prevent abuse, enforce rate limits, investigate suspicious activity, and revoke sessions when required by account-security actions.
6. Transactional Email
LessAct uses Resend to send transactional account Email. Current message types include Email verification, Password recovery, Password-change notifications, and Google account link or unlink security notifications.
Resend receives the destination Email address and message content needed for delivery. LessAct keeps operational delivery information such as message purpose, provider message identifier, delivery status, failure category, and event timestamps.
7. How Information Is Used
- Create and maintain registered and Guest accounts.
- Authenticate users, maintain sessions, and recover accounts.
- Provide profiles, learning activities, games, progress, collections, community features, and account settings.
- Deliver requested account and security messages.
- Prevent abuse, apply moderation, enforce bans, and protect service reliability.
- Produce account-level learning analytics and aggregate operational metrics from service activity.
- Investigate support, delivery, and technical problems.
8. Service Providers
Google Identity Services provides Google Sign-In and verifies the Google identity information described above. Google-hosted profile images may also load from a Google domain when used in a profile.
Resend processes transactional Email and returns delivery events used for account-message operations.
Google Fonts supplies the typefaces loaded by the current LessAct frontend. A browser request to a hosted font service includes ordinary connection information such as IP address and User-Agent.
9. Retention
Current authentication settings expire verification and Password recovery links after 30 minutes, registered refresh sessions after 7 days, and Guest access on a 30-day sliding window with a 90-day maximum from Guest creation.
When the maintenance job is run, expired or used authentication-action records become eligible for removal after 7 additional days. Transactional Email delivery records are retained for 90 days and signed Email webhook-event records for 30 days under the current configuration.
Unverified pending accounts are reported for manual review after 30 days but are not automatically deleted. Registered accounts, profiles, linked identities, learning progress, inventory, and gameplay history are not automatically removed by the authentication cleanup job.
Some community records have separate moderation and retention rules. Records connected to reports, account safety, service integrity, or transaction history may be kept longer than ordinary public content.
10. Account Choices and Deletion
You can update supported profile details, reset your Password, sign out, and link or unlink Google when the account has another sign-in method and the security checks are satisfied. Removing Google deletes that linked Google sign-in record but does not delete the LessAct account or its product data.
LessAct does not currently provide self-service account deletion or an automatic complete-deletion process for registered accounts. Contact support@lessact.com to ask about account information or deletion. Requests require manual review; LessAct does not state a fixed completion time, and some records may need to remain for security, moderation, transaction integrity, disputes, or applicable obligations.
11. YouTube API Services
When enabled for LessAct Live, LessAct uses YouTube API Services for an authorized LessAct administrator to connect a YouTube channel and run a YouTube-connected live game session. This administrator-operated feature is not available to ordinary LessAct players through the public site.
Data accessed and purpose
For a connected channel, LessAct receives OAuth authorization information (including the granted scope and token expiry), the authorizing channel ID, active live-broadcast information (broadcast ID, title, live-chat ID, and scheduled or actual start time), and live-chat activity (message ID, event type, author channel ID, message text, and published time). LessAct uses this information to identify an active broadcast, receive and process live chat for a LessAct Live session, prevent duplicate participation, and operate, secure, and diagnose the integration. LessAct does not use YouTube to upload, edit, delete, or otherwise write YouTube content.
Eligible chat input can become a LessAct game vote. Resulting choices, receipt times, deduplication records, and vote totals are LessAct-generated game records; they are not official YouTube metrics.
Storage, processing, and sharing
Raw chat text and raw YouTube channel, broadcast, live-chat, message, and viewer identifiers are processed in memory for the live-session workflow and are not stored in LessAct's database. LessAct stores encrypted access and refresh-token envelopes while a connection is active, the granted scope and connection status/timestamps, an administrator-supplied operator alias, HMAC-derived identifiers used for channel, broadcast, viewer, and message deduplication, and encrypted pagination cursors used for live-chat ingestion.
Authorized LessAct administrators can see the operator alias and connection status needed to run the integration. The implementation does not send raw YouTube chat content or raw YouTube identifiers to LessAct's transactional-email, Google Sign-In, or font providers. Live-game operational logs and metrics are designed to exclude tokens, chat text, viewer identities, and raw YouTube identifiers. We do not use YouTube data for advertising.
Google and YouTube process information under their own policies. Read the Google Privacy Policy.
Disconnecting YouTube and revoking access
An authorized LessAct administrator can use Disconnect in Admin → Live Games → YouTube. LessAct then asks Google to revoke the available credential, clears its local access and refresh credentials immediately, and prevents connected live-session inputs from continuing to use them. If Google's revocation request cannot be confirmed, local credentials are still cleared and the connection is marked for follow-up deletion.
You may also remove LessAct access from Google Account third-party access settings. Removing LessAct access there prevents further authorized access. LessAct detects external revocation when it validates, uses, or periodically revalidates the connection; it then clears credentials and begins the applicable deletion process described below.
Deleting YouTube data and retention
Disconnecting starts LessAct's YouTube-data deletion process. Credentials are cleared immediately. The current worker deletes the remaining connection linkage (including the pseudonymous channel and broadcast linkage, encrypted cursor, operator alias, stored scope, and connection-consent fields) within seven calendar days. When YouTube vote input is enabled, the configured cleanup also removes retained pseudonymous vote/message claims for completed or cancelled live sessions after seven days. LessAct does not retain raw live-chat text.
The authorized administrator who connected the channel can use Disconnect to make this request; the registered LessAct-account lifecycle does not itself revoke a YouTube connection. If that administrator cannot access the control, contact support@lessact.com to request help with the connection or its stored data. LessAct does not currently provide self-service deletion of a registered LessAct account. Deleting LessAct-held information does not delete videos, live chats, or other information hosted by YouTube.
Credentials
LessAct does not ask for or receive your YouTube password. Channel authorization occurs through Google's OAuth authorization flow, and the only requested YouTube scope is youtube.readonly.
12. Security
LessAct uses access controls, protected credentials, secure production cookies, request validation, rate limits, session rotation and revocation, and security monitoring. No online service can guarantee perfect security, so users should protect their sign-in methods and contact support if they suspect unauthorized account activity.
13. Policy Updates and Contact
This policy may change when LessAct features or information practices change. The Last updated date at the top will identify the current published version.
For privacy or account-data questions, contact support@lessact.com.