Privacy policy
This English version is a translation of the French reference text (version 1.3). It reflects the same practices; in the event of a discrepancy, the French version prevails, subject to section 64.
Version: 1.3
Effective date: September 25, 2026
SUMMARY — PRIVACY BY DESIGN
Upchin is built on a simple principle: the sensitive information needed to control screen time should, as far as possible, stay on the User’s device.
In the current version of Upchin:
- no Upchin account is required to use the Application;
- UPCHIN CORPORATION does not sell Users’ personal data and does not use any data for behavioral advertising or cross-app tracking;
- the selections of apps, categories and websites made through Apple Screen Time / Family Controls remain processed locally, using the mechanisms provided by Apple;
- the names or identifiers of the targeted apps, the targeted websites, actual screen time, the detailed history of phone use, the content of custom messages and the User’s location are not transmitted to UPCHIN CORPORATION;
- unless the User declines, Upchin transmits limited usage statistics about the use of the Application itself, for example progress through onboarding, usage sessions, the protections enabled, counts or durations expressed in ranges, certain purchase results and closed error codes;
- these statistics are pseudonymized: they are linked by a random identifier specific to the installation, created on the device, unrelated to the User’s identity, stored in hashed form on our servers and erasable at any time; event times are rounded to the hour and the IP address is not retained;
- the User can decline these statistics from the moment of installation or turn them off at any time in Settings → Privacy, which erases the local data and triggers the erasure of the corresponding data on our servers; the User can also export, at any time, what the Application has transmitted;
- if notifications are enabled, a separate technical installation record is created so that notifications can be delivered;
- some data may also be processed when a User voluntarily contacts support, visits the upchin.app website or makes a purchase through Apple.
This summary is intended to make the Policy easier to read; it does not replace the detailed provisions below.
I. IDENTITY AND SCOPE
1. Data controller
This Privacy Policy describes the processing of personal data relating to the Upchin mobile application, its extensions and widgets, and the upchin.app website, when they are operated by:
UPCHIN CORPORATION
Société par actions simplifiée (SAS) with a share capital of €500
Registered office: 78 avenue des Champs-Élysées, bureau 326, 75008 Paris, France
Paris Trade and Companies Register (RCS): 109 154 351
SIREN: 109 154 351
SIRET (registered office): 109 154 351 00018
EU VAT number: FR86 109154351
Privacy and support e-mail: support@upchin.app
Phone: +33 6 87 35 36 29
Hereinafter “UPCHIN CORPORATION”, “Upchin”, “we”, “our” or “the Publisher”.
UPCHIN CORPORATION is the controller of the processing operations whose purposes and means it determines itself. Apple processes certain data for its own purposes, under its own terms and policies.
No data protection officer (DPO) has been appointed as of the effective date of this Policy. Any question relating to data protection may be sent to support@upchin.app.
2. Scope
This Policy applies to:
- the Upchin Application;
- its extensions, widgets and associated components;
- the features that use the Apple Screen Time, Family Controls, Managed Settings, Device Activity, StoreKit interfaces and other required system interfaces;
- the upchin.app website;
- exchanges with Upchin support;
- the information the Publisher receives from Apple in connection with the distribution and sale of the Application.
It does not govern the processing that Apple, a telecommunications operator, a browser, another application or any other third party carries out for its own purposes.
3. Definitions
For the purposes of this Policy:
- “Application” means Upchin, its extensions and widgets;
- “Apple” means Apple Inc., its subsidiaries and the entities operating the relevant Apple services;
- “local data” means information processed or stored only on the User’s device or in an associated Apple system space to which UPCHIN CORPORATION has no server-side access;
- “personal data” means any information relating to an identified or identifiable natural person within the meaning of applicable law;
- “Apple Services” means in particular iOS, the App Store, StoreKit, Screen Time, Family Controls, Managed Settings, Device Activity and the system services used by Upchin;
- “User” means any person using the Application or the website.
II. UPCHIN’S PRIVACY PRINCIPLES
4. Local processing by default
Upchin is designed so that its core digital-habit features can work without creating a user profile on UPCHIN CORPORATION’s servers.
Whenever the information needed for a feature to work can stay on the device, Upchin favors that local processing.
The fact that a piece of information is technically accessible to the Application on the device does not mean that it is transmitted to UPCHIN CORPORATION.
5. No Upchin account
In the current version, normal use of Upchin does not require creating a user account with UPCHIN CORPORATION.
For the normal operation of the Application, we therefore do not ask you to create an Upchin profile containing a name, an e-mail address, a password or a social sign-in identifier.
An Apple account may nevertheless be required to download the Application, use certain Apple features or make a purchase. That account is administered by Apple, not by UPCHIN CORPORATION.
