LAST UPDATED: 01 JULY 2026 · EFFECTIVE IMMEDIATELY · v3.2
This Privacy Policy (“Policy”) applies to the website lunjitrading.com (the “Website”) and to all mobile applications published by Lunji Trading (“we”, “us”, “our”) on the Apple App Store, Google Play Store, and any other distribution platform we may use (collectively, the “Apps”). It explains how we collect, use, disclose, and safeguard information when you visit the Website or use the Apps.
By accessing the Website or downloading, installing, or using any of the Apps, you confirm that you have read and understood this Policy. If you do not agree with any provision, please discontinue use immediately and uninstall the Apps.
Studio Name: Lunji Trading
Website: lunjitrading.com
Studio Address: University of Stirling Innovation Park, Stirling, Scotland, United Kingdom
General Contact: contact@lunjitrading.com
Support Contact: support@lunjitrading.com
Our overarching philosophy is privacy-by-default and data-minimisation. Our Apps are engineered to process as much data as possible on-device. Where networked services are required, we use end-to-end encryption and never sell personal data.
For the purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable data protection laws, the data controller is:
Lunji Trading
University of Stirling Innovation Park
Stirling, Scotland, United Kingdom
Email: contact@lunjitrading.com
We have appointed a Data Protection Officer (DPO) who can be contacted at contact@lunjitrading.com with the subject line “DPO”. The DPO oversees compliance with this Policy and applicable data protection legislation, and serves as the point of contact for supervisory authorities and data subjects.
For users in the United Kingdom, our nominated representative under Article 27 UK GDPR is available upon written request. For users in the European Union, our nominated representative under Article 27 EU GDPR is available upon written request.
We apply the principle of data minimisation. We collect the minimum information necessary to provide and improve our services. The categories of information we may collect include:
Our Apps may allow you to create, store, and synchronise content (notes, documents, vaults, budgets, training data, etc.). All such content is stored on your device by default. Cloud synchronisation, where offered, is end-to-end encrypted with keys held solely on your devices — we cannot read your content.
We use the information we collect for the following purposes:
We do not use your information for automated decision-making that produces legal effects concerning you, except as required for fraud prevention (e.g., automated bot detection).
Under GDPR Article 6, we rely on the following legal bases:
Some of our Apps integrate third-party advertising platforms to support free tiers and to keep the apps accessible to as many users as possible. Where present, these integrations are designed to comply with the Apple App Store Guidelines (notably Guidelines 5.1.1 and 5.1.2), the Google Play Developer Policy (Ads policy), the EU GDPR, the UK GDPR, the US CCPA/CPRA, the Brazilian LGPD, and applicable age-protection laws.
Advertising is always opt-in on iOS via the App Tracking Transparency (ATT) framework, and on Android via the appropriate privacy controls. Users can revoke consent at any time in device settings or within each App’s settings panel.
The following advertising platforms may be integrated within our Apps. Each operates under its own privacy policy; we list them so that you can review their practices.
For Apps distributed in the European Economic Area (EEA), the United Kingdom, and Switzerland, advertising requires prior consent under the ePrivacy Directive. We implement an IAB-registered Consent Management Platform (CMP) that surfaces the IAB Transparency & Consent Framework (TCF v2.2) signal to all integrated vendors. Vendors not on the IAB Global Vendor List are blocked until consent is provided.
We do not serve personalised advertising to users under the age of 13 (or higher age of digital consent in the relevant jurisdiction). Our Apps that may attract a younger audience either (a) disable advertising entirely, (b) serve only contextual, non-personalised advertising, or (c) gate the entire App behind an age verification screen. See §12 for full age-related provisions.
Our advertising integrations respect sensitive-category restrictions: we do not permit behavioural targeting based on health conditions (e.g., pregnancy, mental health), sexual orientation, religious belief, political affiliation, or trade union membership. AdMob and the major networks offer sensitive-category exclusion APIs that we enable by default.
You can opt out of personalised advertising at any time:
Where advertising is enabled, the following formats may be presented. Each is designed to be dismissible, labelled as advertising, and never disguised as content.
Small, fixed-size or adaptive rectangular ad units displayed at the top or bottom of a screen. Banner ads load asynchronously and consume a constant amount of screen real estate. They do not interrupt the user’s flow and can be dismissed by closing the containing screen. Banner ads are typically filled via the SDKs listed in §7.1, with waterfall or bidding mediation managed by AdMob, AppLovin MAX, or equivalent platforms.
