ZUOZHILIN
LOADING POLICY...
zuozhilin logo ZUOZHILIN
  • Home
  • Services
  • Advantages
  • Updates
  • Contact
Home / Privacy Policy

Privacy Policy

Your privacy is fundamental to everything we build. This policy explains in detail how we collect, use, protect, and respect your personal information across all our services and applications.

Last Updated: January 15, 2026
Effective Date: January 15, 2026

Table of Contents

  • 1. Introduction & Scope
  • 2. Definitions
  • 3. Information We Collect
  • 4. How We Use Information
  • 5. Legal Basis for Processing
  • 6. Data Storage & Localization
  • 7. Third-Party Services & Ad Networks
  • 8. Google AdMob Integration
  • 9. Advertising Formats We Use
  • 10. Other Advertising Platforms
  • 11. App Store Compliance
  • 12. Apple App Store Policies
  • 13. Google Play Store Policies
  • 14. Data Sharing & Disclosure
  • 15. Data Security Measures
  • 16. Data Retention
  • 17. Your Rights & Choices
  • 18. Age Restrictions & Children
  • 19. International Data Transfers
  • 20. GDPR Compliance (EU/UK)
  • 21. CCPA Compliance (California)
  • 22. LGPD Compliance (Brazil)
  • 23. PIPL Compliance (China)
  • 24. Other Regional Regulations
  • 25. Cookies & Tracking Technologies
  • 26. Do Not Track Signals
  • 27. Changes to This Policy
  • 28. Contact Us

1. Introduction & Scope

Welcome to zuozhilin.com ("we," "our," or "us"). We are a research and development studio based at the University of Stirling Innovation Park, United Kingdom, dedicated to creating minimalist, privacy-first digital products. This Privacy Policy applies to all our websites, mobile applications, products, and services (collectively, the "Services").

This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website, download or use our mobile applications (including but not limited to Local Workflow Scripts, Collection Value Tracker, Body Metrics Logger, Property Document Vault, Inspiration Organizer, Budget Cycle Engine, and any future applications we may develop), or otherwise interact with us.

Our Core Privacy Philosophy: We believe privacy is a fundamental right. Our products are designed with a "local-first" approach—meaning your data stays on your device by default. We minimize data collection to only what is necessary, and we never sell your personal information to third parties.

Please read this Privacy Policy carefully. By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our Services.

2. Definitions

For the purposes of this Privacy Policy, the following definitions apply:

  • "Personal Data" means any information that identifies, or can be used to identify, an individual user, either alone or in combination with other information.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
  • "Data Controller" refers to zuozhilin.com, which determines the purposes and means of processing Personal Data.
  • "Data Processor" refers to any third party that processes Personal Data on behalf of the Data Controller.
  • "User" or "you" refers to any individual who accesses or uses our Services.
  • "Device" refers to any device used to access our Services, including smartphones, tablets, computers, or other electronic devices.
  • "Application" or "App" refers to any mobile or desktop application developed and published by zuozhilin.com.
  • "Service" refers collectively to our website, applications, products, and related services.
  • "Sensitive Personal Data" means any category of personal information requiring special protection, such as health data, biometric data, or precise location data.
  • "Cookies" refers to small text files stored on your device by websites you visit.

3. Information We Collect

We collect minimal information to provide and improve our Services. The categories of information we may collect include:

3.1 Information You Provide Directly

  • Account Information: When you contact us or subscribe to our newsletter, we may collect your name, email address, and any other information you voluntarily provide.
  • Communications: When you contact us via email, contact forms, or other channels, we collect the contents of your communications and any metadata associated with them.
  • User-Generated Content: Information, files, photos, notes, documents, or other content you create, upload, or store within our applications (stored locally on your device, not on our servers).
  • Feedback and Reviews: Comments, ratings, reviews, or other feedback you provide about our Services.

3.2 Information Collected Automatically

  • Device Information: Device type, operating system version, device model, browser type and version, screen resolution, language settings, and unique device identifiers (e.g., IDFA, GAID, IDFV).
  • Usage Data: Information about how you use our Services, including features accessed, time spent, interaction patterns, crash logs, and performance data (only when explicitly opted-in).
  • Log Information: IP address, access times, referring URLs, and other diagnostic data when you visit our website.
  • Approximate Location: Country and region derived from IP address (used only for content localization and analytics; never precise location).

3.3 Information from Third Parties

  • App Store Information: When you download our applications through Apple App Store, Google Play Store, or other app distribution platforms, those platforms may provide us with aggregated download and crash statistics.
  • Advertising Networks: When our free applications display advertisements through third-party ad networks, those networks may collect certain information as described in their respective privacy policies (detailed in Section 7-10).

3.4 Information We Do NOT Collect

We want to be transparent about what we do NOT collect:

  • We do not collect precise GPS location data.
  • We do not collect your contacts, photos, or media library (unless you explicitly choose to add a specific item to our apps).
  • We do not collect your phone's microphone, camera, or sensor data without explicit consent for a specific feature.
  • We do not sell, rent, or trade your personal information.
  • We do not engage in cross-app tracking or behavioral advertising profiling.
  • We do not collect your government ID numbers, financial account credentials, or passwords.

4. How We Use Information

We use the information we collect for the following purposes:

  • Service Operation: To provide, maintain, and improve our Services, including processing your requests and transactions.
  • Customer Support: To respond to your inquiries, requests, support tickets, and provide technical assistance.
  • Product Improvement: To understand how users interact with our Services, identify trends, fix bugs, and develop new features (only with aggregated or anonymized data when possible).
  • Communications: To send you updates, newsletters, marketing communications, and other information about our products (with your consent, which you can withdraw at any time).
  • Security: To detect, prevent, and address fraud, security issues, abuse, and other harmful activities.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, or governmental requests.
  • Advertising: In our free applications, to display relevant advertisements through third-party ad networks (detailed in Sections 7-10). You can opt out of personalized advertising through your device settings.
  • Analytics: To perform aggregate, anonymous analytics about usage patterns (only with explicit consent or where permitted by law).

5. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), United Kingdom, and other jurisdictions that require a legal basis for processing personal data, we rely on the following legal bases:

  • Consent: Where you have given clear consent for us to process your personal data for a specific purpose (e.g., for analytics, marketing communications, or personalized advertising).
  • Contract: Where processing is necessary for the performance of a contract with you (e.g., providing the Services you have requested).
  • Legitimate Interests: Where processing is necessary for our legitimate interests, except where such interests are overridden by your fundamental rights and freedoms (e.g., for security, fraud prevention, basic analytics).
  • Legal Obligation: Where processing is necessary for compliance with a legal obligation to which we are subject.

6. Data Storage & Localization

Local-First Storage: Our products are designed with local-first storage as the default. This means your personal content (documents, photos, notes, fitness data, financial records, collections) is stored on your device, encrypted, and under your control.

What stays on your device:

  • All user-generated content within our applications
  • Account credentials and authentication tokens (stored in secure enclaves)
  • Application settings and preferences
  • Encrypted local backups (when enabled)

What may be stored on our servers (limited):

  • Email addresses of users who contact us or subscribe to newsletters
  • Aggregated, anonymized analytics data (with consent)
  • Support ticket contents and metadata
  • App store-related download and crash statistics

Data Center Locations: When we do store data on our servers, we use reputable cloud infrastructure providers with data centers primarily located in: the European Union (Ireland, Frankfurt), the United Kingdom (London), the United States (for backup redundancy), and other regions as required for optimal service delivery. All data is encrypted in transit (TLS 1.3) and at rest (AES-256).

Retention Periods: Server-side data is retained only as long as necessary to fulfill the purposes outlined in this policy, typically:

  • Contact form submissions: 2 years
  • Newsletter subscriptions: Until you unsubscribe
  • Support tickets: 3 years after closure
  • Analytics data (aggregated): 14 months maximum
  • Server logs: 90 days

7. Third-Party Services & Ad Networks

Our free applications may integrate with various third-party services, primarily advertising networks and analytics providers. These services may collect information about you when you use our applications. Each service has its own privacy practices, and we encourage you to review them.

Important: We carefully select third-party partners that align with our privacy values. However, the data collection and use practices of these third parties are governed by their own privacy policies, not this one.

8. Google AdMob Integration

Our applications may integrate Google AdMob ("AdMob"), a mobile advertising platform provided by Google LLC ("Google"). AdMob is one of the most widely-used mobile ad platforms and is integrated into many of our free applications.

8.1 What AdMob Does

AdMob enables us to monetize our free applications by displaying advertisements supplied by Google and its advertising partners. AdMob uses various technologies to serve ads, including:

  • Device identifiers (Advertising ID / IDFA on iOS, Google Advertising ID on Android)
  • IP address (used for approximate location and fraud detection)
  • App usage information and event tracking
  • Cookies and similar tracking technologies (where applicable)
  • Information about the ads served, viewed, or clicked

8.2 How AdMob Uses This Information

AdMob uses the collected information to:

  • Serve and display targeted advertisements based on your interests and demographics
  • Measure ad performance, click-through rates, and conversion
  • Detect and prevent click fraud and invalid traffic
  • Provide aggregated reporting to developers (us) about ad performance
  • Improve Google's advertising services and technology

8.3 Google AdMob Privacy Practices

Google AdMob complies with applicable advertising industry standards, including:

  • IAB Europe Transparency & Consent Framework (TCF): For GDPR compliance in Europe
  • App Tracking Transparency (ATT): For iOS 14.5+ users, we will request permission before tracking
  • Limited Ad Tracking (LAT): Respecting iOS users' choice to limit ad tracking
  • Google's EU User Consent Policy: For users in the EEA and UK
  • Google Play Families Policy: For apps targeted at children
  • Digital Services Act (DSA) compliance in applicable regions

8.4 Your Choices with AdMob

You can opt out of personalized advertising through:

  • iOS: Settings → Privacy & Security → Tracking → Toggle off "Allow Apps to Request to Track"
  • Android: Settings → Google → Ads → Toggle off "Opt out of Ads Personalization"
  • Google's Ads Settings: Visit adssettings.google.com
  • In-App Controls: Many of our apps include an in-app "Privacy" or "Ad Settings" option

8.5 Children's Data and AdMob

AdMob does not serve personalized advertising to users known to be under the age of consent in their jurisdiction. For users under 13 (or applicable age in their region), we configure AdMob to serve only contextually appropriate, non-personalized ads. See Section 18 for more details.

9. Advertising Formats We Use

Our free applications may display advertisements in the following formats. Each format serves a specific purpose and is subject to user choice and applicable regulations:

9.1 Banner Ads

Description: Rectangular text or image ads that appear at the top or bottom of the screen. They remain visible while the user interacts with the app.

Implementation: Standard AdMob banner ad units with configurable sizes (e.g., 320x50, 728x90 for tablets). Banners refresh on a schedule or user interaction.

Privacy Considerations: Banners do not require user interaction to be displayed. They use standard ad targeting technologies as described in Section 8.

9.2 Interstitial Ads

Description: Full-screen ads that appear at natural transition points in the app flow, such as between levels, after completing a task, or when navigating between major sections of the app.

Implementation: AdMob interstitial ad units with proper frequency capping (typically no more than one interstitial per user per 3-5 minutes of app use) to avoid disrupting user experience.

Privacy Considerations: We implement proper "ready-to-serve" checks and respect the Google "AdMob" guidelines for interstitials, including not showing them unexpectedly or during critical user actions.