6. No sale of data and no behavioral advertising
UPCHIN CORPORATION:
- does not sell Users’ personal data;
- does not rent out User databases;
- does not use Screen Time or motion data to build advertising profiles;
- does not use such data for targeted or behavioral advertising;
- does not share personal data for cross-context behavioral advertising;
- does not track Users across third-party companies’ apps or websites for advertising purposes.
7. No decisions producing legal effects
Upchin’s automated mechanisms serve to apply the rules chosen by the User, for example a schedule, a usage delay, a manual block or a motion-related rule.
They do not constitute automated decision-making producing legal effects or similarly significant effects on the User within the meaning of applicable data protection legislation.
III. DATA PROCESSED IN THE APPLICATION
8. Selections of apps, categories and domains
Upchin may allow the User to select apps, app categories or internet domains through the interfaces provided by Apple.
Depending on the Apple features used, these selections may be represented by identifiers or tokens designed by Apple to preserve privacy.
Upchin uses this information solely to carry out the rules chosen by the User, in particular to:
- apply a block;
- schedule a block;
- trigger a restriction after a set duration;
- display the status of a rule;
- allow the User to change their configuration.
These selections and tokens are meant to remain on the device or in the Apple system spaces needed for the Application to work. In the normal operation of the Application, UPCHIN CORPORATION does not receive on its servers the list of apps, categories or domains selected by the User.
9. Usage data and Screen Time
Depending on the iOS version, the permissions granted and the features used, Apple’s interfaces may allow Upchin to monitor certain usage events, duration thresholds or activity information needed to run the configured rules.
Where more detailed usage information is made available by Apple with the User’s explicit permission, Upchin uses it only for the features the User has requested.
This information is meant to be processed locally.
In the normal operation of the Application, UPCHIN CORPORATION does not receive on its servers:
- the detailed history of apps used;
- the detailed history of websites visited;
- the content viewed within apps;
- the messages, photographs or documents contained in other apps;
- the individual Screen Time history used to operate Upchin’s restrictions.
Upchin is not intended to read the personal content displayed inside blocked or monitored apps.
10. Restriction settings
The Application may store locally the settings defined by the User, such as:
- the times and days of a Weekly Schedule;
- the durations and thresholds of a Delay Lock;
- the duration of a block;
- the activation and configuration of Motion Lock;
- the configuration of Back IRL;
- the apps, categories or domains associated with a rule;
- the Application’s general preferences;
- the states needed for widgets and extensions to work.
Detailed settings remain meant to be processed locally. Unless the User declines, the usage statistics described in section 26 may nevertheless include limited, categorized information about the use of these features, for example the type of protection enabled, a schedule creation or deletion action, the number of time slots or days expressed as a range, or the size of the app selection expressed as a range.
The telemetry never transmits the names or identifiers of the selected apps, the name of a rule or schedule, or the detailed times configured.
11. Custom messages
When the User writes a custom message intended to appear on a block screen, that text is stored in order to provide the corresponding feature.
In the current version, this content is meant to be kept locally, and UPCHIN CORPORATION is not intended to receive it.
The User should not use a custom message as a place to store highly sensitive or irreplaceable information.
12. Progress data and estimates
Upchin may compute and display information about digital habits, progress, blocking periods or potentially reclaimed time.
These computations may rely on:
- locally available data;
- Screen Time events or thresholds;
- the configured rules;
- values entered or confirmed by the User;
- computation assumptions.
The detailed data used for operation and estimates stays local. When the usage statistics described in section 26 are enabled, certain indicators may be sent only in categorized form or as ranges, for example the number of days the app was opened, the number of blocks, the configured duration of a delay or the size of an app selection.
UPCHIN CORPORATION does not receive the User’s actual screen time or their detailed history of phone use.
13. Motion data and Motion Lock
Motion Lock may use the device capabilities that detect motion or movement.
Depending on the version of the feature and the capabilities of iOS, the processing may rely in particular on:
- motion sensors;
- physical activity or derived information;
- movement information;
- and, where technically necessary and authorized by the User, location information.
This information is used to determine locally whether the condition chosen for Motion Lock is met.
UPCHIN CORPORATION does not receive the User’s position, geographic coordinates, location history or the raw motion data used by Motion Lock.
When the usage statistics described in section 26 are enabled, Upchin may transmit only the status of the location permission (for example: always allowed, allowed while in use, denied or not requested). This status contains no position.
UPCHIN CORPORATION does not use Motion Lock to build a server-side movement history, sell location data, track a User for advertising purposes or analyze their movements remotely.
14. Notifications
Upchin may request permission to display notifications when they are useful to the operation of the Application.
If the User enables notifications, the Application may register an installation on UPCHIN CORPORATION’s server so that notifications can be routed. This record may include:
- a random technical identifier assigned to the installation;
- a technical authentication secret stored in the device keychain;
- the notification token provided for routing notifications;
- the Upchin version and build number;
- the major iOS version;
- the Application language;
- the device family (for example iPhone or iPad);
- a technical flag distinguishing a simulator from a real device.
