Privacy Policy
A complete, honest account of the data we collect, how we protect it, who we share it with (almost no one), and the rights you have over it. We aim to be the privacy-respecting alternative in the industry.
1. Overview & Philosophy
songzejiancai.com ("we", "us", "our", or the "Studio") operates this website and a suite of native applications including FlowForge, CurioValue, PostureLog, DeedVault, SparkDeck, and CycleBudget (collectively, the "Services"). This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit, install, or use our Services.
Our guiding principle is local-first, privacy-first: by default, your data stays on your device, encrypted with hardware-rooted keys. We do not require an account, we do not track you across apps or websites, and we do not sell your data 鈥?ever. Where we use third-party services (such as advertising networks in our free apps), we disclose every such partnership here, in plain language.
2. Definitions
- "Personal Data" means any information that identifies, or can reasonably be used to identify, an individual.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
- "Service" or "Services" means the website at songzejiancai.com and the mobile applications published by songzejiancai.com.
- "User" or "you" means any individual who accesses or uses the Services.
- "Device" means any computer, smartphone, tablet, smartwatch, or other device used to access the Services.
- "Local Storage" means data stored on your Device, as opposed to a remote server.
- "Ad Identifier" means Apple's Identifier for Advertising (IDFA) or Google's Advertising ID (GAID), subject to your device-level opt-out.
- "SDK" means a software development kit integrated into our apps for a specific function such as advertising or analytics.
- "EEA" means the European Economic Area.
- "UK" means the United Kingdom.
- "California Resident" means a natural person who resides in the State of California, USA.
3. Data We Collect
Our apps are designed to function without collecting any personal data from you. The data we do collect falls into the following categories:
3.1 Data You Provide Directly
- Contact form submissions (on this website only): Your name, email address, company, and message body when you contact us via the form at /contact.html.
- Newsletter subscription (on this website only): Your email address if you opt into our quarterly studio dispatch.
- Support emails: Information you include when emailing support@songzejiancai.com.
3.2 Data Collected Automatically by Our Apps
- App version and build number: To determine compatibility and route support.
- Device model and OS version: Aggregated, used only for compatibility troubleshooting.
- Locale and language setting: To serve the correct localized interface.
- Crash logs (only if you opt in via the in-app toggle): Anonymized stack traces. Off by default.
3.3 Data We Do NOT Collect
- We do not collect your name, email, phone number, or address in any app unless you explicitly enter it for support.
- We do not collect your precise or coarse location.
- We do not read your contacts, calendar, photos, microphone, or camera.
- We do not track your activity across other apps or websites.
- We do not create advertising profiles or use fingerprinting techniques.
- We do not require or collect account credentials.
3.4 Data Stored Locally on Your Device
In apps that store content (e.g., CurioValue stores your collection, DeedVault stores your documents), that content is stored encrypted, on your Device, using keys that are rooted in your device's secure hardware (Secure Enclave on Apple, StrongBox on Android, TPM on PCs). The keys never leave your Device.
4. How We Use Your Data
We use the limited data we collect only for the following purposes:
- To respond to your inquiries when you contact us.
- To send you the newsletter you explicitly subscribed to (you may unsubscribe at any time).
- To deliver, maintain, and improve our Services, including debugging and compatibility.
- To comply with legal obligations where applicable.
- To display advertising in free apps, as further described in Section 8.
We do not use your data for automated decision-making, profiling for marketing, credit scoring, or any purpose that would produce legal or similarly significant effects on you.
5. Legal Bases for Processing (GDPR / UK GDPR)
For Users in the EEA, UK, or Switzerland, we rely on the following legal bases under the GDPR:
- Consent (Art. 6(1)(a) GDPR): For optional analytics, crash reporting, and the display of advertising. You may withdraw consent at any time.
- Contract (Art. 6(1)(b) GDPR): To respond to your inquiries and provide the Services you have requested.
