01 · Scope & Applicability
This Privacy Policy describes the personal data xinghzhe ("we", "us", "our", "xinghzhe.com", "xinghzhe Tech Lab") collects, how we use it, how we share it, and what choices you have. It applies to:
- The xinghzhe.com website and any sub-domain under xinghzhe.com;
- The xinghzhe iOS, iPadOS, watchOS, visionOS and macOS applications published on the Apple App Store under the developer name "xinghzhe Tech Lab", including — but not limited to — Flow Automator, Collectible Index, Posture Studio, Estate Vault, Fragment, Cyclical Budget, and future releases ("Apps");
- The xinghzhe Android and Wear OS applications published on the Google Play Store under the developer name "xinghzhe Tech Lab";
- Any API, SDK or development tool we ship under the xinghzhe mark;
- Any newsletter, blog, customer-support email exchange and direct-mail campaign controlled by xinghzhe.
This Policy does not apply to third-party websites, services or applications that we do not control — including the Apple App Store, the Google Play Store, and any third-party ad networks that we may integrate in the Apps. We publish the full list of those ad networks and their privacy policies in section 07.
02 · Definitions
For the purposes of this Policy:
- "Personal data" means any information that identifies or can reasonably be used to identify a natural person, including name, email address, IP address, device identifier or any combination thereof.
- "Processing" means any operation performed on personal data, including collection, storage, modification, retrieval, consultation, disclosure, restriction, deletion or destruction.
- "User" means any natural person who installs, accesses or interacts with the Services.
- "Minor" means any user under the age of digital consent in their country of residence (13 in the United States under COPPA, 16 in the EU and UK under GDPR / UK-GDPR, 14 in Brazil under LGPD, 14 in South Korea under PIPA, 18 in China under PIPL as adjusted).
- "Sensitive data" means special-category data under Article 9 GDPR, including health, biometric, racial or ethnic origin data.
03 · Data Controller & EU/UK Representatives
The data controller for the Services is xinghzhe Tech Lab, registered in Scotland (United Kingdom) under company registration SC555102, with its principal office at University of Stirling Innovation Park, Stirling FK9 4LA, United Kingdom.
For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") xinghzhe has appointed a Data Protection Officer reachable at privacy@xinghzhe.com. Because xinghzhe does not have a physical establishment in the European Union, GDPR Article 27 representation is fulfilled through the contact details above.
For the purposes of the UK GDPR and the Data Protection Act 2018, the Information Commissioner (ICO) is the competent supervisory authority. You may lodge a complaint with the ICO at ico.org.uk or with your local supervisory authority.
04 · Categories of Data We Collect
| Category | Examples | Collected? | Lawful basis (GDPR) |
|---|---|---|---|
| Account data | Email address, display name, password hash (Argon2id) | Only on opt-in cloud sync | Contract (Art. 6(1)(b)) |
| User-content data | Documents, voice memos, photographs you save in our apps | Yes — stored locally | Contract / legitimate interest |
| Device data | Model, OS version, locale, locale-format, system theme preference | Yes — anonymous | Legitimate interest (Art. 6(1)(f)) |
| Diagnostics | Crash reports, opt-in performance traces | Opt-in only | Consent (Art. 6(1)(a)) |
| Ad data (free-tier Apps) | Device advertising identifier (IDFA / GAID), coarse location, contextual event data | Only inside free-tier apps with ads enabled | Consent (ePrivacy / GDPR) |
| Support correspondence | Email contents, attachments you send us | Yes — when you contact us | Contract / legitimate interest |
| Payment data | Last 4 digits of payment card, billing country | Handled by Apple / Google — never by xinghzhe | Not applicable (controller is the storefront) |
| Biometric data | Face ID / Touch ID templates | On-device only — never leaves your device | Consent / security |
| Sensitive health data | Posture-session inferences, training duration, range of motion | On-device only — processed with Core ML, never uploaded | Explicit consent (Art. 9(2)(a)) |
05 · Purposes & Legal Bases
We process personal data for the following purposes:
- To deliver the core functionality of each App and the website (contract).
- To provide customer support and respond to enquiries (contract / legitimate interest).
- To detect and prevent fraud and abuse (legitimate interest).
- To comply with legal obligations, including retention of tax invoices, EU DSA risk-assessment reporting and law-enforcement disclosure requests (legal obligation).
- To display advertising in the free-tier of selected Apps (consent — see sections 07 and 08).
- To send marketing communications to users who have actively subscribed (consent).
- To improve our products through aggregate, fully-anonymised analytics (legitimate interest; you may opt out).
06 · App Store, Play Store & Distribution Disclosure
Our Apps are distributed through:
- Apple App Store & Mac App Store, operated by Apple Distribution International Limited (Hollyhill Industrial Estate, Cork, Ireland), acting as the merchant of record for in-app purchases and subscriptions. Apple's privacy practices are described in the Apple Privacy Policy and the Apple Media Services Terms. Apple processes your Apple ID, payment data and download history as a separate controller. Each App's App Privacy section (the iOS 14+ "nutrition label" required by Apple) is filled in to mirror this Privacy Policy.
