Privacy Policy — Yayu
Last updated: 22 September 2026
Yayu shows one Chinese word a day. There are no accounts and no sign-in, and nothing here is sold.
What the app does send is small and it is not nothing, so it is written out below rather than waved at. Four things leave the phone: anonymous counts of which parts of the app get used, crash reports when a build breaks, an install count from the service that builds the app, and a request to Google for the adverts the app shows.
What stays on your device
Everything the app needs to work ships inside it, and everything it learns about you stays in a database on the phone:
- The word list, the dictionary data, the calligraphic typefaces and the pronunciation recordings — all bundled with the app, so it works offline.
- Which words you have already seen, the word shown on a given day, and where you are in the trail you have browsed.
- The words you have hearted.
- Your settings: the typeface you last chose, whether pinyin and zhuyin are shown, which word types and HSK levels you want drawn from, and your daily reminder's time and on/off state.
None of that is transmitted anywhere, and there is no account to sync it to. Searching the word list happens entirely on the phone — what you type is never sent. The home-screen widget reads the same on-device data and sends nothing of its own. Deleting the app deletes all of it.
Usage counts
Yayu counts how its features are used, so that decisions about what to build get made from something better than a guess. The counts go to a small server we run ourselves, hosted on Cloudflare, and they are designed so that no single person's use can be read out of them:
No identifier. Nothing in the request names you, your phone, or an install. There is no account id, no advertising id, no install id and no session. (The adverts are a separate request to a different company and do carry one — see Adverts below. The two are never joined.)
No clock reading from your phone, and counts are sent in batches, so the exact moment you did something is not recorded.
Nothing is read from the connection. Not your IP address, not the country or city our host could tell us for free, not your browser or app user agent. None of it is written down.
Nothing you typed. The app has no code that can put text you wrote into a count — the only words it can send are ones it looked up in its own dictionary, and that is enforced by how the app is built rather than by a promise to be careful.
Words from that dictionary are a different matter, and as of the release carrying this change they are recorded for three actions. See below.
What is counted is the shape of a session: the app being opened, moving forward or back through words, opening Settings, keeping a word with the heart, sending a word to the Pleco dictionary app, exporting a word list or a card image, playing a pronunciation, what became of the daily-reminder prompt, whether you allowed or refused notification permission when asked (and whether you were asked in the feed or in Settings), and a reminder being opened — that last one recording which of morning, afternoon or evening it was, but not the date or the clock time.
Three of these record which word it was: keeping a word, sending one to Pleco, and exporting a single word. Keeping and sending carry the word itself — 端午節 — alongside its HSK level, whether it is a word, an idiom or a phrase, and the calligraphic face it was drawn in. A single-word export carries the word and the file format, and nothing else. Exporting a list records only that a list was exported, not what was in it.
That is a real thing to know about you, so it is worth saying plainly what it does and does not amount to. Every word in question comes from the dictionary that ships inside the app, so none of them is anything you wrote. What the record shows is which of those words you chose — and over time that is a picture of what you are studying. There is no account and no device identifier attached to it, so nothing joins that picture to your name; but we would rather describe it than let you discover it. If you would rather it were not recorded, the honest answer today is that there is no switch for it, and you should weigh that before keeping words you would not want counted.
Sending a word to Pleco is counted only if you have Pleco installed, because the button that does it only appears if you do — so that count does tell us a Chinese dictionary app is on the phone, in the aggregate. We do not read the list of apps on your device and could not; the app asks the system one narrow question, can anything here open a Pleco link, and the answer never leaves your phone. Every count carries, alongside it, your platform (iOS or Android), your device model and OS version, the app version, and whether you have a subscription — as a plain yes or no, with no purchase details attached. The exact list of counted actions is fixed in the app's source and changes only when a release changes it.
That device description is deliberately coarse, but it is a description: a rare enough combination of model, OS and app version could in principle point at one phone. We treat these counts as data that could be associated with you, and say so here rather than assume otherwise.
Crash reports
When the app crashes or hits an error, a report goes to Sentry, so the fault can be found and fixed. This is narrower than crash reporting usually is, on purpose:
- Crashes and errors only. No performance tracing: ordinary, working sessions are not sampled, because that is usage data by another name.