This record is created only if notifications are enabled. It does not contain the User’s name, e-mail address, Apple ID, IDFA, IDFV, list of apps or Screen Time data.
A reinstallation creates a new technical identity if notifications are enabled again; the previous installation is revoked as part of the service’s intended operation.
Notifications generated purely locally continue to be scheduled and displayed through the device’s system features.
15. Widgets and App Group
Upchin may use the Apple mechanisms that allow the Application and its extensions or widgets to share locally the information strictly necessary for their operation.
These exchanges may concern in particular:
- the status of a block;
- a duration;
- a preference;
- the information needed for the Back IRL action;
- configuration states.
The use of a shared Apple space between the Application and its own extensions does not mean that data is sent to UPCHIN CORPORATION’s servers.
IV. APPLE PERMISSIONS
16. Screen Time / Family Controls permission
Certain features require the explicit permission provided for by Apple in order to use the Screen Time / Family Controls interfaces.
The User may refuse or withdraw this permission through the options offered by iOS.
Withdrawing the permission may render certain features inoperative and may invalidate the tokens or selections previously provided by Apple.
17. Motion and location permissions
Where Motion Lock requires a motion, physical activity or location permission, iOS presents the corresponding system prompt.
Upchin uses the permission only for the functional purposes presented to the User.
The User may change or withdraw a permission in the iOS settings. Withdrawal may prevent Motion Lock from working properly.
18. Principle of permission minimization
Upchin seeks to request only the permissions needed for the features in use.
A system permission is not a general authorization allowing UPCHIN CORPORATION to use the information concerned for another purpose.
V. DATA PROCESSED OUTSIDE THE APPLICATION
19. Support and voluntary communications
When a User contacts support@upchin.app, UPCHIN CORPORATION may receive:
- their e-mail address;
- their name or nickname if it appears in the message;
- the content of their request;
- the attachments they choose to send;
- technical information they provide voluntarily;
- the date and the metadata needed to route the message.
Purposes:
- responding to the request;
- providing support;
- diagnosing a problem;
- preventing abuse;
- keeping evidence of an exchange where necessary.
Legal basis for the EEA:
- performance of the contract or pre-contractual measures where the support relates to the service;
- legitimate interest in responding to requests and securing the service;
- legal obligation where retention of information is required.
Users are asked not to send unnecessary screenshots containing third parties’ personal data, medical data, passwords, authentication codes or other highly sensitive information.
20. The upchin.app website and technical logs
When the upchin.app website is visited, the hosting infrastructure may automatically process technical information needed to deliver and secure the site, such as:
- IP address;
- date and time of the request;
- page or resource requested;
- HTTP response code;
- browser type or user agent;
- technical connection information;
- data needed to detect errors, attacks or abusive use.
Purposes:
- providing the website;
- ensuring security;
- detecting errors;
- preventing attacks and abuse;
- performing technical diagnostics.
Legal basis for the EEA: UPCHIN CORPORATION’s legitimate interest in operating and securing its website.
Technical logs are retained for a limited period matching security and diagnostic needs, in principle 30 days at most, unless longer retention is required because of a security incident, an investigation, a legal obligation or a dispute.
21. Cookies and tracking technologies on the website
UPCHIN CORPORATION does not use advertising cookies or technologies designed to track visitors across different websites for behavioral advertising purposes.
Mechanisms strictly necessary for the operation or security of the website may be used where required.
If UPCHIN CORPORATION later adds an audience measurement solution, a third-party service or a mechanism requiring consent, this Policy and, where necessary, the website’s consent interface will be updated before it is used.
22. Apple purchases and subscriptions
In-app purchases, one-time purchases, subscriptions, renewals and refunds offered in the Application are administered by Apple.
Apple may process in particular:
- the Apple account;
- payment details;
- purchase history;
- tax information;
- receipts and transactions;
- the account territory;
- the information needed for fraud prevention.
UPCHIN CORPORATION does not receive the full number of the payment card used with Apple.
To verify an entitlement, Upchin may process the necessary StoreKit information, for example the status of a purchase, subscription, entitlement or transaction.
UPCHIN CORPORATION may also receive from Apple commercial, financial, tax or performance reports relating to the distribution of the Application. This information is processed to administer the business, accounting, tax obligations, refunds and fraud prevention.
Apple independently determines a significant part of the processing carried out in connection with the App Store and the Apple account. That processing is governed by Apple’s policies.
23. App Analytics and diagnostics provided by Apple
Apple may make available to UPCHIN CORPORATION, through App Store Connect and Apple’s developer tools, statistics relating in particular to downloads, sessions, performance and crashes of the Application.
The usage and diagnostic data that Apple shares with developers depends in particular on the sharing choices the User makes in the Apple environment. Apple applies its own privacy mechanisms and may provide certain statistics in aggregated form or subject to privacy thresholds.