- Legitimate interests (Art. 6(1)(f) GDPR): For maintaining the security and integrity of our Services, fraud prevention, and basic aggregated analytics.
- Legal obligation (Art. 6(1)(c) GDPR): To comply with valid legal requests from competent authorities.
Where we rely on legitimate interests, you have the right to object. See Section 19.
6. Local-First Storage Architecture
The default storage location for all user-generated content in our apps is on your Device. We have architected our products so that the most private path is also the most performant path 鈥? local access is faster than network access and eliminates entire categories of risk.
6.1 Encryption at Rest
All local storage uses AES-256-GCM or ChaCha20-Poly1305 encryption with keys bound to your device's secure hardware (Apple Secure Enclave, Android StrongBox / Keymaster, Windows TPM). On jailbroken or rooted devices, security guarantees may be reduced.
6.2 Optional Cloud Sync
Where offered (e.g., DeedVault family sharing), cloud sync is end-to-end encrypted. Our servers see only ciphertext; we cannot decrypt your data. If you disable sync, your data remains exclusively on your Device(s).
6.3 Account-Free Operation
None of our apps require you to create an account, sign in with a third-party identity provider, or share your email with us in order to function.
7. App Store Distribution & Platform Policies
7.1 Apple App Store
Our apps are distributed via the Apple App Store under the developer account associated with songzejiancai.com. We comply with the Apple Developer Program License Agreement, the App Store Review Guidelines, and applicable App Tracking Transparency (ATT) requirements.
- We integrate the App Tracking Transparency (ATT) framework on iOS 14.5+ devices, requesting permission before accessing the IDFA.
- We honor the user's selection 鈥?if you decline ATT, no advertising identifier is read and no personalized advertising is shown.
- We do not engage in any "tracking" as defined by Apple's policies.
- We comply with the EU's Digital Markets Act (DMA) requirements for app distribution and privacy disclosures.
7.2 Google Play Store
Our Android apps are distributed via the Google Play Store. We comply with the Google Play Developer Distribution Agreement, the Google Play Developer Policy, and the User Data Policy.
- We declare our data practices in the Google Play Console Data Safety form for every app.
- We honor the user's opt-out of personalized advertising through Google Play Services.
- We respond to Google's Families Policy requirements for any apps accessible to children.
- We declare all SDKs and their data collection practices accurately.
7.3 Apple Mac App Store
Our macOS apps are distributed via the Mac App Store and notarized for direct distribution. They inherit the sandboxing and review requirements of macOS, plus all of the App Store privacy commitments described above.
7.4 Other App Marketplaces
If we distribute through alternative marketplaces (e.g., the Amazon Appstore, the Samsung Galaxy Store, the Huawei AppGallery, regional storefronts in the EEA, UK, India, Japan, Korea, Brazil, or elsewhere), we comply with each marketplace's privacy and developer requirements in addition to our own.
8. Advertising & Ad Networks
Our free apps display advertising through a curated set of ad networks. These ads are contextual by default; we never enable cross-app behavioral tracking in our products.
8.1 How Ads Are Selected
- Contextual targeting: Ads are selected based on the immediate content and language of the app, never on your activity in other apps.
- No first-party data sharing: We do not transmit any user identifier we maintain to ad networks for their own purposes.
- Frequency capping: We cap the number of times any given ad is shown to a user.
- No retargeting outside the app: An ad shown in FlowForge will not "follow" you into another app.
- Children-safe defaults: In any app accessible to children (or set to a child-mode), all advertising is disabled.
8.2 Opting Out of Personalized Advertising
You may opt out at any time, through any of:
- iOS: Settings 鈫?Privacy & Security 鈫?Tracking 鈫?toggle off "Allow Apps to Request to Track"
- iOS: Settings 鈫?Privacy & Security 鈫?Apple Advertising 鈫?toggle off "Personalized Ads"
- Android: Settings 鈫?Google 鈫?Ads 鈫?toggle on "Opt out of Ads Personalization"
- In-app: Each app contains a "Privacy & Ads" screen with an immediate toggle
8.3 Children's Mode and Ads
In any app rated for children (per App Store and Google Play age ratings), all advertising is disabled at the SDK level. Children-mode users see no ads, period.
