gzcangshu.com gzcangshu
Home Services Advantages Updates Contact
Get Started
Home Services Advantages Updates Contact
Home / Privacy Policy
Legal

Privacy Policy.

How we collect, use, and protect your information — written in plain language. Our local-first philosophy means we collect less, by design.

On this page

  • 1. Overview
  • 2. Data We Collect
  • 3. How We Use Data
  • 4. Local-First Architecture
  • 5. App Store Policies
  • 6. Advertising & SDK Integrations
  • 7. Ad Format Disclosures
  • 8. Cookies & Tracking
  • 9. Data Sharing
  • 10. Data Retention
  • 11. Security Measures
  • 12. Your Rights & Choices
  • 13. GDPR (EU/EEA)
  • 14. UK GDPR
  • 15. CCPA/CPRA (California)
  • 16. COPPA (Children Under 13)
  • 17. Age Restrictions
  • 18. International Transfers
  • 19. Region-Specific Policies
  • 20. Changes to Policy
  • 21. Contact Us
Effective Date January 15, 2026
Last Updated January 15, 2026
Version 4.2
Data Controller gzcangshu.com
Contact contact@gzcangshu.com

1. Overview

gzcangshu.com ("we," "us," "our," or "the Company") operates a research-driven software development studio headquartered at Bristol & Bath Science Park, United Kingdom. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website (gzcangshu.com), use our mobile applications published on various app stores (including Apple's App Store, Google Play, Microsoft Store, Amazon Appstore, Samsung Galaxy Store, and Huawei AppGallery), or otherwise interact with our services (collectively, the "Services").

Our core privacy principle: We design our products so that user data stays on the user's device by default. We collect the minimum information necessary to operate our Services, we do not sell personal information, and we do not engage in cross-site behavioural advertising. Where third-party advertising or analytics is integrated into our mobile applications (such as AdMob, Facebook Audience Network, or Unity Ads), we make every reasonable effort to minimise data collection, restrict the categories of data shared, and offer users clear controls over advertising personalisation in accordance with applicable laws.

Summary in plain language: We build local-first software. Your data lives on your device unless you explicitly choose to sync it. Our mobile applications that display advertising do so through SDKs that comply with Apple's App Tracking Transparency framework, Google's Play Store Families Policy, and the EU's TCF 2.2. We never sell your personal data.

2. Data We Collect

2.1 Information You Provide Directly

When you contact us, subscribe to updates, or otherwise communicate with us, we may collect:

  • Name and contact information (email address, postal address when relevant)
  • Communication content (your messages, feedback, support requests)
  • Account credentials if you create an account with our Services
  • Any other information you choose to provide

2.2 Information Collected Automatically

When you visit our website, we may automatically collect:

  • IP address and approximate geographic location (country / city level)
  • Browser type, version, and operating system
  • Referring URL and pages visited
  • Date, time, and duration of visits
  • Device identifiers (mobile device type, screen resolution)

2.3 Information From Mobile Applications

Our mobile applications are designed to operate without transmitting personal data off your device. Where local-first operation is not feasible, we collect only the minimum necessary:

  • App Store Receipt Validation: Anonymous receipt validation tokens shared with Apple/Google for licence verification
  • Crash Diagnostics (opt-in): If you opt in to share crash reports, anonymised diagnostic data may be collected
  • Advertising Identifiers (limited apps): Where advertising is displayed, the IDFA (iOS) or GAID (Android) is accessed only after your explicit consent via App Tracking Transparency

2.4 Cookies and Similar Technologies

Our website uses a minimal set of cookies — primarily those strictly necessary for site functionality. See Section 8 for full details.

3. How We Use Data

We use collected information for the following purposes:

  1. Service Operation: To provide, maintain, secure, and improve our Services
  2. Communication: To respond to your enquiries and send you updates you have requested
  3. Analytics: To understand aggregate usage patterns and improve our products (only with anonymised, aggregated data)
  4. Legal Compliance: To comply with applicable laws, regulations, and legal processes
  5. Security: To detect, prevent, and address fraud, security issues, and abuse
  6. Advertising: Where advertising is integrated into specific apps, to display ads and measure their basic effectiveness — only after you have provided the necessary consent

We do NOT use your data for:

  • Selling personal information to data brokers or third-party marketers
  • Cross-site behavioural advertising beyond the bounds of the specific app you are using
  • Profiling for automated decision-making that produces legal or similarly significant effects
  • Any purpose unrelated to operating and improving our Services without your consent

