Last revised and effective: September 23, 2026.
Applicable product: the YinyangFlow app and related services. This English Policy applies to services outside Mainland China, including Singapore, Malaysia, the United States, the United Kingdom and the EEA. Protection does not depend on your app marketplace or device system, and interface language alone does not determine applicable law. Mandatory local privacy rules prevail to the extent of any inconsistency.
Operator and data controller: Noonwake Technology Limited, the English name of 深圳市晌午不眠科技有限公司, the same company registered in Shenzhen, Guangdong, China. It is not a separate overseas legal entity.
I. General Processing Principles
We process personal information lawfully, fairly and transparently, in good faith and only as necessary for specified, reasonable purposes. We apply data minimization.
We do not collect information unrelated to core functions at first launch or in unrelated situations without your explicit consent. If you decline or withdraw consent, we stop the relevant processing and provide equivalent basic services where technically feasible. Refusing optional processing does not disable unrelated core features.
Third-party SDKs used for optional analytics, advertising attribution or other non-essential processing are initialized and carry out that processing only after we clearly explain the purposes, data categories and recipients and obtain the appropriate valid consent. This applies across app marketplaces and distribution channels. Accepting this Policy does not authorize all optional processing. Components used for login, payment, security or notifications that you request are activated as needed only after a valid legal basis and required notices and permissions are in place; analytics and marketing are not bundled into necessary processing. You may withdraw consent, without affecting the lawfulness of prior processing.
We do not collect information at excessive frequency. A capability involving a one-time read, such as a crash-log report, is triggered only when necessary.
Purposes and legal bases. We process data to create and manage accounts, provide requested interpretations and interactions, generate and store results, handle payment and benefits, prevent fraud, maintain security, answer requests and comply with law. Where the applicable law recognizes them, legal bases may include contractual necessity, legal obligations, consent or legitimate interests in security and service operation, after any required assessment. We identify the applicable basis for the processing concerned. Optional analytics, attribution, precise location, personalized recommendations and similar processing are separated from core processing as required by law.
II. Information We Collect, Purposes and Context
A. Account and Basic Profile Information
You may provide a nickname, profile picture, gender, region and language setting, and a login identifier such as a phone number, email address or supported third-party account identifier. We use necessary information for registration, login, account recovery and basic services. If you decline information necessary for registration or a particular feature, that registration or feature may not be available. Optional profile information is not required for unrelated core services.
B. Device and Network Information
For service operation and protection, we process device model, operating-system version, resolution, manufacturer, system language, network type, carrier, app version, crash and performance logs, request timestamps and anonymized device-environment metrics.
Purposes include security, stability, troubleshooting, removal of duplicate statistical records, anti-abuse and attack prevention. These data are used for security and quality purposes, not precise individual profiling or commercial trading.
C. Usage Logs
For product improvement, we may process app open and close times, page clicks, dwell times, error codes and crash stacks. These help optimize experience, plan capacity and diagnose problems. Events are recorded when interactions occur and are not linked across apps. Optional analytics remains subject to the separate consent rules above.
D. AI Interactions, Generated Results and Uploaded Content
When you choose an interpretation, conversation, generation or upload feature, the data may include date and time of birth, birthplace, location used for true-solar-time or similar calculations, questions, prompts, conversation history, generated results, feedback and photographs, audio, video or other files you upload. We also process membership and Coin records to provide the services and benefits you purchase. We do not require optional data that is unnecessary for your requested feature.
Inputs and related content are generally uploaded to our servers or contracted cloud, hosting or AI providers to perform computation, generate results, store and synchronize content, protect security and troubleshoot issues. We use encrypted transmission, storage encryption where necessary, access controls and, where compatible with the purpose, de-identification, masking or anonymization.
We may use inputs, related interactions and feedback to evaluate and improve response quality, service performance and model capabilities. Before this use, we remove, replace, mask or separate directly identifying details and apply access controls and other safeguards. We limit processing to what is necessary for those purposes and provide separate notice, consent or opt-out mechanisms where required. De-identification reduces identification risk but does not necessarily make data anonymous or impossible to re-identify. Service providers are contractually restricted to disclosed purposes and security obligations.
Sensitive information. Questions or conversations may reveal emotional, mental-health, physical-health, religious or other sensitive information. We process it only as necessary for a requested feature and on a valid legal basis, including explicit consent where required. The app does not provide emergency medical or mental-health care.
Important: Information Not Collected by Default
Unless you expressly consent in the relevant feature, we do not collect the following by default:
- IMEI, IMSI, MEID or a device MAC address;
- Installed-application lists or installed-package-name lists;
- Precise GPS location;
- Contacts, text messages, call history, calendar, photo-album or audio/video content, or the device's telephone number;
- 5G core-network identifiers such as SUPI or SUCI.
