Privacy
policy.
A clear and complete account of how tongkenxin.com handles information across this website and our mobile applications.
Effective date: 4 August 2026 · Version 1.1
1. Who we are and what this policy covers
tongkenxin.com is a technology research and development team based at the University of Stirling Innovation Park, Stirling, Scotland, United Kingdom. In this policy, “we”, “us” and “our” mean tongkenxin.com. Our business support email is support@tongkenxin.com; general privacy, contact and legal notices can be sent to contact@tongkenxin.com. The team operates a local-first product philosophy and applies it across every service.
1.1 Scope of this policy
This policy covers the tongkenxin.com website, our App Store applications distributed on Apple App Store and Google Play, our support communications, product research, and related services (together, the “Services”). It also covers any in-app notices, email correspondence and partner-mediated flows that lead to a tongkenxin.com-controlled product.
1.2 Product-specific addenda
Individual applications may display a shorter in-app notice or a product-specific addendum. If an addendum conflicts with this policy, the product-specific notice controls for that product. In all other cases, this policy remains the binding privacy reference.
1.3 Our privacy promise
Our core principle is “data stays local” wherever the product can work that way. We design for minimal collection, local processing, purposeful permissions, no unnecessary cloud storage and no hidden tracking. Where a third party is needed — for example, to display advertising, process a payment or fulfil a regulated duty — we disclose that dependency here and provide the controls required by applicable law.
2. Information we handle
2.1 Information you give us
- Contact data: your name, email address, organisation, topic and the contents of a support or business enquiry.
- Support data: app name, device model, operating-system version, app version, screenshots, log excerpts or other information you voluntarily include. Please do not send passwords, payment card numbers, government identifiers, health records or other sensitive information unless we specifically request it through a secure channel.
- App content: entries, notes, budgets, collection records, posture logs, document files, inspiration fragments, vault credentials and other content that you create in an app. Our intended architecture is local-only unless a particular app clearly says otherwise. We do not read local content for advertising.
- Purchase information: Apple or Google may tell us that a transaction, subscription or refund was completed, cancelled or restored. We do not receive your full payment-card details.
- Feedback and research: product feedback, survey answers, opt-in research notes and bug-report content that you provide through a recognised channel.
- Preferences: consent choices, notification settings, language, theme and privacy settings.
2.2 Information collected automatically
- Website technical data: IP address, coarse location derived from IP, browser type, device type, operating system, requested pages, referrer, timestamps, response codes and basic error logs. We use this for security, availability and aggregated performance.
- App technical data: app version, language, country/region, device model, OS version, advertising identifier where permitted, IP address or truncated IP address, crash diagnostics, performance signals, and fraud-prevention signals. The actual fields depend on the SDKs enabled in a particular app and your choices.
- Cookies and local storage: this website may use strictly necessary browser storage to remember a privacy choice. We do not use cross-site advertising cookies on this corporate website. Third-party app SDKs may use their own identifiers as described in section 6.
- Aggregated telemetry: rolled-up usage events such as feature counts, screen transitions, error rates and performance trends. Where possible, events are aggregated before leaving the device.
2.3 Information from others
We may receive app installation, billing, attribution, fraud, crash, or security information from Apple, Google, hosting providers, analytics and crash-diagnostic providers, and advertising partners. We do not buy lists of personal information. We may receive a referral URL or campaign identifier when you voluntarily arrive through a campaign. A support platform may deliver your message to us without us requesting the underlying contact list.
2.4 What we deliberately do not collect
We do not require you to create an account to use our core apps, we do not upload your local content to our servers, and we do not run cross-product behavioural advertising. We do not request access to your contacts, location in the background, microphone, or camera unless a specific feature you activate requires it. We do not use sensitive personal data to infer characteristics or to deliver targeted advertising.
3. Website storage, permissions, signals and controls
3.1 Cookies and browser storage
This website is designed to work without analytics, marketing cookies or cross-site advertising cookies. It may use a small, strictly necessary local-storage entry to remember whether you selected “essential only” or “accept all” in the privacy-choice notice. That preference is stored on your device, is not sent to us as a profile, and can be removed by clearing site data in your browser. If you email us, your email provider may place its own security or delivery cookies under its separate policy.