9. AdMob & Google Compliance
Where our apps display advertising, we commonly integrate the Google Mobile Ads SDK (AdMob). This section documents our compliance with Google's policies in plain language.
9.1 SDK Initialization
- The AdMob SDK initializes lazily and only when an ad is requested, not at app launch.
- On iOS 14.5+, the SDK requests App Tracking Transparency permission before any IDFA collection.
- On Android, the SDK reads the Google Advertising ID only after explicit consent where required.
9.2 Data Collected by AdMob
When AdMob is integrated in our apps, it may collect:
- Device-level identifiers (IDFA / GAID) 鈥?only with consent
- IP address (truncated, not used for precise geolocation)
- Device make, model, and OS version
- App-identifier and ad-unit-identifier
- Impression, click, and conversion events (for billing and fraud prevention)
- Crash logs and SDK diagnostics
9.3 What AdMob Does NOT Receive From Our Apps
- User-generated content stored on-device (e.g., your collection in CurioValue, your documents in DeedVault)
- Your name, email, or any contact information (unless you entered it for app support)
- Your precise location
- Your contacts, calendar, photos, microphone, or camera data
9.4 Google's Policies We Rely On
- We comply with the Google EU User Consent Policy for EEA, UK, and Switzerland users.
- We display a consent dialog before any non-essential cookies or personal data are processed by Google services.
- We do not pass sensitive categories (health, financial, government IDs) to Google's personalization.
- We honor Google's Restricted Data Processing signal where applicable.
- We comply with Google Play Families Policy for any child-directed content.
9.5 Children's Apps and AdMob
Apps classified as "Designed for Families" or marked child-directed do not transmit
the advertising identifier to AdMob. AdMob's tagForChildDirectedTreatment (TFCD) and
tagForUnderAgeOfConsent (TFUA) flags are set where required.
10. Ad Format Inventory
The following ad formats may be displayed in our free apps. Each format is described below along with the controls available to you.
10.1 Banner Ads
Small rectangular ads typically displayed at the top or bottom of a screen. They remain on-screen while you interact with the app. They auto-refresh on a cap-based schedule.
- User controls: May be hidden via in-app "Hide Banner Ads" toggle (where offered). May be suppressed via system-wide ad personalization opt-out.
- Privacy: Does not require persistent storage on your device beyond standard SDK caching.
10.2 Interstitial Ads
Full-screen ads shown at natural transition points (e.g., between levels, after completing a flow, upon app re-launch). They include a clear "X" or "Close" affordance as required by the source network.
- User controls: Frequency capped per session; dismissable after a brief required view-time.
- Privacy: Standard SDK data, no on-device personal data.
10.3 Rewarded Video Ads
Opt-in video ads that the user chooses to watch in exchange for an in-app reward (e.g., unlocking a feature, extending a session, or removing an in-app paywall temporarily). The user always knows the reward before the ad begins, and can always close the ad.
- User controls: 100% opt-in. No reward is offered without explicit user choice.
- Privacy: Reward events are tallied locally; only aggregate counts are reported.
10.4 Native Ads
Ads styled to match the visual language of the surrounding content (e.g., a sponsored item in a list). They are always labelled with "Ad", "Sponsored", or "Promoted" as required by the source network and applicable law.
- User controls: Dismissible; tap the "Why this ad?" link for opt-out options.
10.5 App Open Ads (Splash Ads)
Full-screen ads shown when the app is opened or resumed from background. They are always dismissable and never block critical app functionality.
- User controls: Tap "Close" to dismiss immediately. Will not repeat within a session.
10.6 MREC (Medium Rectangle) Ads
300脳250 pixel ads typically embedded in scrollable content. They refresh on a schedule and are dismissable.
