HomeServicesAdvantages UpdatesContact

Privacy Policy

A complete description of how dlwenyuan.com collects, uses, discloses and protects information across our website and our portfolio of mobile applications published on the Apple App Store, Google Play and other distribution platforms.

Effective1 January 2026
Last updated10 August 2026
Version3.2
Jurisdictions coveredUK · EU · United States · Canada · Mainland China · Australia · Brazil · Japan · South Korea · Singapore
Data controllerdlwenyuan.com
Contactcontact@dlwenyuan.com

1. Introduction

dlwenyuan.com ("we", "us", "our", the "Studio") operates the website dlwenyuan.com and publishes a portfolio of mobile applications (the "Apps") on third-party distribution platforms including, without limitation, the Apple App Store, Google Play, the Amazon Appstore, the Huawei AppGallery, the Samsung Galaxy Store and alternative app marketplaces. This Privacy Policy explains how we collect, use, disclose, retain and protect information when you interact with our website, our Apps, or otherwise communicate with us.

We are committed to the principles of minimalism, privacy by architecture and transparency. Where we have a choice we design our systems so the smallest possible amount of personal data is processed — preferably none at all. When we rely on third-party software development kits ("SDKs") to operate ad-supported Apps we disclose those providers here in full so you can make an informed choice.

By accessing our website or using our Apps you confirm that you have read and understood this Privacy Policy. If you do not agree with any part of this Policy, please discontinue use of the relevant service and contact us at contact@dlwenyuan.com so that we can address your concerns.

2. Definitions

  • Personal Data means any information relating to an identified or identifiable natural person, as defined under Article 4(1) of the UK General Data Protection Regulation and the EU GDPR.
  • Processing means any operation performed on Personal Data, including collection, storage, use, disclosure or erasure.
  • Controller means the entity that determines the purposes and means of Processing. For the Studio's website and Apps, the Controller is dlwenyuan.com.
  • Processor means an entity that processes Personal Data on behalf of the Controller (for example an advertising SDK provider or a cloud-hosting partner).
  • SDK means a software development kit embedded into our Apps to enable a specific function such as advertising or analytics.
  • End-User means any natural person who downloads, installs or otherwise interacts with our Apps.
  • Child means any End-User under the age of 13, or such higher age as may be required by the law of the End-User's place of residence (for example 14 in Mainland China, 16 in South Korea for consent to information society services).

3. Scope of this Policy

This Policy applies to:

  • The website dlwenyuan.com and all sub-pages;
  • Every mobile application published by the Studio on the Apple App Store, Google Play and any other distribution platform, in every region in which the App is available;
  • Email, support-ticketing and other written communications sent to the addresses listed on our website;
  • Any other service we operate that explicitly links to this Policy.

This Policy does not apply to:

  • Third-party websites or services linked from our website or Apps, which are governed by their own privacy policies;
  • Distribution platforms (such as Apple or Google) acting as independent controllers of the data they receive from you when you create an account with them.

4. Information We Collect

We follow the principle of data minimisation. The information we collect falls into three categories.

4.1 Information you provide directly

  • Contact form data — name, email address, company name and the free-text message you submit via the form on our Contact page, together with the enquiry type.
  • Support correspondence — any information you include when emailing support@dlwenyuan.com, such as device model, operating-system version, screenshots and reproduction steps for a bug.
  • Marketing opt-ins — if you actively subscribe to a newsletter or press list we will store your email address and the date of consent.

4.2 Information collected automatically

  • Website logs — IP address, user-agent string, referrer, requested URL, response status and timestamp. Logs are retained for a maximum of 30 days for security and capacity planning and then aggregated or deleted.
  • Aggregated, on-device counters — for example the number of times a feature is used within an App. These counters never leave your device and contain no identifiers.
  • Crash reports — anonymised stack traces and device metadata captured by our internal crash-reporting module. Crash reports do not include personal content you have created inside an App.

4.3 Information collected by advertising SDKs

Where an App displays advertising it may load SDKs from the providers listed in Section 8. Those SDKs may collect device identifiers (such as the Google Advertising ID or the Apple Identifier for Advertisers — IDFA), coarse location derived from IP address, app-usage signals and ad-interaction events. You can reset or limit these identifiers at any time using your operating-system privacy settings.

