Privacy Policy
This policy explains what Lock In Chinese ("we") processes on this website and in the Lock In Chinese app. If anything is unclear, email us at hello@lockinchinese.com.
The short version
- The app is local-first. Your exact study records and Apple's Screen Time data stay on your device. The app sends limited usage analytics, diagnostics, and the information needed to load onboarding and manage subscription or paid 30-day access.
- The Chinese homepage no longer shows a waitlist signup form; it links directly to the App Store. The retained waitlist endpoint can still store an email from an older cached page or client. The website also sends limited funnel analytics and diagnostics, and uses an IP address to rate-limit waitlist submissions.
- We use Meta to measure advertising results, as described below. We do not sell data.
The website (lockinchinese.com)
The homepage previously invited visitors to join a waitlist; that signup form no longer appears now that Lock In Chinese is available on the App Store. If an email was submitted while the waitlist was live, or an older cached page or client still submits one, we store the email address in Cloudflare Workers KV, together with the language site and signup timestamp. We do not pass the email to a third-party email marketing service, and there is no double opt-in. You can ask us to delete it at any time by emailing hello@lockinchinese.com.
The waitlist endpoint uses the visitor IP address as a Cloudflare rate-limit key. The IP address is not added to the waitlist record or the funnel-analytics event.
The site sends two funnel events: a retained waitlist endpoint request still
creates waitlist_joined, and selecting an App Store badge creates
store_clicked. Each event contains a random event ID, event name, timestamp,
app and web-platform labels, language, and source. It does not contain the
waitlist email, IP address, or a persistent visitor identifier. Events go to
our Cloudflare analytics endpoint and then to Amplitude's EU endpoint.
The website server is instrumented with Sentry's EU service for errors and performance monitoring when its Sentry endpoint is enabled. Performance tracing samples 5% of requests.
The website also uses Meta Pixel through Cloudflare Zaraz to report page views and measure advertising results. Cloudflare sends these events to Meta from its servers. This processing can include page URLs, timestamps, browser and device information, IP addresses, and advertising cookie identifiers. Website tracking is separate from Apple's tracking permission in the iPhone app.
The Lock In Chinese app
Lock In Chinese works without an account and keeps its core learning and Screen Time records on your device:
-
Learning records. The exact words you study and your spaced-repetition schedule are stored locally. They are not included in the usage-analytics events sent to our endpoint, Amplitude, or Cloudflare Workers Analytics Engine.
-
Screen Time. The app uses Apple's Screen Time / Family Controls framework to seal apps behind a quiz. Your selected app, category, and website-domain tokens and your usage history stay under iOS's on-device protections. We do not receive which items you selected or how long you use them. When you apply a seal, usage analytics include only the total number of selected apps, categories, and website domains.
-
Usage analytics. The app reports events such as an onboarding step being answered, a quiz being completed, or a seal being applied. These events use counts and fixed labels. Only the reviewed categorical onboarding steps (
goal,level,screen_time,commitment_level, andpledge) may include their fixed answer value. Values from every other step, including the name field and any unknown remotely supplied step, are redacted before analytics leave the app. Events use a random identifier generated for each app launch; the app has no account. This analytics stream does not include Apple's advertising identifier.Events first go to our Cloudflare endpoint and then to Amplitude's EU endpoint. Onboarding events also go to Cloudflare Workers Analytics Engine with the event name, flow, experiment and variant, screen or step, config source, platform, and timestamp. In debug builds, events can still enter the local durable queue, but that queue is not uploaded.
-
Advertising measurement. In versions with Meta app events enabled, the app asks for Apple's tracking permission after onboarding and purchase screens, when the unlocked Home screen is visible. Only after you allow tracking does it initialize the Meta SDK and send app activation and installation events. Meta can use device identifiers, including Apple's advertising identifier, and app interaction data to measure advertising results. Declining tracking does not prevent you from using the app. You can change this permission in iOS Settings under Privacy & Security → Tracking. These identifiers and events can be linked with data Meta holds to measure our advertising. Automatic purchase logging in the Meta SDK is disabled. Purchases continue to use Apple StoreKit and RevenueCat.
-
Crashes, errors, and performance. Release builds use Sentry's EU service for crashes and errors and sample 20% of performance traces. Sentry's automatic app, view-controller, and HTTP tracing is enabled. We do not attach your name or email and do not capture screenshots. Sentry is disabled in debug builds.
-
Send Feedback (screen and voice recording). The app includes an optional feedback recorder. When it is available to your build and you turn Send Feedback on in Settings, shaking your device records your screen and, with your microphone permission, your voice narration, so you can show us a problem instead of describing it. The recording is uploaded to our feedback service and used only to diagnose the issue you reported. Nothing is recorded unless you start a recording yourself, and you can turn the feature off at any time in Settings. iOS shows a system recording indicator whenever a recording is running. If you never enable it, no screen or audio data is captured.
-
Audio for pronunciation. Word audio is downloaded on demand from our content endpoint. The request carries only which audio pack is being fetched.
-
Onboarding and paywall content. On launch, the app requests onboarding and paywall configuration from a server we operate. The request includes a persistent random per-install profile ID, locale, and, when available, the device country or region setting so the device receives a consistent flow variant. It does not include your name, exact study records, SRS schedule, or Screen Time data.
-
Purchases and RevenueCat. Purchases are handled through Apple's App Store and managed with RevenueCat, Inc. RevenueCat processes the purchase and subscription data needed to unlock and restore access. It also receives locale, the available country or region setting, and the fixed categorical onboarding answers for goal, self-reported level, selected screen-time band, commitment level, and pledge completion. If you buy, it also records the onboarding flow and paywall variant shown. RevenueCat does not receive the name you typed, values from unknown onboarding steps, exact study records, your SRS schedule, or actual Apple Screen Time data. Apple's privacy terms also apply to the transaction.
-
Paid 30-day pass. The alternative offer is a single App Store payment for 30 days of access, with no automatic renewal. The app verifies the transaction with StoreKit and stores the access period on your device. Closing or declining an offer does not grant a free pass.
-
The name you type in onboarding. An onboarding screen after the opening introduction asks what to call you. The name is stored on your device and is not sent anywhere.
Children
Lock In Chinese is not directed at children under 13, and we do not knowingly collect data from them.
Changes
If this policy changes, we will update the effective date at the top of this page. Material changes to how we handle data will be announced on this page before they take effect.
Contact
Questions about privacy: hello@lockinchinese.com.