UPCHIN CORPORATION may use this information to:
- measure the general operation and adoption of the Application;
- detect and fix crashes or anomalies;
- improve stability and compatibility;
- understand the Application’s general commercial performance.
This information provided by Apple is not used by UPCHIN CORPORATION to build an advertising profile of the User or to track the User across third-party companies’ apps and websites.
VI. WHAT UPCHIN DOES NOT COLLECT FOR ITS OWN SERVERS
24. No centralization of behavioral data
Even when the usage statistics described in section 26 are enabled, UPCHIN CORPORATION does not centralize on its servers:
- the detailed list of installed apps;
- the names or identifiers of the apps selected in Family Controls;
- the selected domains or websites;
- actual screen time;
- the detailed history of apps used;
- browsing history;
- the content of messages or communications;
- the device’s photographs and videos;
- contacts;
- the position or detailed location history;
- the raw motion data used by Motion Lock;
- the content of custom messages;
- the answers to the onboarding questionnaire, personal goals or first name;
- the name of a rule or schedule;
- the User’s detailed personal restriction times;
- the exact time of the User’s actions (only a time rounded to the hour is transmitted);
- the User’s IP address;
- the clear-text value of the pseudonymous installation identifier (stored only in hashed form);
- any identity data: name, e-mail address, Apple ID, IDFA, IDFV.
The statistics described in section 26 concern the use of Upchin itself and use closed categories or values grouped into ranges.
25. No advertising SDK
UPCHIN CORPORATION does not knowingly integrate into Upchin any SDK whose purpose is to build an advertising profile or to track the User across third-party companies’ apps and websites.
26. Analytics and telemetry
Pseudonymized usage statistics, enabled by default
Upchin transmits to UPCHIN CORPORATION usage statistics relating to the use of the Application itself. This transmission is enabled by default from the first launch; the User is informed of it by this policy, available within the Application, and may disable it at any time under the conditions described below (“Declining, disabling and erasure”).
These statistics may include, as closed categories or grouped values:
- the start of a usage session of the Application (a new session is counted after thirty minutes of inactivity);
- each onboarding screen left and the time spent on that screen expressed in ranges, as well as whether onboarding was completed;
- certain major usage milestones, such as first launch, first protection enabled, first block, paywall displayed or first purchase;
- the status of the Screen Time permission and the context in which it was requested;
- the type of protection enabled or disabled (Delay Lock, Motion Lock, widget or schedule) and whether the disabling was voluntary or automatic;
- the origin of a block, its planned duration and its actual duration expressed in ranges, and whether it completed or was interrupted;
- the display of a paywall, the result of a purchase or restore and the type of plan concerned;
- closed technical codes relating to certain errors or unavailability;
- schedule editing actions and numbers of days or time slots expressed in ranges;
- the status of the location permission, without any position;
- whether custom messages and notifications are enabled;
- certain milestone snapshots at D+1, D+7, D+30 and D+90, containing only categorized or range-grouped indicators.
Each event is also accompanied by: the Application version and build number; the major iOS version; the device family (iPhone or iPad); the Application language; the App Store storefront country; a flag indicating that it comes from a test build (TestFlight or development); the version of the information text presented; a random identifier specific to that event, used only to avoid counting the same submission twice; the time of the event rounded to the full hour; the number of the current usage session; and a sequence number within that session.
Pseudonymous installation identifier
The events of a single installation are linked together by an installation identifier with the following characteristics:
- it is a random number (UUID) generated on the device when collection begins;
- it is not derived from any information about the User or the device: not the IDFA, the IDFV, the Apple ID, or the installation number or token used for notifications;
- it is never matched with an account, an e-mail address, a notification token, a purchase or any other identity data;
- it is kept on the device in a file excluded from iCloud backup and disappears when the Application is uninstalled;
- it is stored on our servers only in a form hashed with a secret specific to UPCHIN CORPORATION, so that the value present on the device never appears in the database;
- it is deleted when the User disables the statistics or resets the Application, and replaced by a new identifier unrelated to the previous one if the statistics are re-enabled;
- its lifetime is limited to thirteen months: after that period, the Application automatically replaces it with a new identifier unrelated to the previous one, so that events cannot be correlated beyond that period.
This identifier makes it possible to measure, at the level of an installation and without knowing the User’s identity, journeys (for example progress through onboarding), retention rates (return of the installation at D+1, D+7 and D+30), frequency of use and feature adoption over time.
Degraded timestamp and IP address
The Application deliberately rounds the time of each event to the full hour before transmission; the exact time never leaves the device, and the server rejects any event timestamped more precisely. Durations (time spent on a screen, duration of a block, session cut-off) are measured locally and then transmitted only as ranges.
The IP address is needed for network transport but is retained neither in the telemetry data nor in the server logs for the collection and erasure routes. The server infrastructure is configured accordingly.