Local-first principle. Any creative content you produce inside an App — recordings, photos, notes, inventories — is stored only on your device unless you explicitly export or sync it. We do not maintain a server-side copy of your creative content.

5. How We Use Information

We use the information we collect for the following purposes:

  1. Service operation — to deliver the core functionality of our website and Apps, authenticate requests where strictly necessary, and prevent abuse.
  2. Support — to respond to your enquiries, troubleshoot issues and improve documentation.
  3. Security — to detect and prevent fraudulent, abusive or malicious activity, and to enforce our terms.
  4. Aggregated insights — to understand feature adoption at a coarse, anonymous aggregate (for example "20% of users opened the multitrack view this week") so that we can prioritise engineering work.
  5. Advertising — in ad-supported Apps, to request and display ads that are relevant to your general interests, measure their performance and prevent fraud, all subject to the controls described in Section 8 and the choices offered by your operating system.
  6. Legal compliance — to comply with applicable laws, regulations and valid legal processes.

We never sell Personal Data. We never rent Personal Data. We never share Personal Data with advertising networks beyond what is described in Section 8.

7. App Stores & Distribution Platforms

Our Apps are distributed through one or more of the following platforms. Each platform acts as an independent controller of the data it processes to operate the store, manage your account and verify downloads. Please consult their respective privacy policies for details.

  • Apple App Store — operated by Apple Inc. Privacy practices are described in the Apple Privacy Policy and the App Store Review Guidelines. Apple requires that all apps using certain tracking APIs request permission via the App Tracking Transparency framework. Where we display advertising in our iOS Apps we honour ATT consent and we never engage in fingerprinting or device-graph look-alike modelling.
  • Google Play — operated by Google LLC. Privacy practices are described in the Google Privacy Policy. Apps published on Google Play must comply with the Google Play Developer Policy and the Google Play Families Policy if they target children. We comply with both.
  • Amazon Appstore — operated by Amazon.com, Inc. Privacy practices are described in the Amazon Privacy Notice. Apps distributed via Amazon must comply with the Amazon Appstore Developer Content Policies.
  • Huawei AppGallery — operated by Huawei Technologies Co., Ltd. Privacy practices are described in the Huawei Privacy Statement. Apps distributed via AppGallery must comply with the Huawei AppGallery Review Guidelines.
  • Samsung Galaxy Store — operated by Samsung Electronics Co., Ltd. Privacy practices are described in the Samsung Privacy Policy.
  • Alternative / regional stores — including but not limited to the Xiaomi GetApps store, OPPO Software Store, VIVO V-Appstore and the Tencent AppBao. Each is governed by its own operator's policies and applicable local law.

For each platform we:

  • Provide accurate app-store metadata describing our privacy practices and data collection;
  • Submit accurate privacy-questionnaire responses (such as Apple's App Privacy Details section and Google's Data safety form);
  • Honour any user choice expressed at the platform level, including parental controls and child-directed settings;
  • Cooperate with platform takedown and remediation requests when a privacy incident is identified.

8. Advertising Networks & SDKs (Including AdMob)

To keep our free Apps free, certain Apps published by the Studio display advertising served by third-party advertising networks. Each network provides a SDK that runs inside the App and is responsible for selecting and rendering ads, measuring performance, and (where you have granted consent) personalising the ads you see.

The advertising SDKs our Apps integrate with may include, without limitation, the following providers. We update this list whenever we add or remove a provider. The "data categories" column summarises the data shared by the SDK with its backend, as disclosed in the provider's own privacy documentation.

8.1 Google AdMob (Google AdSense for Apps)

AdMob is provided by Google Ireland Limited (for users in the EEA / UK) and Google LLC (for users elsewhere). When an App displays ads via AdMob the SDK may collect:

  • Device identifiers: Google Advertising ID (GAID) on Android, Identifier for Advertisers (IDFA) on iOS (only after App Tracking Transparency consent);
  • Coarse location derived from IP address (country or city level);
  • App-usage signals such as session length, ad impressions and clicks;
  • Device metadata (model, OS version, screen size, locale);
  • Crash and performance data for SDK stability.

