Privacy & Data Protection
Privacy Policy
Youyin is built with a local-first, privacy-by-design architecture. Your learning progress, custom flashcards, and preferences are stored exclusively on your own device and are never transmitted to a remote server.
100% Local Storage
No Accounts or Sign-up
No Tracking or Ads
Full Data Control
This Privacy Policy explains how Heapforge Ltd. (“Heapforge”, “we”, “us” or “our”) collects, uses, shares and protects personal data when you visit https://youyin.madladsquad.com, use Youyin, or otherwise contact us. It also explains the rights you have and how to exercise them.
1. Who we are
The data controller responsible for your personal data is Heapforge Ltd., registered in England and Wales:
- Company
- Heapforge Ltd.
- Company number
- 17418393
- Registered office
- 82A James Carter Road, Mildenhall, Bury St. Edmunds, Suffolk, England, IP28 7DE, United Kingdom
- Privacy contact
- privacy@heapforge.com
2. Scope
This policy applies to personal data we process through this service, as well as when you communicate with us. It does not apply to third-party websites or services that we link to, which have their own privacy policies.
3. Personal data we collect
We try to collect only what we need. Depending on how you interact with us, this may include:
- Contact information – such as your name and email address, when you email us or otherwise get in touch.
- Communications – the content of messages you send us, including any attachments, and our replies.
- Technical and usage information – such as your IP address, browser type, device information, the pages you request, and the date and time of your visit. This is processed automatically when you access our website, mainly for security and to deliver the site to you.
- Account and transaction information – where you use a paid service, information needed to provide it (for example, purchase confirmations). We do not directly collect or store full payment card details.
- Any other information you choose to provide to us.
We do not intentionally collect special category data (such as health, religious or biometric data). Please do not send us such information unless we have specifically asked for it.
4. How we use personal data and our lawful bases
Under the UK and EU GDPR, we must have a lawful basis for each use of your personal data.
| Purpose | Lawful basis |
|---|---|
| Delivering our website and services to you | Legitimate interests (operating our website and business); contract, where you use our services |
| Protecting our website and services from abuse, fraud, bots and attacks | Legitimate interests (keeping our services and users secure) |
| Responding to your emails and enquiries | Legitimate interests (communicating with people who contact us); contract, where the enquiry relates to a service you use or are about to use |
| Providing, managing and supporting services you have purchased | Contract |
| Keeping business records and meeting legal, tax and regulatory obligations | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests |
| Any purpose for which we ask for your consent | Consent (which you can withdraw at any time) |
Where we rely on legitimate interests, we have considered whether those interests are outweighed by your rights and freedoms. You can contact us for more information about this balancing.
We do not sell your personal data.
5. Third-party service providers
We use a number of trusted service providers to run our business. They process personal data on our behalf and under our instructions, and are bound by contractual obligations to protect it. Our main providers are listed below.
5.1 Cloudflare
We use services provided by Cloudflare, Inc. to host, deliver and protect our website:
- Security and bot protection – Cloudflare screens traffic to our website to protect it against denial-of-service attacks, automated bots and other malicious activity. To do this, it analyses information such as IP addresses, browser and device characteristics and request details, and may set a strictly necessary security cookie.
- Website hosting – our website is served using Cloudflare's hosting and edge computing services (Cloudflare Pages and Workers), which process web requests and other technical information in order to deliver pages to you.
- Content delivery – static files such as images, scripts and stylesheets are stored and delivered using Cloudflare's storage and content delivery network (Cloudflare R2).
Cloudflare operates a global network, so your data may be processed in data centres close to your location, including outside the UK and EU. For more information, see Cloudflare's Privacy Policy: https://www.cloudflare.com/privacypolicy/
5.2 Google Workspace
We use Google Workspace, provided by Google, as our email provider. When you email us, your message – including your name, email address, message content, attachments and related metadata – is received, stored and processed on Google's systems. Google processes this data on our behalf under its business data processing terms and does not use Workspace customer data for advertising.
For more information, see Google's Privacy Policy (https://policies.google.com/privacy) and Google Cloud Privacy Notice (https://cloud.google.com/terms/cloud-privacy-notice).