Purpose
These statistics are used solely to:
- understand where onboarding works or fails;
- measure the general adoption of features;
- understand which protection mechanisms are used;
- assess the general operation of blocks;
- measure frequency of use and installation retention;
- reconstruct, pseudonymously, an installation’s journey in order to understand where the product fails;
- improve the payment and restore flows;
- detect certain technical errors;
- evaluate product experience variants;
- improve Upchin.
They are not used for advertising, behavioral marketing, individual scoring, cross-app tracking or building a personal profile. They are neither sold, nor cross-referenced with other apps or services, nor passed on to an analytics provider.
Legal basis
In the EEA, this processing is based on UPCHIN CORPORATION’s legitimate interest in measuring and improving its own product, implemented using pseudonymized and minimized data (closed categories, values in ranges, rounded time, no third party), with information provided at installation and an immediate, permanent right to object. Where the law applicable to the User makes this type of measurement subject to prior consent, UPCHIN CORPORATION complies with it.
Declining, disabling and erasure
The User may decline or disable these statistics:
- at any time in Settings → Privacy.
Disabling takes effect immediately: no further event is recorded or transmitted; the local queue, the local ledger and the installation identifier are erased; the Application asks our servers to erase all data associated with that identifier, a request repeated until confirmed if the network is temporarily unavailable. A full reset of the Application (“Reset all data”, after confirmation) has the same effect.
If the statistics are re-enabled, the User receives the appropriate information again and a new identifier, unrelated to the previous one, is created. A substantial change to the information text may cause this choice to be presented again.
Declining or disabling causes no loss of functionality.
Transparency and export
From Settings → Privacy, the User may at any time save or share a text file containing the collection status, the installation identifier, the local ledger, the events awaiting submission and the log of submissions, rejections and erasures. This file is produced on the device and is transmitted to no one, unless the User chooses to share it themselves.
Transmission and local storage
Only the main Application performs transmissions. The Screen Time extensions and the widget do not transmit telemetry directly; when they produce a relevant event, it is stored locally so that the main Application can transmit it.
The local queue is capped and unsent events expire after 30 days at the latest. The telemetry files (identifier, ledger, queue, local log) are excluded from iCloud backup.
Hosting and retention
Events are received by server infrastructure controlled by UPCHIN CORPORATION and hosted in Europe. No analytics provider has access to it.
Telemetry data is retained for 24 months at most, then automatically deleted. Erasure requested by the Application (disabling or reset) is immediate and covers all data associated with the identifier.
When the Application is uninstalled without prior disabling, the identifier disappears from the device and the Application can no longer request erasure; the remaining data can then be linked to no device and no person, and expires according to the periods above.
Internal access
The data received is consulted through an internal dashboard with restricted access, which presents aggregates (funnels, retention, adoption) and, for product diagnostic purposes, the sequence of events of an installation identified by its hashed key only. Events originating from the Publisher’s test builds are excluded from these statistics by default.
Regions in which this collection is disabled
No Upchin usage statistics are collected or transmitted in the following regions:
- mainland China;
- Hong Kong;
- Macao;
- Taiwan.
This exclusion is determined locally from signals such as the App Store storefront country, the iOS region or the time zone. These signals are used to prevent collection in the regions concerned and are not transmitted as telemetry data for those Users.
UPCHIN CORPORATION may also disable collection remotely, globally or for certain regions or versions. When such disabling is applied, the local telemetry queue and the installation identifier are deleted.
VII. PURPOSES AND LEGAL BASES
27. Table of processing operations controlled by UPCHIN CORPORATION
| Processing | Purpose | Main legal basis in the EEA |
|---|---|---|
| Functional configuration processed locally | Providing the chosen features | Performance of the requested service |
| Screen Time processed locally | Triggering and displaying Upchin features | Performance of the requested service; system permission where required |
| Motion/location processed locally | Operating Motion Lock | Performance of the requested service; system permission where required |
| Pseudonymized usage statistics (section 26) | Product analysis, improvement, error detection, retention measurement | Legitimate interest (pseudonymized and minimized data, identifier limited to thirteen months, no third party, information at installation, immediate objection); express consent wherever local law requires it |
| Technical record for notifications | Delivering the requested notifications | Performance of the requested service; notification permission |
| Support e-mails | Responding, assisting, diagnosing | Contract / pre-contractual measures / legitimate interest |
| Website technical logs | Providing and securing the website | Legitimate interest |
| Transaction information received from Apple | Paid access, accounting, fraud | Contract / legal obligation / legitimate interest |
| Data required by a legal obligation | Tax, accounting, authorities | Legal obligation |
Where consent is the legal basis for a processing operation, the User may withdraw it at any time without affecting the lawfulness of the processing carried out before withdrawal.
VIII. RECIPIENTS AND SHARING
28. Internal access
Data actually received by UPCHIN CORPORATION is accessible only to the people who need it for their role, in particular for:
- support;
- administration;
- security;
- accounting;
- compliance with legal obligations.