10.7 Offer Wall
Where offered, an opt-in screen listing multiple rewarded offers. Users voluntarily choose which to complete in exchange for in-app rewards.
- User controls: 100% opt-in. No offer is presented without explicit entry into the wall.
10.8 Playable Ads
Interactive ad units that let you try a mini-version of an advertised app before downloading. Only shown in rewarded contexts with explicit user opt-in.
11. All Advertising Partners
Below is the complete list of advertising and monetization partners we integrate in our free apps. Each partner's privacy policy applies in addition to this one. You may opt out of personalized advertising from any of these partners using your device settings or the partner's own opt-out mechanism (where available).
| Partner | Type | Formats Used | Privacy Policy |
|---|---|---|---|
| Google AdMob | Ad Network | Banner, Interstitial, Rewarded, Native, App Open | policies.google.com/privacy |
| Google Ad Manager | Ad Exchange | Banner, Interstitial, Native | policies.google.com/privacy |
| Meta Audience Network | Ad Network | Banner, Interstitial, Rewarded, Native | facebook.com/policy.php |
| Unity Ads | Ad Network | Banner, Interstitial, Rewarded, Playable | unity.com/legal/privacy-policy |
| AppLovin MAX | Mediation / Ad Network | Banner, Interstitial, Rewarded, Native, App Open | applovin.com/privacy |
| ironSource | Mediation / Ad Network | Interstitial, Rewarded, Offer Wall | is.com/privacy-policy |
| Vungle (Liftoff) | Ad Network | Interstitial, Rewarded, Native | vungle.com/privacy |
| Pangle (ByteDance) | Ad Network | Banner, Interstitial, Rewarded, Native | pangleglobal.com/privacy |
| InMobi | Ad Network | Banner, Interstitial, Rewarded, Native, Video | inmobi.com/privacy-policy |
| Chartboost (Zynga) | Ad Network | Interstitial, Rewarded, Banner | chartboost.com/legal/privacy-policy |
| Digital Turbine (AdColony) | Ad Network | Interstitial, Rewarded, Banner | digitalturbine.com/privacy-policy |
| Mintegral | Ad Network | Banner, Interstitial, Rewarded, Native, App Open, Playable | mintegral.com/en/privacy |
| Tapjoy | Ad Network | Offer Wall, Rewarded | tapjoy.com/legal/tapjoy-privacy-policy |
| Liftoff (Vungle + GameRefinery) | Ad Network | Interstitial, Rewarded | liftoff.io/privacy |
| Smaato | Ad Exchange | Banner, Interstitial, Native, Video | smaato.com/privacy |
| Verizon Media / Yahoo | Ad Exchange | Banner, Native | verizonmedia.com/privacy |
| Amazon Publisher Services | Ad Exchange | Banner, Interstitial, Native | amazon.com/privacy |
| DT Exchange (Fyber, Digital Turbine) | Mediation | Banner, Interstitial, Rewarded | digitalturbine.com/privacy-policy |
| MyTarget (Mail.ru) | Ad Network | Banner, Interstitial, Native | legal.my.com/us/privacy |
| Yandex Advertising | Ad Network | Banner, Interstitial, Native | yandex.com/legal/privacy |
| Criteo | Ad Network | Banner, Native | criteo.com/privacy |
| Taboola | Native Ads | Native Content | taboola.com/privacy-policy |
| Outbrain | Native Ads | Native Content | outbrain.com/legal/privacy |
12. Cookies & Tracking Technologies (Website)
Our website is designed to not require cookies for any of its core functionality. We do not use analytics cookies. We do not use advertising cookies. The only cookies set are those strictly necessary to remember your preferences (such as dark/light mode and dismissed banners).