5.3 Other recipients
We may also share some personal data with:
- professional advisers such as accountants, lawyers and insurers, where necessary;
- law enforcement, regulators, courts or other authorities, where required by law or to protect our rights, users or the public;
- a buyer, successor or investor in connection with a merger, acquisition, restructuring or sale of all or part of our business, subject to appropriate confidentiality protections.
6. Cookies and similar technologies
We only use cookies and similar technologies that are strictly necessary for our website to function securely, such as security cookies to distinguish genuine visitors from automated bots. These do not require your consent under UK and EU law, and we do not use them to track you across other websites.
If we introduce non-essential cookies (for example, for analytics or advertising), we will update this policy and, where required by law, ask for your consent before setting them.
7. International data transfers
We are based in the United Kingdom, and some of our service providers process data in other countries, including the United States.
Where personal data is transferred outside the UK or the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
- transfers to countries recognised as providing an adequate level of protection (adequacy regulations/decisions);
- transfers to organisations certified under the EU-U.S. Data Privacy Framework and its UK Extension (the “UK-US data bridge”);
- Standard Contractual Clauses approved by the European Commission, together with the UK International Data Transfer Addendum or UK International Data Transfer Agreement, where applicable.
You can contact us for more information about the safeguards we use.
8. How long we keep personal data
We keep personal data only for as long as necessary for the purposes described in this policy, including to meet legal, accounting or reporting requirements. As a general guide:
- Email correspondence – kept for 24 months after our last contact, unless it relates to an ongoing matter or we need to keep it longer for legal reasons.
- Security and technical logs – kept for short periods only, as needed for security and troubleshooting.
- Business and transaction records – kept for as long as required by law (in the UK, typically up to six years after the end of the relevant financial year).
When data is no longer needed, we delete or anonymise it securely.
9. How we protect personal data
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration. These include encryption in transit, access controls and choosing reputable providers with strong security practices. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
If a personal data breach occurs that is likely to put your rights at risk, we will notify you and the relevant authorities as required by law.
10. Your rights (UK, EU, EEA and Switzerland)
If you are in the UK, EU, EEA or Switzerland, you have the following rights, subject to certain conditions and exceptions:
- Access – to request a copy of the personal data we hold about you.
- Rectification – to ask us to correct inaccurate or incomplete data.
- Erasure – to ask us to delete your data in certain circumstances.
- Restriction – to ask us to limit how we use your data in certain circumstances.
- Data portability – to receive data you provided to us in a structured, commonly used format, or have it transferred to another organisation.
- Objection – to object to processing based on our legitimate interests, and to object at any time to direct marketing.
- Withdraw consent – where we rely on consent, you may withdraw it at any time without affecting earlier processing.
- Not to be subject to solely automated decisions with legal or similarly significant effects.
To exercise any of these rights, email us at privacy@heapforge.com. We will respond within one month, which may be extended by up to two further months for complex requests. We may need to verify your identity before responding. Exercising your rights is usually free of charge.
11. Other countries
If you live in another country with privacy laws that give you rights over your personal data, please contact us and we will respond in accordance with the law that applies to you.
12. Children's privacy
Our website and services are not directed at children under the minimal age for data processing consent, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Automated decision-making
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Automated security tools (such as bot protection) may block or challenge suspicious traffic; if you believe you have been blocked in error, please contact us.
14. Links to other websites
Our website may contain links to third-party websites or services. We are not responsible for their privacy practices, and we encourage you to read their privacy policies.
15. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top shows when it was last revised. If we make significant changes, we will take reasonable steps to let you know, for example by a notice on our website.
16. Contact us and complaints
If you have any questions about this policy or how we handle your personal data, please contact us:
- E-mail: privacy@heapforge.com
- Post: Heapforge Ltd., 82A James Carter Road, Mildenhall, Bury St. Edmunds, Suffolk, England, IP28 7DE, United Kingdom
We would appreciate the chance to address your concerns first, but you have the right to complain to a data protection authority:
- United Kingdom: Information Commissioner's Office (ICO) – https://ico.org.uk/make-a-complaint/
- EU/EEA: the supervisory authority in the country where you live, work or where the alleged infringement took place – a list is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en
- Other regions: your local data protection or privacy regulator.