If any such data becomes necessary, collection is enabled only in the corresponding feature after the required consent. We provide a way to disable it and an equivalent alternative as described for that feature.
III. Third-Party SDKs
The following disclosures apply only when the SDK is actually integrated into the version and feature you use. A version-specific list identifies the provider, purpose, data categories, activation conditions and privacy policy. A component absent from your version is not initialized and does not collect information. A technical identifier or system name does not limit this Policy to that operating system. New SDKs or purposes are disclosed in advance and any required consent is obtained.
Overseas versions do not integrate the Number Authentication SDK or China Unicom Authentication SDK. Those two components are not part of the overseas SDK list.
1. TalkingData Mobile Analytics SDK — Where Integrated
Provider: Beijing Tendcloud Tianxia Technology Co., Ltd.
Purpose: app usage statistics, crash analysis, anti-fraud and attribution analysis.
Data categories: the version-specific disclosure describes the enabled fields. The component's disclosed capabilities include device model, operating-system and app versions, device identifiers such as IMEI, IMSI, MEID, MAC address and Android ID, network type, carrier information, installed-application information, location, crash logs and performance data. These capabilities are not a statement that every field is collected, nor authorization to enable all fields. Optional or restricted fields remain subject to the default non-collection rule, actual technical configuration, necessity, separate notices and required consent. A domestic one-tap login capability is not provided by this overseas disclosure.
Activation: optional analytics and attribution begin only after the valid consent described in Section I. Location requires the relevant consent and permission.
Provider privacy policy: TalkingData Privacy Policy.
2. JPush SDK — Where Integrated
Provider: Shenzhen Hexun Huagu Information Technology Co., Ltd.
Purpose: delivering push notifications accurately and reliably, preventing abuse of the notification service, and analyzing notification performance where separately permitted.
Data categories: the version-specific disclosure describes enabled fields. Disclosed component capabilities include device model, operating-system and app versions, identifiers such as Android ID and OAID, network type, IP address, Wi-Fi SSID and BSSID, MAC address, approximate or precise location, installed-application information, delivery status, crash logs and exception logs. Only fields actually enabled, necessary and lawfully authorized may be processed. Listing a capability does not authorize collection of every field. Location requires the relevant consent and permission; optional analytics is not bundled with necessary delivery.
Background wake-up and auto-start: after required disclosure, your express consent and notification permission, the SDK may wake or start the app process in the background within system limits to receive and display notifications. This occurs only for notification purposes. If you disable system notification permission or in-app push settings, we stop triggering this behavior through that mechanism to the extent supported by the system.
Provider privacy policy: JPush Privacy Policy.
IV. Permissions
- Files, photos or media access: only when you choose to save or upload content, we request the necessary access through the permission or file-selection mechanism provided by your device system. Caching the app's own logs does not itself require broad access to device storage. Declining optional access does not affect unrelated core features.
- Notifications: message alerts; you can disable them in system settings.
- Camera, microphone and photo library: optional capture or upload features; permission is requested only when you use the feature.
- Location: optional location-based recommendations or activity displays; permission is requested only when you use the feature.
We do not invoke permissions without your awareness or outside a reasonable business context. Any necessary background wake-up for notifications is subject to your express consent and the explanation above.
V. Sharing, Transfers and Public Disclosure
Sharing with providers. We share the minimum necessary data with providers such as cloud-computing, hosting, AI and messaging providers only for the disclosed feature and on a lawful basis. Contracts limit processing to authorized purposes, require safeguards and prohibit unauthorized secondary use.
Corporate changes. In a merger, division, reorganization or similar transaction, we require the recipient to remain bound by this Policy and provide any legally required notice or renewed consent.
Public disclosure. We do not generally make personal information public. Any legally required disclosure is limited to what the law requires, with minimization and anonymization where compatible with that obligation.
VI. Storage Locations and Retention
Storage location. We store personal information for your service in the country or region assigned to the app marketplace through which you downloaded the app. “Region” means the marketplace region at download, not your device language, nationality or real-time travel location.
If a cross-region download, marketplace-region change or account migration involves a storage-location change, we explain the actual effect before migration and handle it under applicable law. Changing interface language alone is not consent to move your data. This statement does not promise that a self-service region-change or migration feature is available.
Cross-border access or processing. Where an SDK, cloud service, AI provider or other recipient would receive, access or process personal information outside that storage country or region, we separately disclose the destination, recipient or legally permitted recipient category, purpose, data categories, transfer method, retention and safeguards, and any consequences of refusal. We complete the applicable legal transfer procedures and obtain any required consent before the processing. Legally recognized transfer mechanisms and supplementary safeguards are used where required. Consent does not replace another required transfer mechanism, and a local-storage statement does not itself authorize overseas access.
