This page applies to TakeYup!'s global edition. Any comparisons with the China edition are retained as background; China-only descriptions do not apply to this app.
Guangzhou Kuke Internet Information Technology Co., Ltd ("we") takes your privacy seriously. Our principle is local first: if something can be done on your device, we do not send it to a server. The personal-habit features of TakeYup! need no account. TakeYup!'s team features need you to sign in, and only when you use them do we process, on our servers, the information those features need. What follows sets out what we process, why, who else receives it, how long we keep it and how you can manage it.
1. Principles we hold to
- Local first — Image recognition and personal habit records all happen on your device. The photos you take to check in, and camera frames, are never sent to us.
- Never sold — We do not sell or rent your personal information, and we do not use it for advertising. We pass information to the service providers named in this policy only in the cases described here, and only as far as the feature in question requires.
- No tracking — Our apps contain no third-party advertising SDKs, do no cross-app tracking and build no profile of you.
- Minimal by default — We do not collect what we do not need. TakeYup!'s personal features work without an account; only TakeYup!'s team features require signing in.
2. TakeYup! (iOS)
TakeYup! is a habit-tracking app whose central feature is checking in with a photo. It has two parts. Personal habits need no account: their data stays on your device, and you can choose to sync it to your own iCloud. Teams, the Plaza and the Inbox need you to sign in: team profiles, check-ins on team habits and interactions are stored on our servers so that you and your teammates can use them. TakeYup! comes as two separate apps, a China edition and a global edition, whose accounts, servers and data are entirely separate:
- Global edition — You sign in with Apple or X. The app connects to api.takeyup.com; the servers are provided by Amazon Web Services (AWS) and located outside mainland China. Content you submit for others to see may first be checked by AWS automated moderation services and, where needed, reviewed by our moderators.
Every personal-habit feature works without signing in. Signing in does not upload your personal habits, personal check-in records or check-in photos either; see 2.3 for the team check-in data sent to our servers.
2.1 Information kept on your device
The following stays on your device (and, if you turn on iCloud sync, in your own iCloud; see 2.2). We cannot access it:
- Personal habits — The names, icons, categories, frequencies, targets, check-in windows and reminders of your personal habits are stored in the app's own database.
- Personal check-in records — The time, recognition result, repetitions, focus time, meals and calories of your personal check-ins; and your stars, stickers, achievements, My foods list and calorie goals. All of it is held in the app's own database.
- Check-in photos — Stored in the app's own directory. They are not added to your photo library and are never uploaded to our servers, including check-ins on team habits. Only the latest 10 check-in photos of each habit are kept. You can turn off "Keep photos on this phone" for a habit: its check-in photos are deleted straight away, its reference photos are kept encrypted and no longer shown, and recognition carries on working.
- Reference photos — Reference photos you take or pick for a habit stay on your device. The photos you choose are uploaded only when, as a team leader, you set shared reference photos for a team habit, or when you submit a personal reference photo request (see 2.3).
- On-device recognition — Working out which habit a photo belongs to, recognising poses, spotting photos of screens and blurry shots, and recognising dishes are all done on your device by models bundled with the app. Camera frames are never uploaded. The image features and skeleton points that recognition produces also stay on your device (except the skeleton points of a team's shared reference photos, which the leader uploads; see 2.3). The first time the anti-cheating model is used, iOS fetches that model's decryption key from Apple; this involves none of your photos or habit data.
- Camera and photos — The camera is used only when you check in with a photo or a pose, take a reference photo or scan a QR code. Photos are accessed through the system photo picker, so the app only receives the images you select.
- Focus whitelist — If you turn on a focus whitelist for a habit, the app uses the iOS Screen Time API to restrict apps outside the whitelist while you focus. The apps you choose are stored on your device as opaque identifiers provided by the system; we cannot see which apps you chose or how you use them.