- Google Play Store, operated by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) and Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Each Play Store listing contains a Data Safety section that summarises which categories of data are collected, shared and whether processing is optional or required.
- Alternative distribution channels for macOS apps (such as a direct download from xinghzhe.com) where offered. In those cases xinghzhe is the merchant of record and uses Stripe (Stripe Payments Europe Ltd, Ireland) as payment processor — see §11.
- TestFlight for beta distributions — Apple Distribution International Limited again acts as the relevant distribution intermediary and privacy controller for beta-test downloads.
- Firebase App Distribution by Google LLC for Android beta builds — Firebase's own privacy policy applies to that distribution channel.
Each App listing on a storefront is accompanied by the legally-required privacy labels and, in the case of the EU/UK, a App Privacy Information Sheet declaring the categories of data collected. The labels are reproduced below in aggregated form:
| App | Identifiers | Usage data | Diagnostics | User content (local) | Financial info | Tracking |
|---|---|---|---|---|---|---|
| Flow Automator | Device ID | Diagnostics | Optional | Yes (script files) | Not collected | Optional, opt-in (ads) |
| Collectible Index | Device ID | Diagnostics | Optional | Yes (collection data) | Not collected | Optional, opt-in |
| Posture Studio | Device ID | Diagnostics | Optional | Yes (session data — health) | Not collected | Optional, opt-in |
| Estate Vault | Device ID | Diagnostics | Optional | Yes (encrypted documents) | Not collected | Not used |
| Fragment | Device ID | Diagnostics | Optional | Yes (notes) | Not collected | Optional, opt-in |
| Cyclical Budget | Device ID | Diagnostics | Optional | Yes (budgets) | Not collected | Optional, opt-in |
The "Tracking" column refers to tracking as defined by Apple's App Tracking Transparency framework (ATT). When tracking is enabled, it is opt-in for users in iOS 14.5+ — the App Tracking prompt is shown the first time an ad unit is about to be displayed, and the user can revoke permission at any time in Settings → Privacy & Security → Tracking. Users who decline tracking still see ads, but they are contextual (no cross-app profiling).
07 · Advertising Networks — Full Disclosure
To keep some Apps free, xinghzhe integrates with reputable advertising networks on an opt-in basis only. Each network has been audited by xinghzhe's privacy team and reviewed against (i) the GDPR, (ii) the UK-GDPR, (iii) the Apple App Store Guidelines 5.1.1, (iv) Google Play's User Data Policy, (v) the IAB Europe Transparency & Consent Framework (TCF v2.2), and (vi) the Children's privacy baseline required for Apps rated under Apple's "All Ages" guideline or carrying an age rating of 9+ and above on the IARC scale.
The list of advertising networks and partners xinghzhe may integrate with, in the order of frequency, is reproduced below. Each entry includes: legal entity, jurisdiction, applicable IAB TCF vendor ID (where registered), the user-facing description of the service, the data they receive, the legal basis in the EEA/UK, an opt-out method, and the privacy policy URL.
| # | Partner / Brand | Operating entity | Jurisdiction | IAB TCF Vendor ID | Linked privacy policy |
|---|---|---|---|---|---|
| 1 | Google AdMob | Google Ireland Ltd (EEA / UK), Google LLC (rest of world) | IE / US | 755 | policies.google.com/privacy · AdMob help |
| 2 | Google AdSense | Google Ireland Ltd (EEA / UK), Google LLC (rest of world) | IE / US | 755 | policies.google.com/technologies/ads |
| 3 | Google Ad Manager (DFP) | Google Ireland Ltd (EEA / UK), Google LLC (rest of world) | IE / US | 755 | policies.google.com/privacy |
| 4 | Google AdX (Authorized Buyers) | Google Ireland Ltd (EEA / UK), Google LLC (rest of world) | IE / US | 755 | adxbuyer |
| 5 | Meta Audience Network | Meta Platforms Ireland Ltd (EEA / UK), Meta Platforms Inc. (US) | IE / US | 10 | facebook.com/policy.php |
| 6 | Facebook Pixel (web only) | Meta Platforms Ireland Ltd (EEA / UK) | IE | 10 | facebook.com/policy.php |
| 7 | Instagram Ads (Meta) | Meta Platforms Ireland Ltd | IE | 10 | help.instagram.com/519522125107875 |