29. Technical service providers
UPCHIN CORPORATION may use strictly necessary service providers, in particular for:
- hosting the infrastructure or the website;
- hosting e-mail;
- connectivity and security;
- infrastructure maintenance;
- accounting or legal obligations.
These providers act according to their applicable legal role and are authorized to process data only for the services concerned.
No third-party analytics or advertising SDK is integrated into the Upchin telemetry described in section 26.
Using a hosting or infrastructure provider does not give it access to the Screen Time data, the names of the selected apps, the position or the motion data, which remain on the device.
30. Apple
Apple receives and processes the data needed for its own services, in particular the App Store, StoreKit, the Apple account, billing and certain system interfaces.
UPCHIN CORPORATION does not control all of the processing carried out by Apple.
31. Authorities and legal obligations
UPCHIN CORPORATION may disclose information it holds where such disclosure is required by a legal obligation, a court decision or a competent authority, or where it is necessary for the establishment, exercise or defense of legal claims.
UPCHIN CORPORATION cannot hand over to an authority local data that it does not possess and to which it has no access.
32. Corporate transactions
In the event of a merger, acquisition, restructuring, transfer of business or transfer of assets, the data actually held by UPCHIN CORPORATION may be transferred to the successor to the extent permitted by law and subject to the applicable safeguards.
Such a transfer does not automatically turn the User’s purely local data into data held by the company.
IX. INTERNATIONAL TRANSFERS
33. Principle
UPCHIN CORPORATION is established in France.
The data actually held by the company may be processed in France, in the European Economic Area or, depending on the technical service providers used, in other countries.
Where an international transfer of personal data is subject to the GDPR or comparable legislation, UPCHIN CORPORATION uses the applicable legal mechanism, for example:
- an adequacy decision;
- standard contractual clauses;
- another safeguard recognized by the regulations;
- or a legally available derogation in appropriate cases.
The User may contact support@upchin.app for further information on the safeguards applicable to a transfer concerning them.
34. Data remaining on the device
Data that remains exclusively on the User’s device and is not transmitted to UPCHIN CORPORATION is not the subject of an international transfer by UPCHIN CORPORATION.
X. RETENTION
35. Local data
Local functional data is retained according to the operation of iOS and the User’s choices.
It may be deleted in particular when:
- the User erases a configuration in the Application;
- the User uninstalls the Application;
- iOS deletes or resets the data concerned;
- Apple permissions are revoked;
- the device is reset or replaced.
The local telemetry queue is limited to 30 days at most. The installation identifier, the ledger and the local telemetry log are kept on the device as long as collection is enabled; they are deleted immediately when the User disables the statistics or resets the Application.
The files concerned are excluded from iCloud backup. A reinstallation starts telemetry from scratch, with a new identifier.
UPCHIN CORPORATION cannot guarantee the recovery of local data it has never received.
36. Support
Support exchanges are retained for the time needed to handle the request and then, in principle, for 24 months at most after the last exchange, unless longer retention is justified by:
- a legal obligation;
- the prevention of abuse;
- a warranty;
- a dispute or risk of dispute;
- the establishment, exercise or defense of legal claims.
37. Technical logs
The website’s technical logs are retained for 30 days at most in principle, subject to longer retention strictly necessary for the analysis of a security incident, a legal obligation or legal proceedings.
38. Accounting and transaction information
Information that the law requires to be kept for accounting, tax or proof-of-transaction purposes is retained for the applicable statutory period.
XI. SECURITY
39. Security measures
UPCHIN CORPORATION applies technical and organizational measures proportionate to the nature of the data actually processed and the risks involved.
Upchin’s local design reduces the amount of behavioral data that needs to be centralized.
Measures may include in particular:
- data minimization;
- access control;
- security updates;
- protection of administrative systems and accounts;
- encryption provided by the protocols and infrastructure used;
- limitation of retention periods;
- separation of environments where relevant.
No computer system can, however, guarantee absolute security.
40. Security incident
Where an incident concerns data actually held by UPCHIN CORPORATION, the company applies the obligations to notify the persons concerned and the competent authorities imposed by applicable legislation.
Data that has never left the User’s device cannot be compromised by a breach of a UPCHIN CORPORATION server.
XII. USER CHOICES AND CONTROL
41. iOS permissions
The User can control the available permissions from the iOS settings, in particular those relating to:
- Screen Time / Family Controls where the system allows it;
- motion and physical activity;
- location;
- notifications.
Withdrawing a permission may prevent a feature from working.
Independently of system permissions, the User may also enable or disable the usage statistics in Settings → Privacy, and export from there all of the telemetry information present on their device.
42. Deleting local data
Where data is exclusively local, UPCHIN CORPORATION has no remote copy to delete.
Depending on the data concerned, the User may:
- change or delete a rule in Upchin;
- reset the settings concerned;
- withdraw permissions;
- uninstall the Application.