Full-screen ad units presented at natural transition points (e.g., between levels in a game, between screens in a workflow). They are clearly labelled “Advertisement”, display a countdown timer before the close button becomes interactive, and never appear back-to-back or interrupt an in-progress user action. Frequency capping is enforced to limit how often any one user sees an interstitial.
Opt-in video ads that users choose to watch in exchange for an in-app reward (e.g., unlocking a feature, extending a timer, receiving bonus content). The reward is contingent on completion of the video, and the user is informed in advance of the reward and the required watch duration. Rewarded video ads are particularly valued by ad networks and are subject to the most stringent content review by the mediation platforms.
Ad units styled to match the surrounding content but always labelled with a visible “Ad” or “Sponsored” badge. Used sparingly to avoid deceiving the user.
Full-screen ads presented when the user re-opens the App after backgrounding it. Open ads include a clearly visible close button after a brief period and never block core functionality of the App beyond a few seconds. They are skipped entirely when the user has opted out of personalised advertising.
300×250 (or platform equivalent) in-feed ad units commonly used in scrollable content.
All ad formats comply with Apple App Store Guideline 5 (specifically 5.1.1, 5.1.2, 5.1.3) and Google Play Developer Policy “Ads” section, including:
Our Apps published on the Apple App Store comply with the Apple Developer Program License Agreement, the App Store Review Guidelines (including Section 5 “Software Requirements” and Section 5.1 “Privacy”), the App Store Review Guidelines for Kids Category apps where applicable, and Apple’s Human Interface Guidelines. Each App ships with a clearly labelled Privacy Policy URL accessible from the App Store listing and from within the App itself (Settings → Privacy).
We honour the App Tracking Transparency (ATT) framework: any tracking activity as defined by Apple is preceded by the system ATT prompt and only proceeds with the user’s affirmative consent. Our advertising SDKs are configured to respect the user’s ATT response.
Each App’s “App Privacy” section in the App Store accurately reflects the data we collect, the data linked to the user, and the purposes of processing. We update this disclosure whenever our data practices change and submit updated versions via App Store Connect.
Our Apps published on Google Play comply with the Google Play Developer Distribution Agreement, the Google Play Developer Policy (including the “User Data” and “Ads” sections), the Families Policy where applicable, and the EU User Consent Policy. Each App ships with a Privacy Policy URL accessible from the Play Store listing.
For Apps distributed in the EEA, we use Google Play’s “Data safety” section to provide a transparent, accurate summary of data practices. We honour Google Play’s “Delete account” requirement for Apps that enable account creation.
We honour Google’s EU User Consent Policy: any request for consent is presented in clear, plain language, granular per purpose, and never bundled with consent for unrelated processing. We support Google Play’s “Data safety” form, including the declaration of data shared with third parties (advertising networks).
Where our Apps are distributed through alternative channels (Huawei AppGallery, Samsung Galaxy Store, Amazon Appstore, Mac App Store, direct distribution), we apply the privacy and disclosure standards of the Apple App Store and Google Play Store as our baseline. Each platform’s specific requirements (e.g., Huawei’s data localisation in Mainland China, Samsung’s content policy) are honoured in addition.
We are based in the United Kingdom. Where personal data is transferred outside the UK / EEA (for example, to a US-based service provider), we rely on one or more of the following safeguards:
Cloud infrastructure (where used) is hosted in UK / EU regions by default. Our advertising partners may process data in the United States and other jurisdictions; each partner’s privacy policy details their data-handling locations.
This section explains how our practices align with the major data protection regimes applicable to our users. Where regional laws provide additional rights, those rights are honoured in addition to the baseline GDPR rights described in §14.
The EU General Data Protection Regulation (Regulation (EU) 2016/679) applies to all users in the EEA. We honour all GDPR rights (access, rectification, erasure, restriction, portability, objection) and operate in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity & confidentiality, and accountability (Article 5).
The UK GDPR and the Data Protection Act 2018 apply to all users in the United Kingdom. Our compliance framework aligns with the ICO’s accountability framework, and we maintain a Record of Processing Activities (RoPA) as required by Article 30.
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants California residents rights to know, delete, correct, and limit the use of sensitive personal information. We extend these rights to all US users regardless of state residency, in compliance with the Colorado Privacy Act (CPA), the Virginia Consumer Data Protection Act (VCDPA), the Connecticut Personal Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), the Texas Data Privacy and Security Act (TDPSA), the Oregon Consumer Privacy Act (OCPA), and other applicable state laws.
We do not sell personal information. We do not share personal information for cross-context behavioural advertising without opt-in consent where required.