| 8 | Unity Ads | Unity Technologies ApS (Denmark, EEA), Unity Technologies SF (US) | DK / US | 1484 | unity.com/legal/privacy-policy |
| 9 | AppLovin (MAX / SparkLabs) | AppLovin Corporation | US | 8 | applovin.com/privacy |
| 10 | ironSource (now Unity) | ironSource Ltd | IL / US | 2034 | is.com/privacy-policy |
| 11 | Vungle (now Liftoff) | Vungle Ltd / Liftoff Mobile Inc. | UK / US | 1360 | liftoff.io/privacy-policy |
| 12 | Pangle / TikTok Ads | ByteDance Ltd / Pangle (UK entity) | UK / CN | 2243 | pangleglobal.com/privacy-policy |
| 13 | TikTok for Developers | TikTok Technology Ltd (UK / IE) | IE / UK | 2243 | tiktok.com/legal/privacy-policy |
| 14 | InMobi | InMobi Technology Services Pvt. Ltd. | IN | 333 | inmobi.com/privacy-policy |
| 15 | Chartboost | Chartboost, Inc. (now Zynga) | US | 363 | chartboost.com/legal/privacy-policy |
| 16 | Tapjoy | Tapjoy, Inc. | US | 1361 | tapjoy.com/legal/privacy-policy |
| 17 | AdColony (now Digital Turbine) | AdColony, Inc. | US | 218 | adcolony.com/privacy-policy |
| 18 | Digital Turbine (post-feb-24) | Digital Turbine (UK) Ltd | UK / US | 218 | digitalturbine.com/privacy-policy |
| 19 | MoPub (X / Twitter MoPub) | MoPub Inc. (now X / Twitter) | US | 908 | mopub.com/legal/privacy |
| 20 | X Ads (Twitter) | Twitter International Company (IE) | IE / US | 1319 | twitter.com/privacy |
| 21 | Smaato (now Verve Group) | Smaato Inc. | US / DE | 69 | verve.com/privacy-policy |
| 22 | Start.io (StartApp) | Start.io (US) Inc. | US / IL | 1555 | start.io/policy/privacy |
| 23 | Amazon Publisher Services (APS) | Amazon Europe Core S.à r.l. (LU) | LU / US | 793 | aps.amazon.com/aps/privacy-policy |
| 24 | Amazon Ads (formerly Amazon DSP) | Amazon Europe Core S.à r.l. | LU / US | 793 | advertising.amazon.com/legal/privacy |
| 25 | Criteo | Criteo S.A. | FR | 91 | criteo.com/privacy |
| 26 | Yahoo Ads (Verizon Media → Yahoo) | Yahoo EMEA Ltd (IE) | IE / US | 25 | legal.yahoo.com/privacy |
| 27 | Microsoft Advertising (Bing Ads) | Microsoft Ireland Operations Ltd | IE / US | 1 | about.ads.microsoft.com/privacy |
| 28 | Microsoft Clarity (UA / analytics) | Microsoft Ireland Operations Ltd | IE / US | n/a (analytics) | clarity.microsoft.com/terms |
| 29 | Pinterest Ads | Pinterest Europe Ltd (IE) | IE / US | 741 | policy.pinterest.com/privacy-policy |
| 30 | Reddit Ads | Reddit Ireland Ltd | IE | 2222 | reddit.com/policies/privacy-policy |
| 31 | Snap Ads (Snapchat) | Snap Group Ltd (UK / IE) | UK / US | 478 | snap.com/privacy-policy |
| 32 | LinkedIn Ads | LinkedIn Ireland Unlimited Company | IE | 159 | linkedin.com/legal/privacy-policy |
| 33 | Spotify Ad Studio | Spotify AB | SE | 180 | spotify.com/legal/privacy-policy |
| 34 | Mintegral (now Mobvista) | Mintegral International Ltd (HK) | HK / CN | 1209 | mintegral.com/en/privacy |
| 35 | BidMachine | BidMachine Inc. | US | 1324 | bidmachine.io/privacy-policy |
| 36 | Ogury | Ogury Ltd (UK) | UK / FR | 1891 | ogury.com/privacy-policy |
| 37 | LoopMe | LoopMe Ltd (UK / US) | UK | 1598 | loopme.com/privacy-policy |
| 38 | Moloco | Moloco, Inc. | US / KR | 1036 | moloco.com/privacy-policy |
| 39 | Yahoo Research (post-Verizon) | Yahoo EMEA Ltd | IE | 25 | legal.yahoo.com |
| 40 | Tremor International (now Nexxen) | Tremor International Ltd (UK) | UK / IL | 1027 | nexxen.com/privacy-policy |
| 41 | PubMatic | Pubmatic, Inc. | US | 76 | pubmatic.com/legal/privacy-policy |
| 42 | Index Exchange | Index Exchange Inc. | US | 10 | indexexchange.com/privacy |
| 43 | Magnite (Rubicon) | Magnite Inc. | US | 158 | magnite.com/legal/advertising-technology-privacy-policy |
| 44 | OpenX | OpenX Software Ltd (UK) | UK / PL | 69 | openx.com/legal/privacy-policy |
| 45 | Sovrn (formerly VigLink) | Sovrn Holdings, Inc. | US | 1095 | sovrn.com/privacy-policy |
| 46 | Conversant / ValueClick (now Wunderkind) | Conversant LLC | US | 100 | conversantmedia.com/legal/privacy-policy |
| 47 | Taboola | Taboola.com Ltd (UK) | UK / IL / US | 21 | taboola.com/privacy-policy |
| 48 | Outbrain | Outbrain UK Ltd | UK / IL / US | 164 | outbrain.com/legal/privacy-policy |
| 49 | Sharethrough | Sharethrough Ltd (UK) | UK / US / CA | 1580 | sharethrough.com/privacy-policy |
| 50 | Triton Digital (now iHeartMedia) | Triton Digital Holdings, Inc. | US | 1247 | tritondigital.com/privacy-policy |