12.1 Cookies We Use
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
sz_theme |
Remembers your light/dark preference | Functional | 365 days |
sz_consent |
Records your cookie consent choice | Functional | 180 days |
sz_banner_dismissed |
Prevents re-showing dismissed notices | Functional | 30 days |
12.2 Cookies We Do Not Use
- No Google Analytics cookies
- No Facebook Pixel cookies
- No third-party advertising cookies
- No cross-site tracking cookies
- No fingerprinting
12.3 Local Storage (this site)
We use localStorage only to remember your dismissal of the cookie banner and to persist
UI state. You can clear local storage at any time via your browser's developer tools.
13. Analytics
We do not use Google Analytics, Mixpanel, Amplitude, Segment, Heap, or any other third-party analytics service on our website or in our apps.
Our apps contain optional, opt-in, on-device-only counters that you may view in the "About this app" screen. These counters record things like "sessions opened" and "features used" 鈥? and never leave your device unless you explicitly tap "Send diagnostic report".
14. Third-Party Services
Beyond advertising networks, our Services may integrate the following types of third-party services:
- Crash & performance: Apple Crash Reports, Google Play vitals, Firebase Crashlytics (opt-in only). Crash data is anonymized and used solely to fix bugs.
- Payment processing: Apple In-App Purchase, Google Play Billing, Stripe, PayPal. These processors receive only the data necessary to complete the transaction.
- Customer support: We may use helpdesk tools (such as Zendesk or Front) to manage support emails. Their privacy policies apply in addition.
- Cloud infrastructure: Where cloud features are used (e.g., DeedVault optional sync), we use AWS or Google Cloud Platform. All data is encrypted in transit and at rest.
- Email delivery: For our newsletter and transactional email, we use reputable providers (such as Postmark, SendGrid, or Mailgun).
15. International Data Transfers
Our studio is based in the United States. If you access the Services from outside the United States, you understand that your information may be transferred to, stored in, and processed in the United States.
For transfers from the EEA, UK, or Switzerland to the United States, we rely on the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA), and equivalent mechanisms for Switzerland. Where data is stored locally on your Device only, no transfer occurs.
For transfers from the People's Republic of China, we comply with the Personal Information Protection Law (PIPL), the Data Security Law (DSL), and the Cybersecurity Law (CSL), including security assessments, standard contracts, or certification as required.
16. Regional Compliance
16.1 European Economic Area (EEA) & United Kingdom
We comply with the General Data Protection Regulation (GDPR) and the UK GDPR, including:
- Lawful, fair, and transparent processing
- Purpose limitation and data minimization
- Accuracy and storage limitation
- Integrity, confidentiality, and accountability
- Data subject rights (access, rectification, erasure, restriction, portability, objection)
- Appointment of an EU representative where required
- Records of processing activities (Art. 30)
- Data Protection Impact Assessments (Art. 35) where required
- Notification of personal data breaches (Art. 33) within 72 hours
16.2 California, USA
We comply with the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and applicable California regulations. California residents have the right to:
- Know what personal information is collected, used, shared, or sold
- Delete personal information we have collected
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information
- Limit the use of sensitive personal information
- Non-discrimination for exercising these rights
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
16.3 Virginia, USA
We comply with the Virginia Consumer Data Protection Act (VCDPA), including consumer rights to access, correct, delete, and obtain a portable copy of personal data, and the right to opt out of targeted advertising, sale, or profiling.
16.4 Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, and Other US States
We comply with applicable state privacy laws, granting residents the rights of access, correction, deletion, portability, and opt-out of targeted advertising and sale.
16.5 Canada
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws including Quebec's Law 25. We honor rights of access, correction, and withdrawal of consent.
16.6 United Kingdom
We comply with the UK GDPR and the Data Protection Act 2018. We are registered with the ICO where applicable and honor all data subject rights.
16.7 Australia
We comply with the Privacy Act 1988 and the Australian Privacy Principles (APPs). We honor the rights of access, correction, and complaint to the Office of the Australian Information Commissioner (OAIC).