9.3 Rewarded Video Ads

Description: Users voluntarily opt in to watch a video ad in exchange for an in-app reward (e.g., unlocking a premium feature temporarily, earning virtual currency, accessing additional content, removing ads for a period).

Implementation: AdMob rewarded video ad units with clear UI indicators showing the reward amount and that an ad is being shown.

Privacy Considerations: Rewarded ads are always user-initiated. We never auto-play rewarded content. Users can choose to skip the reward if they don't want to watch.

Compliance: We comply with all platform policies for rewarded ads, including proper disclosure, reward delivery, and prohibition of forced engagement with ad content.

9.4 Native Ads

Description: Ads that match the visual design and feel of the app's content. They appear as natural content within feeds, lists, or other layouts, marked with a "Sponsored" or "Ad" label.

Implementation: AdMob native ad formats with custom rendering that maintains the app's minimalist aesthetic.

9.5 App Open Ads

Description: Ads shown when a user opens or returns to the app. They display briefly and dismiss automatically.

Implementation: AdMob app open ad format, integrated carefully to not disrupt the launch experience.

9.6 Ad Frequency Controls

We implement reasonable ad frequency controls across all formats to ensure a positive user experience. We never use aggressive ad practices such as:

  • Ads that obstruct navigation or essential features
  • Ads that interfere with app functionality or input controls
  • Misleading ad placements designed to generate accidental clicks
  • Ads that cannot be closed within 5 seconds when required by platform policy

10. Other Advertising Platforms

In addition to Google AdMob, our applications may integrate with other advertising networks. Each network serves ads according to its own policies and is selected based on performance, privacy practices, and regional availability. We list the most significant networks below; not all networks are integrated into all of our applications.

10.1 Meta Audience Network (Facebook)

Provider: Meta Platforms, Inc.

Purpose: Display of Facebook-sourced advertisements and measurement of advertising effectiveness.

Data Collected: Device identifiers, IP address, event data, advertising IDs, and contextual information.

Privacy Policy: facebook.com/privacy/policy

Opt-out: Users can opt out through Facebook's Ad Preferences at facebook.com/adpreferences and through iOS/Android device settings.

10.2 Unity Ads

Provider: Unity Technologies

Purpose: Display of video and display advertisements in mobile games and applications.

Data Collected: Device identifiers, IP address, device hardware and software information, event data, and contextual information.

Privacy Policy: unity.com/legal/privacy-policy

Opt-out: Available through Unity's privacy portal and device-level advertising preferences.

10.3 AppLovin

Provider: AppLovin Corporation

Purpose: Mobile ad serving and monetization.

Data Collected: Advertising IDs, device information, IP address, event data, and ad interaction data.

Privacy Policy: applovin.com/privacy

Opt-out: Through device settings and AppLovin's opt-out tools.

10.4 Vungle (now part of Liftoff)

Provider: Liftoff Mobile, Inc.

Purpose: Video advertising and in-app monetization.

Data Collected: Device IDs, IP address, app usage, ad interactions, and contextual information.

Privacy Policy: vungle.com/privacy

Opt-out: Through device settings and Vungle's privacy portal.

10.5 ironSource (now Unity)

Provider: ironSource Ltd. (acquired by Unity Technologies)

Purpose: App monetization and ad mediation.

Data Collected: Device IDs, IP address, device characteristics, app events, and advertising engagement data.

Privacy Policy: is.com/privacy-policy

Opt-out: Through device advertising settings.

10.6 InMobi

Provider: InMobi Technology Services Pvt. Ltd.

Purpose: Mobile advertising platform with global reach.

Data Collected: Advertising IDs, IP address, device information, location data (with consent), and behavioral data.

Privacy Policy: inmobi.com/privacy-policy

Opt-out: Through InMobi's preference center and device settings.

10.7 Chartboost (now part of Zynga/InMobi)

Provider: Chartboost, Inc.

Purpose: In-app programmatic advertising, particularly for gaming apps.

Data Collected: Device IDs, IP address, device characteristics, ad interaction data, and in-app events.

Privacy Policy: chartboost.com/privacy

10.8 Pangle (TikTok for Business)

Provider: ByteDance Ltd.

Purpose: TikTok's ad network, providing global reach especially in Asia-Pacific.

Data Collected: Device IDs, IP address, device information, ad interaction data, and event data.

Privacy Policy: pangleglobal.com/privacy

Regional Considerations: Special compliance considerations for users in mainland China, including CSL (Cybersecurity Law) and PIPL.

10.9 Mintegral

Provider: Mintegral International Limited

Purpose: Programmatic advertising platform with strong APAC presence.

Data Collected: Device IDs, IP address, device information, and ad interaction data.

Privacy Policy: mintegral.com/en/privacy

10.10 Tapjoy

Provider: Tapjoy, Inc.

Purpose: Rewarded advertising and offerwall monetization.

Data Collected: Device IDs, IP address, device information, user engagement data, and reward completion data.

Privacy Policy: tapjoy.com/legal

10.11 StartApp

Provider: StartApp Inc.

Purpose: App discovery, monetization, and analytics.

Data Collected: Device IDs, IP address, device characteristics, app usage data, and contextual information.

Privacy Policy: startapp.com/privacy

10.12 Smaato

Provider: Smaato, Inc. (now part of Verve Group)

Purpose: Real-time advertising exchange for mobile apps.

Data Collected: Device IDs, IP address, device information, and ad request/response data.

Privacy Policy: smaato.com/privacy

10.13 AdColony (now part of Digital Turbine)

Provider: Digital Turbine, Inc.

Purpose: Video advertising and interactive ad formats.

Data Collected: Device IDs, IP address, device information, and ad interaction data.