| 51 | AdTheorent | AdTheorent, Inc. | US | 1789 | adtheorent.com/privacy-policy |
| 52 | Fluct (now LG Ad Solutions / CRT) | Fluct Ltd. | JP | 1750 | fluct.jp/en/privacy |
| 53 | i-mobile | i-mobile Co., Ltd. | JP | 1741 | i-mobile.co.jp/privacy |
| 54 | Zucks (now PopIn) | Zucks Inc. / PopIn Inc. | JP | 1629 | popin.cc/en/privacy_policy |
| 55 | OneSignal (push / messaging only, no ads) | OneSignal, Inc. | US | n/a | onesignal.com/privacy_policy |
| 56 | Firebase Analytics (analytics) | Google Ireland Ltd / Google LLC | IE / US | 755 | firebase.google.com/support/privacy |
| 57 | Adjust (attribution / analytics) | Adjust GmbH (DE) | DE / US | 1348 | adjust.com/privacy |
| 58 | AppsFlyer (attribution / analytics) | AppsFlyer Ltd (Israel, IE) | IL / IE | 1668 | appsflyer.com/legal/privacy-policy |
| 59 | Branch (attribution) | Branch Metrics, Inc. | US | 1188 | branch.io/policies/privacy |
| 60 | Kochava (attribution) | Kochava Inc. | US | 816 | kochava.com/privacy-policy |
| 61 | Singular (attribution) | Singular Labs Inc. | US | 1173 | singular.net/privacy-policy |
| 62 | Kargo (mobile-CTV ads) | Kargo Networks Inc. | US | 1246 | kargo.com/privacy-policy |
| 63 | Adikteev (retargeting) | Adikteev SAS | FR | 1876 | adikteev.com/privacy-policy |
| 64 | Sublime Skinz (display) | Sublime Skinz SAS | FR | 1517 | sublimeskinz.com/privacy-policy |
| 65 | Kayzen (DSP) | Kayzen SAS | FR | 1860 | kayzen.io/privacy-policy |
| 66 | Smadex (DSP) | Smadex SLU | ES | 1739 | smadex.com/privacy |
| 67 | MediaMath (DSP, now Display & Video 360 / Curated) | MediaMath, Inc. | US | 228 | mediamath.com/privacy-policy |
| 68 | The Trade Desk (DSP) | The Trade Desk, Inc. | US / UK | 21 | thetradedesk.com/privacy-policy |
| 69 | Adform (DSP / SSP) | Adform A/S (Denmark) | DK | 50 | site.adform.com/privacy-policy |
| 70 | SmartHub (by Smart AdServer) | Smart AdServer SAS | FR | 45 | smartadserver.com/privacy-policy |
| 71 | Equativ (formerly Smart AdServer) | Equativ SA | FR | 45 | equativ.com/privacy-policy |
| 72 | TripleLift | TripleLift, Inc. | US | 125 | triplelift.com/privacy |
| 73 | Mobilewalla (audience / data) | Mobilewalla Inc. | US | 1888 | mobilewalla.com/privacy-policy |
| 74 | Lotame | Lotame Solutions, Inc. | US | 167 | lotame.com/privacy |
| 75 | Oracle Advertising (formerly Grapeshot / AddThis) | Oracle Corp. | US / UK | 136 | oracle.com/legal/privacy |
| 76 | Yandex Ads (display / video) | Yandex LLC (RU, IO) | RU / CY | 115 | yandex.com/legal/privacy |
| 77 | VK Ads (mail.ru) | VK LLC | RU | 1202 | vk.com/privacy |
| 78 | Roku Ads | Roku Ltd (UK / IE) | UK / US | 1501 | roku.com/privacy-notice |
| 79 | AWS (advertising context only) | Amazon Web Services EMEA SARL | LU / US | 793 | aws.amazon.com/privacy |
| 80 | Bytedance Pangle Extra (Global) | ByteDance Ltd. | UK / CN | 2243 | pangleglobal.com/privacy-policy |
Compliance matrix for ad partners
Each of the partners above has been reviewed against the following baseline. Compliance status is documented in our internal register and re-audited at least every twelve months, or whenever a partner publishes a material change to its SDK or privacy notice.
| Criterion | What we check | Status |
|---|---|---|
| GDPR / UK-GDPR Art. 28 contract | DPA, SCCs, or IDTA in place | Verified, 100% |
| IAB TCF v2.2 compliance | Vendor list declared to the SDK | Verified, 100% |
| COPPA compatibility | No behaviourally-targeted ads to known children | Verified |
| Apple ATT support | Honours IDFA-zero & LAT on iOS 14.5+ | Verified |
| Children-Directed Data Stop | Respects ad-blocking signals under our age gate | Verified |
| Google Families Policy | AdMob / AdX & YouTube family compliance | Verified |
| EU DSA risk-classification | Recognised ad networks & DSA-compliant reports | Verified |
| Sub-processor transparency | Sub-processors disclosed in this Policy | Verified |
| Data residency for EU/UK | EU/UK end-points active where available | Verified, 100% |
| Security certifications | SOC 2 Type II / ISO 27001 / ISO 27701 | Verified for 92% |
08 · Ad Formats & Behavioural Targeting
The xinghzhe Apps integrate the following advertising formats. Each format is gated by the consents described in §07 and by the age gate described in §09.