16.8 New Zealand
We comply with the Privacy Act 2020 and the Information Privacy Principles (IPPs).
16.9 Japan
We comply with the Act on the Protection of Personal Information (APPI) and provide for the rights of disclosure, correction, and cessation of use.
16.10 South Korea
We comply with the Personal Information Protection Act (PIPA), including rights of access, correction, deletion, and withdrawal of consent, and breach notification requirements.
16.11 Singapore
We comply with the Personal Data Protection Act 2012 (PDPA), including consent, notification, access, correction, and accuracy obligations.
16.12 Brazil
We comply with the Lei Geral de Prote莽茫o de Dados (LGPD), including the rights of confirmation, access, correction, anonymization, portability, deletion, and information about sharing.
16.13 India
We comply with the Digital Personal Data Protection Act, 2023 (DPDP Act), including consent, data principal rights, and breach notification.
16.14 People's Republic of China
Where applicable, we comply with the Personal Information Protection Law (PIPL), the Data Security Law (DSL), and the Cybersecurity Law (CSL), including consent, data localization where required, and security assessment obligations.
16.15 South Africa
We comply with the Protection of Personal Information Act (POPIA), including the rights of access, correction, and objection.
16.16 Other Jurisdictions
We extend the protections described in this Policy to all users, regardless of jurisdiction. If your jurisdiction grants additional rights not enumerated above, we honor them. To exercise your rights, contact us at contact@songzejiancai.com.
17. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Contact form submissions | Up to 24 months after last contact | To respond, follow up, and maintain business history |
| Newsletter subscriptions | Until you unsubscribe | You may unsubscribe via any email's footer link |
| Support emails | Up to 36 months | To support the lifetime of our products |
| App content stored on your device | Until you delete it | You control retention via the app |
| Crash reports (opt-in) | 90 days | To triage and fix reported issues |
| Server logs (if any) | 30 days | Security and operational monitoring |
18. Security Measures
We employ industry-standard administrative, technical, and physical safeguards to protect your information:
- Encryption in transit: TLS 1.3 with modern cipher suites for all network communication.
- Encryption at rest: AES-256 for all stored data.
- Hardware-backed key storage: Secure Enclave, StrongBox, TPM where available.
- Access control: Least-privilege access to production systems, with audit logs.
- Code review: All production changes go through peer review.
- Vulnerability management: Regular dependency audits and penetration testing.
- Incident response: Documented breach response procedures, including the 72-hour GDPR notification clock.
- Backup encryption: All backups encrypted with keys held separately from the data.
- Employee training: Privacy and security training for all team members handling data.
Despite our efforts, no security measure is perfect. If you discover a vulnerability, please report it responsibly to contact@songzejiancai.com. We commit to acknowledging security reports within 48 hours.
19. Your Rights & Choices
Depending on your jurisdiction, you may have some or all of the following rights. To exercise any right, contact us at contact@songzejiancai.com.
- Right of access: Request a copy of the personal data we hold about you.
- Right of rectification: Correct inaccurate or incomplete personal data.
- Right of erasure ("right to be forgotten"): Request deletion of your personal data.
- Right to restriction of processing: Request that we limit how we use your data.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
- Right to lodge a complaint: File a complaint with your local data protection authority.
- Right not to be subject to automated decision-making: We do not subject you to such processing.
- Right to opt out of sale or sharing (CCPA/CPRA): We do not sell personal information.
- Right to limit use of sensitive personal information (CCPA/CPRA).
- Right to non-discrimination for exercising your privacy rights.
19.1 Response Times
We respond to verified requests within 30 days (45 days under CCPA, 30 days under GDPR). If we need additional time, we will notify you with the reason and the extended deadline.
19.2 Verification
To protect your privacy, we verify your identity before acting on requests. We may request additional information necessary to confirm your identity. Authorized agents may submit requests on your behalf where permitted by law (e.g., CCPA).