- Reminders and Live Activities — Scheduled reminders, alarms and the focus timer's Live Activity are all scheduled locally by your device and do not pass through our servers.
2.2 iCloud sync and moving to a new phone
- iCloud sync — Off by default. If you turn it on in Settings, your personal habits, check-ins, check-in and reference photos, categories, stars and stickers, achievements, My foods list, calorie goals and trial start date are stored in the private iCloud database of your own Apple Account and synced between devices signed in to that account. Apple holds this data under its own terms; we cannot access it. Check-ins on team habits and team shared photos are not synced through iCloud. You can turn sync off at any time.
- Moving to a new phone — Put both phones on the same Wi-Fi (or turn on Bluetooth and keep them close) and scan a QR code to move all your data straight from the old phone to the new one. The data is encrypted with a one-time key carried in the QR code and travels only between the two phones, with no server involved.
2.3 Information we collect when you sign in and use team features
When you sign in and use team features, we process the following on our servers:
- Sign-in information — In the China edition you sign in with your phone number, which Alibaba Cloud's number verification service confirms belongs to you. In the global edition you sign in with Apple or X: with Apple we do not ask for your name or email address, and with X we never see your X password. For Apple, X and other third-party accounts, we keep only a one-way hash of the account identifier the provider returns.
- Account profile — A randomly generated account ID, your nickname, your avatar (a photo you upload or one of the preset avatars built into the app) and, if you choose to add one, an email address, which only you and authorised platform staff can see. We also record your interface language and time zone: the language decides which teams the Plaza shows you, and the time zone is used to work out your trial and team dates.
- Sign-in credentials — The credentials our server issues when you sign in are stored only in this device's keychain; the server keeps only a hash of them. Signing out deletes them from the device and invalidates them.
- Push identifiers — While you are signed in with "Message alerts" on, the app uploads the push token Apple assigns and this device's app identifier (identifierForVendor) so that we can send you alerts. They are deleted when you turn message alerts off, sign out or delete your account.
- Subscription verification — When you buy or restore a subscription while signed in, the app sends the transaction information signed by Apple (transaction ID, product, purchase and expiry dates) to our server for verification, so that membership features work in teams. When you buy while signed in, the app also gives Apple your account ID as a transaction tag so that the subscription can be matched to your account. We never see your payment method, card or Apple ID.
- Team profile — For teams you create or manage: the name, the description (in editions where this is available), the team icon (an uploaded image or a preset icon), colour and time zone, settings such as whether the team is shown in the Plaza, whether joining needs approval, the member limit and automatic removal of inactive members, and invite codes.
- Membership — When you joined and left each team, your role (leader or member), join requests, leadership transfers and removals.
- Team habits and personal plans — A team habit's name, icon, check-in method, check-in windows, timer and other rules; the shared reference photos the leader uploads (for pose check-ins, also the skeleton points recognised on the leader's device) and default reminder settings for members; when a personal habit is turned into a team habit, that habit's local ID on your device; and your own frequency, target and time zone for that habit.
- Check-ins on team habits — Check-in records for team habits are uploaded. The information currently uploaded includes: which habit, the check-in time (with time zone), the method (photo, pose or press-and-hold), whether it was recognised automatically or confirmed by you, the repetitions and hold time of a pose check-in, and the personal reference authorisation used. As team features are updated, other data from team check-in records may also be uploaded to provide those features. Check-in photos are not uploaded, and neither are your personal habits or personal check-in records.
- Personal reference photo requests — The photos you submit (up to 9 per request, shrunk to 512 × 512 on your device before upload), the item label and note (in editions where notes are available), and, once a request is approved, the SHA-256 checksums of those photos.
- Interactions and posts — Likes, votes, star gifts and sticker redemptions; and, in editions where posting is available, the posts (title, text and up to 9 images) and comments you publish.
- Messages — Messages sent to your Inbox (such as likes, join requests, review results and penalty notices) and whether you have read them.