Uninstalling may cause the irreversible loss of local data.
43. Requests relating to data held by UPCHIN CORPORATION
For data actually held by the company that can be linked to an identifiable person or installation, for example a support exchange or a technical notification record, the User may send their request to:
support@upchin.app
UPCHIN CORPORATION may request the information strictly necessary to verify the identity of the requester before disclosing or deleting data.
For usage statistics already transmitted, the right to erasure is exercised directly from the Application: disabling in Settings → Privacy or a full reset triggers the deletion of all data associated with the installation identifier on our servers. As UPCHIN CORPORATION is unable to link a pseudonymous identifier to a person, a request made by e-mail cannot identify these events; in any case, they remain subject to the automatic deletion periods set out in section 26.
The company will not artificially create a personal database solely in order to respond to a request concerning information it does not hold or cannot reasonably link to the requester.
XIII. RIGHTS IN THE EUROPEAN UNION AND THE EEA
44. GDPR rights
Where the GDPR applies, the data subject may, under the statutory conditions, have the following rights:
- right of access;
- right to rectification;
- right to erasure;
- right to restriction of processing;
- right to object;
- right to data portability where the conditions are met;
- right to withdraw consent at any time;
- right not to be subject to certain solely automated decisions;
- right to lodge a complaint with a supervisory authority.
A request may be sent to support@upchin.app.
45. Complaints in France
The User may lodge a complaint with the:
Commission nationale de l’informatique et des libertés (CNIL)
3 Place de Fontenoy — TSA 80715
75334 Paris Cedex 07
France
www.cnil.fr
This option does not prevent the User from first contacting UPCHIN CORPORATION in order to try to resolve their request directly.
46. Data processed only locally
The rights provided for by the GDPR concern data processed by the controller.
Where UPCHIN CORPORATION does not receive and cannot identify data kept exclusively on the device, certain requests will in practice have to be carried out by the User using the controls of the Application or of iOS.
UPCHIN CORPORATION will, where possible, explain the corresponding procedure.
XIV. CHILDREN AND MINORS
47. Positioning of the service
Upchin is rated 9+ on the App Store.
A minor should use the Application only with the prior permission and under the effective supervision of their legal representative, and where applicable law allows it; subscribing is a matter for the Apple account holder, who must have the legal capacity to enter into a contract.
Upchin requests no information that would identify the User and does not seek to build profiles of children.
48. Collection from minors
UPCHIN CORPORATION does not seek to build a database of children’s profiles.
Upchin’s local architecture is designed to limit the transmission to the Publisher of information about digital use, whatever the User’s age.
If UPCHIN CORPORATION learns that it has directly collected personal data from a child in breach of an applicable mandatory rule, it will take the reasonable steps necessary to delete that data or bring the processing into compliance.
Local rules requiring parental consent remain applicable.
XV. UNITED STATES LAW
49. United States — general principles
Residents of the United States have the rights provided for by federal law and by the law of their State where it applies.
UPCHIN CORPORATION does not sell personal data and does not use Users’ personal data for cross-context behavioral advertising.
50. States with comprehensive privacy laws
Where a State law grants an applicable right, the User may in particular have the right to request:
- access to, or confirmation of, processing;
- correction;
- deletion;
- a copy or portability;
- information about certain disclosures;
- to opt out of certain uses, in particular sale, targeted advertising or certain profiling.
UPCHIN CORPORATION does not unlawfully discriminate against a person who exercises a legal privacy right.
Requests may be sent to support@upchin.app.
51. California
For California residents, UPCHIN CORPORATION does not “sell” or “share” personal data for cross-context behavioral advertising within the meaning given to those terms by applicable California legislation.
To the extent that California law applies to UPCHIN CORPORATION and to the processing concerned, a resident may exercise the rights provided for by that legislation by writing to support@upchin.app.
XVI. INDIA
52. Data protection
Where Indian digital personal data protection legislation applies, UPCHIN CORPORATION processes digital personal data in accordance with the applicable obligations, in particular regarding:
- notice;
- purpose;
- security;
- the exercise of rights;
- the handling of grievances;
- deletion when retention is no longer necessary or legally required.
53. Grievances in India
A data principal may address a grievance relating to Upchin to:
UPCHIN CORPORATION — Privacy / Grievance Contact
Grievance Officer: Mingran SUN, President of UPCHIN CORPORATION
78 avenue des Champs-Élysées, bureau 326
75008 Paris, France
support@upchin.app
Local obligations requiring the appointment or publication of an additional contact will be applied when they become applicable to UPCHIN CORPORATION in view of its activity.
XVII. JAPAN
54. Users in Japan
Where the Act on the Protection of Personal Information (APPI) applies, UPCHIN CORPORATION complies with the rights and obligations applicable to the personal data it actually holds.
Requests for access, correction, cessation of use or deletion provided for by applicable law may be sent to support@upchin.app.