8.1 · Banner ads
Small rectangular or banner-shaped ad units displayed at the top or bottom of an App screen. Banner ads are loaded asynchronously and refreshed on a configurable interval (default: 60 seconds). No session-state is persisted on xinghzhe's servers — the ad request itself may include the device advertising identifier (IDFA on iOS, GAID on Android) and a coarse (city-level) location when permitted by the user.
8.2 · Interstitial ads
Full-screen ad units displayed at natural transition points (e.g. between two automation flows in Flow Automator, between two collection pages in Collectible Index). Interstitials are explicitly not shown to a user more than once every two minutes, in compliance with the IAB Open Measurement SDK's "frequency cap" guidelines.
8.3 · Rewarded video ads
User-initiated full-screen video ads where the user opts in to watch a video in exchange for an in-app reward (for example, unlocking a premium template in Flow Automator for 24 hours, or extending a free-trial period in Collectible Index). The reward is only granted when the user has watched at least 50 % of the video and confirmed the close button themselves, in accordance with the IAB OM SDK definition of a "completed view".
8.4 · Native / in-feed ads
Ad units styled to match the look-and-feel of the surrounding content cards (a technique commonly called "Sponsored" cards). Each native ad is clearly labelled with a "Sponsored" or "Ad" mark to avoid deception, in accordance with the FTC Endorsement Guides, EU Directive 2006/114/EC on Misleading and Comparative Advertising, and the ASA Code.
8.5 · Open-screen (splash) ads
Ad units displayed for the first few seconds when the App launches. Splash / open-screen ads are time-limited (maximum 5 seconds) and never block interaction with the App beyond that window. A user who has declined behavioural tracking on iOS still sees a contextual, non-targeted open-screen ad.
8.6 · Playable / interactive ads
In a limited number of sessions, an interactive "playable" ad may be offered as an alternative to a rewarded video — for instance as a preview of a future Cyclical Budget feature. Playable ads honour the same consent gates as rewarded video ads.
8.7 · Behavioural targeting and personalisation
Behavioural targeting (also called "interest-based advertising" or "personalised ads") is opt-in. When a user declines the App Tracking prompt on iOS or the "Personalise ads" toggle on Android, all ads served by xinghzhe Apps are limited to contextual information — that is, the content of the screen on which the ad is displayed. xinghzhe does not build cross-app, cross-device user profiles and does not participate in cross-app retargeting. The IAB Europe TCF "Purpose 1" (Store and/or access information on a device) is set, "Purpose 2" (Select basic ads) is set, and "Purpose 3" (Select personalised ads) is set only after consent is captured.
8.8 · Frequency capping
xinghzhe enforces the following frequency caps:
| Format | Maximum per session | Maximum per 24 h | Maximum per 7 d |
|---|---|---|---|
| Banner | 40 impressions | 200 impressions | 1,400 impressions |
| Interstitial | 2 impressions | 8 impressions | 40 impressions |
| Rewarded video | 6 impressions | 20 impressions | 120 impressions |
| Open-screen | 1 impression | 4 impressions | 20 impressions |
| Native | 8 impressions | 32 impressions | 160 impressions |
09 · Age Verification & Minors (COPPA / GDPR-K)
xinghzhe's products are designed for a general audience and are not directed at children under the age of digital consent (13 in the United States under COPPA, 16 in the European Union and the United Kingdom under GDPR / UK-GDPR, 14 in South Korea under PIPA, 14 in Brazil under LGPD, 14 in California under CCPA as amended, 18 in China under PIPL as adjusted). However, we recognise that some users in this age range may wish to use our Apps — the rules below apply.
9.1 · How we verify age
- On first launch of any xinghzhe App, the user is asked to enter their year of birth. The age is computed locally and never transmitted to xinghzhe.
- If the computed age is at or above the age of digital consent in their stated country, the App operates in standard mode.
- If the computed age is below the local age of digital consent, the App enters a "minor" mode in which:
- All advertising IDs are zeroed out at every request and we deliberately pass Apple's "Limit Ad Tracking" signal (iOS 14.5+) as a hard no-track.
- In-app behavioural targeting is impossible because no user-level ID is stored.
- The user's profile is locked to "child-safe" themes and language variants.
- Any purchase flow (in-app purchase or subscription) is gated by an Ask to Buy requirement on Apple platforms, the Family Library approval requirement on Google Play, or a verifiable parental-consent flow implemented via the COPPA-Recognised safe-harbour method.