- Reports, feedback and appeals — The category, title and text you enter; for a report, we also keep the public version of the reported content at that moment as evidence. You can send feedback without signing in: in that case we keep the contact email you choose to give, if any, and a SHA-256 hash of a random feedback token the app generates on this device (the token itself stays in the device keychain), so that you can follow the progress on this device.
- Block list — Whom you have blocked and when.
- Registration and IP location — When your account is created, we record the IP address at that moment, the country or region code derived from it, and whether it falls in mainland China or in Hong Kong, Macao, Taiwan or elsewhere. While you use online features signed in, we derive your IP location from the IP address you connect from using an offline IP database (province and city within China, country elsewhere); for this we keep only the result, not the IP address.
- Server logs — Our servers log the IP address, time, endpoint and outcome of requests, for security and troubleshooting. Rate limits on phone sign-in use a hash of the IP address.
Images you upload are re-encoded once on your device and again on the server, removing location (GPS), camera and other metadata. Avatars, team icons and reference photos are shrunk to 512 × 512, and post images to no more than 1280 × 720. Images and other data are stored on the servers of the edition you use.
2.4 How we use this information
When you tick the box on the sign-in screen agreeing to the Terms of Use and this policy, we process the information above on the basis of your consent and because it is needed to provide the features you ask for. Content moderation, identity verification and record keeping are also based on legal requirements, and security measures on the need to protect the service and other users. Specifically, we use it to:
- Provide team features — Sign-in, teams, team habits, leaderboards, stars, the Inbox and push alerts. Leaderboard scores are calculated by our server from check-ins on team habits.
- Keep things fair and safe — Check that check-ins follow team rules (for example, only check-ins submitted within 72 hours count), limit request rates, and detect and deal with cheating, abuse, spam and content that breaks the rules.
- Moderate content and meet legal obligations — Review content you submit for others to see, handle reports, feedback and appeals, keep records as the law requires, and cooperate with lawful investigations by the authorities.
- Membership — Verify subscriptions and decide whether membership features are available in teams.
- Support — Reply to your feedback. If you leave an email address, we use it only to contact you about that piece of feedback.
We do not use your information for advertising or to profile you. If we ever want to use it for a purpose not described in this policy, we will ask for your consent first.
2.5 Who can see your information
- Members of the same team — Your public nickname and avatar, role, join date and the number of likes you have received in that team; your completion rate, check-in count, streak and leaderboard score on team habits; and what you post and like in the team. In the China edition, teammates also see your IP location (the global edition does not show it). While your personal reference photo request is open for voting, the teammates who can vote see its photos.
- Teams you ask to join — When you ask to join a team, its members see your public nickname and avatar.
- Other users in the Plaza — For teams shown in the Plaza: the name, icon, colour, member count and limit, number of team habits, total check-ins over the last 7 days, and whether joining needs approval; in editions where posting is available, also the team description and the shared reference photos of its habits. The Plaza never shows member lists, anyone's individual check-ins, or the posts and comments inside a team.
- People you block — Once you block someone, neither of you can see the other's avatar, nickname, posts, comments or leaderboard entry, neither of you receives messages triggered by the other, and they cannot join a team you lead. They are not notified. If you are a team leader, you can still see a blocked member in Manage Members so that you can remove them.
- Our moderators and administrators — To review content, handle reports and run the service, they can see what you submit and the related records, the email address you chose to add, and your phone number in masked form; our back office offers no way to view a full phone number.
- Only you — Your personal habits, check-in photos, phone number, content that has not yet passed review, and your reports, feedback and appeals.
Your nickname, avatar, team profile, team habits and other content are normally shown to others only after they pass review; until then only you can see them.
2.6 Content moderation
To comply with the law and keep the community healthy, everything that others will see is reviewed: nicknames, avatars, team names, descriptions and icons, team habit names and shared reference photos, personal reference photo requests, posts and comments. The preset avatars and team icons built into the app need no review.