- No personal identifiers. Usernames, email addresses and IP addresses are switched off. The app has none to send in any case — there are no accounts.
- A session record, which may carry an install identifier. Alongside crash reports the app sends a small record each time it runs: when the run started, how long it lasted, and whether it ended normally or in a crash. That is what makes it possible to say how common a crash is rather than only that it happened. Sentry's own libraries may attach an identifier for the install to those records. Where it exists, it identifies an installation of the app, never you, and it is never joined to anything you do elsewhere.
- No console logs. The console trail is excluded from reports, because it is the likeliest place for a word you were reading, or something you searched for, to end up.
A report carries what is needed to diagnose the fault: the error and its stack trace, the trail of events the app recorded on its way there — minus the console output — and your device model, OS version and app version. Nothing you were reading, searching for or had saved is part of it.
Crash reporting is off entirely unless the app is built with a reporting key configured. Sentry's own handling of what it receives is covered by their privacy policy.
Install counts
Yayu is built with Expo, and one of the Expo components inside the app reports each cold launch to Expo, giving us install and usage counts. It sends a randomly generated install identifier, the app version, the platform and the OS version — nothing about what you did in the app.
That identifier is a random value created the first time the app runs and stored on the phone. It is not derived from your device or from you, it is not shared with our own usage counts — different server, different request, nothing that joins the two — and deleting the app clears it. Expo's handling of it is covered by their privacy policy.
Notifications
If you turn on the daily reminder, it is scheduled by your phone's own operating system, ahead of time, from words already on the device. There is no push server, no push token, and nothing about a reminder leaves the phone.
Sharing a word
Exporting a word list writes a file into the app's temporary storage and hands it to your phone's share sheet; sharing a card does the same with an image. Where it goes from there is your choice and your other app's business — Yayu does not upload it anywhere. That an export happened is counted, as above; what was in it is not.
Adverts
Yayu shows adverts in two places: a card that appears in the feed in place of a word every few swipes, and a full-screen advert on the way into your Favorites list. They are supplied by Google AdMob.
- Not straight away. Neither kind appears to a new reader. The feed card starts on the third separate day you open the app and the full-screen advert on the fifth — and until the first of those, the advert software is never started at all, so nothing described below leaves your phone.
- On iPhone and iPad the adverts are not personalised. They are chosen without building a profile of you, which is why Yayu never asks for permission to track you across other companies' apps and websites.
- Where the law requires your consent — the EEA and the UK — you are asked before any advert is requested, and until you answer, none is. You can change your answer at any time under Settings → Your advert choices. Declining does not switch adverts off. It limits what Google is allowed to use when choosing them, so you may see less relevant adverts — or, sometimes, none, when nothing suitable is available. That choice is shown only where it applies, so you will not see the row elsewhere.
- There is no setting that turns them off outright. There is no paid tier in this release, so there is no advert-free version of the app to choose.
To show an advert, the app asks Google for one. On Android that request carries your device's advertising ID — an identifier your phone provides for this purpose, which you can reset or opt out of under Settings → Privacy → Ads. On iPhone and iPad no such identifier is sent, because the adverts there are not personalised. The request also carries your IP address and a description of your device. Google uses this for its own advertising business rather than on our behalf, so what it does with it is covered by Google's privacy policy and their partner-sites notice.
That advertising ID is not the install identifier described above, is not sent with our usage counts, and nothing on our side joins the two. We do not receive it. What reaches us from adverts is a count of how many were shown, in Google's dashboard, with nobody's identity attached.
Every advert card is marked as one. Nothing you read, search for, heart or export is sent to Google, and the app does not tell Google which word you were looking at.
What Yayu does not do
- No third-party trackers beyond the advert request described above.
- No advertising identifier on iPhone and iPad, and no tracking anywhere, which is why the app never asks for permission to track you.
- No selling of data to anyone. Apart from Google's part in showing the adverts, the services named above act for us, on our instructions, and not for themselves.
- No access to your location, contacts, photos, microphone or camera.
Children
Yayu is not directed at children and does not knowingly collect personal information from anyone, children included.
Changes
If this policy changes, the date at the top changes with it.
Contact
Questions about this policy: Yayu.daily.chinese@gmail.com