4. Local-First Architecture

Our products are engineered around the principle that user data should remain on the user's device by default. Concretely, this means:

  • On-Device Storage: Personal content, documents, ideas, budgets, fitness data, and collection data are stored locally on your device using encrypted databases (Core Data, SQLite with SQLCipher extensions)
  • Optional Sync: Where we offer cross-device sync, it is end-to-end encrypted using AES-256 with keys derived from your password via Argon2id — we cannot read your data
  • No Account Required: Most of our applications are fully functional without creating an account
  • Data Export: We provide standard data export (JSON, CSV) so you can leave at any time and take your data with you
  • Data Deletion: Uninstalling the app or deleting your account permanently removes all associated data from our servers within 30 days

5. App Store Policies

Our applications are distributed through the following app stores, each of which has its own policies that govern our conduct and the data practices of our apps:

5.1 Apple App Store

Our iOS, iPadOS, macOS, watchOS, and visionOS applications are published on Apple's App Store and comply with:

  • App Store Review Guidelines (Apple Developer, current version)
  • Apple Developer Program License Agreement
  • App Privacy Details — we declare all data practices in the privacy "nutrition labels" on each App Store listing
  • App Tracking Transparency (ATT) — we request permission via the ATT framework before accessing IDFA in any app that integrates advertising SDKs
  • Privacy Manifest (PrivacyInfo.xcprivacy) — required APIs and tracking domains are declared in each app's privacy manifest
  • EU Digital Services Act and Digital Markets Act compliance for users in the EU

5.2 Google Play Store

Our Android applications (where applicable) are published on Google Play and comply with:

  • Google Play Developer Program Policies
  • Google Play Console Data Safety Form — accurate disclosures of data collection and sharing
  • Families Policy — applications likely to be accessed by children comply with the Google Play Families Policy
  • EU User Consent Policy — consent obtained for ads personalisation and tracking

5.3 Microsoft Store

Where applicable, our Windows applications are published on the Microsoft Store and comply with:

  • Microsoft Store Policies
  • Microsoft Privacy Statement

5.4 Amazon Appstore

Where applicable, our applications are available on the Amazon Appstore and comply with:

  • Amazon Developer Services Agreement
  • Amazon Appstore Developer Guidelines

5.5 Samsung Galaxy Store

Where applicable, our applications are published on the Samsung Galaxy Store and comply with:

  • Samsung Galaxy Store Developer Agreement
  • Samsung Privacy Policy

5.6 Huawei AppGallery

Where applicable, our applications are published on Huawei AppGallery and comply with:

  • Huawei Developer Service Agreement
  • Huawei Privacy Policy

5.7 Xiaomi Mi Store / Oppo Software Store / Vivo App Store

Where applicable, our applications comply with the respective developer agreements and privacy policies of these regional Android app stores.

6. Advertising & SDK Integrations

Some of our applications integrate third-party advertising and analytics Software Development Kits (SDKs) to support free-tier functionality. Each SDK is selected to comply with applicable privacy regulations and minimise data exposure.

The following advertising and analytics platforms may be integrated in our apps (current and historical):

