Last updated 3 August 2026
The short version
Looking words up needs no account and tells us nothing about you. On the websites, your search history, preferences and offline dictionary stay on your own device, and our analytics sets no cookies and cannot follow you elsewhere. We do not sell your data or share it for advertising, and an account — needed only for purchases — means we hold your email address and a record of what you have bought.
Who We Are
This policy is provided by EmberMitre Limited ("we", "us"), the data controller for everything described here. We are registered in Hong Kong, at:
EmberMitre Limited12th Floor
No. 3 Lockhart Road
Wanchai
Hong Kong
It covers our websites — hanpingchinese.com and hanping.app — and the Hanping Chinese apps for Android and iOS, along with Pixolor. Where one of these behaves differently from the others, this policy says so rather than leaving you to guess.
If you have a question about any of it, please contact us.
What We Collect, and Why
Looking words up requires no account and tells us nothing about you. The dictionary works without you identifying yourself, and we would rather keep it that way.
Website analytics
Our websites use Cloudflare Web Analytics, which counts visits and shows us which pages get used. It sets no cookies, does not fingerprint your device, and cannot follow you to other sites. It records the page, where you arrived from, and general device and country information. Our lawful basis is legitimate interest in understanding how the site is used (Art. 6(1)(f)).
In the apps
The Hanping apps use Firebase Analytics for usage statistics and Firebase Crashlytics for error reporting. You can turn both off in the app's own Settings. The websites have no equivalent setting because their analytics has nothing tied to you to switch off. Lawful basis: legitimate interest in understanding how the apps are used and keeping them reliable (Art. 6(1)(f)).
Hosting
Our sites run on Cloudflare, which handles your IP address and request details in order to serve pages and absorb abuse. Lawful basis: legitimate interest in operating and securing the service (Art. 6(1)(f)).
If you sign in
An account is optional and only needed for purchased features. We collect your email address, or your Google account email if you sign in that way. Sign-in runs through Firebase Authentication and is protected by Cloudflare Turnstile, which checks you are not an automated script. Lawful basis: performance of our contract with you (Art. 6(1)(b)).
If you buy something
Purchases run through RevenueCat whichever platform you are on. The payment itself is taken by Google Play on Android, the App Store on iOS, or Stripe on the web and on Android builds that did not come from Google. Your card details go to whichever of those took the payment, and never to us. We are told what you are entitled to, and we keep a record of the purchase — what it was, when it happened, and which store it came through — because that is what lets your entitlement follow you to a new device. Lawful basis: performance of our contract with you (Art. 6(1)(b)).
If you contact us
When you write to us through the contact form, we receive the name, email address and message you type, and we keep the exchange for as long as it takes to deal with it properly. Our email — that reply, and also sign-in codes and password-reset messages — is delivered by Resend. Lawful basis: legitimate interest in answering people who write to us (Art. 6(1)(f)), or performance of our contract with you for sign-in and password-reset mail (Art. 6(1)(b)).
If you subscribe to the newsletter
The newsletter is opt-in and entirely separate from having an account. If you turn it on, we pass your email address to Mailchimp, who send the mail on our behalf. Turning it off again removes you from that list. Lawful basis: your consent (Art. 6(1)(a)), which you can withdraw at any time.
Word lookups
Searching sends nothing about you anywhere. One exception is worth naming: when we have no entry for a word, our server asks Wikipedia's dictionary (Wiktionary) whether it exists there, so we can offer a link that helps. That request carries the word by itself — not your IP address, and nothing identifying you.
Pronunciation audio
Spoken readings are ordinary audio files served from our own servers. Playing one sends no information to anyone else.
What Stays On Your Device
On our websites, some things never leave your browser at all, and we cannot see them:
- your search history
- your Simplified/Traditional, pinyin/zhuyin and light/dark preferences
- the offline dictionary, if you choose to save one
These live in your browser's own storage. Clearing your browser data removes them, and the offline dictionary can be removed any time from the "Available offline" control at the foot of the page.
The apps likewise keep your history and settings on the device.
Cookies
We use no cookies for advertising, and none for tracking. Our website analytics is cookieless by design, which is a large part of why we chose it.
If you sign in, Firebase stores what it needs to keep you signed in. That is the only case where anything is kept in your browser on our behalf beyond the preferences described above.
How Long We Keep It
- Your account — your email address for as long as the account is open. Deleting your account from the app removes it straight away, along with anything you had backed up online and the links joining your purchases to it. If you would rather ask us to do it, we will, within 30 days.
- Purchase records — kept, but unlinked from you. Closing your account detaches your purchases from it, so the account no longer reaches them; the purchase stays attached to the store account that made it, which is why closing your Hanping account never costs you something you paid for. Sign in again with the same store account and your entitlement comes back. We hold these while a refund, a chargeback or a dispute is still possible.
- Records held by the payment providers — Google, Apple and Stripe keep their own account of a transaction you made with them, under their own policies and their own legal obligations, and that is not ours to delete. RevenueCat is different: it holds its copy on our instructions, so if you ask us, we can have it removed.
- Sign-in codes — about a day. The six-digit code itself stops working after ten minutes; the row behind it, including a one-way hash of your IP address used to spot abuse, is deleted roughly a day later.
- Cloud backups, if a future version of the apps offers them — until you delete the account, at which point they go with it.
- Messages you send us — we keep correspondence for as long as it may still matter to supporting your licence, which does not expire, and for as long as any dispute it relates to is unresolved. We review what is held and clear out what no longer meets either test.
- Newsletter — until you unsubscribe.
- App analytics — event data for 14 months, and the user-level records behind it for two. Crash reports follow Firebase's own 90-day limit, which is theirs to set rather than ours.
- Website analytics — held by Cloudflare under their retention period, and aggregated rather than tied to you in the first place.
If you want anything removed sooner, ask us and we will do it, so far as it is ours to delete — the one exception being the payment providers' own records described above.
Your Rights
If you are in the UK or the EEA, you have the right to:
- access the personal data we hold about you
- have it corrected if it is wrong
- have it deleted
- restrict or object to how we use it — including, at any time, where we rely on legitimate interests
- receive a copy in a portable form
To exercise any of these, contact us. We will verify your identity first, which protects you as much as it protects us, and we do not charge for it.
You can also complain to your data protection authority. In the UK that is the Information Commissioner's Office; in the EEA it is the authority for the country you live in. Because we are a Hong Kong company we are also subject to the Personal Data (Privacy) Ordinance, which gives you rights of access and correction wherever you live, and complaints can go to the Privacy Commissioner for Personal Data, Hong Kong.
App-specific Notes
- Hanping Chinese Camera uses the device's camera to scan text in the real world. No image data is sent from the device. The camera is never used while the camera preview window is not visible on screen.
- Hanping Chinese Popup uses the device's screen recording capability to scan text anywhere on screen, not only inside the app. No image data is sent from the device. While screen recording is taking place, Android shows the "Cast" icon in the status bar.
- Pixolor uses the device's screen recording capability to capture pixels on screen, not only inside the app. No image data is sent from the device. While screen recording is taking place, Android shows the "Cast" icon in the status bar.
Children
Hanping is a language-learning tool made for a general audience. We do not knowingly collect personal data from children under 13. If you believe a child has given us personal data, tell us and we will delete it.
Security
We use appropriate technical and organisational measures to protect the data we hold — access controls, encryption in transit, and established providers who are themselves accountable for the infrastructure they run.
Collecting as little as possible is part of that. Data we never hold cannot be lost.
Changes To This Policy
We will update this page whenever our practices change, and revise the date at the top. A material change will be more than a quiet edit.