AdMob uses this data to select and serve ads, measure ad performance, prevent fraud and (with consent) personalise advertising. AdMob partners with a range of third-party demand sources; you can review the certified external partners list at any time via the AdMob SDK documentation.

You can opt out of personalised advertising from AdMob at any time by resetting your GAID / IDFA in your device settings, or by enabling the operating-system "Limit Ad Tracking" / "Opt out of Ads Personalisation" controls.

For users in the EEA, UK and Switzerland, Google relies on Consent Mode — a mechanism that transmits your consent choices to all participating Google ad-tech products. Our Apps integrate with Google UMP (User Messaging Platform) to surface a compliant consent dialog before any non-essential personalisation takes place.

More information: Google Privacy Policy, How Google uses information from sites or apps that use Google services, and the AdMob SDK help-centre documentation.

8.2 Other advertising networks we integrate

To maximise fill-rate, prevent single-vendor dependency and keep ads relevant, our Apps may also integrate SDKs from the providers listed below. Each provider acts as an independent controller for the data it processes; please consult their respective privacy notices.

Meta Audience Network (Meta Platforms Ireland Ltd / Meta Platforms, Inc.)

Audience Network serves ads inside our Apps using Meta's bidding system. When integrated we honour the App Tracking Transparency framework on iOS and equivalent controls on Android. Privacy practices are described in the Meta Privacy Policy and the Audience Network SDK documentation.

Unity Ads (Unity Technologies ApS / Unity Software Inc.)

Unity Ads serves video and interactive ads inside games and Apps. The provider processes device identifiers, coarse location, and engagement events to select ads and measure performance. See the Unity Privacy Policy for details.

AppLovin (AppLovin Corporation)

AppLovin's MAX mediation and direct-deal SDKs may be integrated. AppLovin processes device identifiers, ad-interaction events and contextual signals to deliver ads. See the AppLovin Privacy Policy.

Pangle / ByteDance (Pangle Pte. Ltd.)

Pangle is the TikTok / ByteDance ad network. It may process device identifiers, coarse location and ad-interaction signals. Privacy practices are described in the TikTok / ByteDance Privacy Policy and the Pangle documentation.

Vungle (Liftoff Mobile, Inc.)

Vungle provides rewarded video and playable ads. It processes device identifiers, coarse location and engagement signals. See the Vungle Privacy Policy.

ironSource (Unity Software Inc., following the 2022 merger)

ironSource mediation and direct-deal SDKs may be integrated. The provider processes device identifiers, ad-interaction events and engagement signals. See the ironSource Privacy Policy.

Chartboost (Chartboost, Inc., a Digital Turbine company)

Chartboost provides direct ads and in-app bidding. It processes device identifiers, coarse location and ad-interaction signals. See the Chartboost Privacy Policy.

InMobi (InMobi Technology Services Pvt. Ltd.)

InMobi serves ads and provides mediation. It processes device identifiers, coarse location and engagement signals. See the InMobi Privacy Policy.

Tapjoy (Tapjoy, Inc.)

Tapjoy provides offerwall and rewarded video ads. It processes device identifiers, advertising opt-out signals and engagement data. See the Tapjoy Privacy Policy.

Digital Turbine (Digital Turbine, Inc.)

Digital Turbine provides mediation, exchange and direct-deal ads. It processes device identifiers, coarse location and ad-interaction signals. See the Digital Turbine Privacy Policy.

Mintegral (Mintegral International S.à r.l. / Hagoogi Limited)

Mintegral serves ads and provides programmatic bidding. It processes device identifiers, coarse location and ad-interaction events. See the Mintegral Privacy Policy.

Smaato (Smaato, Inc.)

Smaato operates an ad-exchange platform. It processes device identifiers, coarse location and ad-interaction signals. See the Smaato Privacy Policy.

AdColony (Digital Turbine, Inc., following the 2021 acquisition)

AdColony serves video and interactive ads. It processes device identifiers, coarse location and engagement signals. See the AdColony Privacy Policy.

Liftoff (Liftoff Mobile, Inc.)

Liftoff provides programmatic advertising and retargeting. It processes device identifiers, coarse location and ad-interaction events. See the Liftoff Privacy Policy.