- Global edition — May first be checked by AWS automated moderation: text by Amazon Bedrock Guardrails, images by Amazon Rekognition, and text inside images is read by Rekognition and then checked by Guardrails. Anything that cannot be settled automatically goes to our moderators. Requests are sent to the AWS Singapore region, and Bedrock Guardrails may process them in AWS Asia Pacific regions (Singapore, Tokyo, Seoul, Osaka, Mumbai and Sydney). Only the content under review is sent to AWS: never your phone number, email address, sign-in details or billing information.
- Review records — The text and images of every submission are kept as review records for re-review, appeals and lawful investigations. When content is deleted or taken down, or an account is deleted, the version others see is removed, but the review records are not. Once a personal reference photo request ends, its photos are no longer shown to teammates but are likewise kept as review records.
2.7 Third-party services and SDKs
We give the providers below only what the relevant feature needs, and never your personal habits or check-in photos. Each handles the information under its own privacy policy.
- Apple — The App Store and StoreKit (purchases, renewals and transaction verification); the Apple Push Notification service (delivering alerts to your device; a notification contains the message title and text, which may include a team name or nickname); iCloud (only if you turn on sync); and the Core ML model key service (see 2.1). The global edition also uses Sign in with Apple.
- X Corp. (global edition) — When you choose to sign in with X, you authorise it in a web sign-in window provided by the system. Our server exchanges the authorisation code with X to look up your X user ID and keeps only a hash of it; we do not read your posts, follows or messages.
- Amazon Web Services (global edition) — Cloud servers, plus the Amazon Rekognition and Amazon Bedrock Guardrails moderation services (see 2.6).
Open-source components such as GRDB run only on your device and send nothing to anyone. IP location is derived on our servers from the offline ip2region database, without calling any outside service. TakeYup! contains no third-party advertising, analytics or crash-reporting SDK.
2.8 Where data is stored
- Global edition — Account and team data is stored on AWS servers located outside mainland China; where automated moderation is enabled, it runs in AWS Asia Pacific regions (see 2.6). If you live elsewhere, your information is transferred to these locations for processing, and we protect it as applicable law requires.
- Apple services — iCloud, push notifications and the App Store are run by Apple, which decides where that data is stored.
2.9 How long we keep it
- Data on your device — Until you delete it, use Erase Data or uninstall the app. Data in iCloud stays until you delete it.
- Account and team data — For as long as your account exists; when you delete your account, as described in 2.10.
- Sign-in verification data — Sign-in requests expire after 5 minutes. Number verification sessions have their encrypted number cleared when they expire and are deleted after 30 days.
- Unused uploads — Images that, after upload, are not used by any content, request or review record may be cleaned up no earlier than 7 days after upload.
- Review, report and appeal records — Including the photos of personal reference photo requests, review decisions, the handling records of reports and appeals, and audit logs, kept for re-review, appeals, disputes and legal obligations for as long as these purposes require, or longer where the law sets a minimum retention period.
- Leaderboard settlements and star ledgers — Kept as team results and account records for as long as these purposes require.
- Server logs — Kept only as long as needed for troubleshooting and security.
Once a retention period ends, we delete or anonymise the information, unless the law requires otherwise.
2.10 Deleting your account
You can delete your account on the app's Account screen. For safety you need to have signed in within the last 10 minutes and to confirm. Deletion cannot be undone, and it works as follows:
- Account closed — Your account and all its sign-in methods stop working at once and every session is ended. Your phone number, linked third-party sign-ins, push identifiers, IP location, registration record and block list are deleted. Signing in later with the same phone number or third-party account creates a brand-new account; nothing from the old one comes back.
- Profile anonymised — Your nickname becomes "Deleted user", your avatar and email address are removed, and your posts, comments and cheers are taken down.
- Teams — You leave every team automatically. Teams you lead are handed to a member automatically; a team with no member able to take over is disbanded.