9.2 · COPPA-specific safeguards (US)
- We do not knowingly collect personal information from a child under 13 other than the irreducible amount necessary for the App to operate locally on the device.
- We do not condition any feature of the App on the child providing more information than is reasonably necessary.
- We provide parents with the ability to review any personal information collected from their child, request deletion, and prevent further collection — by contacting us at privacy@xinghzhe.com. Parents can also operate a "Family Mode" toggle in the device-level Settings.
- We do not use any of the persistent identifiers set out in 16 CFR §312.2 for behavioural or targeted advertising when the user is identified as a minor.
9.3 · GDPR-K / UK Age-Appropriate Design Code
- We have performed a DPIA (Data Protection Impact Assessment) per Article 35 GDPR against the UK Information Commissioner's Office Age-Appropriate Design Code (the "Children's Code"). A summary of mitigation measures is published in our public transparency report.
- All default settings in our Apps are configured to the highest privacy level for minors.
- Profiling of minors for the purpose of serving personalised advertising is disabled across all our properties.
- Geolocation features that rely on fine location require verifiable parental consent if the user is a known minor.
- Language used in the App is age-appropriate and free from manipulative patterns.
9.4 · California SB-1424 / AB-2273 (California Age-Appropriate Design Code Act)
If the California Act enters force or its provisions apply via a successor regulation, xinghzhe has committed to honour the same high-privacy default for California-resident minors as for the EU / UK and to perform an annual risk-assessment review.
10 · Country & Regional Privacy Policies
This section extends the base Policy to particular countries and regions. In case of any conflict between this section and the rest of the Policy, this section prevails for users in the relevant jurisdiction.
10.1 · European Economic Area (EEA) & United Kingdom (UK)
The lawful bases for processing are Article 6(1)(a) consent, Article 6(1)(b) contract, Article 6(1)(c) legal obligation and Article 6(1)(f) legitimate interest. Sensitive data is processed only on the basis of Article 9(2)(a) explicit consent. Cross-border transfers outside the EEA / UK take place on the basis of the Standard Contractual Clauses (Decision 2021/914) and the UK Addendum (the "UK IDTA").
10.2 · United States — California (CCPA / CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa, Indiana, Tennessee, New Hampshire, New Jersey, Delaware, Kentucky, Maryland, Minnesota, Rhode Island
If you are a resident of California or one of the above states, you have the following rights:
- The right to know what personal information we have collected about you, the categories of sources, the business or commercial purposes, and the categories of third parties with whom we share it.
- The right to access the specific pieces of personal information we have collected about you in the preceding 12 months.
- The right to delete personal information we have collected from you, subject to statutory exceptions.
- The right to correct inaccurate personal information.
- The right to opt out of the sale or sharing of personal information.
- The right to limit the use and disclosure of sensitive personal information to that which is necessary to perform the services or provide the goods reasonably expected by an average consumer.
- The right to non-discrimination for exercising any of your privacy rights.
xinghzhe does not sell personal information. We do share limited device-level identifiers (IDFA / GAID, IP-derived country) with the ad networks listed in §07, and you may opt out by toggling "Limit Ad Tracking" on iOS or "Opt out of ads personalisation" on Android — those platform-level signals are honoured by every ad partner we integrate. You may also contact us at privacy@xinghzhe.com to lodge a "Do Not Sell or Share" request or a "Limit Use of My Sensitive Personal Information" request.
10.3 · Canada (PIPEDA, Quebec Law 25)
For Canadian users our privacy officer is reachable at privacy@xinghzhe.com. We honour the right of access, the right of correction, the right of withdrawal of consent, and the right of complaint to the Office of the Privacy Commissioner of Canada, and for Quebec-resident users the additional rights under Loi 25.
10.4 · Australia (Privacy Act 1988, 2024 amendments)
For Australian users we are required to notify you of our Notifiable Data Breaches scheme. If a data breach is likely to result in serious harm, we will prepare a statement and submit it to the Office of the Australian Information Commissioner and notify affected users as soon as practicable.
10.5 · Brazil (LGPD, ANPD)
For Brazilian users we have appointed a Data Protection Officer reachable at privacy@xinghzhe.com and we comply with the Lei Geral de Proteção de Dados (Law 13.709/2018) and the regulations of the Autoridade Nacional de Proteção de Dados. The legal bases, data-subject rights, and international-transfer rules follow Article 7 LGPD.
10.6 · Japan (APPI, 2022 amendments)
For Japanese users we observe the Act on the Protection of Personal Information as amended in 2022, including the requirement to obtain opt-in consent for opt-out transfers to third parties in third countries that do not have an adequacy decision equivalent to the EU's.
10.7 · South Korea (PIPA, 2023 amendments)
For Korean users we observe the Personal Information Protection Act as amended in 2023, including the requirement to obtain opt-in consent for transfers outside Korea and to designate a domestic representative. Our Korean representative is reachable at korea@xinghzhe.com.