Yahoo (Yahoo! Inc., part of the Apollo Global Management group)

Yahoo provides programmatic advertising. It processes device identifiers, coarse location and ad-interaction signals. See the Yahoo Privacy Policy.

Criteo (Criteo S.A.)

Criteo provides retargeting and personalised advertising. It processes device identifiers, browsing signals and ad-interaction data. See the Criteo Privacy Policy.

Moloco (Moloco, Inc.)

Moloco provides programmatic advertising and machine-learning-driven bidding. It processes device identifiers, coarse location and ad-interaction events. See the Moloco Privacy Policy.

Other providers that may be present

From time to time we may integrate smaller or regional providers such as:

  • Yandex Ads (for users in Russia and CIS countries);
  • Naver Ads and Kakao AdBiz (for users in South Korea);
  • Tencent Ads (for users in Mainland China);
  • LINE Ads (for users in Japan and Taiwan);
  • Baidu Union (for users in Mainland China);
  • Glispa, Airpush and similar mediation providers.

Whenever a new SDK is integrated into an App we update this section, bump the Policy version number, and re-submit the App to the relevant store for review. Where the SDK materially changes the data flows we will request fresh consent through the in-app consent dialog before any personalised ads are served.

8.3 Mediation and bidding

To maximise ad fill and CPM, our Apps may use ad-mediation layers (such as Google AdMob Mediation, AppLovin MAX or Unity LevelPlay) which call multiple ad networks in real-time and select the highest bidder for each impression. In a real-time bidding ("header bidding" / "in-app bidding") auction, the device may broadcast an ad request to multiple buyers simultaneously. Buyers receive only a contextual signal (device class, country, language, ad-unit ID) unless consent for personalised advertising has been granted.

8.4 Ad-fraud prevention

All integrated advertising SDKs perform some level of fraud detection, including validating that impressions come from genuine End-Users rather than automated bot traffic. Where SDKs flag suspicious activity they may share signals with their trust-and-safety teams; no additional personal data is created as part of this process.

9. Ad Formats We Use

Across our ad-supported Apps we may display one or more of the following standard ad formats. Each format is supplied by the SDKs listed in Section 8 and is governed by the same consent rules.

9.1 Banner ads

Banner ads are rectangular image or text ads displayed at the top or bottom of a screen, or inline within a list view. They refresh on a timer or after user navigation. Banners do not cover the full screen and can be dismissed by the user by simply scrolling past them. Where a banner is personalised, the personalisation is governed by the consent you provided for the relevant advertising SDK.

9.2 Interstitial (full-screen) ads

Interstitial ads appear as a full-screen overlay between natural transitions in an App — for example between levels of a game or after completing a recording session. They always include a clear "close" or "continue" affordance and we configure frequency caps to prevent consecutive interstitials from being shown. Interstitials that include interactive components (such as playable ads or playable end-cards) include a clear countdown before the close button is enabled.

9.3 Rewarded video ads

Rewarded video ads are full-screen video ads that the user actively chooses to watch in exchange for an in-app reward (for example, an additional export slot, a feature unlock, or a virtual bonus). The reward is always disclosed before the user opts in, the user can skip the video after the introductory seconds and the reward is granted only after the video completes (or after the user opts to skip past the post-roll).

9.4 Native ads

Native ads are designed to match the visual style of the surrounding content. We mark every native ad with the label "Sponsored" or "Ad" so that users can distinguish it from editorial content. Native ads are never placed in a way that could be confused with user-generated content.

9.5 App-open (splash) ads

Some of our Apps may display an app-open ad on launch — a brief, full-screen ad that appears immediately after the splash screen and before the main interface loads. We honour any operating-system "limit ad tracking" / App Tracking Transparency choice for this format, and we provide a clear "skip" affordance after the standard skip interval.

9.6 Ad choices and controls

You can always opt out of personalised advertising by:

  • Selecting Settings → Privacy → Advertising → Limit Ad Tracking on iOS;
  • Selecting Settings → Google → Ads → Opt out of Ads Personalisation on Android;
  • Resetting your GAID or IDFA via your device settings;
  • Using the in-app "Ad preferences" dialog surfaced through Google UMP (where applicable).