Retention. We keep information only for the shortest period necessary for each processing purpose, then delete or anonymize it. Account deletion removes associated profile data, usage records, AI-generated content and other user content, and ends account benefits such as VIP membership, purchased Coins and unused interpretation credits. These cannot be restored; mandatory consumer remedies remain unaffected.
Only to prevent repeated claims for a one-time new-user reward using the same phone number or email, we may retain a minimal eligibility identifier while reasonably necessary for that purpose. We review its necessity periodically and delete or anonymize it when no longer needed. We do not use it for marketing, restoring an account or unrelated purposes. Other legally required records are kept only for the legally required period.
VII. Your Rights and How to Exercise Them
Subject to the law applicable to your request, you may request access to your information, correction of inaccurate or incomplete information, deletion, restriction of processing, data portability, objection to certain processing, withdrawal of consent and review of solely automated decisions where the law provides that right. Withdrawal does not affect earlier lawful processing and may prevent a feature that depends on the withdrawn consent.
Submit a request through in-app Feedback or support@noonwake.com. We verify identity proportionately and respond within the applicable legal deadline. You may complain to the competent privacy regulator, including Singapore's Personal Data Protection Commission, Malaysia's Personal Data Protection Commissioner, the UK's Information Commissioner's Office, an EEA supervisory authority or a competent US authority, as applicable.
Local rights, exceptions and deadlines apply even where English is the chosen interface language. We do not require you to waive a mandatory privacy or consumer right as a condition of using the service.
VIII. Children and Young People
Children's privacy consent, contractual capacity and purchasing authorization are separate matters. App-marketplace ratings do not replace them. The Rules for the Protection of Minors' Personal Information provide further safeguards and prevail where they give more specific protection.
- Singapore: parental or guardian consent is required below 13. For ages 13–17, we assess whether the young person can understand the processing and consequences; guardian consent is sought where they cannot. Other protections for minors remain applicable.
- Malaysia: for consent-based processing of data relating to a person below 18, consent is obtained from a parent, guardian or person with parental responsibility.
- United States: where COPPA applies, we obtain verifiable parental consent before collecting, using or disclosing personal information online from a child below 13, except for a specific lawful exception. State protections for older minors also remain applicable.
- United Kingdom: when relying on consent for an online service offered directly to a child below 13, we obtain authorization from a person with parental responsibility. Protections for children below 18 and applicable age-appropriate-design duties remain relevant.
- EEA: for consent-based online services offered directly to children, the national threshold under GDPR Article 8 is between 13 and 16. Below the applicable national threshold, consent must be given or authorized by the holder of parental responsibility and reasonably verified. These rules do not determine contractual capacity.
We do not activate processing that requires guardian consent or verification before completing those requirements. If we discover processing without the required consent, we stop it and delete the information or take another lawful remedial measure. A child clicking “Agree” is not proof of guardian consent. We do not use children's information for targeted advertising or unrelated profiling.
IX. AI Content and Service Limitations
Some content is generated by AI to provide companionship, interaction and inspiration. It is not medical, psychological-treatment, legal, investment or other professional advice. Seek qualified help for serious emotional, mental or physical health concerns; contact local emergency services for immediate danger. These limitations do not remove any mandatory privacy or consumer protection.
X. Security and Incident Response
We use access controls, encrypted transmission through HTTPS/TLS, least-privilege permissions, audit records and other measures to prevent unauthorized access or disclosure. If an incident occurs, we take remedial action and provide notifications and regulatory reports within the periods required by applicable law.
XI. Contact
Company: Noonwake Technology Limited (深圳市晌午不眠科技有限公司), Shenzhen, Guangdong, China.
Email: support@noonwake.com. You may also submit a request through Settings — Feedback in the app.
XII. Updates and Notices
We may update this Policy when business practices or law change. Material changes, including new purposes, data categories or third-party integrations, are prominently explained with an effective date. We obtain renewed express consent where required before applying the change. Previous versions and update records are available through Settings — Privacy Policy.
XIII. Disputes and Remedies
You may bring a dispute relating to this Policy or the service before a court with lawful jurisdiction where you are located, including your habitual residence, or before a court with lawful jurisdiction where we are located in Shenzhen, Guangdong, China. Negotiation is voluntary and is not a prerequisite to suing. If we bring proceedings, we comply with applicable mandatory jurisdiction and consumer-protection rules. No other non-excludable jurisdiction or right to complain to a regulator is restricted. Any choice of Mainland Chinese law under the Terms of Service does not deprive you of mandatory local privacy, consumer or other non-waivable protections.