Where personal data is provided to a service provider or recipient located abroad, the rules applicable to international transfers are complied with.
XVIII. SOUTH KOREA
55. Users in South Korea
Where the Personal Information Protection Act (PIPA) applies, UPCHIN CORPORATION processes personal information in accordance with the applicable local requirements, in particular regarding:
- transparency;
- minimization;
- security;
- retention;
- the exercise of rights;
- international transfers;
- breach notification where necessary.
Requests may be sent to:
UPCHIN CORPORATION — Privacy Contact
support@upchin.app
78 avenue des Champs-Élysées, bureau 326, 75008 Paris, France
Phone: +33 6 87 35 36 29
Mandatory local rules applicable to children and to the consent of legal representatives prevail over any contrary provision of this Policy.
XIX. MAINLAND CHINA, HONG KONG, MACAO AND TAIWAN
56. Distinct territories
Mainland China, Hong Kong, Macao and Taiwan have distinct regulatory frameworks.
This section must be read together with the mandatory rules of the territory concerned.
57. Mainland China
Where the Personal Information Protection Law (PIPL) or another applicable Chinese rule governs processing carried out by UPCHIN CORPORATION, the required information concerning:
- the purpose;
- the categories of information;
- the processing methods;
- the retention periods;
- the recipients;
- transfers outside China;
- the exercise of rights,
is provided in accordance with applicable law.
Upchin’s local design limits the amount of digital-usage information that could be transferred to UPCHIN CORPORATION outside China.
Where personal information is actually transferred from mainland China to a recipient located outside China, UPCHIN CORPORATION applies the transparency obligations, the separate-consent requirements and the transfer mechanisms required where they are legally applicable.
58. Hong Kong
Where the Hong Kong Personal Data (Privacy) Ordinance applies, UPCHIN CORPORATION complies with the principles applicable to the collection, use, security, retention of and access to the personal data it holds.
59. Taiwan
Where the Taiwan Personal Data Protection Act applies, Users have the mandatory rights provided for by that legislation with respect to the personal data actually held by UPCHIN CORPORATION.
Requests for these territories may be sent to support@upchin.app.
XX. OTHER TERRITORIES
60. Precedence of mandatory local rights
Where the User resides in a territory that grants them additional mandatory rights, those rights are not removed by this Policy.
UPCHIN CORPORATION applies this Policy subject to the mandatory local rules actually applicable to its activity.
XXI. APPLE AND APP PRIVACY
61. App Store declarations
UPCHIN CORPORATION keeps the “App Privacy” declarations on the App Store listing consistent with the Application’s actual practices.
Data processed exclusively on the device is not declared as collected by UPCHIN CORPORATION when it never leaves the device.
For the usage statistics described in section 26, the App Store listing declares the categories “Device ID”, “Product Interaction” and “Other Usage Data”, collected for analytics purposes, as “Data Not Linked to You” and not used for tracking: the installation identifier is a random number that is associated with no identity, no account and no contact details, it is hashed on our servers, and event times are rounded to the hour.
A technical installation identifier and a notification token may be processed for the notifications feature when it is enabled.
The App Store declarations must be updated whenever a version of the Application actually changes these practices.
62. Technical changes
If a future version of Upchin introduces, in particular:
- an Upchin account;
- server synchronization;
- a cloud backup controlled by UPCHIN CORPORATION;
- an analytics SDK that collects data;
- a crash-reporting service that transmits identifiers or personal data;
- a social feature;
- a new use of Screen Time data;
- remote collection of motion or location data;
UPCHIN CORPORATION will update this Policy and, where necessary, the App Privacy declarations, the information screens and the consent mechanisms before or upon the rollout of that feature, in accordance with applicable law.
XXII. CHANGES TO THE POLICY
63. Updates
UPCHIN CORPORATION may amend this Policy to take account of:
- a change to the Application;
- a change in the law;
- a change in Apple’s services;
- a new service provider;
- a new feature;
- a change in security or retention practices.
The version in force states its effective date.
Where a change substantially affects the way personal data is used and the law so requires, the User is informed appropriately and new consent is requested where required.
XXIII. LANGUAGES
64. Translations
This Policy may be translated into several languages so as to be accessible to international Users.
Translations must faithfully reflect the practices described in the reference version.
Where a local law requires a local-language version to prevail or imposes a particular interpretation, that mandatory rule applies.
XXIV. CONTACT
65. Questions, rights and complaints
For any question relating to privacy, to exercise a right or to report a problem concerning personal data:
UPCHIN CORPORATION
Privacy / Support Upchin
78 avenue des Champs-Élysées, bureau 326
75008 Paris
France
E-mail: support@upchin.app
Phone: +33 6 87 35 36 29
Where the request concerns data stored exclusively on the device and never received by UPCHIN CORPORATION, we may not be technically able to access that data. We will indicate, where possible, how to manage it directly in Upchin or in iOS.