3.2 Mobile permissions
An app asks for a device permission only when a feature needs it. Depending on the product, permissions may include notifications, photos and files, camera, microphone, motion and fitness data, or local network access. We explain the reason before requesting permission where the platform allows it. You can deny or later revoke a permission in your operating-system settings. Revoking a permission may disable the related feature but does not delete content already saved locally; delete that content in the app or using your device controls.
3.3 Consent management
Where consent is required, our consent interface records the choice, the version of the notice, the region inferred for compliance and the time of the choice. We do not make access to a core, non-ad-supported function conditional on consent to personalised advertising. You may withdraw consent at any time; withdrawal does not make earlier lawful processing unlawful.
3.4 Do-not-track and global privacy signals
Browsers and operating systems may send privacy signals such as Global Privacy Control. We will honour a signal where the law requires us to do so and where our technical implementation can reliably identify it. A general “Do Not Track” browser signal is not consistently standardised; our no-sale / no-share approach applies regardless.
3.5 Choices, toggles and opt-outs
You can manage many of our uses through the controls we provide: in-app privacy settings, the device-level advertising identifier controls, the operating-system permission toggles, the email unsubscribe link, the consent notice on this website and your right to request deletion. Where a choice is supported by a third-party partner, that partner offers its own opt-out under its own policy.
4. Data map for common app categories
| App category | Local content we expect to handle | Typical optional services |
|---|---|---|
| Workflow automation | Scripts, task names, schedules and execution preferences | Crash diagnostics, optional notifications and contextual ads |
| Collection valuation | Item descriptions, images, purchase details and user estimates | Market-source requests only when a feature explicitly requires them; ads where disclosed |
| Posture and body training | Training sessions, measurements, goals and progress history | Local notifications, anonymous performance diagnostics and contextual ads |
| Property document vault | Encrypted documents, labels, reminders and local keys | Device backup controlled by you; we do not receive document contents |
| Inspiration organiser | Notes, images, tags, colours and categories | Share-sheet actions chosen by you; no advertising profile from content |
| Budget engine | Categories, amounts, periods and spending rules | Local notifications and non-personalised ads where disclosed |
This table describes our intended local-first architecture, not a promise that every future product has identical behaviour. Before using an app, review its store listing and in-app notice. If a product requires a server feature, that product will state the additional data, purpose, retention and deletion method before activation.
5. Why we use information and our legal bases
| Purpose | Typical data | Legal basis where required |
|---|---|---|
| Provide, maintain and secure the website and apps | Technical logs, device and app version, support details | Contract; legitimate interests in security and operation |
| Respond to support and business enquiries | Name, email and message | Steps at your request; contract; legitimate interests |
| Process subscriptions or purchases | Transaction status and entitlement | Contract; legal obligations |
| Show and measure advertising in ad-supported apps | Ad identifier, coarse location, device and ad event | Consent where required; legitimate interests for contextual ads and fraud prevention |
| Improve reliability and understand product use | Aggregated events, crash and performance data | Consent where required; legitimate interests; contract |
| Meet legal, accounting and safety obligations | Relevant transaction, correspondence and security records | Legal obligation; vital interests; legitimate interests |
We do not use app content to create advertising profiles. We do not sell personal information. We do not make decisions producing legal or similarly significant effects solely through automated processing. Where we rely on legitimate interests, you may object on grounds related to your specific situation and we will reassess.
6. Advertising and monetisation in our apps
Some applications may be free and supported by advertising. Advertising is configured per application and may change after an update. We may use mediation or one or more of the following providers, subject to the app’s current build, your location, consent, device settings and the provider’s own privacy terms:
Google AdMob, Google Mobile Ads SDK, Google Ad Manager, Google Authorized Buyers, Meta Audience Network, AppLovin MAX, AppLovin Exchange, Unity Ads, Unity LevelPlay (formerly ironSource), Liftoff Monetize, Liftoff Vungle, Mintegral, Pangle (by ByteDance), Chartboost, Digital Turbine, InMobi, Moloco, Start.io, Verve Group, Amazon Publisher Services, Microsoft Advertising (Xandr), Yahoo Advertising (Verizon Media), Criteo, Taboola, Outbrain, Snapchat Ads, X Ads (Twitter), Reddit Ads, LinkedIn Ads, TikTok Ads, Bidmachine, Smaato, AdColony, Fyber, Slick Innovations, Ogury, LoopMe, Maio (by i-mobile), Nexage, MoPub (deprecated), One by AOL, Millennial Media, AdBundes, Epom, and other reputable mediation or demand partners that are disclosed by the relevant app or consent-management interface.
Listing a provider does not mean every app uses every provider. The app’s store listing, in-app privacy choices and the provider documentation identify the partners active at the time.
6.1 Ad formats
- App-open / launch ads: shown while an app is starting or returning to the foreground, where supported.
- Rewarded video ads: optional video ads that may unlock a clearly described in-app benefit after you choose to watch and complete one.
- Interstitial ads: full-screen ads shown at a natural transition, never intended to interrupt a critical user action.
- Banner ads: rectangular ads displayed in designated app areas.
- Native ads: in-feed or in-list ads that match the visual rhythm of the surrounding content.
- Offerwall: where supported, a list of optional partner offers that may earn a clearly described reward.
6.2 What advertising partners may process
Depending on the partner and your choices, an SDK may process an advertising identifier (such as Apple’s IDFA or Google Advertising ID), IP address, approximate location, device model, OS, language, app and ad-placement identifiers, impression / click / reward events, limited diagnostic data and signals used to prevent fraud. A partner may combine those signals with information it already holds under its own policy. We do not provide the contents of your local documents, notes, budgets, collections or posture records to ad networks.
6.3 Choices and consent
- On iOS, we request AppTrackingTransparency permission before accessing IDFA for tracking where required. You can change this in Settings → Privacy & Security → Tracking.
- On Android, you can reset or limit the advertising ID in Google settings. You may also see an in-app consent dialog for personalised advertising.
- In the UK, EEA, Switzerland and other consent jurisdictions, we ask for consent before personalised advertising or non-essential advertising storage. You may withdraw or change consent in the app’s privacy controls where provided.
- When consent is refused or withdrawn, we request contextual or non-personalised advertising where available. Advertising may still appear, and basic fraud / security processing may continue under a lawful basis.
- Apple’s App Store privacy labels and Google Play’s Data safety section provide product-specific summaries. They are not a substitute for this policy.
- Children and under-age users never see personalised advertising; the mediation setup for those audiences is set to contextual or filtered demand where required.
Advertising partners may be independent controllers. Their policies and opt-out mechanisms are available from their websites. You can also review the European Interactive Digital Advertising Alliance controls, the US YourAdChoices controls and the DAA AppChoices tool for mobile.
7. App Store, Google Play and other platform rules
Our apps may be distributed through Apple’s App Store, Google Play, alternative Android marketplaces, Huawei AppGallery, Samsung Galaxy Store, Amazon Appstore, Mac App Store and, where applicable, other official marketplaces. Apple, Google and the relevant operator independently process account, payment, device and download information under their own policies. We comply with applicable Apple App Store Review Guidelines, App Store privacy nutrition labels, App Tracking Transparency rules, the European Union’s Digital Services Act and Digital Markets Act, Google Play Developer Programme Policies, Data safety disclosures, Families policies and User Data policies. Product disclosures are updated when material data practices change.
Where an app offers an account, we provide a way to request deletion through the in-app privacy settings and through the “Request account deletion” page referenced in the store listing. Where an app works without an account, local content can be deleted by deleting it within the app, by uninstalling the app, or by using the device-level reset feature, subject to device backup behaviour. Uninstalling does not automatically erase information held by a third-party ad, store, payment or support provider; their deletion tools apply.
8. Sharing, processors and disclosures
We share information only as needed to operate the Services, and we require service providers to protect it and use it only for the instructed purpose. Categories include:
- hosting, DNS, email, security, monitoring and customer-support providers;
- Apple, Google, Huawei, Samsung, Amazon and other payment or entitlement providers;
- analytics and crash-diagnostic providers, with minimised or aggregated data where possible;
- advertising and mediation partners listed in section 6, when the relevant app is ad-supported;
- professional advisers, insurers, auditors, banks or authorities where legally required, or to protect rights, safety and prevent fraud;
- a successor entity in a merger, acquisition, restructuring or asset transfer, subject to continuing protections and notice where required;
- law-enforcement or regulators in response to a valid legal process, after appropriate review where feasible.
We do not sell, rent or share personal information for another company’s direct marketing. We do not permit ad partners to access local-only app content. We do not allow our processors to combine our data with data they hold for their own purposes without our instruction and an appropriate legal basis.
9. International transfers and retention
Our providers may process information in the UK, EEA, United States, Switzerland, Singapore, Japan, Canada, Australia, India or another country. Where UK GDPR or EU GDPR applies, we use an adequacy decision, the UK International Data Transfer Agreement or Addendum, the EU Standard Contractual Clauses, or another legally recognised safeguard. You may request information about the applicable safeguard by emailing contact@tongkenxin.com.
We retain information only as long as reasonably needed:
- support correspondence is generally kept for up to 24 months after resolution;
- security logs are generally kept for up to 12 months;
- consent records and legal / accounting records are kept for the statutory period required in the United Kingdom, the United States, Canada, the European Union or another relevant jurisdiction;
- aggregated or anonymised analytics may be retained indefinitely, since they no longer identify a person;
- app content remains on your device until you delete it or the app removes it;
- advertising events are subject to the retention windows of the partner SDK and your device settings.
Providers may retain data under their own policies. We securely delete or anonymise data when the period ends.
10. Your rights by region
You can contact us at any time to ask what information we hold, request correction, deletion, restriction or portability, object to processing, withdraw consent, or complain. We may need to verify your identity and will not discriminate against you for exercising a right.
10.1 United Kingdom, European Economic Area and Switzerland
Under the UK GDPR, EU GDPR and applicable Swiss data law, you may access, correct, erase, restrict, object, receive a portable copy, withdraw consent and object to direct marketing. You may complain to the UK Information Commissioner’s Office (ico.org.uk), your EU / EEA supervisory authority or the Swiss Federal Data Protection and Information Commissioner.
10.2 United States
We do not sell or share personal information as those terms are defined by many US laws. Residents of California may request access, correction, deletion, portability and information about collection and disclosure under the CCPA / CPRA, and may opt out of sale or sharing, although we do not sell or share. Residents of Colorado, Connecticut, Virginia, Utah, Iowa, Indiana, Tennessee, Texas, Montana, Oregon, Delaware, New Jersey, New Hampshire, Kentucky, Nebraska, Maryland, Minnesota, Rhode Island, Arkansas, Florida and other states with comprehensive privacy laws may have equivalent rights, including appeal, consent withdrawal, limits on sensitive data use and targeted-ad opt-out. Email contact@tongkenxin.com with “US privacy request” and your state. We do not use sensitive personal data to infer characteristics or provide targeted ads from website data. We do not respond to Do-Not-Track signals as a sale / share opt-out because we do not sell or share.
10.3 Canada
Canadian users may exercise access, correction and complaint rights under PIPEDA and substantially similar provincial laws including Québec Law 25. Where applicable, you may request de-indexing, portability and the cessation of automated decisions.
10.4 Latin America
Brazilian users may exercise LGPD rights through the ANPD framework, including confirmation of existence, access, correction, anonymisation, portability, deletion, information about sharing and revocation of consent. Mexican users may exercise ARCO rights under the LFPDPPP. Users in Argentina, Chile, Colombia, Peru, Uruguay and other jurisdictions with local privacy laws retain the rights granted by those laws.