  • Google AdMob (AdSense for Apps / Google Mobile Ads SDK) — primary monetisation partner; provides banner ads, interstitial ads, rewarded video ads, and native ads. Privacy Policy: policies.google.com/privacy. AdMob is integrated with Google's User Messaging Platform (UMP) for GDPR consent.
  • Google Ad Manager (formerly DoubleClick for Publishers / DFP / Google AdX) — used for direct-sold and programmatic ads. policies.google.com/privacy
  • Google AdSense — contextual ads for web properties. policies.google.com/privacy
  • Google Analytics for Firebase — anonymised, opt-in event tracking. firebase.google.com/support/privacy
  • Facebook Audience Network (Meta Audience Network) — banner, interstitial, rewarded video, and native ads. facebook.com/policy.php
  • Unity Ads (Unity LevelPlay / ironSource) — rewarded video and interstitial ads in games and utility apps. unity.com/legal/privacy-policy
  • AppLovin (AppLovin MAX) — banner, interstitial, rewarded video, and native ads. applovin.com/privacy
  • ironSource — rewarded video, interstitial, and offerwall ads. is.com/privacy-policy
  • Vungle (now part of Liftoff) — rewarded video and interstitial ads. vungle.com/privacy
  • Chartboost — interstitial, rewarded video, and native ads in games. chartboost.com/privacy
  • AdColony (now Digital Turbine) — video and playable ads. adcolony.com/privacy-policy
  • InMobi — banner, interstitial, rewarded video, and native ads. inmobi.com/privacy-policy
  • Tapjoy — offerwall and rewarded ads. tapjoy.com/privacy-policy
  • Pangle (Bytedance Ads) — banner, interstitial, rewarded video, and native ads. pangleglobal.com/privacy
  • Amazon Publisher Services (APS) / Amazon Ads — header bidding and direct ads. amazon.com/privacy
  • Verizon Media / Yahoo Ads (now part of Microsoft Advertising) — programmatic advertising. verizonmedia.com/privacy
  • Smaato — programmatic header bidding. smaato.com/privacy
  • MobFox (now part of Verve Group) — programmatic advertising. verve.com/privacy-policy
  • StartApp — app discovery ads. startapp.com/privacy
  • Millennial Media (part of Viant) — programmatic advertising. viantinc.com/privacy-policy
  • Ogury — personified advertising. ogury.com/privacy-policy
  • BidMachine — programmatic header bidding. bidmachine.io/privacy-policy
  • Digital Turbine — programmatic and direct advertising. digitalturbine.com/privacy-policy
  • HyprMX — rewarded video ads. hyprmx.com/privacy-policy
  • Luna — programmatic advertising platform. lunadna.com/privacy
  • Loopme — video and programmatic advertising. loopme.com/privacy-policy
  • Yandex Ads — programmatic advertising. yandex.com/legal/privacy
  • Criteo — retargeting and programmatic advertising. criteo.com/privacy
  • Mintegral — programmatic advertising. mintegral.com/en/privacy
  • MyTarget (VK / Mail.ru) — programmatic advertising. legal.my.com/us/privacy

Each SDK is integrated with appropriate consent management: Google UMP (TCF 2.2 compliant), Apple's ATT prompt, and equivalent consent flows where required by local law. You can withdraw consent at any time via the in-app "Privacy" settings menu.

7. Ad Format Disclosures

The advertising SDKs integrated into our apps may display any of the following ad formats. Each format is subject to the consent rules described above:

7.1 Banner Ads

Static or animated rectangular advertisements displayed at the top or bottom of a screen. They may refresh automatically. Used by AdMob, Facebook Audience Network, AppLovin MAX, InMobi, Smaato, and others. These ads use contextual information (e.g., app category, general geographic region) and may use device identifiers only with consent.

7.2 Interstitial Ads

Full-screen advertisements displayed at natural transition points in an app (e.g., between levels, after completing an action). Users can dismiss these ads. Used by AdMob, Facebook Audience Network, Unity Ads, AppLovin, ironSource, Chartboost, AdColony, Vungle, Tapjoy, InMobi, and others.

7.3 Rewarded Video Ads

Full-screen video advertisements that users voluntarily watch in exchange for an in-app reward (e.g., extra features, virtual currency). Users must explicitly opt in by tapping a "Watch Ad" or similar button. Used by AdMob, Unity Ads, ironSource, AppLovin, Vungle, Chartboost, AdColony, Tapjoy, Mintegral, Pangle, and others.

7.4 Native Ads

Ads designed to match the visual design of the app in which they appear. They are labelled "Sponsored" or "Ad" to distinguish them from organic content. Used by AdMob, Facebook Audience Network, AppLovin, InMobi, and others.

7.5 Open Screen / Splash Ads

Ads displayed when an app is first launched, before the main content loads. Used by AdMob, ironSource, AppLovin, and others. We avoid splash ads where possible to preserve user experience.

7.6 Offerwall Ads

Listings of multiple rewarded actions (install another app, complete a survey, etc.) that users complete in exchange for in-app rewards. Used by Tapjoy, ironSource, and others.

All ad formats are subject to:

  • Children-appropriate content filtering per COPPA and Google Play Families Policy
  • Geographic restrictions per applicable sanctions and embargo lists
  • Ad quality reviews enforced by each ad network
  • The right of users to limit ad personalisation through in-app settings

8. Cookies & Tracking

Our website uses a minimal, privacy-respecting set of cookies:

Cookie Purpose Type Duration
gzcangshu_consent Stores your cookie preferences Strictly necessary 1 year
session_id Session management Strictly necessary Session
gzcangshu_lang Language preference Functional 1 year

We do not use third-party analytics cookies on our marketing website. We do not use cross-site tracking cookies. We do not use advertising cookies on our marketing website.