The Personal Information Protection and Electronic Documents Act (PIPEDA) and, in Quebec, An Act to modernize legislative provisions as regards the protection of personal information (Law 25) apply. We comply with the ten fair information principles of PIPEDA and the enhanced consent, transparency, and data-processor obligations of Law 25.
The Lei Geral de Proteção de Dados (LGPD) applies. We honour all rights of data subjects (confirmation, access, correction, anonymisation, portability, elimination, information on sharing) and have appointed a Data Protection Officer reachable at contact@lunjitrading.com.
The Privacy Act 1988 and the Australian Privacy Principles (APPs) apply. We handle personal information in accordance with the APPs and notify users of any eligible data breaches under the Notifiable Data Breaches scheme.
We comply with the Information Privacy Principles (IPPs) of the New Zealand Privacy Act 2020.
The Personal Data Protection Act 2012 (PDPA) applies. We comply with the Consent, Purpose, Notification, Accuracy, Protection, Retention Limitation, and Access/Correction obligations.
The Personal Information Protection Act (PIPA) applies. Where PII of Korean residents is processed, we comply with the requirements for consent, purpose limitation, retention, destruction, and overseas transfer notification.
The Act on the Protection of Personal Information (APPI) applies. We comply with requirements for proper acquisition, purpose of use, security, and third-party provision.
The Digital Personal Data Protection Act, 2023 applies to processing of digital personal data of individuals located in India. We comply with consent, purpose limitation, data fiduciary obligations, and the rights of data principals.
Where our Apps are distributed in Mainland China via specific stores (e.g., Huawei AppGallery, Xiaomi GetApps), the Personal Information Protection Law (PIPL) applies. For China-specific builds, personal information is stored within Mainland China, separate consent is obtained for cross-border transfer, and the requirements of GB/T 35273 (Personal Information Security Specification) are honoured.
For users in regions not specifically enumerated above, we apply the GDPR’s baseline protections as a matter of good practice. If you have questions about your specific jurisdiction, please contact our DPO.
Our Apps are categorised by intended audience. We honour the following age-related rules:
Apps intended for general audiences require the user to be at least 13 years old (the minimum age under COPPA) or the higher age of digital consent in the user’s jurisdiction (14 in Italy, Spain, South Korea; 16 in France for certain processing; 18 in Thailand). By using these Apps, you represent that you meet this requirement.
Apps designed for children (under 13) are clearly marked in their App Store listing and the “Designed for Families” or “Kids Category” banner. For these Apps, we:
Where our Apps are likely to be accessed by children (under 18) in the United Kingdom, we conduct a Data Protection Impact Assessment (DPIA) as required by the ICO’s Age-Appropriate Design Code. We default to high privacy settings, do not use nudge techniques, and do not use dark patterns.
Where the App’s audience includes children under 13, verifiable parental consent is obtained before any personal data collection that is not strictly necessary for the activity. Methods of verifiable consent include signed consent forms, credit card / payment verification, government-ID check, or knowledge-based authentication, as required by COPPA.
If you believe we have collected information from a child under the applicable age threshold in error, please contact contact@lunjitrading.com. We will delete the information within 30 days and confirm the deletion in writing.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Where the law requires a longer retention period (e.g., tax or anti-money-laundering), we retain the data for the legally mandated period.
Subject to applicable law, you have the following rights regarding your personal data:
To exercise any of these rights, please email contact@lunjitrading.com with the subject line “Data Subject Request”. We will respond within 30 days (or earlier where required by law). Where requests are complex or numerous, we may extend the response period by up to two further months and will notify you.
For users in the European Union, our lead supervisory authority is the Information Commissioner’s Office (ICO) of the United Kingdom. You may also lodge a complaint with your local supervisory authority.
We employ industry-standard administrative, technical, and physical safeguards to protect personal data, including:
No system is perfectly secure. If we become aware of a security incident affecting your personal data, we will notify you and the relevant authorities in accordance with applicable law.
We may update this Policy from time to time to reflect changes in our practices, our Apps, the law, or for operational, legal, or regulatory reasons. When we make material changes, we will:
We encourage you to review this Policy periodically. Continued use of the Website or Apps after changes indicates acceptance of the updated Policy.
For any questions, complaints, or data subject requests relating to this Policy, please contact us:
Lunji Trading
University of Stirling Innovation Park
Stirling, Scotland, United Kingdom
Email: contact@lunjitrading.com
Support: support@lunjitrading.com
We aim to respond to all privacy enquiries within 48 business hours. Where a request requires additional time, we will keep you informed of progress.
If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority. For users in the United Kingdom, this is the Information Commissioner’s Office (ico.org.uk). For users in the European Union, this is your national supervisory authority.
— END OF POLICY —