Privacy Policy: adcolony.com/privacy-policy

10.14 Verizon Media / Yahoo (now part of Microsoft Xandr)

Provider: Microsoft Corporation

Purpose: Programmatic advertising exchange.

Privacy Policy: verizonmedia.com/policies

10.15 Criteo

Provider: Criteo S.A.

Purpose: Retargeting and personalized advertising.

Privacy Policy: criteo.com/privacy

10.16 TabMo / Programmatic Partners

We may also work with programmatic advertising partners and supply-side platforms (SSPs) for ad mediation. These partners are bound by their own privacy policies and applicable regulations.

10.17 Ad Mediation Platforms

We use ad mediation services (such as Google AdMob Mediation, AppLovin MAX, or ironSource LevelPlay) to optimize ad fill rates and revenue. These platforms aggregate multiple ad networks and select the best ad to display in real-time. Each mediation platform has its own privacy practices and collects data as described in their respective privacy policies.

11. App Store Compliance

Our applications are distributed through major app stores and comply with their respective policies, guidelines, and requirements. We ensure that all our apps meet the following general requirements:

  • Clear, accurate app descriptions and metadata
  • Functional, stable software that doesn't crash or misbehave
  • No deceptive or misleading content or behavior
  • Compliance with applicable laws and regulations
  • Appropriate content ratings and age classifications
  • Privacy policies linked from app store listings and within apps
  • Compliance with platform-specific privacy label requirements (e.g., Apple Privacy Nutrition Labels, Google Play Data Safety)
  • App Tracking Transparency (ATT) compliance on iOS 14.5+

12. Apple App Store Policies

Our iOS applications published on the Apple App Store comply with all applicable Apple policies, including but not limited to:

12.1 App Store Review Guidelines

  • Guideline 1.4.1: Apps must not contain user-generated content that is offensive, insensitive, or that may upset users
  • Guideline 2.1: App Completeness—apps must be fully functional
  • Guideline 3.2.1: In-App Purchases must use IAP
  • Guideline 4.0: Design considerations and minimum functionality
  • Guideline 5.1.1: Privacy—App Tracking Transparency, data collection, user consent
  • Guideline 5.1.2: Data Use and Sharing—app developers must clearly disclose data collection

12.2 App Tracking Transparency (ATT)

On iOS 14.5 and later, our applications that integrate advertising networks request user permission via Apple's App Tracking Transparency framework before tracking users across other companies' apps and websites. The system shows a standardized prompt:

"[App Name] would like permission to track you across other companies' apps and websites."

Users can choose "Allow" or "Ask App Not to Track." If the user denies, we and our advertising partners do not access the device's Identifier for Advertisers (IDFA), and the displayed ads are non-personalized.

12.3 Privacy Nutrition Labels

Our App Store listings include comprehensive Privacy Nutrition Labels that accurately disclose:

  • Types of data collected (Contact Info, Financial Info, Health & Fitness, Identifiers, Usage Data, Diagnostics, etc.)
  • Whether data is linked to user identity
  • Whether data is used for tracking
  • The purposes for which data is used (Functionality, Analytics, Advertising, Product Personalization, etc.)

12.4 iOS Privacy Manifest

Our iOS applications include Privacy Manifest files (PrivacyInfo.xcprivacy) that document the privacy-relevant behaviors of our apps and any third-party SDKs they use, as required by Apple's privacy manifest requirements.

12.5 Apple's Privacy Policy

Apple's privacy practices, including for App Store, iCloud, and other services, are governed by Apple's Privacy Policy available at apple.com/privacy.

13. Google Play Store Policies

Our Android applications published on the Google Play Store comply with all applicable Google Play policies:

13.1 Google Play Developer Policy

  • User Data Policy: Compliance with policies on data collection, sharing, and security
  • Permissions Policy: Only requesting necessary permissions with clear disclosure
  • Families Policy: If applicable, compliance with requirements for apps used by children
  • Privacy Policy Requirement: A valid privacy policy linked from the app's Play Store listing
  • Ad Policy: Compliance with ad policies including ad disclosure, ad behavior, and ad targeting

13.2 Data Safety Form

Our Google Play listings include comprehensive Data Safety sections that accurately disclose:

  • Whether the app collects or shares any of the required data types
  • How the data is used (app functionality, personalization, security, advertising, etc.)
  • Whether data collection is optional or required
  • Whether data is encrypted in transit
  • Whether users can request data deletion
  • Whether the app complies with Google Play Families Policy

13.3 Google Play Console Privacy Declarations

For new app releases and updates, we provide accurate privacy declarations in the Google Play Console, including the Data Safety form and any required declarations for sensitive permissions and APIs.

13.4 Google API Services User Data Policy

If our apps access Google user data (e.g., through Google Sign-In, Google Drive integration, or Google Play Services), we comply with the Google API Services User Data Policy, including the Limited Use requirements.

13.5 Targeting APIs and Sensitive Permissions

Our apps declare and justify the use of any sensitive permissions (e.g., location, camera, microphone, contacts) and any restricted APIs (e.g., SMS, call log) in the Google Play Console. We only use these permissions for the purposes declared and as required for core app functionality.

13.6 Google's Privacy Policy

Google's privacy practices, including for Google Play, are governed by Google's Privacy Policy available at policies.google.com/privacy.

13.7 Other App Stores

In addition to Apple App Store and Google Play, we may distribute our apps through other app stores such as:

  • Amazon Appstore
  • Samsung Galaxy Store
  • Huawei AppGallery
  • Microsoft Store (for desktop apps)
  • Other regional or specialty app stores

Each app store has its own policies and requirements, which we comply with when distributing through them.

