This Privacy Policy explains how HappyCalf Media LLC, doing business as yoyolingo ("yoyolingo," "we," "us," or "our"), collects, uses, discloses, and otherwise processes personal information when you visit www.yoyolingo.app, create or use a yoyolingo account, use our desktop application, make a purchase, contact us, or submit feedback (collectively, the "Services"). If you do not agree with this Policy, do not use the Services.
1. Who we are and how to contact us
HappyCalf Media LLC is responsible for the personal information described in this Policy. Our address is 30 N Gould St Ste N, Sheridan, WY 82801, United States. For privacy questions or requests, email privacy@yoyolingo.app or use www.yoyolingo.app/privacy-request/. For ordinary product support, contact support@yoyolingo.app.
2. Information we collect
Information you provide directly
Depending on how you use the Services, we collect your email address; account and authentication information; account identifiers; information needed to send or verify login codes; messages you send to us; and feedback messages and optional screenshots that you choose to submit. We do not ask for mailing addresses, telephone numbers, government identifiers, biometric information, or payment-card numbers in order to use yoyolingo.
Purchase and subscription information
Paddle acts as merchant of record for purchases made through Paddle Checkout. Paddle collects and processes payment-method information, billing information, taxes, receipts, refunds, chargebacks, and fraud-prevention information under its own notices and terms. We do not receive or store full payment-card numbers or card security codes. We receive limited order, transaction, subscription, refund, chargeback, payment-status, customer-reference, and entitlement information from Paddle as needed to activate and support purchases, administer subscriptions, and meet legal obligations.
Information collected automatically
We collect limited service-operation and security information, including account or session identifiers, device or application identifiers used for authentication, request time, login-verification and rate-limiting events, and security-audit records. If you use a free-trial or referral-code offer, we also process a pseudonymous hash of the authentication device identifier, referral-code redemption records, and trial-entitlement grant, expiry, and usage records. We use these records only to administer the offer and prevent duplicate claims, self-referrals, fraud, and automated abuse. We do not collect hardware serial numbers, MAC addresses, contacts, file paths, media contents, or information about where you share a referral code. When you visit our website or use a networked service, infrastructure providers may also process technical request information such as IP address and browser or device characteristics to deliver and secure the service. We do not use advertising cookies, social-media pixels, cross-site behavioral advertising, or browsing-history profiling.
Information from other sources
We may receive limited transaction and subscription information from Paddle, as described above. We do not obtain personal information from public databases, data brokers, marketing partners, social-media platforms, or affiliate marketing programs.
3. Local media and learning data
yoyolingo is a local-first desktop application. Media files, file paths, full subtitle files, full subtitles, learning history, saved vocabulary, playback progress, waveform caches, and media caches are processed on your device and are not uploaded to yoyolingo merely because you import, view, or play media. You are responsible for ensuring you have the right to use any media or subtitle material you import.
4. Optional AI translation and dictionary features
If you choose to use an optional AI translation or dictionary feature, yoyolingo sends only the subtitle sentence or selected word or phrase that you choose and the language parameters needed to provide that request to the relevant AI provider, currently DeepSeek. The Service is designed not to send your account identifiers, email address, device identifiers, IP address, media files, file paths, full subtitle files, or complete learning history to that provider. Do not include personal information in text you choose to submit to an AI feature. You may opt out of this processing at any time by not using the optional AI feature.
5. How we use information and our legal bases
We use personal information to create and secure accounts; verify logins; provide, activate, and administer the Services and purchases; administer free-trial and referral-code offers; determine offer eligibility and enforce device and one-time-code limits; respond to support and privacy requests; send essential administrative communications; prevent fraud and abuse; protect the security and reliability of our Services; comply with tax, accounting, consumer-protection, and other legal obligations; and establish, exercise, or defend legal claims.
Where the GDPR or UK GDPR applies, our legal bases are performance of a contract, compliance with legal obligations, our legitimate interests in operating and securing the Services (where those interests are not overridden by your rights), consent where required, and protection of vital interests where applicable. We do not use personal information for targeted advertising or for automated decisions producing legal or similarly significant effects.
6. How we disclose information
We disclose personal information only as necessary for the purposes above, including to:
- Cloudflare, for website delivery, account-service infrastructure, security, and secure storage of optional feedback reports;
- Resend, for transactional email delivery and login verification;
- Paddle, our merchant of record, for checkout, payment processing, tax, subscriptions, receipts, refunds, chargebacks, and fraud prevention;
- professional advisers, regulators, law-enforcement authorities, or other parties when required by law or reasonably necessary to protect rights, safety, security, or property; and
- a successor or prospective successor in connection with a merger, financing, acquisition, sale of assets, or similar business transaction, subject to applicable law.
We do not sell personal information and do not share personal information for cross-context behavioral advertising. We do not disclose personal information to online-review platforms, business affiliates, advertising networks, affiliate marketing programs, or unrelated business partners.
DeepSeek processes the text you voluntarily select for an optional AI request as described in Section 4. That text is not designed to contain account or device identifiers; if you intentionally include personal information in selected text, that information will be included in your request to the AI provider.
7. International transfers
We and our providers may process information outside your country of residence. Our Services use Cloudflare infrastructure. The Cloudflare R2 bucket used for optional feedback reports is restricted to the European Union (EU); the Cloudflare D1 account database is restricted to the United States jurisdiction; and Cloudflare Workers operate on Cloudflare’s global network. Accordingly, we do not represent that all Cloudflare processing occurs in one named country. Paddle has identified processing locations that include the United States, United Kingdom, Ireland, Belgium, Germany, and the Netherlands. Resend primarily processes applicable account and email-delivery information in the United States.