10.5 Europe beyond the EEA
Users in the United Kingdom, the European Economic Area, Switzerland, the United Kingdom’s Crown Dependencies and the Faroe Islands retain the rights described in 10.1. The UK GDPR applies to our handling of information about UK users regardless of where the data is processed.
10.6 Asia-Pacific
Australian and New Zealand users may request access and correction under the Privacy Act 1988 and Privacy Act 2020. Japanese users may exercise rights under APPI, including access, correction, erasure and cessation of use. South Korean users may exercise rights under PIPA. Singapore users may exercise rights under PDPA, including access, correction and withdrawal of consent. Taiwanese users may exercise rights under the PDPA. Hong Kong users may exercise rights under the PDPO. Indian users may exercise rights under the Digital Personal Data Protection Act when in force and applicable. Thai users may exercise rights under PDPA. Malaysian users may exercise rights under the PDPA 2010. Indonesian users may exercise rights under the PDP Law. Vietnamese users may exercise rights under the PDPD. Chinese users may exercise rights under PIPL and other applicable rules. Filipino users may exercise rights under the DPA. Users in Pakistan, Bangladesh, Sri Lanka and other South Asian jurisdictions retain rights granted by local law.
10.7 Middle East and Africa
Users in the United Arab Emirates, Saudi Arabia, Bahrain, Qatar, Israel, Kuwait, Oman, Jordan, Lebanon, Egypt, Turkey, Morocco, Tunisia and Nigeria may have rights under local data-protection laws. South African users may exercise rights under POPIA. Kenyan, Ghanaian and other African users retain rights under applicable local law.
10.8 How to make a request
Email contact@tongkenxin.com. Include the email you used, the app or service concerned, your country / state and the right you want to exercise. We normally respond within one month for GDPR requests and within the period required by local law. You may use an authorised agent where local law permits. We may need to verify your identity to protect you from impersonation.
11. Age, children and family protections
Our Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you are under 18, use the Services only with permission from a parent or legal guardian where required. If your local law sets a higher digital-consent age — including 14 in some EU Member States, 16 in many EEA contexts, 14 in the UK under the Age Appropriate Design Code, 16 in Brazil under the LGPD, 18 in South Korea under PIPA, or another age in a particular US state — that higher age and the required parental-consent process apply.
We do not knowingly use personalised advertising for children. We follow Apple’s age-rating and Kids requirements and Google Play Families requirements when an app is eligible for a child or family audience. Where we offer an account-based product, we screen for age signals and block sign-up where the user does not meet the minimum age. If you believe a child has provided information, contact us and we will investigate and delete it where required.
12. Security, accessibility, changes and complaints
12.1 Security
We use access controls, encryption in transit where supported, minimisation, secure development practices, vendor review and incident-response procedures. No online service is completely secure, so please tell us promptly about a suspected vulnerability by emailing contact@tongkenxin.com with the subject “Security”.
12.2 Accessibility
We aim to make privacy notices and controls understandable and accessible. If you need this policy in an alternative format or a language not yet offered, contact us and we will work with you to provide an appropriate version.
12.3 Changes
We may update this policy when our Services, providers or legal obligations change. We will post the new effective date and, where a change is material, provide an in-app or website notice. Your continued use after the effective date means the updated policy applies to future processing.
12.4 Complaints
If you believe we have not handled your information correctly, please contact us first so we can address your concern. You also have the right to complain to a data-protection authority in your country or region. In the UK that is the Information Commissioner’s Office; in the EEA it is your national supervisory authority; in Switzerland it is the FDPIC; in California it is the California Privacy Protection Agency; in Brazil it is the ANPD.
13. Contact the privacy team
Privacy enquiries, rights requests and complaints:
tongkenxin.com
University of Stirling Innovation Park
Stirling, Scotland, United Kingdom
Privacy contact: contact@tongkenxin.com
Business support: support@tongkenxin.com
We will work in good faith to resolve concerns. Nothing in this policy limits a right you have under mandatory privacy law.