14. Data Sharing & Disclosure

We do not sell, rent, or lease your personal information to third parties. We may share information in the following limited circumstances:

14.1 Service Providers

We may share information with trusted third-party service providers who assist us in operating our Services, including:

  • Cloud infrastructure providers (hosting, storage)
  • Email service providers (for communications)
  • Customer support platforms
  • Analytics providers (with consent)
  • Payment processors (for in-app purchases)
  • App store operators (Apple, Google) for app distribution

All service providers are contractually obligated to maintain the confidentiality and security of your information, and to use it only for the specific purposes we authorize.

14.2 Advertising Partners

In our free applications, we may share certain information with our advertising partners as described in Sections 7-10. This sharing is done in accordance with applicable laws and the partner's privacy policy.

14.3 Legal Requirements

We may disclose information when required by law, including:

  • In response to valid legal processes (subpoenas, court orders, warrants)
  • To comply with applicable laws and regulations
  • To protect our rights, property, or safety, or that of our users or others
  • To investigate potential violations of our Terms of Service
  • To detect, prevent, or address fraud, security, or technical issues

14.4 Business Transfers

If zuozhilin.com is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.

14.5 With Your Consent

We may share your information with third parties when you have given us explicit consent to do so.

15. Data Security Measures

We implement industry-standard technical and organizational security measures to protect your information:

15.1 Technical Safeguards

  • Encryption in Transit: All data transmission uses TLS 1.3 or higher
  • Encryption at Rest: Data stored on our servers is encrypted using AES-256
  • Local Device Encryption: User data in apps is encrypted using platform secure storage (iOS Keychain / Android Keystore / EncryptedFile)
  • Hardware-Backed Keys: Where supported, we use Secure Enclave (iOS) and StrongBox/TEE (Android) for key storage
  • Secure Authentication: Biometric authentication (Face ID, Touch ID, Fingerprint) support
  • Code Obfuscation: Our applications use code obfuscation to prevent reverse engineering
  • Certificate Pinning: Network requests use certificate pinning to prevent MITM attacks
  • Regular Security Updates: We promptly release security patches for vulnerabilities

15.2 Organizational Safeguards

  • Access to user data is limited to authorized personnel only
  • All team members sign confidentiality agreements
  • Regular security training for all team members
  • Incident response procedures in place
  • Regular security audits and penetration testing
  • Data minimization principles applied throughout our development process

15.3 Breach Notification

In the event of a data breach affecting your personal information, we will:

  • Notify affected users within 72 hours of discovery, where feasible
  • Notify relevant supervisory authorities as required by law
  • Provide information about the nature and scope of the breach
  • Outline the steps we're taking to address the breach
  • Offer guidance on protective measures users can take

15.4 Limitations

While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data, and you use our Services at your own risk.

16. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for legal, accounting, or reporting requirements. Specific retention periods include:

  • Contact form submissions: 2 years from last interaction
  • Newsletter subscriptions: Until you unsubscribe, plus 30 days for processing
  • Support tickets: 3 years after closure for quality and legal purposes
  • Server logs: 90 days
  • Aggregated analytics: 14 months maximum
  • App store-related data: As per platform retention policies

Local data stored in our applications is retained indefinitely until you choose to delete it, uninstall the app, or clear the app's data. We do not have access to delete your local data; you control this entirely.

Upon expiration of retention periods, we securely delete or anonymize the data so that it can no longer be associated with you.

17. Your Rights & Choices

Depending on your jurisdiction, you have certain rights regarding your personal information:

17.1 General Rights

  • Right of Access: Request a copy of the personal data we hold about you
  • Right of Rectification: Request correction of inaccurate or incomplete data
  • Right of Erasure (Right to be Forgotten): Request deletion of your personal data
  • Right of Restriction: Request that we restrict processing of your data
  • Right of Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to certain types of processing
  • Right to Withdraw Consent: Withdraw previously given consent at any time
  • Right to Lodge a Complaint: File a complaint with a supervisory authority

17.2 How to Exercise Your Rights

To exercise any of these rights, please contact us at contact@zuozhilin.com. We will respond to your request within 30 days. For verification purposes, we may need to confirm your identity before processing your request.

17.3 In-App Privacy Controls

Many of our applications include built-in privacy controls:

  • Toggle for personalized vs. non-personalized ads
  • Reset / delete all app data option
  • Export your data option
  • Granular permission controls
  • Privacy preferences accessible from the app settings

17.4 Cookie and Tracking Choices

You can control cookies and tracking through:

  • Your browser's privacy settings
  • Operating system privacy settings
  • Our website's cookie consent banner (where applicable)
  • Industry opt-out tools (DAA, EDAA, NAI)

18. Age Restrictions & Children

18.1 General Age Requirements

Our Services are not intended for children under the age of 13 (or the applicable age of digital consent in your jurisdiction, which may be 13, 14, 16, or higher depending on your country). We do not knowingly collect personal information from children below the applicable age threshold.

18.2 Age Thresholds by Region

Different regions have different age thresholds for digital consent:

  • United States (COPPA): Under 13 requires parental consent
  • European Union (GDPR): Under 16 (or as low as 13 if member state permits) requires parental consent
  • United Kingdom (UK GDPR): Under 13 requires parental consent
  • California (CCPA): Under 13 requires parental consent (or under 16 for sale of personal information)
  • Brazil (LGPD): Under 18 requires parental consent (under 12 for specific cases)
  • China (PIPL): Under 14 requires parental consent
  • Australia (Privacy Act): "Reasonable steps" for under 15
  • South Korea (PIPA): Under 14 requires parental consent
  • Japan (APPI): Under 18 requires parental consent for specific cases
  • Canada (PIPEDA): Under 13 requires parental consent
  • India (DPDP Act): Under 18 requires parental consent (under 18)
  • Russia (Federal Law 152-FZ): Under 18 requires parental consent for personal data processing

18.3 Our Approach for Minors

For users between the applicable age of consent and 18 years of age, we:

  • Require parental or guardian consent where required by local law
  • Serve only contextually appropriate, non-personalized advertisements (no behavioral targeting)
  • Do not collect data for advertising purposes beyond what's necessary for ad serving
  • Do not use persistent identifiers for behavioral advertising
  • Comply with all applicable children's privacy laws and regulations

18.4 Parental Rights

Parents and guardians have the right to:

  • Review the personal information we have collected from their child
  • Request that we delete their child's personal information
  • Refuse to permit further collection of their child's information

Parents can exercise these rights by contacting us at contact@zuozhilin.com.