Where a transfer is subject to the GDPR, UK GDPR, or similar law, we will use the transfer safeguards required by that law. These may include Standard Contractual Clauses, the UK International Data Transfer Addendum, an adequacy decision, or another valid transfer mechanism made available under the applicable provider terms and data-processing agreement, as applicable.
8. Retention
We retain information only for as long as necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.
- Account information: for the duration of the account relationship. Following a verified deletion request, we delete or anonymize account data within 30 days, except where retention is required for tax, accounting, fraud prevention, dispute resolution, or other legal obligations.
- Service and entitlement information: for the duration of the account, subscription, or purchase relationship and no longer than necessary to provide the Service.
- Free-trial and referral records: for the duration of the offer and up to 24 months afterward to administer the offer, resolve disputes, and prevent duplicate or fraudulent claims. We retain only a pseudonymous device-eligibility hash for this purpose; we do not retain the underlying device identifier in this record.
- Transaction and purchase information: for the period required by applicable tax, accounting, consumer-protection, fraud-prevention, and dispute-resolution requirements.
- Support and privacy inquiries: for the time needed to resolve the inquiry and up to 90 days afterward, unless a longer period is necessary for an ongoing dispute, legal obligation, or security matter.
- Verification, email, and security records: verification codes are retained for up to 10 minutes; transactional-email delivery metadata for up to 90 days; rate-limiting records for up to 24 hours; revoked or expired session records for up to 30 days; and security-audit records for up to 180 days, unless longer retention is necessary to investigate or resolve a security incident, fraud, or legal claim.
- Optional feedback screenshots: stored in secure object storage for up to 2 days and deleted no later than 30 days after the related inquiry is resolved, unless retention is necessary for a legal, security, or dispute-resolution matter.
Local media and learning data remain on your device until you remove them or clear application data.
9. Security
We use reasonable administrative, technical, and organizational measures designed to protect personal information, including access controls, authentication controls, limited credentials, signed webhook validation, and secure service-provider infrastructure. No system or transmission is completely secure; you should use the Services only in a secure environment and notify us promptly of suspected account compromise.
10. Children
yoyolingo is intended only for individuals who are 18 years of age or older. We do not knowingly collect personal information from, or provide Services to, individuals under 18. If we learn that an individual under 18 has created an account or provided personal information, we will take appropriate steps to close the account and delete the personal information, subject to applicable legal retention requirements.
11. Your privacy rights and how to exercise them
Depending on where you live, you may have rights to request access to, correction of, deletion of, restriction of, or objection to processing of your personal information; to receive a portable copy of certain information; to withdraw consent where processing is based on consent; and to appeal a decision regarding a request. These rights are not absolute and may be subject to legal limits and identity verification.
You may submit a request at www.yoyolingo.app/privacy-request/ or email privacy@yoyolingo.app. We will use information supplied in a request only to verify identity or authority and process the request. Authorized agents may be required to provide written authority and we may verify the affected individual’s identity. If we deny a request, you may appeal by emailing privacy@yoyolingo.app.
12. United States privacy disclosures
This section applies to residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, to the extent applicable. In the preceding 12 months, we have collected identifiers (such as email address, account identifiers, and limited technical identifiers); commercial information (such as order, subscription, and payment-status information); internet or other electronic network activity information used for service operation and security; and optional visual information contained in feedback screenshots. We have disclosed those categories to the service providers identified in Section 6 for business purposes. We have not sold personal information or shared it for targeted advertising.
We have not collected California Customer Records information, protected-classification information, biometric information, professional or employment information, education information, geolocation information, or sensitive personal information, except to the limited extent a user voluntarily includes such information in a message or optional screenshot. We do not honor Global Privacy Control as an opt-out signal because we do not sell or share personal information for targeted advertising. We also do not use non-essential cookies, marketing cookies, social-media cookies, pixels, click redirects, or social-media plugins.
California residents may also make a request under California’s "Shine the Light" law by writing to the contact details in Section 1. We do not disclose personal information to third parties for their direct-marketing purposes.
13. Additional regional rights
If you are in the EEA, United Kingdom, Switzerland, Canada, Australia, or New Zealand, you may have additional rights under applicable privacy law. You may contact us using the methods in Section 11 and, where applicable, lodge a complaint with your local data-protection authority. EEA and UK residents may complain to their local supervisory authority or the UK Information Commissioner’s Office. Swiss residents may contact the Federal Data Protection and Information Commissioner. Canadian residents may contact the Office of the Privacy Commissioner of Canada or their provincial regulator. Australian residents may contact the Office of the Australian Information Commissioner, and New Zealand residents may contact the Office of the Privacy Commissioner.
14. Cookies and Do Not Track
Our website does not use Google Analytics, Google Maps APIs, or non-essential advertising or analytics cookies. We may use strictly necessary technical measures for service delivery and security. Because there is no uniform standard for browser Do Not Track signals, we do not respond to Do Not Track signals. This does not change our statement that we do not sell or share personal information for targeted advertising.
15. Changes to this Policy
We may update this Policy when our practices, Services, or legal obligations change. We will post the updated version here and change the effective date. Where required by law, we will provide additional notice of material changes.