9. Data Sharing

We do not sell personal information. We share personal information only in the following limited circumstances:

  • Service Providers: With carefully vetted processors (hosting, email delivery, customer support) bound by data processing agreements
  • Advertising Partners: With ad networks only after you have provided consent through App Tracking Transparency, Google UMP, or equivalent consent frameworks — see Section 6
  • App Stores: With Apple, Google, Microsoft, Amazon, Samsung, Huawei, etc., as required for app distribution, licence validation, and refund processing
  • Legal Requirements: When required by law, valid legal process, or to protect our rights or safety
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to users

10. Data Retention

We retain personal data only for as long as necessary to provide our Services or comply with legal obligations:

  • Account Data: Retained while your account is active; deleted within 30 days of account closure
  • Communication Records: Retained for 24 months for quality and training purposes, then deleted
  • Server Logs: Retained for 90 days, then aggregated or deleted
  • Advertising Data: Retained per each advertising network's own retention policy (typically 13-18 months)
  • Backups: Encrypted backups retained for 30 days, then overwritten

11. Security Measures

We implement industry-standard security measures to protect your information:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Argon2id password hashing
  • Regular third-party security audits and penetration testing
  • Strict access controls and the principle of least privilege
  • SOC 2 Type II-aligned operational practices
  • Incident response and breach notification procedures

12. Your Rights & Choices

Depending on your jurisdiction, you may have some or all of the following rights:

  • Right of Access: Request a copy of personal data we hold about you
  • Right of Rectification: Correct inaccurate or incomplete data
  • Right of Erasure: Request deletion of your personal data
  • Right of Restriction: Limit how we process your data
  • Right of Portability: Receive your data in a portable format
  • Right to Object: Object to processing based on legitimate interest or for direct marketing
  • Right to Withdraw Consent: Withdraw previously given consent at any time
  • Right to Lodge a Complaint: Lodge a complaint with a supervisory authority

To exercise these rights, contact contact@gzcangshu.com. We respond within 30 days.

13. GDPR (EU/EEA)

For users in the European Economic Area, we comply with the General Data Protection Regulation (GDPR). The lawful bases we rely on for processing are:

  • Consent (Art. 6(1)(a)): For advertising personalisation, analytics cookies, and marketing communications
  • Contract (Art. 6(1)(b)): For providing the Services you have requested
  • Legal Obligation (Art. 6(1)(c)): For tax, accounting, and other legal compliance
  • Legitimate Interests (Art. 6(1)(f)): For security, fraud prevention, and product improvement — balanced against your rights

EU Representative: We have appointed an EU representative under Article 27 GDPR. Contact details available upon request.

14. UK GDPR

For users in the United Kingdom, we comply with the UK General Data Protection Regulation and the Data Protection Act 2018. The Information Commissioner's Office (ICO) is the supervisory authority. You may lodge a complaint with the ICO at ico.org.uk.

15. CCPA/CPRA (California)

For California residents, we comply with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). Your rights include:

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information collected
  • Right to opt-out of the sale or sharing of personal information (we do not sell)
  • Right to non-discrimination for exercising CCPA rights
  • Right to correct inaccurate personal information
  • Right to limit use of sensitive personal information

To exercise these rights, contact contact@gzcangshu.com or call our toll-free number. We will respond within 45 days.

16. COPPA (Children Under 13)

We comply with the Children's Online Privacy Protection Act (COPPA) in the United States and equivalent child privacy laws in other jurisdictions. Our applications:

  • Do not knowingly collect personal information from children under 13
  • Are not directed at children under 13
  • Implement neutral age-gates before any advertising or personalisation
  • Disable behavioural advertising for users identified as under 13
  • Use child-directed ad treatments (e.g., Google Play Families self-certification) where applicable
  • Restrict SDKs to those certified for child-directed content per Google Play Families Policy

If we learn that we have collected information from a child under 13 without verifiable parental consent, we will delete it as soon as possible. Parents may contact us to review, delete, or refuse further collection of their child's information.

17. Age Restrictions

Our Services are intended for users aged 13 and over, or the equivalent digital consent age in your country (16 in some EU member states, 14 in others, 13 in the UK and US, 13 in most other countries). Users under this age must obtain verifiable parental or guardian consent before using our Services or providing any personal information.

If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact contact@gzcangshu.com and we will promptly delete the information.