18.5 Children's Online Privacy Protection Act (COPPA)

For users in the United States, we comply with COPPA. We do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected such information, we will delete it promptly. We do not use persistent identifiers to track users under 13 for advertising purposes. We do not condition participation in any activity on the disclosure of more information than is reasonably necessary.

18.6 Google Play Families Policy

If our applications are designated as designed for children or may be used by children, we comply with the Google Play Families Policy, including restrictions on advertising, data collection, and use of certain APIs and SDKs.

18.7 Apple App Store Kids Category

If our applications are included in the Apple App Store's Kids Category, we comply with Apple's Kids Category requirements, which include restrictions on advertising, links out of the app, and data collection from children.

19. International Data Transfers

As a UK-based company with global users, we may transfer your personal data to countries other than your country of residence. When we do so, we ensure appropriate safeguards are in place:

19.1 Transfer Mechanisms

  • European Union / UK: Standard Contractual Clauses (SCCs) approved by the European Commission or UK ICO, plus supplementary measures where required
  • Adequacy Decisions: Transfers to countries with adequacy decisions from the European Commission or UK ICO
  • Data Privacy Framework: For transfers to certified US organizations under the EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework
  • Binding Corporate Rules (BCRs): For intra-group transfers (when applicable)
  • Consent: For specific limited transfers where consent is the appropriate basis

19.2 Specific Country Considerations

We comply with the following international data transfer requirements:

  • EU GDPR (transfers from EEA)
  • UK GDPR (transfers from UK post-Brexit)
  • Schrems II ruling requirements (post-2020 EU-US transfers)
  • Swiss FADP (transfers from Switzerland)
  • China PIPL (transfers from China)
  • Brazil LGPD (transfers from Brazil)
  • Other applicable national laws

20. GDPR Compliance (European Union & United Kingdom)

20.1 Our GDPR Commitments

For users in the European Economic Area (EEA) and the United Kingdom, we comply with the General Data Protection Regulation (GDPR) and the UK GDPR. Our commitments include:

  • Lawfulness, Fairness, Transparency: We process data lawfully, fairly, and transparently
  • Purpose Limitation: We collect data for specified, explicit, and legitimate purposes
  • Data Minimization: We collect only data that is necessary for the purposes for which it is processed
  • Accuracy: We ensure personal data is accurate and kept up to date
  • Storage Limitation: We keep data only as long as necessary
  • Integrity & Confidentiality: We process data securely
  • Accountability: We demonstrate compliance with all GDPR principles

20.2 Legal Bases for Processing

As described in Section 5, we rely on the following legal bases:

  • Consent (Article 6(1)(a))
  • Contract (Article 6(1)(b))
  • Legal obligation (Article 6(1)(c))
  • Vital interests (Article 6(1)(d))
  • Public task (Article 6(1)(e))
  • Legitimate interests (Article 6(1)(f))

20.3 Data Subject Rights under GDPR

You have the right to:

  • Access your personal data (Article 15)
  • Rectify inaccurate data (Article 16)
  • Erase your data, "right to be forgotten" (Article 17)
  • Restrict processing (Article 18)
  • Data portability (Article 20)
  • Object to processing (Article 21)
  • Object to automated decision-making and profiling (Article 22)
  • Withdraw consent at any time (Article 7(3))
  • Lodge a complaint with a supervisory authority (Article 77)

20.4 Data Protection Officer

For GDPR-related inquiries, you can contact our Data Protection Officer (DPO) at contact@zuozhilin.com with the subject line "DPO Inquiry."

20.5 EU Representative

As required by Article 27 of the GDPR, we have appointed an EU representative. Contact information is available upon request to contact@zuozhilin.com.

20.6 Supervisory Authority

You have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA member state of your habitual residence, place of work, or place of the alleged infringement. The Information Commissioner's Office (ICO) is the supervisory authority in the UK:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
Phone: 0303 123 1113

20.7 International Transfers from the EU/UK

As described in Section 19, when we transfer data from the EEA or UK to other jurisdictions, we use appropriate safeguards including Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework where applicable. We conduct transfer impact assessments to ensure your data remains protected.

21. CCPA / CPRA Compliance (California, USA)

21.1 California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)

For California residents, we comply with the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). This section describes your specific rights under these laws.

21.2 Your Rights Under CCPA/CPRA

As a California resident, you have the right to:

  • Right to Know: Request information about the personal information we collect, use, disclose, or sell (Categories, Sources, Business Purposes, Third Parties)
  • Right to Access: Request a copy of the specific personal information we have collected about you
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sale or Sharing: We do not sell personal information; however, you may opt out of any "sharing" for cross-context behavioral advertising
  • Right to Limit Use of Sensitive Personal Information: Restrict our use of sensitive personal information to that necessary to provide the Services
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
  • Right to Data Portability: Receive your information in a portable format

21.3 Categories of Personal Information We Collect

Over the past 12 months, we may have collected the following categories of personal information from California residents:

  • Identifiers: Name, email address, IP address, device IDs
  • Commercial Information: Records of products purchased or considered
  • Internet Activity: Browsing history, app usage, interaction with our Services
  • Geolocation Data: Approximate location derived from IP address (not precise GPS)
  • Inferences: Preferences, characteristics, behaviors

21.4 Sources of Personal Information

We collect personal information from:

  • Directly from you (when you contact us, create content, etc.)
  • Automatically from your device (when you use our Services)
  • From third-party advertising and analytics partners (with consent)

21.5 Business Purposes

We use the personal information for the business purposes described in Section 4 of this policy.