Industry opt-out tools such as YourAdChoices (DAA), Your Online Choices (EDAA) and NAI Consumer Opt-Out can also limit interest-based advertising from participating companies on the web. These tools do not cover in-app advertising but are useful for the website experience.

10. Age Restrictions & Children

The Studio respects the privacy of children and complies with all applicable laws designed to protect them, including without limitation:

  • The US Children's Online Privacy Protection Act (COPPA) and the FTC's COPPA Rule;
  • The EU General Data Protection Regulation (GDPR) and the EDPB guidance on minors;
  • The UK Age-Appropriate Design Code (AADC) issued by the Information Commissioner's Office;
  • The California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA) protections for consumers under 16;
  • The Mainland China Personal Information Protection Law (PIPL) and the Provisions on the Protection of Children's Personal Information;
  • The Brazilian Lei Geral de Proteção de Dados (LGPD);
  • The South Korea Personal Information Protection Act (PIPA) and the Act on the Protection of Information and Communications Infrastructure;
  • The Apple App Store Review Guidelines 1.4.1 / 5.1.1 and Google Play Families Policy.

10.1 Minimum age

Our Apps are intended for a general audience and are not directed at children under 13 (or such higher age as the law of the user's place of residence requires, including 14 in Mainland China, 14 in the EU/UK under the AADC, 16 in South Korea and 16 in the Netherlands for consent to information society services). We do not knowingly collect Personal Data from children below the relevant age threshold.

10.2 Parental notice and verifiable consent

If we discover that we have inadvertently collected Personal Data from a child below the relevant age threshold without verifiable parental consent, we will delete that information as soon as practicable. Parents or guardians who believe this has happened may contact us at contact@dlwenyuan.com to request deletion.

10.3 Age gates and store-level controls

Our Apps distributed through the Apple App Store or Google Play are subject to the platform-level age-gate controls. The end-user's age is determined by the store account, not by our Apps. If you have set an age category in your store account that prevents the download or in-app purchase of our Apps, those controls will be honoured.

10.4 Prohibited data practices for children

Our Apps will never, in respect of any user:

  • Sell or rent Personal Data;
  • Use behavioural advertising techniques that target a user below the applicable age threshold, including profile-based advertising;
  • Build a persistent identifier that allows tracking across Apps or websites without explicit consent;
  • Display ads in a way that encourages in-app purchases or financial transactions to children;
  • Collect any precise location data (GPS) unless strictly necessary for the core functionality of the App and with explicit consent.

Where a child-directed user opens an App that would otherwise display personalised advertising, we configure our mediation stack to serve contextual ads only (no personalisation, no behavioural targeting) regardless of the user's consent signal. The integration of Google UMP and equivalent consent layers helps achieve this configuration transparently.

10.5 Online Safety & Duty of Care

Where we operate in jurisdictions with online-safety duties (such as the UK Online Safety Act 2023, the EU Digital Services Act, Australia's Online Safety Act and the Republic of Korea's Online Safety Act), we comply with the relevant codes of practice for content reporting, transparency and user-protection.

11. Regional Rights & Compliance

Depending on where you live, you may have specific rights in respect of your Personal Data. We honour all of them. You do not need to create an account to exercise these rights.

11.1 United Kingdom & European Economic Area (UK GDPR / EU GDPR)

If you are located in the UK or the EEA you have the right to:

  • Access the Personal Data we hold about you (Article 15);
  • Rectify inaccurate or incomplete Personal Data (Article 16);
  • Request erasure of your Personal Data ("right to be forgotten", Article 17);
  • Restrict or object to processing (Articles 18 and 21);
  • Receive your Personal Data in a structured, commonly used and machine-readable format (Article 20, right to data portability);
  • Withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
  • Lodge a complaint with a supervisory authority — for example the ICO in the UK, the CNIL in France, the BfDI in Germany, the AEPD in Spain, or your local authority.

Where we rely on legitimate interests for any processing, we have conducted and documented a balancing test that you can request.