- Records we keep — To protect other users and meet legal obligations, we keep facts that involve others and the records we must keep, such as your check-ins on team habits and leaderboard settlements, subscription and star records, and moderation and report records. They are no longer linked to your phone number or third-party accounts.
- Your device and iCloud — Your personal habits and check-ins on your device and your data in iCloud are untouched. To delete them, use Erase Data, uninstall the app or delete the data in iCloud settings. Anonymous feedback sent while signed out is not linked to your account and is not deleted with it.
- Subscriptions — Deleting your account does not cancel an App Store subscription; turn off auto-renewal in your Apple ID account settings.
2.11 Your rights and choices
- See and correct — You can view and change your nickname, avatar, email address and team profiles in the app, see what you have submitted and its review status in My Submissions, and follow your reports, feedback and appeals on the Feedback screen.
- Delete — Deleting a habit in TakeYup! also deletes the check-ins and photos filed under it. Settings → Erase Data deletes all your personal habits, check-ins, photos and stars, including their copies in iCloud if sync is on. You can also delete your own posts and comments, withdraw an open personal reference photo request, leave a team, or delete your account (see 2.10).
- Withdraw consent — At any time you can sign out, turn off iCloud sync or message alerts, unlink extra sign-in methods (one must remain), or revoke camera, notification and Screen Time access under Settings → Privacy & Security on iOS. Withdrawing consent does not affect processing already carried out. Without camera access, photo and pose check-ins are unavailable; press-and-hold check-in is unaffected.
- Uninstall — Uninstalling the app removes all local data.
- Contact and complaints — To exercise these rights, or if you have questions about how we handle your information, email us at the address in section 8. We will reply within the time limits set by law once we have verified your identity. You can also complain to the data protection authority where you live.
4. Data security
Data from TakeYup!'s personal features is processed and stored on your device, so its security rests on your device's own mechanisms, such as passcode, file protection and the keychain. Please keep your device secure. TakeYup!'s account and team data is stored on our servers, where we protect it as follows: all traffic uses HTTPS; phone numbers are stored encrypted, and only hashes of sign-in credentials and third-party account identifiers are kept; metadata is removed from uploaded images; images and content are served only to people entitled to see them; and the back office is not reachable from the public internet, with role-based permissions and logged operations. No security measure is perfect. If a personal information security incident occurs, we will inform you and report it to the authorities as the law requires.
5. Children and minors
Our apps are not directed at children under 13, and we do not knowingly collect personal information from children. If you are under 14 (or another age set by the law where you live), please have a parent or guardian read and agree to this policy before you create a TakeYup! account or use team features. If we learn that we have collected a child's personal information without a guardian's consent, we will delete it as soon as possible. Parents and guardians with questions can contact us at the address below.
6. Cookies and this website
Language preference and necessary cookies
This website stores your manually chosen language in localStorage on your device. This preference contains no account information and is not separately submitted to our servers. The language of a requested page may appear in its URL. Cloudflare may use cookies necessary to provide website security services.
In the apps
Our apps themselves use no cookies; all preferences are stored on your local device.
Hosting
This website uses an Amazon Web Services (AWS) origin server in Singapore. Cloudflare provides DNS, CDN and TLS services. The web servers may keep ordinary access logs (such as IP address, time and page requested), used only for security and troubleshooting.
Your choice
You can clear or block local storage and cookies in your browser settings. If the language preference cannot be stored, you can still select a language using the page links.
7. Changes to this policy
If this policy changes materially, we will update the date at the top of this page and tell you prominently within the app; where a change needs your consent again, we will ask you to confirm.
8. Contact us
Guangzhou Kuke Internet Information Technology Co., Ltd, Room C2303 of 1102, No. 585 Jichang Road, Tangjing Street, Baiyun District, Guangzhou, China. If you have any questions about this policy or your personal information, please get in touch: