Privacy Policy
Your privacy is our architecture. This policy describes how Jinyuanh ("we", "us", "our") collects, uses, discloses, and safeguards information when you use our websites, mobile applications published on the App Store, and related services.
Table of Contents
- § 1. Information We Collect
- § 2. How We Use Your Information
- § 3. Local-First Architecture
- § 4. Apple App Store & iOS Compliance
- § 5. Google Play & Android Compliance
- § 6. Advertising Platforms & SDKs
- § 7. GDPR (EU/EEA/UK)
- § 8. CCPA / CPRA (California)
- § 9. LGPD (Brazil)
- § 10. PIPL (China)
- § 11. APPI (Japan) & Asian Jurisdictions
- § 12. Privacy Act (Australia / Canada)
- § 13. Age-Based Protections & COPPA
- § 14. Data Retention & Deletion
- § 15. International Data Transfers
- § 16. Security Measures
- § 17. Your Rights & Choices
- § 18. Children's Privacy
- § 19. Third-Party Services & Links
- § 20. Changes to This Policy
- § 21. Contact Us
§ 1. Information We Collect
1.1 Information You Provide Directly
We collect minimal personal information. When you contact us via email at contact@jinyuanh.com or support@jinyuanh.com, we receive:
- Name (if provided)
- Email address
- Company / organization (optional)
- Message content and any attachments you choose to send
1.2 Information Collected Automatically by Our Mobile Applications
Our iOS and Android applications are engineered under a local-first philosophy. By default, we do NOT collect, transmit, or store the following on remote servers:
- Audio recordings, mixes, or edits you create
- Documents, files, photos, or attachments you process
- GPS routes, locations, or trajectories you record
- Personal goals, credentials, or collection data you enter
- Inventory, recipes, expiry data, or any application-specific content
All such content remains on your device, encrypted at rest using the iOS Data Protection / Android Keystore systems, and is never transmitted to Jinyuanh or any third-party server.
1.3 Standard Device & Diagnostic Data
For the operation of our applications and the delivery of advertising (in apps that include ad-supported modes), the following may be collected by the operating system or by advertising SDKs (see § 6):
- Device model, OS version, locale, language
- IP address (truncated by advertising platforms)
- Advertising identifier (IDFA on iOS, GAID on Android)
- App version, build number
- Crash logs (only when you opt in to share diagnostics with developers)
1.4 Cookies and Similar Technologies (Website Only)
This website does not deploy marketing cookies. We use only essential, first-party functional elements and no third-party tracking.
§ 2. How We Use Your Information
2.1 Purpose Limitation
- To respond to your direct email inquiries
- To deliver the core functionality of our applications on your device
- To deliver advertising in apps that offer an ad-supported tier
- To diagnose crashes and improve app stability
- To comply with applicable law, regulation, or valid legal process
2.2 No Profiling
We do not engage in profiling that produces legal effects concerning you.
2.3 No Sale
We do not sell, rent, or commercially distribute personal information to third parties.
§ 3. Local-First Architecture
3.1 Data Stays on Device
- Audio recordings encoded/decoded via on-device Apple frameworks (AVFoundation, AudioKit)
- Route logger uses Core Location / Google Play Services Location strictly for on-device storage
- Ingredient, goal, and collection data stored in local SQLite / Core Data
- No remote database, no Firebase, no external analytics receive your content
3.2 Optional Cloud Backup
Some apps offer opt-in encrypted backup using iCloud Drive / Google Drive private containers. Backups are encrypted on-device using keys derived from your device passcode.
3.3 No Account Required
None of our applications require account creation, login, or registration.
§ 4. Apple App Store & iOS Compliance
4.1 App Store Privacy Labels
Every Jinyuanh application submitted to the Apple App Store includes an accurate Privacy Label. Our standard disclosure:
- Data Not Collected: Most apps collect no personal data beyond email correspondence.
- Data Used to Track You: Apps integrating advertising SDKs declare advertising identifiers as "Tracking" per Apple's policy.
- Data Not Linked to You: Crash diagnostics and aggregated ad-impression telemetry are not linked to user identity.
4.2 App Tracking Transparency (ATT)
For all iOS apps integrating advertising SDKs we implement Apple's AppTrackingTransparency framework. The IDFA is accessed only after the user affirmatively taps "Allow" on the ATT prompt. If denied, all integrated ad networks serve contextual, non-personalized ads.
4.3 SKAdNetwork
For install and conversion attribution, we use Apple's SKAdNetwork for aggregated post-delay attribution without identifying individuals.
4.4 Privacy Manifest
Each app includes the required PrivacyInfo.xcprivacy manifest declaring required-reason API usage, user-tracking domains, and tracking behavior.
4.5 iOS Data Protection
All files written by our applications are protected by NSFileProtectionComplete where applicable.
§ 5. Google Play & Android Compliance
5.1 Google Play Data Safety Form
Each Android app includes a Google Play Data Safety Form that accurately discloses collection, sharing, and security practices.
5.2 Permissions
Apps request only permissions strictly required for core functionality:
- RECORD_AUDIO — only in the audio editor app, only while recording is active
- ACCESS_FINE_LOCATION — only in the route logger, only when logging is active
- CAMERA — only in apps with optical capture, used locally only
- READ/WRITE_EXTERNAL_STORAGE (legacy) or scoped storage on Android 11+
5.3 Data Safety Disclosures
- Data shared with third parties: Advertising identifier (only when ad-supported tier active and user consents)
- Data collected: None of user content; only standard crash and diagnostic data
- Security practices: Data is encrypted in transit (TLS 1.3) and at rest (Android Keystore)
- Data deletion: Users can delete all app data via in-app settings or by uninstalling
5.4 Families Policy
Where applicable, our apps comply with Google Play's Families Policy. We do not target children under 13 as our primary audience (see § 13).
§ 6. Advertising Platforms & SDKs
6.1 Overview
Some of our free-tier applications monetize via in-app advertising. The following advertising platforms and mediation networks may be integrated. Each network is integrated only after a careful privacy review and only with consent where required.
6.2 Google AdMob / Google Ad Manager
Used for banner ads, interstitial ads, rewarded video ads, and native ads. Privacy implementation:
- GDPR consent obtained via Google UMP (User Messaging Platform) SDK before requesting ads in EEA/UK
- CCPA opt-out respected via SDK parameters
- Children's ads tag set to TRUE for users under 13
- AdMob ad content filtered via max_ad_content_rating
- Data collection: Advertising ID, coarse device info, IP (truncated), interaction with ads
- Privacy policy: policies.google.com/privacy
6.3 Meta Audience Network (Facebook)
Used for banner, interstitial, rewarded video, and native ads. Privacy implementation:
- Meta Limited Data Use (LDU) mode activated for California users
- Event filtering applied through Meta SDK Data Processing Options
- Data collection: Advertising ID, device info, ad interaction
- Privacy policy: facebook.com/policy.php
6.4 Unity Ads
Used for rewarded video, interstitial, and banner ads. Privacy implementation:
- GDPR/CCPA consent flags passed via metadata
- User-level opt-out supported
- Data collection: device info, advertising ID, IP, ad interaction
- Privacy policy: unity.com/legal/privacy-policy
6.5 AppLovin (MAX Mediation)
Used as both an ad source and mediation platform. Privacy implementation:
- AppLovin's "Age-12" flag disables tracking for users under 13
- GDPR/CCPA consent strings propagated through SDK
- Data collection: Advertising ID, device model, OS, IP, ad events
- Privacy policy: applovin.com/privacy/
6.6 ironSource
Used as mediation layer and direct ad source. Privacy implementation:
- Consent string forwarded for GDPR compliance
- COPPA age-gate flag supported
- Data collection: device, advertising ID, IP, session data
- Privacy policy: is.com/privacy-policy/
6.7 Vungle (Liftoff)
Used for rewarded video and interstitial ads. Privacy implementation:
- User consent passed via consents API
- "Do Not Sell" honored for California users
- Data collection: device info, advertising ID, ad events
- Privacy policy: liftoff.io/privacy-policy/
6.8 Pangle (TikTok for Business / ByteDance)
Used for video and native ads. Privacy implementation:
- Consent and COPPA flags supported
- EU/UK users served only contextual ads without personalization until consent
- Data collection: device, advertising ID, ad interaction
- Privacy policy: pangleglobal.com/privacy
6.9 TikTok Audience Network
Limited Use disclosure; respects limit_ad_tracking flag.
6.10 Chartboost
Privacy controls via SDK; CCPA opt-out signals respected. chartboost.com/legal/privacy-policy/
6.11 Tapjoy
Used for rewarded video and offerwall. Consent flags forwarded.
6.12 InMobi
GDPR and CCPA consent respected; child-directed flag supported.
6.13 Yahoo (Verizon Media)
Honors consent and opt-out signals.
6.14 AdColony
Video and interactive ads; privacy signals respected.
6.15 Smaato
SSP; respects IAB TCF v2 signals.
6.16 Mintegral
mintegral.com/en/privacypolicy
6.17 BidMachine
Header bidding SDK. Respects IAB TCF v2 / US Privacy signals. bidmachine.io/privacy-policy
6.18 Ogury
Consent and age gating supported. ogury.com/privacy-policy
6.19 LoopMe
loopme.com/privacy-policy
6.20 Amazon Publisher Services (APS)
Header bidding SSP. amazon.com/adprivacy
6.21 Verizon Media / Yahoo Native
Honors consent flags. legal.yahoo.com/xw/en/yahoo/privacy/index.html
6.22 Criteo
criteo.com/privacy
6.23 TabMo / Digital Turbine
digitalturbine.com/privacy-policy
6.24 SuperAwesome (Kids-Focused)
COPPA / GDPR-K compliant where integrated for child-directed contexts. superawesome.com/privacy-policy
6.25 Kidoz
COPPA / GDPR-K compliant. kidoz.net/privacy-policy
6.26 Pubmatic
pubmatic.com/legal/privacy-policy
6.27 Index Exchange
indexexchange.com/privacy
6.28 OpenX
openx.com/legal/privacy-policy
6.29 Rubicon / Magnite
magnite.com/legal/privacy-policy
6.30 Consumable
consumable.com/privacy-policy
6.31 AdColony Compliance Detail
AdColony (now part of Digital Turbine) implements the IAB Transparency & Consent Framework v2.0/v2.2 and supports privacy signals through SDK configuration.
6.32 Google Authorized Buyers & SDK Bidding
Where Open Bidding / Authorized Buyers is enabled, Google acts as a real-time auctioneer. Privacy controls at policies.google.com/privacy.
6.33 AdMob Open Ads / Splash Compliance
Per AdMob policies: Open ads (splash) must be displayed using the Google Mobile Ads SDK with proper app-ads.txt integration and must not interfere with app functionality.
6.17 Ad Network Categories Used
Our apps may display the following ad formats:
- Banner Ads: Standard IAB-sized display banners
- Interstitial Ads: Full-screen static or video ads
- Rewarded Video Ads: User-initiated video ads awarding benefits
- Native Ads: Customizable ads matching app aesthetic
- Splash / Open Ads: Briefly shown at app launch per AdMob Open Ad policy
6.18 Frequency Capping & User Control
Ad frequency is capped. Users may opt out of personalized advertising via iOS Settings or Android Google Settings.
6.19 AdMob-Specific Publisher Requirements
Per Google's publisher requirements, our apps display:
- A clear "Why this ad?" link when personalized ads are served
- Proper handling of "AdChoices" icon on every ad served
- Strict separation between ad content and app content
- No ads that simulate system notifications
- Compliance with AdMob Program Policies and Family Ads Policy
§ 7. GDPR (EU/EEA/UK)
7.1 Data Controller
For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR, the data controller is Jinyuanh. You can reach our data protection contact at contact@jinyuanh.com.
7.2 Legal Bases for Processing
- Consent (Art. 6(1)(a)) — advertising personalization, optional cloud backup, optional diagnostic sharing
- Contract (Art. 6(1)(b)) — responding to your inquiries when you request services
- Legitimate Interest (Art. 6(1)(f)) — basic service operation, security, fraud prevention
- Legal Obligation (Art. 6(1)(c)) — tax, accounting, legal compliance
7.3 Your GDPR Rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), object (Art. 21), withdraw consent (Art. 7(3)), and lodge a complaint with your supervisory authority (Art. 77).
7.4 IAB TCF v2.2 Compliance
Our advertising stacks honor IAB Tech Lab Transparency & Consent Framework v2.2 signals.
7.5 UK Representative
For UK GDPR inquiries, contact contact@jinyuanh.com. You may also complain to the Information Commissioner's Office (ICO).
§ 8. CCPA / CPRA (California)
8.1 Your Rights Under CCPA/CPRA
California residents have the right to know, access, delete, correct, opt out of sale or sharing, limit use of sensitive PI, and non-discrimination.
8.2 Categories of Personal Information (Past 12 Months)
- Identifiers: email address (only when you contact us)
- Commercial information: in-app purchase history (handled by Apple/Google, not us)
- Internet activity: limited to interactions with ad SDKs in free-tier apps
- Geolocation: NOT collected by Jinyuanh
8.3 How to Exercise Rights
Email contact@jinyuanh.com with subject "California Privacy Request".
8.4 Shine the Light
We do not share personal information with third parties for their direct marketing.
8.5 Global Privacy Control (GPC)
We honor GPC signals as a valid opt-out for California residents.
§ 9. LGPD (Brazil)
Under LGPD, Brazilian users have GDPR-analogous rights. Contact contact@jinyuanh.com.
§ 10. PIPL (China)
Our apps do not provide services to users in mainland China. We do not transfer data outside the user's device.
§ 11. APPI (Japan) & Other Asian Jurisdictions
- Japan APPI: Access, correction, deletion via contact@jinyuanh.com
- South Korea PIPA: Access, correction, deletion, suspension via contact@jinyuanh.com
- Singapore PDPA: Access and correction via contact@jinyuanh.com
- Hong Kong PCPDO: Via contact@jinyuanh.com
- Taiwan PDPA: Via contact@jinyuanh.com
- India DPDP 2023: Via contact@jinyuanh.com
§ 12. Privacy Act (Australia / Canada)
Australia (1988): Access and correction via contact@jinyuanh.com. OAIC complaints available.
Canada (PIPEDA) / Quebec Law 25: Access and correction via contact@jinyuanh.com.
12.3 Additional Jurisdictions
- Mexico (LFPDPPP): Ley Federal de Protección de Datos Personales en Posesión de los Particulares — ARCO rights (Acceso, Rectificación, Cancelación, Oposición) via contact@jinyuanh.com.
- Russia (Federal Law 152-FZ): Personal Data Law — data localization and cross-border transfer controls. Russian users contact contact@jinyuanh.com.
- Turkey (KVKK): Kişisel Verileri Koruma Kanunu — rights to information, access, rectification, deletion via contact@jinyuanh.com.
- Saudi Arabia (PDPL): Personal Data Protection Law — access, correction, deletion via contact@jinyuanh.com; complaints to NDMOAU.
- UAE (PDPL): Federal Decree-Law No. 45/2021 — rights to access, correction, deletion via contact@jinyuanh.com.
- Switzerland (FADP): Revised Federal Act on Data Protection — analogous GDPR-style rights via contact@jinyuanh.com.
- Norway / Iceland / Liechtenstein: EEA extensions — same rights as GDPR via contact@jinyuanh.com.
- Thailand (PDPA): Personal Data Protection Act B.E. 2562 — rights via contact@jinyuanh.com; complaints to PDPC.
- Indonesia (UU PDP): UU No. 27/2022 — rights via contact@jinyuanh.com.
- Malaysia (PDPA 2010): Personal Data Protection Act — rights via contact@jinyuanh.com.
- Philippines (DPA 2012): Data Privacy Act — rights via contact@jinyuanh.com; complaints to NPC.
- Vietnam (PDPD 2023): Personal Data Protection Decree — rights via contact@jinyuanh.com.
- New Zealand (Privacy Act 2020): Rights via contact@jinyuanh.com; complaints to OPC.
- South Africa (POPIA): Protection of Personal Information Act — rights via contact@jinyuanh.com; complaints to Information Regulator.
- Argentina (Law 25.326): Personal Data Protection Law — rights via contact@jinyuanh.com; complaints to AAIP.
- Chile (Law 19.628): Data Protection Law — rights via contact@jinyuanh.com.
- Colombia (Law 1581/2012): Habeas Data rights via contact@jinyuanh.com; complaints to SIC.
- Peru (Law 29733): Personal Data Protection Law — rights via contact@jinyuanh.com.