18. International Transfers

We are headquartered in the United Kingdom. Where personal data is transferred outside the UK or EEA, we ensure adequate protection through:

  • UK International Data Transfer Agreement (IDTA)
  • EU Standard Contractual Clauses (SCCs)
  • UK Extension to the EU-US Data Privacy Framework
  • Adequacy decisions by the UK government or European Commission
  • Encryption in transit and at rest
  • Strict access controls

19. Region-Specific Policies

19.1 European Union (EU/EEA)

GDPR applies. See Section 13. Local supervisory authorities exist in each member state. Examples: CNIL (France), BfDI (Germany), Garante (Italy), AEPD (Spain), AP (Netherlands), DPA (Denmark), Datainspektionen (Sweden).

19.2 United Kingdom

UK GDPR + Data Protection Act 2018. See Section 14. Supervisory authority: Information Commissioner's Office (ICO).

19.3 United States

Multiple sector-specific and state laws apply: CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), TDPSA (Texas), OCPA (Oregon), NJDPA (New Jersey), DPDPA (Delaware), ICDPA (Iowa), INCDPA (Indiana), MCDPA (Maryland), MNCDPA (Minnesota), NHPA (New Hampshire), RIPA (Rhode Island), plus federal COPPA, HIPAA (where applicable), GLBA, and CAN-SPAM Act.

19.4 Canada

PIPEDA (Personal Information Protection and Electronic Documents Act) plus Quebec's Law 25 (modernised privacy framework). Office of the Privacy Commissioner of Canada is the federal supervisory authority; Commission d'accès à l'information (CAI) in Quebec.

19.5 Australia

Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Notifiable Data Breaches scheme. Office of the Australian Information Commissioner (OAIC).

19.6 New Zealand

Privacy Act 2020. Office of the Privacy Commissioner (OPC).

19.7 Japan

Act on the Protection of Personal Information (APPI). Personal Information Protection Commission (PPC).

19.8 South Korea

Personal Information Protection Act (PIPA). Personal Information Protection Commission (PIPC).

19.9 Singapore

Personal Data Protection Act 2012 (PDPA). Personal Data Protection Commission (PDPC).

19.10 Brazil

Lei Geral de Proteção de Dados (LGPD). Autoridade Nacional de Proteção de Dados (ANPD).

19.11 China (PRC)

Personal Information Protection Law (PIPL), Cybersecurity Law (CSL), Data Security Law (DSL). Cyberspace Administration of China (CAC).

19.12 India

Digital Personal Data Protection Act 2023 (DPDP Act). Ministry of Electronics and Information Technology (MeitY).

19.13 Russia

Federal Law No. 152-FZ on Personal Data. Roskomnadzor.

19.14 Germany, France, Italy, Spain, Netherlands, Belgium, Austria, Switzerland, Ireland

GDPR applies as in other EU/EEA countries. Switzerland has its own FADP (Federal Act on Data Protection) which is largely aligned with GDPR. National supervisory authorities: BfDI (Germany), CNIL (France), Garante (Italy), AEPD (Spain), AP (Netherlands), DPA (Belgium), DSB (Austria), FDPIC (Switzerland), DPC (Ireland).

19.15 Other Regions

For users in jurisdictions not specifically listed above, we apply GDPR-equivalent or stricter standards by default. You can always contact us at contact@gzcangshu.com for region-specific information.

20. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Effective Date" at the top of this policy and, where appropriate, notify users through our Services or by email. We encourage you to review this policy periodically to stay informed about how we protect your information.

Material changes will be communicated at least 30 days in advance, providing you the opportunity to review and, where required by law, consent to the updated terms.

21. Contact Us

If you have any questions about this Privacy Policy, our data practices, or wish to exercise your rights, please contact us:

  • Email (Privacy Enquiries): contact@gzcangshu.com
  • Email (General Support): support@gzcangshu.com
  • Postal Address: gzcangshu.com, Bristol & Bath Science Park, United Kingdom
  • Response Time: We aim to respond to all privacy enquiries within 30 days

Last revised: 15 January 2026 · Document version: 4.2
For previous versions of this policy, contact contact@gzcangshu.com.

gzcangshu.com gzcangshu.com

A research-driven development team building local-first, privacy-respecting digital products from Bristol & Bath, UK.

Company

  • Home
  • Services
  • Advantages
  • Updates
  • Contact

Contact

  • contact@gzcangshu.com
  • support@gzcangshu.com
  • Bristol & Bath Science Park
  • United Kingdom

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • GDPR Compliance
  • Children's Privacy
© 2026 gzcangshu.com. All rights reserved. Made with care in Bristol, UK.
PrivacyTermsCookiesContact