20. Children's Privacy
Protecting children's privacy is a core value of songzejiancai.com. Our practices comply with:
- COPPA (Children's Online Privacy Protection Act) 鈥?United States
- COPPA Rule (16 CFR Part 312)
- GDPR-K (special protections for children in the EEA and UK)
- Google Play Families Policy
- Apple's Kids Category requirements
- India's DPDP Act provisions for children
- China PIPL special protections for minors
20.1 Our Practices
- We do not knowingly collect personal data from children under 13 (or under the age defined by your jurisdiction, if higher).
- We do not show behavioral advertising to children.
- In any app classified as for children, all advertising is disabled at the SDK level.
- We do not allow in-app purchases by children in our child-directed apps without verifiable parental consent.
20.2 Parental Rights
Parents and guardians may at any time:
- Review the personal data we have collected from their child (if any)
- Request deletion of their child's personal data
- Refuse to permit further collection of their child's personal data
To exercise these rights, contact us at contact@songzejiancai.com.
21. Age Requirements
| Age Threshold | Application | Effect |
|---|---|---|
| Under 13 (or local equivalent) | All apps | No personal data collection. No advertising. No IAP. |
| 13 鈥?15 (EEA / UK) | All apps | Parental consent required for non-essential processing. Advertising disabled. |
| 16 鈥?17 (Korea) | All apps | Parental consent required for personal data processing. |
| 14 (China) | All apps | Parental consent required for personal data processing. Sensitive data requires separate consent. |
| 18 (US, general) | All apps | Full Service access including optional purchases. |
If you believe we have inadvertently collected data from a child in violation of these policies, please contact us at contact@songzejiancai.com and we will delete the data within 7 days.
22. DMCA & Intellectual Property Notices
We respect the intellectual property rights of others and expect our users to do the same. In accordance with the U.S. Digital Millennium Copyright Act of 1998 ("DMCA"), the text of which may be found on the U.S. Copyright Office website at copyright.gov, we will respond expeditiously to claims of copyright infringement.
22.1 Notification
If you believe that any material on our Services infringes upon any copyright which you own or control, you may file a notification of claimed infringement with our designated copyright agent. Your notification must include:
- A physical or electronic signature of the rights holder or authorized agent
- Identification of the copyrighted work claimed to have been infringed
- Identification of the material that is claimed to be infringing or to be the subject of infringing activity, with information sufficient to permit us to locate the material
- Contact information including address, telephone number, and email
- A statement that you have a good-faith belief that use of the material in the manner complained of is not authorized
- A statement that the information in the notification is accurate, and under penalty of perjury, that you are authorized to act on behalf of the owner
22.2 Designated Agent
Our designated DMCA agent can be reached at:
- Email: contact@songzejiancai.com
- Mail: DMCA Agent, songzejiancai.com, Virginia Innovation Center, USA
22.3 Counter-Notification
If you believe content removed under a DMCA notice was the result of a mistake or misidentification, you may submit a counter-notification meeting the requirements of 17 U.S.C. 搂 512(g).
23. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the current revision. Material changes 鈥?those affecting your rights, expanding data collection, or adding new ad partners 鈥?will be announced in-app and via email (where you have provided an email address), at least 30 days before they take effect.
Where required by law (e.g., GDPR Art. 7(3)), we will request fresh consent before applying material changes. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy, except where additional consent is required by applicable law.
24. Contact & Data Protection Officer
For any questions, comments, or requests related to this Privacy Policy or our data practices, please contact:
- Email: contact@songzejiancai.com
- Support: support@songzejiancai.com
- Mail: songzejiancai.com, Virginia Innovation Center, USA
- Data Protection Officer: contact@songzejiancai.com (subject line "DPO")
We aim to acknowledge all inquiries within 2 business days and resolve them within 30 days.
If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority. EU/EEA users may find their supervisory authority at edpb.europa.eu; UK users may contact the ICO at ico.org.uk; California users may contact the California Privacy Protection Agency at cppa.ca.gov.