11.2 United States — California (CCPA / CPRA)

If you are a California resident you have the right to:

  • Know what categories of Personal Data we collect, the sources, the purposes and the categories of recipients;
  • Request access to and a portable copy of your Personal Data;
  • Request deletion of your Personal Data, subject to certain exceptions;
  • Correct inaccurate Personal Data;
  • Limit the use and disclosure of sensitive Personal Data;
  • Opt out of any "sale" or "sharing" of Personal Data — note that we do not sell or share Personal Data as those terms are defined under the CCPA / CPRA.

California residents under 16 must affirmatively opt in to any sale or sharing; we never sell or share, and therefore no opt-in is requested.

11.3 United States — other states

We comply with the privacy laws of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MTCDPA), Iowa (ICDPA), Tennessee (TIPA), Indiana (INCDPA), New Hampshire (NHPA), New Jersey (NJPA), Delaware (DPDPA), Maryland (MOCPA), Kentucky (KCPAA), Minnesota (MNDPA), Rhode Island (RIDPA), Washington (My Health My Data Act, where applicable) and any other U.S. state privacy statute that becomes effective.

11.4 Canada (PIPEDA & Quebec Law 25)

If you are located in Canada you have the right to access your Personal Data, challenge its accuracy, withdraw consent and lodge a complaint with the Office of the Privacy Commissioner of Canada. In Quebec we comply with Law 25 including the requirements on consent, transparency, privacy-by-design and breach notification.

11.5 Mainland China (PIPL & DSL)

If you are located in Mainland China we comply with the Personal Information Protection Law (PIPL), the Data Security Law (DSL), the Cybersecurity Law (CSL) and the Provisions on the Protection of Children's Personal Information. We will only transfer your Personal Data outside of Mainland China after completing a security assessment or signing the standard contract with the receiving party as required by the CAC, and only with your separate consent.

11.6 Australia (Privacy Act 1988 & APPs)

We comply with the Australian Privacy Principles (APPs). You may request access, correction or removal of your Personal Data, and may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

11.7 Brazil (LGPD)

Brazilian users have the rights of confirmation, access, correction, anonymisation, portability, deletion and information about sharing under the Lei Geral de Proteção de Dados. The Brazilian National Data Protection Authority (ANPD) is the supervisory body.

11.8 South Korea (PIPA)

Korean users have rights of access, correction, suspension of processing and damages under the Personal Information Protection Act. Cross-border transfers require separate consent; we will provide the relevant notices before any transfer takes place.

11.9 Japan (APPI)

We comply with the Act on the Protection of Personal Information (APPI). Japanese users may request disclosure, correction and cessation of use of personal data, and may file complaints with the Personal Information Protection Commission.

11.10 Singapore (PDPA)

Singaporean users have rights of access, correction and withdrawal of consent under the Personal Data Protection Act. The Personal Data Protection Commission (PDPC) is the supervisory body.

11.11 How to exercise your rights

To exercise any of the rights above, please email contact@dlwenyuan.com from the email address you wish to verify. We may need to verify your identity before fulfilling your request — this is to prevent fraudulent requests. We will respond within the statutory window for your jurisdiction (typically 30 days, or 45 days under the CCPA / CPRA). There is no fee for exercising your rights.

12. Cookies & Tracking Technologies on Our Website

The dlwenyuan.com website uses a minimal number of cookies and similar technologies. We do not run third-party advertising trackers on our website. The categories we may use are:

  • Strictly necessary cookies — small amounts of session data needed to remember your navigation choices (for example the form field entries). These cookies do not require consent under the ePrivacy Directive because they are strictly necessary for the service you have requested.
  • Functional cookies — for example a preference to remember the language you selected. These cookies are only set if you accept them.
  • Analytical cookies — first-party, privacy-respecting analytics that aggregate page views without identifying you personally. Where required by law (for example in the EEA / UK), we will request your consent before setting these cookies.

You can manage your cookie preferences at any time by clicking the "Cookie settings" link in our footer (when present) or by configuring your browser to block or delete cookies. You can also use the YourAdChoices opt-out tool to limit interest-based advertising from participating companies.

Our apps do not set cookies in the browser sense, but they may use the SDKs described in Section 8 which use device-resident storage to support advertising and analytics functionality.

13. Sharing & Disclosure

We do not sell or rent Personal Data. We share information only as follows:

  • With service providers — vendors that perform services on our behalf, including hosting, email delivery, cloud storage, crash reporting, customer-support tooling and ad mediation. Each provider is bound by a data-processing agreement that limits the use of your data to the specified purpose.
  • With advertising SDKs — as described in Section 8, only where you have granted consent (or where contextual ads are served without personalisation).
  • For legal reasons — when we believe in good faith that disclosure is necessary to (a) comply with a valid subpoena, court order or other legal process; (b) enforce our terms; (c) protect our property, safety or that of our users; or (d) detect, prevent or address fraud, security or technical issues.
  • Business transfers — in the event of a merger, acquisition, financing, reorganisation, bankruptcy or sale of assets, your information may be transferred as part of that transaction. We will notify you by email and/or a prominent notice on our website of any change in ownership or uses of your Personal Data.
  • Aggregated or de-identified information — we may share aggregated, anonymised or de-identified information with partners for industry research, marketing analytics or public reporting. Such information cannot reasonably be used to identify you.

14. Data Retention

We retain Personal Data for the minimum period necessary for the purposes described in this Policy, after which it is deleted or anonymised. Specifically:

  • Contact-form submissions — retained for up to 24 months for support and quality purposes, then deleted.
  • Support correspondence — retained for up to 36 months to enable follow-up, then archived in aggregate form or deleted.
  • Website logs — retained for a maximum of 30 days for security and capacity planning, then aggregated or deleted.
  • Aggregated, on-device counters — never leave your device.
  • Crash reports — retained for up to 90 days, then deleted.
  • Data shared with advertising SDKs — retained by the SDK provider under their own retention schedule as described in their privacy policies.

Where statutory or regulatory obligations require longer retention (for example for accounting or tax records), we will retain the relevant data for the period required.

15. Security Measures

We take the security of your Personal Data seriously and apply industry-standard administrative, technical and physical safeguards designed to protect it against unauthorised access, alteration, disclosure or destruction. These include:

  • TLS 1.3 encryption in transit for the website and APIs;
  • Hardware-backed encryption (iOS / Android secure enclaves) for any data stored locally inside an App;
  • Strict access control with least-privilege permissions for our team;
  • Continuous code review and dependency scanning;
  • Periodic third-party security and privacy audits;
  • Incident response procedures with notification timelines consistent with the GDPR (72 hours), CCPA, PIPL and other applicable laws.

No method of transmission over the Internet, however, is 100% secure. We cannot guarantee absolute security. If you ever believe your interaction with us is no longer secure (for example you suspect your account credentials are compromised), please notify us immediately at contact@dlwenyuan.com.

16. International Data Transfers

The Studio is established in the United Kingdom. Some of our service providers and advertising partners are located in the United States, the European Union and other jurisdictions. When we transfer Personal Data outside the country of collection we rely on appropriate safeguards, including:

  • For transfers from the EEA / UK to a third country: the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum;
  • For transfers from Mainland China: the CAC standard contract or security assessment as required by the PIPL;
  • For transfers from other jurisdictions: equivalent contractual or regulatory mechanisms, including the EU-U.S. Data Privacy Framework, the UK Extension to the DPF and applicable APEC Cross-Border Privacy Rules.

17. Third-Party Links & Services

Our website and Apps may contain links to third-party websites or services that we do not control. This Policy does not apply to those third parties. We encourage you to read the privacy notices of every third-party service that collects your Personal Data.

18. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, technology, applicable law or for other operational, legal or regulatory reasons. When we make material changes we will:

  • Update the "Effective" and "Last updated" dates at the top of this Policy;
  • Increase the version number;
  • For changes that affect previously collected Personal Data, notify users via email and/or a prominent in-app notice, and where required seek fresh consent.

19. Contacting Us

If you have any questions about this Policy, our data-processing practices or your rights, please contact us:

  • By email: contact@dlwenyuan.com (general enquiries, privacy rights)
  • By email: support@dlwenyuan.com (technical support for our published Apps)
  • By post: dlwenyuan.com, Sheffield Technology Park, United Kingdom

We will respond to your query within the time limits required by applicable law.