10.8 · China (PIPL, 2021)
For users in the People's Republic of China we observe the Personal Information Protection Law. Cross-border transfers are made only when a CAC-led security assessment has been completed, or via a Standard Contract with the provincial CAC filed, or under a privacy certification issued by a recognised body. Our PRC representative is china@xinghzhe.com.
10.9 · Russia (152-ФЗ)
For users in the Russian Federation we observe Federal Law 152-FZ on Personal Data. Data of Russian users is processed and stored on servers physically located in Russia (Moscow and St. Petersburg data centres).
10.10 · India (DPDPA, 2023)
For Indian users we comply with the Digital Personal Data Protection Act, 2023. Our Data Fiduciary in India is reachable at india@xinghzhe.com.
10.11 · Singapore (PDPA, 2020 amendment), Hong Kong (PCPDO, 2021 amendment), Taiwan (PDPA, 2023 amendment), New Zealand (Privacy Act 2020), South Africa (POPIA, 2013), and other jurisdictions
xinghzhe maintains a watching brief on every jurisdiction's privacy regulations and aligns its internal policies to the strictest of the in-force laws applicable to any data subject. For specific inquiries please contact privacy@xinghzhe.com.
11 · Cookies, SDKs & Web Storage
This section is the "Cookie Notice" referred to in the footer of every page. Cookies are small text files placed by your browser. The xinghzhe.com website uses the following categories of cookies and similar technologies (collectively, "Cookies"):
| Category | Purpose | Provider | Lifetime | Lawful basis (EEA / UK) |
|---|---|---|---|---|
| Strictly necessary | Cookie-consent preference, language, security tokens, CSRF tokens | xinghzhe | Session / 12 months | Art. 6(1)(f) legitimate interest — strictly necessary under ePrivacy Recital 32 |
| Functional | Remembering theme, reduced-motion preference, font-size preference | xinghzhe | 12 months | Art. 6(1)(a) consent |
| Analytics (opt-in) | Aggregate, fully-anonymised page-view statistics | Plausible Analytics (EU-hosted) | None / daily aggregated | Art. 6(1)(a) consent |
| Marketing | none | — | — | — |
xinghzhe.com does not deploy Facebook Pixel, Google Analytics, AdSense, third-party advertising cookies or any cross-site tracking cookies. The Plausible Analytics instance we use is self-hosted in Germany and does not set any cookies — it operates on cookieless aggregate counters.
You can withdraw or change your cookie preference at any time by clicking the cookie icon visible in the bottom-left of every page, or by clearing your browser's storage. Please refer to your browser's documentation for instructions on managing Cookies (for example Safari, Chrome, Firefox or Edge).
12 · Data Processing, DPA & Sub-Processors
The Data Processing Agreement (DPA) supplements this Policy and is available on request at privacy@xinghzhe.com. It incorporates the EU Standard Contractual Clauses (Decision 2021/914) and the UK International Data Transfer Addendum to the EU SCCs. Our current sub-processors are listed below and updated each time a new one is added.
| # | Sub-processor | Purpose | Region | Safeguard |
|---|---|---|---|---|
| 1 | Amazon Web Services EMEA SARL | Cloud hosting (EU region eu-west-1, eu-central-1) | IE / DE | SCCs |
| 2 | Cloudflare Inc. | Edge CDN, DDoS protection | EU edge nodes | SCCs |
| 3 | Fastmail Pty Ltd | Email delivery for support and contact | AU / EU | SCCs |
| 4 | Stripe Payments Europe Ltd | Payment processing for direct-download macOS apps | IE | SCCs |
| 5 | GitHub Inc. | Source-code hosting (private repositories) | US | SCCs + IDTA |
| 6 | Atlassian Pty Ltd | Issue tracking and project management | EU data centres | SCCs |
| 7 | Hetzner Online GmbH | Off-site backup storage (Stirling) | DE | SCCs |
| 8 | Apple Distribution International Ltd | App Store distribution & in-app payment processing | IE | Apple App Store Terms |
| 9 | Google Ireland Ltd | Play Store distribution & Firebase analytics opt-in | IE | Play Store Terms + SCCs |
| 10 | Adjust GmbH | Attribution analytics (opt-in) | DE | SCCs |
| 11 | AppsFlyer Ltd | Attribution analytics (opt-in) | IE / IL | SCCs |
| 12 | Branch Metrics Inc. | Attribution & deep linking | US | SCCs |
| 13 | Sentry GmbH (EU self-hosted) | Crash & error reporting (opt-in) | DE | SCCs |
13 · International Data Transfers
Personal data is primarily processed in the European Union (Dublin and Frankfurt) and the United Kingdom (London). Where data is transferred outside the EEA and the UK, we rely on one or more of the following safeguards:
- The EU Commission's adequacy decisions (currently covering Andorra, Argentina, Canada (commercial), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, United Kingdom, Uruguay and the United States under the EU-U.S. Data Privacy Framework).
- The UK Commissioner's adequacy regulations.
- The EU Standard Contractual Clauses (Decision 2021/914) and the UK International Data Transfer Addendum (the "UK IDTA"), supplemented by technical and organisational measures (transfer impact assessment, encryption-in-transit, encryption-at-rest, pseudonymisation, contractual transparency obligations on the importer).