21.6 Do We Sell or Share Personal Information?

No, we do not sell personal information. In the past 12 months, we have not sold any personal information of California residents to third parties for monetary or other valuable consideration.

We may "share" certain limited information (such as device identifiers) with our advertising partners for cross-context behavioral advertising purposes. You have the right to opt out of this sharing. See Section 21.7 below.

21.7 How to Exercise Your CCPA Rights

To exercise your California privacy rights:

  • Email us at contact@zuozhilin.com with the subject line "CCPA Request"
  • Use our "Do Not Sell or Share My Personal Information" link (if applicable)
  • Use in-app privacy controls
  • Authorized agents may submit requests on your behalf with proper authorization

We will respond to verifiable consumer requests within 45 days. If we need additional time, we will notify you of the extension (up to 90 days total).

21.8 Shine the Light Law

California Civil Code Section 1798.83 (Shine the Light) allows California residents to request information about the categories of personal information disclosed to third parties for those third parties' direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.

22. LGPD Compliance (Brazil)

22.1 Lei Geral de Proteção de Dados (LGPD)

For users in Brazil, we comply with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados - LGPD, Law No. 13.709/2018).

22.2 Your Rights Under LGPD

As a Brazilian data subject, you have the right to:

  • Confirmação: Confirmation of the existence of data processing
  • Acesso: Access to your personal data
  • Correção: Correction of incomplete, inaccurate, or outdated data
  • Anonimização, Bloqueio ou Eliminação: Anonymization, blocking, or deletion of unnecessary or excessive data
  • Portabilidade: Data portability
  • Eliminação: Deletion of personal data processed with consent
  • Informação sobre Compartilhamento: Information about public and private entities with which data is shared
  • Informação sobre a Possibilidade de Não Fornecer Consentimento: Information about the consequences of refusing to provide consent
  • Revogação do Consentimento: Withdrawal of consent
  • Reclamação à ANPD: Complaint to the National Data Protection Authority (ANPD)

22.3 Legal Bases for Processing Under LGPD

We rely on the following legal bases under Article 7 of the LGPD:

  • Consent (Art. 7, I)
  • Compliance with legal or regulatory obligation (Art. 7, II)
  • Execution of public policies (Art. 7, III)
  • Studies by research entities (Art. 7, IV)
  • Execution of a contract (Art. 7, V)
  • Exercise of rights in legal proceedings (Art. 7, VI)
  • Protection of life or physical safety (Art. 7, VII)
  • Health protection (Art. 7, VIII)
  • Legitimate interests (Art. 7, IX)
  • Credit protection (Art. 7, X)

22.4 Data Protection Officer (Encarregado)

Our DPO can be contacted at contact@zuozhilin.com with the subject line "LGPD Encarregado."

22.5 ANPD Complaints

You have the right to file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.

23. PIPL Compliance (China)

23.1 Personal Information Protection Law of the People's Republic of China

For users in the People's Republic of China, we comply with the Personal Information Protection Law (PIPL), the Data Security Law (DSL), and the Cybersecurity Law (CSL).

23.2 Your Rights Under PIPL

As a data subject in China, you have the right to:

  • 知情权 (Right to Know): Right to be informed about how your personal information is processed
  • 决定权 (Right to Decide): Right to make or restrict decisions about the processing of your personal information
  • 查询权 (Right of Access): Right to access and copy your personal information
  • 更正权 (Right to Correct): Right to request correction of inaccurate or incomplete information
  • 删除权 (Right to Delete): Right to request deletion under certain conditions
  • 解释权 (Right to Explanation): Right to an explanation of processing rules

23.3 Cross-Border Data Transfers

If we transfer personal information out of China, we comply with PIPL requirements, which may include:

  • Security assessment by the Cyberspace Administration of China (CAC)
  • Standard contractual clauses approved by the CAC
  • Personal information protection certification
  • Other conditions specified by laws and regulations

We currently limit cross-border transfers to data that is necessary for providing our Services and take appropriate measures to protect your information during such transfers.

23.4 Sensitive Personal Information

Under PIPL, sensitive personal information is personal information that, once leaked or illegally used, may easily lead to the infringement of human dignity or harm to the safety of persons or property. This includes biometric information, religious beliefs, specific identity information, medical health information, financial information, location tracking, and personal information of minors under 14.

We process sensitive personal information only with separate consent and with strict necessity and purpose limitation.

23.5 Local Storage Requirements

For critical information infrastructure operators and personal information processors meeting certain thresholds, PIPL and CSL may require data to be stored within China. We assess whether these requirements apply to us and, where they do, ensure compliance with local storage obligations.

24. Other Regional Regulations

24.1 Canada (PIPEDA & Quebec Law 25)

We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, Quebec's Law 25 (modernizing privacy legislation). Canadian users have rights to access, correct, and withdraw consent for their personal information.

24.2 Australia (Privacy Act 1988 & Australian Privacy Principles)

We comply with the Privacy Act 1988 and the Australian Privacy Principles (APPs). Australian users can file complaints with the Office of the Australian Information Commissioner (OAIC).

24.3 Japan (Act on the Protection of Personal Information - APPI)

We comply with APPI, including requirements for use of personal information only within the agreed purpose, security controls, and cross-border transfer consent requirements.

24.4 South Korea (Personal Information Protection Act - PIPA)

We comply with South Korea's PIPA, including requirements for explicit consent, cross-border data transfer notification, and data subject rights. South Korean users can file complaints with the Personal Information Protection Commission.

24.5 Singapore (Personal Data Protection Act - PDPA)

We comply with Singapore's PDPA, including the Do Not Call (DNC) registry requirements for marketing communications.

24.6 India (Digital Personal Data Protection Act - DPDP Act)

We comply with India's DPDP Act 2023, including requirements for consent, data minimization, and data principal rights.

24.7 Russia (Federal Law No. 152-FZ on Personal Data)

We comply with Russian personal data laws, including the requirement to store Russian citizens' personal data on servers located in Russia.

24.8 Switzerland (FADP)

We comply with the Swiss Federal Act on Data Protection (FADP) and acknowledge the role of the Federal Data Protection and Information Commissioner (FDPIC).

24.9 Thailand (PDPA)

We comply with Thailand's Personal Data Protection Act, including cross-border data transfer requirements.

24.10 United Arab Emirates & Saudi Arabia (PDPL)

We comply with the Personal Data Protection Laws in the UAE and Saudi Arabia, including cross-border data transfer requirements.

24.11 Other Jurisdictions

We are committed to complying with applicable privacy laws in all jurisdictions where our Services are used. If you have specific questions about the privacy laws applicable in your country, please contact us at contact@zuozhilin.com.

25. Cookies & Tracking Technologies

25.1 What Are Cookies?

Cookies are small text files that are stored on your device when you visit a website. They are widely used to make websites work more efficiently and to provide information to website owners. We use cookies and similar technologies (such as local storage, web beacons, and pixels) on our website and in our applications.

25.2 Types of Cookies We Use

  • Strictly Necessary Cookies: Essential for the website to function properly. These cannot be disabled.
  • Performance Cookies: Collect information about how visitors use our website (e.g., which pages are visited most often)
  • Functionality Cookies: Remember choices you make (e.g., language preference) to provide enhanced features
  • Targeting/Advertising Cookies: Used to deliver advertisements more relevant to you and your interests

25.3 Third-Party Cookies

Some cookies on our website are placed by third parties. These may include:

  • Google Analytics (for website analytics)
  • Social media platforms (for social sharing features)
  • Embedded content providers (e.g., YouTube, Vimeo)

25.4 Managing Cookies

You can control cookies through:

  • Your browser's privacy settings
  • Our website's cookie consent management tool
  • Industry opt-out tools such as:
    • Digital Advertising Alliance (DAA): aboutads.info
    • European Interactive Digital Advertising Alliance (EDAA): youronlinechoices.com
    • Network Advertising Initiative (NAI): networkadvertising.org

25.5 Do Not Track (DNT)

We honor Do Not Track (DNT) signals. When we detect a DNT signal from your browser, we do not use tracking technologies, place tracking cookies, or use tracking pixels on our website.

25.6 Global Privacy Control (GPC)

We honor Global Privacy Control (GPC) signals as a valid opt-out mechanism for the sale and sharing of personal information under applicable laws.

26. Do Not Track Signals & Global Privacy Control

We respect user privacy choices expressed through:

  • Do Not Track (DNT): Browser-level setting to disable tracking
  • Global Privacy Control (GPC): Browser or extension-based signal indicating privacy preferences
  • Apple's App Tracking Transparency (ATT): iOS-level tracking permission
  • Android's Advertising ID Reset: Reset or opt-out via device settings
  • Privacy Badger, uBlock Origin, and other privacy tools

When we detect these signals, we disable relevant tracking, advertising personalization, and analytics collection to the extent technically feasible.

27. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, and other factors. When we make changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Post a notice on our website and/or within our applications for material changes
  • Where required by law, seek your consent before applying the changes
  • Maintain a historical archive of previous versions (available upon request)

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of our Services after any changes indicates your acceptance of the updated Privacy Policy.

For significant changes, we may provide more prominent notice (such as an in-app notification or email) and, where required by law, request your explicit consent.

28. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, our data practices, or your rights, please contact us:

zuozhilin.com — Data Protection Office

  • Email (Privacy Inquiries): contact@zuozhilin.com
  • Email (General Support): support@zuozhilin.com
  • Mailing Address:
    zuozhilin.com
    University of Stirling Innovation Park
    Stirling, Scotland
    United Kingdom, FK9 4LA
  • Jurisdiction: United Kingdom (UK GDPR applies)
  • Response Time: We aim to respond to all privacy inquiries within 30 days

Complaints and Supervisory Authorities

If you are not satisfied with our response to your privacy concern, you have the right to lodge a complaint with a supervisory authority. The relevant authority depends on your location:

  • UK: Information Commissioner's Office (ICO) — ico.org.uk
  • EU: Your local Data Protection Authority (DPA)
  • California: California Attorney General — oag.ca.gov/privacy
  • Brazil: ANPD — gov.br/anpd
  • Canada: Office of the Privacy Commissioner of Canada — priv.gc.ca

This Privacy Policy is provided in English. Translations may be provided for convenience, but in case of any discrepancy, the English version prevails.

© 2024-2026 zuozhilin.com. All rights reserved.

zuozhilin logo ZUOZHILIN

A research and development studio crafting minimalist, privacy-first digital products. Based at the University of Stirling Innovation Park, UK.

Company

  • Home
  • Services
  • Advantages
  • Updates
  • Contact

Solutions

  • Automation
  • Fitness
  • Finance
  • Security
  • Productivity

Contact

  • support@zuozhilin.com
  • contact@zuozhilin.com
  • University of Stirling Innovation Park, UK
© 2024-2026 zuozhilin.com. All rights reserved.
Privacy Policy Terms of Service app-ads.txt