- Israel (PPL 5741-1981): Protection of Privacy Law — rights via contact@jinyuanh.com.
- Egypt (Law 151/2020): Personal Data Protection Law — rights via contact@jinyuanh.com.
- Kenya (DPA 2019): Data Protection Act — rights via contact@jinyuanh.com; complaints to ODPC.
- Nigeria (NDPR 2019): Nigeria Data Protection Regulation — rights via contact@jinyuanh.com; complaints to NITDA.
§ 13. Age-Based Protections & COPPA
13.1 Minimum Age
Our services are not directed to children under 13 (or higher where required: 16 in EEA under GDPR, 14 in China/Brazil/Korea). We do not knowingly collect personal information from children below the applicable threshold.
13.2 COPPA (USA)
- Do not condition participation on collection of more data than necessary
- Obtain verifiable parental consent before collection from children under 13
- Provide parents the right to review, delete, and stop further collection
- Do not display behavioral advertising to children under 13 in child-directed apps
13.3 Age-Screen Mechanisms
Where advertising is integrated, our apps pass the tagForUnderAgeOfConsent flag to ad SDKs.
13.4 Reporting Inappropriate Collection
If you believe we have inadvertently collected information from a child, contact contact@jinyuanh.com immediately.
§ 14. Data Retention & Deletion
- Email inquiries: Retained up to 24 months
- App local data: Retained until user deletes via in-app feature or uninstall
- Cloud backups (opt-in): Retained in your private cloud account until deletion
- Crash & diagnostic logs: 90 days
§ 15. International Data Transfers
International data transfers are limited to email correspondence (US-based hosting) and advertising SDK traffic (when ad-tier is in use). Where transfers occur from EU/EEA/UK to the United States, we rely on Standard Contractual Clauses (SCCs) — specifically the 2021 Controller-to-Controller and Controller-to-Processor modules — and equivalent safeguards in our third-party processor relationships.
15.1 Data Localization Commitments
Jinyuanh products store all user-generated content on the user's device. We do not maintain backend servers that store user content. Where data does leave the device (such as an email you send us), the geographic location of processing is determined by the email provider (US-based).
15.2 Transfer Mechanisms
- EU/EEA/UK → US: Standard Contractual Clauses (2021/914)
- Switzerland → US: Swiss-US Data Privacy Framework
- UK → US: UK International Data Transfer Addendum
- Cross-border processing within EU/EEA: GDPR adequacy
15.3 Government Access Requests
In the event of a lawful government request for data, we commit to:
- Verify the legal basis and jurisdiction of the request
- Notify affected users where legally permitted
- Challenge requests that are overbroad or unlawful
- Publish aggregate statistics of government requests received
- Provide redacted copies of requests where permissible
15.4 Data Residency Statements by Region
Because we operate a "data stays on device" architecture, data residency obligations in regions including Russia (data localization), UAE (PDPL localization), and others are inherently satisfied at the architectural level: user data is never transferred to remote servers in the first place.
§ 16. Security Measures
- All communication with our infrastructure uses TLS 1.3
- App data at rest is protected by iOS Data Protection / Android Keystore
- Annual third-party penetration testing and vulnerability scanning
- Incident response plan with 72-hour breach notification commitment
§ 17. Your Rights & Choices
Regardless of your jurisdiction, you have the right to access, correct, delete, opt out, and lodge a complaint. To exercise any right, email contact@jinyuanh.com. We respond within 30 days.
§ 18. Children's Privacy
Our applications are general-audience. We do not knowingly collect data from children under the local minimum age. See § 13.
§ 19. Third-Party Services & Links
This website may link to external platforms. We are not responsible for their privacy practices.
- Apple App Store / iCloud — apple.com/legal/privacy
- Google Play — policies.google.com/privacy
- GitHub — docs.github.com/en/site-policy
§ 20. Changes to This Policy
We may update this policy. Material changes will be highlighted at the top of this page.
§ 21. Contact Us
For any privacy-related inquiry, please contact:
- Email (Primary): contact@jinyuanh.com
- Support: support@jinyuanh.com
- Mailing Address: Sky Song Innovation Park, Arizona State University, Arizona, United States
// END OF PRIVACY POLICY // EFFECTIVE 2026.01.01 // VERSION 3.2.0