- The Swiss SCC equivalents (FDPIC-approved).
- Explicit consent in the limited circumstances where none of the above apply.
For each transfer, xinghzhe maintains a Transfer Impact Assessment on file. A summary is available on request.
14 · Data Retention
| Data type | Default retention | Notes |
|---|---|---|
| Personal content stored locally in an App | Until the user deletes it | Not transmitted to xinghzhe by default |
| Account data (email, password hash) | Until account deletion + 30 days | Export available at any time prior |
| Support correspondence | 7 years (statutory minimum) | Encrypted at rest; minimisation applied |
| Crash / diagnostic data (opt-in) | 90 days | Self-hosted, EU region |
| Backups | 30 days | Encrypted, immutable, EU region |
| Financial invoices | 10 years | UK statutory minimum |
| Cookie consent record | 12 months | Proof of consent — ICO guidance |
| Law-enforcement disclosure records | 5 years | ICO guidance on transparency |
15 · Security Measures
We implement the technical and organisational measures required under Article 32 GDPR, including:
- Encryption in transit — TLS 1.3 only, HSTS preload, OCSP stapling, modern cipher suites (AES-256-GCM, ChaCha20-Poly1305).
- Encryption at rest — AES-256-GCM / XTS-AES-256 on all user-data storage volumes.
- End-to-end encryption (E2EE) for vault products using the user's own keys, with key-wrapping via PBKDF2-SHA512 (310k iterations) or Argon2id, and biometric gating via Secure Enclave / StrongBox where supported by the hardware.
- Multi-factor authentication for every employee with access to production systems.
- Principle of least privilege, audited quarterly.
- Continuous vulnerability scanning with Trivy, Snyk and GitGuardian.
- Annual third-party penetration tests by an independent CREST-accredited firm.
- Secure software-development lifecycle: code review, threat-modelling per component, SBOM, signed release builds.
- Backup strategy: daily incremental + weekly full, immutable for 30 days, with quarterly restore tests.
- Incident-response plan documented, tested at least once per year; the Data Protection Officer is on-call 24/7 in case of personal-data breaches.
16 · Your Rights (GDPR / UK-GDPR / CCPA)
Subject to the conditions and exemptions set out in the applicable law, you have the right to:
- Be informed about what personal data we process and why (this Policy).
- Access the personal data we hold about you.
- Rectify inaccurate personal data.
- Request erasure ("right to be forgotten") of your personal data.
- Restrict or object to our processing of your personal data.
- Receive a portable copy of the personal data you have provided (data portability).
- Withdraw consent at any time, where processing is based on consent — without affecting the lawfulness of processing carried out before withdrawal.
- Lodge a complaint with a supervisory authority — in the UK: the Information Commissioner's Office (
ico.org.uk); in an EU member state: your local data-protection authority; in California: the California Privacy Protection Agency; in Brazil: the ANPD. - For California residents specifically: opt out of the sale or sharing of personal information, and limit the use of sensitive personal information, as detailed in §10.2.
To exercise any of these rights, write to privacy@xinghzhe.com. We respond within 30 calendar days (GDPR / UK-GDPR) or 45 days (CCPA), free of charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act. We will ask for evidence of identity sufficient to confirm that the requester is the data subject.
17 · DSA & Transparency Reporting
Although xinghzhe is not classified as a Very Large Online Platform under Regulation (EU) 2022/2065 ("Digital Services Act"), we publish a quarterly Transparency Report covering: the categories and volumes of in-app advertising served, the categories of ad-partner activity, the categories of content moderation actions taken (if any), and a count of data-subject requests received and responded to. The report is available at contact via email.
18 · AI / Machine-Learning Specific Disclosure
Where our Apps or research prototypes use machine-learning models, the following additional rules apply:
- All inference runs on-device by default. Models are packaged into the App and downloaded with the App bundle.
- If a feature requires a remote model (for example a foundation model too large for the device), the user is presented with an explicit opt-in and is informed of the data categories transferred.
- No user content is used to train models without explicit, granular, revocable consent.
- Personal data used for fine-tuning of foundational models is deleted after each training run; we do not retain training inputs beyond the training session.
- Generated outputs are stored only if the user requests a save; they are not uploaded for any purpose other than the user's own cloud sync.
- We comply with the EU AI Act, the UK AI White Paper, the US AI Bill of Rights, China's Generative AI Interim Measures, and Korea's AI Basic Act.
19 · Changes to this Policy
We will post any material changes to this Privacy Policy at this URL with a new "Last updated" date and, where the change is significant, an in-app banner. Where consent is the lawful basis, we will request a renewed consent before any new processing takes effect.
20 · Contact
For any privacy question or to exercise your rights, please contact:
- Email (privacy): privacy@xinghzhe.com
- Email (general): contact@xinghzhe.com
- Email (support): support@xinghzhe.com
- Postal: xinghzhe Tech Lab, Data Protection Officer, University of Stirling Innovation Park, Stirling FK9 4LA, United Kingdom.